This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] DEEWOO ! Please help HJT Log pasted

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

HELP! Having a nightmare with DEEWOO. Tried quarantine using Asquared Free, System Restore(None Available), Remove Progs and Removing offending files (C:\WINDOWS\system32\pcnttsdl.exe DWmmm01FF and C:\WINDOWS\system32\rswnw64l.exe DWmmm01FF - I believe). Just wont go. Think it just adds lots of adware which is running my system to a standstill.

Downloaded HJT and ERUND. Have read some other threads so know I should wait before continuing.

Here is my log. Thank you

Carl


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:29:15, on 18/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\a-squared free\a2service.exe
C:\WINDOWS\Q2FybCBRdWFydGVybWFpbg\command.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\windows\system32\rswnw64l.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\regsvr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Carl\Application Data\gadcom\gadcom.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\pcnttsdl.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\GetPack\GetPack24.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [IMJPMIG8.2] msime82.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [HPHUPD08] C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [trioService] "C:\PROGRA~1\Freeze.com\Halloween\\trioService.exe "
O4 - HKLM\..\Run: [prunnet] "C:\WINDOWS\system32\prun.exe"
O4 - HKLM\..\Run: [{D6-6C-C3-3D-DW}] C:\windows\system32\rswnw64l.exe DWmmm01FF
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\pcnttsdl.exe DWmmm01FF
O4 - HKLM\..\Run: [8ccd6c92] rundll32.exe "C:\WINDOWS\system32\frwssnju.dll",b
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [vdfhaeheeuhnyxqtq] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\pyinryaknafj.dll"
O4 - HKCU\..\Run: [MsServer] msfun80.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [prunnet] "C:\WINDOWS\system32\prun.exe"
O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\Carl\Application Data\gadcom\gadcom.exe" 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKCU\..\Run: [GetPack24] "C:\Program Files\GetPack\GetPack24.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32\pcnttsdl.exe
O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\rswnw64l.exe
O4 - Global Startup: Exif Launcher S.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZUxdm443YYGB
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Amazing%20Adventures%20The%20Lost%20Tomb/Images/stg_drm.ocx
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by119fd.bay119.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.euchannels.net/KooPlayer.ocx
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Br…018/flashax.cab
O20 - AppInit_DLLs: cwulmy.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Q2FybCBRdWFydGVybWFpbg\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 10573 bytes
Hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.
Ok I'm back after fiddling for some time. Have editted and re-editted this so apologise if you have been on trying to access.
Anyway here's an update from your last message to now:

Couldn't get Safe Mode to work (no beep and when I did get screen up by switching off during boot, it wouldn't toggle to safe mode??

Ran SDFix Runthis.bat anyway and it had no 'Y' option (tried Y anyway but nothing happened on reboot)

Options that are available are 1,2,3,4 A,B,C,D,H,R,U or E (exit)


A is create system report
B is create service /driver list
C is Create catchMe log
D is Export Safeboot Key
H is Add Window Default Host File
R is Repair Safeboot Key
U is Download Latest SDFix
1 is download ASquared
2 is DoWnload Norman Malware Cleaner
3 is Sav32cu
4 is AVPTOOL

So….

Downloaded and ran COMBOFIX

I tried this because I read through other posts on this and other sites. I havent DEEWOO, it is no longer in Start up and looks to be gone. Still didnt get a beep when loading up however never tried F8 to see if safe mode works (will do next time I log in). I have pasted the Combofix log below. What do you think? Below this is an updated HJT log? Below this I have pasted a scan report from ASquared which I run to see if i had any adware. I quarantined Trojan-Downloader.W32.Small.buy which came out as a high risk and a trace registry for Kazaa which I havent got downloaded on this PC.

I AM STILL GETTING POP UPS - while on line - not intense 3 pagescame on and after 30 mins+ another page popped up. Havent done reboot yet but doubt this affects it.

What do you recommend now. Also what should I download as protection for my system against adware,spyware,malware,virus etc. I have ASquared (which has worked with some things) and also this Norton Check Up thing(Which doesnt do anything really, so will delete shortly I think)

Once again thanks for your assistance. Now for the reboot!! Speak soon, thanks


================================================================================
==================================

ComboFix 08-11-19.08 - Carl 2008-11-20 10:22:10.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.543 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
c:\docume~1\Carl\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\Carl\Application Data\gadcom
c:\documents and settings\Carl\Application Data\gadcom\gadcom.exe
c:\documents and settings\Carl\Application Data\ShoppingReport
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\Config.xml
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\db\Aliases.dbs
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\db\Sites.dbs
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\report\aggr_storage.xml
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\report\send_storage.xml
c:\documents and settings\Carl\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
c:\documents and settings\Carl\Favorites\Online Security Test.url
c:\documents and settings\Carl\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\Carl\Start Menu\Programs\Startup\Deewoo.lnk
c:\documents and settings\Carl\Start Menu\Programs\Startup\DW_Start.lnk
c:\documents and settings\LocalService\Application Data\NetMon
c:\documents and settings\LocalService\Application Data\NetMon\domains.txt
c:\documents and settings\LocalService\Application Data\NetMon\log.txt
c:\program files\GetPack
c:\program files\GetPack\dictame.gz
c:\program files\GetPack\GetPack24.exe
c:\program files\GetPack\trgtame.gz
c:\program files\iCheck
c:\program files\iCheck\Uninstall.exe
c:\program files\Mjcore
c:\program files\Mjcore\Mjcore.dll
c:\program files\network monitor
c:\program files\network monitor\netmon.exe
c:\program files\OneStepSearch
c:\program files\OneStepSearch\home.js
c:\program files\OneStepSearch\readme.html
c:\program files\pcast
c:\recycler\ADAPT_Installer.exe
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\windows\Downloaded Program Files\setup.inf
c:\windows\Q2FybCBRdWFydGVybWFpbg\
c:\windows\Q2FybCBRdWFydGVybWFpbg\\asappsrv.dll
c:\windows\Q2FybCBRdWFydGVybWFpbg\\command.exe
c:\windows\Q2FybCBRdWFydGVybWFpbg\\kZIVvF1lxqIVx3pVvqIDv0.vbs
c:\windows\Q2FybCBRdWFydGVybWFpbg\command.exe
c:\windows\system32\aqmmyf.dll
c:\windows\system32\atmtd.dll
c:\windows\system32\cgaiho(2).dll
c:\windows\system32\cwulmy.dll
c:\windows\system32\ddcBQkHY.dll
c:\windows\system32\dwwnw64r.exe
c:\windows\system32\fwpsuvnh.ini
c:\windows\system32\gside.exe
c:\windows\system32\hnvuspwf.dll
c:\windows\system32\kltgacrf.dll
c:\windows\system32\kprqfdio.dll
c:\windows\system32\mlqlma.dll
c:\windows\system32\MSINET.oca
c:\windows\system32\msnav32.ax
c:\windows\system32\pac.txt
c:\windows\system32\ppjfuq.dll
c:\windows\system32\rkpvvptx.dll
c:\windows\system32\rqRLdETM.dll
c:\windows\system32\rswnw64l.exe
c:\windows\system32\ssqPICRI.dll
c:\windows\system32\sxvgbvab.dll
c:\windows\system32\ujnsswrf.ini
c:\windows\system32\winpfz33.sys
c:\windows\system32\YHkQBcdd.ini
c:\windows\system32\YHkQBcdd.ini2
c:\windows\system32\ykogmycl.ini
c:\windows\system32\zxdnt3d.cfg
c:\windows\ufdata2000.log
c:\windows\uninstall_nmon.vbs

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_CMDSERVICE
——-\Legacy_NETWORK_MONITOR
——-\Service_cmdService
——-\Service_Network Monitor


((((((((((((((((((((((((( Files Created from 2008-10-20 to 2008-11-20 )))))))))))))))))))))))))))))))
.

2008-11-20 09:11 . 2008-11-20 09:11 1,529,241 –a—— C:\SDFix.exe
2008-11-20 08:52 . 2008-11-20 08:52 41,472 –a—— c:\windows\system32\vxnpwxlw.dll
2008-11-20 00:13 . 2008-11-20 09:59 d——– C:\SDFix
2008-11-20 00:07 . 2008-11-20 00:07 465,920 –a—— c:\windows\system32\iesvcmon.exe
2008-11-20 00:07 . 2008-11-20 00:07 53,938 –a—— c:\windows\system32\cont_adsoftinc-remove.exe
2008-11-19 10:15 . 2008-11-19 10:15 600,576 –a—— c:\windows\system32\jpvycakhwzdspam.dll
2008-11-19 07:24 . 2008-11-19 07:24 41,472 –a—— c:\windows\system32\gklxpket.dll
2008-11-18 23:49 . 2008-11-18 23:49 41,472 –a—— c:\windows\system32\dwtqibih.dll
2008-11-18 23:29 . 2008-11-18 23:29 d——– c:\program files\Trend Micro
2008-11-18 22:57 . 2008-11-18 22:57 d——– c:\program files\ERUNT
2008-11-18 22:29 . 2008-11-20 08:52 88,372 –a—— c:\windows\system32\jpvycakhwzdspam.dll-uninst.exe
2008-11-17 23:48 . 2008-11-17 23:48 41,472 –a—— c:\windows\system32\upryaxhx.dll
2008-11-17 23:43 . 2008-11-17 23:43 d——– c:\program files\PartyGaming
2008-11-17 16:59 . 2008-11-17 16:59 d——– c:\documents and settings\Carl\Application Data\IUpd721
2008-11-17 16:46 . 2008-11-17 16:46 548,928 –a—— c:\windows\system32\pcnttsdl.exe
2008-11-17 16:46 . 2008-11-17 16:46 153,483 –a—— c:\windows\system32\g76.exe
2008-11-17 16:46 . 2008-11-18 12:30 77,895 –a—— c:\windows\system32\cirjrsdilspfpvb.exe
2008-11-17 16:45 . 2008-11-17 16:45 d——– c:\windows\system32\sX3i19
2008-11-17 16:45 . 2008-11-17 16:45 d——– c:\windows\system32\nas
2008-11-17 16:45 . 2008-11-17 16:46 d——– c:\windows\system32\mex
2008-11-17 16:45 . 2008-11-17 16:45 d——– c:\windows\system32\ITX
2008-11-17 16:45 . 2008-11-17 16:45 d——– c:\windows\system32\dcs2
2008-11-17 16:45 . 2008-11-17 16:46 d——– c:\temp\PRE45
2008-11-17 16:45 . 2008-11-20 10:23 d——– C:\Temp
2008-11-17 16:45 . 2008-11-17 16:45 35,840 –a—— c:\windows\system32\prun.exe
2008-11-15 15:32 . 2008-11-15 15:32 d——– c:\program files\TVUPlayer
2008-11-15 15:32 . 2008-11-15 15:32 d——– c:\documents and settings\Carl\LocalLow
2008-11-15 15:32 . 2008-11-15 15:32 d——– c:\documents and settings\All Users\Application Data\TVU Networks
2008-11-01 09:37 . 2008-11-01 09:37 178,176 –a—— c:\windows\system32\pyinryaknafj.dll
2008-10-28 15:20 . 2008-10-28 15:20 555,008 –a—— c:\windows\system32\nsn59D.dll
2008-10-26 14:35 . 2008-10-26 14:35 d——– c:\program files\iLike
2008-10-21 22:53 . 2008-10-21 22:53 d——– c:\program files\Freeze.com
2008-10-21 22:53 . 2008-10-21 23:07 243 –a—— C:\log.html

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-17 23:43 ——— d—–w c:\program files\Winferno
2008-11-11 10:18 ——— d—–w c:\documents and settings\Carl\Application Data\Image Zone Express
2008-11-03 19:46 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-03 08:33 ——— d—–w c:\program files\Common Files\Adobe
2008-11-02 20:43 ——— d—–w c:\program files\Windows Live
2008-11-02 15:15 ——— d—–w c:\program files\PKR
2008-11-01 12:05 ——— d—–w c:\program files\Zylom Games
2008-10-30 17:03 ——— d—–w c:\program files\iTunes
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-21 13:23 ——— d—–w c:\program files\Microsoft Silverlight
2008-10-12 09:28 ——— d—–w c:\documents and settings\Carl\Application Data\Zylom
2008-10-12 09:28 ——— d—–w c:\documents and settings\Carl\Application Data\Jane s Hotel Family Hero
2008-10-07 20:00 ——— d—–w c:\documents and settings\Carl\Application Data\Total Eclipse
2008-10-06 16:29 ——— d—–w c:\documents and settings\All Users\Application Data\Sandlot Games
2008-10-02 20:46 ——— d—–w c:\documents and settings\Carl\Application Data\PlayFirst
2008-10-02 20:46 ——— d—–w c:\documents and settings\All Users\Application Data\PlayFirst
2008-09-28 21:07 ——— d—–w c:\program files\UUTV
2008-09-28 10:49 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-09-28 09:50 ——— d—–w c:\documents and settings\All Users\Application Data\SpinTopV1005
2008-09-28 09:42 ——— d—–w c:\program files\FinePixViewerS
2008-09-27 20:54 ——— d—–w c:\documents and settings\All Users\Application Data\Zylom
2008-09-26 10:19 ——— d—–w c:\documents and settings\All Users\Application Data\GameHouse
2008-09-21 12:48 ——— d—–w c:\documents and settings\Carl\Application Data\SpinTop
2007-06-04 21:44 20,632 —-a-w c:\documents and settings\Carl\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5CF9E491-A3D7-4C5A-CA99-A8DE8FA87955}]
2008-11-20 09:44 325120 –a—— c:\windows\system32\pyinryaknafj.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74fe2921-9c19-35aa-8e46-c45c444e809c}]
2008-10-28 15:20 555008 –a—— c:\windows\system32\nsn59D.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E0E80497-094E-6810-BB98-70792C1068C4}]
2008-11-19 10:15 600576 –a—— c:\windows\system32\jpvycakhwzdspam.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]
"prunnet"="c:\windows\system32\prun.exe" [2008-11-17 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-12 7626752]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-12 86016]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 49152]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-06-23 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"prunnet"="c:\windows\system32\prun.exe" [2008-11-17 35840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"iesvcmon"="c:\windows\system32\iesvcmon.exe" [2008-11-20 465920]
"vdfhaeheeuhnyxqtq"="c:\windows\system32\pyinryaknafj.dll" [2008-11-20 325120]
"nwiz"="nwiz.exe" [2006-07-12 c:\windows\system32\nwiz.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-01 c:\windows\RTHDCPL.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 c:\windows\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 c:\windows\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]
"iLike"="c:\program files\iLike\1.1.51\ilikesidebar.exe" [2008-09-10 63024]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Exif Launcher S.lnk - c:\program files\FinePixViewerS\QuickDCF2.exe [2008-01-18 303104]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-01-20 671744]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=ppjfuq.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Documents and Settings\\Carl\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\PPMate\\PPMate\\ppmate.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=

R2 LBeepKE;LBeepKE;c:\windows\system32\Drivers\LBeepKE.sys [2007-01-20 3712]
S3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [2007-01-21 167424]
.
Contents of the 'Scheduled Tasks' folder

2008-11-12 c:\windows\Tasks\At1.job
- c:\program files\norton pc checkup\pc_checkup.exe [2008-06-29 21:50]

2008-11-15 c:\windows\Tasks\At2.job
- c:\program files\norton pc checkup\pc_checkup.exe [2008-06-29 21:50]

2008-10-22 c:\windows\Tasks\rpc.job
- c:\program files\Winferno\RegistryPowerCleaner\RegPowerClean.exe []
.
- - - - ORPHANS REMOVED - - - -

BHO-{c9f821c6-221f-4c6e-8f47-359adc5f2b01} - c:\windows\system32\ppjfuq.dll
BHO-{E4EDCFE7-5488-4A47-B175-4F45FBA15683} - c:\windows\system32\ddcBQkHY.dll
HKCU-Run-GetPack24 - c:\program files\GetPack\GetPack24.exe
HKLM-Run-trioService - c:\progra~1\Freeze.com\Halloween\\trioService.exe
HKLM-Run-{D6-6C-C3-3D-DW} - c:\windows\system32\rswnw64l.exe
HKLM-Run-IMJPMIG8.2 - msime82.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Carl\Application Data\Mozilla\Firefox\Profiles\3eyqhdeo.default\
FF -: plugin - c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF -: plugin - c:\documents and settings\Carl\Application Data\Mozilla\Firefox\Profiles\3eyqhdeo.default\extensions\[removed]\plugins\npTVUAx.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF -: plugin - c:\program files\Virtools\3D Life Player\npvirtools.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-20 10:34:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\a-squared Free\a2service.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Common Files\Logitech\khalshared\KHALMNPR.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
c:\windows\system32\regsvr32.exe
.
**************************************************************************
.
Completion time: 2008-11-20 10:45:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-20 10:45:21

Pre-Run: 24,163,655,680 bytes free
Post-Run: 25,139,478,528 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer

275 — E O F — 2008-11-12 22:18:40

================================================================================
====================
HIJACKTHIS LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:25:50, on 20/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\WINDOWS\system32\iesvcmon.exe
C:\WINDOWS\System32\regsvr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
c:\program files\a-squared free\a2service.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: agadoo browser enhancer - {5CF9E491-A3D7-4C5A-CA99-A8DE8FA87955} - C:\WINDOWS\system32\pyinryaknafj.dll
O2 - BHO: adsoftinc - {74fe2921-9c19-35aa-8e46-c45c444e809c} - C:\WINDOWS\system32\nsn59D.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: mysidesearch search enhancer - {E0E80497-094E-6810-BB98-70792C1068C4} - C:\WINDOWS\system32\jpvycakhwzdspam.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [HPHUPD08] C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [prunnet] "C:\WINDOWS\system32\prun.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iesvcmon] "C:\WINDOWS\system32\iesvcmon.exe"
O4 - HKLM\..\Run: [vdfhaeheeuhnyxqtq] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\pyinryaknafj.dll"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [prunnet] "C:\WINDOWS\system32\prun.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [iLike] C:\Program Files\iLike\1.1.51\ilikesidebar.exe /checkforupdate (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
O4 - Global Startup: Exif Launcher S.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZUxdm443YYGB
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Amazing%20Adventures%20The%20Lost%20Tomb/Images/stg_drm.ocx
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by119fd.bay119.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.euchannels.net/KooPlayer.ocx
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Br…018/flashax.cab
O20 - AppInit_DLLs: ppjfuq.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 9839 bytes

================================================================================
==================================
a-squared Free - Version 3.1
Last update: 13/02/2008 23:19:01

Scan settings:

Objects: Memory, Traces, Cookies, C:\WINDOWS\, C:\Program Files
Scan archives: On
Heuristics: On
ADS Scan: On

Scan start: 20/11/2008 11:32:47

c:\documents and settings\carl\application data\microsoft\internet explorer\quick launch\titan poker.lnk detected: Trace.File.Titan Poker
c:\documents and settings\all users\start menu\programs\titan poker\titan poker.lnk detected: Trace.File.Titan Poker
c:\documents and settings\all users\start menu\programs\titan poker\uninstall titan poker.lnk detected: Trace.File.Titan Poker
Key: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\software\kazaa detected: Trace.Registry.KaZaA
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Titan Poker –> Order detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_music detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_avatar_num detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_sounds detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options-fullscreen detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options-volume detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> ButtonText detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> Default Visible detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> Exec detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> HotIcon detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> Icon detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> MenuText detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> ToolTip detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Titan Poker –> DisplayName detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Titan Poker –> UninstallString detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> account detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> advertisercode detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> banner detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> creferer detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> profile detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> referer detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> safemode detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> uninstall detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> uninstall_lang detected: Trace.Registry.Titan Poker
c:\program files\winferno\registrypowercleaner detected: Trace.Directory.RegistryPowerCleaner
c:\program files\partygaming detected: Trace.Directory.PartyPoker
c:\program files\partygaming\images detected: Trace.Directory.PartyPoker
c:\program files\partygaming\language detected: Trace.Directory.PartyPoker
c:\program files\partygaming\language\en_us detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\de_de detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\de_de\images detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images\games detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images\games\cardgames detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images\games\cardgames\blackjack detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images\games\cardgames\blackjack\blackjack detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images\games\cardgames\multiplayerbj detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\en_us\images\games\cardgames\multiplayerbj\multiplayerblackjack detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\es_es detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partycasino\language\es_es\images detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partypoker detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partypoker\images detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partypoker\language detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partypoker\language\en_us detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partypoker\language\en_us\articles detected: Trace.Directory.PartyPoker
c:\program files\partygaming\partypoker\language\en_us\images detected: Trace.Directory.PartyPoker
c:\documents and settings\carl\start menu\programs\partypoker detected: Trace.Directory.PartyPoker
c:\documents and settings\all users\start menu\programs\titan poker detected: Trace.Directory.Titan Poker
c:\documents and settings\carl\application data\microsoft\internet explorer\quick launch\partypoker.lnk detected: Trace.File.PartyPoker
c:\program files\partygaming\ara.ini detected: Trace.File.PartyPoker
c:\program files\partygaming\dm.dll detected: Trace.File.PartyPoker
c:\program files\partygaming\libeay32.dll detected: Trace.File.PartyPoker
c:\program files\partygaming\llh.dll detected: Trace.File.PartyPoker
c:\program files\partygaming\partycasino\gra.ini detected: Trace.File.PartyPoker
c:\program files\partygaming\partycasino\partycasino.dll detected: Trace.File.PartyPoker
c:\program files\partygaming\partycasino\sys.ini detected: Trace.File.PartyPoker
c:\program files\partygaming\partygaming.exe detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\gra.ini detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\language\en_us\articles\54866.atc detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\language\en_us\articles\54870.atc detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\language\en_us\articles\62958.atc detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\partypoker.dll detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\ppunistall.bat detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\runapp.exe detected: Trace.File.PartyPoker
c:\program files\partygaming\partypoker\sys.ini detected: Trace.File.PartyPoker
c:\program files\partygaming\ssleay32.dll detected: Trace.File.PartyPoker
c:\program files\partygaming\zlib1.dll detected: Trace.File.PartyPoker
c:\documents and settings\carl\start menu\programs\partypoker\partypoker.lnk detected: Trace.File.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 1 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 10 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 2 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 4 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 5 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 6 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 7 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> 9 detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> AdsLastKnownState detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> AppPath detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> BlackjackSounds detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> BlackjackVoice detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> EnableCallOuts detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> EnableCardAnimations detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> EnableCongratulations detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> EnableSounds detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> FourColourDeck detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> HHEnableLog detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> HHLogDays detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> HHLogSize detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> id detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> InitialPort detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> InstallState detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> MuckLosingHand detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> SL detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> TableType detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming\PartyPoker –> useCount detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming –> AutoLoginToOtherGames detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming –> CFDialogShown detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming –> FreshInstall detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\PartyGaming –> OldCFformat detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> ButtonText detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> CLSID detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> Default Visible detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> Exec detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> HotIcon detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> Icon detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> MenuStatusBar detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> MenuText detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} –> Path detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> DisplayIcon detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> DisplayName detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> DisplayVersion detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> InstallDate detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> InstallLocation detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> InstallSource detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> InstallSourceFile detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> Publisher detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> SilentSettings detected: Trace.Registry.PartyPoker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker –> UninstallString detected: Trace.Registry.PartyPoker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> funaccount detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> funnickname detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> funusername detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> global_login_hint detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> lobby_favouritegames detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_autologinfun detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_dealervoices detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_filter_empty detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_filter_finished detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_filter_full detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_filter_inprogress detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_showsidegames detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_poker_smallview detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> options_xlslots detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> poker_login_type detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> poker_nickname detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> ptdevm detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> tribeca_playernotes detected: Trace.Registry.Titan Poker
Value: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\Software\Titan Poker –> username detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543} –> CLSID detected: Trace.Registry.Titan Poker
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Titan Poker –> homedir detected: Trace.Registry.Titan Poker
C:\Documents and Settings\Carl\Cookies\[removed][1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@adtech[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@advertising[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@atdmt[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@computerhope[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@doubleclick[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\[removed][1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@hitbox[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@hotbar[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\[removed][1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@media6degrees[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@mediaplex[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@mediatraffic[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@pro-market[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@realmedia[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@revenuehit[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\[removed][1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\[removed][3].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@tradedoubler[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@tribalfusion[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Carl\Cookies\carl@zedo[1].txt detected: Trace.TrackingCookie
C:\WINDOWS\system32\ITX\CMAE3av.exe detected: Trojan-Downloader.Win32.Small.buy
C:\Program Files\EA GAMES\The Sims 2 Double Deluxe\Base\TSBin\Sims2.exe detected: Heuristic.Dialer.RAS
C:\Program Files\EA GAMES\The Sims 2 Double Deluxe\EP2\TSBin\Sims2EP2.exe detected: Heuristic.Dialer.RAS
C:\Program Files\EA GAMES\The Sims 2 Double Deluxe\SP4\TSBin\Sims2SP4.exe detected: Heuristic.Dialer.RAS

Scanned

Files: 96776
Traces: 369019
Cookies: 214
Processes: 42

Found

Files: 4
Traces: 146
Cookies: 21
Processes: 0
Registry keys: 0

Scan end: 20/11/2008 12:02:15
Scan time: 0:29:28

C:\WINDOWS\system32\ITX\CMAE3av.exe quarantined: Trojan-Downloader.Win32.Small.buy
Key: HKEY_USERS\S-1-5-21-1078081533-117609710-725345543-1004\software\kazaa quarantined: Trace.Registry.KaZaA

quarantined:

Files: 1
Traces: 1
Cookies: 0
Please only do the steps I ask you to do or you may wreck your PC


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

file::
c:\windows\system32\vxnpwxlw.dll
c:\windows\system32\iesvcmon.exe
c:\windows\system32\cont_adsoftinc-remove.exe
c:\windows\system32\jpvycakhwzdspam.dll
c:\windows\system32\gklxpket.dll
c:\windows\system32\dwtqibih.dll
c:\windows\system32\jpvycakhwzdspam.dll-uninst.exe
c:\windows\system32\upryaxhx.dll
c:\windows\system32\pcnttsdl.exe
c:\windows\system32\g76.exe
c:\windows\system32\cirjrsdilspfpvb.exe
c:\windows\system32\prun.exe
c:\windows\system32\pyinryaknafj.dll
c:\windows\system32\nsn59D.dll
C:\log.html

folder::
c:\windows\system32\sX3i19
c:\windows\system32\nas
c:\windows\system32\mex
c:\windows\system32\ITX
c:\windows\system32\dcs2
c:\temp\PRE45
c:\program files\Freeze.com



Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Here it is. Thanks. PC seems ok. No pop ups since i booted up.




ComboFix 08-11-19.08 - Carl 2008-11-21 17:26:45.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.600 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Carl\Desktop\cfscript.txt
* Created a new restore point

FILE ::
C:\log.html
c:\windows\system32\cirjrsdilspfpvb.exe
c:\windows\system32\cont_adsoftinc-remove.exe
c:\windows\system32\dwtqibih.dll
c:\windows\system32\g76.exe
c:\windows\system32\gklxpket.dll
c:\windows\system32\iesvcmon.exe
c:\windows\system32\jpvycakhwzdspam.dll
c:\windows\system32\jpvycakhwzdspam.dll-uninst.exe
c:\windows\system32\nsn59D.dll
c:\windows\system32\pcnttsdl.exe
c:\windows\system32\prun.exe
c:\windows\system32\pyinryaknafj.dll
c:\windows\system32\upryaxhx.dll
c:\windows\system32\vxnpwxlw.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\log.html
c:\program files\Freeze.com
c:\temp\PRE45
c:\temp\PRE45\pG8.log
c:\windows\system32\dcs2
c:\windows\system32\dcs2\CGZ3I5.exe
c:\windows\system32\dwtqibih.dll
c:\windows\system32\g76.exe
c:\windows\system32\gklxpket.dll
c:\windows\system32\iesvcmon.exe
c:\windows\system32\ITX
c:\windows\system32\mex
c:\windows\system32\nas
c:\windows\system32\nas\amitg44.exe
c:\windows\system32\pcnttsdl.exe
c:\windows\system32\prun.exe
c:\windows\system32\sX3i19
c:\windows\system32\sX3i19\sX3i191065.exe
c:\windows\system32\upryaxhx.dll
c:\windows\system32\vxnpwxlw.dll

.
((((((((((((((((((((((((( Files Created from 2008-10-21 to 2008-11-21 )))))))))))))))))))))))))))))))
.

2008-11-20 09:11 . 2008-11-20 09:11 1,529,241 –a—— C:\SDFix.exe
2008-11-20 00:13 . 2008-11-20 09:59 d——– C:\SDFix
2008-11-18 23:29 . 2008-11-18 23:29 d——– c:\program files\Trend Micro
2008-11-18 22:57 . 2008-11-18 22:57 d——– c:\program files\ERUNT
2008-11-17 16:59 . 2008-11-17 16:59 d——– c:\documents and settings\Carl\Application Data\IUpd721
2008-11-17 16:45 . 2008-11-21 17:27 d——– C:\Temp
2008-11-15 15:32 . 2008-11-15 15:32 d——– c:\program files\TVUPlayer
2008-11-15 15:32 . 2008-11-15 15:32 d——– c:\documents and settings\Carl\LocalLow
2008-11-15 15:32 . 2008-11-15 15:32 d——– c:\documents and settings\All Users\Application Data\TVU Networks
2008-10-26 14:35 . 2008-10-26 14:35 d——– c:\program files\iLike

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-20 13:48 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-20 13:46 ——— d—–w c:\program files\Common Files\InstallShield
2008-11-17 23:43 ——— d—–w c:\program files\Winferno
2008-11-11 10:18 ——— d—–w c:\documents and settings\Carl\Application Data\Image Zone Express
2008-11-03 19:46 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-03 08:33 ——— d—–w c:\program files\Common Files\Adobe
2008-11-02 20:43 ——— d—–w c:\program files\Windows Live
2008-11-02 15:15 ——— d—–w c:\program files\PKR
2008-11-01 12:05 ——— d—–w c:\program files\Zylom Games
2008-10-30 17:03 ——— d—–w c:\program files\iTunes
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-21 13:23 ——— d—–w c:\program files\Microsoft Silverlight
2008-10-16 14:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 14:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 14:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 14:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 14:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 14:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 14:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 14:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 14:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-12 09:28 ——— d—–w c:\documents and settings\Carl\Application Data\Zylom
2008-10-12 09:28 ——— d—–w c:\documents and settings\Carl\Application Data\Jane s Hotel Family Hero
2008-10-07 20:00 ——— d—–w c:\documents and settings\Carl\Application Data\Total Eclipse
2008-10-06 16:29 ——— d—–w c:\documents and settings\All Users\Application Data\Sandlot Games
2008-10-02 20:46 ——— d—–w c:\documents and settings\Carl\Application Data\PlayFirst
2008-10-02 20:46 ——— d—–w c:\documents and settings\All Users\Application Data\PlayFirst
2008-09-30 16:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-28 21:07 ——— d—–w c:\program files\UUTV
2008-09-28 10:49 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-09-28 09:50 ——— d—–w c:\documents and settings\All Users\Application Data\SpinTopV1005
2008-09-28 09:42 ——— d—–w c:\program files\FinePixViewerS
2008-09-27 20:54 ——— d—–w c:\documents and settings\All Users\Application Data\Zylom
2008-09-26 10:19 ——— d—–w c:\documents and settings\All Users\Application Data\GameHouse
2008-09-21 12:48 ——— d—–w c:\documents and settings\Carl\Application Data\SpinTop
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-08-26 07:24 826,368 —-a-w c:\windows\system32\wininet.dll
2007-06-04 21:44 20,632 —-a-w c:\documents and settings\Carl\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( snapshot@2008-11-20_10.44.21.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-18 21:10:48 94,920 -c–a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-10-16 14:09:44 92,696 -c–a-w c:\windows\system32\dllcache\cdm.dll
- 2008-07-18 21:09:44 563,912 -c–a-w c:\windows\system32\dllcache\wuapi.dll
+ 2008-10-16 14:12:20 561,688 -c–a-w c:\windows\system32\dllcache\wuapi.dll
- 2008-07-18 21:10:42 53,448 -c–a-w c:\windows\system32\dllcache\wuauclt.exe
+ 2008-10-16 14:09:44 51,224 -c–a-w c:\windows\system32\dllcache\wuauclt.exe
- 2008-07-18 21:09:42 1,811,656 -c–a-w c:\windows\system32\dllcache\wuaueng.dll
+ 2008-10-16 14:13:40 1,809,944 -c–a-w c:\windows\system32\dllcache\wuaueng.dll
- 2008-07-18 21:09:46 325,832 -c–a-w c:\windows\system32\dllcache\wucltui.dll
+ 2008-10-16 14:12:22 323,608 -c–a-w c:\windows\system32\dllcache\wucltui.dll
- 2008-07-18 21:10:20 36,552 -c–a-w c:\windows\system32\dllcache\wups.dll
+ 2008-10-16 14:08:58 34,328 -c–a-w c:\windows\system32\dllcache\wups.dll
- 2008-07-18 21:09:44 205,000 -c–a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-10-16 14:13:40 202,776 -c–a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-10-16 14:08:58 34,328 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-10-16 14:09:44 43,544 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-12 7626752]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-12 86016]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 49152]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-06-23 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"nwiz"="nwiz.exe" [2006-07-12 c:\windows\system32\nwiz.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-01 c:\windows\RTHDCPL.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 c:\windows\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 c:\windows\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]
"iLike"="c:\program files\iLike\1.1.51\ilikesidebar.exe" [2008-09-10 63024]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Exif Launcher S.lnk - c:\program files\FinePixViewerS\QuickDCF2.exe [2008-01-18 303104]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-01-20 671744]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=ppjfuq.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Documents and Settings\\Carl\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\PPMate\\PPMate\\ppmate.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=

R2 LBeepKE;LBeepKE;c:\windows\system32\Drivers\LBeepKE.sys [2007-01-20 3712]
S3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [2007-01-21 167424]
.
Contents of the 'Scheduled Tasks' folder

2008-10-22 c:\windows\Tasks\rpc.job
- c:\program files\Winferno\RegistryPowerCleaner\RegPowerClean.exe []
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-iesvcmon - c:\windows\system32\iesvcmon.exe



**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-21 17:29:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
Completion time: 2008-11-21 17:34:33
ComboFix-quarantined-files.txt 2008-11-21 17:33:31
ComboFix2.txt 2008-11-20 10:45:28

Pre-Run: 25,135,702,016 bytes free
Post-Run: 25,219,936,256 bytes free

192 — E O F — 2008-11-12 22:18:40
Hello

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.




Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Pop ups were slowly happening again. here is log as requested Malwarebytes' Anti-Malware 1.30 Database version: 1414 Windows 5.1.2600 Service Pack 2 21/11/2008 20:21:01 mbam-log-2008-11-21 (20-21-01).txt Scan type: Quick Scan Objects scanned: 48526 Time elapsed: 3 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 19 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\bho_myjavacore.mjcore (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\bho_myjavacore.mjcore.1 (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{80ef304a-b1c4-425c-8535-95ab6f1eefb8} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\BHO_MyJavaCore.DLL (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
as requested… thanks for the quick replies and advice. :thumbup:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Friday, November 21, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, November 21, 2008 17:19:10
Records in database: 1399689
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\

Scan statistics:
Files scanned: 83657
Threat name: 19
Infected objects: 26
Suspicious objects: 0
Duration of the scan: 01:16:49


File name / Threat name / Threats count
C:\Documents and Settings\All Users\Application Data\SecTaskMan\algsrvs.exe.q_804C000_q Infected: Virus.Win32.Texel.h 1
C:\fun.xls.exe Infected: Virus.Win32.Texel.h 1
C:\Program Files\PKR\pkr.exe Infected: not-a-virus:Monitor.Win32.PKRPoker.f 1
C:\Program Files\Windows Live\Messenger\msimg32.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cv 1
C:\Program Files\Windows Live\Messenger\riched20.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cj 1
C:\Qoobox\Quarantine\C\AUTORUN.INF.vir Infected: Worm.Win32.AutoRun.aka 1
C:\Qoobox\Quarantine\C\Documents and Settings\Carl\Application Data\gadcom\gadcom.exe.vir Infected: Trojan.Win32.Agent.amyy 1
C:\Qoobox\Quarantine\C\Program Files\GetPack\GetPack24.exe.vir Infected: not-a-virus:AdWare.Win32.Agent.hbm 1
C:\Qoobox\Quarantine\C\Program Files\Network Monitor\netmon.exe.vir Infected: not-a-virus:Monitor.Win32.NetMon.a 1
C:\Qoobox\Quarantine\C\WINDOWS\Q2FybCBRdWFydGVybWFpbg\asappsrv.dll.vir Infected: not-a-virus:AdWare.Win32.CommAd.a 1
C:\Qoobox\Quarantine\C\WINDOWS\Q2FybCBRdWFydGVybWFpbg\command.exe.vir Infected: not-a-virus:AdWare.Win32.CommAd.a 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\cgaiho(2).dll.vir Infected: Trojan.Win32.Monder.zab 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\cwulmy.dll.vir Infected: Trojan.Win32.Monder.zab 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\dcs2\CGZ3I5.exe.vir Infected: not-a-virus:AdWare.Win32.Agent.hib 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\dwwnw64r.exe.vir Infected: Trojan-Downloader.Win32.Agent.afzg 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\g76.exe.vir Infected: Trojan-Clicker.Win32.Agent.bsk 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\gside.exe.vir Infected: Trojan-Downloader.Win32.Zlob.ymu 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\nas\amitg44.exe.vir Infected: Trojan-Downloader.Win32.Agent.afzg 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\pcnttsdl.exe.vir Infected: not-a-virus:AdWare.Win32.ZenoSearch.ca 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\prun.exe.vir Infected: Trojan.Win32.VB.guf 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\rqRLdETM.dll.vir Infected: Trojan.Win32.Agent.anyk 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\rswnw64l.exe.vir Infected: Trojan-Downloader.Win32.Agent.afzg 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ssqPICRI.dll.vir Infected: Trojan.Win32.Agent.anyk 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\sX3i19\sX3i191065.exe.vir Infected: Trojan-Downloader.Win32.VB.irr 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\sxvgbvab.dll.vir Infected: Trojan.Win32.Monder.zab 1
C:\WINDOWS\system32\pCastCtl.dll Infected: not-a-virus:AdWare.Win32.Dudu.f 1

The selected area was scanned.
==============================================================================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:17:25, on 21/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
c:\program files\a-squared free\a2service.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Carl\Local Settings\Temp\jkos-Carl\binaries\ScanningProcess.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [HPHUPD08] C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [iLike] C:\Program Files\iLike\1.1.51\ilikesidebar.exe /checkforupdate (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
O4 - Global Startup: Exif Launcher S.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Amazing%20Adventures%20The%20Lost%20Tomb/Images/stg_drm.ocx
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by119fd.bay119.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.euchannels.net/KooPlayer.ocx
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Br…018/flashax.cab
O20 - AppInit_DLLs: ppjfuq.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 9221 bytes
Hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O20 - AppInit_DLLs: ppjfuq.dll


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.




Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\Documents and Settings\All Users\Application Data\SecTaskMan
    C:\fun.xls.exe
    C:\Program Files\PKR
    C:\WINDOWS\system32\pCastCtl.dll
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Also post a new HJT log
had Generic host crash on reboot will let you know if that happens again on next reboot


========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\Documents and Settings\All Users\Application Data\SecTaskMan moved successfully.
C:\fun.xls.exe moved successfully.
C:\Program Files\PKR\miles moved successfully.
C:\Program Files\PKR\help moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20081116 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20081115 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20081022 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20081020 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20081019 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20081016 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20081012 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20081005 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20081003 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20081002 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080928 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080927 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080921 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080917 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080913 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080912 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080902 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080822 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080821 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080820 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080810 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080808 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080807 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080806 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080804 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080803 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080802 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080724 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080723 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080722 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080721 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080720 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080719 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080718 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080717 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080716 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080715 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080714 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080713 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080712 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080711 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080709 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080708 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080707 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080706 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080705 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080704 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080703 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080702 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080701 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080630 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080629 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080628 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080627 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080626 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080625 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080624 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080623 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080622 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080621 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080620 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080619 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080618 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080617 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080615 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080614 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080613 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080612 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080611 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080610 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080609 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080608 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080607 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080606 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080605 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080604 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080603 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080602 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080531 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080530 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080529 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080526 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080525 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080524 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080523 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080520 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080519 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080518 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080517 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080516 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080515 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080513 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080509 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080508 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080507 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080506 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080505 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080504 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080503 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080502 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080501 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080430 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080428 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080427 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080426 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080425 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080422 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080421 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080420 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080418 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080417 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080416 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080415 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080411 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080329 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080328 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080321 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080320 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080229 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080216 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080215 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080213 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080209 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080208 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080206 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080205 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080202 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080201 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080131 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080130 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080128 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080127 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080126 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080125 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080124 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080123 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080122 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080120 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080117 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080116 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080115 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080114 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080110 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080109 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080108 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080107 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080106 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080105 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20080104 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071230 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071229 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071228 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071227 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071224 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071223 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071220 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071219 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071218 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071217 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071216 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071215 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071214 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071213 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071212 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071211 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071210 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071209 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071208 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq\20071207 moved successfully.
C:\Program Files\PKR\handhistory\godfathercwq moved successfully.
C:\Program Files\PKR\handhistory moved successfully.
C:\Program Files\PKR\cache\deltacache moved successfully.
C:\Program Files\PKR\cache moved successfully.
C:\Program Files\PKR moved successfully.
C:\WINDOWS\system32\pCastCtl.dll unregistered successfully.
C:\WINDOWS\system32\pCastCtl.dll moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Carl\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Carl\LOCALS~1\Temp\_hphtra07.log scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Carl\LOCALS~1\Temp\~DF1683.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Carl\LOCALS~1\Temp\~DF168E.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\logishrd\LVPrcInj01.dll scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11222008_043320

Files moved on Reboot…
C:\DOCUME~1\Carl\LOCALS~1\Temp\hpodvd09.log moved successfully.
C:\DOCUME~1\Carl\LOCALS~1\Temp\_hphtra07.log moved successfully.
File C:\DOCUME~1\Carl\LOCALS~1\Temp\~DF1683.tmp not found!
File C:\DOCUME~1\Carl\LOCALS~1\Temp\~DF168E.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\WINDOWS\temp\logishrd\LVPrcInj01.dll
C:\WINDOWS\temp\logishrd\LVPrcInj01.dll NOT unregistered.
File move failed. C:\WINDOWS\temp\logishrd\LVPrcInj01.dll scheduled to be moved on reboot.

========================================================================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:44:59, on 22/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\a-squared free\a2service.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [HPHUPD08] C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [iLike] C:\Program Files\iLike\1.1.51\ilikesidebar.exe /checkforupdate (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
O4 - Global Startup: Exif Launcher S.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Amazing%20Adventures%20The%20Lost%20Tomb/Images/stg_drm.ocx
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by119fd.bay119.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.euchannels.net/KooPlayer.ocx
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Br…018/flashax.cab
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 9062 bytes
Your logs are clean

Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    [external image: Posted Image]



  • Make sure you have an Internet Connection.
  • Download OTCleanIt to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTCleanUp to reach the Internet, please allow the application to do so.
  • Click Yes to beging the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.



Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :
http://www.adobe.com/products/acrobat/readstep2.html




Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:

SpywareBlaster protects against bad ActiveX
IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here

* SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program or there will be a conflict.

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.


*ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

*NoScript - Addon for Firefox that stops all scripts from running on websites. Stops malicious software from invading via flash, java, javascript, and many other entry points.

*Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here

Thank you for your patience, and performing all of the procedures requested.
ran OTCleanIt but it never got rid of ERUNT, Malwarebytes or Hijackthis. Should I leave these on the system or manually get rid? Just about to download your recommendations so thanks for everything. I will only use Mozilla Firefox from today also.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI