This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] ALMOST made in through 2008 without an issue

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks in advance for your help, it's much appreciated.

FYI…I was redirected to update to HIJACK 2.0 Even though the HiJack This page told me not to…

NOTE: Merijn sold HijackThis to TrendMicro. They’ve released HijackThis V2 (version 2), and the quick start guide for it can be found here. Unless you’re using Windows Vista, HJT v2 is not required.

Since I'm not running Vista, i paid attention to the directions and now, I'm re-writing my post. Just thought I'd respectfully point out the inconsistency on the site.

So, onto my problem 2.0…

Been getting quite a few pop-ups over the past couple days.

Ran the following before posting…

ERUNT
ATF Cleaner
Malwarebytes' Anti-Malware

Here's the AM Log:

Malwarebytes' Anti-Malware 1.30
Database version: 1419
Windows 5.1.2600 Service Pack 2

2008-11-24 23:32:57
mbam-log-2008-12-24 (23-32-57).txt

Scan type: Quick Scan
Objects scanned: 59685
Time elapsed: 5 minute(s), 47 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 5
Registry Keys Infected: 56
Registry Values Infected: 3
Registry Data Items Infected: 4
Folders Infected: 7
Files Infected: 18

Memory Processes Infected:
C:\Documents and Settings\Jim\Application Data\Twain\Twain.exe (Adware.Agent) -> Unloaded process successfully.

Memory Modules Infected:
C:\WINDOWS\system32\xxyyaBuv.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\ssqRHAsp.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\jftbni.dll (Trojan.Vundo) -> Delete on reboot.
C:\Program Files\Webtools\webtools.dll (Trojan.BHO) -> Delete on reboot.
C:\Program Files\Mjcore\Mjcore.dll (Adware.Agent) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{063e1b2c-6dd7-451d-abc1-254b050e368f} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{063e1b2c-6dd7-451d-abc1-254b050e368f} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7e0cbfb3-a444-4fb8-8915-d7558a914fb9} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{7e0cbfb3-a444-4fb8-8915-d7558a914fb9} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a63e645f-13bd-45ed-b15f-6e8c1bd57279} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqrhasp (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{a63e645f-13bd-45ed-b15f-6e8c1bd57279} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a63e645f-13bd-45ed-b15f-6e8c1bd57279} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{063e1b2c-6dd7-451d-abc1-254b050e368f} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7e0cbfb3-a444-4fb8-8915-d7558a914fb9} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{63334394-3da3-4b29-a041-03535909d361} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e4a04a1-a24d-45ae-aca4-949778400813} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d88e1558-7c2d-407a-953a-c044f5607cea} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d88e1558-7c2d-407a-953a-c044f5607cea} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d88e1558-7c2d-407a-953a-c044f5607cea} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\loaderx.installer (Adware.Winad) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\loaderx.installer.1 (Adware.Winad) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\testcpv6.bho (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\testcpv6.bho.1 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{80ef304a-b1c4-425c-8535-95ab6f1eefb8} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{ff46f4ab-a85f-487e-b399-3f191ac0fe23} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{28caeff3-0f18-4036-b504-51d73bd81abc} (Adware.MediaAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{825cf5bd-8862-4430-b771-0c15c5ca8def} (Adware.MediaAccess) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{014da6c1-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7c559105-9ecf-42b8-b3f7-832e75edd959} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227d9c-0efe-4f8a-aa55-30386a3f5686} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8f9e2be3-766d-4831-bb0e-766d5b819995} (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1a26f07f-0d60-4835-91cf-1e1766a0ec56} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{ca4f0d8d-5f2b-4f16-838a-8d52249eab21} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{13197ace-6851-45c3-a7ff-c281324d5489} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6f7d-442c-93e3-4a4827c2e4c8} (Adware.NetOptimizer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\speedrunner (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\BHO_MyJavaCore.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\testCPV6.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{a63e645f-13bd-45ed-b15f-6e8c1bd57279} (Trojan.Vundo) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\twain (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gadcom (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\xxyyabuv -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\xxyyabuv -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Trojan.Agent) -> Data: msansspc.dll -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\Media Pass (Adware.Winad) -> Quarantined and deleted successfully.
C:\Program Files\STC (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\Webtools (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\EliteToolBar (Adware.EliteToolBar) -> Quarantined and deleted successfully.
C:\Program Files\Mjcore (Trojan.BHO) -> Delete on reboot.
C:\Documents and Settings\Jim\Application Data\gadcom (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\Jim\Application Data\speedrunner (Adware.SurfAccuracy) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\jftbni.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\xxyyaBuv.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\vuBayyxx.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vuBayyxx.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssqRHAsp.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\qgrnnfkw.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wkfnnrgq.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jim\Application Data\Twain\Twain.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Webtools\webtools.dll (Trojan.BHO) -> Delete on reboot.
C:\Program Files\Mjcore\Mjcore.dll (Adware.Agent) -> Delete on reboot.
C:\Documents and Settings\Jim\Application Data\gadcom\gadcom.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\opnomjhf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rxorgbxs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\omqepujm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qclozz.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jim\Application Data\speedrunner\config.cfg (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jim\Application Data\speedrunner\SRUninstall.exe (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msansspc.dll (Trojan.Agent) -> Delete on reboot.


and Here's the HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:00, on 2008-11-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device

Support\bin\AppleMobileDeviceService.exe
g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft

Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program

Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.

exe
G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCD.exe
C:\Program

Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
I:\Program Files\iTunes\iTunesHelper.exe
C:\Program

Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier

.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\config\systemprofile\Application

Data\gadcom\gadcom.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
G:\program Files\Malwarebytes' Anti-Malware\mbam.exe
g:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O3 - Toolbar: &Google -

{2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program

Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program

Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.

exe /auto
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "G:\program

Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [InCD] I:\Nero\Nero 7\Nero

StartSmart\InCD\InCD.exe
O4 - HKLM\..\Run: [KernelFaultCheck]

%systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program

Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program

Files\Common Files\Apple\Mobile Device

Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "I:\Program

Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)]

"G:\program Files\Malwarebytes' Anti-Malware\mbam.exe"

/runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware]

G:\program Files\Malwarebytes' Anti-Malware\mbamgui.exe

/install /silent
O4 - HKCU\..\Run: [swg] C:\Program

Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier

.exe
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program

Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] G:\program

Files\Daemon tools\DAEMON Tools Pro\DTProAgent.exe

-autorun
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common

Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel

- res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research -

{92780B25-18CC-41C8-B9BE-3C9C571A8263} -

I:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) -

{e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -

{e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://aimexpress.aol.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134}

(MySpace Uploader Control) -

http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C}

(View22RTE Class) -

http://66.242.36.104/app/view22RTE.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}

(Shockwave Flash Object) -

http://fpdownload2.macromedia.com/get/shockwave/cabs/fla

sh/swflash.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044}

(AxisMediaControlEmb Class) -

http://corriherptz.axiscam.net:9552/activex/AMC.cab
O16 - DPF: {E990F195-3598-4C13-BD01-F8752E9BD8F5}

(CFHandler Class) -

http://www.mediamonitors.com/Analysis/ClientFileHandler.

cab
O17 -

HKLM\System\CCS\Services\Tcpip\..\{FB81C809-2055-49EB-A8

1E-7C622743A397}: NameServer = 24.247.24.53,24.247.15.53
O20 - AppInit_DLLs: jftbni.dll
O23 - Service: Adobe LM Service - Adobe Systems -

C:\Program Files\Common Files\Adobe Systems

Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. -

C:\Program Files\Common Files\Apple\Mobile Device

Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. -

g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program

Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google -

C:\Program Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) -

Macrovision Corporation - C:\Program Files\Common

Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG -

I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) -

NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP -

C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 6201 bytes
Hi beaumondetroit,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

When posting logs from notepad, please click on Format at the top of the notepad window. Make sure Word Wrap is unchecked.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://www.bleepingcomputer.com/forums/topic114351.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi Tomk

Thanks for the help…

Here's the ComboFix log: (with word wrap off…:o)

ComboFix 08-11-26.01 - Jim 2008-11-25 21:53:58.6 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1171 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Jim\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\Jim\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\Jim\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\qgtaugor.ini
c:\windows\wiaserviv.log
J:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ZESOFT


((((((((((((((((((((((((( Files Created from 2008-10-26 to 2008-11-26 )))))))))))))))))))))))))))))))
.

2008-11-24 23:23 . 2008-11-24 23:23 d——– c:\documents and settings\Jim\Application Data\Malwarebytes
2008-11-24 23:23 . 2008-11-24 23:23 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-24 23:23 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-24 23:23 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-24 21:40 . 2008-11-24 21:40 d——– c:\program files\Common Files\Download Manager
2008-11-24 19:54 . 2008-11-24 19:54 d——– c:\documents and settings\Jim\Application Data\Twain
2008-11-24 18:52 . 2007-12-20 23:11 81,920 –a—— c:\windows\system32\IEDFix.exe
2008-11-23 18:16 . 2008-11-23 18:16 d——– c:\windows\system32\config\systemprofile\Application Data\gadcom
2008-11-23 17:56 . 2008-11-23 17:56 d——– c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2008-11-23 17:55 . 2008-11-23 17:55 d——– c:\documents and settings\Jim\Application Data\DAEMON Tools Pro
2008-11-23 17:55 . 2008-11-23 17:55 717,296 –a—— c:\windows\system32\drivers\sptd.sys
2008-11-13 19:55 . 2008-11-13 19:55 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:10 453,632 ——w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-15 17:57 332,800 ——w c:\windows\system32\dllcache\netapi32.dll
2008-10-03 18:41 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 12:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 12:57 1,846,016 ——w c:\windows\system32\dllcache\win32k.sys
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-09-04 16:42 1,106,944 ——w c:\windows\system32\dllcache\msxml3.dll
2008-08-29 15:18 87,336 —-a-w c:\windows\system32\dns-sd.exe
2008-08-29 14:53 61,440 —-a-w c:\windows\system32\dnssd.dll
2008-08-28 11:04 333,056 ——w c:\windows\system32\dllcache\srv.sys
2008-08-27 09:24 3,593,216 —-a-w c:\windows\system32\dllcache\mshtml.dll
2004-07-24 05:31 210,576 —-a-w c:\documents and settings\Jim\Application Data\GDIPFONTCACHEV1.DAT
2002-03-12 04:06 560 —-a-w c:\program files\#readme.txt
2002-03-06 22:55 88,064 —-a-w c:\program files\USBMN1X1.DLL
2002-03-06 22:55 7,302 —-a-w c:\program files\USBMM1X1.VXD
2002-03-06 22:55 32,476 —-a-w c:\program files\USBMM1X1.SYS
2002-03-06 22:55 234,496 —-a-w c:\program files\UNINSTAL.EXE
2002-03-06 22:55 2,928 —-a-w c:\program files\MM1X1USB.INF
2002-03-06 22:55 2,901 —-a-w c:\program files\USBMM1X1.INF
2002-03-06 22:55 17,920 —-a-w c:\program files\USBMM1X1.DLL
2002-03-06 22:55 15,740 —-a-w c:\program files\USB11LDR.SYS
2002-03-06 22:55 12,144 —-a-w c:\program files\USBMM1X1.DRV
2002-03-06 22:55 11,551 —-a-w c:\program files\#INSTALL.TXT
1999-03-01 12:36 74,524 —-a-w c:\program files\cdrwin.hlp
1999-03-01 12:36 609 —-a-w c:\program files\cdrwin.cnt
1999-03-01 12:36 166 —-a-w c:\program files\file_id.diz
1999-03-01 12:36 1,450 —-a-w c:\program files\cdrwin.nfo
1999-03-01 12:36 1,024 —-a-w c:\program files\cdrwin.dat
2005-02-12 21:43 475 –sh–w c:\windows\system32\vnek.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-19 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-01-15 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-01-19 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomcatStartup 2.5"="c:\program files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2008-01-19 188416]
"StatusClient 2.6"="c:\program files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2008-01-19 61440]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"!AVG Anti-Spyware"="g:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"InCD"="i:\nero\Nero 7\Nero StartSmart\InCD\InCD.exe" [2005-08-30 865280]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"iTunesHelper"="i:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"nwiz"="nwiz.exe" [2006-08-11 c:\windows\system32\nwiz.exe]

c:\documents and settings\Jim\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=jftbni.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= usbmn1x1.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"vidc.DIVX"= divxdec.ax
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= c:\windows\system32\i263_32.drv
"msacm.imc"= c:\windows\system32\imc32.acm

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"i:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"=
"i:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"i:\\Program Files\\iTunes\\iTunes.exe"=

R3 XD2_DspCtrl;XD2 DSP Control;c:\windows\system32\DRIVERS\XD2_DspCtrl.sys [2005-01-12 84256]
S3 atirage;atirage;c:\windows\system32\DRIVERS\atiragem.sys [2001-01-01 70528]
S3 RimSerPort;RIM Virtual Serial Port;c:\windows\system32\DRIVERS\RimSerial.sys [2006-02-05 18432]
S3 USB11LDR;USB Midi 1x1 Loader;c:\windows\system32\drivers\usb11ldr.sys [2005-03-06 13504]
S3 USBMM1X1;USB Midi 1x1 Driver;c:\windows\system32\drivers\usbmm1x1.sys []
S3 USBMN1X1;USB Midi 1x1;c:\windows\system32\drivers\usbmn1x1.sys [2005-03-06 22272]
S4 hpt3xx;hpt3xx; []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c61f480-7b7c-11dc-bfc4-000f661c6917}]
\Shell\AutoRun\command - j:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f3edc01-9b75-11dc-bfc9-000f661c6917}]
\Shell\AutoRun\command - k:\wd_windows_tools\setup.exe
.
Contents of the 'Scheduled Tasks' folder

2008-11-25 c:\windows\Tasks\{DC6DAE2D-2D62-4C1E-A4E3-8415DCA74A47}_FLICKER-JJ9HCKO_Jim.job
- c:\windows\system32\mobsync.exe [2004-08-04 03:56]

2008-10-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-DAEMON Tools Pro Agent - g:\program files\Daemon tools\DAEMON Tools Pro\DTProAgent.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Settings,ProxyOverride = ;*.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: {FB81C809-2055-49EB-A81E-7C622743A397} = 24.247.24.53,24.247.15.53

c:\windows\system32\atl.dll - c:\windows\system32\shfolder.dll
c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\GdiPlus.dll
c:\windows\system32\DXFLib.dll
c:\windows\system32\devil.dll
c:\windows\system32\opcode.dll
c:\windows\Downloaded Program Files\View22RTE.dll
O16 -: {BCBC9371-595D-11D4-A96D-00105A1CEF6C}
hxxp://66.242.36.104/app/view22RTE.cab
c:\windows\Downloaded Program Files\v22.inf

O16 -: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://corriherptz.axiscam.net:9552/activex/AMC.cab
c:\windows\Downloaded Program Files\setup.inf

c:\windows\Downloaded Program Files\ClientFileHandler.dll - O16 -: {E990F195-3598-4C13-BD01-F8752E9BD8F5}
hxxp://www.mediamonitors.com/Analysis/ClientFileHandler.cab
c:\windows\Downloaded Program Files\default.inf
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-25 22:09:16
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
i:\nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
g:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\program files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\HPZipm12.exe
.
**************************************************************************
.
Completion time: 2008-11-25 22:12:09 - machine was rebooted [Jim]
ComboFix-quarantined-files.txt 2008-11-26 03:12:06
ComboFix4.txt 2008-02-01 11:28:44
ComboFix3.txt 2008-02-02 19:35:10
ComboFix5.txt 2008-11-26 02:17:36
ComboFix2.txt 2008-02-03 13:44:52

Pre-Run: 830,373,888 bytes free
Post-Run: 929,120,256 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

205 — E O F — 2008-11-13 04:56:33
beaumondetroit,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c61f480-7b7c-11dc-bfc4-000f661c6917}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f3edc01-9b75-11dc-bfc9-000f661c6917}]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

Also please post a new HijackThis log.
beaumondetroit, Please try this: Drag the copy of ComboFix that you have on your desktop to your recycled bin. Reboot your computer. Download a new copy of Combofix. Drag CFScript.txt into the new icon. (try again with the new version :) )
Tomk -

It's still freezeing up on the ComboFix. It hangs at the "running scan, may take 10 minutes or longer" screen. I let it run all last night, thinking I'll give it a few more than 10 minutes.

I ran the Kapersky and fresh HJT scans just so I could post something more than "nope, it's still not working."



——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Saturday, November 29, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, November 28, 2008 22:47:08
Records in database: 1424489
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
E:\
F:\
G:\
H:\
I:\
J:\
T:\

Scan statistics:
Files scanned: 215166
Threat name: 32
Infected objects: 94
Suspicious objects: 0
Duration of the scan: 05:45:19


File name / Threat name / Threats count
C:\WINDOWS\system32\axpfbho.exe Infected: not-a-virus:AdWare.Win32.NoName.e 1
C:\WINDOWS\system32\greenstd.exe Infected: Trojan-Downloader.Win32.Vivia.aa 1
C:\WINDOWS\system32\kwdstd.exe Infected: Trojan-Downloader.Win32.Vivia.aa 1
C:\WINDOWS\system32\ssm.exe Infected: Trojan-Downloader.Win32.Agent.gp 1
C:\WINDOWS\system32\ezPopStub.exe Infected: not-a-virus:AdWare.Win32.EZula.u 1
C:\WINDOWS\system32\funcade_MARKETING11_install.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.q 2
C:\WINDOWS\system32\funcade_MARKETING11_install.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.n 8
C:\WINDOWS\system32\funcade_MARKETING11_install.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.y 1
C:\WINDOWS\system32\funcade_MARKETING11_install.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.l 2
C:\WINDOWS\system32\funcade_MARKETING11_install.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.p 1
C:\WINDOWS\system32\COMMCOSS.DLL Infected: not-a-virus:AdWare.Win32.SafeSurfing.j 1
C:\WINDOWS\system32\wys.dll Infected: not-a-virus:AdWare.Win32.WhileSurf.a 1
C:\WINDOWS\Downloaded Program Files\QDow_AS2.dll Infected: Trojan-Downloader.Win32.QDown.p 1
C:\Documents and Settings\All Users\Application Data\msw\MSW.exe Infected: not-a-virus:AdWare.Win32.Searcher.h 1
C:\Documents and Settings\All Users\Application Data\msw\msw_uninstall.exe Infected: not-a-virus:AdWare.Win32.Searcher.h 1
C:\Documents and Settings\All Users\Application Data\msw\msw_uninstall.exe Infected: not-a-virus:RiskTool.Win32.PsKill.a 1
C:\Documents and Settings\Jim\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Documents and Settings\Jim\Desktop\SmitfraudFix.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Program Files\08nvkk14\75v9eiyi.DLL Infected: not-a-virus:AdWare.Win32.ClearSearch.al 1
C:\Program Files\08nvkk14\11568772.exe Infected: not-a-virus:AdWare.Win32.ClearSearch.av 1
C:\Program Files\08nvkk14\csUNinst.DLL Infected: not-a-virus:AdWare.Win32.ClearSearch.al 1
C:\Program Files\08nvkk14\korrkmlm.DLL Infected: not-a-virus:AdWare.Win32.ClearSearch.al 1
C:\Program Files\08nvkk14\2fnr15mu.DLL Infected: not-a-virus:AdWare.Win32.ClearSearch.al 1
C:\Program Files\hijackthis\backups\backup-20050225-192940-598.dll Infected: not-a-virus:WebToolbar.Win32.MyWebSearch 1
C:\Program Files\hijackthis\backups\backup-20050225-192941-573.dll Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.e 1
C:\System Volume Information\_restore{076D66DD-8D73-4DE7-BBB3-B255598F6CF1}\RP1125\A0181838.dll Infected: Trojan.Win32.Monder.zzs 1
C:\System Volume Information\_restore{076D66DD-8D73-4DE7-BBB3-B255598F6CF1}\RP1126\A0182029.DLL Infected: Trojan.Win32.Monder.zzs 1
C:\System Volume Information\_restore{076D66DD-8D73-4DE7-BBB3-B255598F6CF1}\RP1126\A0182032.dll Infected: Trojan.Win32.Monderb.xer 1
C:\System Volume Information\_restore{076D66DD-8D73-4DE7-BBB3-B255598F6CF1}\RP1126\A0182033.dll Infected: Trojan.Win32.Monder.zzq 1
C:\System Volume Information\_restore{076D66DD-8D73-4DE7-BBB3-B255598F6CF1}\RP1126\A0182034.dll Infected: Trojan.Win32.Monder.zzq 1
C:\System Volume Information\_restore{076D66DD-8D73-4DE7-BBB3-B255598F6CF1}\RP1126\A0182035.DLL Infected: Trojan.Win32.Monder.zzq 1
C:\System Volume Information\_restore{076D66DD-8D73-4DE7-BBB3-B255598F6CF1}\RP1126\A0182045.dll Infected: Trojan.Win32.Monder.zzq 1
C:\System Volume Information\_restore{076D66DD-8D73-4DE7-BBB3-B255598F6CF1}\RP1126\A0182048.dll Infected: Trojan.Win32.Monderb.xer 1
C:\System Volume Information\_restore{076D66DD-8D73-4DE7-BBB3-B255598F6CF1}\RP1126\A0182051.exe Infected: Trojan.Win32.Agent.aorq 1
C:\QooBox\Quarantine\C\WINDOWS\system32\000070.exe.vir Infected: Trojan-Downloader.Win32.Small.hqc 1
C:\QooBox\Quarantine\C\WINDOWS\system32\escpqdfx.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe 1
C:\QooBox\Quarantine\C\WINDOWS\system32\rwfwfusl.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe 1
C:\QooBox\Quarantine\C\WINDOWS\system32\drlggrsl.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ebnotbby.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ikrqrvnp.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe 1
C:\QooBox\Quarantine\C\WINDOWS\system32\dqdrlhiv.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe 1
C:\QooBox\Quarantine\C\WINDOWS\system32\pcowiesu.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe 1
C:\QooBox\Quarantine\C\WINDOWS\system32\belrncwr.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe 1
C:\QooBox\Quarantine\C\WINDOWS\system32\avovaffk.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.kp 1
C:\QooBox\Quarantine\C\WINDOWS\system32\axitayyt.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\bhsnvwhe.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.qup 1
C:\QooBox\Quarantine\C\WINDOWS\system32\buorvsjs.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\cntkoueu.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ctxjhbwv.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\elbgrpej.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.eby 1
C:\QooBox\Quarantine\C\WINDOWS\system32\euaeshpq.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\fgmcavpo.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\fheesfmm.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\gcasafgx.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\hkdhaxkv.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\hrqvovll.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\hytlimdk.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ipsnkyeg.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\jaagpetm.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\jpcwmoli.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\kkkaywxu.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.qup 1
C:\QooBox\Quarantine\C\WINDOWS\system32\mscjiqps.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.quv 1
C:\QooBox\Quarantine\C\WINDOWS\system32\nejjknrp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.edw 1
C:\QooBox\Quarantine\C\WINDOWS\system32\nrjumnba.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.quc 1
C:\QooBox\Quarantine\C\WINDOWS\system32\oiucjlux.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\okvnuvdk.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\orfmsvqb.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\outhdgyg.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.quv 1
C:\QooBox\Quarantine\C\WINDOWS\system32\oxwncjfd.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.quc 1
C:\QooBox\Quarantine\C\WINDOWS\system32\pkxfprcf.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\rocbtqot.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\rpkeeyog.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\sfjgvlnq.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\sxwctmdj.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\udwbxhuv.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.kp 1
C:\QooBox\Quarantine\C\WINDOWS\system32\uepuxyne.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\wcduspkp.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\wwjejmjt.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\xieiaino.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\xoalouwo.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\xtmjfefu.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\xuhwiikh.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.edw 1
C:\QooBox\Quarantine\C\WINDOWS\system32\xwtdwfmu.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ybrkernf.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\catchme2008-01-31_204140.02.zip Infected: Trojan.Win32.Monder.gen 1

The selected area was scanned.

HJT Scan

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:43, on 2008-11-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCD.exe
I:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
G:\program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - g:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [InCD] I:\Nero\Nero 7\Nero StartSmart\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "I:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://aimexpress.aol.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://66.242.36.104/app/view22RTE.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://corriherptz.axiscam.net:9552/activex/AMC.cab
O16 - DPF: {E990F195-3598-4C13-BD01-F8752E9BD8F5} (CFHandler Class) - http://www.mediamonitors.com/Analysis/ClientFileHandler.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB81C809-2055-49EB-A81E-7C622743A397}: NameServer = 24.247.24.53,24.247.15.53
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 6399 bytes
beaumondetroit,

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\system32\axpfbho.exe
    C:\WINDOWS\system32\greenstd.exe
    C:\WINDOWS\system32\kwdstd.exe
    C:\WINDOWS\system32\ssm.exe
    C:\WINDOWS\system32\ezPopStub.exe
    C:\WINDOWS\system32\funcade_MARKETING11_install.exe
    C:\WINDOWS\system32\COMMCOSS.DLL
    C:\WINDOWS\system32\wys.dll
    C:\WINDOWS\Downloaded Program Files\QDow_AS2.dll
    C:\Documents and Settings\All Users\Application Data\msw\MSW.exe
    C:\Documents and Settings\All Users\Application Data\msw\msw_uninstall.exe
    C:\Program Files\08nvkk14\75v9eiyi.DLL
    C:\Program Files\08nvkk14\11568772.exe
    C:\Program Files\08nvkk14\csUNinst.DLL
    C:\Program Files\08nvkk14\korrkmlm.DLL
    C:\Program Files\08nvkk14\2fnr15mu.DLL
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Then

Please run Malwarebytes again and paste the report here.
Tomk, Here's the OT log… ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\WINDOWS\system32\axpfbho.exe moved successfully. C:\WINDOWS\system32\greenstd.exe moved successfully. C:\WINDOWS\system32\kwdstd.exe moved successfully. C:\WINDOWS\system32\ssm.exe moved successfully. C:\WINDOWS\system32\ezPopStub.exe moved successfully. C:\WINDOWS\system32\funcade_MARKETING11_install.exe moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\COMMCOSS.DLL C:\WINDOWS\system32\COMMCOSS.DLL NOT unregistered. C:\WINDOWS\system32\COMMCOSS.DLL moved successfully. C:\WINDOWS\system32\wys.dll unregistered successfully. C:\WINDOWS\system32\wys.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\Downloaded Program Files\QDow_AS2.dll C:\WINDOWS\Downloaded Program Files\QDow_AS2.dll NOT unregistered. C:\WINDOWS\Downloaded Program Files\QDow_AS2.dll moved successfully. C:\Documents and Settings\All Users\Application Data\msw\MSW.exe moved successfully. C:\Documents and Settings\All Users\Application Data\msw\msw_uninstall.exe moved successfully. DllUnregisterServer procedure not found in C:\Program Files\08nvkk14\75v9eiyi.DLL C:\Program Files\08nvkk14\75v9eiyi.DLL NOT unregistered. C:\Program Files\08nvkk14\75v9eiyi.DLL moved successfully. C:\Program Files\08nvkk14\11568772.exe moved successfully. DllUnregisterServer procedure not found in C:\Program Files\08nvkk14\csUNinst.DLL C:\Program Files\08nvkk14\csUNinst.DLL NOT unregistered. C:\Program Files\08nvkk14\csUNinst.DLL moved successfully. DllUnregisterServer procedure not found in C:\Program Files\08nvkk14\korrkmlm.DLL C:\Program Files\08nvkk14\korrkmlm.DLL NOT unregistered. C:\Program Files\08nvkk14\korrkmlm.DLL moved successfully. DllUnregisterServer procedure not found in C:\Program Files\08nvkk14\2fnr15mu.DLL C:\Program Files\08nvkk14\2fnr15mu.DLL NOT unregistered. C:\Program Files\08nvkk14\2fnr15mu.DLL moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Jim\LOCALS~1\Temp\toolbox_healer45922.log scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jim\LOCALS~1\Temp\~DFE3ED.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jim\LOCALS~1\Temp\~DFE3F4.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11292008_133155 Files moved on Reboot… C:\DOCUME~1\Jim\LOCALS~1\Temp\toolbox_healer45922.log moved successfully. File C:\DOCUME~1\Jim\LOCALS~1\Temp\~DFE3ED.tmp not found! File C:\DOCUME~1\Jim\LOCALS~1\Temp\~DFE3F4.tmp not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. and Here's the Malwarebytes Log Malwarebytes' Anti-Malware 1.30 Database version: 1419 Windows 5.1.2600 Service Pack 2 2008-11-29 13:52:59 mbam-log-2008-11-29 (13-52-59).txt Scan type: Quick Scan Objects scanned: 59123 Time elapsed: 5 minute(s), 29 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
OK. ComboFix ran. Didn't know if you wanted the CF log, but just in case,here you go:

ComboFix 08-11-29.02 - Jim 2008-11-29 15:32:36.7 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1615 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-29 )))))))))))))))))))))))))))))))
.

2008-11-29 13:31 . 2008-11-29 13:31 d——– C:\_OTMoveIt
2008-11-24 23:23 . 2008-11-24 23:23 d——– c:\documents and settings\Jim\Application Data\Malwarebytes
2008-11-24 23:23 . 2008-11-24 23:23 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-24 23:23 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-24 23:23 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-24 21:40 . 2008-11-24 21:40 d——– c:\program files\Common Files\Download Manager
2008-11-24 19:54 . 2008-11-24 19:54 d——– c:\documents and settings\Jim\Application Data\Twain
2008-11-24 18:52 . 2007-12-20 23:11 81,920 –a—— c:\windows\system32\IEDFix.exe
2008-11-23 18:16 . 2008-11-23 18:16 d——– c:\windows\system32\config\systemprofile\Application Data\gadcom
2008-11-23 17:56 . 2008-11-23 17:56 d——– c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2008-11-23 17:55 . 2008-11-23 17:55 d——– c:\documents and settings\Jim\Application Data\DAEMON Tools Pro
2008-11-23 17:55 . 2008-11-23 17:55 717,296 –a—— c:\windows\system32\drivers\sptd.sys
2008-11-13 19:55 . 2008-11-13 19:55 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:10 453,632 ——w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-15 17:57 332,800 ——w c:\windows\system32\dllcache\netapi32.dll
2008-10-03 18:41 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 12:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 12:57 1,846,016 ——w c:\windows\system32\dllcache\win32k.sys
2008-09-06 04:30 241,704 ——w c:\windows\system32\dllcache\wgaLogon.dll
2008-09-06 04:29 917,032 ——w c:\windows\system32\dllcache\WgaTray.exe
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-09-04 16:42 1,106,944 ——w c:\windows\system32\dllcache\msxml3.dll
2008-08-29 15:18 87,336 —-a-w c:\windows\system32\dns-sd.exe
2008-08-29 14:53 61,440 —-a-w c:\windows\system32\dnssd.dll
2004-07-24 05:31 210,576 —-a-w c:\documents and settings\Jim\Application Data\GDIPFONTCACHEV1.DAT
2002-03-12 04:06 560 —-a-w c:\program files\#readme.txt
2002-03-06 22:55 88,064 —-a-w c:\program files\USBMN1X1.DLL
2002-03-06 22:55 7,302 —-a-w c:\program files\USBMM1X1.VXD
2002-03-06 22:55 32,476 —-a-w c:\program files\USBMM1X1.SYS
2002-03-06 22:55 234,496 —-a-w c:\program files\UNINSTAL.EXE
2002-03-06 22:55 2,928 —-a-w c:\program files\MM1X1USB.INF
2002-03-06 22:55 2,901 —-a-w c:\program files\USBMM1X1.INF
2002-03-06 22:55 17,920 —-a-w c:\program files\USBMM1X1.DLL
2002-03-06 22:55 15,740 —-a-w c:\program files\USB11LDR.SYS
2002-03-06 22:55 12,144 —-a-w c:\program files\USBMM1X1.DRV
2002-03-06 22:55 11,551 —-a-w c:\program files\#INSTALL.TXT
1999-03-01 12:36 74,524 —-a-w c:\program files\cdrwin.hlp
1999-03-01 12:36 609 —-a-w c:\program files\cdrwin.cnt
1999-03-01 12:36 166 —-a-w c:\program files\file_id.diz
1999-03-01 12:36 1,450 —-a-w c:\program files\cdrwin.nfo
1999-03-01 12:36 1,024 —-a-w c:\program files\cdrwin.dat
2005-02-12 21:43 475 –sh–w c:\windows\system32\vnek.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-19 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-01-15 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-01-19 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomcatStartup 2.5"="c:\program files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2008-01-19 188416]
"StatusClient 2.6"="c:\program files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2008-01-19 61440]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"!AVG Anti-Spyware"="g:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"InCD"="i:\nero\Nero 7\Nero StartSmart\InCD\InCD.exe" [2005-08-30 865280]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"iTunesHelper"="i:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"nwiz"="nwiz.exe" [2006-08-11 c:\windows\system32\nwiz.exe]

c:\documents and settings\Jim\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=jftbni.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= usbmn1x1.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"vidc.DIVX"= divxdec.ax
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= c:\windows\system32\i263_32.drv
"msacm.imc"= c:\windows\system32\imc32.acm

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"i:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"=
"i:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"i:\\Program Files\\iTunes\\iTunes.exe"=

R3 XD2_DspCtrl;XD2 DSP Control;c:\windows\system32\DRIVERS\XD2_DspCtrl.sys [2005-01-12 84256]
S3 atirage;atirage;c:\windows\system32\DRIVERS\atiragem.sys [2001-01-01 70528]
S3 RimSerPort;RIM Virtual Serial Port;c:\windows\system32\DRIVERS\RimSerial.sys [2006-02-05 18432]
S3 USBMM1X1;USB Midi 1x1 Driver;c:\windows\system32\drivers\usbmm1x1.sys []
S3 USBMN1X1;USB Midi 1x1;c:\windows\system32\drivers\usbmn1x1.sys [2005-03-06 22272]
S4 hpt3xx;hpt3xx; []
.
Contents of the 'Scheduled Tasks' folder

2008-11-28 c:\windows\Tasks\{DC6DAE2D-2D62-4C1E-A4E3-8415DCA74A47}_FLICKER-JJ9HCKO_Jim.job
- c:\windows\system32\mobsync.exe [2004-08-04 03:56]

2008-10-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = ;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: {FB81C809-2055-49EB-A81E-7C622743A397} = 24.247.24.53,24.247.15.53

c:\windows\system32\atl.dll - c:\windows\system32\shfolder.dll
c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\GdiPlus.dll
c:\windows\system32\DXFLib.dll
c:\windows\system32\devil.dll
c:\windows\system32\opcode.dll
c:\windows\Downloaded Program Files\View22RTE.dll
O16 -: {BCBC9371-595D-11D4-A96D-00105A1CEF6C}
hxxp://66.242.36.104/app/view22RTE.cab
c:\windows\Downloaded Program Files\v22.inf

O16 -: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://corriherptz.axiscam.net:9552/activex/AMC.cab
c:\windows\Downloaded Program Files\setup.inf

c:\windows\Downloaded Program Files\ClientFileHandler.dll - O16 -: {E990F195-3598-4C13-BD01-F8752E9BD8F5}
hxxp://www.mediamonitors.com/Analysis/ClientFileHandler.cab
c:\windows\Downloaded Program Files\default.inf
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-29 15:34:25
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-11-29 15:35:18
ComboFix-quarantined-files.txt 2008-11-29 20:35:18
ComboFix4.txt 2008-02-02 19:35:10
ComboFix5.txt 2008-11-27 00:19:12
ComboFix3.txt 2008-02-03 13:44:52
ComboFix2.txt 2008-11-26 03:12:14

Pre-Run: 621,068,288 bytes free
Post-Run: 650,436,608 bytes free

164 — E O F — 2008-11-27 08:34:42


And here's the HJT Log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:36, on 2008-11-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCD.exe
I:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
G:\program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - g:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [InCD] I:\Nero\Nero 7\Nero StartSmart\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "I:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://aimexpress.aol.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://66.242.36.104/app/view22RTE.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://corriherptz.axiscam.net:9552/activex/AMC.cab
O16 - DPF: {E990F195-3598-4C13-BD01-F8752E9BD8F5} (CFHandler Class) - http://www.mediamonitors.com/Analysis/ClientFileHandler.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB81C809-2055-49EB-A81E-7C622743A397}: NameServer = 24.247.24.53,24.247.15.53
O20 - AppInit_DLLs: jftbni.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 6425 bytes
beaumondetroit,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Also please provide a new HijackThis log and let me know how it's running.
Hey Tomk, ComboFix is still hanging up. One thing that seems odd is that it tells me that there is a new version of ComboFix available and asks me if I want to DL it, I say yes, then it says it's not available and would I like to continue with the current version. I say yes. it goes throught the file save proceedure for the back up registry and then it tells me that 10 minutes is the normal scan time…Then it hangs up. I rebooted and ran ComboFix on it's own and it made it though the entire scan. It's just the script that it's not liking. Thanks! Jim
beaumondetroit,

Fine. Then we'll just do it this way.

  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Then post a new HijackThis log.
Here's the OT Log:

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows\\"AppInit_DLLs"|"" /E : value set successfully!
========== FILES ==========
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Jim\LOCALS~1\Temp\toolbox_healer51019.log scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Jim\LOCALS~1\Temp\~DFBB22.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Jim\LOCALS~1\Temp\~DFBB29.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11302008_193300

Files moved on Reboot…
C:\DOCUME~1\Jim\LOCALS~1\Temp\toolbox_healer51019.log moved successfully.
File C:\DOCUME~1\Jim\LOCALS~1\Temp\~DFBB22.tmp not found!
File C:\DOCUME~1\Jim\LOCALS~1\Temp\~DFBB29.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.


and here is a new HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:40, on 2008-11-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCD.exe
C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
I:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
G:\program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - g:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [InCD] I:\Nero\Nero 7\Nero StartSmart\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "I:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://aimexpress.aol.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://66.242.36.104/app/view22RTE.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://corriherptz.axiscam.net:9552/activex/AMC.cab
O16 - DPF: {E990F195-3598-4C13-BD01-F8752E9BD8F5} (CFHandler Class) - http://www.mediamonitors.com/Analysis/ClientFileHandler.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB81C809-2055-49EB-A81E-7C622743A397}: NameServer = 24.247.24.53,24.247.15.53
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 6349 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI