This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virtumonde will not leave my computer

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings,

Recently I have become infected with what i believe to be the Virtumonde trojan.
I have Spyware Doctor and multiple scans identified the infection as such.

Each scan claimed to remove the infection, but did nothing of the sort.
I believe the problem is in the following files:

meyobuha.dll
legadaza.dll

These files are in the folder c:\WINDOWS\system32 but can only be seen by allowing hidden system files to be viewed.
These files are attached to all major processes running and cannot be deleted.

As per your self-help section, I downloaded and ran VundoFix V7.0.6- scan was clean.

The virus is still there and everytime I search the web I get full screen pop-ups.

Could you please assist me? :pullhair:

I have included a HT log for your perusal.

Thanks.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:22:27 AM, on 3/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {038d190c-1171-4122-af9d-6e4af1daafd5} - C:\WINDOWS\system32\saheloju.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ClickCatcher MSIE handler - {16664845-0E00-11D2-8059-000000000000} - C:\Program Files\Common Files\ReGet Shared\Catcher.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: ReGet Bar - {17939A30-18E2-471E-9D3A-56DD725F1215} - C:\Program Files\ReGet Software\ReGet Deluxe 5.2\IEBar.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [CPM055e8b99] Rundll32.exe "c:\windows\system32\meyobuha.dll",a
O4 - HKLM\..\Run: [dejavoheba] Rundll32.exe "C:\WINDOWS\system32\legadaza.dll",s
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Control and Monitor] C:\Program Files\Auto Shutdown Genius\ControlMonitor.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_5.cab
O16 - DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} (F5 Networks Policy Agent Host Class) -
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1180862377687
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\meyobuha.dll,C:\WINDOWS\system32\badaliyo.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\meyobuha.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\meyobuha.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

–
End of file - 15305 bytes
Hi obbie,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://www.bleepingcomputer.com/forums/topic114351.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thanks Tomk!!!!!!!!!!! :notworthy: What a quick response. I had some trouble running ComboFix- did not run at all in normal mode. Ran in safe mode with networking and it worked, but froze on reboot. Ran again and experienced success. Basically all I am trying to say is that I hope the log is complete……I have included it as an attachment Thanks again TomK! 📎ComboFix.txt
obbie,

Azureus and uTorrent
You have Azureus and uTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm
See Clean/Infected P2P Programs here

I would recommend that you uninstall Azureus and uTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Please paste replies unless you are specifically asked to attach it.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Thanks TomK.

Here is the Malwarebytes' Anti-Malware log:

Malwarebytes' Anti-Malware 1.30
Database version: 1450
Windows 5.1.2600 Service Pack 2

3/12/2008 12:56:23 PM
mbam-log-2008-12-03 (12-56-23).txt

Scan type: Quick Scan
Objects scanned: 60523
Time elapsed: 3 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OLE\DRam prosessor (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\system32\win32GI (Backdoor.Bifrose) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\gevuniya.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yabutuwi.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\win32GI\klog.dat (Backdoor.Bifrose) -> Quarantined and deleted successfully.


here is the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:58:37 PM, on 3/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\PROGRA~1\DVDREG~1\DVDRegionFree.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ClickCatcher MSIE handler - {16664845-0E00-11D2-8059-000000000000} - C:\Program Files\Common Files\ReGet Shared\Catcher.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: ReGet Bar - {17939A30-18E2-471E-9D3A-56DD725F1215} - C:\Program Files\ReGet Software\ReGet Deluxe 5.2\IEBar.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_5.cab
O16 - DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} (F5 Networks Policy Agent Host Class) -
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1180862377687
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

–
End of file - 14656 bytes

You are so speedy…..a million thanks…
obbie,

Your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
Thanks TomK

I would like to be 100% sure. My computer came with windows already loaded- so I do not have a disk for it.
Is this a problem?

Also, would I loose all my files if I reformat and reinstall windows?

Thanks,

Here is the log:

——————–\\ Lop S&D 4.2.4-9c XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : AMD Athlon™ 64 X2 Dual Core Processor 3800+ )
BIOS : Phoenix - Award BIOS v6.00PG
USER : Compaq_Owner ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Not Activated)
Firewall : Norton AntiVirus 15.5.0.23 (Activated)
C:\ (Local Disk) - NTFS - Total:179 Go (Free:70 Go)
D:\ (Local Disk) - FAT32 - Total:6 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (Local Disk) - FAT32 - Total:698 Go (Free:469 Go)

"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( Wed 03/12/2008|14:21 )

——————–\\ Listing folders in APPLIC~1

[21/11/2008|11:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[10/11/2008|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {D5ABFFAD-D592-4F98-B02B-587125B4801F}
[25/09/2007|08:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[20/01/2007|10:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe Systems
[02/08/2007|07:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[13/10/2006|08:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[21/05/2008|07:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Avira
[05/08/2008|12:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Azureus
[17/01/2008|04:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Downloaded Installations
[14/09/2008|10:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ DVD Shrink
[07/01/2008|04:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ FLEXnet
[27/02/2007|01:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[18/11/2007|03:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Grisoft
[14/04/2008|08:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Installations
[22/02/2006|11:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[19/11/2007|11:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Kaspersky Lab
[24/11/2008|03:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ LightScribe
[03/12/2008|12:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[08/09/2008|12:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[17/01/2008|10:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft Help
[24/11/2008|03:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Nero
[11/10/2007|08:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Nokia
[01/08/2007|10:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ part owns grid style
[10/11/2008|05:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PC Drivers Headquarters
[10/10/2007|11:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PC Suite
[22/10/2008|08:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PC Tools
[13/10/2006|05:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Roxio
[02/11/2007|11:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sandlot Games
[22/02/2006|11:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBSI
[11/09/2007|01:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Skype
[13/10/2006|05:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sonic
[13/10/2006|06:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sony Corporation
[12/11/2007|01:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SRSLabs
[01/08/2007|10:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Style Trust Pile Heart
[13/11/2007|08:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SUPERAntiSpyware.com
[10/11/2008|11:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Symantec
[13/10/2008|11:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Syncrosoft
[03/12/2008|02:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[15/11/2007|08:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Uniblue
[22/06/2007|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage

[20/05/2007|06:03] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Ableton
[26/11/2008|01:02] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ AccurateRip
[14/01/2005|03:16] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Adobe
[25/04/2007|08:12] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ AdobeUM
[11/10/2007|07:08] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Apple Computer
[20/05/2007|11:25] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Applied Acoustics Systems
[02/07/2006|01:31] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Atari
[08/09/2008|03:01] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ ATI
[03/12/2008|10:21] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Azureus
[02/07/2006|07:27] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ CyberLink
[10/10/2007|10:36] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Datalayer
[26/11/2008|01:16] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ dBpoweramp
[17/04/2007|08:45] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ DivX
[19/11/2008|04:18] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ dvdcss
[21/01/2008|12:30] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ foobar2000
[31/10/2007|07:05] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ funkitron
[01/06/2007|08:18] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Google
[12/07/2007|03:22] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Help
[08/07/2006|10:20] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ HP
[22/12/2006|07:04] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ HPQ
[15/12/2004|09:22] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Identities
[02/07/2006|01:24] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Leadertech
[13/10/2006|04:26] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Macromedia
[03/12/2008|12:51] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Malwarebytes
[07/04/2008|10:10] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Microsoft
[25/08/2008|08:57] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ mIRC
[22/08/2007|09:51] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Mozilla
[02/07/2006|04:32] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ MSNInstaller
[24/11/2008|03:41] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Nero
[09/12/2007|09:23] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Nokia
[03/04/2008|02:30] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Nokia Multimedia Player
[20/01/2007|11:08] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Opera
[09/12/2007|09:42] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ PC Suite
[03/12/2008|12:39] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ PC Tools
[10/04/2008|01:35] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Pegasys Inc
[02/10/2007|07:44] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Real
[03/12/2008|01:39] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ ReGet Software
[18/04/2007|03:54] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Roxio
[22/08/2007|09:53] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ SecondLife
[08/09/2008|01:41] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ SecuROM
[17/10/2008|10:51] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Skype
[17/10/2008|02:49] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ skypePM
[22/11/2006|12:19] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Sonic
[13/10/2006|08:39] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Sony Corporation
[14/10/2008|10:54] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Steinberg
[27/02/2007|01:10] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Sun
[17/01/2008|03:25] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ SUPERAntiSpyware.com
[22/08/2007|10:24] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Syntrillium
[02/07/2006|03:59] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Template
[15/11/2007|06:37] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Uniblue
[26/11/2008|12:57] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ uTorrent
[10/11/2008|05:10] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ VideoReDo-TVSuite
[02/11/2007|12:06] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ vlc
[10/04/2008|12:45] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Vso
[02/11/2007|11:21] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Wildfire
[09/07/2007|09:41] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ WinBatch

[21/11/2007|07:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Apple Computer
[08/09/2008|03:01] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ ATI
[15/12/2004|09:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Identities
[22/02/2006|11:38] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Macromedia
[23/02/2006|12:21] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[22/02/2006|11:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Real

[07/09/2008|05:39] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Adobe
[15/12/2004|09:22] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[13/10/2006|05:11] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Roxio

[15/12/2004|09:22] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[03/12/2008 12:00 PM][–a——] C:\WINDOWS\tasks\shutdown.job
[28/11/2008 10:58 PM][–a——] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[15/11/2007 10:32 PM][–a——] C:\WINDOWS\tasks\Uniblue SpyEraser.job
[03/12/2008 11:17 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[04/08/2004 10:00 PM][-rah—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[20/05/2007|11:27] C:\Program Files\ AAS
[20/05/2007|05:46] C:\Program Files\ Ableton
[11/04/2008|08:38] C:\Program Files\ AC3Filter
[12/12/2007|08:38] C:\Program Files\ Activision
[03/11/2008|10:30] C:\Program Files\ Adobe
[24/11/2008|04:08] C:\Program Files\ Ahead
[16/11/2007|09:57] C:\Program Files\ AnswersThatWork
[01/09/2008|08:39] C:\Program Files\ Apple Software Update
[21/05/2007|09:00] C:\Program Files\ Arturia
[05/08/2008|12:39] C:\Program Files\ AskSBar
[03/11/2008|11:35] C:\Program Files\ Atari
[08/09/2008|02:56] C:\Program Files\ ATI Technologies
[12/11/2008|10:04] C:\Program Files\ Auto Shutdown Genius
[05/11/2007|11:29] C:\Program Files\ Autodesk
[21/05/2008|07:34] C:\Program Files\ Avira
[13/10/2006|06:30] C:\Program Files\ Bethesda Softworks
[18/09/2008|05:28] C:\Program Files\ Bonjour
[03/12/2008|11:15] C:\Program Files\ Common Files
[24/11/2004|06:06] C:\Program Files\ ComPlus Applications
[28/08/2007|11:03] C:\Program Files\ coolpro2
[16/10/2008|09:34] C:\Program Files\ Cosmi
[07/09/2008|05:55] C:\Program Files\ Cucusoft
[10/10/2007|10:18] C:\Program Files\ DIFX
[21/05/2007|08:55] C:\Program Files\ Digidesign
[31/10/2008|04:19] C:\Program Files\ DivX
[26/09/2007|07:04] C:\Program Files\ DVD Region+CSS Free
[14/09/2008|10:58] C:\Program Files\ DVD Shrink
[01/12/2008|07:08] C:\Program Files\ DVDlabPro2
[07/07/2006|09:43] C:\Program Files\ EA Games
[01/06/2007|08:53] C:\Program Files\ foobar2000
[30/10/2007|08:20] C:\Program Files\ Gabest
[03/05/2008|03:53] C:\Program Files\ Google
[14/09/2008|08:44] C:\Program Files\ Haali
[18/04/2007|07:09] C:\Program Files\ Hewlett-Packard
[17/01/2008|02:16] C:\Program Files\ HP
[16/03/2007|04:34] C:\Program Files\ illiminable
[12/06/2008|02:15] C:\Program Files\ Illustrate
[10/11/2008|11:46] C:\Program Files\ InstallShield Installation Information
[02/04/2008|11:24] C:\Program Files\ Internet Explorer
[21/11/2008|11:19] C:\Program Files\ iPod
[21/11/2008|11:19] C:\Program Files\ iTunes
[05/08/2008|12:29] C:\Program Files\ Java
[20/04/2007|09:37] C:\Program Files\ LimeWire
[28/07/2008|12:38] C:\Program Files\ Logitech
[12/12/2007|07:24] C:\Program Files\ MagicDisc
[27/04/2007|06:21] C:\Program Files\ MagicISO
[03/12/2008|12:51] C:\Program Files\ Malwarebytes' Anti-Malware
[22/02/2006|11:22] C:\Program Files\ Messenger
[15/12/2004|09:23] C:\Program Files\ microsoft frontpage
[16/07/2008|07:13] C:\Program Files\ Microsoft Games
[02/07/2006|03:51] C:\Program Files\ Microsoft IntelliPoint
[02/07/2006|03:50] C:\Program Files\ Microsoft IntelliType Pro
[17/01/2008|03:15] C:\Program Files\ Microsoft Office
[27/04/2007|06:52] C:\Program Files\ Microsoft Visual Studio
[17/01/2008|03:15] C:\Program Files\ Microsoft Works
[27/04/2007|06:51] C:\Program Files\ Microsoft.NET
[25/08/2008|02:32] C:\Program Files\ mIRC
[15/12/2004|09:23] C:\Program Files\ Movie Maker
[03/12/2008|01:15] C:\Program Files\ Mozilla Firefox
[27/04/2007|06:53] C:\Program Files\ MSBuild
[15/12/2004|09:23] C:\Program Files\ MSN
[15/12/2004|09:23] C:\Program Files\ MSN Gaming Zone
[01/03/2007|11:03] C:\Program Files\ MSN Messenger
[04/06/2007|08:49] C:\Program Files\ MSXML 4.0
[02/08/2007|11:05] C:\Program Files\ MSXML 6.0
[21/05/2007|08:47] C:\Program Files\ Native Instruments
[24/11/2008|03:13] C:\Program Files\ Nero
[15/12/2004|09:23] C:\Program Files\ NetMeeting
[14/04/2008|08:53] C:\Program Files\ Nokia
[17/01/2008|03:26] C:\Program Files\ Oberon Media
[03/07/2006|08:19] C:\Program Files\ OfficeUpdate11
[23/02/2006|12:06] C:\Program Files\ Online Services
[12/11/2007|01:21] C:\Program Files\ Orban
[14/06/2007|12:23] C:\Program Files\ Outlook Express
[14/04/2008|08:54] C:\Program Files\ PC Connectivity Solution
[10/11/2008|05:45] C:\Program Files\ PC Drivers HeadQuarters
[13/10/2006|06:21] C:\Program Files\ PC-Doctor 5 for Windows
[23/02/2006|12:03] C:\Program Files\ PC-Doctor for DOS
[29/11/2008|12:45] C:\Program Files\ PeerGuardian2
[10/04/2008|01:34] C:\Program Files\ Pegasys Inc
[16/03/2007|04:35] C:\Program Files\ piPOol
[16/10/2008|09:31] C:\Program Files\ PowerISO
[10/05/2008|03:45] C:\Program Files\ Project64
[08/08/2008|12:58] C:\Program Files\ ptrk2008-09
[21/11/2008|11:17] C:\Program Files\ QuickTime
[20/05/2007|05:38] C:\Program Files\ RdDrv001
[22/02/2006|11:39] C:\Program Files\ Real
[02/08/2007|11:00] C:\Program Files\ Reference Assemblies
[08/08/2008|12:36] C:\Program Files\ ReGet Software
[13/10/2006|05:06] C:\Program Files\ Roxio
[11/09/2007|01:28] C:\Program Files\ Skype
[22/02/2006|11:53] C:\Program Files\ Sonic
[05/08/2007|12:43] C:\Program Files\ Sony
[13/10/2006|06:18] C:\Program Files\ Sony Corporation
[03/12/2008|02:20] C:\Program Files\ Spyware Doctor
[24/05/2008|01:11] C:\Program Files\ Starcraft
[03/11/2008|11:32] C:\Program Files\ Steinberg
[17/01/2008|03:25] C:\Program Files\ SUPERAntiSpyware
[13/10/2008|11:49] C:\Program Files\ Syncrosoft
[08/09/2008|02:51] C:\Program Files\ SystemRequirementsLab
[18/11/2007|05:15] C:\Program Files\ Trend Micro
[15/11/2007|06:26] C:\Program Files\ Uniblue
[24/11/2004|06:07] C:\Program Files\ Uninstall Information
[28/02/2007|10:36] C:\Program Files\ utorrent
[02/11/2007|12:04] C:\Program Files\ VideoLAN
[09/11/2008|09:44] C:\Program Files\ VideoReDoTVSuite
[22/11/2008|08:48] C:\Program Files\ Vuze
[15/05/2008|03:30] C:\Program Files\ Western Digital
[15/05/2008|03:22] C:\Program Files\ Western Digital Technologies
[19/09/2008|12:46] C:\Program Files\ WinAVI MP4 Converter
[22/06/2007|09:46] C:\Program Files\ Windows Media Connect 2
[22/06/2007|03:10] C:\Program Files\ Windows Media Player
[15/12/2004|09:23] C:\Program Files\ Windows NT
[24/11/2008|03:11] C:\Program Files\ Windows Sidebar
[24/11/2004|06:07] C:\Program Files\ WindowsUpdate
[11/10/2007|12:20] C:\Program Files\ WinRAR
[15/12/2004|09:24] C:\Program Files\ xerox
[10/04/2008|02:00] C:\Program Files\ Xilisoft
[19/09/2008|12:11] C:\Program Files\ Xvid

——————–\\ Listing Folders in C:\Program Files\Common Files

[10/11/2008|11:44] C:\Program Files\Common Files\ Adobe
[20/01/2007|10:48] C:\Program Files\Common Files\ Adobe Systems Shared
[21/11/2008|11:19] C:\Program Files\Common Files\ Apple
[18/04/2007|12:32] C:\Program Files\Common Files\ AVSMedia
[10/11/2008|11:50] C:\Program Files\Common Files\ Blizzard Entertainment
[16/10/2008|09:34] C:\Program Files\Common Files\ Borland Shared
[16/10/2008|09:34] C:\Program Files\Common Files\ Cosmi
[27/04/2007|06:52] C:\Program Files\Common Files\ DESIGNER
[20/05/2007|05:47] C:\Program Files\Common Files\ Digidesign
[22/02/2006|11:34] C:\Program Files\Common Files\ HP
[22/02/2006|11:54] C:\Program Files\Common Files\ InstallShield
[22/02/2006|11:18] C:\Program Files\Common Files\ Java
[24/11/2008|04:09] C:\Program Files\Common Files\ LightScribe
[28/07/2008|12:39] C:\Program Files\Common Files\ Logitech
[25/09/2007|08:40] C:\Program Files\Common Files\ Macrovision Shared
[28/01/2008|09:27] C:\Program Files\Common Files\ Microsoft Shared
[15/12/2004|09:23] C:\Program Files\Common Files\ MSSoap
[20/05/2007|11:45] C:\Program Files\Common Files\ Native Instruments
[24/11/2008|03:30] C:\Program Files\Common Files\ Nero
[14/04/2008|08:55] C:\Program Files\Common Files\ Nokia
[15/12/2004|09:23] C:\Program Files\Common Files\ ODBC
[03/12/2008|12:39] C:\Program Files\Common Files\ PC Tools
[14/04/2008|08:55] C:\Program Files\Common Files\ PCSuite
[02/07/2006|01:24] C:\Program Files\Common Files\ PocketSoft
[02/10/2007|07:44] C:\Program Files\Common Files\ Real
[08/08/2008|11:38] C:\Program Files\Common Files\ ReGet Shared
[13/10/2006|05:06] C:\Program Files\Common Files\ Roxio Shared
[15/12/2004|09:23] C:\Program Files\Common Files\ Services
[28/07/2008|01:22] C:\Program Files\Common Files\ Skype
[13/10/2006|05:06] C:\Program Files\Common Files\ Sonic Shared
[13/10/2006|06:18] C:\Program Files\Common Files\ Sony Shared
[15/12/2004|09:23] C:\Program Files\Common Files\ SpeechEngines
[22/02/2006|11:40] C:\Program Files\Common Files\ SureThing Shared
[10/11/2008|11:49] C:\Program Files\Common Files\ Symantec Shared
[16/10/2007|06:58] C:\Program Files\Common Files\ Symbian
[14/06/2007|12:23] C:\Program Files\Common Files\ System
[22/02/2006|11:53] C:\Program Files\Common Files\ TiVo Shared

——————–\\ Process

( 51 Processes )

iexplore.exe ~ [PID:3308]

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

C:\DOCUME~1\ALLUSE~1\APPLIC~1\Style Trust Pile Heart

——————–\\ Searching within the Registry

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-03 14:22:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\COMPAQ~1\Application Data\Azureus\torrents\AVS_Video_Converter_v4.3.1.371_+_crack_[h33t][thecliffhanger]_[mininova][1]
.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\Azureus\torrents\ReGet Deluxe 5.2 Build 320 RC + Crack.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Adobe_Acrobat_Professional_v8_Full_Version_with_Keygen.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Apex Video Converter Super v6.59+Keygen-HeartBug.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Autodesk Maya 2008 Unlimited (win32)keygen included.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\AVG 2008 crack.exe.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\AVG Anti-Spyware Pro V7.5.1.43 Crack -ICU.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Avs Video Converter v5.5 Incl Crack !.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Cool Edit Pro 2.1 with Crack.zip.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\DivX.Create.PRO.Bundle.V.6.1.1.-.incl.KeyGen.-.by.ShadoX.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Koi Fish 3D Screensaver + crack .rar.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Magic Iso 5.3b216 + Crack.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Magic ISO Maker v5.3+keygen.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Nero Burning ROM 8.1.1.0 [PL] [Activation Keygen].torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Office 2007 Enterprise Version with Keygen.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\PowerISO v3.6 with working keygen.zip.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\REAL MS Office 2003 Keygen.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware Doctor 5.1 + Keygen.rar.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware Doctor v5.5.1.322 + Keygen [updated].torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware.doctor+working.crack(DFT).torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware_Doctor_5.1.0.272___Crack.rar.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Sp_yware_Do_ctor5.x.0.1.20.xCrackandSerial.rar.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Symantec Norton Internet Security 2008 +Crack.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\The Ultimate Troubleshooter 3.77 + crack.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Xilisoft Complet-Pack All Video Audio Converters Incl Keygen zipped.torrent
C:\DOCUME~1\COMPAQ~1\My Documents\Ableton\Live Library\Presets\Audio Effects\Vinyl Distortion\Crack.adv
C:\DOCUME~1\COMPAQ~1\My Documents\Azureus Downloads\Spyware Doctor v6.0.0.385(FULL) totally clean and updateable\Spyware Doctor v6.0.0.385(FULL)\CRACK
C:\DOCUME~1\COMPAQ~1\My Documents\Azureus Downloads\Spyware Doctor v6.0.0.385(FULL) totally clean and updateable\Spyware Doctor v6.0.0.385(FULL)\CRACK\How to Activate.txt
C:\DOCUME~1\COMPAQ~1\My Documents\Azureus Downloads\Spyware Doctor v6.0.0.385(FULL) totally clean and updateable\Spyware Doctor v6.0.0.385(FULL)\CRACK\Update.exe
C:\DOCUME~1\COMPAQ~1\Recent\CRACK.lnk


[F:4][D:4]-> C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
[F:8][D:0]-> C:\DOCUME~1\COMPAQ~1\Cookies
[F:131][D:4]-> C:\DOCUME~1\COMPAQ~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Wed 03/12/2008|14:23 - Option : [1]

——————–\\ Scan completed at 14:23:48
UPDATE: Ran a scan with Spyware Doctor: Found Info & PUAs (I believe this to be combofix) Found Generic Trojan in HKEY_USERS\………….\Software\Wget Clean successfully. Does this help?
obbie,

My computer came with windows already loaded- so I do not have a disk for it.
Is this a problem?

You need a disk to format and reinstall windows.

Also, would I loose all my files if I reformat and reinstall windows?

You could backup pictures and data, scan them before reloading. I wouldn't recommend transferring executable programs.


You are still infected.

Restart Lop S&D

This time choose Option 3 (Fix - Hosts)
Don't close the window during suppression!
Post the log which is created: (%SystemDrive%\lopR.txt)

Then

You got infected because you download cracks and keygens. You only have to download a couple of cracks before you are virtually guaranteed to be infected. The odds go up exponentially when you are using cracked security programs.

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\DOCUME~1\COMPAQ~1\Application Data\Azureus\torrents\AVS_Video_Converter_v4.3.1.371_+_crack_[h33t][thecliffhanger]_[mininova][1]
    .torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\Azureus\torrents\ReGet Deluxe 5.2 Build 320 RC + Crack.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Adobe_Acrobat_Professional_v8_Full_Version_with_Keygen.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Apex Video Converter Super v6.59+Keygen-HeartBug.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Autodesk Maya 2008 Unlimited (win32)keygen included.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\AVG 2008 crack.exe.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\AVG Anti-Spyware Pro V7.5.1.43 Crack -ICU.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Avs Video Converter v5.5 Incl Crack !.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Cool Edit Pro 2.1 with Crack.zip.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\DivX.Create.PRO.Bundle.V.6.1.1.-.incl.KeyGen.-.by.ShadoX.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Koi Fish 3D Screensaver + crack .rar.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Magic Iso 5.3b216 + Crack.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Magic ISO Maker v5.3+keygen.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Nero Burning ROM 8.1.1.0 [PL] [Activation Keygen].torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Office 2007 Enterprise Version with Keygen.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\PowerISO v3.6 with working keygen.zip.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\REAL MS Office 2003 Keygen.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware Doctor 5.1 + Keygen.rar.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware Doctor v5.5.1.322 + Keygen [updated].torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware.doctor+working.crack(DFT).torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware_Doctor_5.1.0.272___Crack.rar.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Sp_yware_Do_ctor5.x.0.1.20.xCrackandSerial.rar.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Symantec Norton Internet Security 2008 +Crack.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\The Ultimate Troubleshooter 3.77 + crack.torrent
    C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Xilisoft Complet-Pack All Video Audio Converters Incl Keygen zipped.torrent
    C:\DOCUME~1\COMPAQ~1\My Documents\Ableton\Live Library\Presets\Audio Effects\Vinyl Distortion\Crack.adv
    C:\DOCUME~1\COMPAQ~1\My Documents\Azureus Downloads\Spyware Doctor v6.0.0.385(FULL) totally clean and updateable\Spyware Doctor v6.0.0.385(FULL)\CRACK
    C:\DOCUME~1\COMPAQ~1\My Documents\Azureus Downloads\Spyware Doctor v6.0.0.385(FULL) totally clean and updateable\Spyware Doctor v6.0.0.385(FULL)\CRACK\How to Activate.txt
    C:\DOCUME~1\COMPAQ~1\My Documents\Azureus Downloads\Spyware Doctor v6.0.0.385(FULL) totally clean and updateable\Spyware Doctor v6.0.0.385(FULL)\CRACK\Update.exe
    C:\DOCUME~1\COMPAQ~1\Recent\CRACK.lnk
    
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Also please supply a new HijackThis log.
Lop S&D log:

——————–\\ Lop S&D 4.2.4-9c XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : AMD Athlon™ 64 X2 Dual Core Processor 3800+ )
BIOS : Phoenix - Award BIOS v6.00PG
USER : Compaq_Owner ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Not Activated)
Firewall : Norton AntiVirus 15.5.0.23 (Activated)
C:\ (Local Disk) - NTFS - Total:179 Go (Free:70 Go)
D:\ (Local Disk) - FAT32 - Total:6 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (Local Disk) - FAT32 - Total:698 Go (Free:469 Go)

"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [3] ( Thu 04/12/2008|12:11 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ FIX

Deleted! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Style Trust Pile Heart

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


——————–\\ Listing folders in APPLIC~1

[21/11/2008|11:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[10/11/2008|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {D5ABFFAD-D592-4F98-B02B-587125B4801F}
[25/09/2007|08:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[20/01/2007|10:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe Systems
[02/08/2007|07:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[13/10/2006|08:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[21/05/2008|07:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Avira
[05/08/2008|12:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Azureus
[17/01/2008|04:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Downloaded Installations
[14/09/2008|10:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ DVD Shrink
[07/01/2008|04:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ FLEXnet
[27/02/2007|01:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[18/11/2007|03:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Grisoft
[14/04/2008|08:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Installations
[22/02/2006|11:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[19/11/2007|11:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Kaspersky Lab
[24/11/2008|03:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ LightScribe
[03/12/2008|12:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[08/09/2008|12:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[17/01/2008|10:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft Help
[24/11/2008|03:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Nero
[11/10/2007|08:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Nokia
[01/08/2007|10:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ part owns grid style
[10/11/2008|05:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PC Drivers Headquarters
[10/10/2007|11:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PC Suite
[22/10/2008|08:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PC Tools
[13/10/2006|05:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Roxio
[02/11/2007|11:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sandlot Games
[22/02/2006|11:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBSI
[11/09/2007|01:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Skype
[13/10/2006|05:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sonic
[13/10/2006|06:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sony Corporation
[12/11/2007|01:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SRSLabs
[13/11/2007|08:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SUPERAntiSpyware.com
[10/11/2008|11:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Symantec
[13/10/2008|11:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Syncrosoft
[04/12/2008|11:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[15/11/2007|08:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Uniblue
[22/06/2007|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage

[20/05/2007|06:03] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Ableton
[26/11/2008|01:02] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ AccurateRip
[14/01/2005|03:16] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Adobe
[25/04/2007|08:12] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ AdobeUM
[11/10/2007|07:08] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Apple Computer
[20/05/2007|11:25] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Applied Acoustics Systems
[02/07/2006|01:31] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Atari
[08/09/2008|03:01] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ ATI
[03/12/2008|10:21] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Azureus
[02/07/2006|07:27] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ CyberLink
[10/10/2007|10:36] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Datalayer
[26/11/2008|01:16] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ dBpoweramp
[17/04/2007|08:45] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ DivX
[19/11/2008|04:18] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ dvdcss
[21/01/2008|12:30] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ foobar2000
[31/10/2007|07:05] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ funkitron
[01/06/2007|08:18] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Google
[12/07/2007|03:22] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Help
[08/07/2006|10:20] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ HP
[22/12/2006|07:04] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ HPQ
[15/12/2004|09:22] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Identities
[02/07/2006|01:24] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Leadertech
[13/10/2006|04:26] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Macromedia
[03/12/2008|12:51] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Malwarebytes
[07/04/2008|10:10] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Microsoft
[25/08/2008|08:57] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ mIRC
[22/08/2007|09:51] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Mozilla
[02/07/2006|04:32] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ MSNInstaller
[24/11/2008|03:41] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Nero
[09/12/2007|09:23] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Nokia
[03/04/2008|02:30] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Nokia Multimedia Player
[20/01/2007|11:08] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Opera
[09/12/2007|09:42] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ PC Suite
[03/12/2008|12:39] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ PC Tools
[10/04/2008|01:35] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Pegasys Inc
[02/10/2007|07:44] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Real
[03/12/2008|01:39] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ ReGet Software
[18/04/2007|03:54] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Roxio
[22/08/2007|09:53] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ SecondLife
[08/09/2008|01:41] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ SecuROM
[17/10/2008|10:51] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Skype
[17/10/2008|02:49] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ skypePM
[22/11/2006|12:19] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Sonic
[13/10/2006|08:39] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Sony Corporation
[14/10/2008|10:54] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Steinberg
[27/02/2007|01:10] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Sun
[17/01/2008|03:25] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ SUPERAntiSpyware.com
[22/08/2007|10:24] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Syntrillium
[02/07/2006|03:59] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Template
[15/11/2007|06:37] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Uniblue
[26/11/2008|12:57] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ uTorrent
[10/11/2008|05:10] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ VideoReDo-TVSuite
[02/11/2007|12:06] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ vlc
[10/04/2008|12:45] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Vso
[02/11/2007|11:21] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Wildfire
[09/07/2007|09:41] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ WinBatch

[21/11/2007|07:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Apple Computer
[08/09/2008|03:01] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ ATI
[15/12/2004|09:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Identities
[22/02/2006|11:38] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Macromedia
[23/02/2006|12:21] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[22/02/2006|11:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Real

[07/09/2008|05:39] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Adobe
[15/12/2004|09:22] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[13/10/2006|05:11] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Roxio

[15/12/2004|09:22] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[04/12/2008 12:00 PM][–a——] C:\WINDOWS\tasks\shutdown.job
[28/11/2008 10:58 PM][–a——] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[15/11/2007 10:32 PM][–a——] C:\WINDOWS\tasks\Uniblue SpyEraser.job
[03/12/2008 11:17 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[04/08/2004 10:00 PM][-rah—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[20/05/2007|11:27] C:\Program Files\ AAS
[20/05/2007|05:46] C:\Program Files\ Ableton
[11/04/2008|08:38] C:\Program Files\ AC3Filter
[12/12/2007|08:38] C:\Program Files\ Activision
[03/11/2008|10:30] C:\Program Files\ Adobe
[24/11/2008|04:08] C:\Program Files\ Ahead
[16/11/2007|09:57] C:\Program Files\ AnswersThatWork
[01/09/2008|08:39] C:\Program Files\ Apple Software Update
[21/05/2007|09:00] C:\Program Files\ Arturia
[05/08/2008|12:39] C:\Program Files\ AskSBar
[03/11/2008|11:35] C:\Program Files\ Atari
[08/09/2008|02:56] C:\Program Files\ ATI Technologies
[12/11/2008|10:04] C:\Program Files\ Auto Shutdown Genius
[05/11/2007|11:29] C:\Program Files\ Autodesk
[21/05/2008|07:34] C:\Program Files\ Avira
[13/10/2006|06:30] C:\Program Files\ Bethesda Softworks
[18/09/2008|05:28] C:\Program Files\ Bonjour
[03/12/2008|11:15] C:\Program Files\ Common Files
[24/11/2004|06:06] C:\Program Files\ ComPlus Applications
[28/08/2007|11:03] C:\Program Files\ coolpro2
[16/10/2008|09:34] C:\Program Files\ Cosmi
[07/09/2008|05:55] C:\Program Files\ Cucusoft
[10/10/2007|10:18] C:\Program Files\ DIFX
[21/05/2007|08:55] C:\Program Files\ Digidesign
[31/10/2008|04:19] C:\Program Files\ DivX
[26/09/2007|07:04] C:\Program Files\ DVD Region+CSS Free
[14/09/2008|10:58] C:\Program Files\ DVD Shrink
[01/12/2008|07:08] C:\Program Files\ DVDlabPro2
[07/07/2006|09:43] C:\Program Files\ EA Games
[01/06/2007|08:53] C:\Program Files\ foobar2000
[30/10/2007|08:20] C:\Program Files\ Gabest
[03/05/2008|03:53] C:\Program Files\ Google
[14/09/2008|08:44] C:\Program Files\ Haali
[18/04/2007|07:09] C:\Program Files\ Hewlett-Packard
[17/01/2008|02:16] C:\Program Files\ HP
[16/03/2007|04:34] C:\Program Files\ illiminable
[12/06/2008|02:15] C:\Program Files\ Illustrate
[10/11/2008|11:46] C:\Program Files\ InstallShield Installation Information
[02/04/2008|11:24] C:\Program Files\ Internet Explorer
[21/11/2008|11:19] C:\Program Files\ iPod
[21/11/2008|11:19] C:\Program Files\ iTunes
[05/08/2008|12:29] C:\Program Files\ Java
[20/04/2007|09:37] C:\Program Files\ LimeWire
[28/07/2008|12:38] C:\Program Files\ Logitech
[12/12/2007|07:24] C:\Program Files\ MagicDisc
[27/04/2007|06:21] C:\Program Files\ MagicISO
[03/12/2008|12:51] C:\Program Files\ Malwarebytes' Anti-Malware
[22/02/2006|11:22] C:\Program Files\ Messenger
[15/12/2004|09:23] C:\Program Files\ microsoft frontpage
[16/07/2008|07:13] C:\Program Files\ Microsoft Games
[02/07/2006|03:51] C:\Program Files\ Microsoft IntelliPoint
[02/07/2006|03:50] C:\Program Files\ Microsoft IntelliType Pro
[17/01/2008|03:15] C:\Program Files\ Microsoft Office
[27/04/2007|06:52] C:\Program Files\ Microsoft Visual Studio
[17/01/2008|03:15] C:\Program Files\ Microsoft Works
[27/04/2007|06:51] C:\Program Files\ Microsoft.NET
[25/08/2008|02:32] C:\Program Files\ mIRC
[15/12/2004|09:23] C:\Program Files\ Movie Maker
[03/12/2008|01:15] C:\Program Files\ Mozilla Firefox
[27/04/2007|06:53] C:\Program Files\ MSBuild
[15/12/2004|09:23] C:\Program Files\ MSN
[15/12/2004|09:23] C:\Program Files\ MSN Gaming Zone
[01/03/2007|11:03] C:\Program Files\ MSN Messenger
[04/06/2007|08:49] C:\Program Files\ MSXML 4.0
[02/08/2007|11:05] C:\Program Files\ MSXML 6.0
[21/05/2007|08:47] C:\Program Files\ Native Instruments
[24/11/2008|03:13] C:\Program Files\ Nero
[15/12/2004|09:23] C:\Program Files\ NetMeeting
[14/04/2008|08:53] C:\Program Files\ Nokia
[17/01/2008|03:26] C:\Program Files\ Oberon Media
[03/07/2006|08:19] C:\Program Files\ OfficeUpdate11
[23/02/2006|12:06] C:\Program Files\ Online Services
[12/11/2007|01:21] C:\Program Files\ Orban
[14/06/2007|12:23] C:\Program Files\ Outlook Express
[14/04/2008|08:54] C:\Program Files\ PC Connectivity Solution
[10/11/2008|05:45] C:\Program Files\ PC Drivers HeadQuarters
[13/10/2006|06:21] C:\Program Files\ PC-Doctor 5 for Windows
[23/02/2006|12:03] C:\Program Files\ PC-Doctor for DOS
[29/11/2008|12:45] C:\Program Files\ PeerGuardian2
[10/04/2008|01:34] C:\Program Files\ Pegasys Inc
[16/03/2007|04:35] C:\Program Files\ piPOol
[16/10/2008|09:31] C:\Program Files\ PowerISO
[10/05/2008|03:45] C:\Program Files\ Project64
[08/08/2008|12:58] C:\Program Files\ ptrk2008-09
[21/11/2008|11:17] C:\Program Files\ QuickTime
[20/05/2007|05:38] C:\Program Files\ RdDrv001
[22/02/2006|11:39] C:\Program Files\ Real
[02/08/2007|11:00] C:\Program Files\ Reference Assemblies
[08/08/2008|12:36] C:\Program Files\ ReGet Software
[13/10/2006|05:06] C:\Program Files\ Roxio
[11/09/2007|01:28] C:\Program Files\ Skype
[22/02/2006|11:53] C:\Program Files\ Sonic
[05/08/2007|12:43] C:\Program Files\ Sony
[13/10/2006|06:18] C:\Program Files\ Sony Corporation
[03/12/2008|09:02] C:\Program Files\ Spyware Doctor
[24/05/2008|01:11] C:\Program Files\ Starcraft
[03/11/2008|11:32] C:\Program Files\ Steinberg
[17/01/2008|03:25] C:\Program Files\ SUPERAntiSpyware
[13/10/2008|11:49] C:\Program Files\ Syncrosoft
[08/09/2008|02:51] C:\Program Files\ SystemRequirementsLab
[18/11/2007|05:15] C:\Program Files\ Trend Micro
[15/11/2007|06:26] C:\Program Files\ Uniblue
[24/11/2004|06:07] C:\Program Files\ Uninstall Information
[28/02/2007|10:36] C:\Program Files\ utorrent
[02/11/2007|12:04] C:\Program Files\ VideoLAN
[09/11/2008|09:44] C:\Program Files\ VideoReDoTVSuite
[22/11/2008|08:48] C:\Program Files\ Vuze
[15/05/2008|03:30] C:\Program Files\ Western Digital
[15/05/2008|03:22] C:\Program Files\ Western Digital Technologies
[19/09/2008|12:46] C:\Program Files\ WinAVI MP4 Converter
[22/06/2007|09:46] C:\Program Files\ Windows Media Connect 2
[22/06/2007|03:10] C:\Program Files\ Windows Media Player
[15/12/2004|09:23] C:\Program Files\ Windows NT
[24/11/2008|03:11] C:\Program Files\ Windows Sidebar
[24/11/2004|06:07] C:\Program Files\ WindowsUpdate
[11/10/2007|12:20] C:\Program Files\ WinRAR
[15/12/2004|09:24] C:\Program Files\ xerox
[10/04/2008|02:00] C:\Program Files\ Xilisoft
[19/09/2008|12:11] C:\Program Files\ Xvid

——————–\\ Listing Folders in C:\Program Files\Common Files

[10/11/2008|11:44] C:\Program Files\Common Files\ Adobe
[20/01/2007|10:48] C:\Program Files\Common Files\ Adobe Systems Shared
[21/11/2008|11:19] C:\Program Files\Common Files\ Apple
[18/04/2007|12:32] C:\Program Files\Common Files\ AVSMedia
[10/11/2008|11:50] C:\Program Files\Common Files\ Blizzard Entertainment
[16/10/2008|09:34] C:\Program Files\Common Files\ Borland Shared
[16/10/2008|09:34] C:\Program Files\Common Files\ Cosmi
[27/04/2007|06:52] C:\Program Files\Common Files\ DESIGNER
[20/05/2007|05:47] C:\Program Files\Common Files\ Digidesign
[22/02/2006|11:34] C:\Program Files\Common Files\ HP
[22/02/2006|11:54] C:\Program Files\Common Files\ InstallShield
[22/02/2006|11:18] C:\Program Files\Common Files\ Java
[24/11/2008|04:09] C:\Program Files\Common Files\ LightScribe
[28/07/2008|12:39] C:\Program Files\Common Files\ Logitech
[25/09/2007|08:40] C:\Program Files\Common Files\ Macrovision Shared
[28/01/2008|09:27] C:\Program Files\Common Files\ Microsoft Shared
[15/12/2004|09:23] C:\Program Files\Common Files\ MSSoap
[20/05/2007|11:45] C:\Program Files\Common Files\ Native Instruments
[24/11/2008|03:30] C:\Program Files\Common Files\ Nero
[14/04/2008|08:55] C:\Program Files\Common Files\ Nokia
[15/12/2004|09:23] C:\Program Files\Common Files\ ODBC
[03/12/2008|12:39] C:\Program Files\Common Files\ PC Tools
[14/04/2008|08:55] C:\Program Files\Common Files\ PCSuite
[02/07/2006|01:24] C:\Program Files\Common Files\ PocketSoft
[02/10/2007|07:44] C:\Program Files\Common Files\ Real
[08/08/2008|11:38] C:\Program Files\Common Files\ ReGet Shared
[13/10/2006|05:06] C:\Program Files\Common Files\ Roxio Shared
[15/12/2004|09:23] C:\Program Files\Common Files\ Services
[28/07/2008|01:22] C:\Program Files\Common Files\ Skype
[13/10/2006|05:06] C:\Program Files\Common Files\ Sonic Shared
[13/10/2006|06:18] C:\Program Files\Common Files\ Sony Shared
[15/12/2004|09:23] C:\Program Files\Common Files\ SpeechEngines
[22/02/2006|11:40] C:\Program Files\Common Files\ SureThing Shared
[10/11/2008|11:49] C:\Program Files\Common Files\ Symantec Shared
[16/10/2007|06:58] C:\Program Files\Common Files\ Symbian
[14/06/2007|12:23] C:\Program Files\Common Files\ System
[22/02/2006|11:53] C:\Program Files\Common Files\ TiVo Shared

——————–\\ Process

( 53 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-04 12:13:05
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\COMPAQ~1\Application Data\Azureus\torrents\AVS_Video_Converter_v4.3.1.371_+_crack_[h33t][thecliffhanger]_[mininova][1]
.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\Azureus\torrents\ReGet Deluxe 5.2 Build 320 RC + Crack.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Adobe_Acrobat_Professional_v8_Full_Version_with_Keygen.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Apex Video Converter Super v6.59+Keygen-HeartBug.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Autodesk Maya 2008 Unlimited (win32)keygen included.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\AVG 2008 crack.exe.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\AVG Anti-Spyware Pro V7.5.1.43 Crack -ICU.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Avs Video Converter v5.5 Incl Crack !.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Cool Edit Pro 2.1 with Crack.zip.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\DivX.Create.PRO.Bundle.V.6.1.1.-.incl.KeyGen.-.by.ShadoX.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Koi Fish 3D Screensaver + crack .rar.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Magic Iso 5.3b216 + Crack.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Magic ISO Maker v5.3+keygen.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Nero Burning ROM 8.1.1.0 [PL] [Activation Keygen].torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Office 2007 Enterprise Version with Keygen.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\PowerISO v3.6 with working keygen.zip.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\REAL MS Office 2003 Keygen.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware Doctor 5.1 + Keygen.rar.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware Doctor v5.5.1.322 + Keygen [updated].torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware.doctor+working.crack(DFT).torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware_Doctor_5.1.0.272___Crack.rar.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Sp_yware_Do_ctor5.x.0.1.20.xCrackandSerial.rar.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Symantec Norton Internet Security 2008 +Crack.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\The Ultimate Troubleshooter 3.77 + crack.torrent
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Xilisoft Complet-Pack All Video Audio Converters Incl Keygen zipped.torrent
C:\DOCUME~1\COMPAQ~1\My Documents\Ableton\Live Library\Presets\Audio Effects\Vinyl Distortion\Crack.adv
C:\DOCUME~1\COMPAQ~1\My Documents\Azureus Downloads\Spyware Doctor v6.0.0.385(FULL) totally clean and updateable\Spyware Doctor v6.0.0.385(FULL)\CRACK
C:\DOCUME~1\COMPAQ~1\My Documents\Azureus Downloads\Spyware Doctor v6.0.0.385(FULL) totally clean and updateable\Spyware Doctor v6.0.0.385(FULL)\CRACK\How to Activate.txt
C:\DOCUME~1\COMPAQ~1\My Documents\Azureus Downloads\Spyware Doctor v6.0.0.385(FULL) totally clean and updateable\Spyware Doctor v6.0.0.385(FULL)\CRACK\Update.exe
C:\DOCUME~1\COMPAQ~1\Recent\CRACK.lnk


[F:2][D:4]-> C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
[F:13][D:0]-> C:\DOCUME~1\COMPAQ~1\Cookies
[F:295][D:4]-> C:\DOCUME~1\COMPAQ~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Wed 03/12/2008|14:23 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - Thu 04/12/2008|12:14 - Option : [3]

——————–\\ Scan completed at 12:14:31

OTMoveIT log:

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File/Folder C:\DOCUME~1\COMPAQ~1\Application Data\Azureus\torrents\AVS_Video_Converter_v4.3.1.371_+_crack_[h33t][thecliffhanger]_[mininova][1] not found.
File/Folder .torrent not found.
C:\DOCUME~1\COMPAQ~1\Application Data\Azureus\torrents\ReGet Deluxe 5.2 Build 320 RC + Crack.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Adobe_Acrobat_Professional_v8_Full_Version_with_Keygen.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Apex Video Converter Super v6.59+Keygen-HeartBug.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Autodesk Maya 2008 Unlimited (win32)keygen included.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\AVG 2008 crack.exe.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\AVG Anti-Spyware Pro V7.5.1.43 Crack -ICU.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Avs Video Converter v5.5 Incl Crack !.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Cool Edit Pro 2.1 with Crack.zip.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\DivX.Create.PRO.Bundle.V.6.1.1.-.incl.KeyGen.-.by.ShadoX.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Koi Fish 3D Screensaver + crack .rar.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Magic Iso 5.3b216 + Crack.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Magic ISO Maker v5.3+keygen.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Nero Burning ROM 8.1.1.0 [PL] [Activation Keygen].torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Office 2007 Enterprise Version with Keygen.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\PowerISO v3.6 with working keygen.zip.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\REAL MS Office 2003 Keygen.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware Doctor 5.1 + Keygen.rar.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware Doctor v5.5.1.322 + Keygen [updated].torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware.doctor+working.crack(DFT).torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Spyware_Doctor_5.1.0.272___Crack.rar.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Sp_yware_Do_ctor5.x.0.1.20.xCrackandSerial.rar.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Symantec Norton Internet Security 2008 +Crack.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\The Ultimate Troubleshooter 3.77 + crack.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\Application Data\uTorrent\Xilisoft Complet-Pack All Video Audio Converters Incl Keygen zipped.torrent moved successfully.
C:\DOCUME~1\COMPAQ~1\My Documents\Ableton\Live Library\Presets\Audio Effects\Vinyl Distortion\Crack.adv moved successfully.
C:\DOCUME~1\COMPAQ~1\My Documents\Azureus Downloads\Spyware Doctor v6.0.0.385(FULL) totally clean and updateable\Spyware Doctor v6.0.0.385(FULL)\CRACK moved successfully.
File/Folder C:\DOCUME~1\COMPAQ~1\My Documents\Azureus Downloads\Spyware Doctor v6.0.0.385(FULL) totally clean and updateable\Spyware Doctor v6.0.0.385(FULL)\CRACK\How to Activate.txt not found.
File/Folder C:\DOCUME~1\COMPAQ~1\My Documents\Azureus Downloads\Spyware Doctor v6.0.0.385(FULL) totally clean and updateable\Spyware Doctor v6.0.0.385(FULL)\CRACK\Update.exe not found.
C:\DOCUME~1\COMPAQ~1\Recent\CRACK.lnk moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFBA9F.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFBAAF.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\JETDCD3.tmp scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 12042008_122321

Files moved on Reboot…
File C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFBA9F.tmp not found!
File C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFBAAF.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\JETDCD3.tmp not found!


HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:39:50 PM, on 4/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ClickCatcher MSIE handler - {16664845-0E00-11D2-8059-000000000000} - C:\Program Files\Common Files\ReGet Shared\Catcher.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: ReGet Bar - {17939A30-18E2-471E-9D3A-56DD725F1215} - C:\Program Files\ReGet Software\ReGet Deluxe 5.2\IEBar.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_5.cab
O16 - DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} (F5 Networks Policy Agent Host Class) -
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1180862377687
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

–
End of file - 14600 bytes


THANKS!!!!
obbie,

It's looking good. How's it running?

Let's do an online scan to make sure we didn't miss anything. Be prepared. This scan takes several hours.

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
All clean but for one file: ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Friday, December 5, 2008 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Thursday, December 04, 2008 00:16:01 Records in database: 1435674 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ K:\ Scan statistics: Files scanned: 155407 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 13:43:54 File name / Threat name / Threats count C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Trojan-Spy.HTML.Bankfraud.pd 1 The selected area was scanned.
obbie,

You need to go through your emails and delete all of them that you don't know who are from or what they are for. That particular email carries a Trojan that attempts to steal your banking information. The email that carries this typically claims to be from a financial institution. (there are similar ones out there that claim to be from UPS, Paypal, etc - never click on an email link that you don't know what is!) Once you've deleted all the emails that you don't need to keep, empty your deleted email folder. Then empty your recycle bin.

With that done, Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

Please re-enable any security that was disabled.

Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.

For a tutorial on Firewalls and a listing of some available ones see the link below:

Understanding and Using Firewalls

Keep Microsoft Windows Updated - This will ensure your computer has always the latest security updates available installed on your computer. The easiest way to do this is to turn on Automatic Updates. Do this by:
  • From your desktop, right-click on My Computer,
  • click on Properties
  • Select the Automatic Updates tab
  • Click on Automatic
  • Click on Apply button
  • Click on OK to exit.
If there are new updates to install, install them immediately, until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware

Download and install the free version of WinPatrol - This program protects your computer in a variety of ways and will work well with your existing security software.
Winpatrol


Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.


Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI