This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Having problems with Trojan Infection

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I need some help and advise to get rid of this trojan VirtuMonde in my computer. Since the other day, the PCTool SpyDoctor is giving this messages that a threat is blocked. Found out that it is a trojan.VirtuMonde.

HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:57:44 AM, on 12/6/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\LEXBCES.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Winamp Remote\bin\orbtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Winamp Remote\bin\Orb.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Windows\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [dmvbn.exe] C:\Windows\system32\dmvbn.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Winamp Toolbar Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\pnrpnsp.dll' missing
O13 - Gopher Prefix:
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{E7D7852C-2DF1-487C-8247-E898E65C7B27}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Desktop Manager 5.1.709.19590 (GoogleDesktopManager-091907-194040) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 10656 bytes

Many Thanks from a newbie.
[external image: Posted Image]

Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

1. These tools MUST be run from the executable. (.exe)
2. With Admin Rights (Right click, choose "Run as Administrator")


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Right-click ATF-Cleaner.exe and select "Run as administrator" to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Then:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Right-click mbam-setup.exe, select "Run as administrator" and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Also "copy/paste" a new HijackThis log file into this thread.
Hi LDTate, When I click on that link Malwarebytes, it says that the page can not be found. :( I have downloaded ATF cleaner already. Many thanks for your quick reply. Liz
Got Malwarebytes' now, thanks!

ATF Cleaner cleared 240,111

Here's the malwarebytes' log:

Malwarebytes' Anti-Malware 1.31
Database version: 1466
Windows 6.0.6000

12/6/2008 5:23:34 PM
mbam-log-2008-12-06 (17-23-34).txt

Scan type: Quick Scan
Objects scanned: 50299
Time elapsed: 6 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 5
Files Infected: 90

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e596df5f-4239-4d40-8367-ebadf0165917} (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Information Center (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance (Trojan.Zlob) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Users\Administrator\AppData\Roaming\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Registry Backups (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.

Files Infected:
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Errors.stg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Results.stg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 01 - 08_25_23 PM_614.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 01 - 08_25_33 PM_185.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 02 - 02_34_48 PM_413.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 02 - 02_35_18 PM_101.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 02 - 05_39_10 PM_619.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 02 - 05_39_14 PM_509.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 02 - 08_29_57 PM_446.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 02 - 08_29_59 PM_134.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 02 - 09_15_21 AM_528.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 02 - 09_15_26 AM_357.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 03 - 05_48_17 PM_040.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 03 - 05_48_19 PM_431.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 03 - 07_27_18 PM_553.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 03 - 07_27_28 PM_178.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 03 - 10_19_39 AM_117.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 03 - 10_19_40 AM_945.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 03 - 12_00_21 AM_904.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 03 - 12_00_25 AM_654.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 03 - 12_49_06 AM_231.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 03 - 12_49_10 AM_201.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 02_15_48 PM_599.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 02_15_49 PM_990.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 02_40_04 AM_970.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 02_40_08 AM_267.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 03_57_52 PM_321.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 03_57_53 PM_790.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 04_50_22 PM_051.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 04_50_24 PM_162.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 06_32_15 AM_169.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 06_32_16 AM_903.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 08_45_37 PM_366.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 08_45_41 PM_116.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 11_18_45 PM_883.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 11_18_49 PM_648.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 12_56_06 AM_547.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 12_56_08 AM_312.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 05 - 01_47_45 AM_629.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 05 - 01_47_47 AM_879.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 05 - 08_33_53 AM_529.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 05 - 08_33_59 AM_404.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 06 - 02_30_59 AM_062.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 06 - 02_31_03 AM_452.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 06 - 03_31_52 AM_836.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 06 - 03_31_55 AM_929.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 06 - 07_42_37 AM_071.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 06 - 07_42_39 AM_098.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 07 - 01_28_46 AM_362.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 07 - 01_28_53 AM_243.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 07 - 03_46_13 PM_728.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 07 - 03_46_15 PM_478.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 07 - 07_42_26 AM_840.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 07 - 07_42_33 AM_012.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 07 - 09_42_57 AM_712.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 07 - 09_43_04 AM_353.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 08 - 06_20_39 PM_940.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 08 - 06_20_45 PM_019.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 08 - 08_04_55 AM_454.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 08 - 08_04_57 AM_360.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 08 - 09_22_00 AM_331.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 08 - 09_22_04 AM_371.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 08 - 09_42_31 AM_024.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 08 - 09_42_33 AM_319.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 09 - 03_13_53 PM_851.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 09 - 03_13_55 PM_398.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 09 - 03_44_47 PM_156.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 09 - 03_44_48 PM_906.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 09 - 04_43_06 AM_851.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Log\2007 Jul 09 - 04_43_08 AM_991.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Registry Backups\2007-07-01_20-29-03.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Roaming\RegistrySmart\Registry Backups\2007-07-03_10-27-02.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 02 - 05_22_15 PM_538.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 02 - 05_22_18 PM_117.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 03 - 12_01_55 AM_445.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 03 - 12_01_57 AM_780.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 01_53_04 AM_338.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 04 - 01_53_07 AM_041.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 05 - 12_49_02 AM_035.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 05 - 12_49_04 AM_988.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 06 - 02_32_15 AM_109.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 06 - 02_32_18 AM_125.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 07 - 12_24_40 AM_370.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 07 - 12_24_43 AM_907.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 07 - 12_28_48 AM_525.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 07 - 12_28_49 AM_900.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 08 - 02_12_10 AM_671.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\RegistrySmart\Log\2007 Jul 08 - 02_12_13 AM_821.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Public\avg_free_stf_eu_8_176a1399.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Public\erunt_setup.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.


New HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:24:46 PM, on 12/6/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\LEXBCES.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Winamp Remote\bin\orbtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Winamp Remote\bin\Orb.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Windows\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [dmvbn.exe] C:\Windows\system32\dmvbn.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Winamp Toolbar Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\pnrpnsp.dll' missing
O13 - Gopher Prefix:
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{E7D7852C-2DF1-487C-8247-E898E65C7B27}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Desktop Manager 5.1.709.19590 (GoogleDesktopManager-091907-194040) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 10867 bytes


Liz
Please go to http://virusscan.jotti.org , click on Browse, and upload the following file for analysis:
C:\Windows\system32\dmvbn.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.


If Jotti is too busy you can try these.

http://www.kaspersky.com/scanforvirus.html


http://www.virustotal.com/en/indexf.html

I could not find the C:\Windows\system32\dmvbn.exe file in my computer. Even if I type it on the search for file. Shall I do a complete online scan instead?

Do this:


1. This tool MUST be run from the executable. (.exe)
2. With Admin Rights (Right click, choose "Run as Administrator")


Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Thanks for the very quick reply,LDTate.
The computer seem to be responding a bit slow.
Here is the combofix log:
ComboFix 08-12-04.05 - Administrator 2008-12-06 18:24:12.4 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.1.1033.18.1025 [GMT 1:00]
Running from: c:\users\[removed]\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-11-06 to 2008-12-06 )))))))))))))))))))))))))))))))
.

2008-12-06 17:08 . 2008-12-06 17:08 d——– c:\users\All Users\Malwarebytes
2008-12-06 17:08 . 2008-12-06 17:08 d——– c:\users\Administrator\AppData\Roaming\Malwarebytes
2008-12-06 17:08 . 2008-12-06 17:08 d——– c:\programdata\Malwarebytes
2008-12-06 17:08 . 2008-12-06 17:21 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-06 17:08 . 2008-12-03 19:52 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2008-12-06 17:08 . 2008-12-03 19:52 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2008-12-06 17:07 . 2008-12-06 17:07 2,539,400 –a—— c:\users\Public\mbam-setup.exe
2008-12-06 10:57 . 2008-12-06 10:57 d——– c:\program files\Trend Micro
2008-12-06 10:56 . 2008-12-06 10:56 812,344 –a—— c:\users\Public\HJTInstall.exe
2008-12-06 10:44 . 2008-12-06 10:44 d——– c:\program files\ERUNT
2008-12-06 03:56 . 2008-12-06 03:56 d——– C:\VundoFix Backups
2008-12-06 03:35 . 2008-12-06 03:35 199,680 –a—— c:\users\Public\DirLook.exe
2008-12-06 00:48 . 2008-12-06 12:54 d–h—– C:\$AVG8.VAULT$
2008-12-06 00:12 . 2008-12-06 12:39 d——– c:\windows\System32\drivers\Avg
2008-12-06 00:12 . 2008-12-06 00:12 97,928 –a—— c:\windows\System32\drivers\avgldx86.sys
2008-12-06 00:12 . 2008-12-06 00:12 10,520 –a—— c:\windows\System32\avgrsstx.dll
2008-12-06 00:11 . 2008-12-06 00:11 d——– c:\users\All Users\avg8
2008-12-06 00:11 . 2008-12-06 00:11 d——– c:\programdata\avg8
2008-12-06 00:11 . 2008-12-06 00:11 d——– c:\program files\AVG
2008-12-05 23:38 . 2008-12-05 23:38 488,144 –a—— c:\users\Public\HJTsetup.exe
2008-12-05 17:54 . 2008-12-05 17:54 d——– c:\users\All Users\NortonInstaller
2008-12-05 17:54 . 2008-12-05 17:54 d——– c:\programdata\NortonInstaller
2008-12-05 13:33 . 2008-12-05 13:33 3,057,867 -ra—— c:\users\Public\ComboFix.exe
2008-12-05 13:30 . 2008-12-05 13:30 50,688 –a—— c:\users\Public\ATF-Cleaner.exe
2008-12-05 12:25 . 2008-12-05 12:25 119,808 –a—— c:\users\Public\VundoFix.exe
2008-11-25 00:33 . 2008-11-25 00:36 34,134,544 –a—— c:\users\Public\1447_-_Jam_Sessions_(E).zip
2008-11-25 00:25 . 2008-11-25 00:30 45,476,984 –a—— c:\users\Public\2536_-_Moetan_DS_(J).zip
2008-11-25 00:14 . 2008-11-25 00:17 33,228,156 –a—— c:\users\Public\2181_-_Rosario_to_Vampire_-_Tanabata_no_Miss_Youkai_Gakuen_(J).zip
2008-11-18 21:44 . 2008-11-18 21:44 d——– c:\users\Public\moonshell10_dpgtools
2008-11-18 21:33 . 2008-11-18 21:33 d——– c:\users\Public\Moonshell Tools
2008-11-18 21:24 . 2008-06-17 15:50 d——– c:\users\Public\Moonshell
2008-11-18 21:23 . 2008-11-18 22:08 d——– c:\users\Public\New Folder (2)
2008-11-17 15:23 . 2008-11-17 15:23 1,809,944 –a—— c:\windows\System32\wuaueng.dll
2008-11-17 15:23 . 2008-11-17 15:23 1,524,736 –a—— c:\windows\System32\wucltux.dll
2008-11-17 15:23 . 2008-11-17 15:23 561,688 –a—— c:\windows\System32\wuapi.dll
2008-11-17 15:23 . 2008-11-17 15:23 83,456 –a—— c:\windows\System32\wudriver.dll
2008-11-17 15:23 . 2008-11-17 15:23 51,224 –a—— c:\windows\System32\wuauclt.exe
2008-11-17 15:23 . 2008-11-17 15:23 43,544 –a—— c:\windows\System32\wups2.dll
2008-11-17 15:23 . 2008-11-17 15:23 34,328 –a—— c:\windows\System32\wups.dll
2008-11-17 15:22 . 2008-11-17 15:22 162,064 –a—— c:\windows\System32\wuwebv.dll
2008-11-17 15:22 . 2008-11-17 15:22 31,232 –a—— c:\windows\System32\wuapp.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-06 17:21 ——— d—a-w c:\programdata\TEMP
2008-12-06 11:09 ——— d—–w c:\programdata\Google Updater
2008-12-06 03:10 ——— d—–w c:\program files\Spyware Doctor
2008-12-06 01:03 ——— d—–w c:\program files\Securitoo
2008-12-06 01:03 ——— d—–w c:\program files\Microsoft Silverlight
2008-12-05 23:07 ——— d—–w c:\programdata\F-Secure
2008-12-05 17:13 ——— d—–w c:\program files\Winamp Remote
2008-12-04 15:13 ——— d—–w c:\program files\Common Files\Caere
2008-12-04 13:45 ——— d—–w c:\programdata\Spybot - Search & Destroy
2008-11-17 03:35 ——— d—–w c:\users\Administrator\AppData\Roaming\Skype
2008-11-17 03:26 ——— d—–w c:\users\Administrator\AppData\Roaming\skypePM
2008-11-03 18:28 ——— d—–w c:\programdata\Microsoft Help
2008-11-03 18:06 ——— d—–w c:\program files\Microsoft Works
2008-11-03 18:05 ——— d—–w c:\program files\MSBuild
2008-11-03 17:59 ——— d—–w c:\program files\Microsoft.NET
2008-11-03 17:48 ——— d—–w c:\program files\Microsoft Visual Studio 8
2008-10-30 23:12 81,288 —-a-w c:\windows\system32\drivers\iksyssec.sys
2008-10-30 23:12 66,952 —-a-w c:\windows\system32\drivers\iksysflt.sys
2008-10-30 23:12 40,840 —-a-w c:\windows\system32\drivers\ikfilesec.sys
2008-10-26 09:22 ——— d—–w c:\program files\Wallpapers from MSN
2008-10-25 11:23 ——— d—–w c:\program files\Common Files\SWF Studio
2008-10-21 08:51 ——— d—–w c:\users\Guest\AppData\Roaming\Yahoo!
2008-10-16 09:53 ——— d—–w c:\programdata\Apple
2008-10-16 09:53 ——— d—–w c:\program files\Apple Software Update
2008-10-16 08:10 ——— d—–w c:\users\Administrator\AppData\Roaming\Yahoo!
2008-10-15 19:57 262,144 —-a-w C:\ntuser.dat
2008-10-12 21:57 ——— d—–w c:\program files\Common Files\xing shared
2008-10-12 21:56 ——— d—–w c:\program files\Common Files\Real
2008-10-01 11:27 32 —-a-w c:\users\All Users\ezsid.dat
2008-10-01 11:27 32 —-a-w c:\programdata\ezsid.dat
2008-07-18 07:48 174 –sha-w c:\program files\desktop.ini
2008-05-19 17:54 262,144 —-a-w c:\programdata\ntuser.dat
2007-08-12 13:20 203 —-a-w c:\program files\CD Drive - Shortcut.lnk
2007-08-12 13:20 203 —-a-w c:\program files\CD Drive - Shortcut (3).lnk
2007-08-12 13:20 203 —-a-w c:\program files\CD Drive - Shortcut (2).lnk
.

((((((((((((((((((((((((((((( snapshot_2008-12-06_ 2.22.53.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 11:02:28 163,328 —-a-w c:\windows\ERDNT\12-6-2008\ERDNT.EXE
+ 2008-12-06 09:45:01 3,670,016 —-a-w c:\windows\ERDNT\12-6-2008\Users\00000001\ntuser.dat
+ 2008-12-06 09:45:01 3,067,904 —-a-w c:\windows\ERDNT\12-6-2008\Users\00000002\UsrClass.dat
+ 2008-12-06 09:25:50 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-12-06 09:25:50 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-12-06 01:14:05 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-12-06 09:27:58 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-12-06 09:27:58 262,144 —ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-12-06 01:14:00 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-12-06 09:27:53 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-12-06 09:27:53 262,144 —ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-12-05 17:23:12 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-12-06 11:09:29 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-12-05 17:23:12 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-06 11:09:29 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-05 17:23:12 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-12-06 11:09:29 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-12-05 21:55:49 14,680 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1987592378-4236141434-2783724046-500_UserData.bin
+ 2008-12-06 09:28:56 15,120 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1987592378-4236141434-2783724046-500_UserData.bin
- 2008-12-05 21:55:48 46,388 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-12-06 09:28:54 47,034 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-12-05 21:55:45 45,394 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-12-06 09:28:36 45,394 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 1460560]
"Orb"="c:\program files\Winamp Remote\bin\OrbTray.exe" [2008-01-07 495616]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2008-05-06 202088]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-19 1840128]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2007-10-10 36352]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"dmvbn.exe"="c:\windows\system32\dmvbn.exe" [BU]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-06 1261336]
"SoundMan"="SOUNDMAN.EXE" [2006-06-21 c:\windows\SOUNDMAN.EXE]

c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-04-13 415072]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JPGL"= jpgl.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{0939B334-6604-436D-BD88-B91345352762}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{70DA771C-2645-4E05-9BA2-96E892D7F1F9}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{2A8F0DBF-312C-478C-8B1D-6B4F5DE5D3E0}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{AE2ACE80-4437-41A0-BFED-D71D4D971AAA}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{5FB4796E-2666-4208-89AA-731E7BE31A8A}"= UDP:c:\program files\Morpheus\Morpheus.exe:Morpheus
"{D4F341B0-F6BF-4104-9145-DEA71C7C6FCB}"= TCP:c:\program files\Morpheus\Morpheus.exe:Morpheus
"{2264A4F0-3F68-4F85-8B6B-1816417396A6}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{A6A184EB-2BEA-49FE-98DF-E2E26BAD3CA7}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{C51E980D-B4CC-4683-81B8-2F6D842E1936}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{903795FB-7606-440C-B13A-60392DA3567A}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{E5A07C3E-00D1-4483-9380-9ED7883BD180}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{FD0ECC6F-13B2-4763-A809-E566236173D0}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{A6C313E1-8BF0-49A9-94A1-62E9B83A75E4}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{EE3ADE81-576F-402F-AFB0-D1D8C11CFDFC}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{A9EA6B05-BE7A-4563-B2BF-DA626BA61948}"= Disabled:UDP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{45D08833-AD4E-4301-A688-9CEE50DFBC8C}"= TCP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{83A49EB7-FF00-483F-ABB0-52CA1906F16F}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{9979CE05-4877-4BA0-A2AF-416DDDC78AF8}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{49FE6F6C-E5A9-42FA-9F52-6742ECF37480}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{06118995-E3AF-437E-8449-0DFB0F7985B3}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{EA527255-62C0-41B2-8D8D-D1E87006252E}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{9DA43E3C-2AEE-45E0-8183-B7A117142EBF}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{6BE94E6F-43F9-482F-B8BD-A5917ABA8754}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{196D7C17-9BCF-4CAC-A61D-0AB7CE9ADD9B}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{63B99BE4-23DC-4B48-92BD-83195E3F9B5A}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{DA504238-A139-442F-800A-FC5067D5C443}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{5D414F98-03B1-4D3D-ADF3-70C8F4A1361D}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe
"{03C025E2-76CE-4C8F-8E1E-974AB5850A11}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe
"{4A7B707A-AF01-40BD-B560-F65D92A4A757}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{0333945D-E73C-493A-BF4D-37F093AB3AED}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{033F029C-F17A-427B-B1F3-4018CEE2754D}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{695AAC48-EA31-4428-AA59-1596D4B5DC1C}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{0D95154D-1A63-4024-B286-A98B0BB0E458}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{22A958A5-E690-4EC4-8DF9-3A34E37E627C}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{6C7E8569-CFBF-49E9-BE90-A2C1E3AEAA92}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe:hpqnrs08.exe
"{4A33F8B6-6AA8-4128-A96E-9C97840A76B8}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe:hpqnrs08.exe
"TCP Query User{9B51EE0F-7A6F-4AB7-AA2D-4BFAA889DE82}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{E4DCD183-ECCD-4589-A818-7FA60C95BD98}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{7BB16348-9937-426C-8F1A-44F3F9ACA1EE}c:\\program files\\msn messenger\\livecall.exe"= UDP:c:\program files\msn messenger\livecall.exe:Windows Live Call
"UDP Query User{30B05AD6-B939-4637-8005-616AA593E28E}c:\\program files\\msn messenger\\livecall.exe"= TCP:c:\program files\msn messenger\livecall.exe:Windows Live Call
"{5ECC5437-93ED-43AC-BB2C-BE58BE15C86D}"= UDP:c:\program files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"{24126429-663B-4AA6-8000-31149FC7E30D}"= TCP:c:\program files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"{4BD0C102-B510-4D60-A3C1-CDDED8F4E5F4}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{8239832F-9896-458D-BCD2-41B09C6C30A6}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{9C6C102D-874C-43B4-9C53-F6E96DC987DA}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{05CDA2E8-1161-48A5-84B6-4BB253B89835}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9C2A8628-7948-47C0-91CF-3233A019C2CB}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0552DFAD-C487-48EE-9FD6-45961D7707D0}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{11D11BC1-3568-4769-A74E-D6C9CA89F423}"= Disabled:TCP:c:\program files\Skype\Phone\Skype.exe:Skype
"{084CE4F5-BC43-4259-8EAF-8EAEC0BCCDAC}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-06 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-06 231704]
S0 OemBiosDevice;Royalty OEM Bios Extension;c:\windows\system32\drivers\royal.sys [2007-06-30 240128]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2007-12-13 600912]
S3 GoogleDesktopManager-091907-194040;Google Desktop Manager 5.1.709.19590;"c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-06-30 1840128]
S3 K7216VM11;KONICA MINOLTA 7216;c:\windows\system32\Drivers\K7216.sys [2001-08-16 13824]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-03-16 356920]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a1180cc-2df9-11dd-ba55-00184d7bb29e}]
\shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder

2008-12-06 c:\windows\Tasks\RegistrySmart Scheduled Scan.job
- c:\program files\RegistrySmart\RegistrySmart.exe []

2008-12-06 c:\windows\Tasks\RegistrySmart Scheduled Scan.job
- c:\program files\RegistrySmart []
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Winamp; Toolbar Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: {E7D7852C-2DF1-487C-8247-E898E65C7B27} = 208.67.220.220,208.67.222.222
FireFox -: Profile - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\1wy5qvnr.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-US.google.mozilla.com/firefox&client;=firefox-a&rls;=com.google:en-US:official
FF -: plugin - c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmidas.dll
FF -: plugin - c:\program files\Picasa2\npPicasa2.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-06 18:27:36
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-12-06 18:29:29
ComboFix-quarantined-files.txt 2008-12-06 17:29:02
ComboFix2.txt 2008-12-06 03:12:05
ComboFix3.txt 2008-12-06 01:24:13
ComboFix4.txt 2008-12-05 12:53:04

Pre-Run: 73,651,388,416 bytes free
Post-Run: 73,631,162,368 bytes free

259 — E O F — 2008-07-18 06:30:59


And the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:41:47 PM, on 12/6/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Winamp Remote\bin\orbtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Winamp Remote\bin\Orb.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [dmvbn.exe] C:\Windows\system32\dmvbn.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Winamp; Toolbar Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\pnrpnsp.dll' missing
O13 - Gopher Prefix:
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{E7D7852C-2DF1-487C-8247-E898E65C7B27}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Desktop Manager 5.1.709.19590 (GoogleDesktopManager-091907-194040) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 9501 bytes


Liz
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\dmvbn.exe

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dmvbn.exe"=-

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Thank you for your elaborate explanation. Did what you have instructed me to do.
Here is the combofix log:
ComboFix 08-12-05.06 - Administrator 2008-12-06 19:09:25.5 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.1.1033.18.1401 [GMT 1:00]
Running from: c:\users\[removed]\ComboFix.exe
Command switches used :: c:\users\Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\windows\system32\dmvbn.exe
.

((((((((((((((((((((((((( Files Created from 2008-11-06 to 2008-12-06 )))))))))))))))))))))))))))))))
.

2008-12-06 17:08 . 2008-12-06 17:08 d——– c:\users\All Users\Malwarebytes
2008-12-06 17:08 . 2008-12-06 17:08 d——– c:\users\Administrator\AppData\Roaming\Malwarebytes
2008-12-06 17:08 . 2008-12-06 17:08 d——– c:\programdata\Malwarebytes
2008-12-06 17:08 . 2008-12-06 17:21 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-06 17:08 . 2008-12-03 19:52 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2008-12-06 17:08 . 2008-12-03 19:52 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2008-12-06 17:07 . 2008-12-06 17:07 2,539,400 –a—— c:\users\Public\mbam-setup.exe
2008-12-06 10:57 . 2008-12-06 10:57 d——– c:\program files\Trend Micro
2008-12-06 10:56 . 2008-12-06 10:56 812,344 –a—— c:\users\Public\HJTInstall.exe
2008-12-06 10:44 . 2008-12-06 10:44 d——– c:\program files\ERUNT
2008-12-06 03:56 . 2008-12-06 03:56 d——– C:\VundoFix Backups
2008-12-06 03:35 . 2008-12-06 03:35 199,680 –a—— c:\users\Public\DirLook.exe
2008-12-06 00:48 . 2008-12-06 12:54 d–h—– C:\$AVG8.VAULT$
2008-12-06 00:12 . 2008-12-06 12:39 d——– c:\windows\System32\drivers\Avg
2008-12-06 00:12 . 2008-12-06 00:12 97,928 –a—— c:\windows\System32\drivers\avgldx86.sys
2008-12-06 00:12 . 2008-12-06 00:12 10,520 –a—— c:\windows\System32\avgrsstx.dll
2008-12-06 00:11 . 2008-12-06 00:11 d——– c:\users\All Users\avg8
2008-12-06 00:11 . 2008-12-06 00:11 d——– c:\programdata\avg8
2008-12-06 00:11 . 2008-12-06 00:11 d——– c:\program files\AVG
2008-12-05 23:38 . 2008-12-05 23:38 488,144 –a—— c:\users\Public\HJTsetup.exe
2008-12-05 17:54 . 2008-12-05 17:54 d——– c:\users\All Users\NortonInstaller
2008-12-05 17:54 . 2008-12-05 17:54 d——– c:\programdata\NortonInstaller
2008-12-05 13:33 . 2008-12-06 19:01 3,060,445 -ra—— c:\users\Public\ComboFix.exe
2008-12-05 13:30 . 2008-12-05 13:30 50,688 –a—— c:\users\Public\ATF-Cleaner.exe
2008-12-05 12:25 . 2008-12-05 12:25 119,808 –a—— c:\users\Public\VundoFix.exe
2008-11-25 00:33 . 2008-11-25 00:36 34,134,544 –a—— c:\users\Public\1447_-_Jam_Sessions_(E).zip
2008-11-25 00:25 . 2008-11-25 00:30 45,476,984 –a—— c:\users\Public\2536_-_Moetan_DS_(J).zip
2008-11-25 00:14 . 2008-11-25 00:17 33,228,156 –a—— c:\users\Public\2181_-_Rosario_to_Vampire_-_Tanabata_no_Miss_Youkai_Gakuen_(J).zip
2008-11-18 21:44 . 2008-11-18 21:44 d——– c:\users\Public\moonshell10_dpgtools
2008-11-18 21:33 . 2008-11-18 21:33 d——– c:\users\Public\Moonshell Tools
2008-11-18 21:24 . 2008-06-17 15:50 d——– c:\users\Public\Moonshell
2008-11-18 21:23 . 2008-11-18 22:08 d——– c:\users\Public\New Folder (2)
2008-11-17 15:23 . 2008-11-17 15:23 1,809,944 –a—— c:\windows\System32\wuaueng.dll
2008-11-17 15:23 . 2008-11-17 15:23 1,524,736 –a—— c:\windows\System32\wucltux.dll
2008-11-17 15:23 . 2008-11-17 15:23 561,688 –a—— c:\windows\System32\wuapi.dll
2008-11-17 15:23 . 2008-11-17 15:23 83,456 –a—— c:\windows\System32\wudriver.dll
2008-11-17 15:23 . 2008-11-17 15:23 51,224 –a—— c:\windows\System32\wuauclt.exe
2008-11-17 15:23 . 2008-11-17 15:23 43,544 –a—— c:\windows\System32\wups2.dll
2008-11-17 15:23 . 2008-11-17 15:23 34,328 –a—— c:\windows\System32\wups.dll
2008-11-17 15:22 . 2008-11-17 15:22 162,064 –a—— c:\windows\System32\wuwebv.dll
2008-11-17 15:22 . 2008-11-17 15:22 31,232 –a—— c:\windows\System32\wuapp.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-06 17:38 ——— d—–w c:\program files\Winamp Remote
2008-12-06 17:21 ——— d—a-w c:\programdata\TEMP
2008-12-06 11:09 ——— d—–w c:\programdata\Google Updater
2008-12-06 03:10 ——— d—–w c:\program files\Spyware Doctor
2008-12-06 01:03 ——— d—–w c:\program files\Securitoo
2008-12-06 01:03 ——— d—–w c:\program files\Microsoft Silverlight
2008-12-05 23:07 ——— d—–w c:\programdata\F-Secure
2008-12-04 15:13 ——— d—–w c:\program files\Common Files\Caere
2008-12-04 13:45 ——— d—–w c:\programdata\Spybot - Search & Destroy
2008-11-17 03:35 ——— d—–w c:\users\Administrator\AppData\Roaming\Skype
2008-11-17 03:26 ——— d—–w c:\users\Administrator\AppData\Roaming\skypePM
2008-11-03 18:28 ——— d—–w c:\programdata\Microsoft Help
2008-11-03 18:06 ——— d—–w c:\program files\Microsoft Works
2008-11-03 18:05 ——— d—–w c:\program files\MSBuild
2008-11-03 17:59 ——— d—–w c:\program files\Microsoft.NET
2008-11-03 17:48 ——— d—–w c:\program files\Microsoft Visual Studio 8
2008-10-30 23:12 81,288 —-a-w c:\windows\system32\drivers\iksyssec.sys
2008-10-30 23:12 66,952 —-a-w c:\windows\system32\drivers\iksysflt.sys
2008-10-30 23:12 40,840 —-a-w c:\windows\system32\drivers\ikfilesec.sys
2008-10-26 09:22 ——— d—–w c:\program files\Wallpapers from MSN
2008-10-25 11:23 ——— d—–w c:\program files\Common Files\SWF Studio
2008-10-21 08:51 ——— d—–w c:\users\Guest\AppData\Roaming\Yahoo!
2008-10-16 09:53 ——— d—–w c:\programdata\Apple
2008-10-16 09:53 ——— d—–w c:\program files\Apple Software Update
2008-10-16 08:10 ——— d—–w c:\users\Administrator\AppData\Roaming\Yahoo!
2008-10-15 19:57 262,144 —-a-w C:\ntuser.dat
2008-10-12 21:57 ——— d—–w c:\program files\Common Files\xing shared
2008-10-12 21:56 ——— d—–w c:\program files\Common Files\Real
2008-10-01 11:27 32 —-a-w c:\users\All Users\ezsid.dat
2008-10-01 11:27 32 —-a-w c:\programdata\ezsid.dat
2008-07-18 07:48 174 –sha-w c:\program files\desktop.ini
2008-05-19 17:54 262,144 —-a-w c:\programdata\ntuser.dat
2007-08-12 13:20 203 —-a-w c:\program files\CD Drive - Shortcut.lnk
2007-08-12 13:20 203 —-a-w c:\program files\CD Drive - Shortcut (3).lnk
2007-08-12 13:20 203 —-a-w c:\program files\CD Drive - Shortcut (2).lnk
.

((((((((((((((((((((((((((((( snapshot_2008-12-06_ 2.22.53.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 11:02:28 163,328 —-a-w c:\windows\ERDNT\12-6-2008\ERDNT.EXE
+ 2008-12-06 09:45:01 3,670,016 —-a-w c:\windows\ERDNT\12-6-2008\Users\00000001\ntuser.dat
+ 2008-12-06 09:45:01 3,067,904 —-a-w c:\windows\ERDNT\12-6-2008\Users\00000002\UsrClass.dat
+ 2005-10-20 11:02:28 163,328 —-a-w c:\windows\ERDNT\AutoBackup\12-6-2008\ERDNT.EXE
+ 2008-12-06 17:38:36 3,670,016 —-a-w c:\windows\ERDNT\AutoBackup\12-6-2008\Users\00000001\ntuser.dat
+ 2008-12-06 17:38:36 3,084,288 —-a-w c:\windows\ERDNT\AutoBackup\12-6-2008\Users\00000002\UsrClass.dat
+ 2008-12-06 17:37:47 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-12-06 17:37:47 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-12-06 01:14:05 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-12-06 17:39:35 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-12-06 17:39:35 262,144 —ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-12-06 01:14:00 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-12-06 17:39:41 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2008-12-05 17:23:12 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-12-06 11:09:29 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-12-05 17:23:12 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-06 11:09:29 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-05 17:23:12 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-12-06 11:09:29 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-12-05 12:39:06 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2008-12-06 18:08:56 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2008-12-05 21:55:49 14,680 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1987592378-4236141434-2783724046-500_UserData.bin
+ 2008-12-06 17:40:04 15,160 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1987592378-4236141434-2783724046-500_UserData.bin
- 2008-12-05 21:55:48 46,388 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-12-06 17:40:04 47,154 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-12-05 21:55:45 45,394 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-12-06 17:40:02 45,732 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 1460560]
"Orb"="c:\program files\Winamp Remote\bin\OrbTray.exe" [2008-01-07 495616]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2008-05-06 202088]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-19 1840128]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2007-10-10 36352]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-06 1261336]
"SoundMan"="SOUNDMAN.EXE" [2006-06-21 c:\windows\SOUNDMAN.EXE]

c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-04-13 415072]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JPGL"= jpgl.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{0939B334-6604-436D-BD88-B91345352762}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{70DA771C-2645-4E05-9BA2-96E892D7F1F9}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{2A8F0DBF-312C-478C-8B1D-6B4F5DE5D3E0}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{AE2ACE80-4437-41A0-BFED-D71D4D971AAA}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{5FB4796E-2666-4208-89AA-731E7BE31A8A}"= UDP:c:\program files\Morpheus\Morpheus.exe:Morpheus
"{D4F341B0-F6BF-4104-9145-DEA71C7C6FCB}"= TCP:c:\program files\Morpheus\Morpheus.exe:Morpheus
"{2264A4F0-3F68-4F85-8B6B-1816417396A6}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{A6A184EB-2BEA-49FE-98DF-E2E26BAD3CA7}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{C51E980D-B4CC-4683-81B8-2F6D842E1936}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{903795FB-7606-440C-B13A-60392DA3567A}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{E5A07C3E-00D1-4483-9380-9ED7883BD180}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{FD0ECC6F-13B2-4763-A809-E566236173D0}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{A6C313E1-8BF0-49A9-94A1-62E9B83A75E4}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{EE3ADE81-576F-402F-AFB0-D1D8C11CFDFC}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{A9EA6B05-BE7A-4563-B2BF-DA626BA61948}"= Disabled:UDP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{45D08833-AD4E-4301-A688-9CEE50DFBC8C}"= TCP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{83A49EB7-FF00-483F-ABB0-52CA1906F16F}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{9979CE05-4877-4BA0-A2AF-416DDDC78AF8}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{49FE6F6C-E5A9-42FA-9F52-6742ECF37480}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{06118995-E3AF-437E-8449-0DFB0F7985B3}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{EA527255-62C0-41B2-8D8D-D1E87006252E}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{9DA43E3C-2AEE-45E0-8183-B7A117142EBF}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{6BE94E6F-43F9-482F-B8BD-A5917ABA8754}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{196D7C17-9BCF-4CAC-A61D-0AB7CE9ADD9B}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{63B99BE4-23DC-4B48-92BD-83195E3F9B5A}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{DA504238-A139-442F-800A-FC5067D5C443}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{5D414F98-03B1-4D3D-ADF3-70C8F4A1361D}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe
"{03C025E2-76CE-4C8F-8E1E-974AB5850A11}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe
"{4A7B707A-AF01-40BD-B560-F65D92A4A757}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{0333945D-E73C-493A-BF4D-37F093AB3AED}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{033F029C-F17A-427B-B1F3-4018CEE2754D}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{695AAC48-EA31-4428-AA59-1596D4B5DC1C}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{0D95154D-1A63-4024-B286-A98B0BB0E458}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{22A958A5-E690-4EC4-8DF9-3A34E37E627C}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{6C7E8569-CFBF-49E9-BE90-A2C1E3AEAA92}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe:hpqnrs08.exe
"{4A33F8B6-6AA8-4128-A96E-9C97840A76B8}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe:hpqnrs08.exe
"TCP Query User{9B51EE0F-7A6F-4AB7-AA2D-4BFAA889DE82}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{E4DCD183-ECCD-4589-A818-7FA60C95BD98}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{7BB16348-9937-426C-8F1A-44F3F9ACA1EE}c:\\program files\\msn messenger\\livecall.exe"= UDP:c:\program files\msn messenger\livecall.exe:Windows Live Call
"UDP Query User{30B05AD6-B939-4637-8005-616AA593E28E}c:\\program files\\msn messenger\\livecall.exe"= TCP:c:\program files\msn messenger\livecall.exe:Windows Live Call
"{5ECC5437-93ED-43AC-BB2C-BE58BE15C86D}"= UDP:c:\program files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"{24126429-663B-4AA6-8000-31149FC7E30D}"= TCP:c:\program files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"{4BD0C102-B510-4D60-A3C1-CDDED8F4E5F4}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{8239832F-9896-458D-BCD2-41B09C6C30A6}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{9C6C102D-874C-43B4-9C53-F6E96DC987DA}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{05CDA2E8-1161-48A5-84B6-4BB253B89835}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9C2A8628-7948-47C0-91CF-3233A019C2CB}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0552DFAD-C487-48EE-9FD6-45961D7707D0}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{11D11BC1-3568-4769-A74E-D6C9CA89F423}"= Disabled:TCP:c:\program files\Skype\Phone\Skype.exe:Skype
"{084CE4F5-BC43-4259-8EAF-8EAEC0BCCDAC}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-06 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-06 231704]
S0 OemBiosDevice;Royalty OEM Bios Extension;c:\windows\system32\drivers\royal.sys [2007-06-30 240128]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2007-12-13 600912]
S3 GoogleDesktopManager-091907-194040;Google Desktop Manager 5.1.709.19590;"c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-06-30 1840128]
S3 K7216VM11;KONICA MINOLTA 7216;c:\windows\system32\Drivers\K7216.sys [2001-08-16 13824]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-03-16 356920]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a1180cc-2df9-11dd-ba55-00184d7bb29e}]
\shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder

2008-12-06 c:\windows\Tasks\RegistrySmart Scheduled Scan.job
- c:\program files\RegistrySmart\RegistrySmart.exe []

2008-12-06 c:\windows\Tasks\RegistrySmart Scheduled Scan.job
- c:\program files\RegistrySmart []
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Winamp; Toolbar Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: {E7D7852C-2DF1-487C-8247-E898E65C7B27} = 208.67.220.220,208.67.222.222
FireFox -: Profile - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\1wy5qvnr.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-US.google.mozilla.com/firefox&client;=firefox-a&rls;=com.google:en-US:official
FF -: plugin - c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmidas.dll
FF -: plugin - c:\program files\Picasa2\npPicasa2.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-06 19:12:22
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-12-06 19:14:20
ComboFix-quarantined-files.txt 2008-12-06 18:13:53
ComboFix2.txt 2008-12-06 17:29:32
ComboFix3.txt 2008-12-06 03:12:05
ComboFix4.txt 2008-12-06 01:24:13
ComboFix5.txt 2008-12-06 18:01:48

Pre-Run: 73,010,991,104 bytes free
Post-Run: 72,990,752,768 bytes free

267 — E O F — 2008-07-18 06:30:59


And the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:25:18 PM, on 12/6/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Winamp Remote\bin\Orb.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Winamp; Toolbar Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\pnrpnsp.dll' missing
O13 - Gopher Prefix:
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{E7D7852C-2DF1-487C-8247-E898E65C7B27}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Desktop Manager 5.1.709.19590 (GoogleDesktopManager-091907-194040) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 9407 bytes

The computer kept on refreshing the desktop.
Thanks again

Liz
Do this, reboot and let me know how it's running.

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]
These aren't bad but aren't needed at start up.

1. All tools MUST be run from the executable. (.exe)
With Admin Rights (Right click, choose "Run as Administrator")


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

Close ALL windows and browsers except HijackThis and click "Fix checked"


Reboot and please describe how your computer behaves at the moment.
Good job :thumbup:

Here's my usual all clean post

Log looks good :D


  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.

[*]Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week

(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


[*]Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.

Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.


[*]Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.

This will ensure your computer has always the latest security updates available installed on your computer.
If there are new updates to install, install them immediately, reboot your computer, and revisit the site
until there are no more critical updates.


[*]MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.


[*] Winpatrol



[*]Update all these programs regularly - Make sure you update all the programs I have listed regularly.

Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Also: "How to prevent malware"

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI