This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] major redirects and self installing spyware programs.

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My PC is really having problems, it redirects everything I type into search bar wont let me look up spy ware or mal ware info
a program spyware gaurd 2008 auto installs everytime I uninstall it, and does self scans out of nowhere. Im on a friends PC right now.
and cant seem to do anything i want it to do.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:20:32 PM, on 12/25/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\WINDOWS\vVX6000.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\winscenter.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\TEMP\winlogin.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twext.exe,
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [WinAntiSpyware 2006] "c:\program files\winantispyware 2006 scanner\was6.exe" /min
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Smeyamodetako] rundll32.exe "C:\WINDOWS\Dpoxutoqihoj.dll",e
O4 - HKLM\..\Run: [Gdoqomu] rundll32.exe "C:\WINDOWS\anonicimay.dll",e
O4 - HKLM\..\Run: [PromoReg] C:\WINDOWS\TEMP\TMPD.tmp
O4 - HKLM\..\Run: [xsjfn83jkemfofght] C:\WINDOWS\TEMP\winlogin.exe
O4 - HKLM\..\Run: [spywareguard] C:\Program Files\Spyware Guard 2008\spywareguard.exe
O4 - HKLM\..\RunOnce: [tdss] C:\WINDOWS\TEMP\8998656.exe
O4 - HKLM\..\RunOnce: [ ] C:\WINDOWS\System32\cmd.exe /C del /Q C:\WINDOWS\system32\rdssrv.exe C:\WINDOWS\system32\rdshost.dll C:\WINDOWS\system32\hdfkt.dll
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Universal Installer] "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe" /fromrun /starthidden
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [xsjfn83jkemfofght] C:\WINDOWS\TEMP\winlogin.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\DANNI-~1\LOCALS~1\Temp\csrssc.exe
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [MS AntiSpyware 2009] "C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [xsjfn83jkemfofght] C:\WINDOWS\TEMP\winlogin.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Jnskdfmf9eldfd] C:\WINDOWS\TEMP\csrssc.exe (User 'Default user')
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) - http://connect.comcast.com/dl/Comcast%20Ac…%20Controls.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E93E9DF0-3E59-4331-A269-F1E077C66F00} (GameTap Web Plugin) - http://cnn-5.vo.llnwd.net/c1/static/client…er/gtplugin.cab
O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} (ChessControl Class) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab
O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll
O21 - SSODL: ieModule - {73049CBC-0219-440D-B3C7-081B983D92F5} - C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
O21 - SSODL: InternetConnection - {17E60241-CB03-48B2-AA68-D2AF1AB5875F} - C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\nnswpwsegr.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
–
End of file - 10858 bytes

This post has been edited by Dalmore: Dec 25 2008, 08:56 PM
Hi danielle69

Welcome to the What the tech Forums
My name is mschroe919 and I am going to read your log.
I would like to help you So if you would….
Please be patient and I will be back as soon as possible.

Please while I am gone do these steps:

Show hidden files, Here is how:

Windows XP

* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

NEXT:

Please download ATF Cleaner by Atribune.

Download it


HERE:

This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

NEXT:

Malwarebytes' Anti-Malware

HERE

* Double-click mbam-setup.exe and follow the prompts to install the program.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform FULL SCAN, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
post a new scanner[HJT] log and the Malwarebytes' Anti-Malware log

Be sure not to delete anything intill said ok to. also don't run any other cleanup programs till we
get done it may goof ours up.
Also if you have any questions feel fre to ask first.

When you post another rhjt log and the Malwarebytes' Anti-Malware log , let me know how your PC is behavuing

I will be waiting to see new logs

Please stay with us till you pc is clean, cause what may soon look like your pc is doing fine,
a hidden virus shows up.

mschroe919
I have malware bytes downloaded and installed im sure but it wont let me access this program is there anyway around this?

also I cant download atf cleaner any suggestions?

this malware seems to bew blocking alot fo of stuff.

well here is a new Hijackthis Log. it seems to be getting worse.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:08:09 PM, on 12/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:..WINDOWS..system32..csrss.exe
C:..WINDOWS..system32..winlogon.exe
C:..WINDOWS..system32..services.exe
C:..WINDOWS..system32..lsass.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..System32..svchost.exe
C:..WINDOWS..System32..svchost.exe
C:..WINDOWS..System32..svchost.exe
C:..WINDOWS..system32..spoolsv.exe
C:..WINDOWS..Explorer.EXE
C:..Program Files..Common Files..ArcSoft..Connection Service..Bin..ACService.exe
C:..WINDOWS..System32..CTsvcCDA.exe
C:..Program Files..Java..jre6..bin..jqs.exe
C:..Program Files..Creative..SB Live! 24-bit..Surround Mixer..CTSysVol.exe
C:..Program Files..Logitech..Video..LogiTray.exe
C:..Program Files..Lexmark 2300 Series..lxcgmon.exe
C:..Program Files..Microsoft LifeCam..MSCamS32.exe
C:..Program Files..Comcast..Desktop Doctor..bin..sprtcmd.exe
C:..WINDOWS..vVX6000.exe
C:..Program Files..Adobe..Reader 8.0..Reader..Reader_sl.exe
C:..Program Files..Java..jre6..bin..jusched.exe
C:..WINDOWS..system32..RUNDLL32.EXE
C:..Program Files..Common Files..ArcSoft..Connection Service..Bin..ACDaemon.exe
C:..WINDOWS..system32..rundll32.exe
C:..WINDOWS..TEMP..winlogin.exe
C:..Program Files..Spyware Guard 2008..spywareguard.exe
C:..Program Files..Logitech..Video..FxSvr2.exe
C:..WINDOWS..system32..ctfmon.exe
C:..WINDOWS..TEMP..winlogin.exe
C:..WINDOWS..system32..winscenter.exe
C:..Program Files..Kodak..Kodak EasyShare software..bin..EasyShare.exe
C:..WINDOWS..system32..nvsvc32.exe
C:..WINDOWS..system32..slserv.exe
C:..Program Files..Comcast..Desktop Doctor..bin..sprtsvc.exe
C:..Program Files..Yahoo!..Messenger..ymsgr_tray.exe
C:..WINDOWS..System32..svchost.exe
C:..WINDOWS..system32..lxcgcoms.exe
C:..WINDOWS..System32..alg.exe
C:..Program Files..Internet Explorer..IEXPLORE.EXE
C:..DOCUME~1..DANNI-~1..LOCALS~1..Temp..csrssc.exe
C:..WINDOWS..system32..wuauclt.exe
C:..Program Files..Trend Micro..HijackThis..HijackThis.exe
C:..WINDOWS..System32..wbem..wmiprvse.exe

R0 - HKCU..Software..Microsoft..Internet Explorer..Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Search Bar =

http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU..Software..Microsoft..Internet Explorer..Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU..Software..Microsoft..Windows..CurrentVersion..Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:..WINDOWS..system32..userinit.exe,C:..WINDOWS..system32..twext.exe,
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:..Program

Files..Java..jre6..bin..ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:..Program

Files..Java..jre6..bin..jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:..Program

Files..Java..jre6..lib..deploy..jqs..ie..jqs_plugin.dll
O4 - HKLM……Run: [CTSysVol] C:..Program Files..Creative..SB Live! 24-bit..Surround Mixer..CTSysVol.exe /r
O4 - HKLM……Run: [UpdReg] C:..WINDOWS..UpdReg.EXE
O4 - HKLM……Run: [LogitechVideoRepair] C:..Program Files..Logitech..Video..ISStart.exe
O4 - HKLM……Run: [LogitechVideoTray] C:..Program Files..Logitech..Video..LogiTray.exe
O4 - HKLM……Run: [LXCGCATS] rundll32 C:..WINDOWS..System32..spool..DRIVERS..W32X86..3..LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM……Run: [lxcgmon.exe] "C:..Program Files..Lexmark 2300 Series..lxcgmon.exe"
O4 - HKLM……Run: [ddoctorv2] "C:..Program Files..Comcast..Desktop Doctor..bin..sprtcmd.exe" /P ddoctorv2
O4 - HKLM……Run: [VX6000] C:..WINDOWS..vVX6000.exe
O4 - HKLM……Run: [LifeCam] "C:..Program Files..Microsoft LifeCam..LifeExp.exe"
O4 - HKLM……Run: [Adobe Reader Speed Launcher] "C:..Program Files..Adobe..Reader 8.0..Reader..Reader_sl.exe"
O4 - HKLM……Run: [SunJavaUpdateSched] "C:..Program Files..Java..jre6..bin..jusched.exe"
O4 - HKLM……Run: [NvCplDaemon] RUNDLL32.EXE C:..WINDOWS..system32..NvCpl.dll,NvStartup
O4 - HKLM……Run: [nwiz] nwiz.exe /install
O4 - HKLM……Run: [NvMediaCenter] RUNDLL32.EXE C:..WINDOWS..system32..NvMcTray.dll,NvTaskbarInit
O4 - HKLM……Run: [QuickTime Task] "C:..Program Files..QuickTime..qttask.exe" -atboottime
O4 - HKLM……Run: [ArcSoft Connection Service] C:..Program Files..Common Files..ArcSoft..Connection

Service..Bin..ACDaemon.exe
O4 - HKLM……Run: [Smeyamodetako] rundll32.exe "C:..WINDOWS..Dpoxutoqihoj.dll",e
O4 - HKLM……Run: [Gdoqomu] rundll32.exe "C:..WINDOWS..anonicimay.dll",e
O4 - HKLM……Run: [PromoReg] C:..WINDOWS..TEMP..TMPD.tmp
O4 - HKLM……Run: [xsjfn83jkemfofght] C:..WINDOWS..TEMP..winlogin.exe
O4 - HKLM……Run: [spywareguard] C:..Program Files..Spyware Guard 2008..spywareguard.exe
O4 - HKLM……RunOnce: [tdss] C:..WINDOWS..TEMP..8998656.exe
O4 - HKLM……RunOnce: [ ] C:..WINDOWS..System32..cmd.exe /C del /Q C:..WINDOWS..system32..rdssrv.exe

C:..WINDOWS..system32..rdshost.dll C:..WINDOWS..system32..hdfkt.dll
O4 - HKCU……Run: [LogitechSoftwareUpdate] "C:..Program Files..Logitech..Video..ManifestEngine.exe" boot
O4 - HKCU……Run: [Yahoo! Pager] "C:..Program Files..Yahoo!..Messenger..YahooMessenger.exe" -quiet
O4 - HKCU……Run: [ctfmon.exe] C:..WINDOWS..system32..ctfmon.exe
O4 - HKCU……Run: [xsjfn83jkemfofght] C:..WINDOWS..TEMP..winlogin.exe
O4 - HKCU……Run: [Jnskdfmf9eldfd] C:..DOCUME~1..DANNI-~1..LOCALS~1..Temp..csrssc.exe
O4 - HKUS..S-1-5-18……Run: [MySpaceIM] C:..Program Files..MySpace..IM..MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS..S-1-5-18……Run: [xsjfn83jkemfofght] C:..WINDOWS..TEMP..winlogin.exe (User 'SYSTEM')
O4 - HKUS..S-1-5-18……Run: [Jnskdfmf9eldfd] C:..WINDOWS..TEMP..csrssc.exe (User 'SYSTEM')
O4 - HKUS…DEFAULT……Run: [MySpaceIM] C:..Program Files..MySpace..IM..MySpaceIM.exe (User 'Default user')
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:..Program Files..Kodak..Kodak EasyShare

software..bin..EasyShare.exe
O7 - HKCU..Software..Microsoft..Windows..CurrentVersion..Policies..System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:..Program Files..Java..jre6..bin..jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:..Program

Files..Java..jre6..bin..jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:..WINDOWS..Network Diagnostic..xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:..WINDOWS..Network

Diagnostic..xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:..Program Files..Messenger..msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:..Program

Files..Messenger..msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -

http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) -

http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:..Program

Files..Yahoo!..Common..Yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) -

http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) -

http://connect.comcast.com/dl/Comcast%20Ac…%20Controls.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -

http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) -

http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) -

http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -

http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) -

http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E93E9DF0-3E59-4331-A269-F1E077C66F00} (GameTap Web Plugin) -

http://cnn-5.vo.llnwd.net/c1/static/client…er/gtplugin.cab
O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} (ChessControl Class) -

http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab
O20 - Winlogon Notify: crypt - C:..WINDOWS..SYSTEM32..crypts.dll
O21 - SSODL: ieModule - {73049CBC-0219-440D-B3C7-081B983D92F5} - C:..Documents and Settings..All Users..Application

Data..Microsoft..Internet Explorer..DLLs..ieModule.dll
O21 - SSODL: InternetConnection - {17E60241-CB03-48B2-AA68-D2AF1AB5875F} - C:..Documents and Settings..All

Users..Application Data..Microsoft..Internet Explorer..DLLs..nnswpwsegr.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:..Program Files..Common Files..ArcSoft..Connection

Service..Bin..ACService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:..WINDOWS..System32..CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:..Program Files..Google..Common..Google

Updater..GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:..Program

Files..Java..jre6..bin..jqs.exe
O23 - Service: lxcg_device - - C:..WINDOWS..system32..lxcgcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:..WINDOWS..system32..nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:..WINDOWS..SYSTEM32..slserv.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:..Program

Files..Comcast..Desktop Doctor..bin..sprtsvc.exe

–
End of file - 10445 bytes
almost forgot under my computer / tools there is no folder options… only map network drive…. disconnect network drive…. and synchronize not sure if this means anything or not just figured i'd let u know
Hi Try opening them in safe mode: Windows XP Home Edition * Click Start. * Select Turn off computer. * Select Restart. * During restart, hold down the F8 key on your keyboard until the Windows Startup menu appears. * If your PC starts beeping then release the key for a few seconds before holding it down again. * Select Safe Mode from the Startup menu, and press the Enter button on your keyboard. * Windows should start in Safe Mode. If Windows doesn't restart in Safe Mode then please try again. Let me know if that works. mschr0e919
ok still no folder options under safe or non safe mode….still no malwarebytes program working says it is in task mgr but cant see nothing.

Ok I have hijack log for safe mode and non safe mode not sure if any different.. also have a tsk mgr running list for safe mode and non safe mode for you. and a start up list for you to read. its all i have to show you hope something you see can help me.


ok here is the tsk mgr runinng list……………………..

while under safe mode………..also when I try to run malwarebytes this is code that shows… mbam.exe 00 2,216k
but nothing shows up as its running just hour glass for a sec or two..

name CPU mem usage
notepad.exe 02 6,000k
taskmgr.exe 02 4.3k
explorer.exe 00 21.3k
svhost.exe 00 9.4k
svhost.exe 00 4.7k
svhost.exe 00 15,000k
lsass.exe 00 980k
service.exe 00 5,380k
winlogin.exe 00 6,380k
csrss.exe 00 3,212k
system 00 692k
system idle process SYSTEM 97 16k



while not under safe mode………______________________________________


Easyshare.exe user me 00 7,500
crssc.exe / / 00 6,584
ctfmon.exe 00 7,024
winscenter.exe 00 11,324
spywaregaurd.exe 00 36,576
winlogin.exe 00 6,884
rundll32.exe 00 6,116
FxSxr2.exe 00 7,172
lxcgcoms.exe System 00 5,008
ACDaemon.exe user me 00 7,008
taskmgr.exe // 00/02 9,108
rundll32.exe 00 6,400
jusched.exe 00 6,940
vVX6000.exe 00 6,300
sprtcmd.exe 00 2,120
lxcgmon.exe 00 7,180
LogTray.exe 00 10,568
CTSysVol.exe 00 7,464
notepad.exe 00 9,400 (what im typing this into)
alg.exe local service 00 4,944
Ymsgr_tray.exe user me 00 7,572
svhost.exe system 00 5,012
sprtsvc.exe // 00 1,100
slserv.exe 00 2,884
nvsvc32.exe 00 4,804
MSCamS32.exe 00 3,324
jqs.exe 00 1,652
CTSVCCDA.EXE 00 2,994
ACService.exe 00 3,152
spoolsy.exe 00 5,852
svchost.exe local service 00 3,992
svchost.exe network host 00 4,148
wscntfy.exe user me 00 5,888
svchost.exe system 00 24,808
svchost.exe network host 00 5,472
svchost.exe system 00 8,860
explorer.exe user me 00 30,756
lsass.exe system 00 1,124
services.exe / 00 9,744
winlogon.exe 00 6,940
csrss.exe 00 4,048
System 00 704
System Idle Process 86/98 16

________________________________________________________________________________
_______________
ok here is the start up list this is while under reg. mode……..

StartupList report, 12/27/2008, 3:31:42 AM
StartupList version: 1.52.2
Started from : C:..Program Files..Trend Micro..HijackThis..HijackThis.EXE
Detected: Windows XP SP3 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16762)
* Using default options
==================================================

Running processes:

C:..WINDOWS..system32..csrss.exe
C:..WINDOWS..system32..winlogon.exe
C:..WINDOWS..system32..services.exe
C:..WINDOWS..system32..lsass.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..Explorer.EXE
C:..WINDOWS..system32..ctfmon.exe
C:..Program Files..Trend Micro..HijackThis..HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Startup:
[C:..Documents and Settings..Danni-Doug..Start Menu..Programs..Startup]
PowerReg Scheduler.exe

Shell folders Common Startup:
[C:..Documents and Settings..All Users..Start Menu..Programs..Startup]
Kodak EasyShare software.lnk = C:..Program Files..Kodak..Kodak EasyShare software..bin..EasyShare.exe

————————————————–

Checking Windows NT UserInit:

[HKLM..Software..Microsoft..Windows NT..CurrentVersion..Winlogon]
UserInit = C:..WINDOWS..system32..userinit.exe,C:..WINDOWS..system32..twext.exe,

————————————————–

Autorun entries from Registry:
HKLM..Software..Microsoft..Windows..CurrentVersion..Run

CTSysVol = C:..Program Files..Creative..SB Live! 24-bit..Surround Mixer..CTSysVol.exe /r
UpdReg = C:..WINDOWS..UpdReg.EXE
LogitechVideoRepair = C:..Program Files..Logitech..Video..ISStart.exe
LogitechVideoTray = C:..Program Files..Logitech..Video..LogiTray.exe
LXCGCATS = rundll32 C:..WINDOWS..System32..spool..DRIVERS..W32X86..3..LXCGtime.dll,_RunDLLEntry@16
lxcgmon.exe = "C:..Program Files..Lexmark 2300 Series..lxcgmon.exe"
ddoctorv2 = "C:..Program Files..Comcast..Desktop Doctor..bin..sprtcmd.exe" /P ddoctorv2
(Default) =
VX6000 = C:..WINDOWS..vVX6000.exe
LifeCam = "C:..Program Files..Microsoft LifeCam..LifeExp.exe"
Adobe Reader Speed Launcher = "C:..Program Files..Adobe..Reader 8.0..Reader..Reader_sl.exe"
SunJavaUpdateSched = "C:..Program Files..Java..jre6..bin..jusched.exe"
NvCplDaemon = RUNDLL32.EXE C:..WINDOWS..system32..NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
NvMediaCenter = RUNDLL32.EXE C:..WINDOWS..system32..NvMcTray.dll,NvTaskbarInit
QuickTime Task = "C:..Program Files..QuickTime..qttask.exe" -atboottime
ArcSoft Connection Service = C:..Program Files..Common Files..ArcSoft..Connection Service..Bin..ACDaemon.exe
Smeyamodetako = rundll32.exe "C:..WINDOWS..Dpoxutoqihoj.dll",e
Gdoqomu = rundll32.exe "C:..WINDOWS..anonicimay.dll",e
PromoReg = C:..WINDOWS..TEMP..TMPD.tmp
xsjfn83jkemfofght = C:..WINDOWS..TEMP..winlogin.exe
spywareguard = C:..Program Files..Spyware Guard 2008..spywareguard.exe

————————————————–

Autorun entries from Registry:
HKLM..Software..Microsoft..Windows..CurrentVersion..RunOnce

tdss = C:..WINDOWS..TEMP..8998656.exe
= C:..WINDOWS..System32..cmd.exe /C del /Q C:..WINDOWS..system32..rdssrv.exe C:..WINDOWS..system32..rdshost.dll C:..WINDOWS..system32..hdfkt.dll

————————————————–

Autorun entries from Registry:
HKCU..Software..Microsoft..Windows..CurrentVersion..Run

LogitechSoftwareUpdate = "C:..Program Files..Logitech..Video..ManifestEngine.exe" boot
Yahoo! Pager = "C:..Program Files..Yahoo!..Messenger..YahooMessenger.exe" -quiet
ctfmon.exe = C:..WINDOWS..system32..ctfmon.exe
Universal Installer = "C:..Program Files..ComcastUI..Universal Installer..uinstaller.exe" /fromrun /starthidden
BitTorrent DNA = "C:..Program Files..DNA..btdna.exe"
xsjfn83jkemfofght = C:..WINDOWS..TEMP..winlogin.exe
Jnskdfmf9eldfd = C:..DOCUME~1..DANNI-~1..LOCALS~1..Temp..csrssc.exe

————————————————–

Autorun entries in Registry subkeys of:
HKLM..Software..Microsoft..Windows..CurrentVersion..Run

[OptionalComponents]
=

————————————————–

Shell & screensaver key from C:..WINDOWS..SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:..WINDOWS..System32..sstext3d.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU……Policies: Shell=*Registry value not found*
HKLM……Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - (no file) - {02478D38-C3F9-4efb-9B51-7695ECA05670}
(no name) - C:..Program Files..Java..jre6..bin..ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - C:..Program Files..Java..jre6..bin..jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}
JQSIEStartDetectorImpl - C:..Program Files..Java..jre6..lib..deploy..jqs..ie..jqs_plugin.dll - {E7E6F031-17CE-4C07-BC86-EABFE594F69C}

————————————————–

Enumerating Task Scheduler jobs:

AAD8435891A3F79C.job

————————————————–

Enumerating Download Program Files:

[QuickTime Object]
InProcServer32 = C:..Program Files..QuickTime..QTPlugin.ocx
CODEBASE = http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab

[StagingUI Object]
InProcServer32 = C:..WINDOWS..Downloaded Program Files..StagingUI.ocx
CODEBASE = http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:..WINDOWS..system32..legitcheckcontrol.dll
CODEBASE = http://download.microsoft.com/download/5/b…heckControl.cab

[Installation Support]
InProcServer32 = C:..Program Files..Yahoo!..Common..Yinsthelper.dll
CODEBASE = C:..Program Files..Yahoo!..Common..Yinsthelper.dll

[MSN Games – Buddy Invite]
InProcServer32 = C:..WINDOWS..Downloaded Program Files..ZBuddy.ocx
CODEBASE = http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab

[SupportSoft External Control]
InProcServer32 = C:..WINDOWS..Downloaded Program Files..sprtexternal.dll
CODEBASE = http://connect.comcast.com/dl/Comcast%20Ac…%20Controls.cab

[MySpace Uploader Control]
InProcServer32 = C:..WINDOWS..Downloaded Program Files..MySpaceUploader.ocx
CODEBASE = http://lads.myspace.com/upload/MySpaceUploader1006.cab

[ZonePAChat Object]
InProcServer32 = C:..WINDOWS..Downloaded Program Files..ZPAChat.ocx
CODEBASE = http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab

[GameLauncher Control]
InProcServer32 = C:..WINDOWS..DOWNLO~1..GAMELA~1.OCX
CODEBASE = http://www.acclaim.com/cabs/acclaim_v5.cab

[MSN Games - Installer]
InProcServer32 = C:..WINDOWS..Downloaded Program Files..ZIntro.ocx
CODEBASE = http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab

[Shockwave Flash Object]
InProcServer32 = C:..WINDOWS..system32..Macromed..Flash..Flash9f.ocx
CODEBASE = http://fpdownload.macromedia.com/get/flash…ent/swflash.cab

[MSN Games – Game Communicator]
InProcServer32 = C:..WINDOWS..Downloaded Program Files..StProxy.dll
CODEBASE = http://zone.msn.com/binframework/v10/StProxy.cab55579.cab

[GameTap Web Plugin]
InProcServer32 = C:..WINDOWS..DOWNLO~1..gtplugin.ocx
CODEBASE = http://cnn-5.vo.llnwd.net/c1/static/client…er/gtplugin.cab

[ChessControl Class]
InProcServer32 = C:..WINDOWS..Downloaded Program Files..ZPA_KQRP.dll
CODEBASE = http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:..WINDOWS..system32..SHELL32.dll
CDBurn: C:..WINDOWS..system32..SHELL32.dll
WebCheck: C:..WINDOWS..system32..webcheck.dll
SysTray: C:..WINDOWS..System32..stobject.dll
WPDShServiceObj: C:..WINDOWS..system32..WPDShServiceObj.dll
ieModule: C:..Documents and Settings..All Users..Application Data..Microsoft..Internet Explorer..DLLs..ieModule.dll
InternetConnection: C:..Documents and Settings..All Users..Application Data..Microsoft..Internet Explorer..DLLs..nnswpwsegr.dll

————————————————–
End of report, 8,814 bytes
Report generated in 0.047 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only



ok now for the hi jackthi logs …..first under safe mode..
________________________________________________________________________________
__________________


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:01:10 AM, on 12/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Safe mode

Running processes:
C:..WINDOWS..system32..csrss.exe
C:..WINDOWS..system32..winlogon.exe
C:..WINDOWS..system32..services.exe
C:..WINDOWS..system32..lsass.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..Explorer.EXE
C:..Program Files..Trend Micro..HijackThis..HijackThis.exe
C:..WINDOWS..System32..wbem..wmiprvse.exe

R0 - HKCU..Software..Microsoft..Internet Explorer..Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU..Software..Microsoft..Internet Explorer..Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU..Software..Microsoft..Windows..CurrentVersion..Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:..WINDOWS..system32..userinit.exe,C:..WINDOWS..system32..twext.exe,
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:..Program Files..Java..jre6..bin..ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:..Program Files..Java..jre6..bin..jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:..Program Files..Java..jre6..lib..deploy..jqs..ie..jqs_plugin.dll
O4 - HKLM……Run: [CTSysVol] C:..Program Files..Creative..SB Live! 24-bit..Surround Mixer..CTSysVol.exe /r
O4 - HKLM……Run: [UpdReg] C:..WINDOWS..UpdReg.EXE
O4 - HKLM……Run: [LogitechVideoRepair] C:..Program Files..Logitech..Video..ISStart.exe
O4 - HKLM……Run: [LogitechVideoTray] C:..Program Files..Logitech..Video..LogiTray.exe
O4 - HKLM……Run: [LXCGCATS] rundll32 C:..WINDOWS..System32..spool..DRIVERS..W32X86..3..LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM……Run: [lxcgmon.exe] "C:..Program Files..Lexmark 2300 Series..lxcgmon.exe"
O4 - HKLM……Run: [ddoctorv2] "C:..Program Files..Comcast..Desktop Doctor..bin..sprtcmd.exe" /P ddoctorv2
O4 - HKLM……Run: [VX6000] C:..WINDOWS..vVX6000.exe
O4 - HKLM……Run: [LifeCam] "C:..Program Files..Microsoft LifeCam..LifeExp.exe"
O4 - HKLM……Run: [Adobe Reader Speed Launcher] "C:..Program Files..Adobe..Reader 8.0..Reader..Reader_sl.exe"
O4 - HKLM……Run: [SunJavaUpdateSched] "C:..Program Files..Java..jre6..bin..jusched.exe"
O4 - HKLM……Run: [NvCplDaemon] RUNDLL32.EXE C:..WINDOWS..system32..NvCpl.dll,NvStartup
O4 - HKLM……Run: [nwiz] nwiz.exe /install
O4 - HKLM……Run: [NvMediaCenter] RUNDLL32.EXE C:..WINDOWS..system32..NvMcTray.dll,NvTaskbarInit
O4 - HKLM……Run: [QuickTime Task] "C:..Program Files..QuickTime..qttask.exe" -atboottime
O4 - HKLM……Run: [ArcSoft Connection Service] C:..Program Files..Common Files..ArcSoft..Connection Service..Bin..ACDaemon.exe
O4 - HKLM……Run: [Smeyamodetako] rundll32.exe "C:..WINDOWS..Dpoxutoqihoj.dll",e
O4 - HKLM……Run: [Gdoqomu] rundll32.exe "C:..WINDOWS..anonicimay.dll",e
O4 - HKLM……Run: [PromoReg] C:..WINDOWS..TEMP..TMPD.tmp
O4 - HKLM……Run: [xsjfn83jkemfofght] C:..WINDOWS..TEMP..winlogin.exe
O4 - HKLM……Run: [spywareguard] C:..Program Files..Spyware Guard 2008..spywareguard.exe
O4 - HKLM……RunOnce: [tdss] C:..WINDOWS..TEMP..8998656.exe
O4 - HKCU……Run: [LogitechSoftwareUpdate] "C:..Program Files..Logitech..Video..ManifestEngine.exe" boot
O4 - HKCU……Run: [Yahoo! Pager] "C:..Program Files..Yahoo!..Messenger..YahooMessenger.exe" -quiet
O4 - HKCU……Run: [ctfmon.exe] C:..WINDOWS..system32..ctfmon.exe
O4 - HKCU……Run: [xsjfn83jkemfofght] C:..WINDOWS..TEMP..winlogin.exe
O4 - HKCU……Run: [Jnskdfmf9eldfd] C:..DOCUME~1..DANNI-~1..LOCALS~1..Temp..csrssc.exe
O4 - HKUS..S-1-5-18……Run: [MySpaceIM] C:..Program Files..MySpace..IM..MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS..S-1-5-18……Run: [xsjfn83jkemfofght] C:..WINDOWS..TEMP..winlogin.exe (User 'SYSTEM')
O4 - HKUS..S-1-5-18……Run: [Jnskdfmf9eldfd] C:..WINDOWS..TEMP..csrssc.exe (User 'SYSTEM')
O4 - HKUS…DEFAULT……Run: [MySpaceIM] C:..Program Files..MySpace..IM..MySpaceIM.exe (User 'Default user')
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:..Program Files..Kodak..Kodak EasyShare software..bin..EasyShare.exe
O7 - HKCU..Software..Microsoft..Windows..CurrentVersion..Policies..System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:..Program Files..Java..jre6..bin..jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:..Program Files..Java..jre6..bin..jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:..WINDOWS..Network Diagnostic..xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:..WINDOWS..Network Diagnostic..xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:..Program Files..Messenger..msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:..Program Files..Messenger..msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:..Program Files..Yahoo!..Common..Yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) - http://connect.comcast.com/dl/Comcast%20Ac…%20Controls.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E93E9DF0-3E59-4331-A269-F1E077C66F00} (GameTap Web Plugin) - http://cnn-5.vo.llnwd.net/c1/static/client…er/gtplugin.cab
O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} (ChessControl Class) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab
O20 - Winlogon Notify: crypt - C:..WINDOWS..SYSTEM32..crypts.dll
O21 - SSODL: ieModule - {73049CBC-0219-440D-B3C7-081B983D92F5} - C:..Documents and Settings..All Users..Application Data..Microsoft..Internet Explorer..DLLs..ieModule.dll
O21 - SSODL: InternetConnection - {17E60241-CB03-48B2-AA68-D2AF1AB5875F} - C:..Documents and Settings..All Users..Application Data..Microsoft..Internet Explorer..DLLs..nnswpwsegr.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:..Program Files..Common Files..ArcSoft..Connection Service..Bin..ACService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:..WINDOWS..System32..CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:..Program Files..Google..Common..Google Updater..GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:..Program Files..Java..jre6..bin..jqs.exe
O23 - Service: lxcg_device - - C:..WINDOWS..system32..lxcgcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:..WINDOWS..system32..nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:..WINDOWS..SYSTEM32..slserv.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:..Program Files..Comcast..Desktop Doctor..bin..sprtsvc.exe

–
End of file - 8811 bytes


now for non safe mode……


________________________________________________________________________________
_________


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:42:29 AM, on 12/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:..WINDOWS..system32..csrss.exe
C:..WINDOWS..system32..winlogon.exe
C:..WINDOWS..system32..services.exe
C:..WINDOWS..system32..lsass.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..System32..svchost.exe
C:..WINDOWS..System32..svchost.exe
C:..WINDOWS..System32..svchost.exe
C:..WINDOWS..system32..spoolsv.exe
C:..Program Files..Common Files..ArcSoft..Connection Service..Bin..ACService.exe
C:..WINDOWS..System32..CTsvcCDA.exe
C:..Program Files..Java..jre6..bin..jqs.exe
C:..Program Files..Microsoft LifeCam..MSCamS32.exe
C:..WINDOWS..system32..nvsvc32.exe
C:..WINDOWS..system32..slserv.exe
C:..Program Files..Comcast..Desktop Doctor..bin..sprtsvc.exe
C:..WINDOWS..System32..svchost.exe
C:..WINDOWS..System32..alg.exe
C:..WINDOWS..Explorer.EXE
C:..WINDOWS..system32..wscntfy.exe
C:..Program Files..Creative..SB Live! 24-bit..Surround Mixer..CTSysVol.exe
C:..Program Files..Logitech..Video..LogiTray.exe
C:..Program Files..Lexmark 2300 Series..lxcgmon.exe
C:..Program Files..Comcast..Desktop Doctor..bin..sprtcmd.exe
C:..WINDOWS..vVX6000.exe
C:..Program Files..Java..jre6..bin..jusched.exe
C:..WINDOWS..system32..RUNDLL32.EXE
C:..Program Files..Common Files..ArcSoft..Connection Service..Bin..ACDaemon.exe
C:..WINDOWS..system32..lxcgcoms.exe
C:..Program Files..Logitech..Video..FxSvr2.exe
C:..WINDOWS..system32..rundll32.exe
C:..WINDOWS..TEMP..winlogin.exe
C:..Program Files..Spyware Guard 2008..spywareguard.exe
C:..WINDOWS..system32..winscenter.exe
C:..WINDOWS..system32..ctfmon.exe
C:..Program Files..Kodak..Kodak EasyShare software..bin..EasyShare.exe
C:..Program Files..Yahoo!..Messenger..ymsgr_tray.exe
C:..DOCUME~1..DANNI-~1..LOCALS~1..Temp..csrssc.exe
C:..Program Files..Trend Micro..HijackThis..HijackThis.exe
C:..WINDOWS..System32..wbem..wmiprvse.exe

R0 - HKCU..Software..Microsoft..Internet Explorer..Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU..Software..Microsoft..Internet Explorer..Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU..Software..Microsoft..Windows..CurrentVersion..Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:..WINDOWS..system32..userinit.exe,C:..WINDOWS..system32..twext.exe,
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:..Program Files..Java..jre6..bin..ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:..Program Files..Java..jre6..bin..jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:..Program Files..Java..jre6..lib..deploy..jqs..ie..jqs_plugin.dll
O4 - HKLM……Run: [CTSysVol] C:..Program Files..Creative..SB Live! 24-bit..Surround Mixer..CTSysVol.exe /r
O4 - HKLM……Run: [UpdReg] C:..WINDOWS..UpdReg.EXE
O4 - HKLM……Run: [LogitechVideoRepair] C:..Program Files..Logitech..Video..ISStart.exe
O4 - HKLM……Run: [LogitechVideoTray] C:..Program Files..Logitech..Video..LogiTray.exe
O4 - HKLM……Run: [LXCGCATS] rundll32 C:..WINDOWS..System32..spool..DRIVERS..W32X86..3..LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM……Run: [lxcgmon.exe] "C:..Program Files..Lexmark 2300 Series..lxcgmon.exe"
O4 - HKLM……Run: [ddoctorv2] "C:..Program Files..Comcast..Desktop Doctor..bin..sprtcmd.exe" /P ddoctorv2
O4 - HKLM……Run: [VX6000] C:..WINDOWS..vVX6000.exe
O4 - HKLM……Run: [LifeCam] "C:..Program Files..Microsoft LifeCam..LifeExp.exe"
O4 - HKLM……Run: [Adobe Reader Speed Launcher] "C:..Program Files..Adobe..Reader 8.0..Reader..Reader_sl.exe"
O4 - HKLM……Run: [SunJavaUpdateSched] "C:..Program Files..Java..jre6..bin..jusched.exe"
O4 - HKLM……Run: [NvCplDaemon] RUNDLL32.EXE C:..WINDOWS..system32..NvCpl.dll,NvStartup
O4 - HKLM……Run: [nwiz] nwiz.exe /install
O4 - HKLM……Run: [NvMediaCenter] RUNDLL32.EXE C:..WINDOWS..system32..NvMcTray.dll,NvTaskbarInit
O4 - HKLM……Run: [QuickTime Task] "C:..Program Files..QuickTime..qttask.exe" -atboottime
O4 - HKLM……Run: [ArcSoft Connection Service] C:..Program Files..Common Files..ArcSoft..Connection Service..Bin..ACDaemon.exe
O4 - HKLM……Run: [Smeyamodetako] rundll32.exe "C:..WINDOWS..Dpoxutoqihoj.dll",e
O4 - HKLM……Run: [Gdoqomu] rundll32.exe "C:..WINDOWS..anonicimay.dll",e
O4 - HKLM……Run: [PromoReg] C:..WINDOWS..TEMP..TMPD.tmp
O4 - HKLM……Run: [xsjfn83jkemfofght] C:..WINDOWS..TEMP..winlogin.exe
O4 - HKLM……Run: [spywareguard] C:..Program Files..Spyware Guard 2008..spywareguard.exe
O4 - HKLM……RunOnce: [tdss] C:..WINDOWS..TEMP..8998656.exe
O4 - HKCU……Run: [LogitechSoftwareUpdate] "C:..Program Files..Logitech..Video..ManifestEngine.exe" boot
O4 - HKCU……Run: [Yahoo! Pager] "C:..Program Files..Yahoo!..Messenger..YahooMessenger.exe" -quiet
O4 - HKCU……Run: [ctfmon.exe] C:..WINDOWS..system32..ctfmon.exe
O4 - HKCU……Run: [xsjfn83jkemfofght] C:..WINDOWS..TEMP..winlogin.exe
O4 - HKCU……Run: [Jnskdfmf9eldfd] C:..DOCUME~1..DANNI-~1..LOCALS~1..Temp..csrssc.exe
O4 - HKUS..S-1-5-18……Run: [MySpaceIM] C:..Program Files..MySpace..IM..MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS..S-1-5-18……Run: [xsjfn83jkemfofght] C:..WINDOWS..TEMP..winlogin.exe (User 'SYSTEM')
O4 - HKUS..S-1-5-18……Run: [Jnskdfmf9eldfd] C:..WINDOWS..TEMP..csrssc.exe (User 'SYSTEM')
O4 - HKUS…DEFAULT……Run: [MySpaceIM] C:..Program Files..MySpace..IM..MySpaceIM.exe (User 'Default user')
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:..Program Files..Kodak..Kodak EasyShare software..bin..EasyShare.exe
O7 - HKCU..Software..Microsoft..Windows..CurrentVersion..Policies..System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:..Program Files..Java..jre6..bin..jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:..Program Files..Java..jre6..bin..jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:..WINDOWS..Network Diagnostic..xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:..WINDOWS..Network Diagnostic..xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:..Program Files..Messenger..msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:..Program Files..Messenger..msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:..Program Files..Yahoo!..Common..Yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) - http://connect.comcast.com/dl/Comcast%20Ac…%20Controls.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E93E9DF0-3E59-4331-A269-F1E077C66F00} (GameTap Web Plugin) - http://cnn-5.vo.llnwd.net/c1/static/client…er/gtplugin.cab
O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} (ChessControl Class) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab
O20 - Winlogon Notify: crypt - C:..WINDOWS..SYSTEM32..crypts.dll
O21 - SSODL: ieModule - {73049CBC-0219-440D-B3C7-081B983D92F5} - C:..Documents and Settings..All Users..Application Data..Microsoft..Internet Explorer..DLLs..ieModule.dll
O21 - SSODL: InternetConnection - {17E60241-CB03-48B2-AA68-D2AF1AB5875F} - C:..Documents and Settings..All Users..Application Data..Microsoft..Internet Explorer..DLLs..nnswpwsegr.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:..Program Files..Common Files..ArcSoft..Connection Service..Bin..ACService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:..WINDOWS..System32..CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:..Program Files..Google..Common..Google Updater..GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:..Program Files..Java..jre6..bin..jqs.exe
O23 - Service: lxcg_device - - C:..WINDOWS..system32..lxcgcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:..WINDOWS..system32..nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:..WINDOWS..SYSTEM32..slserv.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:..Program Files..Comcast..Desktop Doctor..bin..sprtsvc.exe

–
End of file - 10152 bytes


hope something helps………………..
ok i downloaded ATF cleaner to disc and ran it on my computer …from main it deleted 356.848mb and from firefox 20.000+ kb also downloaded malwarebytes to disc but still wont run on my machine. gonna try to download other programs ive seen u guys recommend see if anything works will post again with new hijack log
Hi

this will seem strange, But some viruses reconze the name and won't work!


try this in safe mode:

go to where you stored mbam-setup.exe

and change the name to help.exe

to change the name right click on mbam-setup.exe then click on rename



good luck mschroe919
ok now we are getting somewhere :D Im now on this website with MY pc

I was able to go in and change all the names of malwarebytes and it worked …. thank you so much

I still have spyware gaurd 2008 so far :( even after reboot it still there. oh well guess we getting progress

well here is my malwarebytes log followed by another hijackthis log…….



first malwarebytes……………………oh yea it did 2 scans … after first one there was an error after reboot so I wasnt sure hope it doesnt mess anything up.



Malwarebytes' Anti-Malware 1.31
Database version: 1456
Windows 5.1.2600 Service Pack 3

12/28/2008 8:00:51 AM
mbam-log-2008-12-28 (08-00-51).txt

Scan type: Quick Scan
Objects scanned: 56027
Time elapsed: 12 minute(s), 46 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 8
Registry Values Infected: 7
Registry Data Items Infected: 5
Folders Infected: 4
Files Infected: 36

Memory Processes Infected:
C:\Program Files\Spyware Guard 2008\spywareguard.exe (Rogue.SpywareGuard) -> Unloaded process successfully.

Memory Modules Infected:
C:\WINDOWS\system32\crypts.dll (Trojan.Agent) -> Delete on reboot.

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7545d8c8-f53c-4e2f-8fa0-d248ef4a6e61} (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1a26f07f-0d60-4835-91cf-1e1766a0ec56} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\spyware guard 2008 (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spywareguard (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smeyamodetako (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gdoqomu (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PromoReg (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Jnskdfmf9eldfd (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jnskdfmf9eldfd (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\ (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Backdoor.Bot) -> Data: c:\windows\system32\twext.exe -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Backdoor.Bot) -> Data: system32\twext.exe -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twext.exe,) Good: (userinit.exe) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\Spyware Guard 2008 (Rogue.SpywareGuard) -> Delete on reboot.
C:\Program Files\Spyware Guard 2008\quarantine (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\twain_32 (Backdoor.Bot) -> Delete on reboot.
C:\Documents and Settings\Danni-Doug\Start Menu\Programs\Spyware Guard 2008 (Rogue.SpywareGuard) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\TDSScfum.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\TDSSnrsr.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\TDSSofxh.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\TDSSriqp.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\drivers\TDSSmhxt.sys (Trojan.TDSS) -> Delete on reboot.
C:\rpnxsyw.exe (Trojan.TinyDownloader705) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\conf.cfg (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\mbase.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\quarantine.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\queue.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\spywareguard.exe (Rogue.SpywareGuard) -> Delete on reboot.
C:\Program Files\Spyware Guard 2008\uninstall.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\vbase.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\twain_32\local.ds (Backdoor.Bot) -> Delete on reboot.
C:\WINDOWS\system32\twain_32\user.ds (Backdoor.Bot) -> Delete on reboot.
C:\Documents and Settings\Danni-Doug\Start Menu\Programs\Spyware Guard 2008\Spyware Guard 2008.lnk (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Documents and Settings\Danni-Doug\Start Menu\Programs\Spyware Guard 2008\Uninstall.lnk (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\uwasfsd.sys (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\WINDOWS\Dpoxutoqihoj.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\anonicimay.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\twext.exe (Backdoor.Bot) -> Delete on reboot.
C:\WINDOWS\system32\crypts.dll (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\Danni-Doug\Local Settings\Temp\csrssc.exe (Trojan.Downloader) -> Delete on reboot.
C:\WINDOWS\sysexplorer.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\reged.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\spoolsystem.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\sys.com (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\syscert.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\vmreg.dll (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Protect\svhost.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Protect\track.sys (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\csrssc.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Danni-Doug\Desktop\Spyware Guard 2008.lnk (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSfxmp.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\TDSSrhym.log (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\TDSStkdv.log (Trojan.TDSS) -> Delete on reboot.



2nd malwarebytes log………………………………..


Malwarebytes' Anti-Malware 1.31
Database version: 1456
Windows 5.1.2600 Service Pack 3

12/28/2008 8:18:46 AM
mbam-log-2008-12-28 (08-18-46).txt

Scan type: Quick Scan
Objects scanned: 55513
Time elapsed: 11 minute(s), 2 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 4
Registry Data Items Infected: 1
Folders Infected: 3
Files Infected: 18

Memory Processes Infected:
C:\Program Files\Spyware Guard 2008\spywareguard.exe (Rogue.SpywareGuard) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\spyware guard 2008 (Rogue.SpywareGuard) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spywareguard (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smeyamodetako (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gdoqomu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twext.exe,) Good: (userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\Spyware Guard 2008 (Rogue.SpywareGuard) -> Delete on reboot.
C:\Program Files\Spyware Guard 2008\quarantine (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Documents and Settings\Danni-Doug\Start Menu\Programs\Spyware Guard 2008 (Rogue.SpywareGuard) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\Spyware Guard 2008\conf.cfg (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\mbase.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\quarantine.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\queue.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\spywareguard.exe (Rogue.SpywareGuard) -> Delete on reboot.
C:\Program Files\Spyware Guard 2008\uninstall.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\vbase.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Documents and Settings\Danni-Doug\Start Menu\Programs\Spyware Guard 2008\Spyware Guard 2008.lnk (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Documents and Settings\Danni-Doug\Start Menu\Programs\Spyware Guard 2008\Uninstall.lnk (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\sysexplorer.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\reged.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\spoolsystem.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\sys.com (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\syscert.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\vmreg.dll (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\TDSS25c6.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\TDSS25e5.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Danni-Doug\Desktop\Spyware Guard 2008.lnk (Rogue.SpywareGuard) -> Quarantined and deleted successfully.



and for the hijackthis log…………………………………………….


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:30:37 AM, on 12/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Spyware Guard 2008\spywareguard.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\winscenter.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =

http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program

Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program

Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection

Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [xsjfn83jkemfofght] C:\WINDOWS\TEMP\winlogin.exe
O4 - HKLM\..\Run: [spywareguard] C:\Program Files\Spyware Guard 2008\spywareguard.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [xsjfn83jkemfofght] C:\WINDOWS\TEMP\winlogin.exe
O4 - HKUS\S-1-5-18\..\Run: [xsjfn83jkemfofght] C:\WINDOWS\TEMP\winlogin.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [xsjfn83jkemfofght] C:\WINDOWS\TEMP\winlogin.exe (User 'Default user')
O4 - Startup: PowerReg Scheduler.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -

http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program

Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) -

http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) -

http://connect.comcast.com/dl/Comcast%20Ac…%20Controls.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -

http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) -

http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) -

http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -

http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) -

http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E93E9DF0-3E59-4331-A269-F1E077C66F00} (GameTap Web Plugin) -

http://cnn-5.vo.llnwd.net/c1/static/client…er/gtplugin.cab
O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} (ChessControl Class) -

http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab
O21 - SSODL: ieModule - {73049CBC-0219-440D-B3C7-081B983D92F5} - C:\Documents and Settings\All Users\Application

Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
O21 - SSODL: InternetConnection - {17E60241-CB03-48B2-AA68-D2AF1AB5875F} - C:\Documents and Settings\All

Users\Application Data\Microsoft\Internet Explorer\DLLs\nnswpwsegr.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection

Service\Bin\ACService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program

Files\Java\jre6\bin\jqs.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program

Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

–
End of file - 8157 bytes


awaiting orders captain………..
almost forgot but i just checked and i was able to "show hidden files" now not sure it changes anything ….. if so i can run another hijackthis log
hi and happy new year,

NEXT:

Download ComboFix to your Desktop.
Get it

HERE:


HERE:


**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
Please do not re-connect your machine back to the Internet until Combofix has completely finished.


**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:




[external image: Posted Image]

——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the C:\ComboFix.txt along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Give it atleast 20-30 minutes to finish
ok we are getting somewhere now…. spyware gaurd is gone as far as I can see….

here is Combofix log………….


ComboFix 08-12-28.01 - Danni-Doug 2008-12-28 21:18:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.556 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\moduleie.dll
c:\documents and settings\All Users\Application Data\svhost.exe
c:\documents and settings\Doug\Application Data\twain_32
c:\documents and settings\Doug\Application Data\twain_32\user.ds
c:\documents and settings\Guest\Application Data\twain_32
c:\documents and settings\Guest\Application Data\twain_32\user.ds
c:\documents and settings\LocalService\Application Data\twain_32
c:\documents and settings\LocalService\Application Data\twain_32\user.ds
c:\documents and settings\NetworkService\Application Data\twain_32
c:\documents and settings\NetworkService\Application Data\twain_32\user.ds
c:\program files\Spyware Guard 2008
c:\program files\Spyware Guard 2008\conf.cfg
c:\program files\Spyware Guard 2008\mbase.vdb
c:\program files\Spyware Guard 2008\quarantine.vdb
c:\program files\Spyware Guard 2008\queue.vdb
c:\program files\Spyware Guard 2008\spywareguard.exe
c:\program files\Spyware Guard 2008\uninstall.exe
c:\program files\Spyware Guard 2008\vbase.vdb
c:\windows\Downloaded Program Files\UWAS6_0001_N69M0903NetInstaller.exe
c:\windows\jestertb.dll
c:\windows\reged.exe
c:\windows\spoolsystem.exe
c:\windows\sys.com
c:\windows\syscert.exe
c:\windows\sysexplorer.exe
c:\windows\system32\jkse73hedfdgf.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\winscenter.exe
c:\windows\vmreg.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TDSSSERV.SYS
——-\Service_TDSSserv.sys


((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-29 )))))))))))))))))))))))))))))))
.

2008-12-28 18:43 . 2008-12-28 18:45 d——– c:\documents and settings\Danni-Doug\.SunDownloadManager
2008-12-28 18:30 . 2008-12-28 18:30 d——– C:\61c22c20cbe8fe9ff137
2008-12-28 18:07 . 2008-12-28 18:07 d–hs—- C:\found.000
2008-12-28 07:44 . 2008-12-28 07:44 d——– c:\documents and settings\Danni-Doug\Application Data\Malwarebytes
2008-12-28 07:41 . 2008-12-28 07:44 d——– c:\program files\detriot pistons
2008-12-28 07:41 . 2008-12-28 07:41 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-28 07:41 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-28 07:41 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-27 02:49 . 2008-12-27 02:49 61,440 –a—— c:\windows\system32\drivers\iypsvl.sys
2008-12-27 02:35 . 2008-12-27 02:37 d——– c:\program files\Windows Live Safety Center
2008-12-25 23:34 . 2008-12-25 23:34 d——– c:\documents and settings\Guest\Application Data\Skinux
2008-12-25 23:34 . 2008-12-25 23:35 d——– c:\documents and settings\Guest\Application Data\ArcSoft
2008-12-25 23:26 . 2008-12-25 23:26 d——– c:\documents and settings\Doug\Application Data\Skinux
2008-12-25 23:26 . 2008-12-25 23:27 d——– c:\documents and settings\Doug\Application Data\ArcSoft
2008-12-25 23:26 . 2008-12-25 23:26 d——– c:\documents and settings\Doug
2008-12-25 20:04 . 2008-12-25 20:04 d——– c:\program files\Trend Micro
2008-12-25 20:04 . 2008-12-27 03:43 d——– c:\documents and settings\All Users\Application Data\CrucialSoft Ltd
2008-12-25 20:04 . 2008-12-25 20:04 81,931 –a—— C:\uyrte.exe
2008-12-25 20:04 . 2008-12-25 20:04 44,032 –a—— C:\tnpqvcdm.exe
2008-12-25 20:04 . 2008-12-25 20:04 29,701 –a—— C:\elbff.exe
2008-12-25 20:04 . 2008-12-25 20:04 2 –a—— C:\-1273023007
2008-12-25 20:04 . 2008-12-26 22:01 0 –a—— c:\windows\system32\drivers\ff31df41.sys
2008-12-23 02:49 . 2008-12-23 02:49 4,648 –a—— c:\windows\arixabokogike.dll
2008-12-23 02:46 . 2008-12-23 02:46 4,648 –a—— c:\windows\ugupevog.dll
2008-12-18 06:27 . 2008-12-23 06:02 d——– c:\windows\ie8updates
2008-12-17 17:40 . 2008-12-17 17:40 410,984 –a—— c:\windows\system32\deploytk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-29 02:21 79,872 —-a-w c:\windows\system32\drivers\etdfsvapi33.sys
2008-12-28 12:20 ——— d—–w c:\program files\PokerStars
2008-12-26 04:07 ——— d—–w c:\program files\Teamspeak2_RC2
2008-12-24 07:58 ——— d—–w c:\program files\Microsoft LifeCam
2008-12-24 07:44 ——— d—–w c:\program files\iTunes
2008-12-24 07:44 ——— d—–w c:\program files\iPod
2008-12-24 07:41 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-24 07:41 ——— d—–w c:\documents and settings\All Users\Application Data\BVRP Software
2008-12-24 07:39 ——— d—–w c:\program files\Bonjour
2008-12-24 07:37 ——— d—–w c:\program files\Blubster
2008-12-17 22:40 ——— d—–w c:\program files\Java
2008-12-10 18:00 ——— d—–w c:\program files\Lx_cats
2008-11-29 04:11 ——— d—–w c:\program files\FlightGear
2008-11-29 04:09 ——— d—–w c:\program files\Common Files\eSellerate
2008-11-29 02:14 ——— d—–w c:\program files\YSFLIGHT.COM
2008-11-29 01:55 ——— d—–w c:\documents and settings\Danni-Doug\Application Data\flightgear.org
2008-11-28 07:21 ——— d—–w c:\program files\Windows Media Connect 2
2008-11-24 07:22 0 —ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-11-24 07:22 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-11-24 07:21 ——— d—–w c:\program files\Common Files\Motorola Shared
2008-11-09 17:34 ——— d—–w c:\documents and settings\Danni-Doug\Application Data\KodakCredentialStore
2008-11-09 03:14 ——— d—–w c:\program files\Common Files\ArcSoft
2008-11-09 03:14 ——— d—–w c:\documents and settings\Danni-Doug\Application Data\ArcSoft
2008-11-09 03:14 ——— d—–w c:\documents and settings\All Users\Application Data\ArcSoft
2008-11-09 03:13 ——— d—–w c:\program files\ArcSoft
2008-11-09 03:10 ——— d—–w c:\program files\Common Files\Kodak
2008-11-09 03:00 ——— d—–w c:\program files\Kodak
2008-11-09 03:00 ——— d—–w c:\documents and settings\Danni-Doug\Application Data\Skinux
2008-11-09 03:00 ——— d—–w c:\documents and settings\All Users\Application Data\Kodak
2008-11-04 03:28 ——— d—–w c:\program files\QuickTime
2008-11-04 03:28 ——— d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2008-09-28 19:29 24 -c–a-w c:\documents and settings\Danni-Doug\jagex_runescape_preferences.dat
2008-04-14 00:11 509,952 —-a-r c:\documents and settings\Doug\Application Data\twext.exe
2008-04-14 00:11 361,984 —-a-r c:\documents and settings\Guest\Application Data\twext.exe
2008-05-21 00:56 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008052020080521\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="c:\program files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-06-01 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-06-01 217088]
"LXCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 73728]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"VX6000"="c:\windows\vVX6000.exe" [2006-10-13 994096]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-11-20 178688]
"nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]

c:\documents and settings\Danni-Doug\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2007-07-25 256000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\e61xfmd3ppu.sys]
@="\??\c:\windows\system32\drivers\e61xfmd3ppu.sys"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\etdfsvapi33.sys]
@="\??\c:\windows\system32\drivers\etdfsvapi33.sys"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\AeriaGames\\LastChaosUSA\\LC.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=

R2 etdfsvapi33.sys;etdfsvapi33.sys;\??\c:\windows\system32\drivers\etdfsvapi33.sys [2003-03-31 79872]
S1 ff31df41;ff31df41;c:\windows\system32\drivers\ff31df41.sys [2008-12-25 0]
S2 e61xfmd3ppu.sys;e61xfmd3ppu.sys;\??\c:\windows\system32\drivers\e61xfmd3ppu.sys []
S3 mamotou;mamotou;c:\windows\system32\DRIVERS\mamotou.sys [2008-11-24 49489]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\DRIVERS\VX6000Xp.sys [2006-06-29 2383152]
.
Contents of the 'Scheduled Tasks' folder

2008-12-29 c:\windows\Tasks\AAD8435891A3F79C.job
- c:\docume~1\danni-~1\applic~1\showmo~1\meowdvdbarb.exe []
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-xsjfn83jkemfofght - c:\windows\TEMP\winlogin.exe
HKLM-Run-spywareguard - c:\program files\Spyware Guard 2008\spywareguard.exe
HKU-Default-Run-xsjfn83jkemfofght - c:\windows\TEMP\winlogin.exe


.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com

c:\windows\Downloaded Program Files\gtplugin.ocx - O16 -: {E93E9DF0-3E59-4331-A269-F1E077C66F00}
hxxp://cnn-5.vo.llnwd.net/c1/static/client/browserplayer/gtplugin.cab
c:\windows\Downloaded Program Files\gtplugin.inf
FF - ProfilePath - c:\documents and settings\Danni-Doug\Application Data\Mozilla\Firefox\Profiles\4fn9pvih.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-28 21:21:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCGCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe
c:\windows\system32\wscntfy.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-12-28 21:24:49 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-29 02:24:20

Pre-Run: 92,721,451,008 bytes free
Post-Run: 92,763,791,360 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

212 — E O F — 2008-12-23 20:22:16



here is the new hijackthis report log………………………


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:29:06 PM, on 12/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) - http://connect.comcast.com/dl/Comcast%20Ac…%20Controls.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E93E9DF0-3E59-4331-A269-F1E077C66F00} (GameTap Web Plugin) - http://cnn-5.vo.llnwd.net/c1/static/client…er/gtplugin.cab
O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} (ChessControl Class) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

–
End of file - 6793 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI