This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] popup.adv.net removal

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, new to this site.

I have for a few days now have trouble with "popup.adv.net" and "mtn5.goole.ws". I have tried to:
Installed and run several programsnamed "CCleaner", "Malwarebytes' Anti-Malware","Spybot - Search & Destroy"
I have also tried, on other sites advice to use the DOS commands, but they did not solve it:
ipconfig /release
ipconfig /renew
exit

Might missed something.
Would be very glad if someone would be kind enugh to help me resolve this issue.
Here is my HijackThis logg:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:36:32, on 2009-01-05
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Wintab32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe
C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program\Delade filer\Autodesk Shared\Service\AdskScSrv.exe
C:\Program\Delade filer\InterVideo\DeviceService\DevSvc.exe
C:\Program\DCPFLICS\dcpflics.exe
D:\Program\Diskeeper Corporation\Diskeeper\DkService.exe
D:\Program\Bild\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
D:\Program\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
D:\Program\A.C. Element MyUSBOnly\MYUSSER.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\spm\spmdib.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Delade filer\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\Program\Säkerhet\WinPatrol\winpatrol.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\Program\Backupp\Acronis\TrueImageMonitor.exe
D:\Program\Backupp\Acronis\TimounterMonitor.exe
C:\Program\Delade filer\Acronis\Schedule2\schedhlp.exe
D:\Program\Filhantering\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\ZPOINT32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\Delade filer\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\WINDOWS\system32\RUNDLL32.EXE
D:\Program\Säkerhet\ZoneAlarm\zlclient.exe
D:\Program\Multimedia\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program\Internet\Orbitdownloader\orbitdm.exe
D:\Program\Internet\Orbitdownloader\orbitnet.exe
D:\Program\OpenOffice.org 2.4\program\soffice.exe
C:\Program\iPod\bin\iPodService.exe
D:\Program\OpenOffice.org 2.4\program\soffice.BIN
D:\PROGRAM\KOMMUNIKATION\SKYPE\PHONE\SKYPE.EXE
D:\PROGRAM\EPOST\POPMAN\POPMAN.EXE
C:\WINDOWS\System32\svchost.exe
D:\Program\Kommunikation\mIRC\mirc.exe
D:\Program\Internet\GreenBrowser\GreenBrowser.exe
D:\Program\Multimedia\Winamp\winamp.exe
G:\Program\PidginPortable\App\Pidgin\Pidgin.exe
D:\Program\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.animate.se/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9051
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - D:\Program\Internet\Orbitdownloader\GrabPro.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - D:\Program\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - D:\Program\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: BumpTop Explorer Bar - {32CA105A-BD6C-4AFC-B4D9-346262E9F483} - D:\Program\BumpTop\BTShExt.dll
O4 - HKLM\..\Run: [WinPatrol] D:\Program\Säkerhet\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TrueImageMonitor.exe] D:\Program\Backupp\Acronis\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] D:\Program\Backupp\Acronis\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program\Delade filer\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] D:\Program\Filhantering\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Acecad.Wtxpload] C:\WINDOWS\Acecad\Wtxpload.exe Acecad
O4 - HKLM\..\Run: [ZPOINT32] C:\WINDOWS\system32\ZPOINT32.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TkBellExe] "C:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" /source=HKLM
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program\Säkerhet\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program\Multimedia\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "D:\Program\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: OpenOffice.org 2.4.lnk = D:\Program\OpenOffice.org 2.4\program\quickstart.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: OpenOffice.org 2.4.lnk = D:\Program\OpenOffice.org 2.4\program\quickstart.exe (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = D:\Program\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Orbit.lnk = D:\Program\Internet\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &Download by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Post Image to Blog - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - D:\Program\PicLensIE\cooliris.dll
O9 - Extra button: (no name) - {A573D71B-951B-4BAD-B8CC-708AE84769C9} - D:\Program\BumpTop\BTShExt.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1224867717703
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program\Delade filer\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program\Delade filer\InterVideo\DeviceService\DevSvc.exe
O23 - Service: DCPFLICS service (DCPFLICS) - Unknown owner - C:\Program\DCPFLICS\dcpflics.exe
O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - D:\Program\Bild\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: MySQL - Unknown owner - D:\Program\MySQL\MySQL.exe (file missing)
O23 - Service: Removable Storage Control Service (MYUSSER) - PMYUSSER - D:\Program\A.C. Element MyUSBOnly\MYUSSER.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SPM License Server (spmd) - mental images GmbH - C:\spm\spmdib.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program\Delade filer\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: NexTab (Wintab32) - Unknown owner - C:\WINDOWS\system32\Wintab32.exe

–
End of file - 10441 bytes
Hi Acuena,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


Could you please give me the report of your most recent Malwarebytes' scan"

You can find it by starting Mbam
Click on the Log tab
Find the most recent log and double click on it (it should be the one on the bottom of the list)
Copy/Paste that information here.
Hi Tomk!! Here is my latest Mban scan (Note that I translated it into English from Swedish): Malwarebytes' Anti-Malware 1.31 Database version: 1456 Windows 5.1.2600 Service Pack 3 2009-01-05 14:41:03 mbam-log-2009-01-05 (14-41-03).txt Scan type: Quick scan Objects scanned: 57827 Time elapsed: 3 minute(s), 27 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 4 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{d5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\tyshb36rfjdf.dll (Trojan.BHO) -> Quarantined and deleted successfully. C:\WINDOWS\system32.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\kernel32.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\\Lokala inställningar\Temp\winloggn.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
Acuena,

Please download SDFix and save it to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key repeatedly;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual user account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here. We also need you to post a new HijackThis log
Now I have ran the SDfix program and HicjackThiss again. The results are below.
Just got a question regarding the logg from SDfix. In the logg there is a line saying "please note that you need administrator rights to perform deep scan", does that mean that I choose the wrong user and need to redo the scan? If so just say the word and I do it right away.

SDFix logg:


SDFix: Version 1.240
Run by [removed] on 2009-01-12 at 23:45

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-12 23:54:45
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

disk error: C:\WINDOWS\system32\config\system, 0
scanning hidden registry entries …

disk error: C:\WINDOWS\system32\config\software, 0
disk error: C:\Documents and Settings\Johan Andersson\ntuser.dat, 0
scanning hidden files …

disk error: C:\WINDOWS\

please note that you need administrator rights to perform deep scan

Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program\\uTorrent\\uTorrent.exe"="C:\\Program\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"D:\\Program\\Bild\\Autodesk\\3ds Max 9\\3dsmax.exe"="D:\\Program\\Bild\\Autodesk\\3ds Max 9\\3dsmax.exe:*:Enabled:Autodesk 3ds Max 9 32-bit"
"D:\\Program\\Bild\\Autodesk\\Backburner\\monitor.exe"="D:\\Program\\Bild\\Autodesk\\Backburner\\monitor.exe:*:Enabled:backburner 2.3 monitor"
"D:\\Program\\Bild\\Autodesk\\Backburner\\manager.exe"="D:\\Program\\Bild\\Autodesk\\Backburner\\manager.exe:*:Enabled:backburner 2.3 manager"
"D:\\Program\\Bild\\Autodesk\\Backburner\\server.exe"="D:\\Program\\Bild\\Autodesk\\Backburner\\server.exe:*:Enabled:backburner 2.3 server"
"D:\\Program\\Spel\\FEAR\\FEAR.exe"="D:\\Program\\Spel\\FEAR\\FEAR.exe:*:Enabled:FEAR"
"D:\\Program\\Spel\\FEAR\\FEARMP.exe"="D:\\Program\\Spel\\FEAR\\FEARMP.exe:*:Enabled:FEAR"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"D:\\Program\\Verktyg\\UltraVnc\\vncviewer.exe"="D:\\Program\\Verktyg\\UltraVnc\\vncviewer.exe:*:Enabled:vncviewer.exe"
"D:\\Program\\Spel\\FEAR\\FEARXP\\FEARXP.exe"="D:\\Program\\Spel\\FEAR\\FEARXP\\FEARXP.exe:*:Enabled:FEARXP"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program\\Bonjour\\mDNSResponder.exe"="C:\\Program\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"D:\\Program\\Multimedia\\iTunes\\iTunes.exe"="D:\\Program\\Multimedia\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"D:\\PROGRAM\\KOMMUNIKATION\\SKYPE\\PHONE\\SKYPE.EXE"="D:\\PROGRAM\\KOMMUNIKATION\\SKYPE\\PHONE\\SKYPE.EXE:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :



Files with Hidden Attributes :

Mon 18 Aug 2008 15,202 A..H. — "C:\spm\spm-kf.bak"
Wed 27 Feb 2008 0 ..SH. — "C:\WINDOWS\SDE0F159F.tmp"
Mon 1 Jan 1990 45,056 ..SHR — "C:\WINDOWS\system32\KcrnadDrv.dll"
Mon 10 Mar 2008 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 2 Jan 2009 101,004 …H. — "C:\Documents and Settings\Johan Andersson\Application Data\Bump Technologies, Inc\BumpTop\scene.bump.bak"
Mon 24 Nov 2008 165,232 A..H. — "C:\Documents and Settings\Johan Andersson\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll"
Fri 19 Dec 2008 1,714 …HR — "C:\Documents and Settings\Johan Andersson\Application Data\SecuROM\UserData\securom_v7_01.bak"
Tue 30 Sep 2008 39,936 A..H. — "C:\Documents and Settings\Johan Andersson\Mina dokument\Snabbmappar\Mappar\FEAR hacks\data\hacks\pub\RxFinalHack\RxHack.TMP0"

Finished!

HijackThiss logg:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:01:11, on 2009-01-13
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Wintab32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe
C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program\Delade filer\Autodesk Shared\Service\AdskScSrv.exe
C:\Program\Delade filer\InterVideo\DeviceService\DevSvc.exe
C:\Program\DCPFLICS\dcpflics.exe
D:\Program\Diskeeper Corporation\Diskeeper\DkService.exe
D:\Program\Bild\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
D:\Program\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
D:\Program\A.C. Element MyUSBOnly\MYUSSER.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\spm\spmdib.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Delade filer\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\Program\Säkerhet\WinPatrol\winpatrol.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\Program\Backupp\Acronis\TrueImageMonitor.exe
D:\Program\Backupp\Acronis\TimounterMonitor.exe
C:\Program\Delade filer\Acronis\Schedule2\schedhlp.exe
D:\Program\Filhantering\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\ZPOINT32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\Delade filer\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\WINDOWS\system32\RUNDLL32.EXE
D:\Program\Säkerhet\ZoneAlarm\zlclient.exe
D:\Program\Multimedia\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program\Internet\Orbitdownloader\orbitdm.exe
D:\Program\Internet\Orbitdownloader\orbitnet.exe
D:\Program\OpenOffice.org 2.4\program\soffice.exe
D:\Program\OpenOffice.org 2.4\program\soffice.BIN
C:\Program\iPod\bin\iPodService.exe
D:\PROGRAM\KOMMUNIKATION\SKYPE\PHONE\SKYPE.EXE
D:\PROGRAM\EPOST\POPMAN\POPMAN.EXE
D:\Program\Internet\GreenBrowser\GreenBrowser.exe
D:\Program\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.whatthetech.com/forums.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9051
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - D:\Program\Internet\Orbitdownloader\GrabPro.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - D:\Program\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google; Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - D:\Program\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: BumpTop Explorer Bar - {32CA105A-BD6C-4AFC-B4D9-346262E9F483} - D:\Program\BumpTop\BTShExt.dll
O4 - HKLM\..\Run: [WinPatrol] D:\Program\Säkerhet\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TrueImageMonitor.exe] D:\Program\Backupp\Acronis\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] D:\Program\Backupp\Acronis\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program\Delade filer\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] D:\Program\Filhantering\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Acecad.Wtxpload] C:\WINDOWS\Acecad\Wtxpload.exe Acecad
O4 - HKLM\..\Run: [ZPOINT32] C:\WINDOWS\system32\ZPOINT32.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TkBellExe] "C:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" /source=HKLM
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program\Säkerhet\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program\Multimedia\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "D:\Program\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: OpenOffice.org 2.4.lnk = D:\Program\OpenOffice.org 2.4\program\quickstart.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: OpenOffice.org 2.4.lnk = D:\Program\OpenOffice.org 2.4\program\quickstart.exe (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = D:\Program\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Orbit.lnk = D:\Program\Internet\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &Download; by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab; video by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload; selected by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load; all by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Post Image to Blog - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - D:\Program\PicLensIE\cooliris.dll
O9 - Extra button: (no name) - {A573D71B-951B-4BAD-B8CC-708AE84769C9} - D:\Program\BumpTop\BTShExt.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1224867717703
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program\Delade filer\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program\Delade filer\InterVideo\DeviceService\DevSvc.exe
O23 - Service: DCPFLICS service (DCPFLICS) - Unknown owner - C:\Program\DCPFLICS\dcpflics.exe
O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - D:\Program\Bild\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: MySQL - Unknown owner - D:\Program\MySQL\MySQL.exe (file missing)
O23 - Service: Removable Storage Control Service (MYUSSER) - PMYUSSER - D:\Program\A.C. Element MyUSBOnly\MYUSSER.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SPM License Server (spmd) - mental images GmbH - C:\spm\spmdib.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program\Delade filer\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: NexTab (Wintab32) - Unknown owner - C:\WINDOWS\system32\Wintab32.exe

–
End of file - 10297 bytes
Acuena,

It sort of does mean that. However, we're going to run a couple of different scans so you won't need to re-run SDfix. However, please run them from an account with administrator privileges.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://www.bleepingcomputer.com/forums/topic114351.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
I was able to run Rooter but not ComboFix, all three links was dead :(

Here is the logg from Rooter thouge:

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Sempron™ Processor 3000+ )
BIOS : Default System BIOS
USER : Johan Andersson ( Administrator )
BOOT : Normal boot

Antivirus : ZoneAlarm Security Suite Antivirus 8.0.059.000 (Activated)
Firewall : ZoneAlarm Security Suite Firewall 8.0.059.000 (Activated)

A:\ (USB)
C:\ (Local Disk) - NTFS - Total:39 Go (Free:10 Go)
D:\ (Local Disk) - NTFS - Total:147 Go (Free:18 Go)
E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
F:\ (CD or DVD)
H:\ (Local Disk) - FAT32 - Total:465 Go (Free:151 Go)

2009-01-13| 2:51

———————-\\ Search..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.113.140,85.255.112.201
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.113.140,85.255.112.201
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}]
NameServer REG_SZ 85.255.113.140,85.255.112.201
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}]
NameServer REG_SZ 85.255.113.140,85.255.112.201
==> WAREOUT <==

———————-\\ Cracks & Keygens..

C:\DOCUME~1\JOHANA~1\Lokala inst„llningar\Temporary Internet Files\Content.IE5\GHRABHD1\Dapirates1-Part22CrackingRoutersWithHydraGTK122-225-895[1].jpg
C:\DOCUME~1\JOHANA~1\Lokala inst„llningar\Temporary Internet Files\Content.IE5\W5IBC1EF\Dapirates1-Part22CrackingRoutersWithHydraGTK122[1].flv
C:\DOCUME~1\JOHANA~1\Lokala inst„llningar\Temporary Internet Files\Content.IE5\WXQ70TMZ\Dapirates1-CrackingWindowsPasswordsUsingWindowsByHaRdy383-672-655[1].jpg
C:\DOCUME~1\JOHANA~1\Lokala inst„llningar\Temporary Internet Files\Content.IE5\X7H06784\hydra-hydra-gtk-basic-cracking-hacking[1].htm
C:\DOCUME~1\JOHANA~1\Mina dokument\Snabbmappar\Diverse\mIRC_6.31___Crack.4098116.TPB.torrent
C:\DOCUME~1\JOHANA~1\Mina dokument\Snabbmappar\Document\mIRC_6.31___Crack.4098116.TPB.torrent.lnk


1 - "C:\Rooter$\Rooter_1.txt" - 2009-01-13| 2:40

———————-\\ Scan completed at 2:51
Acuena,

You've got a few things going on there. My guess is that their related to those cracks. Sometimes this can be a bit messy. Let's see how we do.

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

  • :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\DOCUME~1\JOHANA~1\Lokala inst„llningar\Temporary Internet Files\Content.IE5\GHRABHD1\Dapirates1-Part22CrackingRoutersWithHydraGTK122-225-895[1].jpg
    C:\DOCUME~1\JOHANA~1\Lokala inst„llningar\Temporary Internet Files\Content.IE5\W5IBC1EF\Dapirates1-Part22CrackingRoutersWithHydraGTK122[1].flv
    C:\DOCUME~1\JOHANA~1\Lokala inst„llningar\Temporary Internet Files\Content.IE5\WXQ70TMZ\Dapirates1-CrackingWindowsPasswordsUsingWindowsByHaRdy383-672-655[1].jpg
    C:\DOCUME~1\JOHANA~1\Lokala inst„llningar\Temporary Internet Files\Content.IE5\X7H06784\hydra-hydra-gtk-basic-cracking-hacking[1].htm
    C:\DOCUME~1\JOHANA~1\Mina dokument\Snabbmappar\Diverse\mIRC_6.31___Crack.4098116.TPB.torrent
    C:\DOCUME~1\JOHANA~1\Mina dokument\Snabbmappar\Document\mIRC_6.31___Crack.4098116.TPB.torrent.lnk
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

    Next

    Please download SmitfraudFix

    Double-click SmitfraudFix.exe
    Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
    Please copy/paste the content of that report into your next reply.

    Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
I have run both OTMoveIt3 and SmitFraudFix with success now. Was not prepared that OTMoveIt3 would reboot my computer :) If you want the logg from OTMoveIt3 just post a note and il post it. Here is the logg from SmitFraudFix. SmitFraudFix v2.388 Scan done at 16:40:33,59, 2009-01-13 Run from C:\Documents and Settings\Johan Andersson\Skrivbord\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Wintab32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program\Delade filer\Autodesk Shared\Service\AdskScSrv.exe C:\Program\Delade filer\InterVideo\DeviceService\DevSvc.exe C:\Program\DCPFLICS\dcpflics.exe D:\Program\Diskeeper Corporation\Diskeeper\DkService.exe D:\Program\Bild\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe D:\Program\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe D:\Program\A.C. Element MyUSBOnly\MYUSSER.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Program\Delade filer\Acronis\Fomatik\TrueImageTryStartService.exe C:\Program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\notepad.exe D:\Program\Säkerhet\WinPatrol\winpatrol.exe C:\WINDOWS\SOUNDMAN.EXE D:\Program\Backupp\Acronis\TrueImageMonitor.exe D:\Program\Backupp\Acronis\TimounterMonitor.exe C:\Program\Delade filer\Acronis\Schedule2\schedhlp.exe D:\Program\Filhantering\PowerISO\PWRISOVM.EXE C:\WINDOWS\system32\ZPOINT32.exe C:\WINDOWS\system32\rundll32.exe C:\Program\Delade filer\Real\Update_OB\realsched.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe C:\WINDOWS\system32\RUNDLL32.EXE D:\Program\Säkerhet\ZoneAlarm\zlclient.exe D:\Program\Multimedia\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe D:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe D:\Program\Internet\Orbitdownloader\orbitdm.exe D:\Program\OpenOffice.org 2.4\program\soffice.exe D:\Program\Internet\Orbitdownloader\orbitnet.exe D:\Program\OpenOffice.org 2.4\program\soffice.BIN C:\Program\iPod\bin\iPodService.exe D:\PROGRAM\KOMMUNIKATION\SKYPE\PHONE\SKYPE.EXE D:\PROGRAM\EPOST\POPMAN\POPMAN.EXE D:\Program\Internet\GreenBrowser\GreenBrowser.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ C:\autorun.inf FOUND ! C:\resycled\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Johan Andersson »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\JOHANA~1\LOKALA~1\Temp »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Johan Andersson\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\JOHANA~1\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» D:\Program »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="Min aktuella startsida" »»»»»»»»»»»»»»»»»»»»»»»» o4Patch !!!Attention, following keys are not inevitably infected!!! o4Patch Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» IEDFix !!!Attention, following keys are not inevitably infected!!! IEDFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix !!!Attention, following keys are not inevitably infected!!! Agent.OMZ.Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» VACFix !!!Attention, following keys are not inevitably infected!!! VACFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» 404Fix !!!Attention, following keys are not inevitably infected!!! 404Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit"="C:\\WINDOWS\\system32\\userinit.exe," "System"="" »»»»»»»»»»»»»»»»»»»»»»»» RK »»»»»»»»»»»»»»»»»»»»»»»» DNS Your computer may be victim of a DNS Hijack: 85.255.x.x detected ! Description: NVIDIA nForce Networking Controller DNS Server Search Order: 85.255.113.140 DNS Server Search Order: 85.255.112.201 HKLM\SYSTEM\CCS\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CCS\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: NameServer=85.255.113.140,85.255.112.201 HKLM\SYSTEM\CS1\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS1\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: NameServer=85.255.113.140,85.255.112.201 HKLM\SYSTEM\CS2\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: NameServer=85.255.113.140,85.255.112.201 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=85.255.113.140,85.255.112.201 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.113.140,85.255.112.201 HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=85.255.113.140,85.255.112.201 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Acuena,

You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, double-click SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.

Then please try to run ComboFix per instructions on post #6
Here is the logg and a new HijackThis logg.
EDIT: Forgot to check if I could run ComboFix, I can download it now and are trying now. Posting a new post with the results.

SmitFraudFix:

SmitFraudFix v2.388

Scan done at 18:49:18,75, 2009-01-13
Run from C:\Documents and Settings\Johan Andersson\Skrivbord\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\autorun.inf Deleted
C:\resycled\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» 404Fix

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» RK


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: NameServer=85.255.113.140,85.255.112.201
HKLM\SYSTEM\CS1\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: NameServer=85.255.113.140,85.255.112.201
HKLM\SYSTEM\CS2\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: NameServer=85.255.113.140,85.255.112.201
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=85.255.113.140,85.255.112.201
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.113.140,85.255.112.201
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=85.255.113.140,85.255.112.201


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End




HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:00:23, on 2009-01-13
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Wintab32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe
C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program\Delade filer\Autodesk Shared\Service\AdskScSrv.exe
C:\Program\Delade filer\InterVideo\DeviceService\DevSvc.exe
C:\Program\DCPFLICS\dcpflics.exe
D:\Program\Diskeeper Corporation\Diskeeper\DkService.exe
D:\Program\Bild\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
D:\Program\Säkerhet\WinPatrol\winpatrol.exe
D:\Program\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
D:\Program\A.C. Element MyUSBOnly\MYUSSER.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Delade filer\Acronis\Fomatik\TrueImageTryStartService.exe
D:\Program\Backupp\Acronis\TrueImageMonitor.exe
C:\Program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe
D:\Program\Backupp\Acronis\TimounterMonitor.exe
C:\Program\Delade filer\Acronis\Schedule2\schedhlp.exe
D:\Program\Filhantering\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\ZPOINT32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\Delade filer\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\WINDOWS\system32\RUNDLL32.EXE
D:\Program\Säkerhet\ZoneAlarm\zlclient.exe
D:\Program\Multimedia\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program\Internet\Orbitdownloader\orbitdm.exe
D:\Program\Internet\Orbitdownloader\orbitnet.exe
D:\Program\OpenOffice.org 2.4\program\soffice.exe
D:\Program\OpenOffice.org 2.4\program\soffice.BIN
C:\Program\iPod\bin\iPodService.exe
D:\PROGRAM\KOMMUNIKATION\SKYPE\PHONE\SKYPE.EXE
D:\PROGRAM\EPOST\POPMAN\POPMAN.EXE
C:\WINDOWS\system32\wuauclt.exe
D:\Program\Skriva\UltraEdit\uedit32.exe
D:\Program\Internet\GreenBrowser\GreenBrowser.exe
D:\Program\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.whatthetech.com/forums.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9051
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - D:\Program\Internet\Orbitdownloader\GrabPro.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - D:\Program\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - D:\Program\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: BumpTop Explorer Bar - {32CA105A-BD6C-4AFC-B4D9-346262E9F483} - D:\Program\BumpTop\BTShExt.dll
O4 - HKLM\..\Run: [WinPatrol] D:\Program\Säkerhet\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TrueImageMonitor.exe] D:\Program\Backupp\Acronis\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] D:\Program\Backupp\Acronis\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program\Delade filer\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] D:\Program\Filhantering\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Acecad.Wtxpload] C:\WINDOWS\Acecad\Wtxpload.exe Acecad
O4 - HKLM\..\Run: [ZPOINT32] C:\WINDOWS\system32\ZPOINT32.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TkBellExe] "C:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" /source=HKLM
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program\Säkerhet\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program\Multimedia\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "D:\Program\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: OpenOffice.org 2.4.lnk = D:\Program\OpenOffice.org 2.4\program\quickstart.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: OpenOffice.org 2.4.lnk = D:\Program\OpenOffice.org 2.4\program\quickstart.exe (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = D:\Program\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Orbit.lnk = D:\Program\Internet\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &Download by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Post Image to Blog - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - D:\Program\PicLensIE\cooliris.dll
O9 - Extra button: (no name) - {A573D71B-951B-4BAD-B8CC-708AE84769C9} - D:\Program\BumpTop\BTShExt.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1224867717703
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: NameServer = 85.255.113.140,85.255.112.201
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.140,85.255.112.201
O17 - HKLM\System\CS1\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: NameServer = 85.255.113.140,85.255.112.201
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.113.140,85.255.112.201
O17 - HKLM\System\CS3\Services\Tcpip\..\{09692EA8-C7C0-4110-8EE6-C89313DABF8E}: NameServer = 85.255.113.140,85.255.112.201
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.140,85.255.112.201
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program\Delade filer\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program\Delade filer\InterVideo\DeviceService\DevSvc.exe
O23 - Service: DCPFLICS service (DCPFLICS) - Unknown owner - C:\Program\DCPFLICS\dcpflics.exe
O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - D:\Program\Bild\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: MySQL - Unknown owner - D:\Program\MySQL\MySQL.exe (file missing)
O23 - Service: Removable Storage Control Service (MYUSSER) - PMYUSSER - D:\Program\A.C. Element MyUSBOnly\MYUSSER.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SPM License Server (spmd) - mental images GmbH - C:\spm\spmdib.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program\Delade filer\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: NexTab (Wintab32) - Unknown owner - C:\WINDOWS\system32\Wintab32.exe

–
End of file - 11003 bytes
And here is my log from ComboFix:

ComboFix 09-01-12.04 - Johan Andersson 2009-01-13 19:27:57.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1053.18.1535.1051 [GMT 1:00]
Körs från: c:\documents and settings\Johan Andersson\Skrivbord\ComboFix.exe
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Outdated)
FW: ZoneAlarm Security Suite Firewall *disabled*
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\msqpdxnklydvir.sys
c:\windows\system32\drivers\msqpdxqaexvbat.sys
c:\windows\system32\msqpdxdvdmykkv.dll
c:\windows\system32\tmp.reg
D:\Autorun.inf
D:\resycled
d:\resycled\boot.com
G:\autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivrutiner/Tjänster )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_MSQPDXSERV.SYS


((((((((((((((((((((( Filer Skapade från 2008-12-13 till 2009-01-13 ))))))))))))))))))))))))))))))))))))
.

2009-01-13 18:47 . 2008-01-29 00:59 dr——- c:\documents and settings\Administratör\Start-meny
2009-01-13 18:47 . 2008-01-29 00:59 dr——- c:\documents and settings\Administratör\Start-meny
2009-01-13 18:47 . 2008-11-14 22:31 d——– c:\documents and settings\Administratör\Skrivbord
2009-01-13 18:47 . 2008-11-14 22:31 d——– c:\documents and settings\Administratör\Skrivbord
2009-01-13 18:47 . 2008-01-29 00:59 d–h—– c:\documents and settings\Administratör\Skrivare
2009-01-13 18:47 . 2008-01-29 00:59 d–h—– c:\documents and settings\Administratör\Skrivare
2009-01-13 18:47 . 2008-01-29 00:59 d–h—– c:\documents and settings\Administratör\Nätverket
2009-01-13 18:47 . 2008-01-29 00:59 d–h—– c:\documents and settings\Administratör\Nätverket
2009-01-13 18:47 . 2008-01-29 00:59 d——– c:\documents and settings\Administratör\Mina dokument
2009-01-13 18:47 . 2008-01-29 00:59 d——– c:\documents and settings\Administratör\Mina dokument
2009-01-13 18:47 . 2008-01-29 00:05 d–h—– c:\documents and settings\Administratör\Mallar
2009-01-13 18:47 . 2008-01-29 00:05 d–h—– c:\documents and settings\Administratör\Mallar
2009-01-13 18:47 . 2009-01-13 19:33 d–h—– c:\documents and settings\Administratör\Lokala inställningar
2009-01-13 18:47 . 2009-01-13 19:33 d–h—– c:\documents and settings\Administratör\Lokala inställningar
2009-01-13 18:47 . 2008-01-29 00:59 d——– c:\documents and settings\Administratör\Favoriter
2009-01-13 18:47 . 2008-01-29 00:59 d——– c:\documents and settings\Administratör\Favoriter
2009-01-13 18:47 . 2008-11-14 22:30 d——– c:\documents and settings\Administratör\Application Data\Bump Technologies, Inc
2009-01-13 18:47 . 2009-01-13 18:47 d——– c:\documents and settings\Administratör
2009-01-13 16:29 . 2009-01-13 16:29 d——– C:\_OTMoveIt
2009-01-13 02:39 . 2009-01-13 02:51 d——– C:\Rooter$
2009-01-12 23:44 . 2009-01-12 23:44 578,560 –a–c— c:\windows\system32\dllcache\user32.dll
2009-01-12 23:12 . 2009-01-12 23:54 d——– C:\SDFix
2009-01-05 19:35 . 2009-01-05 19:35 d——– d:\program\Trend Micro
2009-01-05 19:32 . 2009-01-05 19:32 d——– d:\program\ERUNT
2009-01-05 14:35 . 2009-01-05 14:35 d——– d:\program\Malwarebytes' Anti-Malware
2009-01-05 14:35 . 2009-01-05 14:35 d——– c:\documents and settings\Johan Andersson\Application Data\Malwarebytes
2009-01-05 14:35 . 2009-01-05 14:35 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-05 14:35 . 2008-12-03 19:59 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-05 14:35 . 2008-12-03 19:59 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-03 23:03 . 2009-01-12 23:40 d——– c:\windows\ERUNT
2009-01-03 23:03 . 2009-01-03 23:03 d——– C:\ERDNT
2009-01-03 23:02 . 2009-01-03 23:03 d——– C:\!FixIEDef
2009-01-02 23:54 . 2009-01-02 23:54 79 –a—— c:\windows\wininit.ini
2009-01-02 23:30 . 2009-01-02 23:30 46 –a—— c:\windows\p2hhr.bat
2009-01-02 17:43 . 2009-01-02 17:43 d——– c:\documents and settings\Johan Andersson\Application Data\Ace
2009-01-02 15:07 . 2009-01-09 21:58 38 –a—— c:\windows\AviSplitter.INI
2008-12-30 16:17 . 2008-12-30 16:17 d——– C:\Need4Video files
2008-12-30 15:57 . 2008-12-30 15:57 d——– d:\program\Essentials Codec Pack
2008-12-27 13:48 . 2008-12-27 13:48 d——– C:\HOVER
2008-12-26 14:22 . 2008-12-26 19:35 d——– c:\windows\SxsCaPendDel
2008-12-25 04:47 . 2008-05-08 02:03 453,632 –a—— c:\windows\system32\SetACL.ocx
2008-12-24 18:58 . 2008-12-24 18:58 d——– d:\program\CCleaner
2008-12-14 23:48 . 2008-12-14 23:48 d——– c:\documents and settings\LocalService\Start-meny
2008-12-14 16:55 . 2008-12-14 16:55 d——– d:\program\Diskeeper Corporation

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-13 18:39 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\Skype
2009-01-13 18:38 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\Orbit
2009-01-13 18:38 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\OpenOffice.org2
2009-01-13 18:34 2,504,048 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-01-13 18:34 189,124,128 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-01-13 17:56 17,359,967 —-a-w c:\windows\Internet Logs\tvDebug.zip
2009-01-13 01:50 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\uTorrent
2009-01-12 12:03 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-12 11:59 21,840 —-atw c:\windows\system32\SIntfNT.dll
2009-01-12 11:59 17,212 —-atw c:\windows\system32\SIntf32.dll
2009-01-12 11:59 12,067 —-atw c:\windows\system32\SIntf16.dll
2009-01-09 21:10 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\gtk-2.0
2009-01-08 21:19 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\teamspeak2
2009-01-06 17:45 ——— d—–w d:\program\QuickWebb
2009-01-05 15:09 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-03 12:58 ——— d–h–w d:\program\InstallShield Installation Information
2009-01-03 12:58 ——— d—–w d:\program\Spybot - Search & Destroy
2009-01-02 22:18 ——— d—–w d:\program\Spel
2009-01-02 01:26 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\Hamachi
2008-12-14 15:55 ——— d—–w d:\program\PeerGuardian2
2008-12-11 18:13 ——— d—–w d:\program\BumpTop
2008-12-03 19:42 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-03 19:41 ——— d—–w c:\program\Delade filer\Apple
2008-12-03 19:26 ——— d—–w d:\program\Safari
2008-11-30 12:22 25,280 —-a-w c:\windows\system32\drivers\hamachi.sys
2008-11-30 12:22 ——— d—–w d:\program\Hamachi
2008-11-30 12:07 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\PopMan
2008-11-08 19:09 695,578 —-a-w c:\windows\unins000.exe
2008-11-04 19:06 158,757 —-a-w c:\windows\Internet Logs\vsmon_2nd_2008_11_04_20_06_30_small.dmp.zip
2008-11-01 23:02 1,933,312 —-a-w c:\windows\Internet Logs\xDB1A.tmp
2008-10-30 01:24 42,320 —-a-w c:\windows\system32\xfcodec.dll
2008-10-28 22:29 440,832 —-a-w c:\windows\Internet Logs\xDB19.tmp
2008-10-26 18:20 107,888 —-a-w c:\windows\system32\CmdLineExt.dll
2008-10-25 23:50 2,235,392 —-a-w c:\windows\Internet Logs\xDB18.tmp
2008-03-02 01:59 428 —-a-w c:\documents and settings\Johan Andersson\scriptsOrganizer.dat
2008-02-03 00:50 22,328 —-a-w c:\documents and settings\Johan Andersson\Application Data\PnkBstrK.sys
1990-01-01 01:01 45,056 –sh–r c:\windows\system32\KcrnadDrv.dll
.

(((((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* tomma poster & legitima standardposter visas inte
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="d:\program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-06 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="d:\program\Säkerhet\WinPatrol\winpatrol.exe" [2008-01-27 316728]
"TrueImageMonitor.exe"="d:\program\Backupp\Acronis\TrueImageMonitor.exe" [2007-10-30 2595616]
"AcronisTimounterMonitor"="d:\program\Backupp\Acronis\TimounterMonitor.exe" [2007-10-30 909208]
"Acronis Scheduler2 Service"="c:\program\Delade filer\Acronis\Schedule2\schedhlp.exe" [2007-10-30 140568]
"PWRISOVM.EXE"="d:\program\Filhantering\PowerISO\PWRISOVM.EXE" [2008-01-20 217088]
"Acecad.Wtxpload"="c:\windows\Acecad\Wtxpload.exe" [2005-04-30 57344]
"ZPOINT32"="c:\windows\system32\ZPOINT32.exe" [2002-07-04 20480]
"TkBellExe"="c:\program\Delade filer\Real\Update_OB\realsched.exe" [2008-02-05 185896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"FinePrint Dispatcher v5"="c:\windows\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" [2005-04-08 483328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"ZoneAlarm Client"="d:\program\Säkerhet\ZoneAlarm\zlclient.exe" [2008-10-09 981904]
"QuickTime Task"="c:\program\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="d:\program\Multimedia\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"DiskeeperSystray"="d:\program\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-06-07 319488]
"SoundMan"="SOUNDMAN.EXE" [2005-09-22 c:\windows\soundman.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Johan Andersson\Start-meny\Program\Autostart\
OpenOffice.org 2.4.lnk - d:\program\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]

c:\documents and settings\All Users\Start-meny\Program\Autostart\
Adobe Gamma Loader.lnk - c:\program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe [2008-01-29 113664]
Orbit.lnk - d:\program\Internet\Orbitdownloader\orbitdm.exe [2008-02-03 1690824]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{AC0A0B68-633C-91D2-8901-3A81E135D25A}"= "c:\windows\system32\KcrnadDrv.dll" [1990-01-01 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
"msacm.dvacm"= c:\program\DELADE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= c:\program\DELADE~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= c:\program\DELADE~1\ULEADS~1\MPEG\ulmp3acm.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start-meny^Program^Autostart^YouTube Uploader for CASIO.lnk]
path=c:\documents and settings\All Users\Start-meny\Program\Autostart\YouTube Uploader for CASIO.lnk
backup=c:\windows\pss\YouTube Uploader for CASIO.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
–a—— 2007-03-03 13:12 341488 d:\program\Ulead Systems\Ulead VideoStudio 11\uvPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program\\uTorrent\\uTorrent.exe"=
"d:\\Program\\Bild\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"d:\\Program\\Bild\\Autodesk\\Backburner\\monitor.exe"=
"d:\\Program\\Bild\\Autodesk\\Backburner\\manager.exe"=
"d:\\Program\\Bild\\Autodesk\\Backburner\\server.exe"=
"d:\\Program\\Spel\\FEAR\\FEAR.exe"=
"d:\\Program\\Spel\\FEAR\\FEARMP.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program\\Verktyg\\UltraVnc\\vncviewer.exe"=
"d:\\Program\\Spel\\FEAR\\FEARXP\\FEARXP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program\\Bonjour\\mDNSResponder.exe"=
"d:\\Program\\Multimedia\\iTunes\\iTunes.exe"=
"d:\\PROGRAM\\KOMMUNIKATION\\SKYPE\\PHONE\\SKYPE.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800

R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2006-09-26 21920]
R4 MYUSSER;Removable Storage Control Service;d:\program\A.C. Element MyUSBOnly\MYUSSER.EXE [2008-04-19 49152]
S3 atidgllk;atidgllk;c:\windows\atidgllk.sys [2008-04-02 5376]
S3 kwwalpgr;kwwalpgr;\??\c:\docume~1\JOHANA~1\LOKALA~1\Temp\kwwalpgr.sys –> c:\docume~1\JOHANA~1\LOKALA~1\Temp\kwwalpgr.sys [?]
S3 mKernel;mKernel;\??\g:\program\MHS\FGIROBOC –> g:\program\MHS\FGIROBOC [?]
S3 W2acehid;Acecad HID;c:\windows\system32\drivers\w2acehid.sys [2008-02-01 23552]
S3 Wtcls2k;Wtcls2k;c:\windows\system32\drivers\wtcls2k.sys [2008-02-01 12800]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;d:\program\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{93c9d92c-1894-11dd-80c4-00138f7a8f68}]
\Shell\AutoRun\command - H:\backup.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b658598d-9097-11dd-beb0-00138f7a8f68}]
\Shell\AutoRun\command - wscript.exe NewVirusRemoval.vbs
\Shell\open\Command - wscript.exe NewVirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fab0f50f-e525-11dc-b545-00138f7a8f68}]
\Shell\AutoRun\command - H:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fcaa0084-ce00-11dc-a0b7-00138f7a8f68}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com h:
\Shell\Open\command - h:\resycled\boot.com h:

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{582610B8-E496-4813-993C-4B027173FE38}]
d:\program\PixiePack Codec Pack\InstallerHelper.exe
.
Innehållet i mappen 'Schemalagda aktiviteter'

2009-01-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -

Notify-WBSrv - (no file)


.
——- Extra genomsökning ——-
.
uStart Page = hxxp://forums.whatthetech.com/forums.html
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyServer = http=127.0.0.1:9051
uInternet Settings,ProxyOverride = ;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: &Download by Orbit - d:\program\Internet\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - d:\program\Internet\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - d:\program\Internet\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - d:\program\Internet\Orbitdownloader\orbitmxt.dll/202
IE: Post Image to Blog - d:\program\ImageShackToolbar\ImageShackToolbar.dll/5003
IE: Tag This Image - d:\program\ImageShackToolbar\ImageShackToolbar.dll/5002
IE: Transload Image to ImageShack - d:\program\ImageShackToolbar\ImageShackToolbar.dll/5004
IE: Upload All Images to ImageShack - d:\program\ImageShackToolbar\ImageShackToolbar.dll/5000
IE: Upload Image to ImageShack - d:\program\ImageShackToolbar\ImageShackToolbar.dll/5001

- c:\windows\Downloaded Program Files\ImageShackToolbar.osd

- hxxp://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
FF - ProfilePath - c:\documents and settings\Johan Andersson\Application Data\Mozilla\Firefox\Profiles\uwdtmgp5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.animate.se/|http://www.unrealuta.net/index.php
FF - component: c:\documents and settings\Johan Andersson\Application Data\Mozilla\Firefox\Profiles\uwdtmgp5.default\extensions\{7378B8C2-FC38-41b8-A8C9-875D1F5B0A24}\components\NativeComponent.dll
FF - component: c:\documents and settings\Johan Andersson\Application Data\Mozilla\Firefox\Profiles\uwdtmgp5.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\program\Java\jre1.6.0_03\bin\npjava11.dll
FF - plugin: c:\program\Java\jre1.6.0_03\bin\npjava12.dll
FF - plugin: c:\program\Java\jre1.6.0_03\bin\npjava13.dll
FF - plugin: c:\program\Java\jre1.6.0_03\bin\npjava14.dll
FF - plugin: c:\program\Java\jre1.6.0_03\bin\npjava32.dll
FF - plugin: c:\program\Java\jre1.6.0_03\bin\npjpi160_03.dll
FF - plugin: c:\program\Java\jre1.6.0_03\bin\npoji610.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin6.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin7.dll
FF - plugin: c:\program\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF - plugin: c:\program\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: d:\program\Multimedia\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\program\Multimedial\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: d:\program\Multimedial\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: d:\program\Multimedial\RealPlayer\Netscape6\nprpjplug.dll

—- FIREFOX POLICIES —-
d:\program\Internet\FireFox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-13 19:39:43
Windows 5.1.2600 Service Pack 3 NTFS

genomsöker dolda processer …

genomsöker dolda autostartpunkter …

genomsöker dolda filer …

genomsökningen avslutades lyckosamt
dolda filer: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mKernel]
"ImagePath"="\??\g:\program\MHS\FGIROBOC"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"d:\program\MySQL\MySQL Server 5.0\bin\mysqld-nt\" –defaults-file=\"d:\program\MySQL\MySQL Server 5.0\my.ini\" MySQL"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSSdk23]
"ImagePath"="\??\c:\windows\system32\Drivers\PsSdk23.drv"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1177238915-1960408961-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Electronic Arts\C*o*m*m*a*n*d* *a*n*d* *C*o*n*q*u*e*r* *3* *T*i*b*e*r*i*u*m* *W*a*r*s*"!\Support]
"Order"=hex:08,00,00,00,02,00,00,00,94,02,00,00,01,00,00,00,04,00,00,00,9a,00,
00,00,00,00,00,00,8c,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,7a,00,32,\

[HKEY_USERS\S-1-5-21-1177238915-1960408961-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47DA2F9C-DF84-1A90-76A1-122458EB9704}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaecboaglljlhihbkn"=hex:6b,61,69,65,66,6d,61,67,63,70,67,6f,62,66,6b,67,63,66,
68,6e,6a,70,00,00
"haochmldkpdacndh"=hex:6b,61,69,65,66,6d,61,67,63,70,67,6f,62,66,6b,67,63,66,
68,6e,6a,70,00,00
"haicbmpehlgjbkhf"=hex:70,61,70,62,63,70,64,62,6b,6c,6b,64,64,61,68,6f,6c,6d,
61,6f,65,62,6c,70,6c,65,68,6c,66,63,62,62,00,ff
"haicbmpecmghlfco"=hex:70,62,68,63,62,62,69,6f,68,68,6b,61,64,6a,61,6a,63,6e,
70,6a,66,6c,61,63,66,65,68,6c,6f,65,65,66,66,67,65,67,6f,6d,6a,62,6b,6a,69,\

[HKEY_USERS\S-1-5-21-1177238915-1960408961-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:54,fe,20,bc,8d,44,da,4b,f4,76,70,56,c7,dc,e4,97,8f,d4,71,88,d1,c1,5a,
e5,5c,6e,71,a5,1b,74,f8,56,dc,c6,1d,43,ec,73,ff,6a,b3,79,46,2d,05,56,91,fc,\
"??"=hex:db,66,a2,c8,75,06,b6,e9,3d,6c,88,aa,9a,b5,cd,b7
.
——————— DLLer installerade under pågående processer ———————

- - - - - - - > 'lsass.exe'(748)
c:\windows\system32\relog_ap.dll

- - - - - - - > 'explorer.exe'(1524)
d:\program\Säkerhet\WinPatrol\PATROLPRO.DLL
c:\windows\system32\KcrnadDrv.dll
.
———————— Andra pågående processer ————————
.
c:\windows\system32\wintab32.exe
c:\windows\system32\ZoneLabs\vsmon.exe
c:\windows\system32\ZoneLabs\avsys\ScanningProcess.exe
c:\program\Delade filer\Acronis\Schedule2\schedul2.exe
c:\program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program\Delade filer\Autodesk Shared\Service\AdskScSrv.exe
c:\program\Delade filer\InterVideo\DeviceService\DevSvc.exe
c:\program\DCPFLICS\DCPFLICS.exe
d:\program\Diskeeper Corporation\Diskeeper\DkService.exe
d:\program\Bild\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
c:\program\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
d:\program\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
c:\windows\system32\nvsvc32.exe
c:\program\Delade filer\Acronis\Fomatik\TrueImageTryStartService.exe
c:\program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
d:\program\OpenOffice.org 2.4\program\soffice.exe
d:\program\OpenOffice.org 2.4\program\soffice.bin
c:\program\iPod\bin\iPodService.exe
d:\program\Kommunikation\Skype\Phone\Skype.exe
d:\program\Internet\Orbitdownloader\orbitnet.exe
d:\program\Epost\PopMan\PopMan.exe
.
**************************************************************************
.
Sluttid: 2009-01-13 19:45:17 - datorn startades om
ComboFix-quarantined-files.txt 2009-01-13 18:45:04

Före genomsökningen: 12,630,151,168 byte ledigt
Efter genomsökningen: 12,692,144,128 byte ledigt

WindowsXP-KB310994-SP2-Pro-BootDisk-SVE.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

345
Acuena,

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 11…allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u11-windows-i586-p.exe to install the newest version.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    c:\windows\p2hhr.bat
    c:\windows\system32\KcrnadDrv.dll
    c:\docume~1\JOHANA~1\LOKALA~1\Temp\kwwalpgr.sys
    g:\program\MHS\FGIROBOC 
    
    Folder::
    h:\resycled
    
    Registry::
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{AC0A0B68-633C-91D2-8901-3A81E135D25A}"=-
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{93c9d92c-1894-11dd-80c4-00138f7a8f68}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b658598d-9097-11dd-beb0-00138f7a8f68}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fab0f50f-e525-11dc-b545-00138f7a8f68}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fcaa0084-ce00-11dc-a0b7-00138f7a8f68}]
    
    Driver::
    kwwalpgr
    mKernel
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please start your Malwarebytes'
Update it
Run a new scan
Please paste results here.


Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Right now my computer purrs like a kitty and behaves as it shoukd, have not seen any of those popups.

ComboFix log:

ComboFix 09-01-13.03 - Johan Andersson 2009-01-14 4:38:16.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1053.18.1535.950 [GMT 1:00]
Körs från: c:\documents and settings\Johan Andersson\Skrivbord\ComboFix.exe
Använda kommandoväxlar :: c:\documents and settings\Johan Andersson\Skrivbord\CFScript.TXT
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Outdated)
FW: ZoneAlarm Security Suite Firewall *disabled*
* Skapade en ny återställningspunkt

FILE ::
c:\docume~1\JOHANA~1\LOKALA~1\Temp\kwwalpgr.sys
c:\windows\p2hhr.bat
c:\windows\system32\KcrnadDrv.dll
g:\program\MHS\FGIROBOC
.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\p2hhr.bat
c:\windows\system32\KcrnadDrv.dll

.
((((((((((((((((((((((((((((((((((((((( Drivrutiner/Tjänster )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_KWWALPGR
——-\Legacy_MKERNEL
——-\Service_kwwalpgr
——-\Service_mKernel


((((((((((((((((((((( Filer Skapade från 2008-12-14 till 2009-01-14 ))))))))))))))))))))))))))))))))))))
.

2009-01-14 04:34 . 2009-01-14 04:34 410,984 –a—— c:\windows\system32\deploytk.dll
2009-01-14 04:34 . 2009-01-14 04:34 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-01-13 18:47 . 2008-01-29 00:59 dr——- c:\documents and settings\Administratör\Start-meny
2009-01-13 18:47 . 2008-01-29 00:59 dr——- c:\documents and settings\Administratör\Start-meny
2009-01-13 18:47 . 2008-11-14 22:31 d——– c:\documents and settings\Administratör\Skrivbord
2009-01-13 18:47 . 2008-11-14 22:31 d——– c:\documents and settings\Administratör\Skrivbord
2009-01-13 18:47 . 2008-01-29 00:59 d–h—– c:\documents and settings\Administratör\Skrivare
2009-01-13 18:47 . 2008-01-29 00:59 d–h—– c:\documents and settings\Administratör\Skrivare
2009-01-13 18:47 . 2008-01-29 00:59 d–h—– c:\documents and settings\Administratör\Nätverket
2009-01-13 18:47 . 2008-01-29 00:59 d–h—– c:\documents and settings\Administratör\Nätverket
2009-01-13 18:47 . 2008-01-29 00:59 d——– c:\documents and settings\Administratör\Mina dokument
2009-01-13 18:47 . 2008-01-29 00:59 d——– c:\documents and settings\Administratör\Mina dokument
2009-01-13 18:47 . 2008-01-29 00:05 d–h—– c:\documents and settings\Administratör\Mallar
2009-01-13 18:47 . 2008-01-29 00:05 d–h—– c:\documents and settings\Administratör\Mallar
2009-01-13 18:47 . 2009-01-14 04:42 d–h—– c:\documents and settings\Administratör\Lokala inställningar
2009-01-13 18:47 . 2009-01-14 04:42 d–h—– c:\documents and settings\Administratör\Lokala inställningar
2009-01-13 18:47 . 2008-01-29 00:59 d——– c:\documents and settings\Administratör\Favoriter
2009-01-13 18:47 . 2008-01-29 00:59 d——– c:\documents and settings\Administratör\Favoriter
2009-01-13 18:47 . 2008-11-14 22:30 d——– c:\documents and settings\Administratör\Application Data\Bump Technologies, Inc
2009-01-13 18:47 . 2009-01-13 18:47 d——– c:\documents and settings\Administratör
2009-01-13 16:29 . 2009-01-13 16:29 d——– C:\_OTMoveIt
2009-01-13 02:39 . 2009-01-13 02:51 d——– C:\Rooter$
2009-01-12 23:44 . 2009-01-12 23:44 578,560 –a–c— c:\windows\system32\dllcache\user32.dll
2009-01-12 23:12 . 2009-01-12 23:54 d——– C:\SDFix
2009-01-05 19:35 . 2009-01-05 19:35 d——– d:\program\Trend Micro
2009-01-05 19:32 . 2009-01-05 19:32 d——– d:\program\ERUNT
2009-01-05 14:35 . 2009-01-05 14:35 d——– d:\program\Malwarebytes' Anti-Malware
2009-01-05 14:35 . 2009-01-05 14:35 d——– c:\documents and settings\Johan Andersson\Application Data\Malwarebytes
2009-01-05 14:35 . 2009-01-05 14:35 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-05 14:35 . 2008-12-03 19:59 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-05 14:35 . 2008-12-03 19:59 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-03 23:03 . 2009-01-12 23:40 d——– c:\windows\ERUNT
2009-01-03 23:03 . 2009-01-03 23:03 d——– C:\ERDNT
2009-01-03 23:02 . 2009-01-03 23:03 d——– C:\!FixIEDef
2009-01-02 23:54 . 2009-01-02 23:54 79 –a—— c:\windows\wininit.ini
2009-01-02 17:43 . 2009-01-02 17:43 d——– c:\documents and settings\Johan Andersson\Application Data\Ace
2009-01-02 15:07 . 2009-01-09 21:58 38 –a—— c:\windows\AviSplitter.INI
2008-12-30 16:17 . 2008-12-30 16:17 d——– C:\Need4Video files
2008-12-30 15:57 . 2008-12-30 15:57 d——– d:\program\Essentials Codec Pack
2008-12-27 13:48 . 2008-12-27 13:48 d——– C:\HOVER
2008-12-26 14:22 . 2008-12-26 19:35 d——– c:\windows\SxsCaPendDel
2008-12-25 04:47 . 2008-05-08 02:03 453,632 –a—— c:\windows\system32\SetACL.ocx
2008-12-24 18:58 . 2008-12-24 18:58 d——– d:\program\CCleaner
2008-12-14 23:48 . 2008-12-14 23:48 d——– c:\documents and settings\LocalService\Start-meny
2008-12-14 16:55 . 2008-12-14 16:55 d——– d:\program\Diskeeper Corporation

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-14 03:48 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\OpenOffice.org2
2009-01-14 03:47 191,339,040 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-01-14 03:47 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\Orbit
2009-01-14 03:43 2,564,408 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-01-14 03:34 ——— d—–w d:\program\Java
2009-01-14 03:23 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\Skype
2009-01-13 01:50 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\uTorrent
2009-01-12 12:03 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-09 21:10 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\gtk-2.0
2009-01-08 21:19 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\teamspeak2
2009-01-06 17:45 ——— d—–w d:\program\QuickWebb
2009-01-05 15:09 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-03 12:58 ——— d–h–w d:\program\InstallShield Installation Information
2009-01-03 12:58 ——— d—–w d:\program\Spybot - Search & Destroy
2009-01-02 22:18 ——— d—–w d:\program\Spel
2009-01-02 01:26 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\Hamachi
2008-12-14 15:55 ——— d—–w d:\program\PeerGuardian2
2008-12-11 18:13 ——— d—–w d:\program\BumpTop
2008-12-03 19:42 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-03 19:41 ——— d—–w c:\program\Delade filer\Apple
2008-12-03 19:26 ——— d—–w d:\program\Safari
2008-11-30 12:22 25,280 —-a-w c:\windows\system32\drivers\hamachi.sys
2008-11-30 12:22 ——— d—–w d:\program\Hamachi
2008-11-30 12:07 ——— d—–w c:\documents and settings\Johan Andersson\Application Data\PopMan
2008-11-08 19:09 695,578 —-a-w c:\windows\unins000.exe
2008-03-02 01:59 428 —-a-w c:\documents and settings\Johan Andersson\scriptsOrganizer.dat
2008-02-03 00:50 22,328 —-a-w c:\documents and settings\Johan Andersson\Application Data\PnkBstrK.sys
.

((((((((((((((((((((((((((((( snapshot@2009-01-13_19.43.20.00 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-13 22:57:22 135,168 —-a-w c:\windows\system32\java.exe
+ 2009-01-14 03:34:36 144,792 —-a-w c:\windows\system32\java.exe
- 2007-12-13 22:57:24 135,168 —-a-w c:\windows\system32\javaw.exe
+ 2009-01-14 03:34:36 144,792 —-a-w c:\windows\system32\javaw.exe
- 2007-12-13 23:59:16 139,264 —-a-w c:\windows\system32\javaws.exe
+ 2009-01-14 03:34:36 148,888 —-a-w c:\windows\system32\javaws.exe
- 2009-01-13 18:36:01 696,288 —-a-w c:\windows\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2009-01-14 03:48:04 700,936 —-a-w c:\windows\system32\ZoneLabs\avsys\bases\sfdb.dat
- 2008-12-31 17:52:33 10,586,951 —-a-w c:\windows\system32\ZoneLabs\spyware.dat
+ 2009-01-13 19:07:55 10,707,916 —-a-w c:\windows\system32\ZoneLabs\spyware.dat
- 2008-10-24 18:51:43 9,900,691 —-a-w c:\windows\system32\ZoneLabs\spyware0.dat
+ 2009-01-13 19:07:27 10,696,658 —-a-w c:\windows\system32\ZoneLabs\spyware0.dat
- 2009-01-03 06:39:25 23,448,064 —-a-w c:\windows\system32\ZoneLabs\zlqrtdb.dat
+ 2009-01-13 21:42:21 23,448,064 —-a-w c:\windows\system32\ZoneLabs\zlqrtdb.dat
+ 2009-01-14 03:45:13 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_564.dat
+ 2009-01-14 03:45:17 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_56c.dat
+ 2009-01-14 03:47:49 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_c20.dat
.
(((((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* tomma poster & legitima standardposter visas inte
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="d:\program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-06 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="d:\program\Säkerhet\WinPatrol\winpatrol.exe" [2008-01-27 316728]
"TrueImageMonitor.exe"="d:\program\Backupp\Acronis\TrueImageMonitor.exe" [2007-10-30 2595616]
"AcronisTimounterMonitor"="d:\program\Backupp\Acronis\TimounterMonitor.exe" [2007-10-30 909208]
"Acronis Scheduler2 Service"="c:\program\Delade filer\Acronis\Schedule2\schedhlp.exe" [2007-10-30 140568]
"PWRISOVM.EXE"="d:\program\Filhantering\PowerISO\PWRISOVM.EXE" [2008-01-20 217088]
"Acecad.Wtxpload"="c:\windows\Acecad\Wtxpload.exe" [2005-04-30 57344]
"ZPOINT32"="c:\windows\system32\ZPOINT32.exe" [2002-07-04 20480]
"TkBellExe"="c:\program\Delade filer\Real\Update_OB\realsched.exe" [2008-02-05 185896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"FinePrint Dispatcher v5"="c:\windows\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" [2005-04-08 483328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"ZoneAlarm Client"="d:\program\Säkerhet\ZoneAlarm\zlclient.exe" [2008-10-09 981904]
"QuickTime Task"="c:\program\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="d:\program\Multimedia\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"DiskeeperSystray"="d:\program\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-06-07 319488]
"SunJavaUpdateSched"="d:\program\Java\jre6\bin\jusched.exe" [2009-01-14 136600]
"SoundMan"="SOUNDMAN.EXE" [2005-09-22 c:\windows\soundman.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Johan Andersson\Start-meny\Program\Autostart\
OpenOffice.org 2.4.lnk - d:\program\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]

c:\documents and settings\All Users\Start-meny\Program\Autostart\
Adobe Gamma Loader.lnk - c:\program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe [2008-01-29 113664]
Orbit.lnk - d:\program\Internet\Orbitdownloader\orbitdm.exe [2008-02-03 1690824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
"msacm.dvacm"= c:\program\DELADE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= c:\program\DELADE~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= c:\program\DELADE~1\ULEADS~1\MPEG\ulmp3acm.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start-meny^Program^Autostart^YouTube Uploader for CASIO.lnk]
path=c:\documents and settings\All Users\Start-meny\Program\Autostart\YouTube Uploader for CASIO.lnk
backup=c:\windows\pss\YouTube Uploader for CASIO.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
–a—— 2007-03-03 13:12 341488 d:\program\Ulead Systems\Ulead VideoStudio 11\uvPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program\\uTorrent\\uTorrent.exe"=
"d:\\Program\\Bild\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"d:\\Program\\Bild\\Autodesk\\Backburner\\monitor.exe"=
"d:\\Program\\Bild\\Autodesk\\Backburner\\manager.exe"=
"d:\\Program\\Bild\\Autodesk\\Backburner\\server.exe"=
"d:\\Program\\Spel\\FEAR\\FEAR.exe"=
"d:\\Program\\Spel\\FEAR\\FEARMP.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program\\Verktyg\\UltraVnc\\vncviewer.exe"=
"d:\\Program\\Spel\\FEAR\\FEARXP\\FEARXP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program\\Bonjour\\mDNSResponder.exe"=
"d:\\Program\\Multimedia\\iTunes\\iTunes.exe"=
"d:\\PROGRAM\\KOMMUNIKATION\\SKYPE\\PHONE\\SKYPE.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800

R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2006-09-26 21920]
R4 MYUSSER;Removable Storage Control Service;d:\program\A.C. Element MyUSBOnly\MYUSSER.EXE [2008-04-19 49152]
S3 atidgllk;atidgllk;c:\windows\atidgllk.sys [2008-04-02 5376]
S3 W2acehid;Acecad HID;c:\windows\system32\drivers\w2acehid.sys [2008-02-01 23552]
S3 Wtcls2k;Wtcls2k;c:\windows\system32\drivers\wtcls2k.sys [2008-02-01 12800]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;d:\program\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{582610B8-E496-4813-993C-4B027173FE38}]
d:\program\PixiePack Codec Pack\InstallerHelper.exe
.
Innehållet i mappen 'Schemalagda aktiviteter'

2009-01-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
——- Extra genomsökning ——-
.
uStart Page = hxxp://forums.whatthetech.com/forums.html
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyServer = http=127.0.0.1:9051
uInternet Settings,ProxyOverride = ;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: &Download by Orbit - d:\program\Internet\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - d:\program\Internet\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - d:\program\Internet\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - d:\program\Internet\Orbitdownloader\orbitmxt.dll/202
IE: Post Image to Blog - d:\program\ImageShackToolbar\ImageShackToolbar.dll/5003
IE: Tag This Image - d:\program\ImageShackToolbar\ImageShackToolbar.dll/5002
IE: Transload Image to ImageShack - d:\program\ImageShackToolbar\ImageShackToolbar.dll/5004
IE: Upload All Images to ImageShack - d:\program\ImageShackToolbar\ImageShackToolbar.dll/5000
IE: Upload Image to ImageShack - d:\program\ImageShackToolbar\ImageShackToolbar.dll/5001

- c:\windows\Downloaded Program Files\ImageShackToolbar.osd

- hxxp://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
FF - ProfilePath - c:\documents and settings\Johan Andersson\Application Data\Mozilla\Firefox\Profiles\uwdtmgp5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.animate.se/|http://www.unrealuta.net/index.php
FF - component: c:\documents and settings\Johan Andersson\Application Data\Mozilla\Firefox\Profiles\uwdtmgp5.default\extensions\{7378B8C2-FC38-41b8-A8C9-875D1F5B0A24}\components\NativeComponent.dll
FF - component: c:\documents and settings\Johan Andersson\Application Data\Mozilla\Firefox\Profiles\uwdtmgp5.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin6.dll
FF - plugin: c:\program\QuickTime\Plugins\npqtplugin7.dll
FF - plugin: c:\program\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF - plugin: c:\program\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: d:\program\Multimedia\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\program\Multimedial\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: d:\program\Multimedial\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: d:\program\Multimedial\RealPlayer\Netscape6\nprpjplug.dll

—- FIREFOX POLICIES —-
d:\program\Internet\FireFox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-14 04:47:29
Windows 5.1.2600 Service Pack 3 NTFS

genomsöker dolda processer …

genomsöker dolda autostartpunkter …

genomsöker dolda filer …

genomsökningen avslutades lyckosamt
dolda filer: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"d:\program\MySQL\MySQL Server 5.0\bin\mysqld-nt\" –defaults-file=\"d:\program\MySQL\MySQL Server 5.0\my.ini\" MySQL"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSSdk23]
"ImagePath"="\??\c:\windows\system32\Drivers\PsSdk23.drv"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1177238915-1960408961-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Electronic Arts\C*o*m*m*a*n*d* *a*n*d* *C*o*n*q*u*e*r* *3* *T*i*b*e*r*i*u*m* *W*a*r*s*"!\Support]
"Order"=hex:08,00,00,00,02,00,00,00,94,02,00,00,01,00,00,00,04,00,00,00,9a,00,
00,00,00,00,00,00,8c,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,7a,00,32,\

[HKEY_USERS\S-1-5-21-1177238915-1960408961-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47DA2F9C-DF84-1A90-76A1-122458EB9704}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaecboaglljlhihbkn"=hex:6b,61,69,65,66,6d,61,67,63,70,67,6f,62,66,6b,67,63,66,
68,6e,6a,70,00,00
"haochmldkpdacndh"=hex:6b,61,69,65,66,6d,61,67,63,70,67,6f,62,66,6b,67,63,66,
68,6e,6a,70,00,00
"haicbmpehlgjbkhf"=hex:70,61,70,62,63,70,64,62,6b,6c,6b,64,64,61,68,6f,6c,6d,
61,6f,65,62,6c,70,6c,65,68,6c,66,63,62,62,00,ff
"haicbmpecmghlfco"=hex:70,62,68,63,62,62,69,6f,68,68,6b,61,64,6a,61,6a,63,6e,
70,6a,66,6c,61,63,66,65,68,6c,6f,65,65,66,66,67,65,67,6f,6d,6a,62,6b,6a,69,\

[HKEY_USERS\S-1-5-21-1177238915-1960408961-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:54,fe,20,bc,8d,44,da,4b,f4,76,70,56,c7,dc,e4,97,8f,d4,71,88,d1,c1,5a,
e5,5c,6e,71,a5,1b,74,f8,56,dc,c6,1d,43,ec,73,ff,6a,b3,79,46,2d,05,56,91,fc,\
"??"=hex:db,66,a2,c8,75,06,b6,e9,3d,6c,88,aa,9a,b5,cd,b7
.
——————— DLLer installerade under pågående processer ———————

- - - - - - - > 'lsass.exe'(712)
c:\windows\system32\relog_ap.dll
.
———————— Andra pågående processer ————————
.
c:\windows\system32\wintab32.exe
c:\program\Delade filer\Acronis\Schedule2\schedul2.exe
c:\program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program\Delade filer\Autodesk Shared\Service\AdskScSrv.exe
c:\program\Delade filer\InterVideo\DeviceService\DevSvc.exe
c:\program\DCPFLICS\DCPFLICS.exe
d:\program\Diskeeper Corporation\Diskeeper\DkService.exe
d:\program\Java\jre6\bin\jqs.exe
d:\program\Bild\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
c:\program\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
d:\program\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
c:\windows\system32\nvsvc32.exe
c:\program\Delade filer\Acronis\Fomatik\TrueImageTryStartService.exe
c:\program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
d:\program\OpenOffice.org 2.4\program\soffice.exe
d:\program\OpenOffice.org 2.4\program\soffice.bin
d:\program\Internet\Orbitdownloader\orbitnet.exe
c:\program\iPod\bin\iPodService.exe
d:\program\Kommunikation\Skype\Phone\Skype.exe
d:\program\Epost\PopMan\PopMan.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Sluttid: 2009-01-14 4:52:35 - datorn startades om
ComboFix-quarantined-files.txt 2009-01-14 03:52:28
ComboFix2.txt 2009-01-13 18:45:53

Före genomsökningen: 12 283 707 392 byte ledigt
Efter genomsökningen: 12,471,214,080 byte ledigt

326


Mbam log:

Malwarebytes' Anti-Malware 1.32
Database version: 1649
Windows 5.1.2600 Service Pack 3

2009-01-14 11:57:36
mbam-log-2009-01-14 (11-57-36).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 249230
Time elapsed: 2 hour(s), 4 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


HijackThiss log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:59:09, on 2009-01-14
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Wintab32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe
C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program\Delade filer\Autodesk Shared\Service\AdskScSrv.exe
C:\Program\Delade filer\InterVideo\DeviceService\DevSvc.exe
C:\Program\DCPFLICS\dcpflics.exe
D:\Program\Diskeeper Corporation\Diskeeper\DkService.exe
D:\Program\Java\jre6\bin\jqs.exe
D:\Program\Bild\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
D:\Program\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
D:\Program\A.C. Element MyUSBOnly\MYUSSER.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Delade filer\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\Program\Säkerhet\WinPatrol\winpatrol.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\Program\Backupp\Acronis\TrueImageMonitor.exe
D:\Program\Backupp\Acronis\TimounterMonitor.exe
C:\Program\Delade filer\Acronis\Schedule2\schedhlp.exe
D:\Program\Filhantering\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\ZPOINT32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\Delade filer\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\WINDOWS\system32\RUNDLL32.EXE
D:\Program\Multimedia\iTunes\iTunesHelper.exe
D:\Program\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program\Internet\Orbitdownloader\orbitdm.exe
D:\Program\OpenOffice.org 2.4\program\soffice.exe
D:\Program\OpenOffice.org 2.4\program\soffice.BIN
D:\Program\Internet\Orbitdownloader\orbitnet.exe
C:\Program\iPod\bin\iPodService.exe
D:\PROGRAM\KOMMUNIKATION\SKYPE\PHONE\SKYPE.EXE
D:\PROGRAM\EPOST\POPMAN\POPMAN.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
D:\Program\Säkerhet\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\Program\Internet\GreenBrowser\GreenBrowser.exe
D:\Program\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\System32\svchost.exe
D:\Program\Skriva\UltraEdit\uedit32.exe
D:\Program\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.whatthetech.com/forums.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9051
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - D:\Program\Internet\Orbitdownloader\GrabPro.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - D:\Program\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - D:\Program\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: BumpTop Explorer Bar - {32CA105A-BD6C-4AFC-B4D9-346262E9F483} - D:\Program\BumpTop\BTShExt.dll
O4 - HKLM\..\Run: [WinPatrol] D:\Program\Säkerhet\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TrueImageMonitor.exe] D:\Program\Backupp\Acronis\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] D:\Program\Backupp\Acronis\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program\Delade filer\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] D:\Program\Filhantering\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Acecad.Wtxpload] C:\WINDOWS\Acecad\Wtxpload.exe Acecad
O4 - HKLM\..\Run: [ZPOINT32] C:\WINDOWS\system32\ZPOINT32.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TkBellExe] "C:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" /source=HKLM
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program\Säkerhet\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program\Multimedia\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "D:\Program\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: OpenOffice.org 2.4.lnk = D:\Program\OpenOffice.org 2.4\program\quickstart.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: OpenOffice.org 2.4.lnk = D:\Program\OpenOffice.org 2.4\program\quickstart.exe (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = D:\Program\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Orbit.lnk = D:\Program\Internet\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &Download by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Program\Internet\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Post Image to Blog - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://D:\Program\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - D:\Program\PicLensIE\cooliris.dll
O9 - Extra button: (no name) - {A573D71B-951B-4BAD-B8CC-708AE84769C9} - D:\Program\BumpTop\BTShExt.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1224867717703
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program\Delade filer\Acronis\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program\Delade filer\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program\Delade filer\InterVideo\DeviceService\DevSvc.exe
O23 - Service: DCPFLICS service (DCPFLICS) - Unknown owner - C:\Program\DCPFLICS\dcpflics.exe
O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program\Java\jre6\bin\jqs.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - D:\Program\Bild\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: MySQL - Unknown owner - D:\Program\MySQL\MySQL.exe (file missing)
O23 - Service: Removable Storage Control Service (MYUSSER) - PMYUSSER - D:\Program\A.C. Element MyUSBOnly\MYUSSER.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SPM License Server (spmd) - mental images GmbH - C:\spm\spmdib.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program\Delade filer\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: NexTab (Wintab32) - Unknown owner - C:\WINDOWS\system32\Wintab32.exe

–
End of file - 11105 bytes
Acuena,

Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.

  • Make sure you have an Internet Connection.
  • Download OTCleanIt to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTCleanUp to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI