This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hijack This Log - please help! can't get onto

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there. i noticed redirects in firefox, iexplorer, aim and skype over the last 24 hours. i'm on a pc/vista/trendmicro antivirus.

i really appreciate any and all help, as i'd love to fix this to figure out how i can get back to work. :/

thanks in advance!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:20:47 PM, on 1/8/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WTablet\Wacom_TabletUser.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Owner\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\Owner\AppData\Local\Temp\lsass.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Users\Owner\Desktop\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [{7ABCACD8-3F1E-EB4A-995A-4D0B73EC4F57}] "C:\Users\Owner\AppData\Local\Temp\IXP008.TMP\WMPupdate.exe" /r
O4 - HKLM\..\Run: [SYSTEM.rt32] C:\Users\Owner\AppData\Local\Temp\lsass.exe
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [StartCCC] "C:\Program Files\ATI" Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [RunSpySweeperScheduleAtStartup] "C:\Windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{562807D3-12E1-4214-B2D7-680F190A2229}
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Simplify Media] "C:\Program Files\Simplify Media\SimplifyMedia.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = C:\Program Files\Dropbox\dropbox.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MRI_DISABLED
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.ffffound.com
O15 - Trusted Zone: http://www.megapixel.net
O15 - Trusted Zone: http://assets.stepinsidedesign.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{027494C8-8CF0-4E9B-A7A6-6692662BF5D4}: Domain = jupitermedia.lan
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = jupitermedia.lan,jupitermedia.lan,jupitermedia.lan
O17 - HKLM\System\CS1\Services\Tcpip\..\{027494C8-8CF0-4E9B-A7A6-6692662BF5D4}: Domain = jupitermedia.lan
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = jupitermedia.lan,jupitermedia.lan
O17 - HKLM\System\CS2\Services\Tcpip\..\{027494C8-8CF0-4E9B-A7A6-6692662BF5D4}: Domain = jupitermedia.lan
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = jupitermedia.lan,jupitermedia.lan,jupitermedia.lan
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Oz128 Driver\o2flash.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\Windows\system32\Wacom_Tablet.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 11346 bytes
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through the instructions before starting to follow them to make sure you understand everything you have to do.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Apologies in the delay in a response. We are overwhelmed with logs at the moment and there aren't enough helpers to go around.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.

Thanks.
Thank-you so much for your reply!

My browser is being hijacked on google searches, mostly redirecting me to other search pages, and google searches will randomly come up without links. I am also unable to update my windows defender or trendmicro antivirus updates. i could not access the malwarebytes link as i was instructed below. i ran it through http://downforeveryoneorjustme.com, and it is not shown as a valid site.

Please find below my DDS.txt log, and my Attach.zip file has been added as an attachment.

Thanks again.


DDS (Ver_09-01-18.01) - NTFSx86
Run by [removed] at 11:07:55.73 on Mon 01/19/2009
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_11
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1789.854 [GMT -5:00]

AV: Trend Micro AntiVirus *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Program Files\O2Micro Oz128 Driver\o2flash.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\Wacom_Tablet.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Windows\system32\taskeng.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\WTablet\Wacom_TabletUser.exe
C:\Windows\system32\Wacom_Tablet.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Owner\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskeng.exe
C:\Users\Owner\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.ca/
uSEARCH PAGE = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.us.acer.yahoo.com
mDefault_Page_URL = hxxp://en.us.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: MRI_DISABLED - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No File
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [Sidebar] "c:\program files\windows sidebar\sidebar.exe" /autoRun
uRun: [StartCCC] "c:\program files\ati" technologies\ati.ace\core-static\CLIStart.exe
uRun: [Acer Tour Reminder] c:\acer\acertour\Reminder.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [RunSpySweeperScheduleAtStartup] "c:\windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{562807D3-12E1-4214-B2D7-680F190A2229}
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Simplify Media] "c:\program files\simplify media\SimplifyMedia.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [UfSeAgnt.exe] "c:\program files\trend micro\internet security\UfSeAgnt.exe"
mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: []
mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [{7ABCACD8-3F1E-EB4A-995A-4D0B73EC4F57}] "c:\users\owner\appdata\local\temp\ixp008.tmp\WMPupdate.exe" /r
mRun: [SYSTEM.rt32] c:\users\owner\appdata\local\temp\lsass.exe
StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\program files\dropbox\dropbox.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{4c271126-c295-4828-a901-5910ae0c258b}\Icon3E5562ED7.ico
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mri_di~1\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
Trusted Zone: ffffound.com\www
Trusted Zone: megapixel.net\www
Trusted Zone: stepinsidedesign.com\assets
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\mzinexth.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\program files\mozilla firefox\components\iamfamous.dll
FF - component: c:\users\owner\appdata\roaming\mozilla\firefox\profiles\mzinexth.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============

R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2007-4-3 39680]
R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2007-4-2 35712]
R4 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\cyberlink\powerdvd\000.fcl [2007-12-19 13560]
R4 Maxtor Sync Service;Maxtor Service;c:\program files\maxtor\sync\SyncServices.exe [2007-9-28 156976]
R4 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2008-2-14 52240]
R4 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2007-9-28 36368]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2008-10-6 15656]

=============== Created Last 30 ================

2009-01-09 14:36 6,200 a——- c:\windows\system32\INT13EXT.VXD
2009-01-09 14:36 –d—– c:\program files\PC Inspector File Recovery
2009-01-09 14:16 56 a—h— c:\windows\system32\ezsidmv.dat
2009-01-08 17:14 –d—– c:\program files\Lavasoft
2009-01-08 17:13 –d—– c:\programdata\Lavasoft
2009-01-08 17:11 –d—– c:\program files\common files\Wise Installation Wizard
2009-01-07 13:03 –d—– c:\users\owner\.housecall6.6
2009-01-06 18:33 –dshr– C:\resycled
2008-12-22 12:19 634 a——- c:\windows\system32\MAPISVC.INF
2008-12-22 12:18 –d—– c:\program files\Ontrack

==================== Find3M ====================

2008-11-10 05:43 410,984 a——- c:\windows\system32\deploytk.dll
2008-10-31 22:44 52,736 a——- c:\windows\apppatch\iebrshim.dll
2008-10-31 22:44 2,154,496 a——- c:\windows\apppatch\AcGenral.dll
2008-10-31 22:44 541,696 a——- c:\windows\apppatch\AcLayers.dll
2008-10-31 22:44 460,288 a——- c:\windows\apppatch\AcSpecfc.dll
2008-10-31 22:44 173,056 a——- c:\windows\apppatch\AcXtrnal.dll
2008-10-31 22:44 28,672 a——- c:\windows\system32\Apphlpdm.dll
2008-10-31 20:21 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2008-10-29 01:29 2,927,104 a——- c:\windows\explorer.exe
2008-10-21 22:57 241,152 a——- c:\windows\system32\PortableDeviceApi.dll
2008-10-21 20:22 2,048 a——- c:\windows\system32\tzres.dll
2008-10-07 08:53 86,016 a——- c:\windows\inf\infstor.dat
2008-10-07 08:53 51,200 a——- c:\windows\inf\infpub.dat
2008-10-07 08:53 143,360 a——- c:\windows\inf\infstrng.dat
2008-09-05 09:17 174 a–sh— c:\program files\desktop.ini
2008-09-05 09:04 665,600 a——- c:\windows\inf\drvindex.dat
2007-09-10 18:34 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2007-09-10 18:34 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2007-09-10 18:34 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2007-09-10 18:34 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2009-01-19 11:09 262,144 a–sh— c:\windows\serviceprofiles\networkservice\NTUSER.DAT

============= FINISH: 11:10:03.74 ===============

Attachments:

  • [attachment removed: Attach.zip]
Hi.

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.

If this doesn't work either, have you got access to another computer and a memory stick with which you can transfer files over to the infected computer? If so, please download ComboFix to a clean computer and transfer it to the infected, then run it. Otherwise, let me know and we'll find another way round.

Thanks.
ComboFix 09-01-19.03 - Owner 2009-01-19 16:35:51.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1789.1051 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
AV: Trend Micro AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Mozilla Firefox\components\iamfamous.dll
C:\resycled
c:\resycled\boot.com
c:\users\Owner\AppData\Local\Temp\lsass.exe
c:\windows\system32\drivers\msqpdxwwvqpcvq.sys
c:\windows\system32\msqpdxpircanuc.dll
c:\windows\Temp\log.txt
D:\resycled
d:\resycled\boot.com

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_MSQPDXSERV.SYS
——-\Service_MSQPDXSERV.SYS


((((((((((((((((((((((((( Files Created from 2008-12-19 to 2009-01-19 )))))))))))))))))))))))))))))))
.

2009-01-19 16:16 . 2009-01-19 16:21 d——– C:\ComboFix
2009-01-09 14:36 . 2009-01-09 14:36 d——– c:\program files\PC Inspector File Recovery
2009-01-09 14:36 . 2002-02-18 18:40 6,200 –a—— c:\windows\System32\INT13EXT.VXD
2009-01-09 14:16 . 2009-01-09 14:16 56 –ah—– c:\windows\System32\ezsidmv.dat
2009-01-08 23:18 . 2009-01-08 23:18 d——– c:\program files\ERUNT
2009-01-08 17:14 . 2009-01-08 17:14 d——– c:\program files\Lavasoft
2009-01-08 17:13 . 2009-01-08 17:23 d——– c:\users\All Users\Lavasoft
2009-01-08 17:13 . 2009-01-08 17:23 d——– c:\programdata\Lavasoft
2009-01-08 17:11 . 2009-01-08 17:11 d——– c:\program files\Common Files\Wise Installation Wizard
2009-01-07 15:17 . 2009-01-08 01:46 d——– c:\program files\Trillian
2009-01-07 13:03 . 2009-01-07 13:21 d——– c:\users\Owner\.housecall6.6
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Videos
2008-12-25 14:24 . 2006-11-02 05:23 d——– c:\users\Mcx1\Saved Games
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Pictures
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Music
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Links
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Downloads
2008-12-25 14:24 . 2008-12-25 14:24 dr——- c:\users\Mcx1\Documents
2008-12-25 14:24 . 2008-12-25 14:25 d–h—– c:\users\Mcx1\AppData
2008-12-25 14:24 . 2008-12-25 14:24 d——– c:\users\Mcx1
2008-12-22 12:19 . 2001-03-02 11:41 634 –a—— c:\windows\System32\MAPISVC.INF
2008-12-22 12:18 . 2009-01-07 10:11 d——– c:\program files\Ontrack

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-19 21:35 ——— d—–w c:\users\Owner\AppData\Roaming\WTablet
2009-01-19 03:54 ——— d—–w c:\users\Owner\AppData\Roaming\skypePM
2009-01-19 03:54 ——— d—–w c:\users\Owner\AppData\Roaming\Skype
2009-01-19 03:53 ——— d—–w c:\users\Owner\AppData\Roaming\Dropbox
2009-01-09 19:36 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-09 19:25 ——— d—–w c:\program files\TaskCoach
2009-01-08 19:59 ——— d—–w c:\users\Owner\AppData\Roaming\uTorrent
2009-01-07 17:47 ——— d—–w c:\program files\Common Files\AOL
2009-01-02 14:01 ——— d—–w c:\program files\Mozilla Thunderbird
2008-12-22 19:56 ——— d—–w c:\program files\Java
2008-12-19 20:00 ——— d—–w c:\programdata\FLEXnet
2008-12-19 19:36 ——— d—–w c:\users\Owner\AppData\Roaming\NCH Swift Sound
2008-12-19 19:36 ——— d—–w c:\programdata\Viewpoint
2008-12-19 19:36 ——— d—–w c:\program files\NCH Swift Sound
2008-12-19 19:35 ——— d—–w c:\program files\DivX
2008-12-12 05:46 ——— d—–w c:\program files\Windows Mail
2008-11-23 14:22 ——— d—–w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-23 14:22 ——— d—–w c:\program files\iTunes
2008-11-23 14:21 ——— d—–w c:\program files\iPod
2008-11-23 14:21 ——— d—–w c:\program files\Common Files\Apple
2008-11-23 14:19 ——— d—–w c:\program files\QuickTime
2008-11-10 10:43 410,984 —-a-w c:\windows\System32\deploytk.dll
2008-11-01 03:44 541,696 —-a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 —-a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 —-a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 28,672 —-a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:44 2,154,496 —-a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 —-a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 01:21 4,240,384 —-a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-29 06:29 2,927,104 —-a-w c:\windows\explorer.exe
2008-10-22 03:57 241,152 —-a-w c:\windows\System32\PortableDeviceApi.dll
2008-10-22 01:22 2,048 —-a-w c:\windows\System32\tzres.dll
2008-10-21 05:25 296,960 —-a-w c:\windows\System32\gdi32.dll
2008-10-21 05:25 1,645,568 —-a-w c:\windows\System32\connect.dll
2008-09-05 14:17 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2008-06-19 19:51 143360 –a—— c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2008-06-19 19:51 143360 –a—— c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2008-06-19 19:51 143360 –a—— c:\program files\Dropbox\DropboxExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"RunSpySweeperScheduleAtStartup"="c:\windows\system32\msfeedssync.exe" [2008-01-19 12800]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Simplify Media"="c:\program files\Simplify Media\SimplifyMedia.exe" [2008-10-15 5613576]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-09-06 169264]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"Adobe_ID0EYTHM"="c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 1884160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-17 c:\windows\RtHDVCpl.exe]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\program files\Dropbox\dropbox.exe [2008-07-03 8767575]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
VPN Client.lnk - c:\windows\Installer\{4C271126-C295-4828-A901-5910AE0C258B}\Icon3E5562ED7.ico [2008-09-08 6144]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-04-13 415072]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\MRI_DISABLED
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-09-10 535336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
–a—— 2007-02-07 19:21 54832 c:\program files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSet]
–a—— 2007-04-25 16:47 45056 c:\windows\PLFSet.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
——— 2007-03-15 00:01 71216 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
–a—— 2006-11-10 15:35 90112 c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E87E10E6-607C-4C76-8E3E-A0DAEB82EC3F}"= c:\program files\CyberLink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{6A759421-33E0-4E26-8A06-F1965CF848A0}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{240C7D58-A421-48B5-BFA3-FF1975EDEF8D}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{98511BB7-AC96-476D-938E-A3A0050D85FB}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{E13DE3F5-A8B0-4E6D-9DAB-6BDD2DD8D84D}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{C2BB2A4C-3AB5-4163-8BC4-4DCC232F7129}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C98D39D4-DDB0-44A2-9E59-02DB96E28B1F}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{E93CAF6A-3787-4246-B057-83349F3FD40D}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{ECDFDD91-0221-4035-AFB5-571E90852F4A}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{9F307CDF-D310-433C-B133-454EA024C5AE}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{97F3FE01-E32C-4CBB-ABB4-64A66EBBB183}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{FD8F2145-725A-487F-BA6E-E068AE65082C}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{5070C06C-1D38-4555-BD95-EFBB69EAEC61}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{0995ACC1-808C-45EF-A616-7674E5E0D180}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{F4C5A106-7349-4EF2-AE8D-F60F6D00BA35}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{04B5FFD7-7EF4-4D7F-A632-C377C0A4A898}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{06F876BE-78F4-4D88-9C19-1B9C5D952E15}c:\\program files\\mirc\\mirc.exe"= UDP:c:\program files\mirc\mirc.exe:mIRC
"UDP Query User{CEB36888-70AE-46B6-97D3-141A365B8D55}c:\\program files\\mirc\\mirc.exe"= TCP:c:\program files\mirc\mirc.exe:mIRC
"{6F5B6776-1299-4352-BA3F-64BC664DD84C}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{00FA71D1-77B6-4385-B67C-5A659CBE228E}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"TCP Query User{D21F129E-05AA-49F0-80E6-A58063C839AA}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{958EE9C0-8F87-4AAE-A9F1-D5BFE184E6F3}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"{B13CDBBA-47BB-49F8-8C13-8888AFCDE9A8}"= UDP:3703:Adobe Version Cue CS3 Server
"{02B1DD75-0F20-435B-BD96-10781A85B8E5}"= UDP:3704:Adobe Version Cue CS3 Server
"{CE2B38A5-4908-41FC-BCAC-77FFA8FB8EA8}"= UDP:50900:Adobe Version Cue CS3 Server
"{DA3D0563-E7F8-4592-8407-07A260AB8A69}"= UDP:50901:Adobe Version Cue CS3 Server
"{80330BAF-B3EB-483E-94AF-E810EF6527E4}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{741DA650-4F15-430B-B01A-9446CCF12B4A}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{488EA232-7349-4F8B-BF7A-1A0B5199F54A}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{616BEBB8-A52E-4552-8183-3BE2FEE90CB8}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{7C343614-2B03-4F80-9FEE-C61B6225E3D8}"= TCP:62515:vpn
"{C7D5728D-DE2B-4650-B66F-4151C0D17BB2}"= TCP:10000:vpn1
"TCP Query User{D06C4765-9B7E-42ED-B004-5A5DE1AD6751}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{A1669D33-B90F-4FCD-AD99-3C431B397F47}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"TCP Query User{EADF93A5-72AE-429D-AB84-A0B344F24853}c:\\program files\\crossloop\\crossloopconnect.exe"= UDP:c:\program files\crossloop\crossloopconnect.exe:CrossLoop - Simple Secure Screen Sharing
"UDP Query User{8DD1EB09-8F5B-4A29-B176-05DEED3A7D0D}c:\\program files\\crossloop\\crossloopconnect.exe"= TCP:c:\program files\crossloop\crossloopconnect.exe:CrossLoop - Simple Secure Screen Sharing
"{1AC56B75-D75C-4973-857A-590D51AC2BFC}"= UDP:c:\program files\Cisco Systems\VPN Client\ipsecdialer.exe:ipsecdialer.exe
"{E0B922AC-6B7D-4A51-86DF-28CDC2D32CF5}"= TCP:c:\program files\Cisco Systems\VPN Client\ipsecdialer.exe:ipsecdialer.exe
"{9BD1B4D1-5DF5-4A25-B53C-9EC2BD1AB276}"= UDP:c:\program files\Cisco Systems\VPN Client\vpngui.exe:vpngui
"{C325F49B-24C9-4185-B7BB-BECDACCF218F}"= TCP:c:\program files\Cisco Systems\VPN Client\vpngui.exe:vpngui
"{6CEA28DF-39AF-46D2-A7AC-9910E4AD0A74}"= UDP:c:\program files\Cisco Systems\VPN Client\vpnclient.exe:vpnclient
"{082B33CA-EB15-49B8-9B74-0BAF49E39C99}"= TCP:c:\program files\Cisco Systems\VPN Client\vpnclient.exe:vpnclient
"TCP Query User{65073DFC-387F-47B8-A202-B1948B1F4D54}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"UDP Query User{37475A7E-AC04-4476-9E93-36A3A1F78E21}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"{6A879FF1-FAC5-4CD2-9EE4-CA8BE83D87D4}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{046873A2-6672-4CFA-A4BE-DCB9ABD6150B}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{287E0296-FA80-4604-AD0B-D4962A1CE4B9}c:\\program files\\simplify media\\simplifymedia.exe"= UDP:c:\program files\simplify media\simplifymedia.exe:Simplify Media
"UDP Query User{02C4F824-DAE5-4BA5-977F-91D9D84C3D29}c:\\program files\\simplify media\\simplifymedia.exe"= TCP:c:\program files\simplify media\simplifymedia.exe:Simplify Media
"{1CFCAC39-0FB9-4646-91E7-7B749037A2B5}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{E66EDF58-2A3D-4B63-A212-A6D26519AE77}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{D039383D-2689-4C64-B10B-41E3606A970E}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{8E3AB21D-8415-49F2-BE66-B554D4E17DBE}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{2F29F264-EA24-4B1E-9208-AE51A0E916EE}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP000.TMP\adobe.exe:TCP
"{3165DB0A-E0B8-47B7-BF6A-A42E3B95C28D}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP000.TMP\adobe.exe:TCP
"{7E9F1F85-1B1C-4D52-A827-CFF28ABD1610}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP003.TMP\adobe.exe:TCP
"{64A82E9A-4A1F-4267-8E5B-E0C2B6F3571E}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP003.TMP\adobe.exe:TCP
"{D1865ABA-FBBD-4662-A4FE-14DA5FF95AC0}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP007.TMP\adobe.exe:TCP
"{5C64C674-0690-404D-8D46-0CD960FEABF1}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP007.TMP\adobe.exe:TCP
"{548B18D8-48F7-46EB-8C09-359AB280A6F3}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP012.TMP\adobe.exe:TCP
"{74B5972D-28A2-4D20-8708-8CDC9B20360C}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP012.TMP\adobe.exe:TCP
"{D17BF34F-2896-407A-85D6-6D514B0E1529}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP001.TMP\adobe.exe:TCP
"{0F862BB8-CC03-4F38-9E00-3D320A7B7BAD}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP001.TMP\adobe.exe:TCP
"{D8343A8E-062C-438E-A75D-48F4DC9568A3}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP006.TMP\adobe.exe:TCP
"{5FB6AD1F-B219-44C1-8B9A-05B247A609C7}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP006.TMP\adobe.exe:TCP
"TCP Query User{59C24D90-EE94-42E6-AE92-9C5E1179946E}c:\\program files\\trillian\\trillian.exe"= UDP:c:\program files\trillian\trillian.exe:Trillian
"UDP Query User{FAAFD621-79F0-408E-9E22-2B3A66758A7D}c:\\program files\\trillian\\trillian.exe"= TCP:c:\program files\trillian\trillian.exe:Trillian

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP000.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP000.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP003.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP003.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP007.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP007.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP012.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP012.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP001.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP001.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP006.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP006.TMP\adobe.exe:*:Enabled:Windows Messanger

R0 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [2007-04-03 39680]
R0 O2SDRDR;O2SDRDR;c:\windows\System32\drivers\o2sd.sys [2007-04-02 35712]
R3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-02-02 648456]
R4 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\000.fcl [2007-12-19 06:53:51 13560]
R4 TabletServiceWacom;TabletServiceWacom;c:\windows\System32\Wacom_Tablet.exe [2008-10-06 2748200]
R4 tmevtmgr;tmevtmgr;c:\windows\System32\drivers\tmevtmgr.sys [2008-02-14 52240]
R4 tmpreflt;tmpreflt;c:\windows\System32\drivers\tmpreflt.sys [2007-09-28 36368]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\System32\drivers\wacmoumonitor.sys [2008-10-06 15656]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7619f12c-ebbf-11dc-a302-001d7213f26c}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe uc.vbs
.
Contents of the 'Scheduled Tasks' folder

2009-01-19 c:\windows\Tasks\User_Feed_Synchronization-{562807D3-12E1-4214-B2D7-680F190A2229}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 02:33]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Acer Tour Reminder - c:\acer\AcerTour\Reminder.exe
MSConfigStartUp-Acer Tour Reminder - c:\acer\AcerTour\Reminder.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mStart Page = hxxp://en.us.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: www.ffffound.com
Trusted Zone: www.megapixel.net
Trusted Zone: assets.stepinsidedesign.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mzinexth.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mzinexth.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-19 16:39:55
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************
.
Completion time: 2009-01-19 16:43:04
ComboFix-quarantined-files.txt 2009-01-19 21:42:59

Pre-Run: 7,903,387,648 bytes free
Post-Run: 8,488,640,512 bytes free

286 — E O F — 2009-01-05 17:09:27


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:47:31 PM, on 1/19/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\WTablet\Wacom_TabletUser.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\Explorer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\Owner\Desktop\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O1 - Hosts: 63.146.109.223 assets.stepinsidedesign.com:8080
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [StartCCC] "C:\Program Files\ATI" Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [RunSpySweeperScheduleAtStartup] "C:\Windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{562807D3-12E1-4214-B2D7-680F190A2229}
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Simplify Media] "C:\Program Files\Simplify Media\SimplifyMedia.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Dropbox.lnk = C:\Program Files\Dropbox\dropbox.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MRI_DISABLED
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.ffffound.com
O15 - Trusted Zone: http://www.megapixel.net
O15 - Trusted Zone: http://assets.stepinsidedesign.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{027494C8-8CF0-4E9B-A7A6-6692662BF5D4}: Domain = jupitermedia.lan
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = jupitermedia.lan,jupitermedia.lan,jupitermedia.lan,jupitermedia.lan
O17 - HKLM\System\CS1\Services\Tcpip\..\{027494C8-8CF0-4E9B-A7A6-6692662BF5D4}: Domain = jupitermedia.lan
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = jupitermedia.lan,jupitermedia.lan,jupitermedia.lan,jupitermedia.lan
O17 - HKLM\System\CS2\Services\Tcpip\..\{027494C8-8CF0-4E9B-A7A6-6692662BF5D4}: Domain = jupitermedia.lan
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = jupitermedia.lan,jupitermedia.lan,jupitermedia.lan,jupitermedia.lan
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Oz128 Driver\o2flash.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\Windows\system32\Wacom_Tablet.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 9452 bytes



many thanks for your attention.
Hi :)

Open HijackThis. Hit Do A System Scan Only. Place a check next to the following items (if present):
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 63.146.109.223 assets.stepinsidedesign.com:8080
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O15 - Trusted Zone: http://www.ffffound.com
O15 - Trusted Zone: http://www.megapixel.net
O15 - Trusted Zone: http://assets.stepinsidedesign.com

Note: I have highlighted some items in blue. If you recognize these items as being legitimate or added them yourself, do not check them.

Close all browsers and windows except for HijackThis and click Fix Checked.


1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
c:\windows\System32\ezsidmv.dat

FileLook::
c:\program files\Dropbox\DropboxExt.dll 
c:\program files\Dropbox\Dropbox.exe

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7619f12c-ebbf-11dc-a302-001d7213f26c}]

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please right click Internet Explorer on your desktop and then select "Run As Administrator". Next, go to Kaspersky website and perform an online antivirus scan.

NOTE: Internet Explorer will temporarily have administrator privileges, this is required for the scan but dangerous for normal surfing so do NOT open any other websites in IE until after the scan has finished and this window has been closed.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Also, please give a detailed description of how your computer is running and behaving at the moment, listing any remaining problems.

Thanks.
Please find below the requested logs. I've noticed an improvement with Google, as my gmail will now allow forwarding again and, so far, I haven't had any search page redirects. :) I was also able to download trendmicro & windows defender updates.

What is the prognosis, dr? Am I gonna dai?

Thanks so much!


ComboFix 09-01-19.03 - Owner 2009-01-19 23:55:32.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1789.1085 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
AV: Trend Micro AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\windows\System32\ezsidmv.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\msqpdxsrctubjv.sys
c:\windows\System32\ezsidmv.dat
c:\windows\system32\msqpdxhiymycbp.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_MSQPDXSERV.SYS


((((((((((((((((((((((((( Files Created from 2008-12-20 to 2009-01-20 )))))))))))))))))))))))))))))))
.

2009-01-19 16:16 . 2009-01-19 16:21 d——– C:\ComboFix
2009-01-09 14:36 . 2009-01-09 14:36 d——– c:\program files\PC Inspector File Recovery
2009-01-09 14:36 . 2002-02-18 18:40 6,200 –a—— c:\windows\System32\INT13EXT.VXD
2009-01-08 23:18 . 2009-01-08 23:18 d——– c:\program files\ERUNT
2009-01-08 17:14 . 2009-01-08 17:14 d——– c:\program files\Lavasoft
2009-01-08 17:13 . 2009-01-08 17:23 d——– c:\users\All Users\Lavasoft
2009-01-08 17:13 . 2009-01-08 17:23 d——– c:\programdata\Lavasoft
2009-01-08 17:11 . 2009-01-08 17:11 d——– c:\program files\Common Files\Wise Installation Wizard
2009-01-07 15:17 . 2009-01-08 01:46 d——– c:\program files\Trillian
2009-01-07 13:03 . 2009-01-07 13:21 d——– c:\users\Owner\.housecall6.6
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Videos
2008-12-25 14:24 . 2006-11-02 05:23 d——– c:\users\Mcx1\Saved Games
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Pictures
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Music
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Links
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Downloads
2008-12-25 14:24 . 2008-12-25 14:24 dr——- c:\users\Mcx1\Documents
2008-12-25 14:24 . 2008-12-25 14:25 d–h—– c:\users\Mcx1\AppData
2008-12-25 14:24 . 2008-12-25 14:24 d——– c:\users\Mcx1
2008-12-22 12:19 . 2001-03-02 11:41 634 –a—— c:\windows\System32\MAPISVC.INF
2008-12-22 12:18 . 2009-01-07 10:11 d——– c:\program files\Ontrack

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-20 04:52 ——— d—–w c:\users\Owner\AppData\Roaming\WTablet
2009-01-19 21:43 ——— d—–w c:\users\Owner\AppData\Roaming\Dropbox
2009-01-19 03:54 ——— d—–w c:\users\Owner\AppData\Roaming\skypePM
2009-01-19 03:54 ——— d—–w c:\users\Owner\AppData\Roaming\Skype
2009-01-09 19:36 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-09 19:25 ——— d—–w c:\program files\TaskCoach
2009-01-08 19:59 ——— d—–w c:\users\Owner\AppData\Roaming\uTorrent
2009-01-07 17:47 ——— d—–w c:\program files\Common Files\AOL
2009-01-02 14:01 ——— d—–w c:\program files\Mozilla Thunderbird
2008-12-22 19:56 ——— d—–w c:\program files\Java
2008-12-19 20:00 ——— d—–w c:\programdata\FLEXnet
2008-12-19 19:36 ——— d—–w c:\users\Owner\AppData\Roaming\NCH Swift Sound
2008-12-19 19:36 ——— d—–w c:\programdata\Viewpoint
2008-12-19 19:36 ——— d—–w c:\program files\NCH Swift Sound
2008-12-19 19:35 ——— d—–w c:\program files\DivX
2008-12-12 05:46 ——— d—–w c:\program files\Windows Mail
2008-11-23 14:22 ——— d—–w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-23 14:22 ——— d—–w c:\program files\iTunes
2008-11-23 14:21 ——— d—–w c:\program files\iPod
2008-11-23 14:21 ——— d—–w c:\program files\Common Files\Apple
2008-11-23 14:19 ——— d—–w c:\program files\QuickTime
2008-11-10 10:43 410,984 —-a-w c:\windows\System32\deploytk.dll
2008-11-01 03:44 541,696 —-a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 —-a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 —-a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 28,672 —-a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:44 2,154,496 —-a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 —-a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 01:21 4,240,384 —-a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-29 06:29 2,927,104 —-a-w c:\windows\explorer.exe
2008-10-22 03:57 241,152 —-a-w c:\windows\System32\PortableDeviceApi.dll
2008-10-22 01:22 2,048 —-a-w c:\windows\System32\tzres.dll
2008-10-21 05:25 296,960 —-a-w c:\windows\System32\gdi32.dll
2008-10-21 05:25 1,645,568 —-a-w c:\windows\System32\connect.dll
2008-09-05 14:17 174 –sha-w c:\program files\desktop.ini
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.


—- c:\program files\Dropbox\Dropbox.exe —-
Company: Evenflow, Inc.
File Description: Dropbox
File Version: 0.6.285
Product Name: Dropbox
Copyright: Evenflow, Inc.
Original file name: dropbox.exe
MD5: b4ba2e15618baad3a13f4bbf94d377c5


—- c:\program files\Dropbox\DropboxExt.dll —-
Company: Evenflow, Inc.
File Description: Dropbox Shell Extension
File Version: 1.0.0.2
Product Name: Dropbox
Copyright: © 2007-2008 Evenflow, Inc. All rights reserved
Original file name: DropboxExt.dll
MD5: 5bb0e62d62e985280f6b30a933062c0a


((((((((((((((((((((((((((((( snapshot@2009-01-19_16.41.16.76 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-19 21:30:31 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-01-20 04:51:50 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-01-19 21:30:31 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-01-20 04:51:50 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-01-19 21:39:51 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-01-20 04:54:22 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2009-01-19 21:39:45 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-01-20 05:00:36 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-01-20 05:00:36 262,144 —ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-01-09 19:48:35 1,810,608 —-a-w c:\windows\System32\FNTCACHE.DAT
+ 2009-01-20 04:52:10 1,810,608 —-a-w c:\windows\System32\FNTCACHE.DAT
- 2009-01-19 21:36:47 12,244 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-504179511-533580499-2079182871-1003_UserData.bin
+ 2009-01-20 04:54:35 12,284 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-504179511-533580499-2079182871-1003_UserData.bin
- 2009-01-19 21:36:43 82,418 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-01-20 04:54:34 82,434 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-01-19 21:36:35 68,730 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-01-20 04:54:29 68,904 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2008-06-19 19:51 143360 –a—— c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2008-06-19 19:51 143360 –a—— c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2008-06-19 19:51 143360 –a—— c:\program files\Dropbox\DropboxExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"RunSpySweeperScheduleAtStartup"="c:\windows\system32\msfeedssync.exe" [2008-01-19 12800]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Simplify Media"="c:\program files\Simplify Media\SimplifyMedia.exe" [2008-10-15 5613576]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-09-06 169264]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"Adobe_ID0EYTHM"="c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 1884160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-17 c:\windows\RtHDVCpl.exe]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\program files\Dropbox\dropbox.exe [2008-07-03 8767575]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
VPN Client.lnk - c:\windows\Installer\{4C271126-C295-4828-A901-5910AE0C258B}\Icon3E5562ED7.ico [2008-09-08 6144]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-04-13 415072]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\MRI_DISABLED
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-09-10 535336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
–a—— 2007-02-07 19:21 54832 c:\program files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSet]
–a—— 2007-04-25 16:47 45056 c:\windows\PLFSet.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
——— 2007-03-15 00:01 71216 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
–a—— 2006-11-10 15:35 90112 c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E87E10E6-607C-4C76-8E3E-A0DAEB82EC3F}"= c:\program files\CyberLink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{6A759421-33E0-4E26-8A06-F1965CF848A0}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{240C7D58-A421-48B5-BFA3-FF1975EDEF8D}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{98511BB7-AC96-476D-938E-A3A0050D85FB}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{E13DE3F5-A8B0-4E6D-9DAB-6BDD2DD8D84D}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{C2BB2A4C-3AB5-4163-8BC4-4DCC232F7129}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C98D39D4-DDB0-44A2-9E59-02DB96E28B1F}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{E93CAF6A-3787-4246-B057-83349F3FD40D}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{ECDFDD91-0221-4035-AFB5-571E90852F4A}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{9F307CDF-D310-433C-B133-454EA024C5AE}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{97F3FE01-E32C-4CBB-ABB4-64A66EBBB183}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{FD8F2145-725A-487F-BA6E-E068AE65082C}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{5070C06C-1D38-4555-BD95-EFBB69EAEC61}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{0995ACC1-808C-45EF-A616-7674E5E0D180}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{F4C5A106-7349-4EF2-AE8D-F60F6D00BA35}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{04B5FFD7-7EF4-4D7F-A632-C377C0A4A898}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{06F876BE-78F4-4D88-9C19-1B9C5D952E15}c:\\program files\\mirc\\mirc.exe"= UDP:c:\program files\mirc\mirc.exe:mIRC
"UDP Query User{CEB36888-70AE-46B6-97D3-141A365B8D55}c:\\program files\\mirc\\mirc.exe"= TCP:c:\program files\mirc\mirc.exe:mIRC
"{6F5B6776-1299-4352-BA3F-64BC664DD84C}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{00FA71D1-77B6-4385-B67C-5A659CBE228E}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"TCP Query User{D21F129E-05AA-49F0-80E6-A58063C839AA}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{958EE9C0-8F87-4AAE-A9F1-D5BFE184E6F3}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"{B13CDBBA-47BB-49F8-8C13-8888AFCDE9A8}"= UDP:3703:Adobe Version Cue CS3 Server
"{02B1DD75-0F20-435B-BD96-10781A85B8E5}"= UDP:3704:Adobe Version Cue CS3 Server
"{CE2B38A5-4908-41FC-BCAC-77FFA8FB8EA8}"= UDP:50900:Adobe Version Cue CS3 Server
"{DA3D0563-E7F8-4592-8407-07A260AB8A69}"= UDP:50901:Adobe Version Cue CS3 Server
"{80330BAF-B3EB-483E-94AF-E810EF6527E4}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{741DA650-4F15-430B-B01A-9446CCF12B4A}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{488EA232-7349-4F8B-BF7A-1A0B5199F54A}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{616BEBB8-A52E-4552-8183-3BE2FEE90CB8}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{7C343614-2B03-4F80-9FEE-C61B6225E3D8}"= TCP:62515:vpn
"{C7D5728D-DE2B-4650-B66F-4151C0D17BB2}"= TCP:10000:vpn1
"TCP Query User{D06C4765-9B7E-42ED-B004-5A5DE1AD6751}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{A1669D33-B90F-4FCD-AD99-3C431B397F47}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"TCP Query User{EADF93A5-72AE-429D-AB84-A0B344F24853}c:\\program files\\crossloop\\crossloopconnect.exe"= UDP:c:\program files\crossloop\crossloopconnect.exe:CrossLoop - Simple Secure Screen Sharing
"UDP Query User{8DD1EB09-8F5B-4A29-B176-05DEED3A7D0D}c:\\program files\\crossloop\\crossloopconnect.exe"= TCP:c:\program files\crossloop\crossloopconnect.exe:CrossLoop - Simple Secure Screen Sharing
"{1AC56B75-D75C-4973-857A-590D51AC2BFC}"= UDP:c:\program files\Cisco Systems\VPN Client\ipsecdialer.exe:ipsecdialer.exe
"{E0B922AC-6B7D-4A51-86DF-28CDC2D32CF5}"= TCP:c:\program files\Cisco Systems\VPN Client\ipsecdialer.exe:ipsecdialer.exe
"{9BD1B4D1-5DF5-4A25-B53C-9EC2BD1AB276}"= UDP:c:\program files\Cisco Systems\VPN Client\vpngui.exe:vpngui
"{C325F49B-24C9-4185-B7BB-BECDACCF218F}"= TCP:c:\program files\Cisco Systems\VPN Client\vpngui.exe:vpngui
"{6CEA28DF-39AF-46D2-A7AC-9910E4AD0A74}"= UDP:c:\program files\Cisco Systems\VPN Client\vpnclient.exe:vpnclient
"{082B33CA-EB15-49B8-9B74-0BAF49E39C99}"= TCP:c:\program files\Cisco Systems\VPN Client\vpnclient.exe:vpnclient
"TCP Query User{65073DFC-387F-47B8-A202-B1948B1F4D54}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"UDP Query User{37475A7E-AC04-4476-9E93-36A3A1F78E21}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"{6A879FF1-FAC5-4CD2-9EE4-CA8BE83D87D4}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{046873A2-6672-4CFA-A4BE-DCB9ABD6150B}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{287E0296-FA80-4604-AD0B-D4962A1CE4B9}c:\\program files\\simplify media\\simplifymedia.exe"= UDP:c:\program files\simplify media\simplifymedia.exe:Simplify Media
"UDP Query User{02C4F824-DAE5-4BA5-977F-91D9D84C3D29}c:\\program files\\simplify media\\simplifymedia.exe"= TCP:c:\program files\simplify media\simplifymedia.exe:Simplify Media
"{1CFCAC39-0FB9-4646-91E7-7B749037A2B5}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{E66EDF58-2A3D-4B63-A212-A6D26519AE77}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{D039383D-2689-4C64-B10B-41E3606A970E}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{8E3AB21D-8415-49F2-BE66-B554D4E17DBE}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{2F29F264-EA24-4B1E-9208-AE51A0E916EE}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP000.TMP\adobe.exe:TCP
"{3165DB0A-E0B8-47B7-BF6A-A42E3B95C28D}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP000.TMP\adobe.exe:TCP
"{7E9F1F85-1B1C-4D52-A827-CFF28ABD1610}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP003.TMP\adobe.exe:TCP
"{64A82E9A-4A1F-4267-8E5B-E0C2B6F3571E}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP003.TMP\adobe.exe:TCP
"{D1865ABA-FBBD-4662-A4FE-14DA5FF95AC0}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP007.TMP\adobe.exe:TCP
"{5C64C674-0690-404D-8D46-0CD960FEABF1}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP007.TMP\adobe.exe:TCP
"{548B18D8-48F7-46EB-8C09-359AB280A6F3}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP012.TMP\adobe.exe:TCP
"{74B5972D-28A2-4D20-8708-8CDC9B20360C}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP012.TMP\adobe.exe:TCP
"{D17BF34F-2896-407A-85D6-6D514B0E1529}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP001.TMP\adobe.exe:TCP
"{0F862BB8-CC03-4F38-9E00-3D320A7B7BAD}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP001.TMP\adobe.exe:TCP
"{D8343A8E-062C-438E-A75D-48F4DC9568A3}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP006.TMP\adobe.exe:TCP
"{5FB6AD1F-B219-44C1-8B9A-05B247A609C7}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP006.TMP\adobe.exe:TCP
"TCP Query User{59C24D90-EE94-42E6-AE92-9C5E1179946E}c:\\program files\\trillian\\trillian.exe"= UDP:c:\program files\trillian\trillian.exe:Trillian
"UDP Query User{FAAFD621-79F0-408E-9E22-2B3A66758A7D}c:\\program files\\trillian\\trillian.exe"= TCP:c:\program files\trillian\trillian.exe:Trillian

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP000.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP000.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP003.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP003.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP007.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP007.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP012.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP012.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP001.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP001.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP006.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP006.TMP\adobe.exe:*:Enabled:Windows Messanger

R0 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [2007-04-03 39680]
R0 O2SDRDR;O2SDRDR;c:\windows\System32\drivers\o2sd.sys [2007-04-02 35712]
R3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-02-02 648456]
R4 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\000.fcl [2007-12-19 06:53:51 13560]
R4 TabletServiceWacom;TabletServiceWacom;c:\windows\System32\Wacom_Tablet.exe [2008-10-06 2748200]
R4 tmevtmgr;tmevtmgr;c:\windows\System32\drivers\tmevtmgr.sys [2008-02-14 52240]
R4 tmpreflt;tmpreflt;c:\windows\System32\drivers\tmpreflt.sys [2007-09-28 36368]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\System32\drivers\wacmoumonitor.sys [2008-10-06 15656]
.
Contents of the 'Scheduled Tasks' folder

2009-01-20 c:\windows\Tasks\User_Feed_Synchronization-{562807D3-12E1-4214-B2D7-680F190A2229}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 02:33]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mStart Page = hxxp://en.us.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: www.ffffound.com
Trusted Zone: www.megapixel.net
Trusted Zone: assets.stepinsidedesign.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mzinexth.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mzinexth.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-20 00:00:47
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-01-20 0:04:35
ComboFix-quarantined-files.txt 2009-01-20 05:04:31
ComboFix2.txt 2009-01-19 21:43:06

Pre-Run: 8,979,644,416 bytes free
Post-Run: 8,839,315,456 bytes free

315 — E O F — 2009-01-05 17:09:27




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:47:31 PM, on 1/19/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\WTablet\Wacom_TabletUser.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\Explorer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\Owner\Desktop\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O1 - Hosts: 63.146.109.223 assets.stepinsidedesign.com:8080
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [StartCCC] "C:\Program Files\ATI" Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [RunSpySweeperScheduleAtStartup] "C:\Windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{562807D3-12E1-4214-B2D7-680F190A2229}
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Simplify Media] "C:\Program Files\Simplify Media\SimplifyMedia.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Dropbox.lnk = C:\Program Files\Dropbox\dropbox.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MRI_DISABLED
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.ffffound.com
O15 - Trusted Zone: http://www.megapixel.net
O15 - Trusted Zone: http://assets.stepinsidedesign.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{027494C8-8CF0-4E9B-A7A6-6692662BF5D4}: Domain = jupitermedia.lan
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = jupitermedia.lan,jupitermedia.lan,jupitermedia.lan,jupitermedia.lan
O17 - HKLM\System\CS1\Services\Tcpip\..\{027494C8-8CF0-4E9B-A7A6-6692662BF5D4}: Domain = jupitermedia.lan
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = jupitermedia.lan,jupitermedia.lan,jupitermedia.lan,jupitermedia.lan
O17 - HKLM\System\CS2\Services\Tcpip\..\{027494C8-8CF0-4E9B-A7A6-6692662BF5D4}: Domain = jupitermedia.lan
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = jupitermedia.lan,jupitermedia.lan,jupitermedia.lan,jupitermedia.lan
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Oz128 Driver\o2flash.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\Windows\system32\Wacom_Tablet.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 9452 bytes



——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, January 20, 2009
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, January 20, 2009 04:34:43
Records in database: 1651515
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - Critical Areas:
C:\Program Files
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
C:\Windows

Scan statistics:
Files scanned: 124752
Threat name: 3
Infected objects: 6
Suspicious objects: 0
Duration of the scan: 01:49:00


File name / Threat name / Threats count
C:\Program Files\CrossLoop\VNCHooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b 1
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.632 1
C:\Program Files\Trend Micro\Internet Security\Quarantine\AAE.tmp Infected: Trojan-Downloader.Win32.Zlob.abea 1
C:\Program Files\Trend Micro\Internet Security\Temp\VSK4VPFF.0UO Infected: not-a-virus:Client-IRC.Win32.mIRC.632 1
C:\Program Files\Trend Micro\Internet Security\Temp\VSK5VSN7.10N Infected: not-a-virus:Client-IRC.Win32.mIRC.632 1
C:\Program Files\Trend Micro\Internet Security\Temp\VSK6UBL7.1DP Infected: not-a-virus:Client-IRC.Win32.mIRC.632 1

The selected area was scanned.
Hi,

Apologies, I forgot you were running Vista. We need to do something again but slightly differently.

Right-click HijackThis and select Run As Administrator… Hit Do A System Scan Only. Place a check next to the following items (if present):
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 63.146.109.223 assets.stepinsidedesign.com:8080
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O15 - Trusted Zone: http://www.ffffound.com
O15 - Trusted Zone: http://www.megapixel.net
O15 - Trusted Zone: http://assets.stepinsidedesign.com

Note: I have highlighted some items in blue. If you recognize these items as being legitimate or added them yourself, do not check them.

Close all browsers and windows except for HijackThis and click Fix Checked.


I just want to make sure we got it all, you had a nasty one.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.

Any other problems with the computer?

Thanks.
please find below the gmer log. there are a zillion other problems with this computer, but i suspect that they are due to an incompatibility between my cisco vpn and the vista os… couple that with generally cheap hardware… *sigh*

i haven't noticed any further trojan-like issues.

you said that it was a nasty one - can you tell me a little more about this particular issue? even just a name would be great.

Thanks again!

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-20 11:30:04
Windows 6.0.6001 Service Pack 1


—- Kernel code sections - GMER 1.0.14 —-

.text srv.sys 9817E56E 1 Byte [ 33 ]
.text srv.sys 9817EF9C 1 Byte [ 41 ]
.text srv.sys 9817EFB5 1 Byte [ 20 ]
.text srv.sys 9817F607 2 Bytes [ D6, B8 ]
.text srv.sys 9817F60F 2 Bytes [ C6, 7A ]
.text …
? C:\Windows\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !
? C:\Combo-Fix\catchme.sys The system cannot find the path specified. !

—- Devices - GMER 1.0.14 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\tdx \Device\Udp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.14 —-
Hi :)

Please bear with me, I am getting a second opinion on some of the entries in your GMER log.

The "nasty" you had is largely known as the TDSServ Rootkit, and it does a lot to protect itself from removal, as you may have noticed from this:

I am also unable to update my windows defender or trendmicro antivirus updates. i could not access the malwarebytes link as i was instructed

I will post back as soon as I can.

Thanks.
my gmail has begun to be rejected again.

The error that the other server returned was: 554 554 The message was rejected because it contains prohibited virus or spam content (state 18).

ComboFix 09-01-19.05 - Owner 2009-01-20 22:44:55.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1789.1047 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
AV: Trend Micro AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-12-21 to 2009-01-21 )))))))))))))))))))))))))))))))
.

2009-01-20 11:49 . 2009-01-20 11:49 56 –ah—– c:\users\All Users\ezsidmv.dat
2009-01-20 11:49 . 2009-01-20 11:49 56 –ah—– c:\programdata\ezsidmv.dat
2009-01-20 10:48 . 2009-01-20 11:08 250 –a—— c:\windows\gmer.ini
2009-01-20 00:22 . 2008-12-15 21:42 288,768 –a—— c:\windows\System32\drivers\srv.sys
2009-01-20 00:07 . 2009-01-20 00:07 d——– c:\windows\Sun
2009-01-19 16:16 . 2009-01-19 16:21 d——– C:\ComboFix
2009-01-09 14:36 . 2009-01-09 14:36 d——– c:\program files\PC Inspector File Recovery
2009-01-09 14:36 . 2002-02-18 18:40 6,200 –a—— c:\windows\System32\INT13EXT.VXD
2009-01-08 23:18 . 2009-01-08 23:18 d——– c:\program files\ERUNT
2009-01-08 17:14 . 2009-01-08 17:14 d——– c:\program files\Lavasoft
2009-01-08 17:13 . 2009-01-08 17:23 d——– c:\users\All Users\Lavasoft
2009-01-08 17:13 . 2009-01-08 17:23 d——– c:\programdata\Lavasoft
2009-01-08 17:11 . 2009-01-08 17:11 d——– c:\program files\Common Files\Wise Installation Wizard
2009-01-07 15:17 . 2009-01-08 01:46 d——– c:\program files\Trillian
2009-01-07 13:03 . 2009-01-07 13:21 d——– c:\users\Owner\.housecall6.6
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Videos
2008-12-25 14:24 . 2006-11-02 05:23 d——– c:\users\Mcx1\Saved Games
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Pictures
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Music
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Links
2008-12-25 14:24 . 2006-11-02 05:23 dr——- c:\users\Mcx1\Downloads
2008-12-25 14:24 . 2008-12-25 14:24 dr——- c:\users\Mcx1\Documents
2008-12-25 14:24 . 2008-12-25 14:25 d–h—– c:\users\Mcx1\AppData
2008-12-25 14:24 . 2008-12-25 14:24 d——– c:\users\Mcx1
2008-12-22 12:19 . 2001-03-02 11:41 634 –a—— c:\windows\System32\MAPISVC.INF
2008-12-22 12:18 . 2009-01-07 10:11 d——– c:\program files\Ontrack

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-21 03:47 ——— d—–w c:\users\Owner\AppData\Roaming\Skype
2009-01-20 21:09 ——— d—–w c:\users\Owner\AppData\Roaming\skypePM
2009-01-20 08:02 ——— d—–w c:\program files\Windows Mail
2009-01-20 05:04 ——— d—–w c:\users\Owner\AppData\Roaming\Dropbox
2009-01-20 04:52 ——— d—–w c:\users\Owner\AppData\Roaming\WTablet
2009-01-09 19:36 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-09 19:25 ——— d—–w c:\program files\TaskCoach
2009-01-08 19:59 ——— d—–w c:\users\Owner\AppData\Roaming\uTorrent
2009-01-07 17:47 ——— d—–w c:\program files\Common Files\AOL
2009-01-02 14:01 ——— d—–w c:\program files\Mozilla Thunderbird
2008-12-22 19:56 ——— d—–w c:\program files\Java
2008-12-19 20:00 ——— d—–w c:\programdata\FLEXnet
2008-12-19 19:36 ——— d—–w c:\users\Owner\AppData\Roaming\NCH Swift Sound
2008-12-19 19:36 ——— d—–w c:\programdata\Viewpoint
2008-12-19 19:36 ——— d—–w c:\program files\NCH Swift Sound
2008-12-19 19:35 ——— d—–w c:\program files\DivX
2008-11-23 14:22 ——— d—–w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-23 14:22 ——— d—–w c:\program files\iTunes
2008-11-23 14:21 ——— d—–w c:\program files\iPod
2008-11-23 14:21 ——— d—–w c:\program files\Common Files\Apple
2008-11-23 14:19 ——— d—–w c:\program files\QuickTime
2008-11-10 10:43 410,984 —-a-w c:\windows\System32\deploytk.dll
2008-11-01 03:44 541,696 —-a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 —-a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 —-a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 28,672 —-a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:44 2,154,496 —-a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 —-a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 01:21 4,240,384 —-a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-29 06:29 2,927,104 —-a-w c:\windows\explorer.exe
2008-10-22 03:57 241,152 —-a-w c:\windows\System32\PortableDeviceApi.dll
2008-10-22 01:22 2,048 —-a-w c:\windows\System32\tzres.dll
2008-10-21 05:25 296,960 —-a-w c:\windows\System32\gdi32.dll
2008-10-21 05:25 1,645,568 —-a-w c:\windows\System32\connect.dll
2008-09-05 14:17 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((( snapshot@2009-01-19_16.41.16.76 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-21 03:44:34 6,365,184 —-a-w c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
+ 2009-01-20 15:48:26 884,736 —-a-w c:\windows\gmer.dll
+ 2008-04-18 02:13:02 811,008 —-a-w c:\windows\gmer.exe
- 2009-01-19 21:30:31 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-01-20 04:51:50 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-01-19 21:30:31 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-01-20 04:51:50 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-01-19 21:39:51 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-01-20 04:54:22 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2009-01-19 21:39:45 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-01-21 03:47:52 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2009-01-19 21:27:20 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-01-21 03:44:44 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-01-20 15:48:27 85,969 —-a-w c:\windows\System32\drivers\gmer.sys
- 2009-01-09 19:48:35 1,810,608 —-a-w c:\windows\System32\FNTCACHE.DAT
+ 2009-01-20 04:52:10 1,810,608 —-a-w c:\windows\System32\FNTCACHE.DAT
- 2008-12-09 23:24:37 17,593,280 —-a-w c:\windows\System32\mrt.exe
+ 2009-01-10 01:35:28 20,853,704 —-a-w c:\windows\System32\mrt.exe
- 2008-12-19 08:07:53 6,553,600 —-a-w c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-01-20 05:21:40 6,553,600 —-a-w c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2009-01-19 21:36:47 12,244 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-504179511-533580499-2079182871-1003_UserData.bin
+ 2009-01-20 04:54:35 12,284 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-504179511-533580499-2079182871-1003_UserData.bin
- 2009-01-19 21:36:43 82,418 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-01-20 04:54:34 82,434 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-01-19 21:36:35 68,730 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-01-20 04:54:29 68,904 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-12-19 08:00:49 172,125,952 —-a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2009-01-20 05:21:47 172,172,577 —-a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-12-08 23:22:10 2,410,800 —-a-w c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16787_none_f052600a6e8e5046\OESpamFilter.dat
+ 2008-12-08 23:23:32 2,410,800 —-a-w c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.20972_none_f0e1cd3587a85293\OESpamFilter.dat
+ 2008-12-09 23:54:42 2,410,800 —-a-w c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18182_none_f2339d3e6bb96284\OESpamFilter.dat
+ 2008-12-09 23:55:37 2,410,800 —-a-w c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22327_none_f3031ce984a1d682\OESpamFilter.dat
+ 2008-12-16 03:14:37 290,304 —-a-w c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6000.16789_none_d7c3afd4f985c7a2\srv.sys
+ 2008-12-16 03:07:02 290,816 —-a-w c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6000.20976_none_d8551d94129dfc9d\srv.sys
+ 2008-12-16 02:42:39 288,768 —-a-w c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6001.18185_none_d9a5ed52f6aff337\srv.sys
+ 2008-12-16 01:53:56 288,768 —-a-w c:\windows\winsxs\x86_microsoft-windows-smbserver-v1_31bf3856ad364e35_6.0.6001.22331_none_da619a780fa89f17\srv.sys
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2008-06-19 19:51 143360 –a—— c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2008-06-19 19:51 143360 –a—— c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2008-06-19 19:51 143360 –a—— c:\program files\Dropbox\DropboxExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"RunSpySweeperScheduleAtStartup"="c:\windows\system32\msfeedssync.exe" [2008-01-19 12800]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Simplify Media"="c:\program files\Simplify Media\SimplifyMedia.exe" [2008-10-15 5613576]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-09-06 169264]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"Adobe_ID0EYTHM"="c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 1884160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-17 c:\windows\RtHDVCpl.exe]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\program files\Dropbox\dropbox.exe [2008-07-03 8767575]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
VPN Client.lnk - c:\windows\Installer\{4C271126-C295-4828-A901-5910AE0C258B}\Icon3E5562ED7.ico [2008-09-08 6144]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-04-13 415072]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\MRI_DISABLED
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-09-10 535336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
–a—— 2007-02-07 19:21 54832 c:\program files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSet]
–a—— 2007-04-25 16:47 45056 c:\windows\PLFSet.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
——— 2007-03-15 00:01 71216 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
–a—— 2006-11-10 15:35 90112 c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E87E10E6-607C-4C76-8E3E-A0DAEB82EC3F}"= c:\program files\CyberLink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{6A759421-33E0-4E26-8A06-F1965CF848A0}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{240C7D58-A421-48B5-BFA3-FF1975EDEF8D}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{98511BB7-AC96-476D-938E-A3A0050D85FB}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{E13DE3F5-A8B0-4E6D-9DAB-6BDD2DD8D84D}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{C2BB2A4C-3AB5-4163-8BC4-4DCC232F7129}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C98D39D4-DDB0-44A2-9E59-02DB96E28B1F}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{E93CAF6A-3787-4246-B057-83349F3FD40D}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{ECDFDD91-0221-4035-AFB5-571E90852F4A}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{9F307CDF-D310-433C-B133-454EA024C5AE}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{97F3FE01-E32C-4CBB-ABB4-64A66EBBB183}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{FD8F2145-725A-487F-BA6E-E068AE65082C}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{5070C06C-1D38-4555-BD95-EFBB69EAEC61}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{0995ACC1-808C-45EF-A616-7674E5E0D180}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{F4C5A106-7349-4EF2-AE8D-F60F6D00BA35}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{04B5FFD7-7EF4-4D7F-A632-C377C0A4A898}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{06F876BE-78F4-4D88-9C19-1B9C5D952E15}c:\\program files\\mirc\\mirc.exe"= UDP:c:\program files\mirc\mirc.exe:mIRC
"UDP Query User{CEB36888-70AE-46B6-97D3-141A365B8D55}c:\\program files\\mirc\\mirc.exe"= TCP:c:\program files\mirc\mirc.exe:mIRC
"{6F5B6776-1299-4352-BA3F-64BC664DD84C}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{00FA71D1-77B6-4385-B67C-5A659CBE228E}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"TCP Query User{D21F129E-05AA-49F0-80E6-A58063C839AA}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{958EE9C0-8F87-4AAE-A9F1-D5BFE184E6F3}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"{B13CDBBA-47BB-49F8-8C13-8888AFCDE9A8}"= UDP:3703:Adobe Version Cue CS3 Server
"{02B1DD75-0F20-435B-BD96-10781A85B8E5}"= UDP:3704:Adobe Version Cue CS3 Server
"{CE2B38A5-4908-41FC-BCAC-77FFA8FB8EA8}"= UDP:50900:Adobe Version Cue CS3 Server
"{DA3D0563-E7F8-4592-8407-07A260AB8A69}"= UDP:50901:Adobe Version Cue CS3 Server
"{80330BAF-B3EB-483E-94AF-E810EF6527E4}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{741DA650-4F15-430B-B01A-9446CCF12B4A}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{488EA232-7349-4F8B-BF7A-1A0B5199F54A}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{616BEBB8-A52E-4552-8183-3BE2FEE90CB8}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{7C343614-2B03-4F80-9FEE-C61B6225E3D8}"= TCP:62515:vpn
"{C7D5728D-DE2B-4650-B66F-4151C0D17BB2}"= TCP:10000:vpn1
"TCP Query User{D06C4765-9B7E-42ED-B004-5A5DE1AD6751}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{A1669D33-B90F-4FCD-AD99-3C431B397F47}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"TCP Query User{EADF93A5-72AE-429D-AB84-A0B344F24853}c:\\program files\\crossloop\\crossloopconnect.exe"= UDP:c:\program files\crossloop\crossloopconnect.exe:CrossLoop - Simple Secure Screen Sharing
"UDP Query User{8DD1EB09-8F5B-4A29-B176-05DEED3A7D0D}c:\\program files\\crossloop\\crossloopconnect.exe"= TCP:c:\program files\crossloop\crossloopconnect.exe:CrossLoop - Simple Secure Screen Sharing
"{1AC56B75-D75C-4973-857A-590D51AC2BFC}"= UDP:c:\program files\Cisco Systems\VPN Client\ipsecdialer.exe:ipsecdialer.exe
"{E0B922AC-6B7D-4A51-86DF-28CDC2D32CF5}"= TCP:c:\program files\Cisco Systems\VPN Client\ipsecdialer.exe:ipsecdialer.exe
"{9BD1B4D1-5DF5-4A25-B53C-9EC2BD1AB276}"= UDP:c:\program files\Cisco Systems\VPN Client\vpngui.exe:vpngui
"{C325F49B-24C9-4185-B7BB-BECDACCF218F}"= TCP:c:\program files\Cisco Systems\VPN Client\vpngui.exe:vpngui
"{6CEA28DF-39AF-46D2-A7AC-9910E4AD0A74}"= UDP:c:\program files\Cisco Systems\VPN Client\vpnclient.exe:vpnclient
"{082B33CA-EB15-49B8-9B74-0BAF49E39C99}"= TCP:c:\program files\Cisco Systems\VPN Client\vpnclient.exe:vpnclient
"TCP Query User{65073DFC-387F-47B8-A202-B1948B1F4D54}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"UDP Query User{37475A7E-AC04-4476-9E93-36A3A1F78E21}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"{6A879FF1-FAC5-4CD2-9EE4-CA8BE83D87D4}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{046873A2-6672-4CFA-A4BE-DCB9ABD6150B}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{287E0296-FA80-4604-AD0B-D4962A1CE4B9}c:\\program files\\simplify media\\simplifymedia.exe"= UDP:c:\program files\simplify media\simplifymedia.exe:Simplify Media
"UDP Query User{02C4F824-DAE5-4BA5-977F-91D9D84C3D29}c:\\program files\\simplify media\\simplifymedia.exe"= TCP:c:\program files\simplify media\simplifymedia.exe:Simplify Media
"{1CFCAC39-0FB9-4646-91E7-7B749037A2B5}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{E66EDF58-2A3D-4B63-A212-A6D26519AE77}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{D039383D-2689-4C64-B10B-41E3606A970E}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{8E3AB21D-8415-49F2-BE66-B554D4E17DBE}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{2F29F264-EA24-4B1E-9208-AE51A0E916EE}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP000.TMP\adobe.exe:TCP
"{3165DB0A-E0B8-47B7-BF6A-A42E3B95C28D}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP000.TMP\adobe.exe:TCP
"{7E9F1F85-1B1C-4D52-A827-CFF28ABD1610}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP003.TMP\adobe.exe:TCP
"{64A82E9A-4A1F-4267-8E5B-E0C2B6F3571E}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP003.TMP\adobe.exe:TCP
"{D1865ABA-FBBD-4662-A4FE-14DA5FF95AC0}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP007.TMP\adobe.exe:TCP
"{5C64C674-0690-404D-8D46-0CD960FEABF1}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP007.TMP\adobe.exe:TCP
"{548B18D8-48F7-46EB-8C09-359AB280A6F3}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP012.TMP\adobe.exe:TCP
"{74B5972D-28A2-4D20-8708-8CDC9B20360C}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP012.TMP\adobe.exe:TCP
"{D17BF34F-2896-407A-85D6-6D514B0E1529}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP001.TMP\adobe.exe:TCP
"{0F862BB8-CC03-4F38-9E00-3D320A7B7BAD}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP001.TMP\adobe.exe:TCP
"{D8343A8E-062C-438E-A75D-48F4DC9568A3}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP006.TMP\adobe.exe:TCP
"{5FB6AD1F-B219-44C1-8B9A-05B247A609C7}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP006.TMP\adobe.exe:TCP
"TCP Query User{59C24D90-EE94-42E6-AE92-9C5E1179946E}c:\\program files\\trillian\\trillian.exe"= UDP:c:\program files\trillian\trillian.exe:Trillian
"UDP Query User{FAAFD621-79F0-408E-9E22-2B3A66758A7D}c:\\program files\\trillian\\trillian.exe"= TCP:c:\program files\trillian\trillian.exe:Trillian

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP000.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP000.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP003.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP003.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP007.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP007.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP012.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP012.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP001.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP001.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP006.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP006.TMP\adobe.exe:*:Enabled:Windows Messanger

R0 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [2007-04-03 39680]
R0 O2SDRDR;O2SDRDR;c:\windows\System32\drivers\o2sd.sys [2007-04-02 35712]
R4 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\000.fcl [2007-12-19 06:53:51 13560]
R4 TabletServiceWacom;TabletServiceWacom;c:\windows\System32\Wacom_Tablet.exe [2008-10-06 2748200]
R4 tmpreflt;tmpreflt;c:\windows\System32\drivers\tmpreflt.sys [2007-09-28 36368]
S3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-02-02 648456]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\System32\drivers\wacmoumonitor.sys [2008-10-06 15656]
S4 tmevtmgr;tmevtmgr;c:\windows\System32\drivers\tmevtmgr.sys [2008-02-14 52240]
.
Contents of the 'Scheduled Tasks' folder

2009-01-20 c:\windows\Tasks\User_Feed_Synchronization-{562807D3-12E1-4214-B2D7-680F190A2229}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 02:33]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mStart Page = hxxp://en.us.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: www.ffffound.com
Trusted Zone: www.megapixel.net
Trusted Zone: assets.stepinsidedesign.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mzinexth.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mzinexth.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-20 22:47:53
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

[0] 0x061C0010

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(3444)
c:\program files\Dropbox\DropboxExt.dll
c:\program files\Trillian\events.dll
.
Completion time: 2009-01-20 22:50:47
ComboFix-quarantined-files.txt 2009-01-21 03:50:42
ComboFix2.txt 2009-01-20 05:04:36
ComboFix3.txt 2009-01-19 21:43:06

Pre-Run: 8,842,665,984 bytes free
Post-Run: 8,896,069,632 bytes free

318 — E O F — 2009-01-20 08:02:27
Hi, Log looks fine now. What kind of emails are you sending? Are you attaching things to the emails? Do you get that message every time? Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI