This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] cant do a thing! help! please

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hia..seems like i have a hi jacker..all the typical redirecting..etc..only thing is it also wont let me update anything..tried to do spybot..nothing..ad aware..nothing..nortons..sunbelt..vipre..same thing..i cant even do microsoft updates..i've tried every scan i could..panda..trend micro…they work but havent helped..kapersky..cant use because it cant update its files..same for a number of other scans..i did get fooled once byu adware away..but the problems i have were before that, that was just an attempt by me to fix it..i've tried going into safety on msn premium for the anti virus and anti spyware and i just get a blamk page..even just surfing the net if i dont copy and paste an address from something i googled and i just click on it i get redirected..also..sysstem restore is on and monitoring but there werent any restore points..

perhaps it's something more than just a hi jacker…heres my log and i look forward to your help…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:59:32 AM, on 2/5/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/g/startpage.html?Ch…DTP&M=T6426
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "C:\WINDOWS\system32\HDAShCut.exe"
O4 - HKLM\..\Run: [Recguard] "C:\WINDOWS\SMINST\RECGUARD.EXE"
O4 - HKLM\..\Run: [RTHDCPL] "C:\WINDOWS\RTHDCPL.EXE"
O4 - HKLM\..\Run: [nTrayFw] "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKUS\S-1-5-19\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_ind.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1226628046375
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: cbXOHASK - C:\WINDOWS\
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Shield 3\IoloSGCtrl.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sunbelt VIPRE Antivirus Service (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: Security Activity Dashboard Service - Unknown owner - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe (file missing)
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 9803 bytes
[external image: Posted Image]

DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.




Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
ok great..i did that..but i couldnt update anti malware as i stated in my post..thank you for such quicke reply..hopefully resolve this…



Malwarebytes' Anti-Malware 1.33
Database version: 1654
Windows 5.1.2600 Service Pack 2

2/6/2009 1:10:15 AM
mbam-log-2009-02-06 (01-10-15).txt

Scan type: Quick Scan
Objects scanned: 76331
Time elapsed: 10 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/g/startpage.html?Ch…DTP&M=T6426
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "C:\WINDOWS\system32\HDAShCut.exe"
O4 - HKLM\..\Run: [Recguard] "C:\WINDOWS\SMINST\RECGUARD.EXE"
O4 - HKLM\..\Run: [RTHDCPL] "C:\WINDOWS\RTHDCPL.EXE"
O4 - HKLM\..\Run: [nTrayFw] "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKUS\S-1-5-19\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_ind.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1226628046375
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: cbXOHASK - C:\WINDOWS\
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Shield 3\IoloSGCtrl.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sunbelt VIPRE Antivirus Service (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: Security Activity Dashboard Service - Unknown owner - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe (file missing)
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 9736 bytes
Well that didn't find anything.
Lets try one more.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
ok heres the the logs..my test to see if all is back to normal is…i go to microsoft webite and try to do down loads, but i'm getting the page not found error..but so far i havent been redirected…another test is that i try to do anti virus updates and that still failing..even when i tried to refresh this page it kept bringing me to stopzilla and pc tools..actually if you go to line 016 dpf..the sixth one you could see what i get when i try to download windows updates..

ComboFix 09-02-06.01 - Owner 2009-02-06 14:23:13.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2943.2566 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\delete\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
AV: Sunbelt VIPRE *On-access scanning disabled* (Outdated)
FW: BitDefender Firewall *disabled*
FW: NVIDIA Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\404Fix.exe
c:\windows\system32\drivers\TDSSpqxt.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\srecorder.dll
c:\windows\system32\TDSSorvd.dat
c:\windows\system32\TDSSosvn.dll
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
H:\resycled

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_TDSSSERV.SYS)
——-\Legacy_TDSSSERV


((((((((((((((((((((((((( Files Created from 2009-01-06 to 2009-02-06 )))))))))))))))))))))))))))))))
.

8208-10-29 12:48 . 8208-10-29 12:48 d——– c:\documents and settings\All Users\Application Data\Applications
8208-10-29 11:58 . 8208-10-29 11:58 331,805,736 –a—— C:\WindowsXP-KB936929-SP3-x86-ENU.exe
8208-10-29 11:24 . 8208-10-29 11:24 d——– c:\documents and settings\Administrator
8208-10-29 11:21 . 2009-02-06 14:31 d——– c:\program files\DNA
8208-10-29 11:21 . 2009-02-06 14:31 d——– c:\documents and settings\Owner\Application Data\DNA
2009-02-05 00:47 . 2009-02-05 00:47 d——– c:\program files\ERUNT
2009-02-04 22:30 . 2009-02-04 22:30 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-04 22:30 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-04 22:30 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-04 21:57 . 2009-02-04 21:57 d——– c:\program files\Trend Micro
2009-02-04 20:21 . 2009-02-04 20:21 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-02-04 19:21 . 2009-02-04 19:25 d——– c:\program files\Norton Security Scan
2009-02-04 19:21 . 2009-02-04 19:21 d——– c:\program files\Common Files\Symantec Shared
2009-02-04 14:03 . 2009-02-04 14:03 d——– C:\fsaua.data
2009-02-04 00:43 . 2009-02-04 00:43 107 –a—— c:\documents and settings\Owner\Application Data\netstat.bat
2009-02-03 23:32 . 2009-02-03 23:32 d——– c:\documents and settings\Owner\Application Data\Sunbelt
2009-02-03 23:32 . 2009-02-03 23:32 d——– c:\documents and settings\All Users\Application Data\Sunbelt
2009-02-03 23:30 . 2009-02-03 23:30 d——– c:\program files\Sunbelt Software
2009-02-03 23:30 . 2008-04-28 14:48 202,160 –a—— c:\windows\system32\drivers\sbtis.sys
2009-02-03 21:44 . 2009-02-03 21:44 147,456 –a—— c:\windows\system32\VBZIP11.DLL
2009-02-03 21:44 . 2009-02-03 21:44 143,360 –a—— c:\windows\system32\vbuzip10.dll
2009-02-03 21:44 . 2009-02-03 21:44 62,464 –a—— c:\windows\system32\shdocvw.oca
2009-02-03 21:44 . 2009-02-03 21:44 32,768 –a—— c:\windows\system32\REGTOOL5.DLL
2009-02-03 21:44 . 2009-02-03 21:44 3,584 –a—— c:\windows\system32\DisspyUninstall.exe
2009-01-31 19:33 . 2009-01-31 19:33 6,656 –ahs—- c:\windows\system32\Thumbs.db
2009-01-27 20:08 . 2009-01-27 20:08 850 –a—— c:\windows\system32\ProductTweaks.xml
2009-01-27 20:08 . 2009-01-27 20:08 385 –a—— c:\windows\system32\user_gensett.xml
2009-01-27 20:04 . 2009-01-27 20:04 d——– c:\windows\system32\logs
2009-01-27 20:03 . 2009-01-27 20:08 d——– c:\documents and settings\All Users\Application Data\BitDefender
2009-01-27 20:02 . 2009-01-27 20:02 d——– c:\windows\system32\URTTEMP
2009-01-27 20:01 . 2009-02-03 23:27 d——– c:\program files\Common Files\BitDefender
2009-01-26 22:58 . 2009-01-26 22:58 d——– c:\program files\WinAVIVideoConverter
2009-01-26 22:58 . 2009-01-26 22:58 3,082 –a—— c:\windows\system32\affv9869p2now.sys
2009-01-20 12:22 . 2009-01-20 12:22 d——– c:\program files\New Folder
2009-01-20 12:02 . 2009-01-20 12:02 d——– c:\program files\File Scavenger 3.2
2009-01-19 13:35 . 2009-01-19 13:35 d——– c:\documents and settings\LocalService\Application Data\Xfire
2009-01-19 12:25 . 2009-01-19 12:25 d——– c:\program files\Wolfenstein - Enemy Territory
2009-01-19 02:12 . 2009-01-19 02:14 d——– c:\program files\Xfire
2009-01-19 02:12 . 2009-01-19 02:14 d——– c:\documents and settings\Owner\Application Data\Xfire
2009-01-13 17:53 . 2009-02-02 09:14 0 –a—— c:\windows\system32\msxver64.sqr
2009-01-13 17:21 . 2009-01-13 17:21 d——– c:\program files\WinPcap
2009-01-13 17:21 . 2009-01-13 17:51 d——– c:\program files\reconserver
2009-01-09 16:44 . 2009-01-09 16:45 d——– c:\documents and settings\Owner\Application Data\U3
2009-01-09 13:28 . 2009-01-13 09:22 d——– c:\program files\MP5Tool
2009-01-08 01:12 . 2009-01-08 01:19 1,355 –a—— c:\windows\imsins.BAK

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
8208-10-29 16:27 ——— d—–w c:\documents and settings\Administrator\Application Data\Corel
2009-02-06 08:00 ——— d—–w c:\documents and settings\Owner\Application Data\Corel
2009-02-05 05:34 ——— d—–w c:\documents and settings\Owner\Application Data\MSN6
2009-02-04 03:12 ——— d—–w c:\program files\Common Files\Webroot Shared
2009-02-04 02:44 ——— d—–w c:\documents and settings\Owner\Application Data\uTorrent
2009-02-04 02:28 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-31 04:49 ——— d—–w c:\program files\Webroot
2009-01-31 04:47 ——— d—–w c:\documents and settings\Owner\Application Data\Webroot
2009-01-31 04:47 ——— d—–w c:\documents and settings\All Users\Application Data\Webroot
2009-01-31 02:26 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-19 01:59 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-09 06:32 ——— d—–w c:\program files\Mystery Case Files - Ravenhearst
2009-01-09 06:32 ——— d—–w c:\program files\CamStudio
2009-01-04 23:51 ——— d—–w c:\program files\frm backup
2009-01-04 18:07 ——— d—–w c:\documents and settings\All Users\Application Data\Trend Micro
2009-01-04 17:16 ——— d—–w c:\documents and settings\All Users\Application Data\ESET
2009-01-04 03:13 ——— d—–w c:\program files\Rumble Box
2009-01-03 20:53 ——— d—–w c:\program files\Sauerbraten
2008-12-31 00:25 ——— d—–w c:\documents and settings\All Users\Application Data\TomTom
2008-12-29 18:39 ——— d—–w c:\program files\Common Files\Windows Live
2008-12-26 21:25 ——— d—–w c:\documents and settings\All Users\Application Data\NexonUS
2008-12-26 05:19 ——— d—–w c:\program files\TomTom HOME 2
2008-12-26 05:19 ——— d—–w c:\documents and settings\Owner\Application Data\TomTom
2008-12-22 19:13 ——— d—–w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-12-22 19:12 ——— d—–w c:\program files\bfgclient
2008-12-18 18:21 ——— d—–w c:\program files\SlySoft
2008-12-13 00:34 ——— d—–w c:\program files\Desktop Snow for Windows
2008-12-12 19:25 ——— d—–w c:\program files\3DSignal
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-06 21:42 ——— d—–w c:\program files\IObit
2008-11-12 00:13 700 —-a-w c:\program files\ownvrxto.txt
2008-11-09 17:17 39,424 —-a-w c:\windows\zipinst.exe
2008-10-30 19:24 61,224 —-a-w c:\documents and settings\Owner\GoToAssistDownloadHelper.exe
2008-10-11 16:40 354,750,534 —-a-w c:\program files\WolfTeam_IS_20080918_Ver262.exe
2008-10-11 16:04 0 —-a-w c:\program files\CombatArmsSetup.exe
2008-08-17 21:27 925,328 —-a-w c:\program files\32fsu32_004.exe
2008-08-13 04:09 33,877,248 —-a-w c:\program files\CFP_Setup_3.0.25.378_XP_Vista_x64.exe
2004-07-22 14:51 3,432,656 —-a-w c:\program files\ManagedDX.CAB
2004-07-20 02:58 1,156,363 —-a-w c:\program files\BDANT.cab
2004-07-20 02:53 976,020 —-a-w c:\program files\BDAXP.cab
2004-07-09 18:17 13,265,040 —-a-w c:\program files\dxnt.cab
2004-07-09 13:13 703,080 —-a-w c:\program files\BDA.cab
2004-07-09 13:13 15,493,481 —-a-w c:\program files\DirectX.cab
2008-10-24 04:12 88 –sh–r c:\windows\system32\4F43AA00A7.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-19 342848]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2008-12-21 2250256]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864]
"High Definition Audio Property Page Shortcut"="c:\windows\system32\HDAShCut.exe" [2005-01-07 61952]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RTHDCPL"="c:\windows\RTHDCPL.EXE" [2005-09-22 14854144]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-07-29 270336]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2008-10-01 951592]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-04 136600]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ZDSV"= scrvid.dll
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-11 28544]
R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2009-02-03 202160]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [2008-12-02 598856]
R3 scrcap;scrcap;c:\windows\system32\drivers\scrcap.sys [2006-12-27 9006]
S1 pwipf6;pwipf6;c:\windows\system32\drivers\pwipf6.sys –> c:\windows\system32\drivers\pwipf6.sys [?]
S1 Start1Driver;Start1Driver; [x]
S2 SBAMSvc;Sunbelt VIPRE Antivirus Service;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [2008-10-01 869672]
S2 Security Activity Dashboard Service;Security Activity Dashboard Service;c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe –> c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe [?]
S2 Start2Driver;Start2Driver; [x]
S3 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe –> c:\program files\iolo\common\lib\ioloServiceManager.exe [?]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2007-11-14 34448]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2007-11-06 87848]
S3 vidcap;vidcap;c:\windows\system32\DRIVERS\vidcap.sys –> c:\windows\system32\DRIVERS\vidcap.sys [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c638bf30-d6aa-11dd-b635-00161737f6f5}]
\Shell\AutoRun\command - J:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-06 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 16:39]

2008-10-31 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 14:00]

2008-11-06 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 14:00]

2009-02-05 c:\windows\Tasks\Norton Security Scan for Owner.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 04:18]
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-OE - c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
ShellExecuteHooks-{42AE1DA1-FF60-4435-A81F-9B6538F865A6} - (no file)
Notify-cbXOHASK - (no file)
Notify-dimsntfy - (no file)
SafeBoot-TDSSmqlt.sys


.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T6426
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\82i9g6hb.default\
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 14:31:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gaopdxserv.sys]
"imagepath"="\systemroot\system32\drivers\gaopdxwhpkynva.sys"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-80318808-1749694936-3363987519-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{58F33A7D-0382-8B5C-BB44-F7DEEF6DA3E4}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jalkjibdolpogmamnghk"=hex:62,61,68,65,00,13
"jalkjibdolpogmamngdk"=hex:62,61,6c,65,00,13
"ialjoddbpiilpopfma"=hex:6b,61,65,65,64,6d,61,65,62,6b,61,64,6b,6a,66,69,66,68,
6d,6a,69,63,00,00
"habnljeagelcgpdi"=hex:6b,61,65,65,64,6d,62,65,68,6b,66,68,63,70,6d,6f,6d,6d,
64,69,62,70,00,00

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{58F33A7D-0382-8B5C-BB44-F7DEEF6DA3E4}\InProcServer32*]
"kafjikkdflnhiahpopohip"=hex:62,61,66,65,00,8e
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\MSN Messenger\usnsvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-02-06 14:34:14 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-06 19:34:12

Pre-Run: 98,259,755,008 bytes free
Post-Run: 98,385,899,520 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,4,5
284 — E O F — 2009-01-31 02:26:33


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:16:26 PM, on 2/6/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN\MSNCoreFiles\MSN.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/g/startpage.html?Ch…DTP&M=T6426
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "C:\WINDOWS\system32\HDAShCut.exe"
O4 - HKLM\..\Run: [Recguard] "C:\WINDOWS\SMINST\RECGUARD.EXE"
O4 - HKLM\..\Run: [RTHDCPL] "C:\WINDOWS\RTHDCPL.EXE"
O4 - HKLM\..\Run: [nTrayFw] "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_ind.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1226628046375
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Shield 3\IoloSGCtrl.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sunbelt VIPRE Antivirus Service (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: Security Activity Dashboard Service - Unknown owner - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe (file missing)
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 9775 bytes
Wolfenstein - Enemy Territory
Great game.


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:


Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\affv9869p2now.sys

Folder::
c:\Program Files\Bonjour\

Driver::
gaopdxwhpkynva

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
OH YEAH ET great game..wish i could get to play more..before it could completely run it said that it detected a root kit and to save this info..

C:\WINDOWS\system32\drivers\gaopdxwhpkynva.sys

C:\WINDOWS\system32\drivers\gaopdxqocdgulg.dll
then it shut dwn came back on and did the scan..then i had to use task manager to restart because nothing happened after the scan..



ComboFix 09-02-06.01 - Owner 2009-02-06 20:51:29.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2943.2553 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
AV: Sunbelt VIPRE *On-access scanning disabled* (Outdated)
FW: BitDefender Firewall *disabled*
FW: NVIDIA Firewall *disabled*
* Created a new restore point

FILE ::
c:\windows\system32\affv9869p2now.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Bonjour\
c:\program files\Bonjour\\About Bonjour.rtf
c:\program files\Bonjour\\mdnsNSP.dll
c:\program files\Bonjour\\mDNSResponder.exe
c:\windows\system32\affv9869p2now.sys
c:\windows\system32\drivers\gaopdxwhpkynva.sys
c:\windows\system32\gaopdxqocdgulg.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_gaopdxserv.sys


((((((((((((((((((((((((( Files Created from 2009-01-07 to 2009-02-07 )))))))))))))))))))))))))))))))
.

8208-10-29 12:48 . 8208-10-29 12:48 d——– c:\documents and settings\All Users\Application Data\Applications
8208-10-29 11:58 . 8208-10-29 11:58 331,805,736 –a—— C:\WindowsXP-KB936929-SP3-x86-ENU.exe
8208-10-29 11:24 . 8208-10-29 11:24 d——– c:\documents and settings\Administrator
8208-10-29 11:21 . 2009-02-06 14:31 d——– c:\program files\DNA
8208-10-29 11:21 . 2009-02-06 20:49 d——– c:\documents and settings\Owner\Application Data\DNA
2009-02-05 00:47 . 2009-02-05 00:47 d——– c:\program files\ERUNT
2009-02-04 22:30 . 2009-02-04 22:30 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-04 22:30 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-04 22:30 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-04 21:57 . 2009-02-04 21:57 d——– c:\program files\Trend Micro
2009-02-04 20:21 . 2009-02-04 20:21 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-02-04 19:21 . 2009-02-06 15:00 d——– c:\program files\Norton Security Scan
2009-02-04 19:21 . 2009-02-04 19:21 d——– c:\program files\Common Files\Symantec Shared
2009-02-04 14:03 . 2009-02-04 14:03 d——– C:\fsaua.data
2009-02-04 00:43 . 2009-02-04 00:43 107 –a—— c:\documents and settings\Owner\Application Data\netstat.bat
2009-02-03 23:32 . 2009-02-03 23:32 d——– c:\documents and settings\Owner\Application Data\Sunbelt
2009-02-03 23:32 . 2009-02-03 23:32 d——– c:\documents and settings\All Users\Application Data\Sunbelt
2009-02-03 23:30 . 2009-02-03 23:30 d——– c:\program files\Sunbelt Software
2009-02-03 23:30 . 2008-04-28 14:48 202,160 –a—— c:\windows\system32\drivers\sbtis.sys
2009-02-03 21:44 . 2009-02-03 21:44 147,456 –a—— c:\windows\system32\VBZIP11.DLL
2009-02-03 21:44 . 2009-02-03 21:44 143,360 –a—— c:\windows\system32\vbuzip10.dll
2009-02-03 21:44 . 2009-02-03 21:44 62,464 –a—— c:\windows\system32\shdocvw.oca
2009-02-03 21:44 . 2009-02-03 21:44 32,768 –a—— c:\windows\system32\REGTOOL5.DLL
2009-02-03 21:44 . 2009-02-03 21:44 3,584 –a—— c:\windows\system32\DisspyUninstall.exe
2009-01-31 19:33 . 2009-01-31 19:33 6,656 –ahs—- c:\windows\system32\Thumbs.db
2009-01-27 20:08 . 2009-01-27 20:08 850 –a—— c:\windows\system32\ProductTweaks.xml
2009-01-27 20:08 . 2009-01-27 20:08 385 –a—— c:\windows\system32\user_gensett.xml
2009-01-27 20:04 . 2009-01-27 20:04 d——– c:\windows\system32\logs
2009-01-27 20:03 . 2009-01-27 20:08 d——– c:\documents and settings\All Users\Application Data\BitDefender
2009-01-27 20:02 . 2009-01-27 20:02 d——– c:\windows\system32\URTTEMP
2009-01-27 20:01 . 2009-02-03 23:27 d——– c:\program files\Common Files\BitDefender
2009-01-26 22:58 . 2009-01-26 22:58 d——– c:\program files\WinAVIVideoConverter
2009-01-20 12:22 . 2009-01-20 12:22 d——– c:\program files\New Folder
2009-01-20 12:02 . 2009-01-20 12:02 d——– c:\program files\File Scavenger 3.2
2009-01-19 13:35 . 2009-01-19 13:35 d——– c:\documents and settings\LocalService\Application Data\Xfire
2009-01-19 12:25 . 2009-01-19 12:25 d——– c:\program files\Wolfenstein - Enemy Territory
2009-01-19 02:12 . 2009-01-19 02:14 d——– c:\program files\Xfire
2009-01-19 02:12 . 2009-01-19 02:14 d——– c:\documents and settings\Owner\Application Data\Xfire
2009-01-13 17:53 . 2009-02-02 09:14 0 –a—— c:\windows\system32\msxver64.sqr
2009-01-13 17:21 . 2009-01-13 17:21 d——– c:\program files\WinPcap
2009-01-13 17:21 . 2009-01-13 17:51 d——– c:\program files\reconserver
2009-01-09 16:44 . 2009-01-09 16:45 d——– c:\documents and settings\Owner\Application Data\U3
2009-01-09 13:28 . 2009-01-13 09:22 d——– c:\program files\MP5Tool
2009-01-08 01:12 . 2009-01-08 01:19 1,355 –a—— c:\windows\imsins.BAK

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
8208-10-29 16:27 ——— d—–w c:\documents and settings\Administrator\Application Data\Corel
2009-02-06 20:13 ——— d—–w c:\documents and settings\Owner\Application Data\MSN6
2009-02-06 08:00 3,350 –sha-w c:\windows\system32\KGyGaAvL.sys
2009-02-06 08:00 ——— d—–w c:\documents and settings\Owner\Application Data\Corel
2009-02-05 01:21 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-02-04 03:12 ——— d—–w c:\program files\Common Files\Webroot Shared
2009-02-04 02:44 ——— d—–w c:\documents and settings\Owner\Application Data\uTorrent
2009-02-04 02:28 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-31 04:49 ——— d—–w c:\program files\Webroot
2009-01-31 04:47 ——— d—–w c:\documents and settings\Owner\Application Data\Webroot
2009-01-31 04:47 ——— d—–w c:\documents and settings\All Users\Application Data\Webroot
2009-01-31 03:41 81,984 —-a-w c:\windows\system32\bdod.bin
2009-01-31 02:26 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-19 01:59 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-09 06:32 ——— d—–w c:\program files\Mystery Case Files - Ravenhearst
2009-01-09 06:32 ——— d—–w c:\program files\CamStudio
2009-01-04 23:51 ——— d—–w c:\program files\frm backup
2009-01-04 18:07 ——— d—–w c:\documents and settings\All Users\Application Data\Trend Micro
2009-01-04 17:52 77,824 —-a-w c:\windows\system32\kdfapi.dll
2009-01-04 17:52 722,472 —-a-w c:\windows\system32\kdfmgr.exe
2009-01-04 17:52 53,248 —-a-w c:\windows\system32\Kdfhok.dll
2009-01-04 17:52 192,512 —-a-w c:\windows\system32\kdfvmgr.exe
2009-01-04 17:16 ——— d—–w c:\documents and settings\All Users\Application Data\ESET
2009-01-04 03:13 ——— d—–w c:\program files\Rumble Box
2009-01-03 20:53 ——— d—–w c:\program files\Sauerbraten
2008-12-31 00:25 ——— d—–w c:\documents and settings\All Users\Application Data\TomTom
2008-12-29 18:39 ——— d—–w c:\program files\Common Files\Windows Live
2008-12-26 21:25 ——— d—–w c:\documents and settings\All Users\Application Data\NexonUS
2008-12-26 05:19 ——— d—–w c:\program files\TomTom HOME 2
2008-12-26 05:19 ——— d—–w c:\documents and settings\Owner\Application Data\TomTom
2008-12-22 19:13 ——— d—–w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-12-22 19:12 ——— d—–w c:\program files\bfgclient
2008-12-18 18:21 ——— d—–w c:\program files\SlySoft
2008-12-13 00:34 ——— d—–w c:\program files\Desktop Snow for Windows
2008-12-12 19:25 ——— d—–w c:\program files\3DSignal
2008-12-11 20:38 42,320 —-a-w c:\windows\system32\xfcodec.dll
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2008-11-13 18:02 846,336 —-a-w c:\windows\system32\kdfinj.dll
2008-11-12 00:13 700 —-a-w c:\program files\ownvrxto.txt
2008-11-09 17:17 39,424 —-a-w c:\windows\zipinst.exe
2008-10-30 19:24 61,224 —-a-w c:\documents and settings\Owner\GoToAssistDownloadHelper.exe
2008-10-11 16:40 354,750,534 —-a-w c:\program files\WolfTeam_IS_20080918_Ver262.exe
2008-10-11 16:04 0 —-a-w c:\program files\CombatArmsSetup.exe
2008-08-17 21:27 925,328 —-a-w c:\program files\32fsu32_004.exe
2008-08-13 04:09 33,877,248 —-a-w c:\program files\CFP_Setup_3.0.25.378_XP_Vista_x64.exe
2004-07-22 14:51 3,432,656 —-a-w c:\program files\ManagedDX.CAB
2004-07-20 02:58 1,156,363 —-a-w c:\program files\BDANT.cab
2004-07-20 02:53 976,020 —-a-w c:\program files\BDAXP.cab
2004-07-09 18:17 13,265,040 —-a-w c:\program files\dxnt.cab
2004-07-09 13:13 703,080 —-a-w c:\program files\BDA.cab
2004-07-09 13:13 15,493,481 —-a-w c:\program files\DirectX.cab
2008-10-24 04:12 88 –sh–r c:\windows\system32\4F43AA00A7.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-02-06_14.33.16.98 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-07 01:51:03 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_2b8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-19 342848]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2008-12-21 2250256]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864]
"High Definition Audio Property Page Shortcut"="c:\windows\system32\HDAShCut.exe" [2005-01-07 61952]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RTHDCPL"="c:\windows\RTHDCPL.EXE" [2005-09-22 14854144]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-07-29 270336]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2008-10-01 951592]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-04 136600]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ZDSV"= scrvid.dll
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-11 28544]
R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2009-02-03 202160]
R2 SBAMSvc;Sunbelt VIPRE Antivirus Service;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [2008-10-01 869672]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [2008-12-02 598856]
R3 scrcap;scrcap;c:\windows\system32\drivers\scrcap.sys [2006-12-27 9006]
S1 pwipf6;pwipf6;c:\windows\system32\drivers\pwipf6.sys –> c:\windows\system32\drivers\pwipf6.sys [?]
S1 Start1Driver;Start1Driver; [x]
S2 Security Activity Dashboard Service;Security Activity Dashboard Service;c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe –> c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe [?]
S2 Start2Driver;Start2Driver; [x]
S3 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe –> c:\program files\iolo\common\lib\ioloServiceManager.exe [?]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2007-11-14 34448]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2007-11-06 87848]
S3 vidcap;vidcap;c:\windows\system32\DRIVERS\vidcap.sys –> c:\windows\system32\DRIVERS\vidcap.sys [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c638bf30-d6aa-11dd-b635-00161737f6f5}]
\Shell\AutoRun\command - J:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-07 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 16:39]

2008-10-31 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 14:00]

2008-11-06 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 14:00]

2009-02-06 c:\windows\Tasks\Norton Security Scan for Owner.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 04:18]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T6426
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\82i9g6hb.default\
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 20:55:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-80318808-1749694936-3363987519-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{58F33A7D-0382-8B5C-BB44-F7DEEF6DA3E4}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jalkjibdolpogmamnghk"=hex:62,61,68,65,00,13
"jalkjibdolpogmamngdk"=hex:62,61,6c,65,00,13
"ialjoddbpiilpopfma"=hex:6b,61,65,65,64,6d,61,65,62,6b,61,64,6b,6a,66,69,66,68,
6d,6a,69,63,00,00
"habnljeagelcgpdi"=hex:6b,61,65,65,64,6d,62,65,68,6b,66,68,63,70,6d,6f,6d,6d,
64,69,62,70,00,00

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{58F33A7D-0382-8B5C-BB44-F7DEEF6DA3E4}\InProcServer32*]
"kafjikkdflnhiahpopohip"=hex:62,61,66,65,00,8e
.
Completion time: 2009-02-06 20:56:59
ComboFix-quarantined-files.txt 2009-02-07 01:56:53
ComboFix2.txt 2009-02-06 19:34:15

Pre-Run: 98,383,163,392 bytes free
Post-Run: 98,385,379,328 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,4,5
248 — E O F — 2009-01-31 02:26:33



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:07:36 PM, on 2/6/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/g/startpage.html?Ch…DTP&M=T6426
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "C:\WINDOWS\system32\HDAShCut.exe"
O4 - HKLM\..\Run: [Recguard] "C:\WINDOWS\SMINST\RECGUARD.EXE"
O4 - HKLM\..\Run: [RTHDCPL] "C:\WINDOWS\RTHDCPL.EXE"
O4 - HKLM\..\Run: [nTrayFw] "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_ind.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1226628046375
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Shield 3\IoloSGCtrl.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sunbelt VIPRE Antivirus Service (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: Security Activity Dashboard Service - Unknown owner - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe (file missing)
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 9782 bytes
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

RegLockDel::
[-HKEY_USERS\S-1-5-21-80318808-1749694936-3363987519-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{58F33A7D-0382-8B5C-BB44-F7DEEF6DA3E4}*]
[-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{58F33A7D-0382-8B5C-BB44-F7DEEF6DA3E4}\InProcServer32*]

Folder::
c:\program files\Viewpoint

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.
ok this time it just ran…


ComboFix 09-02-06.01 - Owner 2009-02-06 21:52:26.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2943.2373 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
AV: Sunbelt VIPRE *On-access scanning disabled* (Outdated)
FW: BitDefender Firewall *disabled*
FW: NVIDIA Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Viewpoint
c:\program files\Viewpoint\Viewpoint Experience Technology\AxMetaStream_0306003B.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\ClassIDs.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\ComponentMgr_0306003B.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\ComponentRegistry.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLArt.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLShell.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\DataTracking.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\GifReader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\LensFlares.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ObjectMovie.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ServiceComponent.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VectorView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPAudio.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPExtras.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPVideo.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ZoomView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\DownLoadHist.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\HostRegistry.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\MetaStreamConfig.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\MtsAxInstaller.exe
c:\program files\Viewpoint\Viewpoint Experience Technology\MTSDownloadSites.txt
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\Cursors.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\JpegReader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\MTS3Reader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\SWFView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMgr.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPVideo2.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\WaveletReader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.xpt
c:\program files\Viewpoint\Viewpoint Experience Technology\VMPUpdateCount.ini

.
((((((((((((((((((((((((( Files Created from 2009-01-07 to 2009-02-07 )))))))))))))))))))))))))))))))
.

8208-10-29 12:48 . 8208-10-29 12:48 d——– c:\documents and settings\All Users\Application Data\Applications
8208-10-29 11:58 . 8208-10-29 11:58 331,805,736 –a—— C:\WindowsXP-KB936929-SP3-x86-ENU.exe
8208-10-29 11:24 . 8208-10-29 11:24 d——– c:\documents and settings\Administrator
8208-10-29 11:21 . 2009-02-06 20:59 d——– c:\program files\DNA
8208-10-29 11:21 . 2009-02-06 21:49 d——– c:\documents and settings\Owner\Application Data\DNA
2009-02-05 00:47 . 2009-02-05 00:47 d——– c:\program files\ERUNT
2009-02-04 22:30 . 2009-02-04 22:30 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-04 22:30 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-04 22:30 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-04 21:57 . 2009-02-04 21:57 d——– c:\program files\Trend Micro
2009-02-04 20:21 . 2009-02-04 20:21 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-02-04 19:21 . 2009-02-06 15:00 d——– c:\program files\Norton Security Scan
2009-02-04 19:21 . 2009-02-04 19:21 d——– c:\program files\Common Files\Symantec Shared
2009-02-04 14:03 . 2009-02-04 14:03 d——– C:\fsaua.data
2009-02-04 00:43 . 2009-02-04 00:43 107 –a—— c:\documents and settings\Owner\Application Data\netstat.bat
2009-02-03 23:32 . 2009-02-03 23:32 d——– c:\documents and settings\Owner\Application Data\Sunbelt
2009-02-03 23:32 . 2009-02-03 23:32 d——– c:\documents and settings\All Users\Application Data\Sunbelt
2009-02-03 23:30 . 2009-02-03 23:30 d——– c:\program files\Sunbelt Software
2009-02-03 23:30 . 2008-04-28 14:48 202,160 –a—— c:\windows\system32\drivers\sbtis.sys
2009-02-03 21:44 . 2009-02-03 21:44 147,456 –a—— c:\windows\system32\VBZIP11.DLL
2009-02-03 21:44 . 2009-02-03 21:44 143,360 –a—— c:\windows\system32\vbuzip10.dll
2009-02-03 21:44 . 2009-02-03 21:44 62,464 –a—— c:\windows\system32\shdocvw.oca
2009-02-03 21:44 . 2009-02-03 21:44 32,768 –a—— c:\windows\system32\REGTOOL5.DLL
2009-02-03 21:44 . 2009-02-03 21:44 3,584 –a—— c:\windows\system32\DisspyUninstall.exe
2009-01-31 19:33 . 2009-01-31 19:33 6,656 –ahs—- c:\windows\system32\Thumbs.db
2009-01-27 20:08 . 2009-01-27 20:08 850 –a—— c:\windows\system32\ProductTweaks.xml
2009-01-27 20:08 . 2009-01-27 20:08 385 –a—— c:\windows\system32\user_gensett.xml
2009-01-27 20:04 . 2009-01-27 20:04 d——– c:\windows\system32\logs
2009-01-27 20:03 . 2009-01-27 20:08 d——– c:\documents and settings\All Users\Application Data\BitDefender
2009-01-27 20:02 . 2009-01-27 20:02 d——– c:\windows\system32\URTTEMP
2009-01-27 20:01 . 2009-02-03 23:27 d——– c:\program files\Common Files\BitDefender
2009-01-26 22:58 . 2009-01-26 22:58 d——– c:\program files\WinAVIVideoConverter
2009-01-20 12:22 . 2009-01-20 12:22 d——– c:\program files\New Folder
2009-01-20 12:02 . 2009-01-20 12:02 d——– c:\program files\File Scavenger 3.2
2009-01-19 13:35 . 2009-01-19 13:35 d——– c:\documents and settings\LocalService\Application Data\Xfire
2009-01-19 12:25 . 2009-01-19 12:25 d——– c:\program files\Wolfenstein - Enemy Territory
2009-01-19 02:12 . 2009-01-19 02:14 d——– c:\program files\Xfire
2009-01-19 02:12 . 2009-01-19 02:14 d——– c:\documents and settings\Owner\Application Data\Xfire
2009-01-13 17:53 . 2009-02-02 09:14 0 –a—— c:\windows\system32\msxver64.sqr
2009-01-13 17:21 . 2009-01-13 17:21 d——– c:\program files\WinPcap
2009-01-13 17:21 . 2009-01-13 17:51 d——– c:\program files\reconserver
2009-01-09 16:44 . 2009-01-09 16:45 d——– c:\documents and settings\Owner\Application Data\U3
2009-01-09 13:28 . 2009-01-13 09:22 d——– c:\program files\MP5Tool
2009-01-08 01:12 . 2009-01-08 01:19 1,355 –a—— c:\windows\imsins.BAK

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
8208-10-29 16:27 ——— d—–w c:\documents and settings\Administrator\Application Data\Corel
2009-02-07 02:05 ——— d—–w c:\documents and settings\Owner\Application Data\MSN6
2009-02-06 08:00 3,350 –sha-w c:\windows\system32\KGyGaAvL.sys
2009-02-06 08:00 ——— d—–w c:\documents and settings\Owner\Application Data\Corel
2009-02-05 01:21 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-02-04 03:12 ——— d—–w c:\program files\Common Files\Webroot Shared
2009-02-04 02:44 ——— d—–w c:\documents and settings\Owner\Application Data\uTorrent
2009-02-04 02:28 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-31 04:49 ——— d—–w c:\program files\Webroot
2009-01-31 04:47 ——— d—–w c:\documents and settings\Owner\Application Data\Webroot
2009-01-31 04:47 ——— d—–w c:\documents and settings\All Users\Application Data\Webroot
2009-01-31 03:41 81,984 —-a-w c:\windows\system32\bdod.bin
2009-01-31 02:26 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-19 01:59 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-09 06:32 ——— d—–w c:\program files\Mystery Case Files - Ravenhearst
2009-01-09 06:32 ——— d—–w c:\program files\CamStudio
2009-01-04 23:51 ——— d—–w c:\program files\frm backup
2009-01-04 18:07 ——— d—–w c:\documents and settings\All Users\Application Data\Trend Micro
2009-01-04 17:52 77,824 —-a-w c:\windows\system32\kdfapi.dll
2009-01-04 17:52 722,472 —-a-w c:\windows\system32\kdfmgr.exe
2009-01-04 17:52 53,248 —-a-w c:\windows\system32\Kdfhok.dll
2009-01-04 17:52 192,512 —-a-w c:\windows\system32\kdfvmgr.exe
2009-01-04 17:16 ——— d—–w c:\documents and settings\All Users\Application Data\ESET
2009-01-04 03:13 ——— d—–w c:\program files\Rumble Box
2009-01-03 20:53 ——— d—–w c:\program files\Sauerbraten
2008-12-31 00:25 ——— d—–w c:\documents and settings\All Users\Application Data\TomTom
2008-12-29 18:39 ——— d—–w c:\program files\Common Files\Windows Live
2008-12-26 21:25 ——— d—–w c:\documents and settings\All Users\Application Data\NexonUS
2008-12-26 05:19 ——— d—–w c:\program files\TomTom HOME 2
2008-12-26 05:19 ——— d—–w c:\documents and settings\Owner\Application Data\TomTom
2008-12-22 19:13 ——— d—–w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-12-22 19:12 ——— d—–w c:\program files\bfgclient
2008-12-18 18:21 ——— d—–w c:\program files\SlySoft
2008-12-13 00:34 ——— d—–w c:\program files\Desktop Snow for Windows
2008-12-12 19:25 ——— d—–w c:\program files\3DSignal
2008-12-11 20:38 42,320 —-a-w c:\windows\system32\xfcodec.dll
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2008-11-13 18:02 846,336 —-a-w c:\windows\system32\kdfinj.dll
2008-11-12 00:13 700 —-a-w c:\program files\ownvrxto.txt
2008-11-09 17:17 39,424 —-a-w c:\windows\zipinst.exe
2008-10-30 19:24 61,224 —-a-w c:\documents and settings\Owner\GoToAssistDownloadHelper.exe
2008-10-11 16:40 354,750,534 —-a-w c:\program files\WolfTeam_IS_20080918_Ver262.exe
2008-10-11 16:04 0 —-a-w c:\program files\CombatArmsSetup.exe
2008-08-17 21:27 925,328 —-a-w c:\program files\32fsu32_004.exe
2008-08-13 04:09 33,877,248 —-a-w c:\program files\CFP_Setup_3.0.25.378_XP_Vista_x64.exe
2004-07-22 14:51 3,432,656 —-a-w c:\program files\ManagedDX.CAB
2004-07-20 02:58 1,156,363 —-a-w c:\program files\BDANT.cab
2004-07-20 02:53 976,020 —-a-w c:\program files\BDAXP.cab
2004-07-09 18:17 13,265,040 —-a-w c:\program files\dxnt.cab
2004-07-09 13:13 703,080 —-a-w c:\program files\BDA.cab
2004-07-09 13:13 15,493,481 —-a-w c:\program files\DirectX.cab
2008-10-24 04:12 88 –sh–r c:\windows\system32\4F43AA00A7.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-02-06_14.33.16.98 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 17:02:28 163,328 —-a-w c:\windows\ERDNT\AutoBackup\2-6-2009\ERDNT.EXE
+ 2009-02-07 01:59:48 9,674,752 —-a-w c:\windows\ERDNT\AutoBackup\2-6-2009\Users\00000001\NTUSER.DAT
+ 2009-02-07 01:59:48 241,664 —-a-w c:\windows\ERDNT\AutoBackup\2-6-2009\Users\00000002\UsrClass.dat
+ 2009-02-07 01:59:26 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_7d8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-19 342848]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2008-12-21 2250256]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864]
"High Definition Audio Property Page Shortcut"="c:\windows\system32\HDAShCut.exe" [2005-01-07 61952]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RTHDCPL"="c:\windows\RTHDCPL.EXE" [2005-09-22 14854144]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-07-29 270336]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2008-10-01 951592]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-04 136600]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ZDSV"= scrvid.dll
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-11 28544]
R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2009-02-03 202160]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [2008-12-02 598856]
R3 scrcap;scrcap;c:\windows\system32\drivers\scrcap.sys [2006-12-27 9006]
S1 pwipf6;pwipf6;c:\windows\system32\drivers\pwipf6.sys –> c:\windows\system32\drivers\pwipf6.sys [?]
S1 Start1Driver;Start1Driver; [x]
S2 SBAMSvc;Sunbelt VIPRE Antivirus Service;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [2008-10-01 869672]
S2 Security Activity Dashboard Service;Security Activity Dashboard Service;c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe –> c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe [?]
S2 Start2Driver;Start2Driver; [x]
S3 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe –> c:\program files\iolo\common\lib\ioloServiceManager.exe [?]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2007-11-14 34448]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2007-11-06 87848]
S3 vidcap;vidcap;c:\windows\system32\DRIVERS\vidcap.sys –> c:\windows\system32\DRIVERS\vidcap.sys [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c638bf30-d6aa-11dd-b635-00161737f6f5}]
\Shell\AutoRun\command - J:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-07 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 16:39]

2008-10-31 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 14:00]

2008-11-06 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 14:00]

2009-02-06 c:\windows\Tasks\Norton Security Scan for Owner.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 04:18]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T6426
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\82i9g6hb.default\
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 21:54:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-80318808-1749694936-3363987519-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{58F33A7D-0382-8B5C-BB44-F7DEEF6DA3E4}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jalkjibdolpogmamnghk"=hex:62,61,68,65,00,13
"jalkjibdolpogmamngdk"=hex:62,61,6c,65,00,13
"ialjoddbpiilpopfma"=hex:6b,61,65,65,64,6d,61,65,62,6b,61,64,6b,6a,66,69,66,68,
6d,6a,69,63,00,00
"habnljeagelcgpdi"=hex:6b,61,65,65,64,6d,62,65,68,6b,66,68,63,70,6d,6f,6d,6d,
64,69,62,70,00,00

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{58F33A7D-0382-8B5C-BB44-F7DEEF6DA3E4}\InProcServer32*]
"kafjikkdflnhiahpopohip"=hex:62,61,66,65,00,8e
.
Completion time: 2009-02-06 21:56:18
ComboFix-quarantined-files.txt 2009-02-07 02:56:13
ComboFix2.txt 2009-02-07 01:57:01
ComboFix3.txt 2009-02-06 19:34:15

Pre-Run: 98,327,810,048 bytes free
Post-Run: 98,303,909,888 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,4,5
276 — E O F — 2009-01-31 02:26:33

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:57:46 PM, on 2/6/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/g/startpage.html?Ch…DTP&M=T6426
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "C:\WINDOWS\system32\HDAShCut.exe"
O4 - HKLM\..\Run: [Recguard] "C:\WINDOWS\SMINST\RECGUARD.EXE"
O4 - HKLM\..\Run: [RTHDCPL] "C:\WINDOWS\RTHDCPL.EXE"
O4 - HKLM\..\Run: [nTrayFw] "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_ind.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1226628046375
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Shield 3\IoloSGCtrl.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sunbelt VIPRE Antivirus Service (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: Security Activity Dashboard Service - Unknown owner - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe (file missing)
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 9666 bytes
sorry fo9r the late reply..everything is running fine now..no more redirectioning..software updates and everything..what did i have? some type of trojan? perhaps one tht messes with dns settings? how di you figure that out? sorry for all the questions i'm just amazed..thank you so much!!!!
Can you run a new Combofix scan? I need to have another look at those LOCKED REGISTRY KEYS.

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please don't attach the scans / logs, use "copy/paste".
ok..how come each time i run combo fix windows says updates are available? thats the only thing that occurrs by the way..could you briefly tell me why are those registry keys locked? thanks again

ComboFix 09-02-06.04 - Owner 2009-02-08 8:24:40.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2943.2187 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
AV: Sunbelt VIPRE *On-access scanning disabled* (Updated)
FW: BitDefender Firewall *disabled*
FW: NVIDIA Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-01-08 to 2009-02-08 )))))))))))))))))))))))))))))))
.

8208-10-29 12:48 . 8208-10-29 12:48 d——– c:\documents and settings\All Users\Application Data\Applications
8208-10-29 11:58 . 8208-10-29 11:58 331,805,736 –a—— C:\WindowsXP-KB936929-SP3-x86-ENU.exe
8208-10-29 11:24 . 8208-10-29 11:24 d——– c:\documents and settings\Administrator
8208-10-29 11:21 . 2009-02-06 20:59 d——– c:\program files\DNA
8208-10-29 11:21 . 2009-02-08 08:23 d——– c:\documents and settings\Owner\Application Data\DNA
2009-02-07 16:46 . 2008-09-12 11:12 69,168 –a—— c:\windows\system32\drivers\sbapifs.sys
2009-02-07 16:46 . 2008-09-12 11:12 13,360 –a—— c:\windows\system32\drivers\sbaphd.sys
2009-02-05 00:47 . 2009-02-05 00:47 d——– c:\program files\ERUNT
2009-02-04 22:30 . 2009-02-04 22:30 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-04 22:30 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-04 22:30 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-04 21:57 . 2009-02-04 21:57 d——– c:\program files\Trend Micro
2009-02-04 20:21 . 2009-02-04 20:21 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-02-04 19:21 . 2009-02-06 15:00 d——– c:\program files\Norton Security Scan
2009-02-04 19:21 . 2009-02-04 19:21 d——– c:\program files\Common Files\Symantec Shared
2009-02-04 14:03 . 2009-02-04 14:03 d——– C:\fsaua.data
2009-02-04 00:43 . 2009-02-04 00:43 107 –a—— c:\documents and settings\Owner\Application Data\netstat.bat
2009-02-03 23:32 . 2009-02-03 23:32 d——– c:\documents and settings\Owner\Application Data\Sunbelt
2009-02-03 23:32 . 2009-02-03 23:32 d——– c:\documents and settings\All Users\Application Data\Sunbelt
2009-02-03 23:30 . 2009-02-03 23:30 d——– c:\program files\Sunbelt Software
2009-02-03 23:30 . 2008-04-28 14:48 202,160 –a—— c:\windows\system32\drivers\sbtis.sys
2009-02-03 21:44 . 2009-02-03 21:44 147,456 –a—— c:\windows\system32\VBZIP11.DLL
2009-02-03 21:44 . 2009-02-03 21:44 143,360 –a—— c:\windows\system32\vbuzip10.dll
2009-02-03 21:44 . 2009-02-03 21:44 62,464 –a—— c:\windows\system32\shdocvw.oca
2009-02-03 21:44 . 2009-02-03 21:44 32,768 –a—— c:\windows\system32\REGTOOL5.DLL
2009-02-03 21:44 . 2009-02-03 21:44 3,584 –a—— c:\windows\system32\DisspyUninstall.exe
2009-01-31 19:33 . 2009-01-31 19:33 6,656 –ahs—- c:\windows\system32\Thumbs.db
2009-01-27 20:08 . 2009-01-27 20:08 850 –a—— c:\windows\system32\ProductTweaks.xml
2009-01-27 20:08 . 2009-01-27 20:08 385 –a—— c:\windows\system32\user_gensett.xml
2009-01-27 20:04 . 2009-01-27 20:04 d——– c:\windows\system32\logs
2009-01-27 20:03 . 2009-01-27 20:08 d——– c:\documents and settings\All Users\Application Data\BitDefender
2009-01-27 20:02 . 2009-01-27 20:02 d——– c:\windows\system32\URTTEMP
2009-01-27 20:01 . 2009-02-03 23:27 d——– c:\program files\Common Files\BitDefender
2009-01-26 22:58 . 2009-01-26 22:58 d——– c:\program files\WinAVIVideoConverter
2009-01-20 12:22 . 2009-01-20 12:22 d——– c:\program files\New Folder
2009-01-20 12:02 . 2009-01-20 12:02 d——– c:\program files\File Scavenger 3.2
2009-01-19 13:35 . 2009-01-19 13:35 d——– c:\documents and settings\LocalService\Application Data\Xfire
2009-01-19 12:25 . 2009-01-19 12:25 d——– c:\program files\Wolfenstein - Enemy Territory
2009-01-19 02:12 . 2009-01-19 02:14 d——– c:\program files\Xfire
2009-01-19 02:12 . 2009-01-19 02:14 d——– c:\documents and settings\Owner\Application Data\Xfire
2009-01-13 17:53 . 2009-02-02 09:14 0 –a—— c:\windows\system32\msxver64.sqr
2009-01-13 17:21 . 2009-01-13 17:21 d——– c:\program files\WinPcap
2009-01-13 17:21 . 2009-01-13 17:51 d——– c:\program files\reconserver
2009-01-09 16:44 . 2009-01-09 16:45 d——– c:\documents and settings\Owner\Application Data\U3
2009-01-09 13:28 . 2009-01-13 09:22 d——– c:\program files\MP5Tool
2009-01-08 01:12 . 2009-01-08 01:19 1,355 –a—— c:\windows\imsins.BAK

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
8208-10-29 16:27 ——— d—–w c:\documents and settings\Administrator\Application Data\Corel
2009-02-08 03:31 ——— d—–w c:\documents and settings\Owner\Application Data\MSN6
2009-02-06 08:00 3,350 –sha-w c:\windows\system32\KGyGaAvL.sys
2009-02-06 08:00 ——— d—–w c:\documents and settings\Owner\Application Data\Corel
2009-02-05 01:21 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-02-04 03:12 ——— d—–w c:\program files\Common Files\Webroot Shared
2009-02-04 02:44 ——— d—–w c:\documents and settings\Owner\Application Data\uTorrent
2009-02-04 02:28 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-31 04:49 ——— d—–w c:\program files\Webroot
2009-01-31 04:47 ——— d—–w c:\documents and settings\Owner\Application Data\Webroot
2009-01-31 04:47 ——— d—–w c:\documents and settings\All Users\Application Data\Webroot
2009-01-31 03:41 81,984 —-a-w c:\windows\system32\bdod.bin
2009-01-31 02:26 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-19 01:59 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-09 06:32 ——— d—–w c:\program files\Mystery Case Files - Ravenhearst
2009-01-09 06:32 ——— d—–w c:\program files\CamStudio
2009-01-04 23:51 ——— d—–w c:\program files\frm backup
2009-01-04 18:07 ——— d—–w c:\documents and settings\All Users\Application Data\Trend Micro
2009-01-04 17:52 77,824 —-a-w c:\windows\system32\kdfapi.dll
2009-01-04 17:52 722,472 —-a-w c:\windows\system32\kdfmgr.exe
2009-01-04 17:52 53,248 —-a-w c:\windows\system32\Kdfhok.dll
2009-01-04 17:52 192,512 —-a-w c:\windows\system32\kdfvmgr.exe
2009-01-04 17:16 ——— d—–w c:\documents and settings\All Users\Application Data\ESET
2009-01-04 03:13 ——— d—–w c:\program files\Rumble Box
2009-01-03 20:53 ——— d—–w c:\program files\Sauerbraten
2008-12-31 00:25 ——— d—–w c:\documents and settings\All Users\Application Data\TomTom
2008-12-29 18:39 ——— d—–w c:\program files\Common Files\Windows Live
2008-12-26 21:25 ——— d—–w c:\documents and settings\All Users\Application Data\NexonUS
2008-12-26 05:19 ——— d—–w c:\program files\TomTom HOME 2
2008-12-26 05:19 ——— d—–w c:\documents and settings\Owner\Application Data\TomTom
2008-12-22 19:13 ——— d—–w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-12-22 19:12 ——— d—–w c:\program files\bfgclient
2008-12-18 18:21 ——— d—–w c:\program files\SlySoft
2008-12-13 00:34 ——— d—–w c:\program files\Desktop Snow for Windows
2008-12-12 19:25 ——— d—–w c:\program files\3DSignal
2008-12-11 20:38 42,320 —-a-w c:\windows\system32\xfcodec.dll
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2008-11-13 18:02 846,336 —-a-w c:\windows\system32\kdfinj.dll
2008-11-12 00:13 700 —-a-w c:\program files\ownvrxto.txt
2008-11-09 17:17 39,424 —-a-w c:\windows\zipinst.exe
2008-10-30 19:24 61,224 —-a-w c:\documents and settings\Owner\GoToAssistDownloadHelper.exe
2008-10-11 16:40 354,750,534 —-a-w c:\program files\WolfTeam_IS_20080918_Ver262.exe
2008-10-11 16:04 0 —-a-w c:\program files\CombatArmsSetup.exe
2008-08-17 21:27 925,328 —-a-w c:\program files\32fsu32_004.exe
2008-08-13 04:09 33,877,248 —-a-w c:\program files\CFP_Setup_3.0.25.378_XP_Vista_x64.exe
2004-07-22 14:51 3,432,656 —-a-w c:\program files\ManagedDX.CAB
2004-07-20 02:58 1,156,363 —-a-w c:\program files\BDANT.cab
2004-07-20 02:53 976,020 —-a-w c:\program files\BDAXP.cab
2004-07-09 18:17 13,265,040 —-a-w c:\program files\dxnt.cab
2004-07-09 13:13 703,080 —-a-w c:\program files\BDA.cab
2004-07-09 13:13 15,493,481 —-a-w c:\program files\DirectX.cab
2008-10-24 04:12 88 –sh–r c:\windows\system32\4F43AA00A7.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-02-06_14.33.16.98 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 17:02:28 163,328 —-a-w c:\windows\ERDNT\AutoBackup\2-6-2009\ERDNT.EXE
+ 2009-02-07 01:59:48 9,674,752 —-a-w c:\windows\ERDNT\AutoBackup\2-6-2009\Users\00000001\NTUSER.DAT
+ 2009-02-07 01:59:48 241,664 —-a-w c:\windows\ERDNT\AutoBackup\2-6-2009\Users\00000002\UsrClass.dat
+ 2009-02-07 11:57:46 297,086 —-a-r c:\windows\Installer\{628D3C21-B5BE-48D8-A729-2C8E2AF0D07A}\ARPPRODUCTICON.exe
+ 2009-02-07 11:57:46 335,872 —-a-r c:\windows\Installer\{628D3C21-B5BE-48D8-A729-2C8E2AF0D07A}\NewShortcut2_339C927BB4B547F9804FDF51F01D2D57.exe
+ 2009-02-07 11:57:46 335,872 —-a-r c:\windows\Installer\{628D3C21-B5BE-48D8-A729-2C8E2AF0D07A}\NewShortcut21_339C927BB4B547F9804FDF51F01D2D57.exe
- 2007-11-06 15:00:58 87,848 —-a-w c:\windows\system32\drivers\SBREDrv.sys
+ 2008-10-23 09:09:24 92,464 —-a-w c:\windows\system32\drivers\SBREDrv.sys
- 2008-10-01 19:25:04 59,176 —-a-w c:\windows\system32\sbbd.exe
+ 2008-10-28 21:28:12 65,320 —-a-w c:\windows\system32\sbbd.exe
+ 2009-02-07 01:59:26 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_7d8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-19 342848]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2008-12-21 2250256]
"Google Update"="c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-07 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864]
"High Definition Audio Property Page Shortcut"="c:\windows\system32\HDAShCut.exe" [2005-01-07 61952]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RTHDCPL"="c:\windows\RTHDCPL.EXE" [2005-09-22 14854144]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-07-29 270336]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-04 136600]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2008-10-28 955688]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ZDSV"= scrvid.dll
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-11 28544]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2009-02-07 13360]
R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2009-02-03 202160]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2009-02-07 69168]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [2008-12-02 598856]
R3 scrcap;scrcap;c:\windows\system32\drivers\scrcap.sys [2006-12-27 9006]
S1 pwipf6;pwipf6;c:\windows\system32\drivers\pwipf6.sys –> c:\windows\system32\drivers\pwipf6.sys [?]
S1 Start1Driver;Start1Driver; [x]
S2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [2008-10-28 886056]
S2 Security Activity Dashboard Service;Security Activity Dashboard Service;c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe –> c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe [?]
S2 Start2Driver;Start2Driver; [x]
S3 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe –> c:\program files\iolo\common\lib\ioloServiceManager.exe [?]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2007-11-14 34448]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2008-10-23 92464]
S3 vidcap;vidcap;c:\windows\system32\DRIVERS\vidcap.sys –> c:\windows\system32\DRIVERS\vidcap.sys [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - SBAMSVC
*NewlyCreated* - SBAPHD
*NewlyCreated* - SBAPIFS

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c638bf30-d6aa-11dd-b635-00161737f6f5}]
\Shell\AutoRun\command - J:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-08 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 16:39]

2009-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-80318808-1749694936-3363987519-1003.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 16:34]

2008-10-31 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 14:00]

2008-11-06 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 14:00]

2009-02-06 c:\windows\Tasks\Norton Security Scan for Owner.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 04:18]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T6426
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\82i9g6hb.default\
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-08 08:27:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-80318808-1749694936-3363987519-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{58F33A7D-0382-8B5C-BB44-F7DEEF6DA3E4}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jalkjibdolpogmamnghk"=hex:62,61,68,65,00,13
"jalkjibdolpogmamngdk"=hex:62,61,6c,65,00,13
"ialjoddbpiilpopfma"=hex:6b,61,65,65,64,6d,61,65,62,6b,61,64,6b,6a,66,69,66,68,
6d,6a,69,63,00,00
"habnljeagelcgpdi"=hex:6b,61,65,65,64,6d,62,65,68,6b,66,68,63,70,6d,6f,6d,6d,
64,69,62,70,00,00

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{58F33A7D-0382-8B5C-BB44-F7DEEF6DA3E4}\InProcServer32*]
"kafjikkdflnhiahpopohip"=hex:62,61,66,65,00,8e
.
Completion time: 2009-02-08 8:28:52
ComboFix-quarantined-files.txt 2009-02-08 13:28:50
ComboFix2.txt 2009-02-07 02:56:19
ComboFix3.txt 2009-02-07 01:57:01
ComboFix4.txt 2009-02-06 19:34:15

Pre-Run: 97,753,313,280 bytes free
Post-Run: 97,858,408,448 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,4,5
261 — E O F — 2009-01-31 02:26:33







Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:31:02 AM, on 2/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/g/startpage.html?Ch…DTP&M=T6426
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "C:\WINDOWS\system32\HDAShCut.exe"
O4 - HKLM\..\Run: [Recguard] "C:\WINDOWS\SMINST\RECGUARD.EXE"
O4 - HKLM\..\Run: [RTHDCPL] "C:\WINDOWS\RTHDCPL.EXE"
O4 - HKLM\..\Run: [nTrayFw] "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_ind.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1226628046375
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Shield 3\IoloSGCtrl.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: Security Activity Dashboard Service - Unknown owner - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe (file missing)
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 9895 bytes
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

Regnull:: 
[HKEY_USERS\S-1-5-21-80318808-1749694936-3363987519-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{58F33A7D-0382-8B5C-BB44-F7DEEF6DA3E4}*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{58F33A7D-0382-8B5C-BB44-F7DEEF6DA3E4}\InProcServer32*]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log
this time the balloon windows updates didnt pop up



ComboFix 09-02-07.01 - Owner 2009-02-08 10:45:28.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2943.2295 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
AV: Sunbelt VIPRE *On-access scanning disabled* (Updated)
FW: BitDefender Firewall *disabled*
FW: NVIDIA Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-01-08 to 2009-02-08 )))))))))))))))))))))))))))))))
.

8208-10-29 12:48 . 8208-10-29 12:48 d——– c:\documents and settings\All Users\Application Data\Applications
8208-10-29 11:58 . 8208-10-29 11:58 331,805,736 –a—— C:\WindowsXP-KB936929-SP3-x86-ENU.exe
8208-10-29 11:24 . 8208-10-29 11:24 d——– c:\documents and settings\Administrator
8208-10-29 11:21 . 2009-02-06 20:59 d——– c:\program files\DNA
8208-10-29 11:21 . 2009-02-08 10:43 d——– c:\documents and settings\Owner\Application Data\DNA
2009-02-07 16:46 . 2008-09-12 11:12 69,168 –a—— c:\windows\system32\drivers\sbapifs.sys
2009-02-07 16:46 . 2008-09-12 11:12 13,360 –a—— c:\windows\system32\drivers\sbaphd.sys
2009-02-05 00:47 . 2009-02-05 00:47 d——– c:\program files\ERUNT
2009-02-04 22:30 . 2009-02-04 22:30 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-04 22:30 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-04 22:30 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-04 21:57 . 2009-02-04 21:57 d——– c:\program files\Trend Micro
2009-02-04 20:21 . 2009-02-04 20:21 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-02-04 19:21 . 2009-02-06 15:00 d——– c:\program files\Norton Security Scan
2009-02-04 19:21 . 2009-02-04 19:21 d——– c:\program files\Common Files\Symantec Shared
2009-02-04 14:03 . 2009-02-04 14:03 d——– C:\fsaua.data
2009-02-04 00:43 . 2009-02-04 00:43 107 –a—— c:\documents and settings\Owner\Application Data\netstat.bat
2009-02-03 23:32 . 2009-02-03 23:32 d——– c:\documents and settings\Owner\Application Data\Sunbelt
2009-02-03 23:32 . 2009-02-03 23:32 d——– c:\documents and settings\All Users\Application Data\Sunbelt
2009-02-03 23:30 . 2009-02-03 23:30 d——– c:\program files\Sunbelt Software
2009-02-03 23:30 . 2008-04-28 14:48 202,160 –a—— c:\windows\system32\drivers\sbtis.sys
2009-02-03 21:44 . 2009-02-03 21:44 147,456 –a—— c:\windows\system32\VBZIP11.DLL
2009-02-03 21:44 . 2009-02-03 21:44 143,360 –a—— c:\windows\system32\vbuzip10.dll
2009-02-03 21:44 . 2009-02-03 21:44 62,464 –a—— c:\windows\system32\shdocvw.oca
2009-02-03 21:44 . 2009-02-03 21:44 32,768 –a—— c:\windows\system32\REGTOOL5.DLL
2009-02-03 21:44 . 2009-02-03 21:44 3,584 –a—— c:\windows\system32\DisspyUninstall.exe
2009-01-31 19:33 . 2009-01-31 19:33 6,656 –ahs—- c:\windows\system32\Thumbs.db
2009-01-27 20:08 . 2009-01-27 20:08 850 –a—— c:\windows\system32\ProductTweaks.xml
2009-01-27 20:08 . 2009-01-27 20:08 385 –a—— c:\windows\system32\user_gensett.xml
2009-01-27 20:04 . 2009-01-27 20:04 d——– c:\windows\system32\logs
2009-01-27 20:03 . 2009-01-27 20:08 d——– c:\documents and settings\All Users\Application Data\BitDefender
2009-01-27 20:02 . 2009-01-27 20:02 d——– c:\windows\system32\URTTEMP
2009-01-27 20:01 . 2009-02-03 23:27 d——– c:\program files\Common Files\BitDefender
2009-01-26 22:58 . 2009-01-26 22:58 d——– c:\program files\WinAVIVideoConverter
2009-01-20 12:22 . 2009-01-20 12:22 d——– c:\program files\New Folder
2009-01-20 12:02 . 2009-01-20 12:02 d——– c:\program files\File Scavenger 3.2
2009-01-19 13:35 . 2009-01-19 13:35 d——– c:\documents and settings\LocalService\Application Data\Xfire
2009-01-19 12:25 . 2009-01-19 12:25 d——– c:\program files\Wolfenstein - Enemy Territory
2009-01-19 02:12 . 2009-01-19 02:14 d——– c:\program files\Xfire
2009-01-19 02:12 . 2009-01-19 02:14 d——– c:\documents and settings\Owner\Application Data\Xfire
2009-01-13 17:53 . 2009-02-02 09:14 0 –a—— c:\windows\system32\msxver64.sqr
2009-01-13 17:21 . 2009-01-13 17:21 d——– c:\program files\WinPcap
2009-01-13 17:21 . 2009-01-13 17:51 d——– c:\program files\reconserver
2009-01-09 16:44 . 2009-01-09 16:45 d——– c:\documents and settings\Owner\Application Data\U3
2009-01-09 13:28 . 2009-01-13 09:22 d——– c:\program files\MP5Tool
2009-01-08 01:12 . 2009-01-08 01:19 1,355 –a—— c:\windows\imsins.BAK

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
8208-10-29 16:27 ——— d—–w c:\documents and settings\Administrator\Application Data\Corel
2009-02-08 03:31 ——— d—–w c:\documents and settings\Owner\Application Data\MSN6
2009-02-06 08:00 3,350 –sha-w c:\windows\system32\KGyGaAvL.sys
2009-02-06 08:00 ——— d—–w c:\documents and settings\Owner\Application Data\Corel
2009-02-05 01:21 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-02-04 03:12 ——— d—–w c:\program files\Common Files\Webroot Shared
2009-02-04 02:44 ——— d—–w c:\documents and settings\Owner\Application Data\uTorrent
2009-02-04 02:28 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-31 04:49 ——— d—–w c:\program files\Webroot
2009-01-31 04:47 ——— d—–w c:\documents and settings\Owner\Application Data\Webroot
2009-01-31 04:47 ——— d—–w c:\documents and settings\All Users\Application Data\Webroot
2009-01-31 03:41 81,984 —-a-w c:\windows\system32\bdod.bin
2009-01-31 02:26 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-19 01:59 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-09 06:32 ——— d—–w c:\program files\Mystery Case Files - Ravenhearst
2009-01-09 06:32 ——— d—–w c:\program files\CamStudio
2009-01-04 23:51 ——— d—–w c:\program files\frm backup
2009-01-04 18:07 ——— d—–w c:\documents and settings\All Users\Application Data\Trend Micro
2009-01-04 17:52 77,824 —-a-w c:\windows\system32\kdfapi.dll
2009-01-04 17:52 722,472 —-a-w c:\windows\system32\kdfmgr.exe
2009-01-04 17:52 53,248 —-a-w c:\windows\system32\Kdfhok.dll
2009-01-04 17:52 192,512 —-a-w c:\windows\system32\kdfvmgr.exe
2009-01-04 17:16 ——— d—–w c:\documents and settings\All Users\Application Data\ESET
2009-01-04 03:13 ——— d—–w c:\program files\Rumble Box
2009-01-03 20:53 ——— d—–w c:\program files\Sauerbraten
2008-12-31 00:25 ——— d—–w c:\documents and settings\All Users\Application Data\TomTom
2008-12-29 18:39 ——— d—–w c:\program files\Common Files\Windows Live
2008-12-26 21:25 ——— d—–w c:\documents and settings\All Users\Application Data\NexonUS
2008-12-26 05:19 ——— d—–w c:\program files\TomTom HOME 2
2008-12-26 05:19 ——— d—–w c:\documents and settings\Owner\Application Data\TomTom
2008-12-22 19:13 ——— d—–w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-12-22 19:12 ——— d—–w c:\program files\bfgclient
2008-12-18 18:21 ——— d—–w c:\program files\SlySoft
2008-12-13 00:34 ——— d—–w c:\program files\Desktop Snow for Windows
2008-12-12 19:25 ——— d—–w c:\program files\3DSignal
2008-12-11 20:38 42,320 —-a-w c:\windows\system32\xfcodec.dll
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2008-11-13 18:02 846,336 —-a-w c:\windows\system32\kdfinj.dll
2008-11-12 00:13 700 —-a-w c:\program files\ownvrxto.txt
2008-11-09 17:17 39,424 —-a-w c:\windows\zipinst.exe
2008-10-30 19:24 61,224 —-a-w c:\documents and settings\Owner\GoToAssistDownloadHelper.exe
2008-10-11 16:40 354,750,534 —-a-w c:\program files\WolfTeam_IS_20080918_Ver262.exe
2008-10-11 16:04 0 —-a-w c:\program files\CombatArmsSetup.exe
2008-08-17 21:27 925,328 —-a-w c:\program files\32fsu32_004.exe
2008-08-13 04:09 33,877,248 —-a-w c:\program files\CFP_Setup_3.0.25.378_XP_Vista_x64.exe
2004-07-22 14:51 3,432,656 —-a-w c:\program files\ManagedDX.CAB
2004-07-20 02:58 1,156,363 —-a-w c:\program files\BDANT.cab
2004-07-20 02:53 976,020 —-a-w c:\program files\BDAXP.cab
2004-07-09 18:17 13,265,040 —-a-w c:\program files\dxnt.cab
2004-07-09 13:13 703,080 —-a-w c:\program files\BDA.cab
2004-07-09 13:13 15,493,481 —-a-w c:\program files\DirectX.cab
2008-10-24 04:12 88 –sh–r c:\windows\system32\4F43AA00A7.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-02-06_14.33.16.98 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 17:02:28 163,328 —-a-w c:\windows\ERDNT\AutoBackup\2-6-2009\ERDNT.EXE
+ 2009-02-07 01:59:48 9,674,752 —-a-w c:\windows\ERDNT\AutoBackup\2-6-2009\Users\00000001\NTUSER.DAT
+ 2009-02-07 01:59:48 241,664 —-a-w c:\windows\ERDNT\AutoBackup\2-6-2009\Users\00000002\UsrClass.dat
+ 2009-02-07 11:57:46 297,086 —-a-r c:\windows\Installer\{628D3C21-B5BE-48D8-A729-2C8E2AF0D07A}\ARPPRODUCTICON.exe
+ 2009-02-07 11:57:46 335,872 —-a-r c:\windows\Installer\{628D3C21-B5BE-48D8-A729-2C8E2AF0D07A}\NewShortcut2_339C927BB4B547F9804FDF51F01D2D57.exe
+ 2009-02-07 11:57:46 335,872 —-a-r c:\windows\Installer\{628D3C21-B5BE-48D8-A729-2C8E2AF0D07A}\NewShortcut21_339C927BB4B547F9804FDF51F01D2D57.exe
- 2007-11-06 15:00:58 87,848 —-a-w c:\windows\system32\drivers\SBREDrv.sys
+ 2008-10-23 09:09:24 92,464 —-a-w c:\windows\system32\drivers\SBREDrv.sys
- 2008-10-01 19:25:04 59,176 —-a-w c:\windows\system32\sbbd.exe
+ 2008-10-28 21:28:12 65,320 —-a-w c:\windows\system32\sbbd.exe
+ 2009-02-07 01:59:26 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_7d8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-19 342848]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2008-12-21 2250256]
"Google Update"="c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-07 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864]
"High Definition Audio Property Page Shortcut"="c:\windows\system32\HDAShCut.exe" [2005-01-07 61952]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RTHDCPL"="c:\windows\RTHDCPL.EXE" [2005-09-22 14854144]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-07-29 270336]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-04 136600]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2008-10-28 955688]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ZDSV"= scrvid.dll
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-11 28544]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2009-02-07 13360]
R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2009-02-03 202160]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2009-02-07 69168]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [2008-12-02 598856]
R3 scrcap;scrcap;c:\windows\system32\drivers\scrcap.sys [2006-12-27 9006]
S1 pwipf6;pwipf6;c:\windows\system32\drivers\pwipf6.sys –> c:\windows\system32\drivers\pwipf6.sys [?]
S1 Start1Driver;Start1Driver; [x]
S2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [2008-10-28 886056]
S2 Security Activity Dashboard Service;Security Activity Dashboard Service;c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe –> c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe [?]
S2 Start2Driver;Start2Driver; [x]
S3 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe –> c:\program files\iolo\common\lib\ioloServiceManager.exe [?]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2007-11-14 34448]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2008-10-23 92464]
S3 vidcap;vidcap;c:\windows\system32\DRIVERS\vidcap.sys –> c:\windows\system32\DRIVERS\vidcap.sys [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - SBAMSVC
*NewlyCreated* - SBAPHD
*NewlyCreated* - SBAPIFS

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c638bf30-d6aa-11dd-b635-00161737f6f5}]
\Shell\AutoRun\command - J:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-08 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 16:39]

2009-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-80318808-1749694936-3363987519-1003.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 16:34]

2008-10-31 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 14:00]

2008-11-06 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 14:00]

2009-02-06 c:\windows\Tasks\Norton Security Scan for Owner.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 04:18]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T6426
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\82i9g6hb.default\
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\1.2.133.37\npGoogleOneClick7.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-08 10:46:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-02-08 10:47:33
ComboFix-quarantined-files.txt 2009-02-08 15:47:30
ComboFix2.txt 2009-02-08 13:28:53
ComboFix3.txt 2009-02-07 02:56:19
ComboFix4.txt 2009-02-07 01:57:01
ComboFix5.txt 2009-02-08 15:44:57

Pre-Run: 97,836,920,832 bytes free
Post-Run: 97,821,413,376 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,4,5
244 — E O F — 2009-01-31 02:26:33


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:50:17 AM, on 2/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/g/startpage.html?Ch…DTP&M=T6426
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "C:\WINDOWS\system32\HDAShCut.exe"
O4 - HKLM\..\Run: [Recguard] "C:\WINDOWS\SMINST\RECGUARD.EXE"
O4 - HKLM\..\Run: [RTHDCPL] "C:\WINDOWS\RTHDCPL.EXE"
O4 - HKLM\..\Run: [nTrayFw] "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_ind.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1226628046375
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Shield 3\IoloSGCtrl.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: Security Activity Dashboard Service - Unknown owner - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe (file missing)
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 9863 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI