This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] PC is loading very slowly

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

GREAT HELP IS NEEDED.
ty u
this is my hjt log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:14:19 PM, on 2/12/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: (no name) - {4A776C87-BFCF-424E-A6FE-D57A6760F1F5} - C:\WINDOWS\system32\mlJawwTn.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\xxyxWoMe.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {af42d72d-8b78-4880-b241-878620487331} - C:\WINDOWS\system32\rizepato.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [fadilagizo] Rundll32.exe "C:\WINDOWS\system32\gokisoso.dll",s
O4 - HKLM\..\Run: [407270c9] rundll32.exe "C:\WINDOWS\system32\atonogre.dll",b
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKUS\S-1-5-19\..\Run: [fadilagizo] Rundll32.exe "C:\WINDOWS\system32\gokisoso.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [fadilagizo] Rundll32.exe "C:\WINDOWS\system32\gokisoso.dll",s (User 'NETWORK SERVICE')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1219651984062
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\yuhodose.dll
O20 - Winlogon Notify: xxyxWoMe - C:\WINDOWS\SYSTEM32\xxyxWoMe.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 6554 bytes
Hi chankfj, welcome to the forum.

Please be advised, as I'm still in training, all my replies will have to be approved by a teacher or expert before I can post them. This may cause some delays, but I will do my best to keep them as short as possible.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
I will post back soon with additional instructions.


Thanks
Hi chankfj,

Please download ATF Cleaner by Atribune.

Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

Note your computer may boot a little slower the first couple of times.

Next, Please download Malwarebytes Anti-Malware and save it to your desktop.please double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Launch Malwarebytes' Anti-Malware, uncheck Update Malwarebytes' Anti-Malware, if checked, then click Finish.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post the MBAM log and a new HJT (hijackthis) log in your next reply and let us know how your computer is now.

Thanks
here is my hjt log and mbam log :


Malwarebytes' Anti-Malware 1.34
Database version: 1749
Windows 5.1.2600 Service Pack 2

2/13/2009 11:40:34 AM
mbam-log-2009-02-13 (11-40-34).txt

Scan type: Quick Scan
Objects scanned: 62840
Time elapsed: 4 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 5
Registry Keys Infected: 16
Registry Values Infected: 3
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 19

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\atonogre.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\mlJawwTn.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\yuhodose.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\gokisoso.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\xxyxWoMe.dll (Trojan.Vundo) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxyxwome (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fa56a9d1-6870-44ad-8a52-e5907a09e339} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{fa56a9d1-6870-44ad-8a52-e5907a09e339} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{af42d72d-8b78-4880-b241-878620487331} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{af42d72d-8b78-4880-b241-878620487331} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{af42d72d-8b78-4880-b241-878620487331} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\407270c9 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\fadilagizo (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\mljawwtn -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\yuhodose.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\yuhodose.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\yuhodose.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\mljawwtn -> Delete on reboot.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\xxyxWoMe.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\mlJawwTn.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\nTwwaJlm.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nTwwaJlm.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\atonogre.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\ergonota.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cmpufqii.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\iiqfupmc.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nrakrroj.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jorrkarn.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pibyoiyw.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wyioybip.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gokisoso.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\rizepato.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yuhodose.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\geBsTMFy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SVCH0ST.EXE (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\awtsQHWP.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vtUnKbBQ.dll (Trojan.vundo) -> Quarantined and deleted successfully.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:47:40 AM, on 2/13/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\ctfmon.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [fadilagizo] Rundll32.exe "C:\WINDOWS\system32\gokisoso.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [fadilagizo] Rundll32.exe "C:\WINDOWS\system32\gokisoso.dll",s (User 'NETWORK SERVICE')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1219651984062
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 5965 bytes
Hi chankfj,

We're gaining.

Open HJT, do a system scan only, checkmark the following line, if present

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKUS\S-1-5-19\..\Run: [fadilagizo] Rundll32.exe "C:\WINDOWS\system32\gokisoso.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [fadilagizo] Rundll32.exe "C:\WINDOWS\system32\gokisoso.dll",s (User 'NETWORK SERVICE')

Close all other browsers/windows and click fix checked. Answer yes if prompted. Close HJT.

Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it.
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\system32\xxyxWoMe.dll 
    C:\WINDOWS\system32\mlJawwTn.dll 
    C:\WINDOWS\system32\gokisoso.dll
    C:\WINDOWS\system32\yuhodose.dll
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Next Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • OTMOVEIT3 log
  • Combofix log
  • a new HJT log obtained after all other steps have been completed
Please let us know how your computer is now.

Thanks
comp looks better now ty a lot
heres the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:01:29 AM, on 2/14/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\conime.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1219651984062
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 5550 bytes






heres the combofix log:

ComboFix 09-02-12.03 - Owner 2009-02-14 0:39:49.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.[removed].18.1271.878 [GMT 8:00]
執行位置: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Outdated)
FW: Norton Personal Firewall *enabled*
* 成功創造新還原點
.

((((((((((((((((((((((((((((((((((((((( 被刪除的檔案 )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\iAlmcoin.dll
c:\windows\system32\xxxz23.ini~
c:\windows\Tasks\qmngisyq.job

—– BITS: Possible infected sites —–

hxxp://77.74.48.105
.
((((((((((((((((((((((((((((((((((((((( 驅動/服務 )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ILVMONEYDRIVER53
——-\Service_IlvMoneyDRIVER53


((((((((((((((((((((((((( 2009-01-13 至 2009-02-13 的新的檔案 )))))))))))))))))))))))))))))))
.

2009-02-14 00:32 . 2009-02-14 00:32 d——– C:\_OTMoveIt
2009-02-13 11:34 . 2009-02-13 11:34 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2009-02-13 11:33 . 2009-02-13 11:34 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-13 11:33 . 2009-02-13 11:33 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-13 11:33 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-13 11:33 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-12 23:07 . 2009-02-12 23:07 d——– c:\program files\Trend Micro
2009-02-12 23:04 . 2009-02-12 23:04 23,301 –a—— c:\windows\system32\AAWService_2009_02_12_23_04_18.dmp
2009-02-12 15:51 . 2009-02-12 15:51 23,079 –a—— c:\windows\system32\AAWService_2009_02_12_15_51_02.dmp
2009-02-12 15:07 . 2009-02-12 14:33 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-02-12 14:34 . 2009-02-12 14:33 64,160 –a—— c:\windows\system32\drivers\Lbd.sys
2009-02-12 14:29 . 2009-02-12 14:29 d–h-c— c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-12 14:28 . 2009-02-12 14:28 d——– c:\program files\Lavasoft
2009-02-12 14:28 . 2009-02-12 14:28 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-09 20:03 . 2009-02-09 20:03 1,563,678 —hs—- c:\windows\system32\rjrygxrn.ini
2009-02-05 21:55 . 2000-04-26 13:34 1,238,288 –a—— c:\windows\system32\msjt4jlt.dll
2009-02-05 21:55 . 2000-04-26 13:35 170,865 –a—— c:\windows\system32\odbcjet.hlp
2009-02-05 21:55 . 2000-04-26 13:34 39,424 –a—— c:\windows\system32\jetcomp.exe
2009-02-04 22:34 . 2009-02-04 22:35 d——– c:\program files\WinPcap
2009-02-04 16:51 . 2009-02-04 17:46 d——– c:\windows\system32\CatRoot_bak
2009-02-04 16:13 . 2008-10-03 18:15 247,326 —–c— c:\windows\system32\dllcache\strmdll.dll
2009-02-04 14:24 . 2009-02-04 14:29 d——– c:\documents and settings\Owner\.smplayer
2009-02-04 09:21 . 2005-01-23 03:12 679,936 –a—— c:\windows\system32\D3DX81ab.dll
2009-02-04 09:20 . 2009-02-04 10:10 d——– c:\program files\WC3Banlist
2009-02-04 07:50 . 2009-02-04 07:50 d——– c:\windows\Application Data
2009-02-04 07:49 . 2009-02-04 07:49 d——– c:\program files\Common Files\INCA Shared
2009-02-04 07:49 . 2003-07-21 11:17 5,174 –a—— c:\windows\system32\nppt9x.vxd
2009-02-04 07:49 . 2005-01-05 02:43 4,682 –a—— c:\windows\system32\npptNT2.sys
2009-02-04 07:46 . 2009-02-04 07:46 d——– c:\program files\WIZET
2009-02-03 19:07 . 2008-10-10 04:52 4,379,984 –a—— c:\windows\system32\D3DX9_40.dll
2009-02-03 19:07 . 2008-10-10 04:52 2,036,576 –a—— c:\windows\system32\D3DCompiler_40.dll
2009-02-03 19:07 . 2008-10-27 10:04 514,384 –a—— c:\windows\system32\XAudio2_3.dll
2009-02-03 19:07 . 2008-10-10 04:52 452,440 –a—— c:\windows\system32\d3dx10_40.dll
2009-02-03 19:07 . 2008-10-27 10:04 235,856 –a—— c:\windows\system32\xactengine3_3.dll
2009-02-03 19:07 . 2008-10-27 10:04 70,992 –a—— c:\windows\system32\XAPOFX1_2.dll
2009-02-03 19:07 . 2008-07-30 06:20 68,616 –a—— c:\windows\system32\XAPOFX1_1.dll
2009-02-03 19:07 . 2008-10-27 10:04 23,376 –a—— c:\windows\system32\X3DAudio1_5.dll
2009-02-03 19:02 . 2009-02-03 19:06 d–h—– c:\windows\msdownld.tmp
2009-02-03 19:01 . 2009-02-03 19:01 d——– c:\windows\Logs
2009-01-31 10:16 . 2009-01-31 10:16 268 –ah—– C:\sqmdata18.sqm
2009-01-31 10:16 . 2009-01-31 10:16 244 –ah—– C:\sqmnoopt18.sqm
2009-01-31 10:14 . 2009-01-31 10:14 268 –ah—– C:\sqmdata17.sqm
2009-01-31 10:14 . 2009-01-31 10:14 244 –ah—– C:\sqmnoopt17.sqm
2009-01-30 09:28 . 2009-01-30 09:28 268 –ah—– C:\sqmdata16.sqm
2009-01-30 09:28 . 2009-01-30 09:28 244 –ah—– C:\sqmnoopt16.sqm
2009-01-29 12:18 . 2009-01-29 12:18 268 –ah—– C:\sqmdata15.sqm
2009-01-29 12:18 . 2009-01-29 12:18 244 –ah—– C:\sqmnoopt15.sqm
2009-01-29 12:13 . 2009-01-29 12:13 268 –ah—– C:\sqmdata14.sqm
2009-01-29 12:13 . 2009-01-29 12:13 244 –ah—– C:\sqmnoopt14.sqm
2009-01-29 12:02 . 2009-01-29 12:02 268 –ah—– C:\sqmdata13.sqm
2009-01-29 12:02 . 2009-01-29 12:02 244 –ah—– C:\sqmnoopt13.sqm
2009-01-28 19:33 . 2009-01-28 19:33 268 –ah—– C:\sqmdata12.sqm
2009-01-28 19:33 . 2009-01-28 19:33 244 –ah—– C:\sqmnoopt12.sqm
2009-01-28 11:52 . 2009-01-28 11:52 268 –ah—– C:\sqmdata11.sqm
2009-01-28 11:52 . 2009-01-28 11:52 244 –ah—– C:\sqmnoopt11.sqm
2009-01-21 17:00 . 2009-01-21 17:00 d——– c:\documents and settings\Owner\Application Data\BDL+D
2009-01-14 09:49 . 2009-01-14 09:49 268 –ah—– C:\sqmdata10.sqm
2009-01-14 09:49 . 2009-01-14 09:49 244 –ah—– C:\sqmnoopt10.sqm
2009-01-13 21:13 . 2009-01-13 21:13 268 –ah—– C:\sqmdata09.sqm
2009-01-13 21:13 . 2009-01-13 21:13 244 –ah—– C:\sqmnoopt09.sqm

.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-13 16:44 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-02-12 06:10 ——— d—–w c:\program files\BitComet
2009-02-09 02:50 ——— d—–w c:\program files\Warcraft III
2009-02-05 13:55 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-04 06:38 ——— d—–w c:\program files\Garena
2009-01-17 15:26 ——— d—–w c:\documents and settings\Owner\Application Data\Skype
2009-01-17 10:48 ——— d—–w c:\documents and settings\Owner\Application Data\skypePM
2009-01-13 06:08 ——— d—–w c:\documents and settings\Owner\Application Data\DVD Flick
2009-01-08 03:07 ——— d—–w c:\program files\Recuva
2009-01-08 02:43 ——— d—–w c:\program files\DiskInternals
2009-01-04 04:30 ——— d—–w c:\documents and settings\Owner\Application Data\OLYMPUS
2009-01-04 04:26 ——— d—–w c:\program files\OLYMPUS
2009-01-04 04:24 ——— d—–w c:\program files\PIXELA
2009-01-01 15:47 ——— d—–w c:\program files\T-TIME
2008-12-26 10:57 ——— d—–w c:\documents and settings\Owner\Application Data\ImgBurn
2008-12-26 10:56 ——— d—–w c:\program files\ImgBurn
2008-12-25 14:43 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-24 19:35 ——— d—–w c:\program files\Real Alternative
2008-12-24 19:09 ——— d—–w c:\documents and settings\Owner\Application Data\Winamp
2008-12-24 10:12 ——— d—–w c:\documents and settings\Owner\Application Data\AdobeUM
2008-12-23 01:59 ——— d—–w c:\documents and settings\Owner\Application Data\Samsung
2008-12-23 01:55 ——— d—–w c:\program files\Samsung
2008-12-21 16:34 ——— d—–w c:\program files\Common Files\NSV
2008-12-21 16:33 ——— d—–w c:\program files\Winamp
2008-12-21 16:21 ——— d—–w c:\program files\SopCast
2008-12-19 12:31 ——— d—–w c:\program files\Pcsx2_0.9.4
2008-12-19 12:20 715,248 —-a-w c:\windows\system32\drivers\sptd.sys
2008-12-19 11:30 283,648 —-a-w c:\windows\uninst.exe
2008-12-19 10:58 ——— d—–w c:\documents and settings\Owner\Application Data\Sonic
2008-12-19 10:58 ——— d—–w c:\documents and settings\Owner\Application Data\Leadertech
2008-12-19 10:56 ——— d—–w c:\program files\MagicISO
2008-12-18 06:10 ——— d—–w c:\program files\K-Lite Codec Pack
2008-12-15 16:21 ——— d—–w c:\program files\Real
2008-12-15 15:57 ——— d—–w c:\documents and settings\Owner\Application Data\Motive
2008-12-15 15:24 ——— d—–w c:\documents and settings\Owner\Application Data\Media Player Classic
2008-12-15 15:08 ——— d—–w c:\program files\VideoLAN
2008-11-30 17:33 2,829 —-a-w c:\windows\War3Unin.pif
2008-11-30 17:33 139,264 —-a-w c:\windows\War3Unin.exe
2008-07-04 02:33 24,576 —-a-w c:\program files\mozilla firefox\components\CheckTudouVa.dll
2008-08-25 03:50 32 –sha-w c:\windows\{93578138-03D7-4DD0-A61A-A5E326163AA9}.dat
2008-08-25 03:50 32 –sha-w c:\windows\system32\{515EBEFE-739A-45B5-BC21-1BB61D782644}.dat
.

((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 218032]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"MSPY2002"="c:\windows\System32\IME\PINTLGNT\ImScInst.exe" [2003-08-17 59392]
"PHIME2002ASync"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2003-08-17 455168]
"PHIME2002A"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2003-08-17 455168]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-09 71328]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2008-08-25 95960]
"ccRegVfy"="c:\program files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-11-14 59072]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2008-09-29 17:57 21755688 c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"Game.exe"= Game.exe:GostSoul
"c:\\Program Files\\Compaq Connections\\1940576\\Program\\BackWeb-1940576.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-12 64160]
R2 ccPxySvc;Symantec Proxy Service;c:\program files\Norton Personal Firewall\ccPxySvc.exe [2002-11-14 34496]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 DBKDRVR54;DBKDRVR54;\??\c:\program files\Cheat Engine\dbk32.sys –> c:\program files\Cheat Engine\dbk32.sys [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-19 950096]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-07 34064]
S3 s716bus;Sony Ericsson Device 716 driver (WDM);c:\windows\system32\drivers\s716bus.sys [2008-09-02 83208]
S3 s716mdfl;Sony Ericsson Device 716 USB WMC Modem Filter;c:\windows\system32\drivers\s716mdfl.sys [2008-09-02 15112]
S3 s716mdm;Sony Ericsson Device 716 USB WMC Modem Driver;c:\windows\system32\drivers\s716mdm.sys [2008-09-02 108552]
S3 s716mgmt;Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s716mgmt.sys [2008-09-02 100360]
S3 s716nd5;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS);c:\windows\system32\drivers\s716nd5.sys [2008-09-02 23176]
S3 s716obex;Sony Ericsson Device 716 USB WMC OBEX Interface;c:\windows\system32\drivers\s716obex.sys [2008-09-02 98568]
S3 s716unic;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM);c:\windows\system32\drivers\s716unic.sys [2008-09-02 98952]
S3 XDva035;XDva035;\??\c:\windows\system32\XDva035.sys –> c:\windows\system32\XDva035.sys [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b74514ee-da17-11dd-9090-000c76a41459}]
\Shell\auto\command - F:\SVCH0ST.EXE e
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL SVCH0ST.EXE e
.
‘計劃任務’ 文件夾 裡的內容

2009-02-12 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-12 14:32]

2009-02-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-02-13 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-06-19 07:17]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-RecordNow! - (no file)
MSConfigStartUp-CTFMON - (no file)


.
——- 而外的掃描 ——-
.
uStart Page = hxxp://qsg10.hpwis.com/
mStart Page = hxxp://qsg10.hpwis.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
Trusted Zone: microsoft.com\www.update
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo!
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=chrff-brandt_off&type=000123X001US&p=
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJPI142.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPHoldemFireLauncher.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMFireLauncher.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-14 00:44:04
Windows 5.1.2600 Service Pack 2 NTFS

掃描被隱藏的進程 。。。

掃描被隱藏的啟動組 。。。

掃描被隱藏的文件 。。。

掃描完成
被隱藏的檔案: 0

**************************************************************************
.
———————— 其他運行進程 ————————
.
c:\windows\system32\conime.exe
c:\program files\Common Files\Symantec Shared\CCSETMGR.EXE
c:\program files\Norton Personal Firewall\NISUM.EXE
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\CCEVTMGR.EXE
c:\program files\Common Files\Symantec Shared\Security Center\SymWSC.exe
.
**************************************************************************
.
完成時間: 2009-02-14 0:50:53 - 電腦已重新啟動
ComboFix-quarantined-files.txt 2009-02-13 16:50:50

Pre-Run: 20,482,027,520 bytes free
Post-Run: 20,386,455,552 bytes free

264 — E O F — 2009-02-05 12:34:36



heres the otmoveit log:


========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File/Folder C:\WINDOWS\system32\xxyxWoMe.dll not found.
File/Folder C:\WINDOWS\system32\mlJawwTn.dll not found.
File/Folder C:\WINDOWS\system32\gokisoso.dll not found.
File/Folder C:\WINDOWS\system32\yuhodose.dll not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_6iiyFUHepIL1wJFbqWlP scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02142009_003235

Files moved on Reboot…
File C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_6iiyFUHepIL1wJFbqWlP not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\XUL.mfl moved successfully.
Hi chankfj,

Your antivirus program is out of date. Any reason, did it expire?

You also have this program Cheat Engine, I suggest you uninstall it.

We're going to use OTMOVEIT3 again. Run it like you did before but use this fix

  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b74514ee-da17-11dd-9090-000c76a41459}]
    
    :Files
    c:\windows\system32\rjrygxrn.ini
    C:\sqmdata*.sqm
    C:\sqmnoopt*.sqm
    
    :Commands
    [emptytemp]
    [start explorer]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
Please post the log in your next reply.

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file paths, one at a time into the "Suspicious files to scan" box on the top of the page:
  • wait for the results before submitting the second file

    c:\windows\{93578138-03D7-4DD0-A61A-A5E326163AA9}.dat
    c:\windows\system32\{515EBEFE-739A-45B5-BC21-1BB61D782644}.dat

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Your java is out of date. Copy and paste these instructions into a notepad and save it to your desktop so you can refer to them. Your browsers will have to be closed to use this tool.

Please download JavaRa to your desktop and unzip it to its own folder
  • Close all browsers
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.
The current version is JRE6 Update 11
Note JRE6 Update12 may be offered. It is the same except it has support for 64 bit browsers. Either one will be ok)

Please post back with
  • OTMOVEIT3 log
  • VirSCAN.org FREE results
  • new HJT log
Thanks
ya my norton anti virus subscription has expired.
btw, do i just delete the cheat engine file from my program files?
when i m using otmoveit and it ask me to reboot, it turns into a black screen after reboot and i have to restart my com again to have it function normally.

heres the otmoveit log:

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b74514ee-da17-11dd-9090-000c76a41459}\\ deleted successfully.
========== FILES ==========
c:\windows\system32\rjrygxrn.ini moved successfully.
C:\sqmdata00.sqm moved successfully.
C:\sqmdata01.sqm moved successfully.
C:\sqmdata02.sqm moved successfully.
C:\sqmdata03.sqm moved successfully.
C:\sqmdata04.sqm moved successfully.
C:\sqmdata05.sqm moved successfully.
C:\sqmdata06.sqm moved successfully.
C:\sqmdata07.sqm moved successfully.
C:\sqmdata08.sqm moved successfully.
C:\sqmdata09.sqm moved successfully.
C:\sqmdata10.sqm moved successfully.
C:\sqmdata11.sqm moved successfully.
C:\sqmdata12.sqm moved successfully.
C:\sqmdata13.sqm moved successfully.
C:\sqmdata14.sqm moved successfully.
C:\sqmdata15.sqm moved successfully.
C:\sqmdata16.sqm moved successfully.
C:\sqmdata17.sqm moved successfully.
C:\sqmdata18.sqm moved successfully.
C:\sqmnoopt00.sqm moved successfully.
C:\sqmnoopt01.sqm moved successfully.
C:\sqmnoopt02.sqm moved successfully.
C:\sqmnoopt03.sqm moved successfully.
C:\sqmnoopt04.sqm moved successfully.
C:\sqmnoopt05.sqm moved successfully.
C:\sqmnoopt06.sqm moved successfully.
C:\sqmnoopt07.sqm moved successfully.
C:\sqmnoopt08.sqm moved successfully.
C:\sqmnoopt09.sqm moved successfully.
C:\sqmnoopt10.sqm moved successfully.
C:\sqmnoopt11.sqm moved successfully.
C:\sqmnoopt12.sqm moved successfully.
C:\sqmnoopt13.sqm moved successfully.
C:\sqmnoopt14.sqm moved successfully.
C:\sqmnoopt15.sqm moved successfully.
C:\sqmnoopt16.sqm moved successfully.
C:\sqmnoopt17.sqm moved successfully.
C:\sqmnoopt18.sqm moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_RFaljm1TAzUyLTweMAmj scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\yp9f178h.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02142009_085949


heres the online virus scan results:

VirSCAN.org Scanned Report :
Scanned time : 2009/02/14 09:07:39 (SGT)
Scanner results: All Scanners reported not find malware!
File Name : {93578138-03D7-4DD0-A61A-A5E326163AA9}.dat
File Size : 32 byte
File Type : data
MD5 : f46cb35ce945850a5cee2f2aae21cc3e
SHA1 : 6315f9d9cdda79ddb4fa9297db5562c1cd38c8f1
Online report : http://virscan.org/report/d9e1bd103fe6cbd2…01b10c456e.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.29 20090214000148 2009-02-14 2.15 -
AhnLab V3 2009.02.13.03 2009.02.13 2009-02-13 1.03 -
AntiVir 7.9.0.79 7.1.2.25 2009-02-13 1.77 -
Antiy 2.0.18 20090213.2182774 2009-02-13 0.12 -
Authentium 5.1.1 200902131919 2009-02-13 1.09 -
AVAST! 3.0.1 090213-0 2009-02-13 0.81 -
AVG 7.5.52.442 270.10.23/1952 2009-02-13 1.89 -
BitDefender 7.81008.2657700 7.23655 2009-02-14 2.46 -
CA (VET) 9.0.0.143 31.6.6357 2009-02-14 5.21 -
ClamAV 0.94.2 8989 2009-02-14 0.00 -
Comodo 3.0 976 2009-02-13 0.92 -
CP Secure 1.1.0.715 2009.02.14 2009-02-14 6.81 -
Dr.Web 4.44.0.9170 2009.02.13 2009-02-13 3.97 -
F-Prot 4.4.4.56 20090213 2009-02-13 1.06 -
F-Secure 5.51.6100 2009.02.13.04 2009-02-13 4.55 -
Fortinet 2.81-3.117 10.34 2009-02-13 0.18 -
GData 19.3070/19.223 20090214 2009-02-14 3.12 -
ViRobot 20090213 2009.02.13 2009-02-13 0.40 -
Ikarus T3.1.01.45 2009.02.13.72297 2009-02-13 3.68 -
JiangMin 11.0.706 2009.02.13 2009-02-13 1.44 -
Kaspersky 5.5.10 2009.02.13 2009-02-13 0.02 -
KingSoft 2008.9.8.18 2009.2.13.21 2009-02-13 0.61 -
McAfee 5.3.00 5525 2009-02-13 3.19 -
Microsoft 1.4306 2009.02.14 2009-02-14 4.31 -
mks_vir 2.01 2009.02.14 2009-02-14 2.60 -
Norman 6.00.02 6.00.00 2009-02-13 8.01 -
Panda 9.05.01 2009.02.13 2009-02-13 1.55 -
Trend Micro 8.700-1004 5.842.06 2009-02-13 0.02 -
Quick Heal 10.00 2009.02.13 2009-02-13 0.89 -
Rising 20.0 21.16.42.00 2009-02-13 0.28 -
Sophos 2.83.3 4.38 2009-02-14 2.38 -
Sunbelt 4809 4809 2009-02-11 0.47 -
Symantec 1.3.0.24 20090213.003 2009-02-13 0.17 -
nProtect 20090213.02 3127493 2009-02-13 3.67 -
The Hacker [removed] v00256 2009-02-13 0.47 -
VBA32 3.12.8.12 20090213.0909 2009-02-13 1.75 -
VirusBuster 4.5.11.10 10.101.12/904088 2009-02-13 1.15 -


VirSCAN.org Scanned Report :
Scanned time : 2009/02/14 09:11:17 (SGT)
Scanner results: All Scanners reported not find malware!
File Name : {515EBEFE-739A-45B5-BC21-1BB61D782644}.dat
File Size : 32 byte
File Type : data
MD5 : 39b3271834b086542a1d95c9e1c3e2f6
SHA1 : 7218e1241aac9d750c02197c3d098f6af1813372
Online report : http://virscan.org/report/0c5c0ada02f447c2…e393b59a37.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.29 20090214000148 2009-02-14 2.16 -
AhnLab V3 2009.02.13.03 2009.02.13 2009-02-13 1.04 -
AntiVir 7.9.0.79 7.1.2.25 2009-02-13 1.78 -
Antiy 2.0.18 20090213.2182774 2009-02-13 0.12 -
Authentium 5.1.1 200902131919 2009-02-13 1.07 -
AVAST! 3.0.1 090213-0 2009-02-13 0.82 -
AVG 7.5.52.442 270.10.23/1952 2009-02-13 1.89 -
BitDefender 7.81008.2658359 7.23657 2009-02-14 2.46 -
CA (VET) 9.0.0.143 31.6.6357 2009-02-14 5.07 -
ClamAV 0.94.2 8989 2009-02-14 0.00 -
Comodo 3.0 976 2009-02-13 0.91 -
CP Secure 1.1.0.715 2009.02.14 2009-02-14 6.83 -
Dr.Web 4.44.0.9170 2009.02.14 2009-02-14 4.01 -
F-Prot 4.4.4.56 20090213 2009-02-13 1.06 -
F-Secure 5.51.6100 2009.02.13.04 2009-02-13 4.57 -
Fortinet 2.81-3.117 10.34 2009-02-13 0.14 -
GData 19.3070/19.223 20090214 2009-02-14 3.13 -
ViRobot 20090213 2009.02.13 2009-02-13 0.40 -
Ikarus T3.1.01.45 2009.02.13.72297 2009-02-13 3.67 -
JiangMin 11.0.706 2009.02.13 2009-02-13 1.44 -
Kaspersky 5.5.10 2009.02.14 2009-02-14 0.02 -
KingSoft 2008.9.8.18 2009.2.13.21 2009-02-13 0.61 -
McAfee 5.3.00 5525 2009-02-13 3.20 -
Microsoft 1.4306 2009.02.14 2009-02-14 4.30 -
mks_vir 2.01 2009.02.14 2009-02-14 2.68 -
Norman 6.00.02 6.00.00 2009-02-13 8.01 -
Panda 9.05.01 2009.02.13 2009-02-13 1.54 -
Trend Micro 8.700-1004 5.842.06 2009-02-13 0.02 -
Quick Heal 10.00 2009.02.13 2009-02-13 0.89 -
Rising 20.0 21.16.42.00 2009-02-13 0.32 -
Sophos 2.83.3 4.38 2009-02-14 2.36 -
Sunbelt 4809 4809 2009-02-11 0.47 -
Symantec 1.3.0.24 20090213.003 2009-02-13 0.17 -
nProtect 20090213.02 3127493 2009-02-13 3.69 -
The Hacker [removed] v00256 2009-02-13 0.47 -
VBA32 3.12.8.12 20090213.0909 2009-02-13 1.53 -
VirusBuster 4.5.11.10 10.101.12/904088 2009-02-13 1.12 -


heres the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:24:50 AM, on 2/14/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\ctfmon.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\WINDOWS\system32\wuauclt.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qsg10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qsg10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9415/tudouva.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1219651984062
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 7234 bytes
i have updated to windows sp 3 is tt a problem?

this is my new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:45:10 AM, on 2/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\WINDOWS\system32\wuauclt.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qsg10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9415/tudouva.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1219651984062
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 7587 bytes
Hi chankfj,

btw, do i just delete the cheat engine file from my program files?

No, Uninstall Cheat Engine from add/remove programs.

Click the start button, click control panel, double click add/remove programs

Once you uninstall it you can delete this folder c:\program files\Cheat Engine

i have updated to windows sp 3 is tt a problem?

No it shouldn't be. Thanks for the new HJT log.

Just to make sure there isn't infection left, I'll have you do an online scan. After you post back I can assist you in replacing Norton (Symantec), unless you are planning to renew it. Let me know.

Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Desktop is a good place.
  • Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply along with a new HijackThis log.

Thanks
sorry for he late reply .

heres the report from kaspersky:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Sunday, February 15, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Sunday, February 15, 2009 02:04:33
Records in database: 1797942
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\

Scan statistics:
Files scanned: 83133
Threat name: 2
Infected objects: 331
Suspicious objects: 0
Duration of the scan: 04:19:20


File name / Threat name / Threats count
C:\Program Files\Norton AntiVirus\Quarantine\0EE9007B.exe Infected: Packed.Win32.Black.a 1
C:\Program Files\Norton AntiVirus\Quarantine\6BC9063F.exe Infected: Packed.Win32.Black.a 1
C:\WINDOWS\I386\winntupg\FSFILTER.HTM Infected: Worm.Win32.Mefir.k 1
C:\WINDOWS\I386\winntupg\UNSUPMSG.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\3COM.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\AACRAID.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ACER640P.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ACLIENT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ACS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ADAPTEC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ADMPKW2K.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ADMPKXP.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\AHA8940.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\AICDRV.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ALKB2K.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ALPSPRT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\APFILTR.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\APMERROR.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ARTCAS6E.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ASSETCI.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ATGUARD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ATKPROTO.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\AVPGATEK.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\AWARD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\BAYMAN.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\BLACKICE.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\BOSERROR.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CALCOMP.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CANO620P.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CANOS100.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CARDEXEC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CDR4VSD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CERTSRV.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CIC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CIMGR.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CISCOACU.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CLDVD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CLTMGR.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CNBJ51.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CNMULTI1.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CPQDIAGC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CPQIJ.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CPQKBD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CPQMULTI.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CPQPNPMG.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CPQPWREX.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CPUFEAT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CRASHMON.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CRUISE.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CRYSTAL.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CS4281.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CSA64XX.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CSMIGRAT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CSREM32.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\CTZ_CRDL.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DAYT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DECATAPI.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DECML.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DELLPS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DELLTH.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DELPERC2.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DIRECTCD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DLCPROTO.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DMIBIOS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DOCK.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DOCKSVC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DRVNCDB.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DSMU.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DV_COMP.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DV_GEN.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\DWRITE.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\EICONTA.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ELSAMX.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ENSONIQV.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ENSQAUDM.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\EPSCOLOR.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\EPSON1.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\EPSON3.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\EPSON4.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\EPSP1270.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\EPSPHOTO.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\EXCHANGE.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\FAZAM.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\FIDMOU.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\FLOWCH7.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\FTCOMP1.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\FTCOMP2.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\FTCOMP3.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\GENERIC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\GENIUS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\GLINT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\GSNW.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HALHOOK.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HDMIB.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HDMON.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HERCULES.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HP3300C.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HP4050P6.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HP4300C.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HP5300C.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPAIO1.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPAIO2.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPCLJ450.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPCLJ850.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPCOMPAT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDJ1000.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDJ610.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDJ810.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDJ815.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDJ830.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDJ880.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDJ900.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDMI.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK1.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK10.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK11.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK12.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK13.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK14.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK2.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK3.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK4.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK5.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK6.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK7.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK8.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPDSK9.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPI_USB.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPLJ1100.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPLJ4050.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPLJ5E.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPLOCK.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPMMKB.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPMON.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPNRD4M.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPOJG.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPPS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPSMART.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPSPARNT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HPTTIDM.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\HP_PLD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\I2CNT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\IAVBOOT4.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\IBMIR.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\IBMMPG.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\IBMSVA.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\IBMTP4.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\IBMVC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\IBM_UMS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ICPV.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ICSUPGRD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ILS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\IMATION.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\INCOMPAT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\INITIO.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\INTELAPP.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\INTELATA.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\INTELLIP.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\INTLSISL.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\IOCLICK.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\IOMEGA.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ISHRNT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ISOTP4.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ISVGINA.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\IX526FC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\KMW.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\KODK4800.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\KRNLCHK.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LAPLINK.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LAPLNK2K.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LDCM.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LEX3200.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LEXDLC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LEXOPTRA.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LEXTCP.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LM5700.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LM75.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LM78.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LMOPTRA.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LMREPL.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LOGITECH.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LOGKCMD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LQDAUDIO.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\LTMODEM.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MACDRIVE.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MAESTRO0.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MAXELL.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MCA.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MCFILTER.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MCROTK60.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MCROTKC3.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MCROTKS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MELCO.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MFPBR.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MFPHP.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MGACTRL.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MIN8E.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MINPW20.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MNLT1.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MPATH.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MSMQCOMP.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MSP1.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MSP2.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MSSS3.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MSTOCK.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\MTA57080.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\NAV5.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\NBFPROTO.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\NDCPRTNS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\NECPG1.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\NETFMIGT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\NMSMS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\NTDSUPG.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\NTDSUPGD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\NV_AGP.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\NWCLI32.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\OCABLOCK.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\OILCHG25.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\OKIPG1.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\OKIPG2.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\OKIPG8W.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\OMC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\OMNIPG10.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ONSTREAM.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ORB.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PALM.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PANADVD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PANDA.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PCANY.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PCCILLIN.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PCIINFO.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PCPNP.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PELMOUSE.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PFS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PHNIXAD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PHPIPE.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PLUST120.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\POWER.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\POWPATH.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PROCCNT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PROLIGHT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PS2CONT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PSTRIP.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PUMACSM.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\PWRICON.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\QIC117.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\QUICK3.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\RCENTRL.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\REACHOUT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\RIPTIDE.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\RUNONCE.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SBS45FXC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SBS50FXC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SCANDRV.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SDSELECT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SFUNFSCG.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SHARSHTL.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SIGMA.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SIIG.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SIIGC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SISV.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SIWVID.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SKUSBKBF.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SMS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SNA.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SNIDMI.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SNIDPMS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SNIPCI.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SOFTOFF.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SONIC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SONYJDU.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SPXBLOCK.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SQL.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SSCNTRL.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SSI365.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SSPOWER.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\STB.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SWOFF.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SYSHWCFG.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SYSMGMT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\SYSMON.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TITSB.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TIVOLI.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TMASTER.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TMDIGPRO.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TMDUALAG.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TOPTOOLS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TOSDVD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TPCHRSRV.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TPCONFIG.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TPFUEL.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TPPMPORT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TRIDWNW.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TSBAPM.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TSBASD.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TSBDS.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TSBHDDPW.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TSBMC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TSBSELBA.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TSBVCAP.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TSCOMP4.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TSCOMP5.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TSSCIDRV.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\TT128.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\UMAX.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\UTUPGR05.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\UTUPGR06.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\VGAMODE.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\VIDAPPLT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\VISN5300.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\VISN6100.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\WACOMDRV.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\WCE21.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\WCGODRV.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\WCMIGRAT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\WEBSCANX.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\WINACHSF.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\WINSQL.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\WTCLS2K.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\XEROX1.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\XEROX2.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\XEROX4.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\XEROX5.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\XEROX6.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\XEROXWCT.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\XLINK.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\YACXG.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\YMHSYNTH.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\COMPDATA\ZIPMAGIC.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\WINNTUPG\FSFILTER.HTM Infected: Worm.Win32.Mefir.k 1
D:\I386\WINNTUPG\UNSUPMSG.HTM Infected: Worm.Win32.Mefir.k 1

The selected area was scanned.


heres the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:28:47 PM, on 2/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qsg10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9415/tudouva.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1219651984062
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 7494 bytes


ty for ur help
Hi chankfj,

What is your D:\ drive?

Let's see if these detections are false positives by Kaspersky.

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file paths, one at a time into the "Suspicious files to scan" box on the top of the page:
  • wait for the results before submitting the next file

    C:\WINDOWS\I386\winntupg\UNSUPMSG.HTM
    D:\I386\COMPDATA\AVPGATEK.HTM
    D:\I386\COMPDATA\CNBJ51.HTM

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Thanks
errrm the D drive is a partition of C drive. i tink its used for system recovery or wad.

btw heres the scan

VirSCAN.org Scanned Report :
Scanned time : 2009/02/16 02:59:23 (SGT)
Scanner results: All Scanners reported not find malware!
File Name : UNSUPMSG.HTM
File Size : 1181 byte
File Type : HTML document text
MD5 : e94fc996aaad5e50017218cc91df2a03
SHA1 : c061ea1059dfc916340213fa4840988c14d44f75
Online report : http://virscan.org/report/0cd1dda7505141ed…8d0d14a513.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.29 20090216003117 2009-02-16 3.95 -
AhnLab V3 2009.02.16.00 2009.02.16 2009-02-16 2.45 -
AntiVir 7.9.0.79 7.1.2.26 2009-02-15 1.79 -
Antiy 2.0.18 20090215.2186042 2009-02-15 0.12 -
Authentium 5.1.1 200902141427 2009-02-14 1.09 -
AVAST! 3.0.1 090215-0 2009-02-15 0.00 -
AVG 7.5.52.442 270.10.23/1953 2009-02-14 1.95 -
BitDefender 7.81008.2667542 7.23688 2009-02-16 2.48 -
CA (VET) 9.0.0.143 31.6.6358 2009-02-14 4.73 -
ClamAV 0.94.2 8993 2009-02-15 0.00 -
Comodo 3.0 978 2009-02-15 0.94 -
CP Secure 1.1.0.715 2009.02.16 2009-02-16 6.91 -
Dr.Web 4.44.0.9170 2009.02.15 2009-02-15 4.04 -
F-Prot 4.4.4.56 20090214 2009-02-14 1.07 -
F-Secure 5.51.6100 2009.02.15.01 2009-02-15 4.47 -
Fortinet 2.81-3.117 10.44 2009-02-15 0.14 -
GData 19.3114/19.225 20090215 2009-02-15 3.18 -
ViRobot 20090214 2009.02.14 2009-02-14 0.41 -
Ikarus T3.1.01.45 2009.02.15.72304 2009-02-15 3.71 -
JiangMin 11.0.706 2009.02.15 2009-02-15 1.49 -
Kaspersky 5.5.10 2009.02.15 2009-02-15 0.02 -
KingSoft 2008.9.8.18 2009.2.15.20 2009-02-15 0.64 -
McAfee 5.3.00 5527 2009-02-15 3.21 -
Microsoft 1.4306 2009.02.15 2009-02-15 4.40 -
mks_vir 2.01 2009.02.15 2009-02-15 2.65 -
Norman 6.00.02 6.00.00 2009-02-13 8.01 -
Panda 9.05.01 2009.02.14 2009-02-14 1.58 -
Trend Micro 8.700-1004 5.846.01 2009-02-15 0.02 -
Quick Heal 10.00 2009.02.13 2009-02-13 0.89 -
Rising 20.0 21.16.60.00 2009-02-15 0.24 -
Sophos 2.83.3 4.38 2009-02-16 2.39 -
Sunbelt 4809 4809 2009-02-11 0.48 -
Symantec 1.3.0.24 20090215.002 2009-02-15 0.23 -
nProtect 20090215.01 3150113 2009-02-15 3.83 -
The Hacker [removed] v00257 2009-02-14 0.49 -
VBA32 3.12.8.12 20090214.2034 2009-02-14 1.71 -
VirusBuster 4.5.11.10 10.101.14/904128 2009-02-15 1.12 -



VirSCAN.org Scanned Report :
Scanned time : 2009/02/16 03:02:51 (SGT)
Scanner results: All Scanners reported not find malware!
File Name : AVPGATEK.HTM
File Size : 610 byte
File Type : HTML document text
MD5 : b5fc4bda0ca8a0bd669bd8ccea448246
SHA1 : 037be59b65ba9bb363a3701d52a34566b91e2236
Online report : http://virscan.org/report/c53864b412659672…5552e58d13.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.29 20090216003117 2009-02-16 2.16 -
AhnLab V3 2009.02.16.00 2009.02.16 2009-02-16 1.05 -
AntiVir 7.9.0.79 7.1.2.26 2009-02-15 1.77 -
Antiy 2.0.18 20090215.2186042 2009-02-15 0.12 -
Authentium 5.1.1 200902141427 2009-02-14 1.10 -
AVAST! 3.0.1 090215-0 2009-02-15 0.00 -
AVG 7.5.52.442 270.10.23/1953 2009-02-14 1.90 -
BitDefender 7.81008.2667542 7.23688 2009-02-16 2.48 -
CA (VET) 9.0.0.143 31.6.6358 2009-02-14 5.73 -
ClamAV 0.94.2 8993 2009-02-15 0.00 -
Comodo 3.0 978 2009-02-15 1.26 -
CP Secure 1.1.0.715 2009.02.16 2009-02-16 6.90 -
Dr.Web 4.44.0.9170 2009.02.15 2009-02-15 4.01 -
F-Prot 4.4.4.56 20090214 2009-02-14 1.10 -
F-Secure 5.51.6100 2009.02.15.01 2009-02-15 0.04 -
Fortinet 2.81-3.117 10.44 2009-02-15 0.14 -
GData 19.3114/19.225 20090215 2009-02-15 4.03 -
ViRobot 20090214 2009.02.14 2009-02-14 0.41 -
Ikarus T3.1.01.45 2009.02.15.72304 2009-02-15 3.68 -
JiangMin 11.0.706 2009.02.15 2009-02-15 1.52 -
Kaspersky 5.5.10 2009.02.15 2009-02-15 0.02 -
KingSoft 2008.9.8.18 2009.2.15.20 2009-02-15 0.71 -
McAfee 5.3.00 5527 2009-02-15 3.20 -
Microsoft 1.4306 2009.02.15 2009-02-15 5.02 -
mks_vir 2.01 2009.02.15 2009-02-15 2.69 -
Norman 6.00.02 6.00.00 2009-02-13 8.01 -
Panda 9.05.01 2009.02.14 2009-02-14 1.56 -
Trend Micro 8.700-1004 5.846.01 2009-02-15 0.02 -
Quick Heal 10.00 2009.02.13 2009-02-13 0.92 -
Rising 20.0 21.16.60.00 2009-02-15 0.25 -
Sophos 2.83.3 4.38 2009-02-16 2.40 -
Sunbelt 4809 4809 2009-02-11 0.54 -
Symantec 1.3.0.24 20090215.002 2009-02-15 0.20 -
nProtect 20090215.01 3150113 2009-02-15 5.22 -
The Hacker [removed] v00257 2009-02-14 1.06 -
VBA32 3.12.8.12 20090214.2034 2009-02-14 1.56 -
VirusBuster 4.5.11.10 10.101.14/904128 2009-02-15 1.12 -





VirSCAN.org Scanned Report :
Scanned time : 2009/02/16 03:06:14 (SGT)
Scanner results: All Scanners reported not find malware!
File Name : CNBJ51.HTM
File Size : 881 byte
File Type : HTML document text
MD5 : 9b1071af02752074408363475d7b2043
SHA1 : 92621d4f165da520926fb4ae21440d8c714e664c
Online report : http://virscan.org/report/5af84714c82f3409…d935540ca8.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.29 20090216003117 2009-02-16 2.31 -
AhnLab V3 2009.02.16.00 2009.02.16 2009-02-16 1.66 -
AntiVir 7.9.0.79 7.1.2.26 2009-02-15 1.78 -
Antiy 2.0.18 20090215.2186042 2009-02-15 0.12 -
Authentium 5.1.1 200902141427 2009-02-14 1.08 -
AVAST! 3.0.1 090215-0 2009-02-15 0.00 -
AVG 7.5.52.442 270.10.23/1953 2009-02-14 1.92 -
BitDefender 7.81008.2667542 7.23688 2009-02-16 2.48 -
CA (VET) 9.0.0.143 31.6.6358 2009-02-14 6.07 -
ClamAV 0.94.2 8993 2009-02-15 0.00 -
Comodo 3.0 978 2009-02-15 0.94 -
CP Secure 1.1.0.715 2009.02.16 2009-02-16 6.89 -
Dr.Web 4.44.0.9170 2009.02.15 2009-02-15 3.98 -
F-Prot 4.4.4.56 20090214 2009-02-14 1.10 -
F-Secure 5.51.6100 2009.02.15.01 2009-02-15 4.24 -
Fortinet 2.81-3.117 10.45 2009-02-15 0.17 -
GData 19.3115/19.225 20090215 2009-02-15 8.37 -
ViRobot 20090214 2009.02.14 2009-02-14 0.99 -
Ikarus T3.1.01.45 2009.02.15.72304 2009-02-15 3.83 -
JiangMin 11.0.706 2009.02.15 2009-02-15 2.33 -
Kaspersky 5.5.10 2009.02.15 2009-02-15 0.02 -
KingSoft 2008.9.8.18 2009.2.15.20 2009-02-15 0.63 -
McAfee 5.3.00 5527 2009-02-15 3.21 -
Microsoft 1.4306 2009.02.15 2009-02-15 6.20 -
mks_vir 2.01 2009.02.15 2009-02-15 2.68 -
Norman 6.00.02 6.00.00 2009-02-13 8.01 -
Panda 9.05.01 2009.02.14 2009-02-14 2.20 -
Trend Micro 8.700-1004 5.846.01 2009-02-15 0.02 -
Quick Heal 10.00 2009.02.13 2009-02-13 0.98 -
Rising 20.0 21.16.60.00 2009-02-15 0.65 -
Sophos 2.83.3 4.38 2009-02-16 2.40 -
Sunbelt 4809 4809 2009-02-11 0.70 -
Symantec 1.3.0.24 20090215.002 2009-02-15 0.16 -
nProtect 20090215.01 3150113 2009-02-15 10.73 -
The Hacker [removed] v00257 2009-02-14 0.48 -
VBA32 3.12.8.12 20090214.2034 2009-02-14 1.57 -
VirusBuster 4.5.11.10 10.101.14/904128 2009-02-15 1.11 -



and heres the new HJT log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:10:40 AM, on 2/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qsg10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9415/tudouva.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1219651984062
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 7514 bytes
Hi chankfj,

Looks good. We'll clean up the tools and I'll give you some suggestions.

From your desktop, please delete
  • any notepads/logs that were created
I suggest you keep ATF and MBAM. Keep MBAM updated and use it as an on demand scanner.

Next, Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /u

Open OTMOVEIT3 then click the Clean Up button. You may get prompted by your firewall that OTMoveIt wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

If you are not planning on reneming your Symantec (Norton) antivirus program, I suggest you replace it. You can get a free antivirus program from any of these 3 vendors. Download only one and save it to your desktop. Do not install it yet.

Avast
Help and support can be found here Avast Forum
AVG
Help and support can be found here AVG Forum
Antivir PersonalEditionClassic
Help and support can be found here Avira Personal Support Forum

Your current antivirus program is part of a suite. Since the components are interconnected, it would be best to remove the entire suite. You can replace the firewall with a good free one when you are finished.

Download the appropriate Norton Removal Tool from

2002 and earlier

2003 and newer

and save it to your desktop. You will use it later.

Disconnect from the internet completely, pull the plug on the modem if necessary.

Go to add/remove programs and uninstall any program with Symantec or Norton in the name.

Next double click Norton Removal Tool that you downloaded earlier to run the tool.

Follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.

Now install your new antivirus program.

Next, make sure your Windows firewall is turned on,

Click start, click control panel, click Security Center. At the bottom of Security Center click windows firewall. Ensure it is set to On.

Updates and upgrades

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 6 first. Be sure to move any PDF documents to another folder first though. Instructions can be found here.
http://kb.adobe.com/selfservice/viewConten…ternalId=327675

Some Recommendations and prevention tips

I STRONGLY recommend you use an antispyware program with resident (real time) scanning. I suggest

Winpatrol
OR
Windows Defender

You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.

- Keep your antivirus program updated, as well as any other security programs you have.

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI