Options

virtumonde problem...

edited February 2008 in Spyware & Virus Removal
i have zonealarm... and it sees an adware virtumonde.dyx but it wont get rid of it i have hijack this and virtufix but i did virtufix already and it didnt see anything but 1 file and it rebooted my puter so i did the scan on hijack and this is what it says....

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:27:05 AM, on 1/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Documents and Settings\Owner.OurComputer.001\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=W6409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=W6409
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1DEEAD4C-F042-4DC5-AB90-69715EDF2BE9} - C:\WINDOWS\system32\vtstu.dll
O2 - BHO: (no name) - {4F31706C-9136-416A-84EE-9EEEB06849A8} - (no file)
O2 - BHO: {045b2506-ced2-dc48-dfa4-5a9f9d1c9076} - {6709c1d9-f9a5-4afd-84cd-2dec6052b540} - C:\WINDOWS\system32\jffmrwev.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {89A1E40D-0254-4F99-B9AE-B60A2D8754A9} - C:\WINDOWS\system32\jkkigdb.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [MSDrive] rundll32.exe C:\WINDOWS\system32\drvtij.dll,startup
O4 - HKLM\..\Run: [50f84840] rundll32.exe "C:\WINDOWS\system32\labuyvxv.dll",b
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
O20 - Winlogon Notify: crypt32set - C:\WINDOWS\Media\fuwarxyus.dll (file missing)
O20 - Winlogon Notify: jkkigdb - jkkigdb.dll (file missing)
O20 - Winlogon Notify: uvyxsezf - uvyxsezf.dll (file missing)
O20 - Winlogon Notify: winblg32 - C:\WINDOWS\SYSTEM32\winblg32.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\eqefvwhm.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 7254 bytes


if anyone can help plz lemmie know i know i see the
O2 - BHO: (no name) - {1DEEAD4C-F042-4DC5-AB90-69715EDF2BE9} - C:\WINDOWS\system32\vtstu.dll

and that is the file that zonealarm sees

Comments

  • VekaVeka Finland
    edited January 2008
    Hi defcon3. :)

    I'll be handling your log to help you get cleaned up. Please give me some time to look it over.
  • edited January 2008
    vekarppe wrote:
    Hi defcon3. :)

    I'll be handling your log to help you get cleaned up. Please give me some time to look it over.


    thank you vekarppe
  • edited January 2008
    srry i forgot to add the vundofix.exe log


    VundoFix V6.5.10
    Checking Java version...
    Java version is 1.5.0.2
    Old versions of java are exploitable and should be removed.
    Scan started at 7:28:25 AM 1/24/2008
    Listing files found while scanning....
    C:\WINDOWS\system32\uvyxsezf.dll
    Beginning removal...
    Performing Repairs to the registry.
    Done!
  • VekaVeka Finland
    edited January 2008
    Step 1:

    I dont see an antivirus installed. I ask you to download and install one Anti-Virus program below (they are free)

    avast! 4 Home Edition
    AVG Anti-Spyware Free Edition
    Avira AntiVir PersonalEdition Classic

    Reboot your computer after installation.


    Step 2:

    Please download ComboFix from Here or Here to your Desktop.

    * In the event you already have Combofix, this is a new version that I need you to download.
    * It is important that it is saved directly to your desktop
    • Double click on combofix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
  • edited January 2008
    vekarppe wrote:
    Step 1:

    I dont see an antivirus installed.

    isnt the zonealarm i have an antivirus program as well as firewall and other stuff?
  • edited January 2008
    ok here is the combofix log

    ComboFix 08-01-23.1C - Owner 2008-01-25 20:00:39.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.690 [GMT -6:00]
    Running from: C:\Documents and Settings\Owner.OurComputer.001\Desktop\ComboFix.exe
    * Created a new restore point
    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    C:\Program Files\Helper
    C:\Program Files\Helper\superfindout.dll
    C:\Program Files\MSN Messenger\MsnMsgr .Exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\cookies.ini
    C:\WINDOWS\system32\ctfmon .exe
    C:\WINDOWS\system32\edeeg.ini
    C:\WINDOWS\system32\edeeg.ini2
    C:\WINDOWS\system32\jffmrwev.dll
    C:\WINDOWS\system32\labuyvxv.dll
    C:\WINDOWS\system32\mcrh.tmp
    C:\WINDOWS\system32\mll_hp.dll
    C:\WINDOWS\system32\qstwa.ini
    C:\WINDOWS\system32\qstwa.ini2
    C:\WINDOWS\system32\utstv.ini
    C:\WINDOWS\system32\utstv.ini2
    C:\WINDOWS\system32\uvyxsezf.dllbox
    C:\WINDOWS\system32\vtstu.dll
    C:\WINDOWS\system32\vxvyubal.ini
    D:\Autorun.inf
    <pre>
    C:\Program Files\MSN Messenger\MsnMsgr .Exe ---> QooBox
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe ---> QooBox
    C:\WINDOWS\system32\ctfmon .exe ---> QooBox
    </pre>
    
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    \LEGACY_DOMAINSERVICE
    \DomainService

    ((((((((((((((((((((((((( Files Created from 2007-12-26 to 2008-01-26 )))))))))))))))))))))))))))))))
    .
    2008-01-25 20:06 . 2008-01-25 20:06 334,848 --a
    C:\WINDOWS\system32\vtstu.dll.vir
    2008-01-25 20:06 . 2008-01-25 20:06 163,904 --a
    C:\WINDOWS\system32\hypkawoh.dll.vir
    2008-01-25 19:57 . 2000-08-31 08:00 51,200 --a
    C:\WINDOWS\Nircmd.exe
    2008-01-25 16:07 . 2008-01-25 16:07 5 --a
    C:\WINDOWS\system32\50f85ace
    2008-01-23 20:10 . 2008-01-25 18:45 1,907 --a
    C:\rollback.ini
    2008-01-23 12:24 . 2008-01-25 20:18 2,569,760 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
    2008-01-23 12:24 . 2008-01-25 20:16 35,444 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
    2008-01-23 12:13 . 2008-01-25 20:18 <DIR> d
    C:\WINDOWS\Internet Logs
    2008-01-22 19:06 . 2008-01-22 19:06 163,904 --a
    C:\WINDOWS\system32\hypkawoh.dll
    2008-01-22 00:24 . 2008-01-25 20:10 <DIR> d
    C:\Program Files\MSN Messenger
    2008-01-21 19:22 . 2008-01-21 20:05 <DIR> d
    C:\Program Files\Uniblue
    2008-01-21 15:34 . 2004-08-10 13:00 15,360 --a--c--- C:\WINDOWS\system32\dllcache\ctfmon.exe
    2008-01-21 15:34 . 2004-08-10 13:00 15,360 --a
    C:\WINDOWS\system32\ctfmon.exe
    2008-01-21 14:15 . 2008-01-21 14:15 54,764 --a
    C:\WINDOWS\system32\drivers\astq.tga
    2008-01-21 14:15 . 2008-01-21 14:15 2 --a
    C:\1358448879
    2008-01-21 14:14 . 2008-01-21 14:14 23,552 --a
    C:\WINDOWS\system32\winblg32.dll
    2008-01-21 14:03 . 2008-01-21 20:51 <DIR> d
    C:\Program Files\Common Files\Symantec Shared
    2008-01-21 13:35 . 2008-01-21 13:35 716,272 --a
    C:\WINDOWS\system32\drivers\sptd.sys
    2008-01-20 06:01 . 2008-01-20 16:08 2,091 --a
    C:\WINDOWS\system32\profile.out
    2008-01-17 17:30 . 2007-09-24 23:31 69,632 --a
    C:\WINDOWS\system32\javacpl.cpl
    2008-01-16 00:41 . 2008-01-16 01:21 664 --a
    C:\WINDOWS\system32\d3d9caps.dat
    2008-01-15 19:06 . 2008-01-21 19:01 <DIR> d
    C:\Program Files\iTunes
    2008-01-15 19:06 . 2008-01-15 19:06 <DIR> d
    C:\Program Files\iPod
    2008-01-15 19:06 . 2008-01-21 18:56 54,156 --ah
    C:\WINDOWS\QTFont.qfn
    2008-01-15 19:06 . 2008-01-21 16:47 1,409 --a
    C:\WINDOWS\QTFont.for
    2008-01-15 19:05 . 2008-01-15 19:05 <DIR> d
    C:\Program Files\QuickTime
    2008-01-15 19:05 . 2008-01-15 19:05 <DIR> d
    C:\Program Files\Apple Software Update
    2008-01-15 19:05 . 2008-01-15 02:39 30,464 --a
    C:\WINDOWS\system32\drivers\usbaapl.sys
    2008-01-15 19:04 . 2008-01-15 19:04 <DIR> d
    C:\Program Files\Common Files\Apple
    2008-01-12 10:22 . 2008-01-12 10:22 <DIR> d
    C:\WINDOWS\Sun
    2008-01-12 10:22 . 2008-01-12 10:22 <DIR> d
    C:\WINDOWS\.jagex_cache_32
    2008-01-12 10:11 . 2008-01-12 10:11 <DIR> d
    C:\Program Files\SecondLife
    2008-01-12 09:56 . 2008-01-12 10:01 <DIR> d
    C:\Program Files\Second Life
    2008-01-10 16:01 . 2008-01-10 16:01 <DIR> d
    C:\Program Files\DVD Flick
    2008-01-10 16:01 . 2000-05-19 17:56 81,920 --a
    C:\WINDOWS\system32\mbmouse.ocx
    2008-01-10 16:01 . 2000-11-05 15:27 36,864 --a
    C:\WINDOWS\system32\trayicon.ocx
    2008-01-10 15:37 . 2008-01-20 14:23 69 --a
    C:\WINDOWS\NeroDigital.ini
    2008-01-10 15:33 . 2005-09-01 12:03 127,488 --a
    C:\WINDOWS\system32\drivers\imagesrv.sys
    2008-01-10 15:33 . 2005-09-01 12:03 5,888 --a
    C:\WINDOWS\system32\drivers\imagedrv.sys
    2008-01-10 15:32 . 2008-01-10 15:32 <DIR> d
    C:\Program Files\Common Files\Ahead
    2008-01-10 15:32 . 2004-07-26 17:16 1,568,768 --a
    C:\WINDOWS\system32\ImagX7.dll
    2008-01-10 15:32 . 2004-07-26 17:16 476,320 --a
    C:\WINDOWS\system32\ImagXpr7.dll
    2008-01-10 15:32 . 2004-07-26 17:16 471,040 --a
    C:\WINDOWS\system32\ImagXRA7.dll
    2008-01-10 15:32 . 2004-07-09 09:43 364,544 --a
    C:\WINDOWS\system32\TwnLib4.dll
    2008-01-10 15:32 . 2004-07-26 17:16 262,144 --a
    C:\WINDOWS\system32\ImagXR7.dll
    2008-01-10 15:32 . 2000-06-26 11:45 106,496 --a
    C:\WINDOWS\system32\TwnLib20.dll
    2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a
    C:\WINDOWS\system32\QuickTimeVR.qtx
    2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a
    C:\WINDOWS\system32\QuickTime.qts
    2008-01-08 13:26 . 2007-07-30 19:19 271,224 --a
    C:\WINDOWS\system32\mucltui.dll
    2008-01-08 13:26 . 2007-07-30 19:19 207,736 --a
    C:\WINDOWS\system32\muweb.dll
    2008-01-08 13:26 . 2007-07-30 19:19 30,072 --a
    C:\WINDOWS\system32\mucltui.dll.mui
    2008-01-07 22:05 . 2008-01-22 00:24 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
    2008-01-07 21:54 . 2008-01-22 00:25 <DIR> d
    C:\Program Files\Windows Live
    2008-01-07 21:54 . 2008-01-07 22:05 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
    2008-01-07 16:12 . 2008-01-07 16:12 16 --a
    C:\WINDOWS\popcinfo.dat
    2008-01-05 16:23 . 2008-01-05 16:24 <DIR> d
    C:\Program Files\LimeWire
    2008-01-05 03:06 . 2007-08-13 18:54 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
    2008-01-05 03:01 . 2008-01-05 03:01 <DIR> d
    C:\Program Files\MSXML 4.0
    2008-01-05 02:57 . 2006-10-04 08:06 1,197,294 --a--c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
    2008-01-05 02:57 . 2006-10-04 08:06 764,868 --a--c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb
    2008-01-05 02:57 . 2006-10-04 08:06 217,118 --a--c--- C:\WINDOWS\system32\dllcache\apphelp.sdb
    2008-01-05 02:56 . 2008-01-05 02:56 <DIR> d
    C:\Program Files\Windows Media Connect 2
    2008-01-05 02:54 . 2008-01-05 02:54 <DIR> d
    C:\WINDOWS\system32\LogFiles
    2008-01-05 02:54 . 2008-01-05 02:55 <DIR> d
    C:\WINDOWS\system32\drivers\UMDF
    2008-01-05 02:47 . 2006-08-21 03:14 128,896 --a--c--- C:\WINDOWS\system32\dllcache\fltmgr.sys
    2008-01-05 02:47 . 2006-08-21 03:14 23,040 --a--c--- C:\WINDOWS\system32\dllcache\fltmc.exe
    2008-01-05 02:47 . 2006-08-21 06:21 16,896 --a--c--- C:\WINDOWS\system32\dllcache\fltlib.dll
    2008-01-05 02:39 . 2007-07-09 07:16 582,656 --a--c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
    2008-01-05 00:07 . 2008-01-05 00:11 <DIR> d
    C:\Program Files\VLC
    2008-01-04 23:47 . 2008-01-10 15:50 <DIR> d
    C:\Program Files\WinAVI Video Converter
    2008-01-04 23:47 . 2008-01-21 14:52 <DIR> d
    C:\Program Files\uTorrent
    2008-01-04 23:47 . 2008-01-10 15:33 <DIR> d
    C:\Program Files\Nero
    2008-01-04 23:46 . 2008-01-04 23:47 <DIR> d
    C:\Linksys Wireless-G Wireless Network Monitor
    2008-01-04 23:46 . 2004-12-22 02:32 369,024 -ra
    C:\WINDOWS\system32\drivers\BCMWL5.SYS
    2008-01-04 23:32 . 2003-10-13 15:30 94,208 --a
    C:\WINDOWS\system32\GTW32N50.dll
    2008-01-04 23:32 . 2003-09-25 23:28 31,930 --a
    C:\WINDOWS\system32\GTNDIS3.VXD
    2008-01-04 23:32 . 2003-09-25 22:15 15,872 --a
    C:\WINDOWS\system32\GTNDIS5.sys
    2008-01-04 23:25 . 2008-01-04 23:25 2 --a
    C:\WINDOWS\msoffice.ini
    2008-01-04 22:33 . 2008-01-04 22:33 8,192 --a
    C:\WINDOWS\REGLOCS.OLD
    2008-01-04 22:30 . 2008-01-04 22:30 <DIR> d
    C:\WINDOWS\system32\Lang
    2008-01-04 22:30 . 2008-01-04 22:30 940,794 --a
    C:\WINDOWS\system32\LoopyMusic.wav
    2008-01-04 22:30 . 2008-01-04 22:30 146,650 --a
    C:\WINDOWS\system32\BuzzingBee.wav
    2008-01-04 22:30 . 2008-01-04 22:30 333 --a
    C:\WINDOWS\system32\$ncsp$.inf
    2008-01-04 22:30 . 2008-01-04 22:30 0 --a
    C:\WINDOWS\system32\GATEWA_W6409__CRD6A30000525.MRK
    2008-01-04 22:28 . 2008-01-21 13:56 64,672 --a
    C:\WINDOWS\system32\Status.MPF
    2008-01-04 22:25 . 2006-08-14 04:34 332,928 --a--c--- C:\WINDOWS\system32\dllcache\srv.sys
    2008-01-04 22:24 . 2006-06-22 04:47 181,248 --a--c--- C:\WINDOWS\system32\dllcache\rasmans.dll
    2008-01-04 22:24 . 2006-06-26 11:37 148,480 --a--c--- C:\WINDOWS\system32\dllcache\dnsapi.dll
    2008-01-04 22:24 . 2006-05-19 06:59 111,616 --a--c--- C:\WINDOWS\system32\dllcache\dhcpcsvc.dll
    2008-01-04 22:24 . 2006-05-19 06:59 94,720 --a--c--- C:\WINDOWS\system32\dllcache\iphlpapi.dll
    2008-01-04 22:23 . 2008-01-04 22:23 <DIR> d
    C:\Program Files\SIFXINST
    2008-01-04 22:23 . 2008-01-04 22:23 <DIR> d
    C:\Program Files\McAfee
    2008-01-04 22:22 . 2008-01-04 22:22 <DIR> d
    C:\Program Files\gtw_logo
    2008-01-04 22:22 . 2006-05-24 11:28 741,376 --a
    C:\WINDOWS\system32\BigFixSuppress.exe
    2008-01-04 22:22 . 2006-05-24 11:28 741,376 --a
    C:\WINDOWS\system32\BigFixShortcutInStartup.exe
    2008-01-04 22:22 . 2003-03-25 07:00 67,072 --a
    C:\WINDOWS\POWERCFG.EXE
    2008-01-04 22:22 . 2004-04-22 05:48 30,056 --a
    C:\WINDOWS\system32\oemlogo.bmp
    2008-01-04 22:21 . 2008-01-04 22:21 <DIR> d
    C:\Program Files\Microsoft Money 2006
    2008-01-04 22:21 . 2008-01-04 22:21 <DIR> d
    C:\Program Files\Common Files\Nullsoft
    2008-01-04 22:21 . 2006-01-18 20:41 80,512 --a
    C:\WINDOWS\system32\drivers\Rtnicxp.sys
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-01-05 04:20 8,552 ----a-w C:\WINDOWS\system32\drivers\asctrm.sys
    2008-01-05 03:38
    d
    w C:\Program Files\Windows Plus
    2008-01-05 03:38
    d
    w C:\Program Files\microsoft frontpage
    2008-01-05 03:38
    d
    w C:\Program Files\Common Files\New Boundary
    2007-11-14 22:05 75,248 ----a-w C:\WINDOWS\zllsputility.exe
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Power2GoExpress"="NA" []
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 13:00 15360]
    "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
    "Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [ ]
    "readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [ ]
    "RTHDCPL"="RTHDCPL.EXE" [2006-04-17 17:34 16143872 C:\WINDOWS\RTHDCPL.exe]
    "CHotkey"="zHotkey.exe" []
    "Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
    "Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [ ]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
    "MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [ ]
    "MSDrive"="C:\WINDOWS\system32\drvtij.dll" [ ]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [ ]
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2008-01-04 22:19:49 2168360]
    Install Pending Files.LNK - C:\Program Files\SIFXINST\SIFXINST.EXE [2008-01-04 22:23:44 729088]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32set]
    C:\WINDOWS\Media\fuwarxyus.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkigdb]
    jkkigdb.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\uvyxsezf]
    uvyxsezf.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winblg32]
    winblg32.dll 2008-01-21 14:14 23552 C:\WINDOWS\system32\winblg32.dll

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
    .
    Contents of the 'Scheduled Tasks' folder
    "2008-01-16 16:50:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    .
    **************************************************************************
    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-01-25 20:19:40
    Windows 5.1.2600 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden autostart entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    .
    DLLs Loaded Under Running Processes
    PROCESS: C:\WINDOWS\system32\winlogon.exe
    -> C:\WINDOWS\system32\winblg32.dll
    .
    Completion time: 2008-01-25 20:22:18 - machine was rebooted [Owner]
    ComboFix-quarantined-files.txt 2008-01-26 02:22:13
    .
    2008-01-09 09:04:26 --- E O F ---

    and the new Hijackthis log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:27:20 PM, on 1/25/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\lsass.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Documents and Settings\Owner.OurComputer.001\Desktop\HiJackThis.exe
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [MSDrive] rundll32.exe C:\WINDOWS\system32\drvtij.dll,startup
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [lsass] C:\WINDOWS\lsass.exe
    O4 - HKCU\..\Run: [Power2GoExpress] NA
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
    O20 - Winlogon Notify: crypt32set - C:\WINDOWS\Media\fuwarxyus.dll (file missing)
    O20 - Winlogon Notify: jkkigdb - jkkigdb.dll (file missing)
    O20 - Winlogon Notify: uvyxsezf - uvyxsezf.dll (file missing)
    O20 - Winlogon Notify: winblg32 - C:\WINDOWS\SYSTEM32\winblg32.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    --
    End of file - 6249 bytes
  • edited January 2008
    ok i downloaded the avira antivirus program and installed and rebooted the puter.... are there any free good firewalls online?
  • edited January 2008
    also.... the avira program has the update thing on it but it wont seem to update for me... it keeps saying internet connection failed... even though i can surf the net...


    also a new problem arose.... everytime i boot up the computer.... and get past the welcome screen after everything is loaded a error window pops up and says

    RUNDLL

    Error loading C:\Windows\System32\drvtij.dll
    The specified module could not be found.


    i checked the net for drvtij.dll and i cannot find any information about that dll on any website even microsoft.com

    im not sure what it is or what it does....
  • VekaVeka Finland
    edited January 2008
    I prefer Sunbelt Personal Firewall or COMODO. Both are good and free!



    Please do the followings...


    Step 1:

    Open Notepad
    • Click Start, then Run
    • Type notepad.exe in the Run Box.
    Step 2:

    Copy & paste the entire content of the codebox below into the Notepad window
    File:: 
    C:\WINDOWS\system32\vtstu.dll.vir 
    C:\WINDOWS\system32\hypkawoh.dll.vir 
    C:\WINDOWS\system32\50f85ace 
    C:\WINDOWS\system32\drivers\astq.tga 
    C:\WINDOWS\system32\hypkawoh.dll 
    C:\1358448879 
    C:\WINDOWS\system32\winblg32.dll 
    C:\WINDOWS\system32\winblg32.dll 
     
    Registry:: 
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32set] 
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkigdb] 
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\uvyxsezf] 
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winblg32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSDrive"=-
    
    Save the above as CFScript.txt to your Desktop.

    Step 3:

    Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.


    CFScript.gif

    After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
    • A new HijackThis log.
  • edited January 2008
    ok i did that i made the CFScript.txt dragged it on top of combofix and this is what it came up with

    327882R2FWJFW\nircmd.com is not a valid Win32 application.

    then i click ok and it comes up and says

    Windows cannot find 'kmd.exe'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.


    then i hit ok and nothing happens
  • edited January 2008
    here is a hjt log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:24, on 2008-01-30
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\PC Tools Firewall Plus\FWService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\ThreatFire\TFTray.exe
    C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\ThreatFire\TFService.exe
    C:\WINDOWS\ehome\mcrdsvc.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\WINDOWS\explorer.exe
    C:\Documents and Settings\Owner.OurComputer.001\Desktop\HiJackThis.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [MSDrive] rundll32.exe C:\WINDOWS\system32\drvtij.dll,startup
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
    O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKCU\..\Run: [Power2GoExpress] NA
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O20 - Winlogon Notify: crypt32set - C:\WINDOWS\Media\fuwarxyus.dll (file missing)
    O20 - Winlogon Notify: jkkigdb - jkkigdb.dll (file missing)
    O20 - Winlogon Notify: uvyxsezf - uvyxsezf.dll (file missing)
    O20 - Winlogon Notify: winblg32 - winblg32.dll (file missing)
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
    --
    End of file - 7769 bytes


    and the combofix wont work for me i downloaded it to the desktop and got the cfscript.txt and dragged it onto the combofix and it said that nircmd was not a valid Win 32 app.... and it couldnt find KMD.exe
  • edited January 2008
    now i get access is denied and i cant even delete combofix from my desktop... i tried cmd.exe to delete it and it wont work either... says its in use by another app
  • VekaVeka Finland
    edited February 2008
    Hi defcon. Let's try this...

    You may want to print out these instructions or save them as a text document because you'll not have internet access while in Safe Mode.


    Step 1:

    Please download to your Desktop

    OTMoveIt2
    Deckard's System Scanner

    Step 2:

    Reboot into Safe Mode
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually.
    • Instead of Windows loading as normal, a menu with options should appear.
    • Select the first option, to run Windows in Safe Mode, then press "Enter".
    • Choose your usual account.
    Step 3:

    Once in Safe Mode, please click Start > Run. Type Combofix /u and click OK.

    After that, reboot back to Normal Mode.

    Step 4:
    • Please double-click OTMoveIt2 to run it.
    • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
      C:\WINDOWS\system32\vtstu.dll.vir
      C:\WINDOWS\system32\hypkawoh.dll.vir
      C:\WINDOWS\system32\50f85ace
      C:\WINDOWS\system32\drivers\astq.tga
      C:\WINDOWS\system32\hypkawoh.dll
      C:\1358448879
      C:\WINDOWS\system32\winblg32.dll
      C:\WINDOWS\popcinfo.dat
      C:\WINDOWS\system32\winblg32.dll
      
    • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
    • Click the red Moveit! button.
    • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log).
      Please open this log in Notepad and post its contents in your next reply.
    • Close OTMoveIt2
    If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

    Step 5:

    Next, back up the registry as we are going to modify it
    • Click Start > Run > and type regedit > OK
    • Make sure that My Computer is selected.
    • On the File menu, click Export.
    • Choose the name and location (e.g. My Documents), and save it as a registry file.
    Step 6:

    Please open Notepad and copy the contents of the below code box to Notepad
    Windows Registry Editor Version 5.00 
     
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32set] 
     
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkigdb] 
     
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\uvyxsezf] 
     
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winblg32] 
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
    "MSDrive"=-
    
    Click File > Save As

    Save the file to your desktop as Fix.reg (make sure you save as type: all files)

    Step 7:

    Double-click Fix.reg, and answer Yes when prompted.

    After all that, reboot your computer.

    Step 8:

    Run Deckard's System Scanner

    Attention: You must be logged onto an account with administrator privileges.
    • Close all open applications and windows.
    • Double-click on dss.exe to run it, and follow the prompts.
    • When the scan is complete, two text files will open:
      • main.txt (this will be maximized)
      • extra.txt (this will be minimized)
    • Copy and paste the contents of main.txt and the extra.txt to your post in your reply.
    Step 9:

    Please post OTMoveIt2 log, contents of main.txt and extra,txt, along with a new HijackThis.

    :)
  • edited February 2008
    okie dokie... did what u asked here are the logs

    Main.txt

    Deckard's System Scanner v20071014.68
    Run by Owner on 2008-02-05 08:01:05
    Computer is in Normal Mode.
    -- System Restore
    Successfully created a Deckard's System Scanner Restore Point.

    -- Last 2 Restore Point(s) --
    2: 2008-02-05 14:01:10 UTC - RP2 - Deckard's System Scanner Restore Point
    1: 2008-02-05 13:50:17 UTC - RP1 - System Checkpoint

    Backed up registry hives.
    Performed disk cleanup.

    -- HijackThis (run as Owner.exe)
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:02:11 AM, on 2008-02-05
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\PC Tools Firewall Plus\FWService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\ThreatFire\TFTray.exe
    C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\ThreatFire\TFService.exe
    C:\WINDOWS\ehome\mcrdsvc.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\Documents and Settings\Owner.OurComputer.001\Desktop\dss.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\DOCUME~1\OWNERO~1.001\Desktop\Owner.exe
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
    O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKCU\..\Run: [Power2GoExpress] NA
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
    --
    End of file - 7395 bytes
    -- File Associations
    All associations okay.

    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled
    R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver>
    S1 astq - c:\windows\system32\drivers\astq.tga (file missing)
    S3 catchme - c:\windows\temp\catchme.sys (file missing)
    S3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>

    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled
    R2 AntiVirScheduler (AntiVir PersonalEdition Classic Scheduler) - "c:\program files\avira\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; Scheduler>
    R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
    S2 CLTNetCnService (Symantec Lic NetConnect service) - "c:\program files\common files\symantec shared\ccsvchst.exe" /h cccommon (file missing)

    -- Device Manager: Disabled
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Realtek RTL8139/810x Family Fast Ethernet NIC
    Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_D6018086&REV_10\4&2A3BFE78&0&10A4
    Manufacturer: Realtek Semiconductor Corp.
    Name: Realtek RTL8139/810x Family Fast Ethernet NIC
    PNP Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_D6018086&REV_10\4&2A3BFE78&0&10A4
    Service: RTL8023xp

    -- Scheduled Tasks
    2008-01-30 10:50:02 284 --a
    C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

    -- Files created between 2008-01-05 and 2008-02-05
    2008-01-30 12:01:36 0 d--h
    C:\WINDOWS\PIF
    2008-01-26 00:13:36 0 d
    C:\Documents and Settings\LocalService\Start Menu
    2008-01-25 23:22:06 0 d
    C:\Program Files\Spyware Doctor
    2008-01-25 23:22:06 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\PC Tools
    2008-01-25 23:17:44 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\PCToolsFirewallPlus
    2008-01-25 22:58:26 0 d
    C:\Program Files\Common Files\PC Tools
    2008-01-25 22:58:25 0 d
    C:\Program Files\PC Tools Firewall Plus
    2008-01-25 22:57:06 0 d-a
    C:\Documents and Settings\All Users\Application Data\TEMP
    2008-01-25 22:56:49 0 d
    C:\Program Files\ThreatFire
    2008-01-25 22:56:49 0 d
    C:\Documents and Settings\All Users\Application Data\PC Tools
    2008-01-25 21:21:27 0 d
    C:\Program Files\Avira
    2008-01-25 21:21:27 0 d
    C:\Documents and Settings\All Users\Application Data\Avira
    2008-01-25 20:24:11 0 d
    C:\Program Files\Outerinfo
    2008-01-25 20:22:33 0 d
    C:\Program Files\Helper
    2008-01-25 20:22:12 38912 --a
    C:\WINDOWS\system32\ssqrrss.dll
    2008-01-23 12:14:51 0 d
    C:\Documents and Settings\All Users\Application Data\MailFrontier
    2008-01-23 12:14:47 4212 --ah
    C:\WINDOWS\system32\zllictbl.dat
    2008-01-23 12:14:40 11264 --a
    C:\WINDOWS\system32\SpOrder.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows NT(TM) Operating System>
    2008-01-23 12:14:10 0 d
    C:\WINDOWS\system32\ZoneLabs
    2008-01-23 12:13:20 0 d
    C:\WINDOWS\Internet Logs
    2008-01-23 11:50:56 0 d--hs---- C:\WINDOWS\CSC
    2008-01-22 00:24:28 0 d
    C:\Program Files\MSN Messenger
    2008-01-21 19:27:55 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Uniblue
    2008-01-21 19:22:30 0 d
    C:\Program Files\Uniblue
    2008-01-21 19:02:28 0 d
    C:\WINDOWS\system32\appmgmt
    2008-01-21 15:03:39 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Symantec
    2008-01-21 15:02:18 0 d
    C:\Documents and Settings\All Users\Application Data\Downloaded Installations
    2008-01-21 14:46:12 0 d
    C:\Documents and Settings\Default User\Application Data\Apple Computer
    2008-01-21 14:03:41 0 d
    C:\Documents and Settings\All Users\Application Data\Symantec
    2008-01-21 14:03:26 0 d
    C:\Program Files\Common Files\Symantec Shared
    2008-01-21 13:35:38 716272 --a
    C:\WINDOWS\system32\drivers\sptd.sys
    2008-01-16 00:41:34 664 --a
    C:\WINDOWS\system32\d3d9caps.dat
    2008-01-15 19:06:56 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Apple Computer
    2008-01-15 19:06:36 0 d
    C:\Program Files\iPod
    2008-01-15 19:06:27 0 d
    C:\Program Files\iTunes
    2008-01-15 19:05:33 0 d
    C:\Program Files\QuickTime
    2008-01-15 19:05:31 0 d
    C:\Documents and Settings\All Users\Application Data\Apple Computer
    2008-01-15 19:05:13 0 d
    C:\Program Files\Apple Software Update
    2008-01-15 19:04:39 0 d
    C:\Program Files\Common Files\Apple
    2008-01-15 19:04:38 0 d
    C:\Documents and Settings\All Users\Application Data\Apple
    2008-01-13 15:04:05 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\CyberLink
    2008-01-12 10:22:58 0 d
    C:\WINDOWS\.jagex_cache_32
    2008-01-12 10:22:49 0 d
    C:\WINDOWS\Sun
    2008-01-12 10:22:49 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Sun
    2008-01-12 10:12:17 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Mozilla
    2008-01-12 10:11:55 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\SecondLife
    2008-01-12 10:11:16 0 d
    C:\Program Files\SecondLife
    2008-01-12 09:56:28 0 d
    C:\Program Files\Second Life
    2008-01-10 18:37:56 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\dvdcss
    2008-01-10 18:35:36 0 d
    C:\Documents and Settings\All Users\Application Data\CyberLink
    2008-01-10 16:05:28 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\AdobeUM
    2008-01-10 16:01:45 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\DVD Flick
    2008-01-10 16:01:17 0 d
    C:\Program Files\DVD Flick
    2008-01-10 15:32:35 364544 --a
    C:\WINDOWS\system32\TwnLib4.dll <Not Verified; Pegasus Imaging Corp.; TwnLib4>
    2008-01-10 15:32:35 106496 --a
    C:\WINDOWS\system32\TwnLib20.dll <Not Verified; Pegasus Software; TWNLIB20>
    2008-01-10 15:32:33 471040 --a
    C:\WINDOWS\system32\ImagXRA7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
    2008-01-10 15:32:33 262144 --a
    C:\WINDOWS\system32\ImagXR7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
    2008-01-10 15:32:33 1568768 --a
    C:\WINDOWS\system32\ImagX7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
    2008-01-10 15:32:31 0 d
    C:\Program Files\Common Files\Ahead
    2008-01-08 18:15:32 0 d
    C:\Documents and Settings\Guest\Application Data\Google
    2008-01-07 22:07:59 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Contacts
    2008-01-07 22:05:44 0 d
    c- C:\WINDOWS\system32\DRVSTORE
    2008-01-07 21:54:40 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
    2008-01-07 21:54:21 0 d
    C:\Program Files\Windows Live
    2008-01-07 21:54:11 0 d
    C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-01-07 16:16:26 0 d
    C:\Documents and Settings\Guest\Application Data\McAfee.com Personal Firewall
    2008-01-07 16:16:04 0 d
    C:\Documents and Settings\Guest\WINDOWS
    2008-01-07 16:16:04 0 d--h
    C:\Documents and Settings\Guest\Templates
    2008-01-07 16:16:04 0 dr
    C:\Documents and Settings\Guest\Start Menu
    2008-01-07 16:16:04 0 dr-h
    C:\Documents and Settings\Guest\SendTo
    2008-01-07 16:16:04 0 dr-h
    C:\Documents and Settings\Guest\Recent
    2008-01-07 16:16:04 0 d--h
    C:\Documents and Settings\Guest\PrintHood
    2008-01-07 16:16:04 1048576 --ah
    C:\Documents and Settings\Guest\NTUSER.DAT
    2008-01-07 16:16:04 0 d--h
    C:\Documents and Settings\Guest\NetHood
    2008-01-07 16:16:04 0 dr
    C:\Documents and Settings\Guest\My Documents
    2008-01-07 16:16:04 0 d--h
    C:\Documents and Settings\Guest\Local Settings
    2008-01-07 16:16:04 0 dr
    C:\Documents and Settings\Guest\Favorites
    2008-01-07 16:16:04 0 d
    C:\Documents and Settings\Guest\Desktop
    2008-01-07 16:16:04 0 d--hs---- C:\Documents and Settings\Guest\Cookies
    2008-01-07 16:16:04 0 dr-h
    C:\Documents and Settings\Guest\Application Data
    2008-01-07 16:16:04 0 d
    C:\Documents and Settings\Guest\Application Data\You've Got Pictures Screensaver
    2008-01-07 16:16:04 0 d
    C:\Documents and Settings\Guest\Application Data\SampleView
    2008-01-07 16:16:04 0 d---s---- C:\Documents and Settings\Guest\Application Data\Microsoft
    2008-01-07 16:16:04 0 d
    C:\Documents and Settings\Guest\Application Data\Identities
    2008-01-06 11:57:13 0 d
    C:\Documents and Settings\All Users\Application Data\WinZip
    2008-01-05 16:24:51 0 d
    C:\Documents and Settings\Owner.OurComputer.001\LimeWire Store Purchased
    2008-01-05 16:24:51 0 d
    C:\Documents and Settings\Owner.OurComputer.001\LimeWire Shared
    2008-01-05 16:24:51 0 d
    C:\Documents and Settings\Owner.OurComputer.001\LimeWire Saved
    2008-01-05 16:24:29 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Incomplete
    2008-01-05 16:24:15 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\LimeWire
    2008-01-05 16:23:54 0 d
    C:\Program Files\LimeWire
    2008-01-05 03:06:34 0 d
    C:\WINDOWS\network diagnostic
    2008-01-05 03:01:43 0 d
    C:\Program Files\MSXML 4.0
    2008-01-05 02:56:30 0 d
    C:\Program Files\Windows Media Connect 2
    2008-01-05 02:55:09 0 d
    C:\95f6720d8dd27ff35de04d5892c1
    2008-01-05 02:54:58 0 d
    C:\WINDOWS\system32\LogFiles
    2008-01-05 02:54:58 0 d
    C:\WINDOWS\system32\drivers\UMDF
    2008-01-05 02:54:41 0 d
    C:\431b80cb0e136959e9bfea3c
    2008-01-05 02:16:35 0 d
    C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
    2008-01-05 02:15:51 0 d
    C:\WINDOWS\system32\PreInstall
    2008-01-05 02:14:18 0 d--hs---- C:\Documents and Settings\Owner.OurComputer.001\UserData
    2008-01-05 01:50:38 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Macromedia
    2008-01-05 01:50:38 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Adobe
    2008-01-05 01:47:08 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\uTorrent
    2008-01-05 00:11:19 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\vlc
    2008-01-05 00:07:07 0 d
    C:\Program Files\VLC
    2008-01-05 00:06:14 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Google

    -- Find3M Report
    2008-01-25 22:58:26 0 d
    C:\Program Files\Common Files
    2008-01-21 15:34:17 0 d
    C:\Program Files\Digital Media Reader
    2008-01-21 14:52:54 0 d
    C:\Program Files\uTorrent
    2008-01-17 17:30:03 0 d
    C:\Program Files\Java
    2008-01-10 15:50:08 0 d
    C:\Program Files\WinAVI Video Converter
    2008-01-10 15:33:47 0 d
    C:\Program Files\Nero
    2008-01-05 01:50:18 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\McAfee.com Personal Firewall
    2008-01-04 23:42:04 0 d--h
    C:\Program Files\InstallShield Installation Information
    2008-01-04 23:34:53 0 d
    C:\Program Files\Pure Networks
    2008-01-04 23:26:11 0 d
    C:\Program Files\Common Files\AOL
    2008-01-04 22:49:24 0 d
    C:\Program Files\Google
    2008-01-04 22:29:14 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\SampleView
    2008-01-04 22:27:44 0 --a
    C:\REQUEST_OEMRESET_ENDUSER
    2008-01-04 22:23:47 0 d
    C:\Program Files\SIFXINST
    2008-01-04 22:23:10 0 d
    C:\Program Files\McAfee
    2008-01-04 22:22:14 0 d
    C:\Program Files\gtw_logo
    2008-01-04 22:21:55 0 d
    C:\Program Files\Realtek
    2008-01-04 22:21:44 0 d
    C:\Program Files\Microsoft Money 2006
    2008-01-04 22:21:09 0 d
    C:\Program Files\Common Files\Nullsoft
    2008-01-04 22:21:09 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\You've Got Pictures Screensaver
    2008-01-04 22:20:46 0 d
    C:\Program Files\Common Files\Real
    2008-01-04 22:20:42 0 d
    C:\Program Files\Real
    2008-01-04 22:20:30 0 d
    C:\Program Files\Viewpoint
    2008-01-04 22:19:56 335 --a
    C:\WINDOWS\nsreg.dat
    2008-01-04 22:19:49 0 d
    C:\Program Files\BigFix
    2008-01-04 22:19:36 0 d
    C:\Program Files\Microsoft Works
    2008-01-04 22:18:46 0 d
    C:\Program Files\MSN Encarta Plus
    2008-01-04 22:18:13 0 d
    C:\Program Files\Microsoft Digital Image 2006
    2008-01-04 22:18:06 4 --a
    C:\WINDOWS\Pix11.dat
    2008-01-04 22:17:33 0 d
    C:\Program Files\Common Files\Adobe
    2008-01-04 22:16:01 0 d
    C:\Program Files\Gateway Games
    2008-01-04 22:14:49 0 d
    C:\Program Files\WildTangent
    2008-01-04 22:13:25 0 d
    C:\Program Files\Common Files\InstallShield
    2008-01-04 22:12:52 0 d
    C:\Program Files\Common Files\Java
    2008-01-04 22:10:18 0 d
    C:\Program Files\Microsoft ActiveSync
    2008-01-04 22:09:52 0 d
    C:\Program Files\Microsoft.NET
    2008-01-04 22:09:01 0 d
    C:\Program Files\CyberLink
    2008-01-04 22:08:25 2 --a
    C:\AUDIT_INSTALL_IN_PROGRESS
    2008-01-04 22:00:22 2 -r-hs---- C:\USER
    2008-01-04 21:58:38 0 d
    C:\Program Files\CONEXANT
    2008-01-04 21:44:38 60 --a
    C:\WINDOWS\system32\SYSDRV.DAT
    2008-01-04 21:43:06 0 d
    C:\Program Files\Windows NT
    2008-01-04 21:43:03 0 d
    C:\Program Files\Movie Maker
    2008-01-04 21:43:01 0 d
    C:\Program Files\Messenger
    2008-01-04 21:38:45 0 d
    C:\Program Files\Windows Plus
    2008-01-04 21:38:45 0 d
    C:\Program Files\Online Services
    2008-01-04 21:38:45 0 d
    C:\Program Files\MSN Gaming Zone
    2008-01-04 21:38:45 0 d
    C:\Program Files\microsoft frontpage
    2008-01-04 21:38:44 0 d
    C:\Program Files\Common Files\SpeechEngines
    2008-01-04 21:38:44 0 d
    C:\Program Files\Common Files\ODBC
    2008-01-04 21:38:44 0 d
    C:\Program Files\Common Files\New Boundary
    2008-01-04 21:38:44 0 d
    C:\Program Files\Common Files\MSSoap
    2008-01-04 21:38:38 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Identities

    -- Registry Dump
    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" []
    "readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" []
    "RTHDCPL"="RTHDCPL.EXE" [2006-04-17 05:34 PM C:\WINDOWS\RTHDCPL.exe]
    "CHotkey"="zHotkey.exe" []
    "Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
    "Reminder"="%WINDIR%\Creator\Remind_XP.exe" []
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" []
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" []
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" []
    "MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" []
    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-01-25 11:13 PM]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" []
    "ThreatFire"="C:\Program Files\ThreatFire\TFTray.exe" [2007-12-20 11:13 AM]
    "00PCTFW"="C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" [2007-12-31 09:16 AM]
    "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 02:53 PM]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Power2GoExpress"="NA" []
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 01:00 PM]
    "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 PM]
    "Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2008-01-04 10:19:49 PM]
    Install Pending Files.LNK - C:\Program Files\SIFXINST\SIFXINST.EXE [2008-01-04 10:23:44 PM]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"


    -- End of Deckard's System Scanner: finished at 2008-02-05 08:03:38

    Extra.txt

    Deckard's System Scanner v20071014.68
    Run by Owner on 2008-02-05 08:01:05
    Computer is in Normal Mode.
    -- System Restore
    Successfully created a Deckard's System Scanner Restore Point.

    -- Last 2 Restore Point(s) --
    2: 2008-02-05 14:01:10 UTC - RP2 - Deckard's System Scanner Restore Point
    1: 2008-02-05 13:50:17 UTC - RP1 - System Checkpoint

    Backed up registry hives.
    Performed disk cleanup.

    -- HijackThis (run as Owner.exe)
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:02:11 AM, on 2008-02-05
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\PC Tools Firewall Plus\FWService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\ThreatFire\TFTray.exe
    C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\ThreatFire\TFService.exe
    C:\WINDOWS\ehome\mcrdsvc.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\Documents and Settings\Owner.OurComputer.001\Desktop\dss.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\DOCUME~1\OWNERO~1.001\Desktop\Owner.exe
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
    O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKCU\..\Run: [Power2GoExpress] NA
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
    --
    End of file - 7395 bytes
    -- File Associations
    All associations okay.

    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled
    R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver>
    S1 astq - c:\windows\system32\drivers\astq.tga (file missing)
    S3 catchme - c:\windows\temp\catchme.sys (file missing)
    S3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>

    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled
    R2 AntiVirScheduler (AntiVir PersonalEdition Classic Scheduler) - "c:\program files\avira\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; Scheduler>
    R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
    S2 CLTNetCnService (Symantec Lic NetConnect service) - "c:\program files\common files\symantec shared\ccsvchst.exe" /h cccommon (file missing)

    -- Device Manager: Disabled
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Realtek RTL8139/810x Family Fast Ethernet NIC
    Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_D6018086&REV_10\4&2A3BFE78&0&10A4
    Manufacturer: Realtek Semiconductor Corp.
    Name: Realtek RTL8139/810x Family Fast Ethernet NIC
    PNP Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_D6018086&REV_10\4&2A3BFE78&0&10A4
    Service: RTL8023xp

    -- Scheduled Tasks
    2008-01-30 10:50:02 284 --a
    C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

    -- Files created between 2008-01-05 and 2008-02-05
    2008-01-30 12:01:36 0 d--h
    C:\WINDOWS\PIF
    2008-01-26 00:13:36 0 d
    C:\Documents and Settings\LocalService\Start Menu
    2008-01-25 23:22:06 0 d
    C:\Program Files\Spyware Doctor
    2008-01-25 23:22:06 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\PC Tools
    2008-01-25 23:17:44 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\PCToolsFirewallPlus
    2008-01-25 22:58:26 0 d
    C:\Program Files\Common Files\PC Tools
    2008-01-25 22:58:25 0 d
    C:\Program Files\PC Tools Firewall Plus
    2008-01-25 22:57:06 0 d-a
    C:\Documents and Settings\All Users\Application Data\TEMP
    2008-01-25 22:56:49 0 d
    C:\Program Files\ThreatFire
    2008-01-25 22:56:49 0 d
    C:\Documents and Settings\All Users\Application Data\PC Tools
    2008-01-25 21:21:27 0 d
    C:\Program Files\Avira
    2008-01-25 21:21:27 0 d
    C:\Documents and Settings\All Users\Application Data\Avira
    2008-01-25 20:24:11 0 d
    C:\Program Files\Outerinfo
    2008-01-25 20:22:33 0 d
    C:\Program Files\Helper
    2008-01-25 20:22:12 38912 --a
    C:\WINDOWS\system32\ssqrrss.dll
    2008-01-23 12:14:51 0 d
    C:\Documents and Settings\All Users\Application Data\MailFrontier
    2008-01-23 12:14:47 4212 --ah
    C:\WINDOWS\system32\zllictbl.dat
    2008-01-23 12:14:40 11264 --a
    C:\WINDOWS\system32\SpOrder.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows NT(TM) Operating System>
    2008-01-23 12:14:10 0 d
    C:\WINDOWS\system32\ZoneLabs
    2008-01-23 12:13:20 0 d
    C:\WINDOWS\Internet Logs
    2008-01-23 11:50:56 0 d--hs---- C:\WINDOWS\CSC
    2008-01-22 00:24:28 0 d
    C:\Program Files\MSN Messenger
    2008-01-21 19:27:55 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Uniblue
    2008-01-21 19:22:30 0 d
    C:\Program Files\Uniblue
    2008-01-21 19:02:28 0 d
    C:\WINDOWS\system32\appmgmt
    2008-01-21 15:03:39 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Symantec
    2008-01-21 15:02:18 0 d
    C:\Documents and Settings\All Users\Application Data\Downloaded Installations
    2008-01-21 14:46:12 0 d
    C:\Documents and Settings\Default User\Application Data\Apple Computer
    2008-01-21 14:03:41 0 d
    C:\Documents and Settings\All Users\Application Data\Symantec
    2008-01-21 14:03:26 0 d
    C:\Program Files\Common Files\Symantec Shared
    2008-01-21 13:35:38 716272 --a
    C:\WINDOWS\system32\drivers\sptd.sys
    2008-01-16 00:41:34 664 --a
    C:\WINDOWS\system32\d3d9caps.dat
    2008-01-15 19:06:56 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Apple Computer
    2008-01-15 19:06:36 0 d
    C:\Program Files\iPod
    2008-01-15 19:06:27 0 d
    C:\Program Files\iTunes
    2008-01-15 19:05:33 0 d
    C:\Program Files\QuickTime
    2008-01-15 19:05:31 0 d
    C:\Documents and Settings\All Users\Application Data\Apple Computer
    2008-01-15 19:05:13 0 d
    C:\Program Files\Apple Software Update
    2008-01-15 19:04:39 0 d
    C:\Program Files\Common Files\Apple
    2008-01-15 19:04:38 0 d
    C:\Documents and Settings\All Users\Application Data\Apple
    2008-01-13 15:04:05 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\CyberLink
    2008-01-12 10:22:58 0 d
    C:\WINDOWS\.jagex_cache_32
    2008-01-12 10:22:49 0 d
    C:\WINDOWS\Sun
    2008-01-12 10:22:49 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Sun
    2008-01-12 10:12:17 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Mozilla
    2008-01-12 10:11:55 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\SecondLife
    2008-01-12 10:11:16 0 d
    C:\Program Files\SecondLife
    2008-01-12 09:56:28 0 d
    C:\Program Files\Second Life
    2008-01-10 18:37:56 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\dvdcss
    2008-01-10 18:35:36 0 d
    C:\Documents and Settings\All Users\Application Data\CyberLink
    2008-01-10 16:05:28 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\AdobeUM
    2008-01-10 16:01:45 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\DVD Flick
    2008-01-10 16:01:17 0 d
    C:\Program Files\DVD Flick
    2008-01-10 15:32:35 364544 --a
    C:\WINDOWS\system32\TwnLib4.dll <Not Verified; Pegasus Imaging Corp.; TwnLib4>
    2008-01-10 15:32:35 106496 --a
    C:\WINDOWS\system32\TwnLib20.dll <Not Verified; Pegasus Software; TWNLIB20>
    2008-01-10 15:32:33 471040 --a
    C:\WINDOWS\system32\ImagXRA7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
    2008-01-10 15:32:33 262144 --a
    C:\WINDOWS\system32\ImagXR7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
    2008-01-10 15:32:33 1568768 --a
    C:\WINDOWS\system32\ImagX7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
    2008-01-10 15:32:31 0 d
    C:\Program Files\Common Files\Ahead
    2008-01-08 18:15:32 0 d
    C:\Documents and Settings\Guest\Application Data\Google
    2008-01-07 22:07:59 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Contacts
    2008-01-07 22:05:44 0 d
    c- C:\WINDOWS\system32\DRVSTORE
    2008-01-07 21:54:40 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
    2008-01-07 21:54:21 0 d
    C:\Program Files\Windows Live
    2008-01-07 21:54:11 0 d
    C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-01-07 16:16:26 0 d
    C:\Documents and Settings\Guest\Application Data\McAfee.com Personal Firewall
    2008-01-07 16:16:04 0 d
    C:\Documents and Settings\Guest\WINDOWS
    2008-01-07 16:16:04 0 d--h
    C:\Documents and Settings\Guest\Templates
    2008-01-07 16:16:04 0 dr
    C:\Documents and Settings\Guest\Start Menu
    2008-01-07 16:16:04 0 dr-h
    C:\Documents and Settings\Guest\SendTo
    2008-01-07 16:16:04 0 dr-h
    C:\Documents and Settings\Guest\Recent
    2008-01-07 16:16:04 0 d--h
    C:\Documents and Settings\Guest\PrintHood
    2008-01-07 16:16:04 1048576 --ah
    C:\Documents and Settings\Guest\NTUSER.DAT
    2008-01-07 16:16:04 0 d--h
    C:\Documents and Settings\Guest\NetHood
    2008-01-07 16:16:04 0 dr
    C:\Documents and Settings\Guest\My Documents
    2008-01-07 16:16:04 0 d--h
    C:\Documents and Settings\Guest\Local Settings
    2008-01-07 16:16:04 0 dr
    C:\Documents and Settings\Guest\Favorites
    2008-01-07 16:16:04 0 d
    C:\Documents and Settings\Guest\Desktop
    2008-01-07 16:16:04 0 d--hs---- C:\Documents and Settings\Guest\Cookies
    2008-01-07 16:16:04 0 dr-h
    C:\Documents and Settings\Guest\Application Data
    2008-01-07 16:16:04 0 d
    C:\Documents and Settings\Guest\Application Data\You've Got Pictures Screensaver
    2008-01-07 16:16:04 0 d
    C:\Documents and Settings\Guest\Application Data\SampleView
    2008-01-07 16:16:04 0 d---s---- C:\Documents and Settings\Guest\Application Data\Microsoft
    2008-01-07 16:16:04 0 d
    C:\Documents and Settings\Guest\Application Data\Identities
    2008-01-06 11:57:13 0 d
    C:\Documents and Settings\All Users\Application Data\WinZip
    2008-01-05 16:24:51 0 d
    C:\Documents and Settings\Owner.OurComputer.001\LimeWire Store Purchased
    2008-01-05 16:24:51 0 d
    C:\Documents and Settings\Owner.OurComputer.001\LimeWire Shared
    2008-01-05 16:24:51 0 d
    C:\Documents and Settings\Owner.OurComputer.001\LimeWire Saved
    2008-01-05 16:24:29 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Incomplete
    2008-01-05 16:24:15 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\LimeWire
    2008-01-05 16:23:54 0 d
    C:\Program Files\LimeWire
    2008-01-05 03:06:34 0 d
    C:\WINDOWS\network diagnostic
    2008-01-05 03:01:43 0 d
    C:\Program Files\MSXML 4.0
    2008-01-05 02:56:30 0 d
    C:\Program Files\Windows Media Connect 2
    2008-01-05 02:55:09 0 d
    C:\95f6720d8dd27ff35de04d5892c1
    2008-01-05 02:54:58 0 d
    C:\WINDOWS\system32\LogFiles
    2008-01-05 02:54:58 0 d
    C:\WINDOWS\system32\drivers\UMDF
    2008-01-05 02:54:41 0 d
    C:\431b80cb0e136959e9bfea3c
    2008-01-05 02:16:35 0 d
    C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
    2008-01-05 02:15:51 0 d
    C:\WINDOWS\system32\PreInstall
    2008-01-05 02:14:18 0 d--hs---- C:\Documents and Settings\Owner.OurComputer.001\UserData
    2008-01-05 01:50:38 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Macromedia
    2008-01-05 01:50:38 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Adobe
    2008-01-05 01:47:08 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\uTorrent
    2008-01-05 00:11:19 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\vlc
    2008-01-05 00:07:07 0 d
    C:\Program Files\VLC
    2008-01-05 00:06:14 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Google

    -- Find3M Report
    2008-01-25 22:58:26 0 d
    C:\Program Files\Common Files
    2008-01-21 15:34:17 0 d
    C:\Program Files\Digital Media Reader
    2008-01-21 14:52:54 0 d
    C:\Program Files\uTorrent
    2008-01-17 17:30:03 0 d
    C:\Program Files\Java
    2008-01-10 15:50:08 0 d
    C:\Program Files\WinAVI Video Converter
    2008-01-10 15:33:47 0 d
    C:\Program Files\Nero
    2008-01-05 01:50:18 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\McAfee.com Personal Firewall
    2008-01-04 23:42:04 0 d--h
    C:\Program Files\InstallShield Installation Information
    2008-01-04 23:34:53 0 d
    C:\Program Files\Pure Networks
    2008-01-04 23:26:11 0 d
    C:\Program Files\Common Files\AOL
    2008-01-04 22:49:24 0 d
    C:\Program Files\Google
    2008-01-04 22:29:14 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\SampleView
    2008-01-04 22:27:44 0 --a
    C:\REQUEST_OEMRESET_ENDUSER
    2008-01-04 22:23:47 0 d
    C:\Program Files\SIFXINST
    2008-01-04 22:23:10 0 d
    C:\Program Files\McAfee
    2008-01-04 22:22:14 0 d
    C:\Program Files\gtw_logo
    2008-01-04 22:21:55 0 d
    C:\Program Files\Realtek
    2008-01-04 22:21:44 0 d
    C:\Program Files\Microsoft Money 2006
    2008-01-04 22:21:09 0 d
    C:\Program Files\Common Files\Nullsoft
    2008-01-04 22:21:09 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\You've Got Pictures Screensaver
    2008-01-04 22:20:46 0 d
    C:\Program Files\Common Files\Real
    2008-01-04 22:20:42 0 d
    C:\Program Files\Real
    2008-01-04 22:20:30 0 d
    C:\Program Files\Viewpoint
    2008-01-04 22:19:56 335 --a
    C:\WINDOWS\nsreg.dat
    2008-01-04 22:19:49 0 d
    C:\Program Files\BigFix
    2008-01-04 22:19:36 0 d
    C:\Program Files\Microsoft Works
    2008-01-04 22:18:46 0 d
    C:\Program Files\MSN Encarta Plus
    2008-01-04 22:18:13 0 d
    C:\Program Files\Microsoft Digital Image 2006
    2008-01-04 22:18:06 4 --a
    C:\WINDOWS\Pix11.dat
    2008-01-04 22:17:33 0 d
    C:\Program Files\Common Files\Adobe
    2008-01-04 22:16:01 0 d
    C:\Program Files\Gateway Games
    2008-01-04 22:14:49 0 d
    C:\Program Files\WildTangent
    2008-01-04 22:13:25 0 d
    C:\Program Files\Common Files\InstallShield
    2008-01-04 22:12:52 0 d
    C:\Program Files\Common Files\Java
    2008-01-04 22:10:18 0 d
    C:\Program Files\Microsoft ActiveSync
    2008-01-04 22:09:52 0 d
    C:\Program Files\Microsoft.NET
    2008-01-04 22:09:01 0 d
    C:\Program Files\CyberLink
    2008-01-04 22:08:25 2 --a
    C:\AUDIT_INSTALL_IN_PROGRESS
    2008-01-04 22:00:22 2 -r-hs---- C:\USER
    2008-01-04 21:58:38 0 d
    C:\Program Files\CONEXANT
    2008-01-04 21:44:38 60 --a
    C:\WINDOWS\system32\SYSDRV.DAT
    2008-01-04 21:43:06 0 d
    C:\Program Files\Windows NT
    2008-01-04 21:43:03 0 d
    C:\Program Files\Movie Maker
    2008-01-04 21:43:01 0 d
    C:\Program Files\Messenger
    2008-01-04 21:38:45 0 d
    C:\Program Files\Windows Plus
    2008-01-04 21:38:45 0 d
    C:\Program Files\Online Services
    2008-01-04 21:38:45 0 d
    C:\Program Files\MSN Gaming Zone
    2008-01-04 21:38:45 0 d
    C:\Program Files\microsoft frontpage
    2008-01-04 21:38:44 0 d
    C:\Program Files\Common Files\SpeechEngines
    2008-01-04 21:38:44 0 d
    C:\Program Files\Common Files\ODBC
    2008-01-04 21:38:44 0 d
    C:\Program Files\Common Files\New Boundary
    2008-01-04 21:38:44 0 d
    C:\Program Files\Common Files\MSSoap
    2008-01-04 21:38:38 0 d
    C:\Documents and Settings\Owner.OurComputer.001\Application Data\Identities

    -- Registry Dump
    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" []
    "readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" []
    "RTHDCPL"="RTHDCPL.EXE" [2006-04-17 05:34 PM C:\WINDOWS\RTHDCPL.exe]
    "CHotkey"="zHotkey.exe" []
    "Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
    "Reminder"="%WINDIR%\Creator\Remind_XP.exe" []
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" []
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" []
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" []
    "MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" []
    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-01-25 11:13 PM]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" []
    "ThreatFire"="C:\Program Files\ThreatFire\TFTray.exe" [2007-12-20 11:13 AM]
    "00PCTFW"="C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" [2007-12-31 09:16 AM]
    "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 02:53 PM]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Power2GoExpress"="NA" []
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 01:00 PM]
    "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 PM]
    "Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2008-01-04 10:19:49 PM]
    Install Pending Files.LNK - C:\Program Files\SIFXINST\SIFXINST.EXE [2008-01-04 10:23:44 PM]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"


    -- End of Deckard's System Scanner: finished at 2008-02-05 08:03:38

    OTMoveit2.txt

    File/Folder C:\WINDOWS\system32\vtstu.dll.vir not found.
    File/Folder C:\WINDOWS\system32\hypkawoh.dll.vir not found.
    C:\WINDOWS\system32\50f85ace moved successfully.
    File/Folder C:\WINDOWS\system32\drivers\astq.tga not found.
    File/Folder C:\WINDOWS\system32\hypkawoh.dll not found.
    C:\1358448879 moved successfully.
    File/Folder C:\WINDOWS\system32\winblg32.dll not found.
    C:\WINDOWS\popcinfo.dat moved successfully.
    File/Folder C:\WINDOWS\system32\winblg32.dll not found.

    OTMoveIt2 v1.0.17 log created on 02052008_075150
  • edited February 2008
    and the Hjt log

    Hijackthis.log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:08:05 AM, on 2008-02-05
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\PC Tools Firewall Plus\FWService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\ThreatFire\TFTray.exe
    C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\ThreatFire\TFService.exe
    C:\WINDOWS\ehome\mcrdsvc.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\WINDOWS\notepad.exe
    C:\WINDOWS\notepad.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Documents and Settings\Owner.OurComputer.001\Desktop\HiJackThis.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
    O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKCU\..\Run: [Power2GoExpress] NA
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
    --
    End of file - 7334 bytes




    Lots of stuff here Thanks:wink:
  • VekaVeka Finland
    edited February 2008
    Hi, you posted contents of Main.txt twice. ;)

    Please post also extra log ( C:\Deckard\System Scanner ).
  • edited February 2008
    oops did i really do that srry.... heres the extra.log

    Deckard's System Scanner v20071014.68
    Extra logfile - please post this as an attachment with your post.
    -- System Information
    Microsoft Windows XP Professional (build 2600) SP 2.0
    Architecture: X86; Language: English
    CPU 0: Intel(R) Pentium(R) 4 CPU 3.00GHz
    CPU 1: Intel(R) Pentium(R) 4 CPU 3.00GHz
    Percentage of Memory in Use: 37%
    Physical Memory (total/avail): 1405.57 MiB / 877.39 MiB
    Pagefile Memory (total/avail): 3300.05 MiB / 2714.51 MiB
    Virtual Memory (total/avail): 2047.88 MiB / 1929.47 MiB
    C: is Fixed (NTFS) - 143.76 GiB total, 63.35 GiB free.
    D: is Fixed (FAT32) - 5.28 GiB total, 2.12 GiB free.
    E: is CDROM (No Media)
    F: is CDROM (No Media)
    G: is Removable (No Media)
    H: is Removable (No Media)
    I: is Removable (No Media)
    J: is Removable (No Media)
    [URL="file://\\.\PHYSICALDRIVE0"]\\.\PHYSICALDRIVE0[/URL] - WDC WD1600BB-22RDA0 - 149.05 GiB - 2 partitions
    \PARTITION0 (bootable) - Installable File System - 143.76 GiB - C:
    \PARTITION1 - Unknown - 5.29 GiB - D:
    [URL="file://\\.\PHYSICALDRIVE2"]\\.\PHYSICALDRIVE2[/URL] - Generic USB CF Reader USB Device
    [URL="file://\\.\PHYSICALDRIVE4"]\\.\PHYSICALDRIVE4[/URL] - Generic USB MS Reader USB Device
    [URL="file://\\.\PHYSICALDRIVE1"]\\.\PHYSICALDRIVE1[/URL] - Generic USB SD Reader USB Device
    [URL="file://\\.\PHYSICALDRIVE3"]\\.\PHYSICALDRIVE3[/URL] - Generic USB SM Reader USB Device

    -- Security Center
    AUOptions is scheduled to auto-install.
    Windows Internal Firewall is disabled.
    FirstRunDisabled is set.
    FW: PC Tools Firewall Plus v3.0.0 (PC Tools)
    FW: v (McAfee) Disabled
    AV: Avira AntiVir PersonalEdition v 7.0.2.90
    (Avira GmbH)
    AV: v (McAfee) Disabled Outdated
    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
    "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"

    -- Environment Variables
    ALLUSERSPROFILE=C:\Documents and Settings\All Users
    APPDATA=C:\Documents and Settings\Owner.OurComputer.001\Application Data
    CLASSPATH=.;C:\Program Files\Java\jre1.5.0_02\lib\ext\QTJava.zip
    CLIENTNAME=Console
    CommonProgramFiles=C:\Program Files\Common Files
    COMPUTERNAME=OURCOMPUTER
    ComSpec=C:\WINDOWS\system32\cmd.exe
    FP_NO_HOST_CHECK=NO
    HOMEDRIVE=C:
    HOMEPATH=\Documents and Settings\Owner.OurComputer.001
    LOGONSERVER=\\OURCOMPUTER
    NUMBER_OF_PROCESSORS=2
    OS=Windows_NT
    Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\QuickTime\QTSystem
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    PROCESSOR_ARCHITECTURE=x86
    PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 9, GenuineIntel
    PROCESSOR_LEVEL=15
    PROCESSOR_REVISION=0409
    ProgramFiles=C:\Program Files
    PROMPT=$P$G
    QTJAVA=C:\Program Files\Java\jre1.5.0_02\lib\ext\QTJava.zip
    SESSIONNAME=Console
    SystemDrive=C:
    SystemRoot=C:\WINDOWS
    TEMP=C:\DOCUME~1\OWNERO~1.001\LOCALS~1\Temp
    TMP=C:\DOCUME~1\OWNERO~1.001\LOCALS~1\Temp
    USERDOMAIN=OURCOMPUTER
    USERNAME=Owner
    USERPROFILE=C:\Documents and Settings\Owner.OurComputer.001
    windir=C:\WINDOWS

    -- User Profiles
    Owner.OurComputer.001 (admin)
    Administrator (admin)
    Guest (guest)

    -- Add/Remove Programs
    --> C:\Program Files\PC Tools Firewall Plus\unins000.exe /LOG
    --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
    Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Reader 7.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
    Apple Mobile Device Support --> MsiExec.exe /I{D8AB8F0C-CEEB-4A29-8EF5-219B064813F4}
    Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
    ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
    Avira AntiVir PersonalEdition Classic --> C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
    Bejeweled 2 Deluxe --> "C:\Program Files\Gateway Games\Bejeweled 2 Deluxe\Uninstall.exe"
    BigFix --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\BigFix\Uninst.isu" -c"C:\Program Files\BigFix\Lib\UninstallHelper.dll"
    Blackhawk Striker 2 --> "C:\Program Files\Gateway Games\Blackhawk Striker 2\Uninstall.exe"
    Blasterball 2 Revolution --> "C:\Program Files\Gateway Games\Blasterball 2 Revolution\Uninstall.exe"
    Digital Media Reader --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{4AC55A61-BA20-4DF5-ABFF-8F4819E0C875} /l1033
    Diner Dash --> "C:\Program Files\Gateway Games\Diner Dash\Uninstall.exe"
    DVD Flick --> "C:\Program Files\DVD Flick\unins000.exe"
    DVD Solution --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
    FATE --> "C:\Program Files\Gateway Games\FATE\Uninstall.exe"
    Gateway Game Console --> "C:\Program Files\WildTangent\Apps\Gateway Game Console\Uninstall.exe"
    Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
    High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
    HijackThis 2.0.2 --> "C:\Documents and Settings\Owner.OurComputer.001\Desktop\HijackThis.exe" /uninstall
    Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
    iTunes --> MsiExec.exe /I{B85C4D19-6CEB-48CF-BD98-C887AC8C6F94}
    Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
    LimeWire 4.16.4 --> "C:\Program Files\LimeWire\uninstall.exe"
    Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
    Microsoft Digital Image Starter Edition 2006 --> "C:\Program Files\Common Files\Microsoft Shared\Picture It!\RmvSuite.exe" ADDREMOVE=1 SKU=TRIAL VERSION=11
    Microsoft Money 2006 --> "C:\Program Files\Microsoft Money 2006\MNYCoreFiles\Setup\uninst.exe" /s:120
    Microsoft Office Standard Edition 2003 --> MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
    Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
    Microsoft Works --> MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
    Multimedia Keyboard Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6E66ECBD-FCA7-4AE1-A8C5-1CA78BEEB057}\Setup.exe" -l0x9
    Nero 6 Ultra Edition --> C:\Program Files\Nero\nero\uninstall\UNNERO.exe /UNINSTALL
    PC Tools Firewall Plus 3.0 --> "C:\Program Files\PC Tools Firewall Plus\unins000.exe"
    Penguins! --> "C:\Program Files\Gateway Games\Penguins!\Uninstall.exe"
    Polar Bowler --> "C:\Program Files\Gateway Games\Polar Bowler\Uninstall.exe"
    Polar Golfer --> "C:\Program Files\Gateway Games\Polar Golfer\Uninstall.exe"
    Power2Go 4.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
    PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
    QuickTime --> MsiExec.exe /I{6EC874C2-F950-4B7E-A5B7-B1066D6B74AA}
    RealPlayer Basic --> C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
    REALTEK GbE & FE Ethernet PCI NIC Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\setup.exe" -l0x9 -removeonly
    Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
    SCRABBLE --> "C:\Program Files\Gateway Games\SCRABBLE\Uninstall.exe"
    SecondLife (remove only) --> "C:\Program Files\SecondLife\uninst.exe" /P="SecondLife"
    Security Update for Step By Step Interactive Training (KB898458) -->
    Soft Data Fax Modem with SmartCP --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F40&SUBSYS_200014F1\HXFSETUP.EXE -U -IPDBRYCM5K.inf
    Sonic Encoders --> MsiExec.exe /I{9941F0AA-B903-4AF4-A055-83A9815CC011}
    Spyware Doctor 5.5 --> C:\Program Files\Spyware Doctor\unins000.exe /LOG
    ThreatFire 3.0 --> "C:\Program Files\ThreatFire\unins000.exe"
    Tradewinds --> "C:\Program Files\Gateway Games\Tradewinds\Uninstall.exe"
    Uniblue ProcessScanner --> "C:\Program Files\Uniblue\ProcessScanner\unins000.exe"
    Update Rollup 2 for Windows XP Media Center Edition 2005 --> C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe
    VideoLAN VLC media player 0.8.6d --> C:\Program Files\VLC\uninstall.exe
    Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
    WildTangent Web Driver --> C:\Program Files\WildTangent\Apps\CDA\CDAUninstall.exe
    Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
    Windows Live Messenger --> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
    Windows Live Sign-in Assistant --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
    Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
    Windows XP Media Center Edition 2005 KB925766 --> "C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
    WinZip 11.1 --> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}

    -- Application Event Log
    Event Record #/Type2362 / Error
    Event Submitted/Written: 02/05/2008 07:37:34 AM
    Event ID/Source: 485 / ESENT
    Event Description:
    MsnMsgr (1908) An attempt to delete the file "[URL="file://\\.\C:\Documents"]\\.\C:\Documents[/URL] and Settings\Owner.OurComputer.001\Local Settings\Application Data\Microsoft\Messenger\christianl1234@hotmail.com\SharingMetadata\Working\database_5650_F861_50F8_48EF\tmp.edb" failed with system error 5 (0x00000005): "Access is denied. ". The delete file operation will fail with error -1032 (0xfffffbf8).
    Event Record #/Type2361 / Error
    Event Submitted/Written: 02/05/2008 07:37:34 AM
    Event ID/Source: 485 / ESENT
    Event Description:
    MsnMsgr (1908) An attempt to delete the file "[URL="file://\\.\C:\Documents"]\\.\C:\Documents[/URL] and Settings\Owner.OurComputer.001\Local Settings\Application Data\Microsoft\Messenger\christianl1234@hotmail.com\SharingMetadata\Working\database_5650_F861_50F8_48EF\tmp.edb" failed with system error 5 (0x00000005): "Access is denied. ". The delete file operation will fail with error -1032 (0xfffffbf8).
    Event Record #/Type2360 / Error
    Event Submitted/Written: 02/05/2008 07:37:34 AM
    Event ID/Source: 485 / ESENT
    Event Description:
    MsnMsgr (1908) An attempt to delete the file "[URL="file://\\.\C:\Documents"]\\.\C:\Documents[/URL] and Settings\Owner.OurComputer.001\Local Settings\Application Data\Microsoft\Messenger\christianl1234@hotmail.com\SharingMetadata\Working\database_5650_F861_50F8_48EF\tmp.edb" failed with system error 5 (0x00000005): "Access is denied. ". The delete file operation will fail with error -1032 (0xfffffbf8).
    Event Record #/Type2359 / Error
    Event Submitted/Written: 02/05/2008 07:37:34 AM
    Event ID/Source: 485 / ESENT
    Event Description:
    MsnMsgr (1908) An attempt to delete the file "[URL="file://\\.\C:\Documents"]\\.\C:\Documents[/URL] and Settings\Owner.OurComputer.001\Local Settings\Application Data\Microsoft\Messenger\christianl1234@hotmail.com\SharingMetadata\Working\database_5650_F861_50F8_48EF\tmp.edb" failed with system error 5 (0x00000005): "Access is denied. ". The delete file operation will fail with error -1032 (0xfffffbf8).
    Event Record #/Type2358 / Error
    Event Submitted/Written: 02/05/2008 07:37:34 AM
    Event ID/Source: 485 / ESENT
    Event Description:
    MsnMsgr (1908) An attempt to delete the file "[URL="file://\\.\C:\Documents"]\\.\C:\Documents[/URL] and Settings\Owner.OurComputer.001\Local Settings\Application Data\Microsoft\Messenger\christianl1234@hotmail.com\SharingMetadata\Working\database_5650_F861_50F8_48EF\tmp.edb" failed with system error 5 (0x00000005): "Access is denied. ". The delete file operation will fail with error -1032 (0xfffffbf8).

    -- Security Event Log
    No Errors/Warnings found.

    -- System Event Log
    Event Record #/Type2144 / Warning
    Event Submitted/Written: 02/05/2008 07:50:14 AM
    Event ID/Source: 2504 / Server
    Event Description:
    The server could not bind to the transport \Device\NetBT_Tcpip_{0D5F7B81-3DDD-484B-A07B-70456A4BCD67}.
    Event Record #/Type2143 / Warning
    Event Submitted/Written: 02/05/2008 07:50:05 AM
    Event ID/Source: 1007 / Dhcp
    Event Description:
    Your computer has automatically configured the IP address for the Network
    Card with network address 001217855698. The IP address being used is 169.254.90.194.
    Event Record #/Type2142 / Warning
    Event Submitted/Written: 02/05/2008 07:49:54 AM
    Event ID/Source: 1003 / Dhcp
    Event Description:
    Your computer was not able to renew its address from the network (from the
    DHCP Server) for the Network Card with network address 001217855698. The following
    error occurred:
    %%121.
    Your computer will continue to try and obtain an address on its own from
    the network address (DHCP) server.
    Event Record #/Type2138 / Error
    Event Submitted/Written: 02/05/2008 07:47:23 AM
    Event ID/Source: 10005 / DCOM
    Event Description:
    DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
    in order to run the server:
    {1BE1F766-5536-11D1-B726-00C04FB926AF}
    Event Record #/Type2137 / Error
    Event Submitted/Written: 02/05/2008 07:46:06 AM
    Event ID/Source: 10005 / DCOM
    Event Description:
    DCOM got error "%%1084" attempting to start the service MSIServer with arguments ""
    in order to run the server:
    {000C101C-0000-0000-C000-000000000046}

    -- End of Deckard's System Scanner: finished at 2008-02-05 08:03:38
  • VekaVeka Finland
    edited February 2008
    Thank you, defcon3. :)

    Looks pretty good. One file to be deleted.


    You may want to print out these instructions or save them as a text file with Notepad to your desktop because we will be restarting into Safe Mode later on in the fix.


    Step 1:

    Please download to your Desktop

    ATF Cleaner
    AVG Anti-Spyware


    Step 2:
    • Please double-click OTMoveIt2 to run it.
    • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
      C:\WINDOWS\system32\ssqrrss.dll
      
    • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
    • Click the red Moveit! button.
    • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log).
      Please open this log in Notepad and post its contents in your next reply.
    • Close OTMoveIt2
    If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

    Step 3:

    Run ATF Cleaner
    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.
    For Technical Support, double-click the e-mail address located at the bottom of each menu.

    Step 4:

    Install and update AVG Anti-Spyware

    After the installation, a free 30-day trial version containing all the extensions of the full version will be activated. At the end of the trial, these extensions will be deactivated and the program will turn into a feature-limited freeware version.
    • Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
    • Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
    • On the main screen select the icon "Update" then select the "Update now" link.
      • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    • Under "Reports"
      • Select "Do not automatically generate report"
      • Un-Select "Only if threats were found"
    Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.

    Step 5:

    Next, please reboot your computer in Safe Mode by doing the following :
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    • Instead of Windows loading as normal, a menu with options should appear;
    • Select the first option, to run Windows in Safe Mode, then press "Enter".
    • Choose your usual account.
    Step 6:

    Important: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess.
    • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
    • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    • AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.

      Once the scan is complete do the following:
    • If you have any infections you will prompted, then select "Apply all actions"
    • Next select the "Reports" icon at the top.
    • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
    • Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the results of the AVG Anti-Spyware report scan.

    Post back OTMoveIt2 log and AVG Anti-Spyware report, along with a new HijackThis.

    Waiting your reply :)
  • VekaVeka Finland
    edited February 2008
    Are you there, defcon3 ? :)
  • edited February 2008
    yea im here srry about that... been a lil busy lately... will get on the last thing right away
  • edited February 2008
    ok did it last night....here is the

    OTmoveit2

    DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqrrss.dll
    C:\WINDOWS\system32\ssqrrss.dll NOT unregistered.
    C:\WINDOWS\system32\ssqrrss.dll moved successfully.

    OTMoveIt2 v1.0.17 log created on 02092008_221251

    AVG-Antispyware

    AVG Anti-Spyware - Scan Report
    + Created at: 7:36:21 AM 2008-02-10
    + Scan result:

    C:\Program Files\Outerinfo\OinFP.exe -> Downloader.Agent.hjs : Cleaned with backup (quarantined).
    C:\_OTMoveIt\MovedFiles\02092008_221251\WINDOWS\system32\ssqrrss.dll -> Trojan.Obfuscated.lf : Cleaned with backup (quarantined).

    ::Report end

    Hijackthis

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:42:47 AM, on 2008-02-10
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\PC Tools Firewall Plus\FWService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\ThreatFire\TFTray.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\ThreatFire\TFService.exe
    C:\WINDOWS\ehome\mcrdsvc.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\Documents and Settings\Owner.OurComputer.001\Desktop\HiJackThis.exe
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
    O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [Power2GoExpress] NA
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
    --
    End of file - 7627 bytes



    I believe thats it.... i dont know... looks clean right?
  • VekaVeka Finland
    edited February 2008
    I'd like to see an Uninstall list
    • Open HijackThis, click Config, click Misc Tools
    • Click "Open Uninstall Manager"
    • Click "Save List" (generates uninstall_list.txt)
  • edited February 2008
    alright here is the uninstall list for you

    Adobe Flash Player ActiveX
    Adobe Reader 7.0
    Apple Mobile Device Support
    Apple Software Update
    ATI Display Driver
    AVG Anti-Spyware 7.5
    Avira AntiVir PersonalEdition Classic
    Bejeweled 2 Deluxe
    BigFix
    Blackhawk Striker 2
    Blasterball 2 Revolution
    Digital Media Reader
    Diner Dash
    DVD Flick
    DVD Solution
    FATE
    Gateway Game Console
    Google Toolbar for Internet Explorer
    High Definition Audio Driver Package - KB888111
    HijackThis 2.0.2
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 10 (KB903157)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB888795)
    Hotfix for Windows XP (KB891593)
    Hotfix for Windows XP (KB895961)
    Hotfix for Windows XP (KB896256)
    Hotfix for Windows XP (KB899337)
    Hotfix for Windows XP (KB899510)
    Hotfix for Windows XP (KB902841)
    Hotfix for Windows XP (KB906569)
    Hotfix for Windows XP (KB909095)
    Hotfix for Windows XP (KB910728)
    Hotfix for Windows XP (KB912024)
    Hotfix for Windows XP (KB914440)
    Hotfix for Windows XP (KB914906)
    Hotfix for Windows XP (KB915865)
    Hotfix for Windows XP (KB926239)
    Hotfix for Windows XP (KB935448)
    iTunes
    Java(TM) 6 Update 3
    LimeWire 4.16.4
    Microsoft .NET Framework 1.0 Hotfix (KB930494)
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Digital Image Starter Edition 2006
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft Money 2006
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Standard Edition 2003
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Works
    MSXML 4.0 SP2 (KB936181)
    Multimedia Keyboard Driver
    Nero 6 Ultra Edition
    PC Tools Firewall Plus 3.0
    Penguins!
    Polar Bowler
    Polar Golfer
    Power2Go 4.0
    PowerDVD
    QuickTime
    RealPlayer Basic
    REALTEK GbE & FE Ethernet PCI NIC Driver
    Realtek High Definition Audio Driver
    SCRABBLE
    SecondLife (remove only)
    Security Update for Microsoft .NET Framework 2.0 (KB928365)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896424)
    Security Update for Windows XP (KB896688)
    Security Update for Windows XP (KB899589)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB905915)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB908531)
    Security Update for Windows XP (KB911280)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911567)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB912812)
    Security Update for Windows XP (KB912919)
    Security Update for Windows XP (KB913433)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB916281)
    Security Update for Windows XP (KB917159)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917537)
    Security Update for Windows XP (KB917953)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921503)
    Security Update for Windows XP (KB922819)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923414)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924496)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929123)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931261)
    Security Update for Windows XP (KB931784)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB936021)
    Security Update for Windows XP (KB937894)
    Security Update for Windows XP (KB938127)
    Security Update for Windows XP (KB938829)
    Security Update for Windows XP (KB941202)
    Security Update for Windows XP (KB941568)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB941644)
    Security Update for Windows XP (KB942615)
    Security Update for Windows XP (KB943460)
    Security Update for Windows XP (KB943485)
    Security Update for Windows XP (KB944653)
    Soft Data Fax Modem with SmartCP
    Sonic Encoders
    Spyware Doctor 5.5
    ThreatFire 3.0
    Tradewinds
    Uniblue ProcessScanner
    Update for Windows Media Player 10 (KB910393)
    Update for Windows Media Player 10 (KB913800)
    Update for Windows Media Player 10 (KB926251)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB904942)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB912945)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB927891)
    Update for Windows XP (KB930916)
    Update for Windows XP (KB936357)
    Update for Windows XP (KB938828)
    Update for Windows XP (KB942763)
    Update for Windows XP (KB942840)
    Update Rollup 2 for Windows XP Media Center Edition 2005
    VideoLAN VLC media player 0.8.6d
    Viewpoint Media Player
    WildTangent Web Driver
    Windows Internet Explorer 7
    Windows Live installer
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Media Format 11 runtime
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Media Player 11
    Windows XP Hotfix - KB886185
    Windows XP Media Center Edition 2005 KB925766
    WinZip 11.1
  • VekaVeka Finland
    edited February 2008
    Please do the following...

    Step 1:

    Remove this folder

    C:\Program Files\Outerinfo

    Step 2:

    Click Start, and then Run.

    Type (or copy & paste) sc stop CLTNetCnService

    Click OK

    Click Start and Run again.

    Now type (or copy & paste) sc delete CLTNetCnService

    Click OK


    You can also remove this folder as you aren't using Symantec

    C:\Program Files\Common Files\Symantec Shared

    Step 3:

    Your Java is out of date.

    Older versions have vulnerabilities that malicious sites can use to infect your system.

    Please follow these steps to remove older version Java components and update:
    • Download the latest version of Java Runtime Environment (JRE) 6 Update 4 and save it to your desktop.
    • Scroll down to where it says "JJava Runtime Environment (JRE) 6 Update 4...allows end-users to run Java applications".
    • Click the "Download" button to the right.
    • Read the License Agreement and then check the box that says: "Accept License Agreement". The page will refresh.
    • Click on the link to download Windows Offline Installation and save the file to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
    • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u4-windows-i586-p.exe to install the newest version.
    ========================
    [SIZE=-1]
    The n[/SIZE]ext steps are optional but recommended:

    Step 4:


    Uninstall WildTangent Web Driver by using Add or Remove Programs

    Wild Tangent is a video game software company specializing in online games. It has even made a partnership with AOL to include itself as part of the AOL Instant Messenger for their AIM games section. The WildTangent Web Driver is their technology that allows you to play 3D games over the Internet. Although its not technically considered spyware it does have built in components to update itself and gather information about the computer system.

    For more information:

    http://www.pchell.com/support/wildtangent.shtml
    http://www.bleepingcomputer.com/uninstall/1615/WildTangent-Web-Driver.html

    Step 5:

    I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager -- the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.
    To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.
    Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.

    I recommend that you remove the Viewpoint products; however, decide for yourself.

    To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
    1. Click Start, point to Settings, and then click Control Panel.
    2. In Control Panel, double-click Add or Remove Programs.
    3. In Add or Remove Programs, highlight >>Viewpoint component<< , click Remove.
    4. Do the same for each Viewpoint component.
    ========================

    I'd like to know how your computer is running?
  • edited February 2008
    Running very well... much faster now... id say about a 90 percent increase in response time.... like its old self again... i removed the wild tangent the view point and put the new java in.... just for giggles and grins here is another hijack this log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:22:52 PM, on 2008-02-12
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\PC Tools Firewall Plus\FWService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\ThreatFire\TFTray.exe
    C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\ThreatFire\TFService.exe
    C:\WINDOWS\ehome\mcrdsvc.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Windows Media Player\setup_wm.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\Owner.OurComputer.001\Desktop\HiJackThis.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
    O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKCU\..\Run: [Power2GoExpress] NA
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
    --
    End of file - 7656 bytes
  • VekaVeka Finland
    edited February 2008
    Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

    For cookies issue, see here

    Next we remove all used tools.

    Please download OTMoveIt2 and save it to desktop.
    • Double-click OTMoveIt2.exe.
    • Click the CleanUp! button.
    • Select Yes when the "Begin cleanup Process?" prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes, if not delete it by yourself.
    Note: If you receive a warning from your firewall or other security programs regarding OTMoveIt2 attempting to contact the internet, please allow it to do so.
    • Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

      You can find instructions on how to enable and re-enable system restore here:

      Windows XP System Restore Guide
    Re-enable system restore with instructions from tutorial above
    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
    • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
    • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
    • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

      A tutorial on installing & using this product can be found here:

      Using SpywareBlaster to protect your computer from Spyware and Malware


    • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
    Follow this list and your potential for being infected again will reduce dramatically.

    Here are some additional utilities that will enhance your safety
    • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
    • Comodo BOCLEAN <= Stop identity thieves from getting personal information. Instantly detects well over 1,000,000 unique, variant and repack malware in total. And it's free.
    • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:

      Using Winpatrol to protect your computer from malicious software
    Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference!

    The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

    Also, please read this great article by Tony Klein So How Did I Get Infected In First Place

    Happy surfing and stay clean!
  • edited February 2008
    thank you very much i appreciate all the work that you have done and i thank you for your time and effort....

    thanks alot
    defcon3
  • VekaVeka Finland
    edited February 2008
    Glad to be able to help :)
  • TroganTrogan London, UK
    edited February 2008
    Glad we could be of assistance! The help you received here was free.

    This topic is now closed. If you wish it reopened, please send a Private Message to Trogan with a link to your thread.

    If you are not the user who started this thread, you must start your own Thread instead (grin)
    _______________________________
    Have we helped you with any issues you have had with your PC's or other items? If so, you can now help us by Joining Team 93 and fold for a cure.
Sign In or Register to comment.