PDA

View Full Version : Quarantining/Removing My Defective CMDService...



rightontargt4
2007-01-18, 17:06
Hi. I'm only good with computers in certain areas, and technical is not one of them. (At least not this technical) I have a Hijackthis log that I will post on a follow-up post. I have Spybot, and everytime I scan, I pick up more and more malware, and I'm guessing it's because of commandservice. I have probably 3 or 4 adware finders, and they delete what CMDservice puts out, I'm guessing. (I've got Ad-Aware, Prev1X, CCleaner, Spybot). Also, I use Sophos Antivirus (required by the college I'm attending) and there were a few DLL files that were said to be infected with Trojan activity. If anyone can help by guiding me on how to remove/fix those as well, I would greatly appreciate it. The following post is my HijackThis log.

rightontargt4
2007-01-18, 17:07
Logfile of HijackThis v1.99.1
Scan saved at 10:00:55 AM, on 1/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZSTC06.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ryan Littlefield\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\slndxwyw.dll",setvm
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156107684015
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures06.aim.com/ygp/aol/plugin/upf/AOLUPF.en-US-AIM.9.5.1.8.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {AD08A333-609E-11D3-950C-008098601567} - http://wordreference.com/Install/English%20to%20Spanish.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

rightontargt4
2007-01-18, 17:48
Also, if any of the moderators use AIM (AOL Instant Messenger) that might be an easier way to get a hold of me. I'm almost always on, except for when I'm in class.

My screen name is andssheburns.

Thank you.

rightontargt4
2007-01-18, 21:42
I understand that the moderators of this site are busy, I'm just boosting my thread, so I can get some help (hopefully). Thank you for your service!

rightontargt4
2007-01-18, 21:47
By the way, here are the results from my PandaScan.


Part 1:


Incident Status Location

Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\LocalService\Cookies\ryan_littlefield@advertising[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\LocalService\Cookies\ryan_littlefield@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\LocalService\Cookies\ryan_littlefield@atwola[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\LocalService\Cookies\ryan_littlefield@doubleclick[1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\LocalService\Cookies\ryan_littlefield@hitbox[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\LocalService\Cookies\ryan_littlefield@media.adrevolver[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\LocalService\Cookies\ryan_littlefield@mediaplex[1].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\LocalService\Cookies\ryan_littlefield@www.myaffiliateprogram[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Earthlink\6.0\compboy7@earthlink.net\Cookies\ryan littlefield@atwola[1].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Earthlink\6.0\compboy7@earthlink.net\Cookies\ryan littlefield@banner[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Earthlink\6.0\compboy7@earthlink.net\Cookies\ryan littlefield@burstnet[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Earthlink\6.0\compboy7@earthlink.net\Cookies\ryan littlefield@com[2].txt
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Earthlink\6.0\compboy7@earthlink.net\Cookies\ryan littlefield@rightmedia[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Earthlink\6.0\compboy7@earthlink.net\Cookies\ryan littlefield@www.burstbeacon[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Ryan Littlefield\Application Data\Mozilla\Firefox\Profiles\6qmw3r7n.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Ryan Littlefield\Cookies\ryan littlefield@atwola[2].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Ryan Littlefield\Cookies\ryan littlefield@banner[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Ryan Littlefield\Cookies\ryan littlefield@burstnet[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Ryan Littlefield\Cookies\ryan littlefield@com[3].txt
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Ryan Littlefield\Cookies\ryan littlefield@rightmedia[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Ryan Littlefield\Cookies\ryan littlefield@www.burstbeacon[1].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Ryan Littlefield\My Documents\NESgames\WinZip63\download10274610601854068.mpeg
Spyware:Spyware/Virtumonde Not disinfected C:\Program Files\Common Files\{2CC80750-0BB0-1033-0826-041205030001}\services.dll
Adware:adware/keenvalue Not disinfected C:\WINDOWS\browserxtras\pn\remove.exe

rightontargt4
2007-01-18, 21:48
Part 2:

Potentially unwanted tool:Application/FunWeb Not disinfected C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.8.inf
Adware:Adware/AdwareShooter Not disinfected C:\WINDOWS\Microsoft.NET\ndstfp.dll
Potentially unwanted tool:application/bestoffer Not disinfected C:\WINDOWS\smdat32m.sys
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\andvujpg.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\anwuhbvr.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\apmwjdqm.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\baetlbeh.exe
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\bnvqmbwj.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\bqfwvhwc.exe
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\bwqxposk.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\cjhoxjad.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\cnidtffl.exe
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\cpljebph.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\cqpquxwa.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\cxglejes.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\dihanohp.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\doxtpdnw.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\fdpriddg.exe
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\fqtnlohv.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\ftuhinsa.exe
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\fxcrbpwy.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\gcdwvmsy.dll
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\gcgcqvim.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\genuqxmj.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\gnglquiw.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\gntpmjyu.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\gsgibvmt.dll
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\gvtbjdkp.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\gxxltnwj.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\hkfpecys.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\hqvqwqwg.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\hwnuqgnt.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\hxiephvi.exe
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\iqgmtnpc.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\islxjxca.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\iutovjyf.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\jakxhkpj.dll
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\jhtdbwda.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\jmkoegup.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\joipirgk.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\jscmbxra.exe
Spyware:Spyware/Virtumonde

rightontargt4
2007-01-18, 21:49
Part 3:

Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\jybyvstt.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\kbhoifok.dll
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\kbpajxdy.dll
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\kmsnwfhu.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\lcencpxp.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\llkoyfql.exe
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\lpsancwc.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\lsrfnfrh.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\lumatqkl.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\mldaqcsj.dll
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\mxfldnhc.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\ncfmlbjq.exe
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\nedapxao.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\npppmagl.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\npqiafcx.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\nspilnve.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\ntbckwqr.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\nvnhmydm.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\nwdbcggh.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\nyyjhkjq.dll
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\oeimygyk.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\ohcwkjtg.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\oqasfldl.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\ovdjxcvi.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\oyraehuu.exe
Potentially unwanted tool:Application/P2PNetworking Not disinfected C:\WINDOWS\SYSTEM32\P2P Networking v126.cpl
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\paejntkv.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\paulnfgh.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\pbeqlvyg.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\pdkprjyu.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\pemjbnby.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\phqphvak.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\plgpbgek.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\plsvavxb.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\pnlgtkqj.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\prelyoab.dll
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\pxhxvmxk.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\qdrasogi.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\qduonhbi.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\qvtolnfp.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\rcwmicev.exe
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\reuekwsj.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\rftullnm.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\rfubsfoq.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\rhfrbomh.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\rjjryely.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\rkmktnog.dll
Spyware:Spyware/Virtumonde

rightontargt4
2007-01-18, 21:50
Annnd, Part 4.

Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\rsnhbnve.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\rtiwpvxs.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\rwlsayeh.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\sdawniau.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\skywcfcl.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\sosbxhfx.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\soxitomh.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\sqntyyro.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\sxqbouml.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\tbpkesyk.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\tbrsgsar.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\tljcctec.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\tmixjgue.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\udroryce.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\udtewsmy.dll
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\unqkjcxv.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\uvfeiosm.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\uxxmfqck.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\vemmsllt.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\venlkclu.exe
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\vfejoqsd.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\vkhgbulo.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\vqtsmwiu.exe
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\vymyarhx.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\wfinyboq.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\whevlcxq.dll
Adware:Adware/Mirar Not disinfected C:\WINDOWS\SYSTEM32\WinNB58.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\wuxektws.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\wvxuvwmp.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\wwxblckn.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\wyudsohj.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\xkkhtfqk.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\xnxtvbbq.dll
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\xryrfsfq.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\xsvvcqms.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\xyloxeyd.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\xyvmaixi.dll
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\yclcifrd.dll
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\SYSTEM32\yoalsayc.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\yuhvqidj.dll
Adware:Adware/CommAd Not disinfected C:\WINDOWS\UnlhbiBMaXR0bGVmaWVsZA\oB51v21gurlXv3pAuqpPtE.vbs

Mr_JAk3
2007-01-21, 14:01
Hi rightontargt4 and welcome to the Forums :)

You got some infections there...

Create a new folder for HijackThis and move HijackThis.exe into it.

Rename HijackThis.exe to Scanner.exe

Please download VundoFix.exe (http://www.atribune.org/ccount/click.php?id=4) to your desktop.
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

rightontargt4
2007-01-22, 08:43
Alright, cool, thanks... here's my HijackThis log...

Logfile of HijackThis v1.99.1
Scan saved at 1:42:01 AM, on 1/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ryan Littlefield\My Documents\HijackThis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\SYSTEM32\HDBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {278B661A-14A8-D8B0-6AF4-03088B866149} - (no file)
O2 - BHO: (no name) - {3EBED35B-005B-427F-92F0-2D054915144B} - C:\WINDOWS\Microsoft.NET\ndstfp.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: CBHOBJObj Object - {8A406068-D45C-40B9-A096-38AC717FB608} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156107684015
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures06.aim.com/ygp/aol/plugin/upf/AOLUPF.en-US-AIM.9.5.1.8.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {AD08A333-609E-11D3-950C-008098601567} - http://wordreference.com/Install/English%20to%20Spanish.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winqne32 - winqne32.dll (file missing)
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

rightontargt4
2007-01-22, 08:49
Also, I noticed you asked me to post the log of VundoFix, I couldn't find it. However, I ran VundoFix again, and no infected files were found. Is there anything else I need to do?

Thanks!

rightontargt4
2007-01-22, 08:58
I ALSO noticed that CommandService still shows up when I run Spybot....and seems to breed other forms of Adware/Malware. How can I fix/delete this??

Mr_JAk3
2007-01-22, 16:44
Hi, well continue then :)

1. Download this file - combofix.exe (http://download.bleepingcomputer.com/sUBs/combofix.exe)
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

rightontargt4
2007-01-22, 18:11
Alright, here she is.

Part 1

"Ryan Littlefield" - 07-01-22 11:04:36 Service Pack 2
ComboFix 07-01-21 - Running from: "C:\Program Files\Mozilla Firefox"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\SVKP.sys
C:\WINDOWS\system32\WinNB58.dll
C:\autorun.inf
C:\setup.exe
C:\Program Files\Common Files\{2CC80~1
C:\Program Files\VSAdd-in


((((((((((((((((((((((((((((((( Files Created from 2006-12-22 to 2007-01-22 ))))))))))))))))))))))))))))))))))


2007-01-22 01:53 <DIR> d-------- C:\Program Files\UBT
2007-01-21 23:33 <DIR> d-------- C:\VundoFix Backups
2007-01-21 20:42 44,060 --a------ C:\WINDOWS\SYSTEM32\umehgauf.dll
2007-01-20 20:43 76,412 --a------ C:\WINDOWS\SYSTEM32\prdsxqaf.dll
2007-01-20 20:42 44,060 --a------ C:\WINDOWS\SYSTEM32\rltoqeio.dll
2007-01-19 20:42 44,060 --a------ C:\WINDOWS\SYSTEM32\qsxijhay.dll
2007-01-19 00:03 28,672 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\CO_Mon.sys
2007-01-18 20:42 76,412 --a------ C:\WINDOWS\SYSTEM32\oegawvtt.dll
2007-01-18 20:42 44,060 --a------ C:\WINDOWS\SYSTEM32\vbbgvdcv.dll
2007-01-18 10:43 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2007-01-17 20:42 44,060 --a------ C:\WINDOWS\SYSTEM32\wfkjjgww.dll
2007-01-16 20:42 76,412 --a------ C:\WINDOWS\SYSTEM32\rombfcdk.dll
2007-01-16 20:42 44,060 --a------ C:\WINDOWS\SYSTEM32\ofunlvpr.dll
2007-01-16 15:35 <DIR> d-------- C:\WINDOWS\ie7updates
2007-01-16 12:45 15,872 --------- C:\WINDOWS\SYSTEM32\sophosboottasks.exe
2007-01-16 12:45 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-22 11:04 -------- d-------- C:\Program Files\mozilla firefox
2007-01-22 00:01 -------- d-------- C:\Program Files\prevx1
2007-01-18 15:36 -------- d-------- C:\DOCUME~1\RYANLI~1\Application Data\prevx
2007-01-18 12:21 -------- d-------- C:\Program Files\itunes
2007-01-18 12:13 -------- d-------- C:\Program Files\aim
2007-01-16 21:34 -------- d-------- C:\DOCUME~1\RYANLI~1\Application Data\u3
2007-01-16 18:54 -------- d-------- C:\Program Files\world of warcraft
2006-12-15 20:24 13952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxrd.sys
2006-12-15 10:35 42516 --a------ C:\WINDOWS\SYSTEM32\gcgcqvim.dll
2006-12-15 10:35 126996 --a------ C:\WINDOWS\SYSTEM32\xyloxeyd.dll
2006-12-14 22:36 -------- d-------- C:\Program Files\pokerstars
2006-12-14 10:35 42516 --a------ C:\WINDOWS\SYSTEM32\cpljebph.dll
2006-12-13 10:34 42516 --a------ C:\WINDOWS\SYSTEM32\kmsnwfhu.dll
2006-12-12 10:34 42516 --a------ C:\WINDOWS\SYSTEM32\yoalsayc.dll
2006-12-12 10:34 42516 --a------ C:\WINDOWS\SYSTEM32\vymyarhx.dll
2006-12-11 10:34 42516 --a------ C:\WINDOWS\SYSTEM32\yclcifrd.dll
2006-12-10 10:33 42516 --a------ C:\WINDOWS\SYSTEM32\gvtbjdkp.dll
2006-12-09 10:33 42516 --a------ C:\WINDOWS\SYSTEM32\fxcrbpwy.dll
2006-12-08 13:36 7552 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxcom.sys
2006-12-08 13:36 274688 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxfsf.sys
2006-12-08 13:36 18560 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxtdi.sys
2006-12-08 13:36 11648 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxscrmbl.sys
2006-12-08 13:36 100864 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\PxEmu.sys
2006-12-08 10:33 42516 --a------ C:\WINDOWS\SYSTEM32\bwqxposk.dll
2006-12-08 09:32 42516 --a------ C:\WINDOWS\SYSTEM32\unqkjcxv.dll
2006-12-07 10:20 -------- d-------- C:\Program Files\yopza
2006-12-07 09:32 42516 --a------ C:\WINDOWS\SYSTEM32\pxhxvmxk.dll
2006-12-07 09:31 42516 --a------ C:\WINDOWS\SYSTEM32\jybyvstt.dll
2006-12-07 00:29 2374472 --a------ C:\WINDOWS\SYSTEM32\wmvcore.dll
2006-12-06 09:31 42516 --a------ C:\WINDOWS\SYSTEM32\bnvqmbwj.dll
2006-12-05 09:46 42516 --a------ C:\WINDOWS\SYSTEM32\reuekwsj.dll
2006-12-04 11:10 42516 --a------ C:\WINDOWS\SYSTEM32\vfejoqsd.dll
2006-12-03 11:10 42516 --a------ C:\WINDOWS\SYSTEM32\iqgmtnpc.dll
2006-12-02 11:10 42516 --a------ C:\WINDOWS\SYSTEM32\kbpajxdy.dll
2006-12-01 11:10 42516 --a------ C:\WINDOWS\SYSTEM32\lpsancwc.dll
2006-11-30 16:00 42516 --a------ C:\WINDOWS\SYSTEM32\fqtnlohv.dll
2006-11-29 16:00 42516 --a------ C:\WINDOWS\SYSTEM32\nedapxao.dll
2006-11-29 15:03 42516 --a------ C:\WINDOWS\SYSTEM32\xryrfsfq.dll
2006-11-28 15:03 42516 --a------ C:\WINDOWS\SYSTEM32\mxfldnhc.dll
2006-11-27 15:02 42516 --a--c--- C:\WINDOWS\SYSTEM32\jhtdbwda.dll
2006-11-26 15:01 110612 --a------ C:\WINDOWS\SYSTEM32\ftuhinsa.exe
2006-11-17 11:27 60436 --a------ C:\WINDOWS\SYSTEM32\rwlsayeh.dll
2006-11-17 11:27 110612 --a------ C:\WINDOWS\SYSTEM32\wwxblckn.exe
2006-11-16 11:27 60436 --a------ C:\WINDOWS\SYSTEM32\rhfrbomh.dll
2006-11-16 11:27 110612 --a------ C:\WINDOWS\SYSTEM32\ohcwkjtg.exe
2006-11-15 11:27 60436 --a------ C:\WINDOWS\SYSTEM32\wvxuvwmp.dll
2006-11-15 11:27 110612 --a------ C:\WINDOWS\SYSTEM32\rcwmicev.exe
2006-11-14 11:27 60436 --a------ C:\WINDOWS\SYSTEM32\islxjxca.dll
2006-11-14 11:26 110612 --a------ C:\WINDOWS\SYSTEM32\lcencpxp.exe
2006-11-13 11:27 110612 --a------ C:\WINDOWS\SYSTEM32\lsrfnfrh.exe
2006-11-13 11:26 60436 --a------ C:\WINDOWS\SYSTEM32\gsgibvmt.dll
2006-11-13 11:26 110612 --a------ C:\WINDOWS\SYSTEM32\rsnhbnve.exe
2006-11-13 11:25 60436 --a------ C:\WINDOWS\SYSTEM32\rftullnm.dll
2006-11-12 11:25 60436 --a------ C:\WINDOWS\SYSTEM32\wyudsohj.dll
2006-11-12 11:25 110612 --a------ C:\WINDOWS\SYSTEM32\fdpriddg.exe
2006-11-11 11:25 60436 --a------ C:\WINDOWS\SYSTEM32\pbeqlvyg.dll
2006-11-11 11:25 110612 --a------ C:\WINDOWS\SYSTEM32\venlkclu.exe
2006-11-10 11:25 60436 --a------ C:\WINDOWS\SYSTEM32\mldaqcsj.dll
2006-11-10 11:25 110612 --a------ C:\WINDOWS\SYSTEM32\npqiafcx.exe
2006-11-09 11:25 110612 --a------ C:\WINDOWS\SYSTEM32\gnglquiw.exe
2006-11-09 11:24 60436 --a------ C:\WINDOWS\SYSTEM32\prelyoab.dll
2006-11-09 11:24 60436 --a------ C:\WINDOWS\SYSTEM32\paejntkv.dll
2006-11-09 00:23 60436 --a------ C:\WINDOWS\SYSTEM32\lumatqkl.dll
2006-11-09 00:23 110612 --a------ C:\WINDOWS\SYSTEM32\plgpbgek.exe
2006-11-09 00:22 60436 --a------ C:\WINDOWS\SYSTEM32\qvtolnfp.dll
2006-11-08 22:22 60436 --a------ C:\WINDOWS\SYSTEM32\phqphvak.dll
2006-11-08 22:22 110612 --a------ C:\WINDOWS\SYSTEM32\xkkhtfqk.exe
2006-11-08 17:35 60436 --a------ C:\WINDOWS\SYSTEM32\xnxtvbbq.dll
2006-11-08 17:35 110612 --a------ C:\WINDOWS\SYSTEM32\uxxmfqck.exe
2006-11-08 17:33 60436 --a------ C:\WINDOWS\SYSTEM32\paulnfgh.dll
2006-11-08 17:33 110612 --a------ C:\WINDOWS\SYSTEM32\hkfpecys.exe
2006-11-08 00:06 679424 --a------ C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-11-07 22:27 60436 --a------ C:\WINDOWS\SYSTEM32\uvfeiosm.dll
2006-11-07 22:27 110612 --a------ C:\WINDOWS\SYSTEM32\apmwjdqm.exe
2006-11-07 22:25 60436 --a------ C:\WINDOWS\SYSTEM32\jmkoegup.dll
2006-11-07 21:03 6049280 --------- C:\WINDOWS\SYSTEM32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\SYSTEM32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\SYSTEM32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\SYSTEM32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\SYSTEM32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\SYSTEM32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\SYSTEM32\msls31.dll
2006-11-07 16:38 60436 --a------ C:\WINDOWS\SYSTEM32\gcdwvmsy.dll
2006-11-07 16:38 110612 --a------ C:\WINDOWS\SYSTEM32\cnidtffl.exe
2006-11-07 03:27 382976 --a------ C:\WINDOWS\SYSTEM32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\SYSTEM32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\SYSTEM32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\SYSTEM32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\SYSTEM32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\SYSTEM32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\SYSTEM32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\SYSTEM32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\SYSTEM32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\SYSTEM32\ieakui.dll
2006-11-06 18:44 60436 --a------ C:\WINDOWS\SYSTEM32\jakxhkpj.dll
2006-11-06 18:44 110612 --a------ C:\WINDOWS\SYSTEM32\sxqbouml.exe
2006-11-05 18:42 60436 --a------ C:\WINDOWS\SYSTEM32\pnlgtkqj.dll
2006-11-05 18:42 110612 --a------ C:\WINDOWS\SYSTEM32\vqtsmwiu.exe
2006-11-05 18:40 60436 --a------ C:\WINDOWS\SYSTEM32\whevlcxq.dll
2006-11-05 18:40 110612 --a------ C:\WINDOWS\SYSTEM32\tbpkesyk.exe
2006-11-04 18:39 60436 --a------ C:\WINDOWS\SYSTEM32\ntbckwqr.dll
2006-11-04 18:39 110612 --a------ C:\WINDOWS\SYSTEM32\nspilnve.exe
2006-11-04 15:58 60436 --a------ C:\WINDOWS\SYSTEM32\kbhoifok.dll
2006-11-04 15:58 110612 --a------ C:\WINDOWS\SYSTEM32\qduonhbi.exe
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\SYSTEM32\msxml4.dll
2006-11-04 10:34 60436 --a------ C:\WINDOWS\SYSTEM32\soxitomh.dll
2006-11-04 10:34 118804 --a------ C:\WINDOWS\SYSTEM32\oeimygyk.dll
2006-11-04 10:34 110612 --a------ C:\WINDOWS\SYSTEM32\bqfwvhwc.exe
2006-11-04 09:32 60436 --a------ C:\WINDOWS\SYSTEM32\rkmktnog.dll
2006-11-04 09:32 110612 --a------ C:\WINDOWS\SYSTEM32\oqasfldl.exe
2006-11-04 00:29 118804 --a------ C:\WINDOWS\SYSTEM32\andvujpg.dll
2006-11-03 09:31 60436 --a------ C:\WINDOWS\SYSTEM32\dihanohp.dll
2006-11-03 09:31 110612 --a------ C:\WINDOWS\SYSTEM32\baetlbeh.exe
2006-11-03 08:30 60436 --a------ C:\WINDOWS\SYSTEM32\nyyjhkjq.dll
2006-11-03 08:30 110612 --a------ C:\WINDOWS\SYSTEM32\xsvvcqms.exe
2006-11-03 00:49 60436 --a------ C:\WINDOWS\SYSTEM32\genuqxmj.dll
2006-11-03 00:49 110612 --a------ C:\WINDOWS\SYSTEM32\qdrasogi.exe
2006-11-02 00:47 60436 --a------ C:\WINDOWS\SYSTEM32\cxglejes.dll
2006-11-02 00:47 110612 --a------ C:\WINDOWS\SYSTEM32\sdawniau.exe
2006-11-02 00:38 60436 --a------ C:\WINDOWS\SYSTEM32\pemjbnby.dll
2006-11-02 00:38 110612 --a------ C:\WINDOWS\SYSTEM32\jscmbxra.exe
2006-11-02 00:28 60436 --a------ C:\WINDOWS\SYSTEM32\gxxltnwj.dll
2006-11-02 00:28 110612 --a------ C:\WINDOWS\SYSTEM32\cjhoxjad.exe
2006-11-02 00:27 110612 --a------ C:\WINDOWS\SYSTEM32\plsvavxb.exe
2006-11-02 00:26 60436 --a------ C:\WINDOWS\SYSTEM32\joipirgk.dll
2006-11-02 00:26 110612 --a------ C:\WINDOWS\SYSTEM32\udroryce.exe
2006-11-02 00:22 60436 --a------ C:\WINDOWS\SYSTEM32\yuhvqidj.dll
2006-11-02 00:22 60436 --a------ C:\WINDOWS\SYSTEM32\sosbxhfx.dll
2006-11-02 00:22 110612 --a------ C:\WINDOWS\SYSTEM32\hxiephvi.exe
2006-11-01 22:27 60436 --a------ C:\WINDOWS\SYSTEM32\rjjryely.dll
2006-11-01 22:27 110612 --a------ C:\WINDOWS\SYSTEM32\oyraehuu.exe
2006-11-01 22:23 2560 --a------ C:\WINDOWS\_msrstrt.exe
2006-11-01 22:20 60436 --a------ C:\WINDOWS\SYSTEM32\udtewsmy.dll
2006-11-01 22:20 110612 --a------ C:\WINDOWS\SYSTEM32\hwnuqgnt.exe
2006-11-01 20:45 118804 --a------ C:\WINDOWS\SYSTEM32\jsyideju.dll
2006-11-01 19:04 60436 --a------ C:\WINDOWS\SYSTEM32\pdkprjyu.dll
2006-11-01 19:04 110612 --a------ C:\WINDOWS\SYSTEM32\llkoyfql.exe
2006-11-01 17:22 60436 --a------ C:\WINDOWS\SYSTEM32\xyvmaixi.dll
2006-11-01 17:22 110612 --a------ C:\WINDOWS\SYSTEM32\tmixjgue.exe
2006-11-01 16:44 60436 --a------ C:\WINDOWS\SYSTEM32\wuxektws.dll
2006-11-01 16:44 110612 --a------ C:\WINDOWS\SYSTEM32\nwdbcggh.exe
2006-10-31 16:43 60436 --a------ C:\WINDOWS\SYSTEM32\rtiwpvxs.dll
2006-10-31 16:43 110612 --a------ C:\WINDOWS\SYSTEM32\vemmsllt.exe
2006-10-30 16:41 110612 --a------ C:\WINDOWS\SYSTEM32\iutovjyf.exe
2006-10-25 20:46 118804 --a------ C:\WINDOWS\SYSTEM32\odmgpfss.dll
2006-10-24 20:45 118804 --a------ C:\WINDOWS\SYSTEM32\pvhrtkeh.dll

rightontargt4
2007-01-22, 18:12
Annnnd, part 2...

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"PrevxOne"="\"C:\\Program Files\\Prevx1\\PXConsole.exe\""
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"SpybotSnD"="\"C:\\Program Files\\Spybot - Search & Destroy\\SpybotSD.exe\" /autocheck"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
"item"="Ulead Photo Express 4.0 SE Calendar Checker "
"command"="C:\\Program Files\\Ulead Systems\\Ulead Photo Express 4.0 SE\\CalCheck.exe "
"location"="Common Startup"
"path"=""
"backup"=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
"item"="Adobe Gamma Loader.exe"
"command"="C:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe "
"location"="Common Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
"item"="Adobe Gamma Loader"
"command"="C:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe "
"location"="Common Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoUpdate Monitor.lnk]
"item"="AutoUpdate Monitor"
"command"="C:\\Program Files\\Sophos\\AutoUpdate\\ALMon.exe "
"location"="Common Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
"item"="Kodak software updater"
"command"="C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe "
"location"="Common Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
"item"="AIM"
"command"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"item"="Aim6"
"command"="\"C:\\Program Files\\Common Files\\AOL\\Launch\\AOLLaunch.exe\" /d locale=en-US ee://aol/imApp"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AsioReg]
"item"="AsioReg"
"command"="REGSVR32.EXE /S CTASIO.DLL"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDet]
"item"="CTDVDDet"
"command"="C:\\Program Files\\Creative\\SBAudigy2\\DVDAudio\\CTDVDDet.EXE"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
"item"="ctfmon.exe"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
"item"="CTHelper"
"command"="CTHELPER.EXE"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
"item"="CTSysVol"
"command"="C:\\Program Files\\Creative\\SBAudigy2\\Surround Mixer\\CTSysVol.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"item"="DellSupport"
"command"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
"item"="dla"
"command"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"item"="DVDLauncher"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
"item"="HostManager"
"command"="C:\\Program Files\\Common Files\\AOL\\1156393505\\ee\\AOLSoftware.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
"item"="HPDJ Taskbar Utility"
"command"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb06.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
"item"="IntelMeM"
"command"="C:\\Program Files\\Intel\\Modem Event Monitor\\IntelMEM.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
"item"="IPHSend"
"command"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"item"="iTunesHelper"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"item"="MoneyAgent"
"command"="\"C:\\Program Files\\Microsoft Money\\System\\mnyexpr.exe\""
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"item"="MSMSGS"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
"item"="NeroCheck"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"item"="NvCplDaemon"
"command"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"item"="PCMService"
"command"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVModule]
"item"="PVModule"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"item"="QuickTime Task"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"item"="Steam"
"command"="C:\\Valve\\Steam\\Steam.exe -silent"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"item"="SunJavaUpdateSched"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"item"="TkBellExe"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uhvjsul.dll]
"item"="uhvjsul.dll"
"command"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\uhvjsul.dll,mrpmvyf"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
"item"="Ulead AutoDetector"
"command"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UniUploader]
"item"="UniUploader"
"command"="C:\\Program Files\\UniUploader\\UniUploader.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"item"="UpdateManager"
"command"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
"item"="UpdReg"
"command"="C:\\WINDOWS\\UpdReg.EXE"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"item"="WinampAgent"
"command"="C:\\Program Files\\Winamp\\winampa.exe"
"hkey"="HKLM"
"key"="Run"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winqne32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\SAVService

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C]
Shell\AutoRun\command Autorun.exe /s


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\RegCure.job
C:\WINDOWS\tasks\Symantec NetDetect.job

Completion time: 07-01-22 11:09:39

rightontargt4
2007-01-22, 18:13
And that's it! Thanks a lot for all your help by the way, let me know if there's anything I still need to do....like running Spybot again, or having another scan.

Mr_JAk3
2007-01-22, 21:13
Hi again, we'll continue :)
We still have some work to do...

You should print these instructions or save these to a text file. Follow these instructions carefully.

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
Install AVG Anti-Spyware by double clicking the installer.
Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
On the main screen under Your Computer's security.
Click on Change state next to Resident shield. It should now change to inactive.
Click on Change state next to Automatic updates. It should now change to inactive.
Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
Wait until you see the Update succesfull message.
Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates (http://www.ewido.net/en/download/updates/).
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

Disable PrevX realtime protection
Right click on the Prevx icon in your system tray at the bottom-right corner of your screen and choose Show Management Console..
On the Management Console click the Protection Level drop-down menu. You will see three levels:
Maximum
Off
User Defined
Disable all protection by setting the level to Off. You will receive a prompt asking "You are about to change your security settings. Do you wish to continue?" Click Yes.
Click the X on the upper right hand corner to exit the Management console.
Download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1) by Atribune to your desktop.
Do NOT run yet.

Please download the Killbox (http://www.downloads.subratam.org/KillBox.zip).
Unzip it to the desktop but do NOT run it yet.

Make your hidden files visible:
Go to My Computer
Select the Tools menu and click Folder Options
Click the View tab.
Checkmark the "Display the contents of system folders"
Under the Hidden files and folders select "Show hidden files and folders"
Uncheck "Hide protected operating system files"
Click Apply and then the OK and close My Computer.

==================

Open Control Panel -> Add/Remove programs -> Remove all the of the following or similar entries if found:
Pokerstars

and any other programs you didn't install or don't recognize - if your not sure please ask first

Backup your registry:
Start
Run
Type the following to the box and hit Ok: regedit
A window opens, click on File
Choose Export form the menu
Change the save location to C:\
Give the filename, RegBackUp
Make sure that the filetype is set to Registryfiles (*.reg)
Click on Save and Close the window
Open Notepad (NOT WORDPAD!) and copy the following lines from the quote box below into a new document, leaving a blank line at the end. (don't forget to copy and paste the word REGEDIT4) :


REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uhvjsul.dll]



Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

Save the document to your desktop as Fix.reg and filetype: All Files
Go to your desktop and double click on the file to run Fix.reg and when it asks you if you want to merge the contents to the registry, click yes/ok.

Run HijackThis, click Do a system scan only, and check the box next to each of these entries if still present. Close all other windows and press Fix checked. If something isn't there, please continue with the next entry in the list. Fix the O6 entry too if you haven't locked Internet Explorer setings with eg Spybot S&D.
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {278B661A-14A8-D8B0-6AF4-03088B866149} - (no file)
O2 - BHO: (no name) - {3EBED35B-005B-427F-92F0-2D054915144B} - C:\WINDOWS\Microsoft.NET\ndstfp.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: CBHOBJObj Object - {8A406068-D45C-40B9-A096-38AC717FB608} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O20 - Winlogon Notify: winqne32 - winqne32.dll (file missing)

Please run Killbox.

Select "Delete on Reboot".

Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\WINDOWS\SYSTEM32\umehgauf.dll
C:\WINDOWS\SYSTEM32\prdsxqaf.dll
C:\WINDOWS\SYSTEM32\rltoqeio.dll
C:\WINDOWS\SYSTEM32\qsxijhay.dll
C:\WINDOWS\SYSTEM32\oegawvtt.dll
C:\WINDOWS\SYSTEM32\vbbgvdcv.dll
C:\WINDOWS\SYSTEM32\wfkjjgww.dll
C:\WINDOWS\SYSTEM32\rombfcdk.dll
C:\WINDOWS\SYSTEM32\ofunlvpr.dll
C:\WINDOWS\SYSTEM32\gcgcqvim.dll
C:\WINDOWS\SYSTEM32\xyloxeyd.dll
C:\WINDOWS\SYSTEM32\cpljebph.dll
C:\WINDOWS\SYSTEM32\kmsnwfhu.dll
C:\WINDOWS\SYSTEM32\yoalsayc.dll
C:\WINDOWS\SYSTEM32\vymyarhx.dll
C:\WINDOWS\SYSTEM32\yclcifrd.dll
C:\WINDOWS\SYSTEM32\gvtbjdkp.dll
C:\WINDOWS\SYSTEM32\fxcrbpwy.dll
C:\WINDOWS\SYSTEM32\bwqxposk.dll
C:\WINDOWS\SYSTEM32\unqkjcxv.dll
C:\WINDOWS\SYSTEM32\pxhxvmxk.dll
C:\WINDOWS\SYSTEM32\jybyvstt.dll
C:\WINDOWS\SYSTEM32\bnvqmbwj.dll
C:\WINDOWS\SYSTEM32\reuekwsj.dll
C:\WINDOWS\SYSTEM32\vfejoqsd.dll
C:\WINDOWS\SYSTEM32\iqgmtnpc.dll
C:\WINDOWS\SYSTEM32\kbpajxdy.dll
C:\WINDOWS\SYSTEM32\lpsancwc.dll
C:\WINDOWS\SYSTEM32\fqtnlohv.dll
C:\WINDOWS\SYSTEM32\nedapxao.dll
C:\WINDOWS\SYSTEM32\xryrfsfq.dll
C:\WINDOWS\SYSTEM32\mxfldnhc.dll
C:\WINDOWS\SYSTEM32\jhtdbwda.dll
C:\WINDOWS\SYSTEM32\ftuhinsa.exe
C:\WINDOWS\SYSTEM32\rwlsayeh.dll
C:\WINDOWS\SYSTEM32\wwxblckn.exe
C:\WINDOWS\SYSTEM32\rhfrbomh.dll
C:\WINDOWS\SYSTEM32\ohcwkjtg.exe
C:\WINDOWS\SYSTEM32\wvxuvwmp.dll
C:\WINDOWS\SYSTEM32\rcwmicev.exe
C:\WINDOWS\SYSTEM32\islxjxca.dll
C:\WINDOWS\SYSTEM32\lcencpxp.exe
C:\WINDOWS\SYSTEM32\lsrfnfrh.exe
C:\WINDOWS\SYSTEM32\gsgibvmt.dll
C:\WINDOWS\SYSTEM32\rsnhbnve.exe
C:\WINDOWS\SYSTEM32\rftullnm.dll
C:\WINDOWS\SYSTEM32\wyudsohj.dll
C:\WINDOWS\SYSTEM32\fdpriddg.exe
C:\WINDOWS\SYSTEM32\pbeqlvyg.dll
C:\WINDOWS\SYSTEM32\venlkclu.exe
C:\WINDOWS\SYSTEM32\mldaqcsj.dll
C:\WINDOWS\SYSTEM32\npqiafcx.exe
C:\WINDOWS\SYSTEM32\gnglquiw.exe
C:\WINDOWS\SYSTEM32\prelyoab.dll
C:\WINDOWS\SYSTEM32\paejntkv.dll
C:\WINDOWS\SYSTEM32\lumatqkl.dll
C:\WINDOWS\SYSTEM32\plgpbgek.exe
C:\WINDOWS\SYSTEM32\qvtolnfp.dll
C:\WINDOWS\SYSTEM32\phqphvak.dll
C:\WINDOWS\SYSTEM32\xkkhtfqk.exe
C:\WINDOWS\SYSTEM32\xnxtvbbq.dll
C:\WINDOWS\SYSTEM32\uxxmfqck.exe
C:\WINDOWS\SYSTEM32\paulnfgh.dll
C:\WINDOWS\SYSTEM32\hkfpecys.exe
C:\WINDOWS\SYSTEM32\uvfeiosm.dll
C:\WINDOWS\SYSTEM32\apmwjdqm.exe
C:\WINDOWS\SYSTEM32\jmkoegup.dll
C:\WINDOWS\system32\uhvjsul.dll
C:\WINDOWS\SYSTEM32\gcdwvmsy.dll
C:\WINDOWS\SYSTEM32\cnidtffl.exe
C:\WINDOWS\SYSTEM32\jakxhkpj.dll
C:\WINDOWS\SYSTEM32\sxqbouml.exe
C:\WINDOWS\SYSTEM32\pnlgtkqj.dll
C:\WINDOWS\SYSTEM32\vqtsmwiu.exe
C:\WINDOWS\SYSTEM32\whevlcxq.dll
C:\WINDOWS\SYSTEM32\tbpkesyk.exe
C:\WINDOWS\SYSTEM32\ntbckwqr.dll
C:\WINDOWS\SYSTEM32\nspilnve.exe
C:\WINDOWS\SYSTEM32\kbhoifok.dll
C:\WINDOWS\SYSTEM32\qduonhbi.exe
C:\WINDOWS\SYSTEM32\soxitomh.dll
C:\WINDOWS\SYSTEM32\oeimygyk.dll
C:\WINDOWS\SYSTEM32\bqfwvhwc.exe
C:\WINDOWS\SYSTEM32\rkmktnog.dll
C:\WINDOWS\SYSTEM32\oqasfldl.exe
C:\WINDOWS\SYSTEM32\andvujpg.dll
C:\WINDOWS\SYSTEM32\dihanohp.dll
C:\WINDOWS\SYSTEM32\baetlbeh.exe
C:\WINDOWS\SYSTEM32\nyyjhkjq.dll
C:\WINDOWS\SYSTEM32\xsvvcqms.exe
C:\WINDOWS\SYSTEM32\genuqxmj.dll
C:\WINDOWS\SYSTEM32\qdrasogi.exe
C:\WINDOWS\SYSTEM32\cxglejes.dll
C:\WINDOWS\SYSTEM32\sdawniau.exe
C:\WINDOWS\SYSTEM32\pemjbnby.dll
C:\WINDOWS\SYSTEM32\jscmbxra.exe
C:\WINDOWS\SYSTEM32\gxxltnwj.dll
C:\WINDOWS\SYSTEM32\cjhoxjad.exe
C:\WINDOWS\SYSTEM32\plsvavxb.exe
C:\WINDOWS\SYSTEM32\joipirgk.dll
C:\WINDOWS\SYSTEM32\udroryce.exe
C:\WINDOWS\SYSTEM32\yuhvqidj.dll
C:\WINDOWS\SYSTEM32\sosbxhfx.dll
C:\WINDOWS\SYSTEM32\hxiephvi.exe
C:\WINDOWS\SYSTEM32\rjjryely.dll
C:\WINDOWS\SYSTEM32\oyraehuu.exe
C:\WINDOWS\SYSTEM32\udtewsmy.dll
C:\WINDOWS\SYSTEM32\hwnuqgnt.exe
C:\WINDOWS\SYSTEM32\jsyideju.dll
C:\WINDOWS\SYSTEM32\pdkprjyu.dll
C:\WINDOWS\SYSTEM32\llkoyfql.exe
C:\WINDOWS\SYSTEM32\xyvmaixi.dll
C:\WINDOWS\SYSTEM32\tmixjgue.exe
C:\WINDOWS\SYSTEM32\wuxektws.dll
C:\WINDOWS\SYSTEM32\nwdbcggh.exe
C:\WINDOWS\SYSTEM32\rtiwpvxs.dll
C:\WINDOWS\SYSTEM32\vemmsllt.exe
C:\WINDOWS\SYSTEM32\iutovjyf.exe
C:\WINDOWS\SYSTEM32\odmgpfss.dll
C:\WINDOWS\SYSTEM32\pvhrtkeh.dll
Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

Select "All Files".

Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually.

Restart your computer to the safe mode:
Restart your computer
Start tapping the F8 key when the computer restarts.
When the start menu opens, choose Safe mode
Press Enter. The computer then begins to start in Safe mode.

Go to the My Computer and delete the following folders (if present):
C:\Program Files\pokerstars
C:\Program Files\yopza

Run ATF Cleaner Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
Click on Scanner on the toolbar.
Click on the Settings tab.
Under How to act?
Click on Recommended Action and choose Quarantine from the popup menu.
Under How to scan?
All checkboxes should be ticked.
Under Possibly unwanted software:
All checkboxes should be ticked.
Under Reports:
Select Automatically generate report after every scan and uncheck Only if threats were found.
Under What to scan?
Select Scan every file.
Click on the Scan tab.
Click on Complete System Scan to start the scan process.
Let the program scan the machine.
When the scan has finished, follow the instructions below.
IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
At the bottom of the window click on the Apply all Actions button. (3)
http://img509.imageshack.us/img509/4851/scanavgjk2.jpg
When done, click the Save Scan Report button. (4)
Click the Save Report as button.
Save the report to your Desktop.
Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.

================

When you're ready, please post the following logs to here:
- AVG's report
- a fresh HijackThis log

rightontargt4
2007-01-23, 02:36
Allllllllrighty. After a long and arduous process....lol. Here we go.

AVG Report says:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 5:54:29 PM 1/22/2007

+ Scan result:



C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP875\A0201148.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP813\A0189077.DLL -> Adware.MyWaySpeed : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\P2P Networking v126.cpl -> Adware.P2PNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP811\A0187992.dll -> Adware.PrintView : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP874\A0201105.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
C:\VundoFix Backups\ncfmlbjq.exe.bad -> Adware.Searchcolor : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\nvnhmydm.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
HKU\S-1-5-21-4185800433-3889453624-4194486670-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8A406068-D45C-40B9-A096-38AC717FB608} -> Adware.WebDir : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\!KillBox\andvujpg.dll -> Adware.Winfixer : Cleaned with backup (quarantined).
C:\!KillBox\jsyideju.dll -> Adware.Winfixer : Cleaned with backup (quarantined).
C:\!KillBox\odmgpfss.dll -> Adware.Winfixer : Cleaned with backup (quarantined).
C:\!KillBox\oeimygyk.dll -> Adware.Winfixer : Cleaned with backup (quarantined).
C:\!KillBox\pvhrtkeh.dll -> Adware.Winfixer : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\andvujpg.dll -> Adware.Winfixer : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\jsyideju.dll -> Adware.Winfixer : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\odmgpfss.dll -> Adware.Winfixer : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\oeimygyk.dll -> Adware.Winfixer : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\pvhrtkeh.dll -> Adware.Winfixer : Cleaned with backup (quarantined).
C:\Program Files\Common Files\ukmu\ukmud\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined).
C:\Documents and Settings\Ryan Littlefield\Application Data\Earthlink\6.0\compboy7@earthlink.net\Cookies\ryan littlefield@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Ryan Littlefield\Application Data\Earthlink\6.0\compboy7@earthlink.net\Cookies\ryan littlefield@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Ryan Littlefield\Application Data\Earthlink\6.0\compboy7@earthlink.net\Cookies\ryan littlefield@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Ryan Littlefield\Application Data\Earthlink\6.0\compboy7@earthlink.net\Cookies\ryan littlefield@ads.euniverseads[1].txt -> TrackingCookie.Euniverseads : Cleaned.
C:\Documents and Settings\Ryan Littlefield\Application Data\Earthlink\6.0\compboy7@earthlink.net\Cookies\ryan littlefield@sales.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP838\A0192599.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP839\A0192606.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP840\A0192612.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP841\A0192623.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP842\A0192632.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP843\A0192640.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP844\A0192645.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP871\A0199079.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP873\A0201088.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP874\A0201093.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\!KillBox\cxglejes.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\dihanohp.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\gcdwvmsy.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\genuqxmj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\gsgibvmt.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\gxxltnwj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\islxjxca.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\jakxhkpj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\jmkoegup.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\joipirgk.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\kbhoifok.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\lumatqkl.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\mldaqcsj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\ntbckwqr.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\nyyjhkjq.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\paejntkv.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\paulnfgh.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\pbeqlvyg.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\pdkprjyu.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\pemjbnby.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\phqphvak.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\pnlgtkqj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\prelyoab.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\qvtolnfp.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\rftullnm.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\rhfrbomh.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\rjjryely.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\rkmktnog.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\rtiwpvxs.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\rwlsayeh.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\sosbxhfx.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\soxitomh.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\udtewsmy.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\uvfeiosm.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\whevlcxq.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\wuxektws.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\wvxuvwmp.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\wyudsohj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\xnxtvbbq.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\xyvmaixi.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\!KillBox\yuhvqidj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\cxglejes.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\dihanohp.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\gcdwvmsy.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\genuqxmj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\gsgibvmt.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\gxxltnwj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\islxjxca.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\jakxhkpj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\jmkoegup.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\joipirgk.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\kbhoifok.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\lumatqkl.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\mldaqcsj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\ntbckwqr.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\nyyjhkjq.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\paejntkv.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\paulnfgh.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\pbeqlvyg.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\pdkprjyu.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\pemjbnby.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\phqphvak.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\pnlgtkqj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\prelyoab.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\qvtolnfp.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\rftullnm.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\rhfrbomh.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\rjjryely.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\rkmktnog.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\rtiwpvxs.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\rwlsayeh.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\sosbxhfx.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\soxitomh.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\udtewsmy.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\uvfeiosm.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\whevlcxq.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\wuxektws.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\wvxuvwmp.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\wyudsohj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\xnxtvbbq.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\xyvmaixi.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\yuhvqidj.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP813\A0189007.vbs -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP874\A0201095.dll -> Trojan.Small : Cleaned with backup (quarantined).
C:\VundoFix Backups\services.dll.bad -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\UnlhbiBMaXR0bGVmaWVsZA\oB51v21gurlXv3pAuqpPtE.vbs -> Trojan.Small : Cleaned with backup (quarantined).


::Report end

rightontargt4
2007-01-23, 02:37
Here's our HijackThis log.

Logfile of HijackThis v1.99.1
Scan saved at 7:37:43 PM, on 1/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ryan Littlefield\My Documents\HijackThis\Scanner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\SYSTEM32\HDBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156107684015
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures06.aim.com/ygp/aol/plugin/upf/AOLUPF.en-US-AIM.9.5.1.8.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {AD08A333-609E-11D3-950C-008098601567} - http://wordreference.com/Install/English%20to%20Spanish.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

rightontargt4
2007-01-23, 02:38
By the way, I ran Spybot again, and it was able to take care of the Command Service thing. Anything else in either of those reports that looks malicious in any way?

Mr_JAk3
2007-01-23, 12:19
Hi :)

We're almost there...

PLease delete the following folder if found:
C:\WINDOWS\UnlhbiBMaXR0bGVmaWVsZA

Then please run ComboFix again and post it's log to here one more time :bigthumb:

rightontargt4
2007-01-23, 16:42
Okie dokie.. Part 1.

"Ryan Littlefield" - 07-01-23 9:24:22 Service Pack 2
ComboFix 07-01-21 - Running from: "C:\Documents and Settings\Ryan Littlefield\My Documents"

((((((((((((((((((((((((((((((( Files Created from 2006-12-23 to 2007-01-23 ))))))))))))))))))))))))))))))))))


2007-01-22 15:41 <DIR> d-------- C:\!KillBox
2007-01-22 15:32 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-01-22 15:32 <DIR> d-------- C:\Program Files\Grisoft
2007-01-22 15:29 98,374,194 --a------ C:\RegBackUp.reg
2007-01-22 01:53 <DIR> d-------- C:\Program Files\UBT
2007-01-21 23:33 <DIR> d-------- C:\VundoFix Backups
2007-01-21 20:42 44,060 --------- C:\WINDOWS\SYSTEM32\umehgauf.dll
2007-01-20 20:43 76,412 --------- C:\WINDOWS\SYSTEM32\prdsxqaf.dll
2007-01-20 20:42 44,060 --------- C:\WINDOWS\SYSTEM32\rltoqeio.dll
2007-01-19 20:42 44,060 --------- C:\WINDOWS\SYSTEM32\qsxijhay.dll
2007-01-19 00:03 28,672 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\CO_Mon.sys
2007-01-18 20:42 76,412 --------- C:\WINDOWS\SYSTEM32\oegawvtt.dll
2007-01-18 20:42 44,060 --------- C:\WINDOWS\SYSTEM32\vbbgvdcv.dll
2007-01-18 10:43 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2007-01-17 20:42 44,060 --------- C:\WINDOWS\SYSTEM32\wfkjjgww.dll
2007-01-16 20:42 76,412 --------- C:\WINDOWS\SYSTEM32\rombfcdk.dll
2007-01-16 20:42 44,060 --------- C:\WINDOWS\SYSTEM32\ofunlvpr.dll
2007-01-16 15:35 <DIR> d-------- C:\WINDOWS\ie7updates
2007-01-16 12:45 15,872 --------- C:\WINDOWS\SYSTEM32\sophosboottasks.exe
2007-01-16 12:45 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-23 09:19 -------- d-------- C:\Program Files\mozilla firefox
2007-01-22 19:22 -------- d-------- C:\Program Files\prevx1
2007-01-18 15:36 -------- d-------- C:\DOCUME~1\RYANLI~1\Application Data\prevx
2007-01-18 12:21 -------- d-------- C:\Program Files\itunes
2007-01-18 12:13 -------- d-------- C:\Program Files\aim
2007-01-16 21:34 -------- d-------- C:\DOCUME~1\RYANLI~1\Application Data\u3
2007-01-16 18:54 -------- d-------- C:\Program Files\world of warcraft
2006-12-15 20:24 13952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxrd.sys
2006-12-15 10:35 42516 --------- C:\WINDOWS\SYSTEM32\gcgcqvim.dll
2006-12-15 10:35 126996 --------- C:\WINDOWS\SYSTEM32\xyloxeyd.dll
2006-12-14 10:35 42516 --------- C:\WINDOWS\SYSTEM32\cpljebph.dll
2006-12-13 10:34 42516 --------- C:\WINDOWS\SYSTEM32\kmsnwfhu.dll
2006-12-12 10:34 42516 --------- C:\WINDOWS\SYSTEM32\yoalsayc.dll
2006-12-12 10:34 42516 --------- C:\WINDOWS\SYSTEM32\vymyarhx.dll
2006-12-11 10:34 42516 --------- C:\WINDOWS\SYSTEM32\yclcifrd.dll
2006-12-10 10:33 42516 --------- C:\WINDOWS\SYSTEM32\gvtbjdkp.dll
2006-12-09 10:33 42516 --------- C:\WINDOWS\SYSTEM32\fxcrbpwy.dll
2006-12-08 13:36 7552 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxcom.sys
2006-12-08 13:36 274688 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxfsf.sys
2006-12-08 13:36 18560 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxtdi.sys
2006-12-08 13:36 11648 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxscrmbl.sys
2006-12-08 13:36 100864 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\PxEmu.sys
2006-12-08 10:33 42516 --------- C:\WINDOWS\SYSTEM32\bwqxposk.dll
2006-12-08 09:32 42516 --------- C:\WINDOWS\SYSTEM32\unqkjcxv.dll
2006-12-07 09:32 42516 --------- C:\WINDOWS\SYSTEM32\pxhxvmxk.dll
2006-12-07 09:31 42516 --------- C:\WINDOWS\SYSTEM32\jybyvstt.dll
2006-12-07 00:29 2374472 --a------ C:\WINDOWS\SYSTEM32\wmvcore.dll
2006-12-06 09:31 42516 --------- C:\WINDOWS\SYSTEM32\bnvqmbwj.dll
2006-12-05 09:46 42516 --------- C:\WINDOWS\SYSTEM32\reuekwsj.dll
2006-12-04 11:10 42516 --------- C:\WINDOWS\SYSTEM32\vfejoqsd.dll
2006-12-03 11:10 42516 --------- C:\WINDOWS\SYSTEM32\iqgmtnpc.dll
2006-12-02 11:10 42516 --------- C:\WINDOWS\SYSTEM32\kbpajxdy.dll
2006-12-01 11:10 42516 --------- C:\WINDOWS\SYSTEM32\lpsancwc.dll
2006-11-30 16:00 42516 --------- C:\WINDOWS\SYSTEM32\fqtnlohv.dll
2006-11-29 16:00 42516 --------- C:\WINDOWS\SYSTEM32\nedapxao.dll
2006-11-29 15:03 42516 --------- C:\WINDOWS\SYSTEM32\xryrfsfq.dll
2006-11-28 15:03 42516 --------- C:\WINDOWS\SYSTEM32\mxfldnhc.dll
2006-11-27 15:02 42516 -----c--- C:\WINDOWS\SYSTEM32\jhtdbwda.dll
2006-11-26 15:01 110612 --------- C:\WINDOWS\SYSTEM32\ftuhinsa.exe
2006-11-17 11:27 110612 --------- C:\WINDOWS\SYSTEM32\wwxblckn.exe
2006-11-16 11:27 110612 --------- C:\WINDOWS\SYSTEM32\ohcwkjtg.exe
2006-11-15 11:27 110612 --------- C:\WINDOWS\SYSTEM32\rcwmicev.exe
2006-11-14 11:26 110612 --------- C:\WINDOWS\SYSTEM32\lcencpxp.exe
2006-11-13 11:27 110612 --------- C:\WINDOWS\SYSTEM32\lsrfnfrh.exe
2006-11-13 11:26 110612 --------- C:\WINDOWS\SYSTEM32\rsnhbnve.exe
2006-11-12 11:25 110612 --------- C:\WINDOWS\SYSTEM32\fdpriddg.exe
2006-11-11 11:25 110612 --------- C:\WINDOWS\SYSTEM32\venlkclu.exe
2006-11-10 11:25 110612 --------- C:\WINDOWS\SYSTEM32\npqiafcx.exe
2006-11-09 11:25 110612 --------- C:\WINDOWS\SYSTEM32\gnglquiw.exe
2006-11-09 00:23 110612 --------- C:\WINDOWS\SYSTEM32\plgpbgek.exe
2006-11-08 22:22 110612 --------- C:\WINDOWS\SYSTEM32\xkkhtfqk.exe
2006-11-08 17:35 110612 --------- C:\WINDOWS\SYSTEM32\uxxmfqck.exe
2006-11-08 17:33 110612 --------- C:\WINDOWS\SYSTEM32\hkfpecys.exe
2006-11-08 00:06 679424 --a------ C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-11-07 22:27 110612 --------- C:\WINDOWS\SYSTEM32\apmwjdqm.exe
2006-11-07 21:03 6049280 --------- C:\WINDOWS\SYSTEM32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\SYSTEM32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\SYSTEM32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\SYSTEM32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\SYSTEM32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\SYSTEM32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\SYSTEM32\msls31.dll
2006-11-07 16:38 110612 --------- C:\WINDOWS\SYSTEM32\cnidtffl.exe
2006-11-07 03:27 382976 --a------ C:\WINDOWS\SYSTEM32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\SYSTEM32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\SYSTEM32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\SYSTEM32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\SYSTEM32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\SYSTEM32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\SYSTEM32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\SYSTEM32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\SYSTEM32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\SYSTEM32\ieakui.dll
2006-11-06 18:44 110612 --------- C:\WINDOWS\SYSTEM32\sxqbouml.exe
2006-11-05 18:42 110612 --------- C:\WINDOWS\SYSTEM32\vqtsmwiu.exe
2006-11-05 18:40 110612 --------- C:\WINDOWS\SYSTEM32\tbpkesyk.exe
2006-11-04 18:39 110612 --------- C:\WINDOWS\SYSTEM32\nspilnve.exe
2006-11-04 15:58 110612 --------- C:\WINDOWS\SYSTEM32\qduonhbi.exe
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\SYSTEM32\msxml4.dll
2006-11-04 10:34 110612 --------- C:\WINDOWS\SYSTEM32\bqfwvhwc.exe
2006-11-04 09:32 110612 --------- C:\WINDOWS\SYSTEM32\oqasfldl.exe
2006-11-03 09:31 110612 --------- C:\WINDOWS\SYSTEM32\baetlbeh.exe
2006-11-03 08:30 110612 --------- C:\WINDOWS\SYSTEM32\xsvvcqms.exe
2006-11-03 00:49 110612 --------- C:\WINDOWS\SYSTEM32\qdrasogi.exe
2006-11-02 00:47 110612 --------- C:\WINDOWS\SYSTEM32\sdawniau.exe
2006-11-02 00:38 110612 --------- C:\WINDOWS\SYSTEM32\jscmbxra.exe
2006-11-02 00:28 110612 --------- C:\WINDOWS\SYSTEM32\cjhoxjad.exe
2006-11-02 00:27 110612 --------- C:\WINDOWS\SYSTEM32\plsvavxb.exe
2006-11-02 00:26 110612 --------- C:\WINDOWS\SYSTEM32\udroryce.exe
2006-11-02 00:22 110612 --------- C:\WINDOWS\SYSTEM32\hxiephvi.exe
2006-11-01 22:27 110612 --------- C:\WINDOWS\SYSTEM32\oyraehuu.exe
2006-11-01 22:23 2560 --a------ C:\WINDOWS\_msrstrt.exe
2006-11-01 22:20 110612 --------- C:\WINDOWS\SYSTEM32\hwnuqgnt.exe
2006-11-01 19:04 110612 --------- C:\WINDOWS\SYSTEM32\llkoyfql.exe
2006-11-01 17:22 110612 --------- C:\WINDOWS\SYSTEM32\tmixjgue.exe
2006-11-01 16:44 110612 --------- C:\WINDOWS\SYSTEM32\nwdbcggh.exe
2006-10-31 16:43 110612 --------- C:\WINDOWS\SYSTEM32\vemmsllt.exe
2006-10-30 16:41 110612 --------- C:\WINDOWS\SYSTEM32\iutovjyf.exe

rightontargt4
2007-01-23, 16:43
And Part 2....

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"PrevxOne"="\"C:\\Program Files\\Prevx1\\PXConsole.exe\""
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
"item"="Ulead Photo Express 4.0 SE Calendar Checker "
"command"="C:\\Program Files\\Ulead Systems\\Ulead Photo Express 4.0 SE\\CalCheck.exe "
"location"="Common Startup"
"path"=""
"backup"=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
"item"="Adobe Gamma Loader.exe"
"command"="C:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe "
"location"="Common Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
"item"="Adobe Gamma Loader"
"command"="C:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe "
"location"="Common Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoUpdate Monitor.lnk]
"item"="AutoUpdate Monitor"
"command"="C:\\Program Files\\Sophos\\AutoUpdate\\ALMon.exe "
"location"="Common Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
"item"="Kodak software updater"
"command"="C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe "
"location"="Common Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
"item"="AIM"
"command"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"item"="Aim6"
"command"="\"C:\\Program Files\\Common Files\\AOL\\Launch\\AOLLaunch.exe\" /d locale=en-US ee://aol/imApp"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AsioReg]
"item"="AsioReg"
"command"="REGSVR32.EXE /S CTASIO.DLL"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDet]
"item"="CTDVDDet"
"command"="C:\\Program Files\\Creative\\SBAudigy2\\DVDAudio\\CTDVDDet.EXE"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
"item"="ctfmon.exe"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
"item"="CTHelper"
"command"="CTHELPER.EXE"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
"item"="CTSysVol"
"command"="C:\\Program Files\\Creative\\SBAudigy2\\Surround Mixer\\CTSysVol.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"item"="DellSupport"
"command"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
"item"="dla"
"command"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"item"="DVDLauncher"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
"item"="HostManager"
"command"="C:\\Program Files\\Common Files\\AOL\\1156393505\\ee\\AOLSoftware.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
"item"="HPDJ Taskbar Utility"
"command"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb06.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
"item"="IntelMeM"
"command"="C:\\Program Files\\Intel\\Modem Event Monitor\\IntelMEM.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
"item"="IPHSend"
"command"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"item"="iTunesHelper"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"item"="MoneyAgent"
"command"="\"C:\\Program Files\\Microsoft Money\\System\\mnyexpr.exe\""
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"item"="MSMSGS"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
"item"="NeroCheck"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"item"="NvCplDaemon"
"command"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"item"="PCMService"
"command"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVModule]
"item"="PVModule"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"item"="QuickTime Task"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"item"="Steam"
"command"="C:\\Valve\\Steam\\Steam.exe -silent"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"item"="SunJavaUpdateSched"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"item"="TkBellExe"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
"item"="Ulead AutoDetector"
"command"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UniUploader]
"item"="UniUploader"
"command"="C:\\Program Files\\UniUploader\\UniUploader.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"item"="UpdateManager"
"command"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
"item"="UpdReg"
"command"="C:\\WINDOWS\\UpdReg.EXE"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"item"="WinampAgent"
"command"="C:\\Program Files\\Winamp\\winampa.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\SAVService

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_AVGASCLN


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\RegCure.job
C:\WINDOWS\tasks\Symantec NetDetect.job

Completion time: 07-01-23 9:29:52
C:\ComboFix2.txt ... 07-01-22 11:09

rightontargt4
2007-01-23, 16:46
Oops, forgot to tell you, I deleted the aforementioned folder.

Mr_JAk3
2007-01-24, 16:00
Hi again, we'll continue :)
Some of the files just didn't want to die...so let's try again

You should print these instructions or save these to a text file. Follow these instructions carefully.

Restart your computer to the safe mode:
Restart your computer
Start tapping the F8 key when the computer restarts.
When the start menu opens, choose Safe mode
Press Enter. The computer then begins to start in Safe mode.Please run Killbox.

Select "Delete on Reboot".

Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\WINDOWS\SYSTEM32\umehgauf.dll
C:\WINDOWS\SYSTEM32\prdsxqaf.dll
C:\WINDOWS\SYSTEM32\rltoqeio.dll
C:\WINDOWS\SYSTEM32\qsxijhay.dll
C:\WINDOWS\SYSTEM32\oegawvtt.dll
C:\WINDOWS\SYSTEM32\vbbgvdcv.dll
C:\WINDOWS\SYSTEM32\wfkjjgww.dll
C:\WINDOWS\SYSTEM32\rombfcdk.dll
C:\WINDOWS\SYSTEM32\ofunlvpr.dll
C:\WINDOWS\SYSTEM32\gcgcqvim.dll
C:\WINDOWS\SYSTEM32\xyloxeyd.dll
C:\WINDOWS\SYSTEM32\cpljebph.dll
C:\WINDOWS\SYSTEM32\kmsnwfhu.dll
C:\WINDOWS\SYSTEM32\yoalsayc.dll
C:\WINDOWS\SYSTEM32\vymyarhx.dll
C:\WINDOWS\SYSTEM32\yclcifrd.dll
C:\WINDOWS\SYSTEM32\gvtbjdkp.dll
C:\WINDOWS\SYSTEM32\fxcrbpwy.dll
C:\WINDOWS\SYSTEM32\bwqxposk.dll
C:\WINDOWS\SYSTEM32\unqkjcxv.dll
C:\WINDOWS\SYSTEM32\pxhxvmxk.dll
C:\WINDOWS\SYSTEM32\jybyvstt.dll
C:\WINDOWS\SYSTEM32\bnvqmbwj.dll
C:\WINDOWS\SYSTEM32\reuekwsj.dll
C:\WINDOWS\SYSTEM32\vfejoqsd.dll
C:\WINDOWS\SYSTEM32\iqgmtnpc.dll
C:\WINDOWS\SYSTEM32\kbpajxdy.dll
C:\WINDOWS\SYSTEM32\lpsancwc.dll
C:\WINDOWS\SYSTEM32\fqtnlohv.dll
C:\WINDOWS\SYSTEM32\nedapxao.dll
C:\WINDOWS\SYSTEM32\xryrfsfq.dll
C:\WINDOWS\SYSTEM32\mxfldnhc.dll
C:\WINDOWS\SYSTEM32\jhtdbwda.dll
C:\WINDOWS\SYSTEM32\ftuhinsa.exe
C:\WINDOWS\SYSTEM32\wwxblckn.exe
C:\WINDOWS\SYSTEM32\ohcwkjtg.exe
C:\WINDOWS\SYSTEM32\rcwmicev.exe
C:\WINDOWS\SYSTEM32\lcencpxp.exe
C:\WINDOWS\SYSTEM32\lsrfnfrh.exe
C:\WINDOWS\SYSTEM32\rsnhbnve.exe
C:\WINDOWS\SYSTEM32\fdpriddg.exe
C:\WINDOWS\SYSTEM32\venlkclu.exe
C:\WINDOWS\SYSTEM32\npqiafcx.exe
C:\WINDOWS\SYSTEM32\gnglquiw.exe
C:\WINDOWS\SYSTEM32\plgpbgek.exe
C:\WINDOWS\SYSTEM32\xkkhtfqk.exe
C:\WINDOWS\SYSTEM32\uxxmfqck.exe
C:\WINDOWS\SYSTEM32\hkfpecys.exe
C:\WINDOWS\SYSTEM32\apmwjdqm.exe
C:\WINDOWS\SYSTEM32\cnidtffl.exe
C:\WINDOWS\SYSTEM32\sxqbouml.exe
C:\WINDOWS\SYSTEM32\vqtsmwiu.exe
C:\WINDOWS\SYSTEM32\tbpkesyk.exe
C:\WINDOWS\SYSTEM32\nspilnve.exe
C:\WINDOWS\SYSTEM32\qduonhbi.exe
C:\WINDOWS\SYSTEM32\bqfwvhwc.exe
C:\WINDOWS\SYSTEM32\oqasfldl.exe
C:\WINDOWS\SYSTEM32\baetlbeh.exe
C:\WINDOWS\SYSTEM32\xsvvcqms.exe
C:\WINDOWS\SYSTEM32\qdrasogi.exe
C:\WINDOWS\SYSTEM32\sdawniau.exe
C:\WINDOWS\SYSTEM32\jscmbxra.exe
C:\WINDOWS\SYSTEM32\cjhoxjad.exe
C:\WINDOWS\SYSTEM32\plsvavxb.exe
C:\WINDOWS\SYSTEM32\udroryce.exe
C:\WINDOWS\SYSTEM32\hxiephvi.exe
C:\WINDOWS\SYSTEM32\oyraehuu.exe
C:\WINDOWS\SYSTEM32\hwnuqgnt.exe
C:\WINDOWS\SYSTEM32\llkoyfql.exe
C:\WINDOWS\SYSTEM32\tmixjgue.exe
C:\WINDOWS\SYSTEM32\nwdbcggh.exe
C:\WINDOWS\SYSTEM32\vemmsllt.exe
C:\WINDOWS\SYSTEM32\iutovjyf.exe
Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

Select "All Files".

Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually.

Run ComboFix again and post it's log.

rightontargt4
2007-01-25, 08:09
Alright, did what you told me, here we go.
ComboFix log:

"Ryan Littlefield" - 07-01-25 1:03:09 Service Pack 2
ComboFix 07-01-21 - Running from: "C:\Documents and Settings\Ryan Littlefield\My Documents"

((((((((((((((((((((((((((((((( Files Created from 2006-12-25 to 2007-01-25 ))))))))))))))))))))))))))))))))))


2007-01-24 00:24 <DIR> d-------- C:\Program Files\Infinite Crosswords - USA Today 1
2007-01-24 00:24 <DIR> d-------- C:\Program Files\Infinite Crosswords - LA Times 1
2007-01-24 00:24 <DIR> d-------- C:\Program Files\Infinite Crosswords
2007-01-22 15:41 <DIR> d-------- C:\!KillBox
2007-01-22 15:32 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-01-22 15:32 <DIR> d-------- C:\Program Files\Grisoft
2007-01-22 15:29 98,374,194 --a------ C:\RegBackUp.reg
2007-01-22 01:53 <DIR> d-------- C:\Program Files\UBT
2007-01-21 23:33 <DIR> d-------- C:\VundoFix Backups
2007-01-19 00:03 28,672 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\CO_Mon.sys
2007-01-18 10:43 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2007-01-16 15:35 <DIR> d-------- C:\WINDOWS\ie7updates
2007-01-16 12:45 15,872 --------- C:\WINDOWS\SYSTEM32\sophosboottasks.exe
2007-01-16 12:45 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-25 01:02 -------- d-------- C:\Program Files\mozilla firefox
2007-01-24 16:17 -------- d-------- C:\Program Files\world of warcraft
2007-01-23 19:59 -------- d-------- C:\Program Files\quicktime
2007-01-22 19:22 -------- d-------- C:\Program Files\prevx1
2007-01-18 15:36 -------- d-------- C:\DOCUME~1\RYANLI~1\Application Data\prevx
2007-01-18 12:21 -------- d-------- C:\Program Files\itunes
2007-01-18 12:13 -------- d-------- C:\Program Files\aim
2007-01-16 21:34 -------- d-------- C:\DOCUME~1\RYANLI~1\Application Data\u3
2006-12-15 20:24 13952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxrd.sys
2006-12-08 13:36 7552 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxcom.sys
2006-12-08 13:36 274688 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxfsf.sys
2006-12-08 13:36 18560 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxtdi.sys
2006-12-08 13:36 11648 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxscrmbl.sys
2006-12-08 13:36 100864 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\PxEmu.sys
2006-12-07 00:29 2374472 --a------ C:\WINDOWS\SYSTEM32\wmvcore.dll
2006-11-08 00:06 679424 --a------ C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-11-07 21:03 6049280 --------- C:\WINDOWS\SYSTEM32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\SYSTEM32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\SYSTEM32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\SYSTEM32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\SYSTEM32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\SYSTEM32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\SYSTEM32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\SYSTEM32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\SYSTEM32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\SYSTEM32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\SYSTEM32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\SYSTEM32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\SYSTEM32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\SYSTEM32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\SYSTEM32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\SYSTEM32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\SYSTEM32\ieakui.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\SYSTEM32\msxml4.dll
2006-11-01 22:23 2560 --a------ C:\WINDOWS\_msrstrt.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"PrevxOne"="\"C:\\Program Files\\Prevx1\\PXConsole.exe\""
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
"item"="Ulead Photo Express 4.0 SE Calendar Checker "
"command"="C:\\Program Files\\Ulead Systems\\Ulead Photo Express 4.0 SE\\CalCheck.exe "
"location"="Common Startup"
"path"=""
"backup"=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
"item"="Adobe Gamma Loader.exe"
"command"="C:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe "
"location"="Common Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
"item"="Adobe Gamma Loader"
"command"="C:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe "
"location"="Common Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoUpdate Monitor.lnk]
"item"="AutoUpdate Monitor"
"command"="C:\\Program Files\\Sophos\\AutoUpdate\\ALMon.exe "
"location"="Common Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
"item"="Kodak software updater"
"command"="C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe "
"location"="Common Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
"item"="AIM"
"command"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"item"="Aim6"
"command"="\"C:\\Program Files\\Common Files\\AOL\\Launch\\AOLLaunch.exe\" /d locale=en-US ee://aol/imApp"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AsioReg]
"item"="AsioReg"
"command"="REGSVR32.EXE /S CTASIO.DLL"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDet]
"item"="CTDVDDet"
"command"="C:\\Program Files\\Creative\\SBAudigy2\\DVDAudio\\CTDVDDet.EXE"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
"item"="ctfmon.exe"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
"item"="CTHelper"
"command"="CTHELPER.EXE"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
"item"="CTSysVol"
"command"="C:\\Program Files\\Creative\\SBAudigy2\\Surround Mixer\\CTSysVol.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"item"="DellSupport"
"command"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
"item"="dla"
"command"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"item"="DVDLauncher"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
"item"="HostManager"
"command"="C:\\Program Files\\Common Files\\AOL\\1156393505\\ee\\AOLSoftware.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
"item"="HPDJ Taskbar Utility"
"command"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb06.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
"item"="IntelMeM"
"command"="C:\\Program Files\\Intel\\Modem Event Monitor\\IntelMEM.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
"item"="IPHSend"
"command"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"item"="iTunesHelper"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"item"="MoneyAgent"
"command"="\"C:\\Program Files\\Microsoft Money\\System\\mnyexpr.exe\""
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"item"="MSMSGS"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
"item"="NeroCheck"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"item"="NvCplDaemon"
"command"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"item"="PCMService"
"command"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVModule]
"item"="PVModule"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"item"="QuickTime Task"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"item"="Steam"
"command"="C:\\Valve\\Steam\\Steam.exe -silent"
"hkey"="HKEY"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"item"="SunJavaUpdateSched"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"item"="TkBellExe"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
"item"="Ulead AutoDetector"
"command"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UniUploader]
"item"="UniUploader"
"command"="C:\\Program Files\\UniUploader\\UniUploader.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"item"="UpdateManager"
"command"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
"item"="UpdReg"
"command"="C:\\WINDOWS\\UpdReg.EXE"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"item"="WinampAgent"
"command"="C:\\Program Files\\Winamp\\winampa.exe"
"hkey"="HKLM"
"key"="Run"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\SAVService

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\RegCure.job
C:\WINDOWS\tasks\Symantec NetDetect.job

Completion time: 07-01-25 1:08:37
C:\ComboFix2.txt ... 07-01-23 09:29
C:\ComboFix3.txt ... 07-01-22 11:09

Mr_JAk3
2007-01-25, 13:53
Hi again, it is looking clean now :)

You don't seem to a firewall (http://forum.malwareremoval.com/viewtopic.php?p=56#56) running, you must install one firewall.
NOTE: If you're using Windows XP firewall, I recommend that you install a more advanced firewall. Windows firewall doesn't really provide enough protection.
Disable Windows firewall after installing a new firewall.

These are good (free) firewalls: Sunbelt-Kerio (http://www.sunbelt-software.com/Kerio.cfm)
ZoneAlarm (http://www.zonelabs.com/)
Sygate (http://http://www.majorgeeks.com/download.php?det=3356)
Outpost (http://www.majorgeeks.com/download.php?det=1056)

Now you can enable PrevX protection again.

Now you can clean AVG's Quarantine:
Open AVG Anti-Spyware
Click Infections
Click Quarantine tab
Click Select all
Click Remove finally
Close the program
You can remove the tools we used. You may delete the following backup folder; C:\!Killbox

Then you should update your Java to the latest version (6.0) Start
Control Panel
Add/Remove Programs
Delete the old Java, J2SE Runtime Environment 5.0 Update 6
Download the latest version of Java Runtime Environment (JRE) 6.0 (http://java.sun.com/javase/downloads/index.jsp).
Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications."
Click the "Download" button to the right.
Check the box that says: "Accept License Agreement."
The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Install it

Now you can make your hidden files hidden again.
Go to My Computer
Select the Tools menu and click Folder Options
Click the View tab.
Checkmark the "Display the contents of system folders"
Under the Hidden files and folders select "Show hidden files and folders"
Check "Hide protected operating system files"
Click Apply and then the OK and close My Computer.

=============

Now that you seem to be clean, please follow these simple steps in order to keep your computer clean and secure:
Clear your system restore (http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/tips/mcgill1.mspx)
This will clear the system restore folders from possible malware that was left behind during the cleaning process.

Use ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1)
Download and install ATF Cleaner. Clean your temporary files & folders with it regularly.

Use Ad-Aware (http://www.bleepingcomputer.com/forums/?showtutorial=48)
Download and install Ad-Aware. Update it and scan your computer regularly with it.

Use AVG Anti-Spyware (http://www.ewido.net/en/)
Update it and scan your computer regularly with it.

Use Spybot S&D (http://www.bleepingcomputer.com/forums/?showtutorial=43)
Download and install Spybot S&D. Update it and scan your computer regularly with it.

Install SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html)
SpywareBlaster will prevent spyware from being installed.

Install MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm)
This prevents your computer from connecting to harmful sites.

Use Firefox browser (http://www.mozilla.org)
Firefox is faster, safer and better browser than Internet Explorer.

Keep your systen up-to-date (http://windowsupdate.microsoft.com)
Visit Windows Update regularly.

Keep your antivirus and firewall up-to-date
Scan your computer regularly with your antivirus.

Read this article by TonyKlein (http://forums.spybot.info/showthread.php?t=279)
So how did I get infected in the first place?

Stand Up and Be Counted ! (http://www.malwarecomplaints.info/index.php)
The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.


Stay clean and be safe ;)

rightontargt4
2007-01-25, 16:43
Thank you VERY VERY much for helping me. You have no idea how much easier (well, you probably do) this will make things now.

By the way, I have Sophos installed on here, because it's the firewall that the college recommends, and for some reason, I think they have the port that Sophos uses to get its updates blocked.....because neither me nor anyone else on here cannot connect to the update server. But, the college has its own firewall too.

But again, thanks SO much for the help!!!!

Mr_JAk3
2007-01-25, 18:56
You're welcome :)

So you have an up-to-date subscription to Sophos ?
It is just that an antivirus won't protect you if it isn't up-to-date.

You could try manual update too -> Link (http://www.sophos.com/downloads/ide/)

:bigthumb:

rightontargt4
2007-01-25, 19:46
As far as I know, the college handles the subscription....I'll try downloading the manual updates though. Thanks again, again!

Mr_JAk3
2007-01-26, 08:11
You're very welcome :D:

As the problem appears to be resolved this topic has been archived.

If you need it re-opened please send a private message (pm) to a forum staff member and provide a link to the thread; this applies only to the original topic starter.

Glad we could help :2thumb: