PDA

View Full Version : Help with virtumonde



pudge
2008-09-14, 09:51
I came home this afternoon to Avast! warning of virus found, so I clicked remove as always and then I saw that I had yellow warning icon, so I clicked on that and it gave a warning along the lines of my firewall being compromised. I checked my firewall and saw that it had been turned to off and the option to turn on is not available. I have been using the Windows firewall for a few years now without any problems and did not realize until reading forums here that it is not a sufficient firewall protection.

I ran Spybot in normal mode first and received the message to contact the S&D forums for help with removing virtumonde. I browsed the forums and didn't see anything warning against it, so I did click on fix the problems, and just like others report, virtumonde comes right back. I ran Spybot in safe mode and had the same results. Before I downloaded and ran Spybot I had previously tried cleaning with Ad-aware and Vipre and neither were finding this virtumonde -- they were coming up clean after initial scan but I was still getting pop ups when surfing. Since running spybot the pop ups have slowed, but I'm still having issues with some pages not loading, inculding both gmail and yahoo being hit & miss.

My HJT log is below. Thank you for any help you can offer.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:15:02 AM, on 9/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SEMBLY~1\chkdsk.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [30417384] rundll32.exe "C:\WINDOWS\system32\humplbuj.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [GetModule23] "C:\Program Files\GetModule\GetModule23.exe"
O4 - HKCU\..\Run: [Ncao] "C:\PROGRA~1\SEMBLY~1\chkdsk.exe" -vt yazb
O4 - HKCU\..\Run: [GetPack21] "C:\Program Files\GetPack\GetPack21.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://gsn.worldwinner.com/games/v46/shared/FunGamesLoader.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/0450afb63bd974d4eb01/netzip/RdxIE601.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140059931125
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://media.grab.com/media/fbd793/games/files/209/SproutLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://65.242.77.182/activex/AMC.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/chuzzle/popcaploader_v6.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} (AxRUploadControl Object) - http://www.imagestation.com/common/classes/SonyISUpload.cab?v=1,0,0,36
O20 - AppInit_DLLs: pkxzqf.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CSIScanner - Prevx - C:\Program Files\PrevxCSI\prevxcsi.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Sunbelt VIPRE Antivirus Service (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 12252 bytes

km2357
2008-09-14, 20:58
Hello and welcome to Safer Networking.

My name is km2357 and I will be helping you to remove any infection(s) that you may have.

I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

If for any reason you do not understand an instruction or are just unsure then please do not guess, simply post back with your questions/concerns and we will go through it again.

Please do not start another thread or topic, I will assist you at this thread until we solve your problems.

Lastly the fix may take several attempts and my replies may take some time but I will stick with it if you do the same.


I will be back as soon as possible with your first instructions!

km2357
2008-09-14, 21:10
Step # 1:Remove two of your Anti Virus programs.

You are operating your computer with multiple Anti Virus programs running in memory at once:

Avast
Symantec/Norton
VIPRE (Sunbelt)

Anti-virus programs take up an enormous amount of your computer's resources when they are actively scanning your computer. Having two or more anti-virus programs running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash.

Please remove two of them.


Step # 2: Disable Teatimer

Spybot S&D's tea timer normally provides real-time protection from spyware, however it may interfere with what we need to do. We will disable it until the machine is clean when it can be re-enabled.

This is a two step process.
First step: Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
If you have the new version 1.5, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
If you have Version 1.4, Click on Exit Spybot S&D Resident

Second step, For Either Version : Open Spybot S&D
Click Mode, choose Advanced Mode
Go To the bottom of the Vertical Panel on the Left, Click Tools
then, also in left panel, click Resident shows a red/white shield.
If your firewall raises a question, say OK
In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
OK any prompts.
Use File, Exit to terminate Spybot
Reboot your machine for the changes to take effect.


Step # 3 Download CCleaner

Download CCleaner from here (http://www.ccleaner.com/) to clean temp files from your computer.

Double click on the ccsetup.exe file to start the installation of the program.
Select your language and click OK, then next.
Read the license agreement and click I Agree.
Click next to use the default install location.
Under Install Options, choose all the default settings except I would recommend that you unclick/untick install the Yahoo! Toolbar, unless you want it. You can also Uncheck the 'Automatically check for updates' box.
Click Install then finish to complete installation.


Step # 4 Retrieve the Installed Programs List from CCleaner

Open CCleaner if it's not already running.
In the Left Pane, click Tools
Verify that Uninstall is highlighted in color, or click on it.
In the lower Right, click Save to Text File.
Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
You can leave the filename as install.txt
Click Save
Exit CCleaner by clicking on the X button in the upper right of the CCleaner window.



Step # 5: Download and Run ComboFix

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Be sure to save ComboFix.exe to your Desktop

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


Click Yes to allow ComboFix to continue scanning for malware.


When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleaning the system:

CCleaner Install List
C:\ComboFix.txt
New HijackThis log.

Use multiple posts if you can't fit everything into one post.

pudge
2008-09-15, 00:02
Thank you for your quick response.

I removed Vipre and tried to remove Symantec but as it counts down to un-installation, I get a message that says Fatal Error Occurred, and it aborts the un-installation. I've tried several times with the same results. I'd like to keep Avast instead of Symantec because I haven't actually used/updated Symantec in a few years. Any help on removing it?

As for Step 2 and disabling Teatimer, I do not have a blue & white calendar in the system tray today. I remember seeing this last night but it has yet to appear today, even when spybot started.

I have not done the rest of the steps as you said go in order and I don't want to do anything that will delay getting rid of this virtuemonde.

km2357
2008-09-15, 08:27
To remove Norton, do the following:

Go here (http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2005033108162039) and click on your version of Norton Antivirus. Follow the directions and download and save the Norton Removal Tool to your Desktop.

Run the tool by double-clicking it. Follow all instructions and if it doesn't reboot the computer after it is finished, reboot the computer.


Go ahead and skip disabling Teatimer for now and do Steps 3 to 5 of the previous post and post back the CCleaner Install List, ComboFix Log, and a fresh HiJackThis Log for me to look over.

pudge
2008-09-16, 03:07
I was still not able to remove symantec using the program you supplied. Once downloaded and unzipped to run, a popup appeared that said I needed to manually remove Symantec AntiVirus 9 before proceeding with Norton Removal. Manual removal was my problem in the first place, so I'm not sure what that was all about. I even tried to do a repair in order to remove and the repair aborted in the same way. I did go on with the other steps and ran the other scans anyway.

------------------------------



ComboFix 08-09-15.02 - Alisha 2008-09-15 19:46:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.570 [GMT -4:00]
Running from: C:\Documents and Settings\Alisha\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Alisha\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\iCheck
C:\Program Files\iCheck\Uninstall.exe
C:\Program Files\sembly~1
C:\Program Files\sembly~1\??sembly\
C:\Program Files\VnrBlock
C:\Program Files\VnrBlock\xtarga.gz
C:\WINDOWS\BM33724018.txt
C:\WINDOWS\BM33724018.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\Fonts\acrsecB.fon
C:\WINDOWS\Fonts\acrsecI.fon
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\eaqipwnc.dll
C:\WINDOWS\system32\esnfcrag.dll
C:\WINDOWS\system32\fccccCSK.dll
C:\WINDOWS\system32\fcjyvr.dll
C:\WINDOWS\SYSTEM32\hcsqlqhn.ini
C:\WINDOWS\SYSTEM32\hcsqlqhn.ini2
C:\WINDOWS\SYSTEM32\hcsqlqhn.tmp
C:\WINDOWS\system32\hggskxiq.dll
C:\WINDOWS\SYSTEM32\jublpmuh.ini
C:\WINDOWS\SYSTEM32\KSCccccf.ini
C:\WINDOWS\SYSTEM32\KSCccccf.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mhffbpdi.dll
C:\WINDOWS\system32\nhqlqsch.dll
C:\WINDOWS\system32\nnnlmKDt.dll
C:\WINDOWS\system32\pkxzqf.dll
C:\WINDOWS\SYSTEM32\qixksggh.ini
C:\WINDOWS\system32\rrnxhl.dll

.
((((((((((((((((((((((((( Files Created from 2008-08-15 to 2008-09-15 )))))))))))))))))))))))))))))))
.

2008-09-15 18:18 . 2008-09-15 18:18 <DIR> d-------- C:\Program Files\CCleaner
2008-09-15 18:16 . 2008-09-15 18:17 2,928,600 --a------ C:\Program Files\ccsetup211.exe
2008-09-15 17:56 . 2008-09-15 18:09 2,404,352 --a------ C:\Program Files\Norton_Removal_Tool.exe
2008-09-14 01:32 . 2008-09-14 01:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-14 01:32 . 2008-09-14 01:32 812,344 --a------ C:\Program Files\HJTInstall.exe
2008-09-14 01:27 . 2008-09-14 01:27 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-14 01:27 . 2008-09-14 01:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-14 01:27 . 2008-09-14 01:27 <DIR> d-------- C:\Documents and Settings\Alisha\Application Data\Malwarebytes
2008-09-14 01:27 . 2008-09-14 01:27 2,189,864 --a------ C:\Program Files\mbam-setup.exe
2008-09-14 01:27 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-09-14 01:27 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
2008-09-14 01:17 . 2008-09-14 01:21 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-14 01:17 . 2008-09-14 01:17 15,083,520 --a------ C:\Program Files\spybotsd160.exe
2008-09-14 01:13 . 2008-09-14 01:13 532,480 --a------ C:\Program Files\cwshredder.exe
2008-09-13 21:07 . 2008-09-13 21:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt
2008-09-13 20:46 . 2008-09-13 20:47 67,246,856 --a------ C:\Program Files\vipre.exe
2008-09-13 20:06 . 2008-09-14 16:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-09-13 20:05 . 2008-09-13 20:06 618,040 --a------ C:\Program Files\PREVXCSIFREE.EXE
2008-09-13 19:18 . 2008-09-13 19:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-13 19:17 . 2008-09-13 19:17 19,153,264 --a------ C:\Program Files\aaw2008.exe
2008-09-13 18:33 . 2008-09-13 18:33 <DIR> d-------- C:\Program Files\OINAnalytics
2008-09-05 00:59 . 2008-05-01 10:30 331,776 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msadce.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-15 22:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-15 22:08 --------- d-----w C:\Program Files\Symantec
2008-09-14 20:42 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-14 20:39 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-09-14 05:51 1,283 ----a-w C:\Program Files\1221371503967-integrated.jnlp
2008-09-14 00:20 --------- d-----w C:\Program Files\Shutterfly
2008-09-14 00:19 --------- d-----w C:\Program Files\Flock
2008-09-05 00:18 --------- d--h--w C:\Documents and Settings\Alisha\Application Data\Move Networks
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\SYSTEM32\es.dll
2008-07-07 20:32 253,952 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\SYSTEM32\mscms.dll
2008-06-24 16:23 74,240 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mscms.dll
2008-06-23 09:49 18,432 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iedw.exe
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\SYSTEM32\mswsock.dll
2008-06-20 17:41 245,248 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip6.sys
2008-04-26 00:30 4,502,280 ----a-w C:\Program Files\LimeWireWin.exe
2008-04-15 22:35 59,782,440 ----a-w C:\Program Files\iTunesSetup.exe
2007-09-15 01:36 28,868,320 ----a-w C:\Program Files\FileFormatConverters.exe
2007-08-31 22:48 135,680 ----a-w C:\Program Files\MySpaceMp3Gopher.exe
2007-07-01 04:23 9,482,464 ----a-w C:\Program Files\Flock_Setup_0_7_14__photobucket.exe
2007-06-26 15:32 732,795 ----a-w C:\Program Files\uploadr_2.5.0.15_en.exe
2007-06-12 04:41 1,181,812 ----a-w C:\Program Files\FLVPlayerSetup.exe
2007-05-09 04:31 10,320,168 ----a-w C:\Program Files\ShutterflyStudioInstaller.exe
2006-12-10 00:36 203,061 ----a-w C:\Program Files\AIM+Setup.exe
2006-11-05 20:43 5,182,976 ----a-w C:\Program Files\WindowsDefender.msi
2006-09-07 19:58 13,072,520 ----a-w C:\Program Files\setup2.exe
2006-09-02 16:22 740,864 ----a-w C:\Program Files\1033.MST
2006-09-02 16:22 45,639,680 ----a-w C:\Program Files\iPod for Windows 2006-06-28.msi
2006-09-02 16:22 4,632 ----a-w C:\Program Files\0x0409.ini
2006-02-18 06:04 738,864 ----a-w C:\Program Files\setup.exe
2006-01-18 01:22 9,968,960 ----a-w C:\Program Files\setupeng.exe
2005-11-03 15:29 2,497,344 ----a-w C:\Program Files\csbl.exe
2005-10-29 20:52 1,958,208 ----a-w C:\Program Files\csmb.exe
2005-01-08 23:35 5,473,872 ----a-w C:\Program Files\msjavx86_3805.exe
2004-12-11 22:13 16,706,160 ----a-w C:\Program Files\AdbeRdr60_enu_full.exe
2004-12-07 00:19 5,476,352 ----a-w C:\Program Files\SSHSecureShellClient-3.2.3.exe
2004-12-05 16:45 7,741,336 ----a-w C:\Program Files\DivX521XP2K.exe
2004-11-12 22:15 91,956 ----a-w C:\Program Files\3RD-PARTY-LICENSE.txt
2004-11-12 22:15 5,404 ----a-w C:\Program Files\COPYRIGHT
2004-11-12 22:15 151,228 ----a-w C:\Program Files\uninstall.exe
2004-11-12 22:15 14,998 ----a-w C:\Program Files\LICENSE.txt
2004-11-12 22:15 138,420 ----a-w C:\Program Files\uninstall.dos.exe
2004-11-12 22:14 1,462,960 ----a-w C:\Program Files\appserv_uninstall.class
2004-11-05 02:18 4,692,992 ----a-w C:\Program Files\irfanview_plugins_395.exe
2004-11-04 00:58 1,633,280 ----a-w C:\Program Files\ftop3.exe
2004-09-17 02:08 12,652,784 ----a-w C:\Program Files\mp10setup.exe
2004-09-01 23:41 2,848,440 ----a-w C:\Program Files\Install_AIM_4.8.2790.exe
2004-08-25 00:13 3,581,094 ----a-w C:\Program Files\shsetup.exe
2004-08-25 00:08 2,558,672 ----a-w C:\Program Files\sdinstall.exe
2004-08-21 20:23 870,912 ----a-w C:\Program Files\iview392.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 50528]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-03-23 135168]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-25 335872]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-06-23 85696]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 48752]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Kodak EasyShare software.lnk - C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe [2002-09-16 299008]
Monitor.lnk - C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe [2005-06-26 110592]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=rrnxhl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 SBRE;SBRE;C:\WINDOWS\system32\drivers\SBREdrv.sys [ ]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

BHO-{67c1c42a-2d6f-4489-9344-9db57a347088} - C:\WINDOWS\system32\rrnxhl.dll
BHO-{6B221E01-F517-4959-8C41-81948E7F2F17} - (no file)
BHO-{895943B4-99D4-4559-99C5-271D05425367} - C:\Documents and Settings\Alisha\Local Settings\Temporary Internet Files\Content.IE5\DQ4DBMEU\silent.dll[1].bak
BHO-{98F9C0DA-58EA-4243-9718-3BBC35543AC6} - C:\WINDOWS\system32\fccccCSK.dll
BHO-{D7336D32-62F7-43B5-8B8C-3963C72CA498} - C:\WINDOWS\system32\nnnlmKDt.dll
HKCU-Run-GetModule23 - C:\Program Files\GetModule\GetModule23.exe
HKCU-Run-Ncao - C:\PROGRA~1\SEMBLY~1\chkdsk.exe
HKCU-Run-GetPack21 - C:\Program Files\GetPack\GetPack21.exe
HKCU-Run-Sonic RecordNow! - (no file)
HKLM-Run-30417384 - C:\WINDOWS\system32\nhqlqsch.dll
HKLM-Run-BM33724018 - C:\WINDOWS\system32\gpccabmi.dll
ShellExecuteHooks-{D7336D32-62F7-43B5-8B8C-3963C72CA498} - C:\WINDOWS\system32\nnnlmKDt.dll


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Alisha\Application Data\Mozilla\Firefox\Profiles\eoit7h7m.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/?save=0
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-15 19:52:17
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\ati2evxx.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\SYSTEM32\LEXBCES.EXE
C:\WINDOWS\SYSTEM32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\SYSTEM32\DRIVERS\dcfssvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Intel Application Accelerator\IAANTmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\SYSTEM32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2008-09-15 19:59:09 - machine was rebooted [Alisha]
ComboFix-quarantined-files.txt 2008-09-15 23:59:00

Pre-Run: 107,325,669,376 bytes free
Post-Run: 107,316,875,264 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

237 --- E O F --- 2008-09-12 05:36:59

pudge
2008-09-16, 03:13
Adobe Download Manager 1.2 (Remove Only)
Adobe Flash Player ActiveX
Adobe Reader 7.0.8
AIM 6
Apple Mobile Device Support
Apple Software Update
ArcSoft Media Card Companion
ArcSoft Software Suite
ATI Control Panel
ATI Display Driver
avast! Antivirus
AXIS Media Control Embedded
Bonjour
Broadcom Advanced Control Suite 2
CCleaner (remove only)
Compatibility Pack for the 2007 Office system
Dell Photo Printer 720
Dell Solution Center
Dell Support Center
DellSupport
DivX
DivX Content Uploader
DivX Player
DivX Web Player
FLV Player 1.3.3
HijackThis 2.0.2
Intel Application Accelerator
Intel(R) 537EP V9x DF PCI Modem
Internet Explorer Q903235
iPod for Windows 2006-06-28
IrfanView (remove only)
iTunes
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
Java 2 Platform, Enterprise Edition 1.4 SDK
Java 2 Runtime Environment, SE v1.4.2_05
Java 2 Runtime Environment, SE v1.4.2_06
Kodak EasyShare software
Learn2 Player (Uninstall Only)
Macromedia Shockwave Player
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Office Professional Edition 2003
Modem Event Monitor
Modem Helper
Modem On Hold
Move Networks Media Player for Internet Explorer
OIN Analytics
PowerDVD 5.1
QuickTime
Secure Game Player
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Spybot - Search & Destroy
Symantec AntiVirus
Viewpoint Media Player
Windows Defender
Windows Installer 3.1 (KB893803)
Windows XP Service Pack 2


_______________

HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:13:03 PM, on 9/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\CCleaner\CCleaner.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://gsn.worldwinner.com/games/v46/shared/FunGamesLoader.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140059931125
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://media.grab.com/media/fbd793/games/files/209/SproutLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://65.242.77.182/activex/AMC.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} (AxRUploadControl Object) - http://www.imagestation.com/common/classes/SonyISUpload.cab?v=1,0,0,36
O20 - AppInit_DLLs: rrnxhl.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 11399 bytes

km2357
2008-09-16, 09:56
Step # 1: Add/Remove Programs

Go to Start-Settings-Control Panel, click on Add Remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on remove. Then close the Control Panel.

OIN Analytics

Reboot your Computer.



Step # 2 Update Java

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Please follow these steps to remove older version Java components and update.

Updating Java:

Download the latest version of Java Runtime Environment (JRE) 6u7 (http://www.java.com/en/download/manual.jsp).
Click on the link to download Windows Offline Installation and save to your desktop. Do NOT use the Sun Download Manager.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Remove the following old versions of Java:


Java 2 Runtime Environment, SE v1.4.2_05

Java 2 Runtime Environment, SE v1.4.2_06

J2SE Runtime Environment 5.0 Update 2

J2SE Runtime Environment 5.0 Update 4

J2SE Runtime Environment 5.0 Update 6


Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.

From your desktop double-click on the download to install the newest version.



Step # 3: Run CFScript


Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


KILLALL::

File::

C:\Program Files\vipre.exe

Folder::

C:\Documents and Settings\All Users\Application Data\Sunbelt
C:\Program Files\Symantec
C:\Program Files\Symantec AntiVirus
C:\Program Files\Common Files\Symantec Shared
C:\Program Files\OINAnalytics
C:\Program Files\PartyPoker

Registry::

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""
[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]


Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.




http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif


Note: This CFScript is for use on pudge's computer only! Do not use it on your computer.


Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



Step # 4: Remove Hijackthis Entries


Run HijackThis
Click on the Scan button
Put a check beside all of the items listed below (if present):


O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)

O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe

O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe


Close all open windows and browsers/email, etc...
Click on the "Fix Checked" button
When completed, close the application.



Step # 5: Delete services

Please open Notepad. Ensure that word wrap is turned off. Click on Format and make sure that there is not a tick next to Word Wrap. If there's one, click on Word Wrap to remove it. Copy and paste the following in the code box into Notepad:


sc stop ccEvtMgr
sc delete ccEvtMgr
sc stop ccPwdSvc
sc delete ccPwdSvc
sc stop ccSetMgr
sc delete ccSetMgr
sc stop DefWatch
sc delete DefWatch
sc stop SavRoam
sc delete SavRoam
sc stop SNDSrvc
sc delete SNDSrvc
sc stop SPBBCSvc
sc delete SPBBCSvc
sc stop Symantec AntiVirus
sc delete Symantec AntiVirus

Click on File > Save As....

In the File Name box, copy and paste in fix.bat
In the Save as type box, select All Files from the drop-down list.

Click Save and save it to your Desktop.

Double click on fix.bat. A Command Prompt window will open and close quickly. That is normal.

Reboot your computer and try running the Norton Removal tool again.


In your next post/reply, I need to see the following:

1. The ComboFix Log that appears after Step 3 has been completed.
2. A fresh HiJackThis Log taken after all 5 steps have been compeleted.

Use multiple posts if you can't fit everything into one post.

pudge
2008-09-18, 07:36
ComboFix 08-09-16.05 - Alisha 2008-09-18 0:18:52.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.685 [GMT -4:00]
Running from: C:\Documents and Settings\Alisha\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Alisha\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Sunbelt
C:\Documents and Settings\All Users\Application Data\Sunbelt\AntiMalware\Events\EV2008091416250002.xml
C:\Documents and Settings\All Users\Application Data\Sunbelt\AntiMalware\Events\EV2008091416250103.xml
C:\Program Files\Common Files\Symantec Shared
C:\Program Files\Common Files\Symantec Shared\ccAlert.dll
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\ccDec.dll
C:\Program Files\Common Files\Symantec Shared\ccEmlPxy.dll
C:\Program Files\Common Files\Symantec Shared\ccErrDsp.dll
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccInst.dll
C:\Program Files\Common Files\Symantec Shared\ccL35.dll
C:\Program Files\Common Files\Symantec Shared\ccLgView.exe
C:\Program Files\Common Files\Symantec Shared\ccProd.dll
C:\Program Files\Common Files\Symantec Shared\ccProSub.dll
C:\Program Files\Common Files\Symantec Shared\ccPwd.dll
C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccScan.dll
C:\Program Files\Common Files\Symantec Shared\ccSet.dll
C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll
C:\Program Files\Common Files\Symantec Shared\ccWebWnd.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll
C:\Program Files\Common Files\Symantec Shared\Decomposers\DecSDK.dll
C:\Program Files\Common Files\Symantec Shared\Default.rul
C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll
C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL
C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
C:\Program Files\Common Files\Symantec Shared\Help\CCLGVIEW.CHM
C:\Program Files\Common Files\Symantec Shared\Help\LUALL.CHM
C:\Program Files\Common Files\Symantec Shared\sevinst.exe
C:\Program Files\Common Files\Symantec Shared\SNDInst.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDunin.dll
C:\Program Files\Common Files\Symantec Shared\SPBBC\BB.dll
C:\Program Files\Common Files\Symantec Shared\SPBBC\bbRGen.dll
C:\Program Files\Common Files\Symantec Shared\SPBBC\init.kc
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.CAT
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.inf
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCEvt.dll
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\UpdMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPManifests\ccCommon.grd
C:\Program Files\Common Files\Symantec Shared\SPManifests\ccCommon.sig
C:\Program Files\Common Files\Symantec Shared\SPManifests\ccCommon.spm
C:\Program Files\Common Files\Symantec Shared\SPManifests\ccOEH.grd
C:\Program Files\Common Files\Symantec Shared\SPManifests\ccOEH.sig
C:\Program Files\Common Files\Symantec Shared\SPManifests\ccOEH.spm
C:\Program Files\Common Files\Symantec Shared\SPManifests\eraser.grd
C:\Program Files\Common Files\Symantec Shared\SPManifests\eraser.sig
C:\Program Files\Common Files\Symantec Shared\SPManifests\eraser.spm
C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.grd
C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.sig
C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.spm
C:\Program Files\Common Files\Symantec Shared\SPManifests\SPBBC.grd
C:\Program Files\Common Files\Symantec Shared\SPManifests\SPBBC.sig
C:\Program Files\Common Files\Symantec Shared\SPManifests\SPBBC.spm
C:\Program Files\Common Files\Symantec Shared\SPManifests\SYMEVNT.GRD
C:\Program Files\Common Files\Symantec Shared\SPManifests\SYMEVNT.SIG
C:\Program Files\Common Files\Symantec Shared\SPManifests\SYMEVNT.SPM
C:\Program Files\Common Files\Symantec Shared\SSC\ExchngUI.ocx
C:\Program Files\Common Files\Symantec Shared\SSC\IMailUI.ocx
C:\Program Files\Common Files\Symantec Shared\SSC\LDDateTm.ocx
C:\Program Files\Common Files\Symantec Shared\SSC\LDVPCtls.ocx
C:\Program Files\Common Files\Symantec Shared\SSC\LDVPDlgs.ocx
C:\Program Files\Common Files\Symantec Shared\SSC\LDVPTask.ocx
C:\Program Files\Common Files\Symantec Shared\SSC\ldvpui.ocx
C:\Program Files\Common Files\Symantec Shared\SSC\LDVPView.ocx
C:\Program Files\Common Files\Symantec Shared\SSC\LotNtsUI.ocx
C:\Program Files\Common Files\Symantec Shared\SSC\scandlgs.dll
C:\Program Files\Common Files\Symantec Shared\SSC\ScsComms.dll
C:\Program Files\Common Files\Symantec Shared\SSC\SymProtectUI.ocx
C:\Program Files\Common Files\Symantec Shared\SSC\Transman.dll
C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
C:\Program Files\Common Files\Symantec Shared\SSC\webshell.dll
C:\Program Files\Common Files\Symantec Shared\Validate.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\CATALOG.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\CCERASER.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\ECBOOTIL.VXD
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\ECMSVR32.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\eeCtrl.sys
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\ERASER.grd
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\ERASER.sig
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\ERASER.spm
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\eraser.sys
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\esrdef.bin
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\HH
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\NAVENG.EXP
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\NAVENG.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\NAVENG.VXD
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\NAVENG32.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\NAVEX15.EXP
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\NAVEX15.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\NAVEX15.VXD
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\NAVEX32A.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\NCSACERT.TXT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\SCRAUTH.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\SYMAVENG.CAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\SYMAVENG.INF
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\SymErase.cat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\SymErase.inf
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\TCDEFS.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\TCSCAN7.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\TCSCAN8.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\TCSCAN9.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\TECHNOTE.TXT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\TINF.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\TINFIDX.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\TINFL.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\TSCAN1.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\TSCAN1HD.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\V.GRD
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\V.SIG
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\VIRSCAN.INF
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\VIRSCAN1.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\VIRSCAN2.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\VIRSCAN3.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\VIRSCAN4.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\VIRSCAN5.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\VIRSCAN6.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\VIRSCAN7.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\VIRSCAN8.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\VIRSCAN9.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\VIRSCANT.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\vscanmsx.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\WHATSNEW.TXT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060115.008\ZDONE.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\CATALOG.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\CCERASER.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\ECBOOTIL.VXD
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\ECMSVR32.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\eeCtrl.sys
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\ERASER.grd
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\ERASER.sig
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\ERASER.spm
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\eraser.sys
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\esrdef.bin
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\HH
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\NAVENG.EXP
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\NAVENG.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\NAVENG.VXD
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\NAVENG32.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\NAVEX15.EXP
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\NAVEX15.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\NAVEX15.VXD
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\NAVEX32A.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\NCSACERT.TXT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\SCRAUTH.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\SYMAVENG.CAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\SYMAVENG.INF
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\SymErase.cat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\SymErase.inf
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\TCDEFS.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\TCSCAN7.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\TCSCAN8.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\TCSCAN9.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\TECHNOTE.TXT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\TINF.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\TINFIDX.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\TINFL.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\TSCAN1.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\TSCAN1HD.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\V.GRD
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\V.SIG
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\VIRSCAN.INF
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\VIRSCAN1.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\VIRSCAN2.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\VIRSCAN3.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\VIRSCAN4.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\VIRSCAN5.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\VIRSCAN6.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\VIRSCAN7.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\VIRSCAN8.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\VIRSCAN9.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\VIRSCANT.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\vscanmsx.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\WHATSNEW.TXT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060116.007\ZDONE.DAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\catalog.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\cceraser.dll
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ecbootil.vxd
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ecmsvr32.dll
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\eeCtrl.sys
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ERASER.grd
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ERASER.sig
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ERASER.spm
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\eraser.sys
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ESRDEF.BIN
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\hh
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng.exp
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng.sys
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng.vxd
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng32.dll
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\navex15.exp
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\navex15.sys
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\navex15.vxd
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\navex32a.dll
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ncsacert.txt
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\scrauth.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\symaveng.cat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\symaveng.inf
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\SymErase.cat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\SymErase.inf
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tcdefs.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tcscan7.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tcscan8.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tcscan9.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\technote.txt
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tinf.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tinfidx.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tinfl.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tscan1.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tscan1hd.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\v.grd
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\v.sig
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan.inf
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan1.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan2.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan3.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan4.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan5.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan6.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan7.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan8.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan9.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\whatsnew.txt
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\zdone.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\definfo.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\lulock.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\TextHub\virscant.dat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\usage.dat
C:\Program Files\Symantec AntiVirus
C:\Program Files\Symantec AntiVirus\Cliproxy.dll
C:\Program Files\Symantec AntiVirus\Cliscan.dll
C:\Program Files\Symantec AntiVirus\clninst.bat
C:\Program Files\Symantec AntiVirus\COUNTRY.DAT
C:\Program Files\Symantec AntiVirus\Dec3.cfg
C:\Program Files\Symantec AntiVirus\Default.hst
C:\Program Files\Symantec AntiVirus\DefUtDCD.dll
C:\Program Files\Symantec AntiVirus\DefUtDCS.dll
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\Symantec AntiVirus\DWHWizrd.exe
C:\Program Files\Symantec AntiVirus\dwLdPntScan.dll
C:\Program Files\Symantec AntiVirus\GenMar.dll
C:\Program Files\Symantec AntiVirus\I2ldvp3.dll
C:\Program Files\Symantec AntiVirus\IMail.dll
C:\Program Files\Symantec AntiVirus\LDVPREG.exe
C:\Program Files\Symantec AntiVirus\LuaWrap.exe
C:\Program Files\Symantec AntiVirus\LuHstEdt.dll
C:\Program Files\Symantec AntiVirus\LUSETUP.EXE
C:\Program Files\Symantec AntiVirus\Navap32.dll
C:\Program Files\Symantec AntiVirus\NAVAPI32.DLL
C:\Program Files\Symantec AntiVirus\NAVLU.dll
C:\Program Files\Symantec AntiVirus\NAVNTUTL.DLL
C:\Program Files\Symantec AntiVirus\nlnhook.exe
C:\Program Files\Symantec AntiVirus\nLNVP.dll
C:\Program Files\Symantec AntiVirus\nnewdefs.dll
C:\Program Files\Symantec AntiVirus\notesext.dll
C:\Program Files\Symantec AntiVirus\OEHeur.dll
C:\Program Files\Symantec AntiVirus\patch25d.dll
C:\Program Files\Symantec AntiVirus\PATCH32I.DLL
C:\Program Files\Symantec AntiVirus\PLATFORM.DAT
C:\Program Files\Symantec AntiVirus\qscomm32.dll
C:\Program Files\Symantec AntiVirus\QsInfo.dll
C:\Program Files\Symantec AntiVirus\qspak32.dll
C:\Program Files\Symantec AntiVirus\Rec2.dll
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec AntiVirus\SAVCProd.dll
C:\Program Files\Symantec AntiVirus\SavEmail.dll
C:\Program Files\Symantec AntiVirus\savhelp.chm
C:\Program Files\Symantec AntiVirus\savmain.chm
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\savrt.cat
C:\Program Files\Symantec AntiVirus\savrt.dat
C:\Program Files\Symantec AntiVirus\savrt.inf
C:\Program Files\Symantec AntiVirus\savrt.sys
C:\Program Files\Symantec AntiVirus\Savrt\0416NAV~.TMP
C:\Program Files\Symantec AntiVirus\SavRT32.dll
C:\Program Files\Symantec AntiVirus\savrtpel.cat
C:\Program Files\Symantec AntiVirus\savrtpel.inf
C:\Program Files\Symantec AntiVirus\Savrtpel.sys
C:\Program Files\Symantec AntiVirus\SCANCFG.DAT
C:\Program Files\Symantec AntiVirus\SCANDLVR.DLL
C:\Program Files\Symantec AntiVirus\SCANDRES.DLL
C:\Program Files\Symantec AntiVirus\SDPCK32I.dll
C:\Program Files\Symantec AntiVirus\SDSNAPSX.dll
C:\Program Files\Symantec AntiVirus\SDSND32I.DLL
C:\Program Files\Symantec AntiVirus\SDSOK32I.DLL
C:\Program Files\Symantec AntiVirus\SDSTP32I.DLL
C:\Program Files\Symantec AntiVirus\SMSTR32I.DLL
C:\Program Files\Symantec AntiVirus\SRTLEXCL.DAT
C:\Program Files\Symantec AntiVirus\SymProtectStorage.dll
C:\Program Files\Symantec AntiVirus\SystemSnapshotRules.bin
C:\Program Files\Symantec AntiVirus\VPC32.exe
C:\Program Files\Symantec AntiVirus\VPDN_LU.exe
C:\Program Files\Symantec AntiVirus\vpmsece3.dll
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\Symantec
C:\Program Files\Symantec\S32EVNT1.DLL
C:\Program Files\Symantec\SYMEVENT.CAT
C:\Program Files\Symantec\SYMEVENT.INF
C:\Program Files\Symantec\SYMEVENT.SYS
C:\Program Files\vipre.exe

.
((((((((((((((((((((((((( Files Created from 2008-08-18 to 2008-09-18 )))))))))))))))))))))))))))))))
.

2008-09-18 00:15 . 2008-09-18 00:15 <DIR> d-------- C:\Program Files\Common Files\Java
2008-09-18 00:15 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-09-15 18:18 . 2008-09-15 18:18 <DIR> d-------- C:\Program Files\CCleaner
2008-09-15 18:16 . 2008-09-15 18:17 2,928,600 --a------ C:\Program Files\ccsetup211.exe
2008-09-15 17:56 . 2008-09-15 18:09 2,404,352 --a------ C:\Program Files\Norton_Removal_Tool.exe
2008-09-14 01:32 . 2008-09-14 01:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-14 01:32 . 2008-09-14 01:32 812,344 --a------ C:\Program Files\HJTInstall.exe
2008-09-14 01:27 . 2008-09-14 01:27 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-14 01:27 . 2008-09-14 01:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-14 01:27 . 2008-09-14 01:27 <DIR> d-------- C:\Documents and Settings\Alisha\Application Data\Malwarebytes
2008-09-14 01:27 . 2008-09-14 01:27 2,189,864 --a------ C:\Program Files\mbam-setup.exe
2008-09-14 01:27 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-09-14 01:27 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
2008-09-14 01:17 . 2008-09-14 01:21 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-14 01:17 . 2008-09-14 01:17 15,083,520 --a------ C:\Program Files\spybotsd160.exe
2008-09-14 01:13 . 2008-09-14 01:13 532,480 --a------ C:\Program Files\cwshredder.exe
2008-09-13 20:06 . 2008-09-14 16:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-09-13 20:05 . 2008-09-13 20:06 618,040 --a------ C:\Program Files\PREVXCSIFREE.EXE
2008-09-13 19:18 . 2008-09-13 19:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-13 19:17 . 2008-09-13 19:17 19,153,264 --a------ C:\Program Files\aaw2008.exe
2008-09-05 00:59 . 2008-05-01 10:30 331,776 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msadce.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-18 04:15 --------- d-----w C:\Program Files\Java
2008-09-15 22:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-14 20:42 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-14 05:51 1,283 ----a-w C:\Program Files\1221371503967-integrated.jnlp
2008-09-14 00:20 --------- d-----w C:\Program Files\Shutterfly
2008-09-14 00:19 --------- d-----w C:\Program Files\Flock
2008-09-05 00:18 --------- d--h--w C:\Documents and Settings\Alisha\Application Data\Move Networks
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\cdm.dll
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\SYSTEM32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\SYSTEM32\wuauclt.exe
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\SYSTEM32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\SYSTEM32\wups.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\SYSTEM32\wuapi.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\SYSTEM32\wucltui.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\SYSTEM32\wuweb.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\SYSTEM32\wuaueng.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuaueng.dll
2008-07-19 02:07 270,880 ----a-w C:\WINDOWS\SYSTEM32\mucltui.dll
2008-07-19 02:07 210,976 ----a-w C:\WINDOWS\SYSTEM32\muweb.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\SYSTEM32\es.dll
2008-07-07 20:32 253,952 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\SYSTEM32\mscms.dll
2008-06-24 16:23 74,240 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mscms.dll
2008-06-23 09:49 18,432 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iedw.exe
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\SYSTEM32\mswsock.dll
2008-06-20 17:41 245,248 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip6.sys
2008-04-26 00:30 4,502,280 ----a-w C:\Program Files\LimeWireWin.exe
2008-04-15 22:35 59,782,440 ----a-w C:\Program Files\iTunesSetup.exe
2007-09-15 01:36 28,868,320 ----a-w C:\Program Files\FileFormatConverters.exe
2007-08-31 22:48 135,680 ----a-w C:\Program Files\MySpaceMp3Gopher.exe
2007-07-01 04:23 9,482,464 ----a-w C:\Program Files\Flock_Setup_0_7_14__photobucket.exe
2007-06-26 15:32 732,795 ----a-w C:\Program Files\uploadr_2.5.0.15_en.exe
2007-06-12 04:41 1,181,812 ----a-w C:\Program Files\FLVPlayerSetup.exe
2007-05-09 04:31 10,320,168 ----a-w C:\Program Files\ShutterflyStudioInstaller.exe
2006-12-10 00:36 203,061 ----a-w C:\Program Files\AIM+Setup.exe
2006-11-05 20:43 5,182,976 ----a-w C:\Program Files\WindowsDefender.msi
2006-09-07 19:58 13,072,520 ----a-w C:\Program Files\setup2.exe
2006-09-02 16:22 740,864 ----a-w C:\Program Files\1033.MST
2006-09-02 16:22 45,639,680 ----a-w C:\Program Files\iPod for Windows 2006-06-28.msi
2006-09-02 16:22 4,632 ----a-w C:\Program Files\0x0409.ini
2006-02-18 06:04 738,864 ----a-w C:\Program Files\setup.exe
2006-01-18 01:22 9,968,960 ----a-w C:\Program Files\setupeng.exe
2005-11-03 15:29 2,497,344 ----a-w C:\Program Files\csbl.exe
2005-10-29 20:52 1,958,208 ----a-w C:\Program Files\csmb.exe
2005-01-08 23:35 5,473,872 ----a-w C:\Program Files\msjavx86_3805.exe
2004-12-11 22:13 16,706,160 ----a-w C:\Program Files\AdbeRdr60_enu_full.exe
2004-12-07 00:19 5,476,352 ----a-w C:\Program Files\SSHSecureShellClient-3.2.3.exe
2004-12-05 16:45 7,741,336 ----a-w C:\Program Files\DivX521XP2K.exe
2004-11-12 22:15 91,956 ----a-w C:\Program Files\3RD-PARTY-LICENSE.txt
2004-11-12 22:15 5,404 ----a-w C:\Program Files\COPYRIGHT
2004-11-12 22:15 151,228 ----a-w C:\Program Files\uninstall.exe
2004-11-12 22:15 14,998 ----a-w C:\Program Files\LICENSE.txt
2004-11-12 22:15 138,420 ----a-w C:\Program Files\uninstall.dos.exe
2004-11-12 22:14 1,462,960 ----a-w C:\Program Files\appserv_uninstall.class
2004-11-05 02:18 4,692,992 ----a-w C:\Program Files\irfanview_plugins_395.exe
2004-11-04 00:58 1,633,280 ----a-w C:\Program Files\ftop3.exe
2004-09-17 02:08 12,652,784 ----a-w C:\Program Files\mp10setup.exe
2004-09-01 23:41 2,848,440 ----a-w C:\Program Files\Install_AIM_4.8.2790.exe
2004-08-25 00:13 3,581,094 ----a-w C:\Program Files\shsetup.exe
2004-08-25 00:08 2,558,672 ----a-w C:\Program Files\sdinstall.exe
2004-08-21 20:23 870,912 ----a-w C:\Program Files\iview392.exe
.

((((((((((((((((((((((((((((( snapshot@2008-09-15_19.58.21.93 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-11-10 16:27:06 49,248 ----a-w C:\WINDOWS\SYSTEM32\java.exe
+ 2008-06-10 05:21:01 135,168 ----a-w C:\WINDOWS\SYSTEM32\java.exe
- 2005-11-10 16:27:16 49,250 ----a-w C:\WINDOWS\SYSTEM32\javaw.exe
+ 2008-06-10 05:21:04 135,168 ----a-w C:\WINDOWS\SYSTEM32\javaw.exe
- 2005-11-10 18:03:54 127,078 ----a-w C:\WINDOWS\SYSTEM32\javaws.exe
+ 2008-06-10 06:32:34 139,264 ----a-w C:\WINDOWS\SYSTEM32\javaws.exe
+ 2008-07-19 02:10:20 36,552 ----a-w C:\WINDOWS\SYSTEM32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.784\wups.dll
+ 2008-07-19 02:10:40 45,768 ----a-w C:\WINDOWS\SYSTEM32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.784\wups2.dll
+ 2008-09-18 04:23:49 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5f0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 50528]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-03-23 135168]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-25 335872]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Kodak EasyShare software.lnk - C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe [2002-09-16 299008]
Monitor.lnk - C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe [2005-06-26 110592]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 SBRE;SBRE;C:\WINDOWS\system32\drivers\SBREdrv.sys [ ]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-vptray - C:\PROGRA~1\SYMANT~1\VPTray.exe



**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-18 00:24:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\ati2evxx.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\SYSTEM32\LEXBCES.EXE
C:\WINDOWS\SYSTEM32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\SYSTEM32\DRIVERS\dcfssvc.exe
C:\Program Files\Intel\Intel Application Accelerator\IAANTmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\SYSTEM32\wdfmgr.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\ComboFix\pv.cfexe
C:\WINDOWS\SYSTEM32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-09-18 0:30:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-18 04:30:51
ComboFix2.txt 2008-09-15 23:59:10

Pre-Run: 106,903,937,024 bytes free
Post-Run: 106,888,011,776 bytes free

540 --- E O F --- 2008-09-18 02:14:54

pudge
2008-09-18, 07:46
The Norton removal failed once again. I do not know why this keeps happening.

____________________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:44:54 AM, on 9/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://gsn.worldwinner.com/games/v46/shared/FunGamesLoader.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140059931125
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://media.grab.com/media/fbd793/games/files/209/SproutLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://65.242.77.182/activex/AMC.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} (AxRUploadControl Object) - http://www.imagestation.com/common/classes/SonyISUpload.cab?v=1,0,0,36
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 9569 bytes

km2357
2008-09-18, 09:03
The Norton removal failed once again. I do not know why this keeps happening.

I don't think we need to worry about it anymore. Looking over your latest HiJackThis log, I didn't see any signs of Norton/Symantec in it. Looks like we removed it.



Step # 1 Run CCleaner

CCleaner will remove everything from the temp/temporary folders but please note that it will not make back ups!


Before first use, select Options > Advanced and UNCHECK Only delete files in Windows Temp folder older than 48 hours
Then select the items you wish to clean up.

In the Windows Tab:

Clean all entries in the Internet Explorer section except Cookies
Clean all the entries in the Windows Explorer section
Clean all entries in the System section
Clean all entries in the Advanced section
Clean any others that you choose

In the Applications Tab:

Clean all except cookies in the Firefox/Mozilla section if you use it
Clean all in the Opera section if you use it
Clean Sun Java in the Internet Section
Clean any others that you choose

Click the Run Cleaner button.
A pop up box will appear advising this process will permanently delete files from your system.
Click OK and it will scan and clean your system.
Click exit when done.
If it asks you to reboot at the end, click NO



Step # 2 Run Malwarebytes' Anti-Malware

Launch Malwarebytes' Anti-Malware.
Before running a scan, click the Update tab, next click Check for Updates to download any updates, if available.
Next click the Scanner tab and select Perform Quick Scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location.
You can also access the log by doing the following:

Click on the Malwarebytes' Anti-Malware icon to launch the program.
Click on the Logs tab.
Click on the log at the bottom of those listed to highlight it.
Click Open.


In your next post/reply, I need to see the following:

1. MalwareBytes' Log
2. A fresh HiJackThis Log

pudge
2008-09-19, 06:56
Malwarebytes' Anti-Malware 1.28
Database version: 1172
Windows 5.1.2600 Service Pack 2

9/18/2008 11:53:33 PM
mbam-log-2008-09-18 (23-53-33).txt

Scan type: Quick Scan
Objects scanned: 48388
Time elapsed: 20 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
C:\Program Files\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.


_____________

New HJT Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:55:48 PM, on 9/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://gsn.worldwinner.com/games/v46/shared/FunGamesLoader.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140059931125
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://media.grab.com/media/fbd793/games/files/209/SproutLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://65.242.77.182/activex/AMC.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} (AxRUploadControl Object) - http://www.imagestation.com/common/classes/SonyISUpload.cab?v=1,0,0,36
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 9566 bytes

km2357
2008-09-19, 09:29
Step # 1 Update Adobe Acrobat Reader

There is a newer version of Adobe Acrobat Reader available. (See Note below)


First, go to Add/Remove Programs and uninstall all previous versions.
Please go to this link Adobe Acrobat Reader Download Link (http://www.adobe.com/products/acrobat/readstep2.html)
On the right Untick Adobe Phototshop Album Starter Edition if you do not wish to include this in the installation.
Click the Continue button
Click Run, and click Run again
Next click the Install Now button and follow the on screen prompts

Note: Adobe 9 is a large program and if you prefer a smaller program you can get Foxit 2.3 instead from http://www.foxitsoftware.com/pdf/rd_intro.php



Step # 2: Run Kaspersky Online Scan

Please go to Kaspersky website (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) and perform an online antivirus scan.

Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Mail databases Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply.


In your next post/reply, I need to see the following:

1. Kaspersky Log
2. A fresh HiJackThis Log
3. How is your computer doing, any problems?

pudge
2008-09-21, 02:07
My computer has been running without any problems. I have no pop-ups and no problems navigating to gmail.com or yahoo.com as before. Avast! has also stopped popping up every 5 mins. telling me I'm infected. I'm also able to click on links again whereas before the page would just spin/load for a long time unless I physically typed in the url and hit go. I was trying to remember exactly when it started working normally again and I believe it was right after I was finally able to download the combofix and do that scan. It took me a long time to get that page to work, because like I said, pages would only load if I typed in the address and pages for anti-virus software, etc. were taking even loger. I didn't want to get too excited that things were returning to normal because I have read several posts about how people stopped responding to the help thinking the trojan was gone only to be reinfected a few weeks later.

____________________________

kaspersky log:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Saturday, September 20, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Saturday, September 20, 2008 21:16:05
Records in database: 1246108
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\

Scan statistics:
Files scanned: 82754
Threat name: 13
Infected objects: 18
Suspicious objects: 0
Duration of the scan: 01:17:25


File name / Threat name / Threats count
C:\Documents and Settings\Alisha\Local Settings\Temporary Internet Files\Content.IE5\DE10NPZU\x12c[1].htm Infected: Exploit.JS.Agent.vj 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FE80000.VBN Infected: not-a-virus:AdWare.Win32.Chiem.b 1
C:\Program Files\Alwil Software\Avast4\DATA\moved\silent.dll[1].bak.vir Infected: Trojan.Win32.BHO.gts 1
C:\Program Files\shsetup.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.h 2
C:\Program Files\shsetup.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.e 1
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\hggskxiq.dll.vir Infected: Trojan.Win32.Monder.oaf 1
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\nhqlqsch.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aleq 1
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1114\A0107681.exe Infected: Trojan-Downloader.Win32.PurityScan.gb 1
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1114\A0107682.exe Infected: not-a-virus:AdWare.Win32.PurityScan.gp 1
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1120\A0109111.exe Infected: Trojan-Downloader.Win32.Agent.kwg 1
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1125\A0109248.dll Infected: Trojan.Win32.Monder.oaf 1
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1125\A0109262.dll Infected: Trojan.Win32.Pakes.klk 1
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1125\A0109349.dll Infected: Trojan.Win32.Pakes.klk 1
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1125\A0110269.dll Infected: Trojan.Win32.Monder.pqu 1
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1127\A0110336.dll Infected: Trojan.Win32.Monder.oaf 1
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1127\A0110338.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aleq 1
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1139\A0112934.exe Infected: not-a-virus:PSWTool.Win32.Pwdspyhk.a 1

The selected area was scanned.

_____________

HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:57:29 PM, on 9/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Uninstall getPlus(R) for Adobe] "C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1noarp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://gsn.worldwinner.com/games/v46/shared/FunGamesLoader.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140059931125
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://media.grab.com/media/fbd793/games/files/209/SproutLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://65.242.77.182/activex/AMC.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} (AxRUploadControl Object) - http://www.imagestation.com/common/classes/SonyISUpload.cab?v=1,0,0,36
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 10063 bytes

km2357
2008-09-21, 09:15
Kaspersky found some infected System Restore points. They are harmless where they are. Within the next few posts I'll show you how to remove those points and set a new, clean one. Kaspersky also found some files in the Qoobox folder, which is where ComboFix quarantines files. I'll show you how to remove that folder and ComboFix shortly.


Step # 1 Download and Run OTMoveIt2


Please download OTMoveIt2 by OldTimer (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe).

Save it to your desktop.
Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


C:\Documents and Settings\Alisha\Local Settings\Temporary Internet Files\Content.IE5\DE10NPZU\x12c[1].htm
C:\Documents and Settings\All Users\Application Data\Symantec
C:\Program Files\Alwil Software\Avast4\DATA\moved\silent.dll[1].bak.vir
C:\Program Files\shsetup.exe


Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light blue bar) and choose Paste.

Click the red Moveit! button.
Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTMoveIt2

Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

pudge
2008-09-21, 21:05
< C:\Documents and Settings\Alisha\Local Settings\Temporary Internet Files\Content.IE5\DE10NPZU\x12c[1].htm >
File/Folder C:\Documents and Settings\Alisha\Local Settings\Temporary Internet Files\Content.IE5\DE10NPZU\x12c[1].htm not found.
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.TMP moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5 moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\LiveSubscribe moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec moved successfully.
< C:\Program Files\Alwil Software\Avast4\DATA\moved\silent.dll[1].bak.vir >
C:\Program Files\Alwil Software\Avast4\DATA\moved\silent.dll[1].bak.vir moved successfully.
C:\Program Files\shsetup.exe moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09212008_140423

km2357
2008-09-21, 22:01
Everything looks good, you are good to go. :) And if you ever feel down the road you might be infected again, you can always start another thread here and myself or another helper will help you out. :)


To remove ComboFix, do the following:

Go to Start > Run - type in ComboFix /u & click OK


Please open OTMoveIt2.

Click on the CleanUp! button. If your Firewall gives a warning about OTMoveIt wanting to download a file, allow it.
Answer Yes to the prompt.
The program will ask for a reboot. Answer Yes.

Empty your Recycle Bin.


Please take the time to read my All Clean Post.

Please follow these simple steps in order to keep your computer clean and secure:

This is a good time to clear your existing system restore points and establish a new clean restore point

Go to Start > All Programs > Accessories > System Tools > System Restore
Select Create a restore point, and Ok it.
Next, go to Start > Run and type in cleanmgr
Make sure the C:\ drive is selected and click OK. If your computer's Hard Drive is not located on C:, change it to the correct drive letter then click OK.
Select the More options tab
Choose the option to clean up system restore and OK it.
This will remove all restore points except the new one you just created..

Clearing your restore points is not something you should do on a regular basis. Normally, this process only needs to be done after clearing out an infestation of malware.


Make your Internet Explorer more secure This can be done by following these simple instructions: From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub frames across different domains to Prompt When all these settings have been made, click on the OK button.
If it asks you if you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Set correct settings for files that should be hidden in Windows XP
Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
If unchecked please checkHide protected operating system files (Recommended)
If necessary check "Display content of system folders"
If necessary Uncheck Hide file extensions for known file types.
Click OK

Use An Antivirus Software and Keep It Updated - It is very important that your computer has an antivirus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperative that you update your antivirus software at least once a day. If you do not update your antivirus software, then it will not be able to catch any of the new variants that may come out.
Visit Microsoft's Update Site Frequently It is important that you visit Microsoft Updates (http://update.microsoft.com/) regularly. This will ensure your computer has the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Install SpywareBlaster SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
Computer Safety on line Anti Malware (http://forum.malwareremoval.com/viewtopic.php?p=54#54)
Use the hosts file: Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate web pages. We can customize a hosts file so that it blocks certain web pages. However, it can slow down certain computers. This is why using a hosts file is optional. Download mvps hosts file (http://www.mvps.org/winhelp2002/hosts.htm) Make sure you read the instructions on how to install the hosts file. There is a good tutorial HERE (http://www.bleepingcomputer.com/forums/tutorial51.html) If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button on the task bar at the bottom of your screen Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then doubleclick it. On the dropdown box, change the setting from automatic to manual. Click ok..
Use an alternative instant messenger program.Trillian (http://www.trillian.cc/) and Miranda IM (http://www.miranda-im.com/) These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
Please read Tony Klein's excellent article: How I got Infected in the First Place (http://forums.subratam.org/index.php?showtopic=5931)
Please read Understanding Spyware, Browser Hijackers, and Dialers (http://www.bleepingcomputer.com/forums/tutorial41.html)
Please read Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/tutorial82.html)
If you are using Internet Explorer, please consider using an alternate browser: Mozilla's Firefox (http://www.mozilla.org/products/firefox) or
Opera (http://www.opera.com/download/).
If you decide to use either FireFox or Opera, it is very important that you keep them up to date and check frequently for updates of the browser of your choice.
Update all these programs regularly Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
If your computer was infected by a website, a program, IM, MSN, or p2p, check this site because it is Time To Fight Back (http://spyware-free.us/2006/01/time-to-fight-back.html). Follow these steps and your potential for being infected again will reduce dramatically.

Here's a good website to read about Malware prevention:

http://users.telenet.be/bluepatchy/miekiemoes/prevention.html

If your computer is running slow, click here (http://www.malwareremoval.com/tutorials/runningslowly.php) for instructions on how to help speed up your computer.

Good luck!


Please reply one last time so that I know you have read my post and this thread can be closed.

pudge
2008-09-22, 05:21
Thank you very much for all of your help. I am currently going through the list of updates/software to avoid this again.

km2357
2008-09-22, 08:27
You're welcome. I'm glad I was able to help you out. :)