PDA

View Full Version : Virtumonde



rhino52
2009-01-04, 00:01
You can add me to the list of people who have been hit by Virtumonde. :sad:

I first tried to run Spybot to get rid of it and after about one day and three attempts of trying to delete it through Spybot I gave up and looked to the forums. After reading some forums, the next step I took was to run Malwarebytes Anti-Malware.

After completion of this run, I was reading through the forums and read that I should be doing this in normal start up mode. So I changed back from selective startup to normal start up mode and started getting these 3 error messages "RUNDLL Error loading C:\WINDOWS\system32\juvoguru.dll(first) ; .......\nilokuke.dll (second) ; .........\dalusulo.dll (third) The specified module could not be found." I can only assume that they were deleted from the Spybot and Anti-Malware runs but remained in my startup list. I can handle the error messages but I really would like some help to remove this freaking Virtumonde! I have NOT connected to the internet on the computer with the Virtumonde problem since running Malwarebytes Anti-Malware. Any help would be greatly appreciated!!! Thanks in advance! I am not computer savy if that matters. :)

Here is my Hijackthis log file.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:38:17 PM, on 1/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SMrhcn1aj0erer] C:\Program Files\rhcn1aj0erer\rhcn1aj0erer.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [QBReminderFlash] "C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [lphcj1aj0erer] C:\WINDOWS\system32\lphcj1aj0erer.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [govehapupu] Rundll32.exe "C:\WINDOWS\system32\juvoguru.dll",s
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [CPM37dee73b] Rundll32.exe "c:\windows\system32\dalusulo.dll",a
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [34edd4a7] rundll32.exe "C:\WINDOWS\system32\nilokuke.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKUS\S-1-5-19\..\Run: [govehapupu] Rundll32.exe "C:\WINDOWS\system32\juvoguru.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [govehapupu] Rundll32.exe "C:\WINDOWS\system32\juvoguru.dll",s (User 'NETWORK SERVICE')
O4 - S-1-5-18 Startup: ThingTray.lnk = C:\Program Files\ThingWorld\ThingScreenSaver\ThingTray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: ThingTray.lnk = C:\Program Files\ThingWorld\ThingScreenSaver\ThingTray.exe (User 'Default user')
O4 - Startup: ThingTray.lnk = C:\Program Files\ThingWorld\ThingScreenSaver\ThingTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} (SmartAccess Ctl Class) - https://install.charter.com/diskless/bin/ssctlsma.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - https://antivirus.uwlax.edu/WebInst/WebInst.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL c:\windows\system32\ c:\windows\system32\meyaforu.dll c:\windows\system32\ c:\windows\system32\dalusulo.dll ,
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 14913 bytes

Thanks!!!

km2357
2009-01-08, 20:28
Hello and welcome to Safer Networking.

My name is km2357 and I will be helping you to remove any infection(s) that you may have.

I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

If for any reason you do not understand an instruction or are just unsure then please do not guess, simply post back with your questions/concerns and we will go through it again.

Please do not start another thread or topic, I will assist you at this thread until we solve your problems.

Lastly the fix may take several attempts and my replies may take some time but I will stick with it if you do the same.

I will be back as soon as possible with your first instructions!

Sorry for the delay in replying, the forum is very busy. If you still need help, please post a fresh HiJackThis Log.

rhino52
2009-01-09, 20:34
Hi and thank you for the response! I still have NOT connected to the internet, since my first post, on the infected computer. Here is a fresh Hijackthis log file. Thank again for the help, it is greatly appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:27:13 PM, on 1/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\Apoint\Apntex.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SMrhcn1aj0erer] C:\Program Files\rhcn1aj0erer\rhcn1aj0erer.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [lphcj1aj0erer] C:\WINDOWS\system32\lphcj1aj0erer.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [govehapupu] Rundll32.exe "C:\WINDOWS\system32\juvoguru.dll",s
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [CPM37dee73b] Rundll32.exe "c:\windows\system32\dalusulo.dll",a
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [34edd4a7] rundll32.exe "C:\WINDOWS\system32\nilokuke.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKUS\S-1-5-19\..\Run: [govehapupu] Rundll32.exe "C:\WINDOWS\system32\juvoguru.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [govehapupu] Rundll32.exe "C:\WINDOWS\system32\juvoguru.dll",s (User 'NETWORK SERVICE')
O4 - S-1-5-18 Startup: ThingTray.lnk = C:\Program Files\ThingWorld\ThingScreenSaver\ThingTray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: ThingTray.lnk = C:\Program Files\ThingWorld\ThingScreenSaver\ThingTray.exe (User 'Default user')
O4 - Startup: ThingTray.lnk = C:\Program Files\ThingWorld\ThingScreenSaver\ThingTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} (SmartAccess Ctl Class) - https://install.charter.com/diskless/bin/ssctlsma.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - https://antivirus.uwlax.edu/WebInst/WebInst.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL c:\windows\system32\ c:\windows\system32\meyaforu.dll c:\windows\system32\ c:\windows\system32\dalusulo.dll ,
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 14724 bytes


Thanks!

km2357
2009-01-10, 00:16
I still have NOT connected to the internet, since my first post, on the infected computer.

That's fine. I'll let you know when I need to you to connect to the internet on the infected computer. Till then, you can use a flash/USB drive and a clean computer to transfer tools/programs I have you download and their logs back and forth.


Step # 1 Download CCleaner

Download CCleaner from here (http://www.ccleaner.com/) to clean temp files from your computer.

Double click on the ccsetup.exe file to start the installation of the program.
Select your language and click OK, then next.
Read the license agreement and click I Agree.
Click next to use the default install location.
Under Install Options, choose all the default settings except I would recommend that you unclick/untick install the Yahoo! Toolbar, unless you want it. You can also Uncheck the 'Automatically check for updates' box.
Click Install then finish to complete installation.


Step # 2 Retrieve the Installed Programs List from CCleaner

Open CCleaner if it's not already running.
In the Left Pane, click Tools
Verify that Uninstall is highlighted in color, or click on it.
In the lower Right, click Save to Text File.
Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
You can leave the filename as install.txt
Click Save
Exit CCleaner by clicking on the X button in the upper right of the CCleaner window.


Step # 3: Download and Run ComboFix

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

*Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

* IMPORTANT !!! Save ComboFix.exe to your Desktop

When finished, it shall produce a log for you. Please include the CCleaner Install List,C:\ComboFix.txt and a fresh HiJackThis Log in your next reply.

Use multiple posts if you can't fit everything into one post.

rhino52
2009-01-10, 02:41
Here are my three logs. I'm not sure if it matters, but I had to connect to my network in order for Combo Fix to install Recovery Console. Thanks for all your time so far!

CCleaner Install List

µTorrent
2003 Midget Car Screen Saver
7-Zip 3.13
Ad-Aware SE Personal
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Illustrator 10
Adobe Photoshop 7.0
Adobe Reader 7.0.9
Adobe SVG Viewer 3.0
Age of Empires III
Age of Empires III - The Asian Dynasties Trial
Age of Empires III - The WarChiefs
Aloha Solitaire
ALPS Touch Pad Driver
Apple Mobile Device Support
Apple Software Update
ATI Control Panel
ATI Display Driver
Bonjour
Broadcom Management Programs 2
CCleaner (remove only)
Charter High Speed Internet Self-Installation Wizard
Conexant D110 MDC V.92 Modem
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Home Systems Services Agreement
Dell Media Experience
Dell Picture Studio v3.0
Dell System Restore
DellSupport
Digital Line Detect
DivX
DivX Player
FlashGet 1.9.0.1012
GalleryPlayer Images
Get High Speed Internet!
Google Desktop
Google Desktop Plugin - GoogleCalendar
Google Earth
Google Pack Screensaver
Google Talk (remove only)
Google Toolbar for Firefox
Google Toolbar for Internet Explorer
Google Updater
Google Video Player
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
HP Image Zone 3.5
HP PSC & OfficeJet 3.5
HP Software Update
Intel(R) PROSet/Wireless Software
InterActual Player
Internal Network Card Power Management
iTunes
J2SE Runtime Environment 5.0 Update 6
Jasc Paint Shop Photo Album 5
Jasc Paint Shop Pro Studio, Dell Editon
Java 2 Runtime Environment, SE v1.4.2_03
Learn2 Player (Uninstall Only)
LG USB Modem driver
LiveUpdate 3.1 (Symantec Corporation)
Logitech SetPoint
Macromedia Dreamweaver MX
Macromedia Extension Manager
Macromedia Fireworks MX
Macromedia Flash MX
Macromedia Flash Player
Macromedia FreeHand 10
Macromedia Shockwave Player
Malwarebytes' Anti-Malware
Maxthon Browser (remove only)
McAfee SecurityCenter
Memories Disc Creator 2.0
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Professional Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Windows Journal Viewer
MobileMe Control Panel
Modem Helper
Mozilla Firefox (3.0.5)
Mozilla Thunderbird (2.0.0.6)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Musicmatch for Windows Media Player
Musicmatch® Jukebox
My Way Search Assistant
NetWaiting
NetZeroInstallers
Nokia Connectivity Adapter Cable DKU-5
Photodex Presenter
Picasa 2
Portable Media Center
PowerDVD 5.3
QuickBooks Simple Start Special Edition
QuickSet
QuickTime
Safari
SmartFTP Client
Snood for Windows version 3.52-W
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Spybot - Search & Destroy
Star Downloader Free
Symantec AntiVirus
TBS WMP Plug-in
The Axe Effect
Trillian
VideoLAN VLC media player 0.8.6f
Viewpoint Media Player
Vodei Multimedia Processor 2.10
WD Diagnostics
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
WordPerfect Office 12
Zen Portable Media Center (English)

C:\ComboFix.txt

ComboFix 09-01-08.05 - Aaron 2009-01-09 19:48:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.109 [GMT -5:00]
Running from: c:\documents and settings\Aaron\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\IE4 Error Log.txt
c:\windows\system32\bszip.dll
c:\windows\system32\udekukev.ini

----- BITS: Possible infected sites -----

hxxp://77.74.48.105
.
((((((((((((((((((((((((( Files Created from 2008-12-10 to 2009-01-10 )))))))))))))))))))))))))))))))
.

2009-01-09 19:43 . 2009-01-09 19:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\Dell
2009-01-09 19:35 . 2009-01-09 19:35 <DIR> d-------- c:\program files\CCleaner
2009-01-03 17:04 . 2009-01-03 17:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\Cingular
2009-01-03 13:28 . 2009-01-03 13:28 <DIR> d-------- c:\program files\Trend Micro
2009-01-03 12:49 . 2009-01-03 12:49 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-03 12:49 . 2009-01-03 12:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-03 12:49 . 2009-01-03 12:49 <DIR> d-------- c:\documents and settings\Aaron\Application Data\Malwarebytes
2009-01-03 12:49 . 2008-12-03 20:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-03 12:49 . 2008-12-03 20:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-10 00:57 --------- d-----w c:\program files\Symantec AntiVirus
2009-01-03 22:25 --------- d-----w c:\documents and settings\Aaron\Application Data\Aim
2009-01-03 22:23 --------- d-----w c:\program files\Common Files\Real
2009-01-03 22:02 --------- d-----w c:\program files\BitTorrent
2009-01-03 22:02 --------- d-----w c:\program files\BitComet
2009-01-03 17:13 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-02 14:40 --------- d-----w c:\program files\Google
2009-01-02 13:53 --------- d-----w c:\documents and settings\Aaron\Application Data\uTorrent
2009-01-02 04:54 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-01 18:05 --------- d-----w c:\program files\FlashGet
2008-11-25 17:54 --------- d-----w c:\program files\Safari
2008-11-22 03:35 --------- d-----w c:\program files\iTunes
2008-11-22 03:35 --------- d-----w c:\program files\iPod
2008-11-22 03:35 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-22 03:31 --------- d-----w c:\program files\QuickTime
2008-11-22 03:30 --------- d-----w c:\program files\Common Files\Apple
2008-11-21 23:12 --------- d-----w c:\documents and settings\Aaron\Application Data\DesktopKeeley.67EC435B62486C772528D0A6C46FFC4DE1624B6B.1
2008-11-21 23:11 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-11-17 23:49 --------- d-----w c:\documents and settings\Aaron\Application Data\Move Networks
2006-06-04 18:15 123,392 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-21 68856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellTransferAgent"="c:\documents and settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe" [2007-11-13 135168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 344064]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-27 125168]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2006-03-15 421888]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-03-12 11776]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 212992]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2005-09-22 303104]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-06-04 158208]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2005-02-07 606208]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 c:\windows\KHALMNPR.Exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-05-13 110592]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 16:08 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\SmartFTP\\SmartFTP.exe"=
"c:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"c:\\Program Files\\Macromedia\\Flash MX\\Flash.exe"=
"c:\\Program Files\\Macromedia\\FreeHand 10\\FreeHand 10.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9425:TCP"= 9425:TCP:BitComet 9425 TCP
"9425:UDP"= 9425:UDP:BitComet 9425 UDP

S2 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2006-09-27 116464]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376]


--- Other Services/Drivers In Memory ---

*Deregistered* - AegisP
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - APPDRV
*Deregistered* - Apple Mobile Device
*Deregistered* - Arp1394
*Deregistered* - Ati HotKey Poller
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - BITS
*Deregistered* - Bonjour Service
*Deregistered* - Browser
*Deregistered* - ccEvtMgr
*Deregistered* - ccSetMgr
*Deregistered* - Cdfs
*Deregistered* - Compbatt
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - DefWatch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - Dnscache
*Deregistered* - drvnddm
*Deregistered* - DSproct
*Deregistered* - dsunidrv
*Deregistered* - eeCtrl
*Deregistered* - EraserUtilRebootDrv
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - EvtEng
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fax
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - HTTPFilter
*Deregistered* - i2omgmt
*Deregistered* - ImapiService
*Deregistered* - IntelIde
*Deregistered* - IpNat
*Deregistered* - iPod Service
*Deregistered* - IPSec
*Deregistered* - IWCA
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - McDetect.exe
*Deregistered* - McTskshd.exe
*Deregistered* - MDM
*Deregistered* - mdmxsdk
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - NICCONFIGSVC
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - omci
*Deregistered* - PartMgr
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RegSrvc
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - S24EventMonitor
*Deregistered* - s24trans
*Deregistered* - SamSs
*Deregistered* - SavRoam
*Deregistered* - SAVRT
*Deregistered* - SAVRTPEL
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SPBBCDrv
*Deregistered* - SPBBCSvc
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - ssrtln
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - Symantec AntiVirus
*Deregistered* - SymEvent
*Deregistered* - SYMTDI
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - tfsnboio
*Deregistered* - tfsncofs
*Deregistered* - tfsndrct
*Deregistered* - tfsndres
*Deregistered* - tfsnifs
*Deregistered* - tfsnopio
*Deregistered* - tfsnpool
*Deregistered* - tfsnudf
*Deregistered* - tfsnudfa
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - upnphost
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - w32time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WLANKEEPER
*Deregistered* - WMPNetworkSvc
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - e:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{322f4256-24f3-11dd-bd9d-00114375474e}]
\Shell\AutoRun\command - e:\wd_windows_tools\setup.exe
.
Contents of the 'Scheduled Tasks' folder

2008-12-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-12-27 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (AJ-Aaron).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe []
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SMrhcn1aj0erer - c:\program files\rhcn1aj0erer\rhcn1aj0erer.exe
HKLM-Run-RealTray - c:\program files\Real\RealPlayer\RealPlay.exe
HKLM-Run-mmtask - c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe
HKLM-Run-lphcj1aj0erer - c:\windows\system32\lphcj1aj0erer.exe
HKLM-Run-govehapupu - c:\windows\system32\juvoguru.dll
HKLM-Run-CPM37dee73b - c:\windows\system32\dalusulo.dll
HKLM-Run-34edd4a7 - c:\windows\system32\nilokuke.dll
HKLM-Run-DXDllRegExe - dxdllreg.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.dell4me.com/myway
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Download with Star Downloader - c:\program files\Star Downloader\sdie.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: {{d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
Trusted Zone: online.musicmatch.com

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\Downloaded Program Files\WebInst.Dll - O16 -: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC}
hxxps://antivirus.uwlax.edu/WebInst/WebInst.cab
FF - ProfilePath - c:\documents and settings\Aaron\Application Data\Mozilla\Firefox\Profiles\00ygnw7u.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Merriam-Webster Dictionary
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\Aaron\Application Data\Mozilla\plugins\npPxPlay.dll
FF - plugin: c:\program files\BitTorrent_DNA\npbtdna.dll
FF - plugin: c:\program files\Google\Google Updater\1.1.433.23491\npCIDetect4.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-09 20:01:45
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ *NULL*ª*NULL*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ *NULL*«*NULL*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ *NULL*Í*NULL*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ *NULL*Ð*NULL*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1028)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
c:\windows\system32\ati2evxx.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\McAfee.com\Agent\Mcdetect.exe
c:\progra~1\McAfee.com\Agent\McTskshd.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Apoint\ApntEx.exe
c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\MUSICMATCH\Musicmatch Jukebox\mim.exe
c:\program files\Symantec AntiVirus\DoScan.exe
c:\progra~1\MUSICM~1\MUSICM~3\MMDiag.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\program files\Digital Line Detect\DLG.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Logitech\SetPoint\SetPoint.exe
c:\program files\Common Files\Logitech\KHAL\KHALMNPR.EXE
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-09 20:19:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-10 01:19:34

Pre-Run: 10,554,449,920 bytes free
Post-Run: 10,672,046,080 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

396 --- E O F --- 2008-12-17 21:59:04

[B]a fresh HiJackThis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:26:58 PM, on 1/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellTransferAgent] "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"
O4 - S-1-5-18 Startup: ThingTray.lnk = C:\Program Files\ThingWorld\ThingScreenSaver\ThingTray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: ThingTray.lnk = C:\Program Files\ThingWorld\ThingScreenSaver\ThingTray.exe (User 'Default user')
O4 - Startup: ThingTray.lnk = C:\Program Files\ThingWorld\ThingScreenSaver\ThingTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} (SmartAccess Ctl Class) - https://install.charter.com/diskless/bin/ssctlsma.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - https://antivirus.uwlax.edu/WebInst/WebInst.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 13734 bytes

Thanks, let me know if you want me to separate things next time!

km2357
2009-01-10, 09:23
Thanks, let me know if you want me to separate things next time!

You did a fine job spacing out the logs when you posted them. :)

A question about your Anti-Virus:

It looks like you use Norton as your Anti-Virus, but looking through the CCleaner list, I see McAfee SecurityCenter. Does McAfee SecurityCenter have an active Anti-Virus component? If so, then you need to pick between either Norton and McAfee. You should only have one active Anti-Virus at a time installed on your computer. If it is active, choose either to keep it and uninstall Norton or ditch McAfee and keep Norton.

--------------------


IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

µTorrent

I'd like you to read the Guidelines for P2P Programs (http://spywarewarrior.com/viewtopic.php?t=26216) where we explain why it's not a good idea to have them.

Also available here (http://forum.malwareremoval.com/viewtopic.php?t=23812&sid=a609c56441d8a2e5dc8d24e3e96420cc).

My recommendation is you go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).


Step # 1: Add/Remove Programs

Go to Start-Settings-Control Panel, click on Add Remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on remove. Then close the Control Panel.

My Way Search Assistant

Reboot your Computer.


Step # 2: Run CFScript


Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


KILLALL::

Folder::

c:\program files\BitTorrent
c:\program files\BitComet
c:\documents and settings\Aaron\Application Data\uTorrent
c:\Program Files\uTorrent

Registry::

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9425:TCP"=-
"9425:UDP"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{322f4256-24f3-11dd-bd9d-00114375474e}]


Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.




http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif


Note: This CFScript is for use on rhino52's computer only! Do not use it on your computer.


Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

In your next post/reply, I need to see the following:

1. The ComboFix Log that appears after Step 2 has been completed.
2. A fresh HiJackThis Log taken after Step 2 has been completed.

rhino52
2009-01-10, 20:42
It looks like you use Norton as your Anti-Virus, but looking through the CCleaner list, I see McAfee SecurityCenter. Does McAfee SecurityCenter have an active Anti-Virus component? If so, then you need to pick between either Norton and McAfee. You should only have one active Anti-Virus at a time installed on your computer. If it is active, choose either to keep it and uninstall Norton or ditch McAfee and keep Norton.

I've been trying to uninstall McAfee SecurityCenter for quite awhile now. For some reason I was able to uninstall everything but this part. I finally gave up and used selective start up to make sure McAfee would not start up when my computer did. It might not be the best solution but it has been working.


Go to Start-Settings-Control Panel, click on Add Remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on remove. Then close the Control Panel.

My Way Search Assistant

Reboot your Computer.

I tried to uninstall this program but received the following error message.
"RUNDLL
Error loading C:\PROGRA~1\MyWaySA\SrchAsDe\1.bin\desrcas.dll
The specific module could not be found."

I also uninstalled uTorrent as instructed.

My two log files will be in the next post.

Thanks!

rhino52
2009-01-10, 20:46
First part of ComboFix log

ComboFix 09-01-08.05 - Aaron 2009-01-10 13:47:36.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.103 [GMT -5:00]
Running from: c:\documents and settings\Aaron\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Aaron\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Aaron\Application Data\uTorrent
c:\documents and settings\Aaron\Application Data\uTorrent\ Bones Season 3 Episode 3 2007-10-10.1.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ Bones Season 3 Episode 3 2007-10-10.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ Bones S03E04 HDTV XViD.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ Bones S03E06 HDTV XViD-DOT.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\02.BSB.2008.R11.Silverstone.Race1.PDTV.Eurosport2.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\03.BSB.2008.R12.Brands.Hatch.Indy.Race-1.PDTV.Eurosport2.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\06.BSB.2008.R11.Silverstone.Race2.PDTV.Eurosport2.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\07.BSB.2008.R12.Brands.Hatch.Indy.Race-2.PDTV.Eurosport2.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\10,000 BC.[2008].DVDRIP.XVID.[Eng]-DUQA.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\1995 WSBK Laguna Seca.divx.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\2004 MotoGP.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\2006 MotoGP.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\2008 - Weezer (Red Album) Deluxe Edition.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\2008.Beijing.Olympics.08.20.Womens.Beach.Volleyball.Finals.HDTV.XviD-2HD.avi.1.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\2008.Beijing.Olympics.08.20.Womens.Beach.Volleyball.Finals.HDTV.XviD-2HD.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\2008.Summer.Olympics.Women's.Beach.Volleyball.USA.vs.NED.720p.HDTV.x264-NBCSUX.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\2008.TT.on-Bike.[pt1of4].ITV4.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\21[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\3 10 to Yuma[2007]DvDrip[Eng]-FXG.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\30 Rock Season 2.1.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\30 Rock Season 2.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\30.Rock.S03E01.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\30.Rock.S03E02.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\30.Rock.S03E03.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\30.Rock.S03E04.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\30.Rock.S03E04.HDTV.XviD.REPACK-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\30.Rock.S03E05.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\A.History.Of.Violence[2005]DvDrip.AC3[Eng]-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Alain Prost The Professor 1993.wmv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2006-2008.Porsche.videos.galleries.webRip.MPEG-2.English.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008-04-06.Round02.St.Petersburg.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008-04-20.Round03.Long.Beach.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008-05-18.Round04.Salt.Lake.City.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008-07-13.Round05.Lime.Rock.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008-07-20.Round06.Mid.Ohio.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008-08-09.Round07.Road.America.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008.Round.11.Laguna.Seca.NBCHD.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008.Round02.St.Petersburg.ABC.x264.English.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008.Round04.Utah.SpeedTV.x264.English.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008.Round05.Lime.Rock.Speed.MPEG-2.English.mpg.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008.Round05.Lime.Rock.SpeedTV.x264.English.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008.Round06.Mid-Ohio.NBC.x264.English.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008.Round07.Road.America.Speed.x264.English.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008.Round08.Mosport.Race.Speed.x264.English.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008.Round09.Detroit.Race.Speed.x264.English.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008.Round10.Road.Atlanta.Pt.1.Speed.x264.English.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008.Round10.Road.Atlanta.Pt.2.Speed.x264.English.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008.Round11.Laguna Seca.NBCHD.XviD.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.2008.Round8.Mosport.Speed.MPEG-2.English.mpg.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.Round2.StPete.ABC.MPEG-2.English.mpg.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ALMS.Round3.LongBeach.ABC.x264.English.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMA.SS.and.SuperbikeRace2.miller.Divx.English.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMA.Superbike.2008.Race1.VIR.Divx.English.divx.1.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMA.Superbike.2008.Race1.VIR.Divx.English.divx.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMA.Superbike.2008.Round16.Race2.VIR.Divx.English.divx.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMA.Superbike.2008.Round8.Race1.Miller.divx.divx.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMA.Superbike.Round13.MidOhio.SpeedTV.English.Divx.divx.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMA.SupersBike.2008.Round14.Race2.MidOhio.Divx.SpeedTV.English.divx.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMA.Supersport.2008.MidOhioRound.8.Divx.SpeedTV.English.divx.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMA.SuperSport.2008.Road.America.Round6.Divx.English.divx.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMA.Supersport.2008.RoadAtlanta.Divx.English.divx.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMA.Supersport.2008.Round07.Laguna.Seca.Race.SpeedTV.XviD.English.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMA.SuperSport.2008.VIR.Round9.Divx.English.divx.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMA.Supersport.Round4.2008.Sonoma.Infineon.Xvid.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMARacing.Superbike.Birmingham.Supersport.20080420.Speed.xvid.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMASB.2008.Round07.Laguna.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\AMASupersport.Round3.Fontana.DIVX.ENGLISH.divx.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bagpipes&Drums of Scotland.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Beijing.Olympics.2008.08.16.Womens.Beach.Volleyball.China.Vs.USA.Quaterfinal.HDTV.XViD-YesTV.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Benny Benassi - Hypnotica(2003) (MP3-256).torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BILLBOARD TOP 100 2001.(www.lokotorrents.com).torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones-S03E04-HDTV-XviD-XOR-eztv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones-S03E07-HDTV-XviD-NoTV-eztv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones S03E03 DSR XviD-XOR avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones S03E03 PROPER HDTV XviD-XOR[www.torrentsforall.net].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones S03E08 HDTV XviD LOL avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones Season 3.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones.S03E13.HDTV.XviD-NoTV.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones.S03E14.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones.S03E15.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones.S04E01E02.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones.S04E03.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones.S04E04.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones.S04E05.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones.S04E06.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones.S04E07.720p.HDTV.x264-CTU.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones.S04E08.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones.S04E09.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones.S04E10.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Bones.S04E11.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\British.Superbikes.2008.Round10.Croft.Race1.Eurosport2.XviD.English-std.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\British.Superbikes.2008.Round10.Croft.Race2.Eurosport2.XviD.English-std.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB 2008 Oulton Park.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.R05.Snetterton.Race-1.XviD.British.Eurosport2.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.R05.Snetterton.Race-2.XviD.British.Eurosport2.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.R10.Croft.All.Races.PDTV.Eurosport2.XviD.English-lcp.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round02.Thruxton.Race-1.XviD.British.Eurosport2.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round02.Thruxton.Race-2.XviD.British.Eurosport2.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round03.Oulton.Park.Race-2.XviD.British.Eurosport2.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round03.Oulton.Park.Race1.PDTV.Eurosport2.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round04.Brands.Hatch.Race1.PDTV.Eurosport2.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round04.Brands.Hatch.Race2.PDTV.Eurosport2.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round05.Donington.Park.Race1.PDTV.Eurosport2.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round05.Donington.Park.Race2.PDTV.Eurosport2.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round06.Mallory.Park.Race1.PDTV.Eurosport2.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round06.Mallory.Park.Race2.PDTV.Eurosport2.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round07.Oulton.Park.Race1.PDTV.Eurosport2.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round08.Knockhill.Race1.PDTV.Eurosport2.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round08.Knockhill.Race2.PDTV.Eurosport2.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round09.Cadwell.Park.Race1.PDTV.Eurosport2.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\BSB.2008.Round09.Cadwell.Park.Race2.PDTV.Eurosport2.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Burn Notice Season 2 [Complete].torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Burn.Notice.S02E01.HDTV.XviD-2HD.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Burn.Notice.S02E02.HDTV.XviD-aAF.[VTV].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Burn.Notice.S02E03.HDTV.XviD-0TV.[VTV].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Burn.Notice.S02E05.Scatter.Point.PROPER.HDTV.XviD-FQM.[VTV].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Burn.Notice.S02E06.HDTV.XviD-NoTV.[VTV].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Burn.Notice.S02E07.Rough.Seas.HDTV.XviD-FQM.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Burn.Notice.S02E08.720p.HDTV.x264-CTU.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Burn.Notice.S02E09.720p.HDTV.x264-CTU.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Burn_Notice.2x04.Comrades.HDTV_XviD-FoV.[VTV].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Busta Rhymes Ft. Linkin Park - We Made It.mp3.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Californication.S02E06.720p.HDTV.x264-2HD.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Californication.S02E07.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Californication.S02E08.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Californication.S02E09.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Californication.S02E10.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Californication.S02E11.720p.HDTV.x264-aAF.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\CART 2001 - 12 - Mid-Ohio (VHS).mpg.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Casino.Royale[2006]DvDrip[Eng]-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Chaos.Theory[2007]DvDrip.AC3-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Cherish - The Truth [2008][CD+2 SkidVid_XviD+Cov]320Kbps.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Chuck.2x02.Chuck.Versus.The.Seduction.HDTV.XviD-FoV.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Chuck.S02E01.HDTV.XViD-HiQT.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Chuck.S02E03.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Chuck.S02E04.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Chuck.S02E05.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Chuck.S02E06.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Chuck.S02E07.HDTV.XviD-E7.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Chuck.S02E08.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Chuck.S02E09.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Chuck.S02E10.Chuck.Versus.the.DeLorean.HDTV.XviD-FQM.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Club Dread (2004) - DVDRip - MP3 - ENG.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Coldplay - Viva La Vida (2008)Incl Special EditionNLT-Release.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Coldplay - Viva La Vida [2008]MP3[TCRG].torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Colin McRae Rally Legend 2007.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\CORR.2007.Rounds07-08.Antelope.Valley2.Highlights.MotorsTV.XviD.English.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\DaytonaBikeWeek.Superstock&Supersport.20080306.Speed.xvid.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Death.Race[2008][Unrated.Edition]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Deception[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Definitely,Maybe[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\dht.dat
c:\documents and settings\Aaron\Application Data\uTorrent\dht.dat.old
c:\documents and settings\Aaron\Application Data\uTorrent\Drillbit.Taylor[2008][Extended.Survival.Edition]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Eagle.Eye[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Elegy[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Entourage.S05E12.720p.HDTV.X264-DIMENSION.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Estelle - Shine [2008].torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Estelle feat. K.West - American Boy.mp3.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Eureka Season 2.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Eureka Seasons 1 & 2.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Eureka.S03E01.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Eureka.S03E02.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Eureka.S03E03.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Eureka.S03E04.HDTV.XVID-BAJSKORV.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Eureka.S03E05.HDTV.XviD-LOKi.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Eureka.S03E06.HDTV.XviD-aAF.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Eureka.S03E07.HDTV.XviD-NoTV.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Eureka.S03E08.720p.HDTV.x264-aAF.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\F1 2008-18 Brazil Interlagos Race Onboard Premiere Natural Sound Xvid by DennisF1.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\F1.2008.Round06.Monaco.Race.ITV.x264.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Fantastic.Four-Rise.Of.The.Silver.Surfer[2007]DvDrip.AC3[Eng]-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Fat Joe - Me myself and I.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Fat Joe Ft TI R.Kelly,Rick Ross,Lil Wayne & Baby - Make It Rain (Rmx)-(ThatHustle.com).mp3.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Fool's.Gold[2008]DvDrip-aXXo.1.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Fool's.Gold[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Forgetting.Sarah.Marshall[2008][Unrated.Edition]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Formula 1 Saga - Alain Prost (documentary) 227 MB.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Formula1.2008.Round13.Belgium.Race.Speed.MPEG-2.English.mpg.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Four Rooms.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\G. Love & Special Sauce.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Get.Smart[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Good Luck Chuck[2007][Unrated Edition]DvDrip[Eng]-FXG.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Gordon Highlanders - Bagpipes & Drums Of Scotland.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Hancock[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Harold.&.Kumar-Escape.From.Guantanamo.Bay[2008][Unrated.Edition]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\HIMYM - Season 1.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\History Of The TT ITV4.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Hitman.2007.CAM.XviD.NeRoZ.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\hollywellinbgvid_full.wmv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\I.Am.Legend[2007]DvDrip[Eng]-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\In.Bruges[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\In.The.Name.Of.The.King-A.Dungeon.Siege.Tale[2007]DvDrip[Eng]-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Indiana.Jones.And.The.Kingdom.Of.The.Crystal.Skull[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\IndyCar.2008.Nikon.Indy.300.Race.CH7.Xvid.English.RUSTY.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\IndyCar.2008.Round.06.Milwaukee.ABCHD.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\IndyCar.2008.Round.08.Iowa.ABCHD.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\IndyCar.2008.Round.10.Watkins.Glen.ABCHD.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\IndyCar.2008.Round.13.Edmonton.ESPNHD.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\IndyCar.2008.Round.14.Kentucky.ESPN2HD.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Indycar.2008.Round.18-Race.Surfers.Paradise.English.Seven.Xvid-neon87.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\IndyCar.2008.Round07.Texas.Race.ESPN.XviD.English.DoRY.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\IndyCar.2008.Round09.Richmond.Race.ESPN.XviD.English.DoRY.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\IndyCar.2008.Round10.Watkins.Glen.Race.ESPN.XviD.English.DoRY.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\IRL.2008.Round11.Nashville.Race.ESPN.XviD.English.DoRY.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\IRL.2008.Round12.Mid-Ohio.Race.ABCHD.x264.English-MikeyF1.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\IRL.2008.Round15.Infineon.ESPN.XviD.English.DoRY.mkv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Iron.Man[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Isle.of.Man.TT.100.Greatest.Moments.Part1.ITV4.PDTV.XviD-BKS.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Isle.of.Man.TT.100.Greatest.Moments.Part2.ITV4.PDTV.XviD-BKS.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Isle.of.Man.TT.The.Race.That.Time.Forgot.ITV4.PDTV.XviD-BKS.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Jack Johnson - Sleep Through The Static (highest quality).torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Jackie Stewart - The Flying Scott.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Jason Mraz - We Sing, We Dance, We Steal Things [2008].torrent
c:\documents and settings\Aaron\Application Data\uTorrent\John Legend - Evolver [2008][CD+SkidVid_XviD+Cov]320Kbps.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Jumper[2008]DvDrip.AC3-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Juno[2007]DvDrip[Eng]-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Justin Timberlake.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Kenna_Make Sure They See My Face.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Kevin Rudolf & Lil Wayne - Let It Rock.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Kiss.Kiss-Bang.Bang[2005]DvDrip[Eng]-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Las.Vegas.S05.HDTV.XviD-FF_INT.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ld-c.o.r.r.las.vegas.hdtv.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\ld-corr.2008.e01.pomona.hdtv.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\LIBRARIAN Quest for the spear WS ENG DVDrip (DARKTIGER).avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\LMS.2008.Round.03.Spa.Race.XviD.MotorsTV.English-armorgeddon.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\LMS.2008.Round05.Silverstone.Race.MotorsTV.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\LMS.2008.Round4.Nurburgring.Race.MotorsTV.English.French.German.Russian.NAT.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Ludo - You're Awful, I Love You.zip.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MGP_04_SA_RACE.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MIA - Kala [2007][CD+SkidVid_XviD+Cov]192Kbps.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Missy Elliott - Respect M.E. The Greatest Hits [2006] [Hip Hop] [www.file24ever.com].torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP 2006 First 12 Races.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008-07-20.Round11.USA.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008-09-28.Round15.Motegi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008-10-05.Round16.Australia.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round05.France.Qualifying.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round05.France.Race.BBC1.x264.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round05.France.Race.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round06.Italy.Mugello.PDTV.WS.BBC2.XviD.English-RU.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round06.Italy.Qualifying.PDTV.Eurosport2.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round06.Italy.Race.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round07.Spain.Barcelona.FP2.PDTV.Eurosport2.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round07.Spain.Barcelona.Qualifying.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round07.Spain.Barcelona.Race.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round07.Spain.Barcelona.Race.PDTV.WS.BBC2.XviD.English-RU.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round08.Great.Britain.Race.PDTV.BBC2.WS.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round09.Netherlands.Race.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round10.Germany.Race.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round11.USA.Laguna.Seca.Qualifying.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round11.USA.Laguna.Seca.Race.PDTV.BBC.WS.MPEG-2.English.mpg.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round12.Czech.Republic.Race.Eurosport.XviD.English-RU.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round12.Czech.Republic.Race.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round13.San.Marino.Race.PDTV.BBC.MPEG-2.English.mpg.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round13.San.Marino.Race.WS.EurosportHD.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round14.USA.Indianapolis.FP2.WS.EurosportHD.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round14.USA.Indianapolis.PDTV.WS.BBC.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round14.USA.Indianapolis.Race.WS.EurosportHD.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round14.USA.Indianpolis.Qualifying.WS.EurosportHD.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round15.Japan.Race.PDTV.BBC.WS.MPEG-2.English.mpg.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round16.Australia.Qualifying.CH10.XviD.English-VTi.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round16.Australia.Qualifying.WS.EurosportHD.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round16.Australia.Race.CH10.XviD.English-VTi.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round16.Australia.Race.PDTV.BBC.WS.MPEG-2.English.mpg.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round17.Malaysia.FP2.PDTV.Eurosport2.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round17.Malaysia.Qualifying.WS.EurosportHD.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round17.Malaysia.Race.WS.EurosportHD.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round18.Spain.Valencia.Qualifying.WS.EurosportHD.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MotoGP.2008.Round18.Spain.Valencia.Race.PDTV.BBC.WS.MPEG-2.English.mpg.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\MTV.The.Kentucky.Kid.Nicky.Hayden.xvid.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\National.Treasure.2-Book.Of.Secrets[2007]DvDrip[Eng]-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Nature.Raptor.Force.HDTV.XviD-MiRAGETV.1.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Nature.Raptor.Force.HDTV.XviD-MiRAGETV.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Nelly Discography + Tracks.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\OAR - All Sides.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Ocean's.13[2007]DvDrip[Eng]-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Oulton park 2008.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Out Cold [2001] DVDRip.XviD-LiquidNitro.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Pathology[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Pineapple.Express[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Psych S02 Season 2 Complete English Corrected TV.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Psych Season 3 Episodes 1-6.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Psych.S03E07.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Psych.S03E08.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Pussycat Dolls - PCD[SE] [2005][CD+4Vids+Covers].torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Real.Time.With.Bill.Maher.S11E08.HDTV.XviD-aAF.[VTV].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Real.Time.With.Bill.Maher.S11E09.HDTV.XviD-aAF.[VTV].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Real.Time.With.Bill.Maher.S11E10.HDTV.XviD-aAF.[VTV].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Real.Time.With.Bill.Maher.S11E11.HDTV.XviD-aAF.[VTV].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\resume.dat
c:\documents and settings\Aaron\Application Data\uTorrent\resume.dat.old
c:\documents and settings\Aaron\Application Data\uTorrent\rss.dat
c:\documents and settings\Aaron\Application Data\uTorrent\rss.dat.old
c:\documents and settings\Aaron\Application Data\uTorrent\Sahara[2005]DvDrip[Eng]-aXXo.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Season 2.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Semi-Pro[2008]DvDrip.AC3-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\settings.dat
c:\documents and settings\Aaron\Application Data\uTorrent\settings.dat.old
c:\documents and settings\Aaron\Application Data\uTorrent\shawnaleneehi918-110878_full.wmv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\shawnaleneehi920-110876_full.wmv.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Snow Patrol-A Hundred Million Suns-(Advance)-(Rabbit48).torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Snow Patrol - A Hundred Million Suns [mp3-vbr-2008].torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Step.Brothers[2008][Unrated.Edition]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Superbike.2008.Round14.Portugal.Race1.Eurosport.XviD.English-std.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Superbike.2008.Round14.Portugal.Race2.Eurosport.XviD.English-std.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\SuperBike.Magazine.November.2008.English.pdf.pdf.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\SuperBike.Magazine.October.2008.English.pdf.pdf.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Superhero Brother.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Supersport.2008.Round02.Philip.Island.Webstream.XviD.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Supersport.2008.Round14.Portugal.Eurosport.XviD.English-std.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Surfer,Dude[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\T.I. - Paper Trail [2008][CD+3 SkidVid_XviD+Cov]320Kbps.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\T.I. Discography.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Taken[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Tell Me You Love Me- Season 1.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The Assassination of Jesse James[2007]DvDrip[Eng]-FXG.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The Cooler [Eng][DVDrip].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The Killers - Day & Age - Human (Single) - 320 kbps - 2008.mp3.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The Librarian - Quest For The Spear (2004) DVDRip.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\THE LIBRARIAN II-RETURN TO KING SOLOMON`S MINES DVDRIP.AC3.6CH.2006.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\the.bagpipes.and.drums.of.scotland.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The.Bank.Job[2008]DvDrip[Eng]-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The.Colbert.Report.10.20.2008.DSR.XviD-DIMENSION.[VTV].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The.Daily.Show.10.20.2008.DSR.XviD-DIMENSION.[VTV].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The.Dark.Knight[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The.Librarian.Curse.of.Judas.Chalice.2008.HDTV.XviD-aAF.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The.Promotion[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\the.tudors.103.hdtv.xvid.notv.[VTV].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\the.tudors.104.hdtv.xvid.notv.[VTV].avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The.Tudors.S01E01.DVDRip.XviD-BSGTV.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The.Tudors.S01E02.DVDRip.XviD-BSGTV.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The_Killers-Day_And_Age-2008-404.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\The_Killers_Day_and_Age_2008-TL.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Three_6_Mafia-Most_Known_Unknown-2005-h8me.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Timbaland - Discography (3.2oo7).torrent
c:\documents and settings\Aaron\Application Data\uTorrent\TMNT[2007]DvDrip.AC3[Eng]-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\TOP 100 HipHop RnB 2008-04-19 Billboard - Torrent Tatty Feat RIAA Stars @224.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\TOP 100 Hot-Pop 2008-05-03 Billboard - Torrent Tatty Feat RIAA Stars @224.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\TOP 100 Hot-Pop 2008-06-14 Billboard - Torrent Tatty Feat RIAA Stars @224.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Traitor[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Transformers[2007]DvDrip[Eng]-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Tropic.Thunder[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Tru Calling Season1-2 (XviD asd) EnglishV+NapisyPL.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\TT.Isle.Of.Man.2008.Superbike.Race.ITV4.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Twistys - Alektra Blue.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Two Guys and a Girl.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Usher - Here I Stand [2008][CD+SkidVid_XviD+Cov]320Kbps.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\utorrent.lng
c:\documents and settings\Aaron\Application Data\uTorrent\Vantage.Point[2008]DvDrip.AC3-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Wall-E[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Wanted[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\War, Inc[2008]DvDrip[Eng]-FXG.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Weezer - Weezer (The Red Album) [2008] - Rock [www.torrentazos.com].torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Weezer (The Red Album) (320).torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Weezer Red Album_.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Welcome.to.The.Captain.S01E01.HDTV.XviD-XOR.avi.1.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Welcome.to.The.Captain.S01E01.HDTV.XviD-XOR.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Welcome.to.The.Captain.S01E02.HDTV.XviD-XOR.avi.1.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Welcome.to.The.Captain.S01E02.HDTV.XviD-XOR.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Welcome.to.The.Captain.S01E03.HDTV.XviD-XOR.avi.1.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Welcome.to.The.Captain.S01E03.HDTV.XviD-XOR.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Welcome.to.The.Captain.S01E05.HDTV.XviD-XOR.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Welcome_To_The_Captain.1x04.The_Wrecking_Crew.HDTV_XviD-FoV.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\What.Happens.In.Vegas[2008]DvDrip-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Wild.Hogs[2007]DvDrip[Eng]-aXXo.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WindTunnelWithDaveDespain.20081102.Speed.xvid.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\World.Superbike.2008.Round.14.Portimao.Race2.Live.ESP2.mp4.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\World.Superbike.Championship.2008-03-02.Round02.Australia.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\World.Superbike.Championship.2008-04-27.Round04.Assen.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\World.Superbike.Championship.2008-06-01.Round06.USA.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\World.Superbike.Championship.2008-09-21.Round12.Vallelunga.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\World.Superbike.Championship.2008-10-05.Round13.France.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\World.SuperSport.2008.R03.Spain.Valencia.Race.XviD.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\World.Supersport.2008.Round07.San.Marino.Race.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK - 2008-02-23 - Round 01 - Qatar, Losail Race 1 (1000cc).AVI.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK - 2008-04-06 - Round 03 - Spain, Valencia Race 1 (1000cc).AVI.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK - 2008-04-06 - Round 03 - Spain, Valencia Race 2 (600cc).AVI.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK - 2008-04-27 - Round 04 - Netherlands, Assen Race 1 (1000cc).AVI.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK - 2008-04-27 - Round 04 - Netherlands, Assen Race 2 (600cc).AVI.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2007.Round07.Silverstone.Race1.Eurosport.XviD.English.avi.1.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2007.Round07.Silverstone.Race1.Eurosport.XviD.English.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.R03.Valencia.Spain.Race-2.XviD.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.R06.United.States.Race-1.British.Eurosport.XviD-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.R06.United.States.Race1.SpeedTV.mpeg.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.R06.United.States.Race2.SpeedTV.mpeg.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.R06.United.States.Superpole.British.Eurosport.XviD-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.R07.Germany.Race-1.British.Eurosport.XviD-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.R07.Germany.Race-2.British.Eurosport.XviD-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round01.Qatar.Race2.PDTV.Eurosport2.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round02.Australia.Race1.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round02.Australia.Race2.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round03.Spain.Race1.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round04.Netherlands.Race1.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round04.The.Netherlands.Race2.PDTV.Eurosport2.XviD.English-RU.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round05.Italy.Monza.Race2.PDTV.Eurosport2.XviD.English-RU.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round05.Italy.Race1.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round06.USA.Race2.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round08.San.Marino.Race1.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round08.San.Marino.Race2.British.Eurosport2.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round09.Czech.Republic.Race1.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round09.Czech.Republic.Race2.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round10.Great.Britain.Race1.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round10.Great.Britain.Race2.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round11.Europe.Race1.EurosportHD.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round11.Europe.Race2.EurosportHD.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round12.Italy.Vallelunga.Race1.EurosportHD.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round12.Italy.Vallelunga.Race2.EurosportHD.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round13.France.Race1.Eurosport2.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round13.France.Race2.Eurosport2.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.2008.Round14.Portugal.Superpole.Eurosport.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.Supersport.2008.Round01.Qatar.PDTV.Eurosport2.XviD.English-RU.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.Supersport.2008.Round05.Italy.Race.PDTV.Eurosport.XviD.English-asd.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSBK.SuperSupersport.2008.Round04.Assen.Divx.English.divx.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSS.2008.11.Italy.Race.EuroSport.XviD.Eng.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\WSS.2008.Round12.France.Race.Eurosport2.XviD.English-lcp.avi.torrent
c:\documents and settings\Aaron\Application Data\uTorrent\Young.Jeezy-The.Recession-Retail-2008-[NoFS].torrent
c:\program files\BitComet
c:\program files\BitComet\BitComet.xml
c:\program files\BitComet\Downloads.xml
c:\program files\BitComet\Favourite.xml
c:\program files\BitComet\rules\dhtnodes.dat
c:\program files\BitComet\share\my_shares.xml
c:\program files\BitTorrent
c:\program files\BitTorrent\addrmap.dat
c:\program files\BitTorrent\plugin.inf

.

rhino52
2009-01-10, 20:47
Second half of ComboFix log

((((((((((((((((((((((((( Files Created from 2008-12-10 to 2009-01-10 )))))))))))))))))))))))))))))))
.

2009-01-09 19:43 . 2009-01-09 19:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\Dell
2009-01-09 19:35 . 2009-01-09 19:35 <DIR> d-------- c:\program files\CCleaner
2009-01-03 17:04 . 2009-01-03 17:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\Cingular
2009-01-03 13:28 . 2009-01-03 13:28 <DIR> d-------- c:\program files\Trend Micro
2009-01-03 12:49 . 2009-01-03 12:49 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-03 12:49 . 2009-01-03 12:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-03 12:49 . 2009-01-03 12:49 <DIR> d-------- c:\documents and settings\Aaron\Application Data\Malwarebytes
2009-01-03 12:49 . 2008-12-03 20:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-03 12:49 . 2008-12-03 20:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-10 18:55 --------- d-----w c:\program files\Symantec AntiVirus
2009-01-03 22:25 --------- d-----w c:\documents and settings\Aaron\Application Data\Aim
2009-01-03 22:23 --------- d-----w c:\program files\Common Files\Real
2009-01-03 17:13 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-02 14:40 --------- d-----w c:\program files\Google
2009-01-02 04:54 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-01 18:05 --------- d-----w c:\program files\FlashGet
2008-11-25 17:54 --------- d-----w c:\program files\Safari
2008-11-22 03:35 --------- d-----w c:\program files\iTunes
2008-11-22 03:35 --------- d-----w c:\program files\iPod
2008-11-22 03:35 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-22 03:31 --------- d-----w c:\program files\QuickTime
2008-11-22 03:30 --------- d-----w c:\program files\Common Files\Apple
2008-11-21 23:12 --------- d-----w c:\documents and settings\Aaron\Application Data\DesktopKeeley.67EC435B62486C772528D0A6C46FFC4DE1624B6B.1
2008-11-21 23:11 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-11-17 23:49 --------- d-----w c:\documents and settings\Aaron\Application Data\Move Networks
2006-06-04 18:15 123,392 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-21 68856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellTransferAgent"="c:\documents and settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe" [2007-11-13 135168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 344064]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-27 125168]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2006-03-15 421888]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-03-12 11776]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 212992]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2005-09-22 303104]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-06-04 158208]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2005-02-07 606208]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 c:\windows\KHALMNPR.Exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-05-13 110592]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 16:08 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\SmartFTP\\SmartFTP.exe"=
"c:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"c:\\Program Files\\Macromedia\\Flash MX\\Flash.exe"=
"c:\\Program Files\\Macromedia\\FreeHand 10\\FreeHand 10.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=

S2 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2006-09-27 116464]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376]


--- Other Services/Drivers In Memory ---

*Deregistered* - AegisP
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - APPDRV
*Deregistered* - Apple Mobile Device
*Deregistered* - Arp1394
*Deregistered* - Ati HotKey Poller
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - BITS
*Deregistered* - Bonjour Service
*Deregistered* - Browser
*Deregistered* - ccEvtMgr
*Deregistered* - ccSetMgr
*Deregistered* - Cdfs
*Deregistered* - Compbatt
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - DefWatch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - Dnscache
*Deregistered* - drvnddm
*Deregistered* - DSproct
*Deregistered* - dsunidrv
*Deregistered* - eeCtrl
*Deregistered* - EraserUtilRebootDrv
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - EvtEng
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fax
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - HTTPFilter
*Deregistered* - i2omgmt
*Deregistered* - ImapiService
*Deregistered* - IntelIde
*Deregistered* - IpNat
*Deregistered* - iPod Service
*Deregistered* - IPSec
*Deregistered* - IWCA
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - McDetect.exe
*Deregistered* - McTskshd.exe
*Deregistered* - MDM
*Deregistered* - mdmxsdk
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - NICCONFIGSVC
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - omci
*Deregistered* - PartMgr
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RegSrvc
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - S24EventMonitor
*Deregistered* - s24trans
*Deregistered* - SamSs
*Deregistered* - SavRoam
*Deregistered* - SAVRT
*Deregistered* - SAVRTPEL
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SPBBCDrv
*Deregistered* - SPBBCSvc
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - ssrtln
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - Symantec AntiVirus
*Deregistered* - SymEvent
*Deregistered* - SYMTDI
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - tfsnboio
*Deregistered* - tfsncofs
*Deregistered* - tfsndrct
*Deregistered* - tfsndres
*Deregistered* - tfsnifs
*Deregistered* - tfsnopio
*Deregistered* - tfsnpool
*Deregistered* - tfsnudf
*Deregistered* - tfsnudfa
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - upnphost
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - w32time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WLANKEEPER
*Deregistered* - WMPNetworkSvc
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder

2008-12-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-12-27 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (AJ-Aaron).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe []
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.dell4me.com/myway
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Download with Star Downloader - c:\program files\Star Downloader\sdie.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: {{d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
Trusted Zone: online.musicmatch.com

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\Downloaded Program Files\WebInst.Dll - O16 -: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC}
hxxps://antivirus.uwlax.edu/WebInst/WebInst.cab
FF - ProfilePath - c:\documents and settings\Aaron\Application Data\Mozilla\Firefox\Profiles\00ygnw7u.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Merriam-Webster Dictionary
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\Aaron\Application Data\Mozilla\plugins\npPxPlay.dll
FF - plugin: c:\program files\BitTorrent_DNA\npbtdna.dll
FF - plugin: c:\program files\Google\Google Updater\1.1.433.23491\npCIDetect4.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-10 13:58:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ *NULL*ª*NULL*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ *NULL*«*NULL*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ *NULL*Í*NULL*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ *NULL*Ð*NULL*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1060)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
c:\windows\system32\ati2evxx.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\McAfee.com\Agent\Mcdetect.exe
c:\progra~1\McAfee.com\Agent\McTskshd.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\Symantec AntiVirus\DoScan.exe
c:\program files\MUSICMATCH\Musicmatch Jukebox\mim.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\MUSICM~1\MUSICM~3\MMDiag.exe
c:\program files\Digital Line Detect\DLG.exe
c:\program files\Logitech\SetPoint\SetPoint.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logitech\KHAL\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2009-01-10 14:18:06 - machine was rebooted [Aaron]
ComboFix-quarantined-files.txt 2009-01-10 19:17:53
ComboFix2.txt 2009-01-10 01:19:48

Pre-Run: 10,655,264,768 bytes free
Post-Run: 10,645,856,256 bytes free

790 --- E O F --- 2008-12-17 21:59:04

rhino52
2009-01-10, 20:48
HiJackThis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:25:23 PM, on 1/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellTransferAgent] "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"
O4 - S-1-5-18 Startup: ThingTray.lnk = C:\Program Files\ThingWorld\ThingScreenSaver\ThingTray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: ThingTray.lnk = C:\Program Files\ThingWorld\ThingScreenSaver\ThingTray.exe (User 'Default user')
O4 - Startup: ThingTray.lnk = C:\Program Files\ThingWorld\ThingScreenSaver\ThingTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} (SmartAccess Ctl Class) - https://install.charter.com/diskless/bin/ssctlsma.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - https://antivirus.uwlax.edu/WebInst/WebInst.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 13744 bytes


Thanks for all you help! Let me know if you would like it posted differently for multiple posts of a log.

km2357
2009-01-11, 06:15
You did fine splitting up the ComboFix Log like you did. :)

From this post on, you can reconnect your computer to the Internet.


For getting rid of the McAfee SecurityCenter, let's do this:

Download the McAfee Consumer Products Removal tool (http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe) and save it to your Desktop.

Double-click MCPR.exe to start the removal tool and reboot your computer once it is finished.


Step # 1 Update Java

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Please follow these steps to remove older version Java components and update.

Updating Java:

Download the latest version of Java Runtime Environment (JRE) 6u11 (http://www.java.com/en/download/manual.jsp).
Click on the link to download Windows Offline Installation and save to your desktop. Do NOT use the Sun Download Manager.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Remove the following old versions of Java:


Java 2 Runtime Environment, SE v1.4.2_03

J2SE Runtime Environment 5.0 Update 6


Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.

From your desktop double-click on the download to install the newest version.


Step # 2 Run CCleaner

CCleaner will remove everything from the temp/temporary folders but please note that it will not make back ups!


Before first use, select Options > Advanced and UNCHECK Only delete files in Windows Temp folder older than 48 hours
Then select the items you wish to clean up.

In the Windows Tab:

Clean all entries in the Internet Explorer section except Cookies
Clean all the entries in the Windows Explorer section
Clean all entries in the System section
Clean all entries in the Advanced section
Clean any others that you choose

In the Applications Tab:

Clean all except cookies in the Firefox/Mozilla section if you use it
Clean all in the Opera section if you use it
Clean Sun Java in the Internet Section
Clean any others that you choose

Click the Run Cleaner button.
A pop up box will appear advising this process will permanently delete files from your system.
Click OK and it will scan and clean your system.
Click exit when done.
If it asks you to reboot at the end, click NO


Step # 3: Remove Hijackthis Entries


Run HijackThis
Click on the Scan button
Put a check beside all of the items listed below (if present):


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


Close all open windows and browsers/email, etc...
Click on the "Fix Checked" button
When completed, close the application.


Step # 4 Run Malwarebytes' Anti-Malware

Launch Malwarebytes' Anti-Malware.
Before running a scan, click the Update tab, next click Check for Updates to download any updates, if available.
Next click the Scanner tab and select Perform Quick Scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location.
You can also access the log by doing the following:

Click on the Malwarebytes' Anti-Malware icon to launch the program.
Click on the Logs tab.
Click on the log at the bottom of those listed to highlight it.
Click Open.


In your next post/reply, I need to see the following:

1. MalwareBytes' Log
2. A fresh HiJackThis Log

rhino52
2009-01-11, 18:37
I was able to get rid of McAfee with the removal tool! Thank you! :bigthumb:

MalwareBytes' Log

Malwarebytes' Anti-Malware 1.32
Database version: 1643
Windows 5.1.2600 Service Pack 3

1/11/2009 12:21:58 PM
mbam-log-2009-01-11 (12-21-58).txt

Scan type: Quick Scan
Objects scanned: 60072
Time elapsed: 8 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

HiJackThis Log after I fixed the checked problems

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:07:33 PM, on 1/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellTransferAgent] "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} (SmartAccess Ctl Class) - https://install.charter.com/diskless/bin/ssctlsma.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - https://antivirus.uwlax.edu/WebInst/WebInst.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 12471 bytes

km2357
2009-01-12, 08:39
Step # 1 Update Adobe Acrobat Reader

There is a newer version of Adobe Acrobat Reader available. (See Note below)


First, go to Add/Remove Programs and uninstall all previous versions.
Please go to this link Adobe Acrobat Reader Download Link (http://www.adobe.com/products/acrobat/readstep2.html)
On the right Untick Adobe Phototshop Album Starter Edition if you do not wish to include this in the installation.
Click the Continue button
Click Run, and click Run again
Next click the Install Now button and follow the on screen prompts

Note: Adobe 9 is a large program and if you prefer a smaller program you can get Foxit 3.0 instead from http://www.foxitsoftware.com/pdf/rd_intro.php

If you decide to install Foxit 3.0 instead of Adobe, do the following during Foxit's Setup/Installation process:

Uncheck the following boxes:

I accept the License Terms and want to install Foxit Toolbar

Make Ask.com my default search

Create desktop, quick launch and start menu icon to eBay


Step # 2: Run Kaspersky Online Scan

Please go to Kaspersky website (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) and perform an online antivirus scan.

Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Mail databases Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply.


In your next post/reply, I need to see the following:

1. Kaspersky Log
2. A fresh HiJackThis Log
3. How is your computer doing, any problems?

km2357
2009-01-14, 20:16
rhino52? How are things coming along?

rhino52
2009-01-15, 01:51
Sorry for the delay but i've only been able to run step one so far. Every time I try to log into the Kaspersky website I get a page load error. I'm guessing it's because I'm only able to try and run the scan at night during the week :sad:, so I'm hoping that I will be able to get onto the website and run the scan on Saturday. My computer seems to be running much better, as I haven't experienced any pop-ups. I do have two quick questions though.

1. Every time I start up the 'infected' computer it brings up the screen if I want to start up in recovery mode or normal mode. I don't recall this happening before, but I could be wrong. Was just curious if this is normal per the steps we have done so far.

2. Also I have a strange process running now in my process list. It is called TransferAgent.exe at PID 3504. I run process explorer to look at the processes and I haven't seen this process before. Is this a part of the process we are in or something else?

Hopefully I will be able to run the scan within the next couple of days and at the very latest this weekend. Sorry for the delay I was hoping my next post would include all the steps.

km2357
2009-01-15, 07:22
If you're unable to run Kaspersky by this weekend, let me know and I'll have you try another online scanner in its place.



1. Every time I start up the 'infected' computer it brings up the screen if I want to start up in recovery mode or normal mode. I don't recall this happening before, but I could be wrong. Was just curious if this is normal per the steps we have done so far.

This is the screen you get when you install the Recovery Console (ComboFix installed it when you first ran it). It's a normal screen, nothing to worry about. :) It's just there if you need to boot your computer into recovery mode for whatever reason.



2. Also I have a strange process running now in my process list. It is called TransferAgent.exe at PID 3504. I run process explorer to look at the processes and I haven't seen this process before. Is this a part of the process we are in or something else?


http://www.bleepingcomputer.com/startups/TransferAgent.exe-21607.html

It looks like it has something to do with Dell. I would go ahead and leave it alone.

You should be able to find the file here:

C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe

You'll need to unhide your files/folders to see it:

Reconfigure Windows XP to show hidden files:
To enable the viewing of Hidden files follow these steps:


Close all programs so that you are at your desktop.
Double-click on the My Computer icon.
Select the Tools menu and click Folder Options.
After the new window appears select the View tab.
Put a checkmark in the checkbox labeled Display the contents of system folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.
Press the Apply button and then the OK button and shutdown My Computer.
Now your computer is configured to show all hidden files.


Be sure to re-hide your files once you are finished cleaning your computer.

rhino52
2009-01-20, 04:48
I still have not been able to run Kaspersky online virus scan. I will keep trying to run it online, unless you have any other alternatives. Thanks for all your help!

km2357
2009-01-20, 08:04
Ok, let's move on to another online scanner.

Please go to Eset website (http://www.eset.com/onlinescan/) to perform an online scan. Please use Internet Explorer as it uses ActiveX.

Check (tick) this box: YES, I accept the Terms of Use.
Click on the Start button next to it.
When prompted to run ActiveX. click Yes.
You will be asked to install an ActiveX. Click Install.
Once installed, the scanner will be initialized.
After the scanner is initialized, click Start.
Uncheck (untick) Remove found threats box.
Check (tick) Scan unwanted applications.
Click on Scan.
It will start scanning. Please be patient.
Once the scan is done, you will find a log in C:\Program Files\esetonlinescanner\log.txt. Please post this log in your next reply.

rhino52
2009-01-21, 05:08
Here is the log from the Eset scan.

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3782 (20090121)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=07a9c3a1c614f144acbcde68d48eceff
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2009-01-21 04:02:45
# local_time=2009-01-20 11:02:45 (-0500, Eastern Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 3
# scanned=488265
# found=0
# scan_time=7616


And a new log file from Hijack this
# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3782 (20090121)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=07a9c3a1c614f144acbcde68d48eceff
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2009-01-21 04:02:45
# local_time=2009-01-20 11:02:45 (-0500, Eastern Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 3
# scanned=488265
# found=0
# scan_time=7616

Thanks!

rhino52
2009-01-21, 05:09
Sorry for the duplicate paste, here is the real Hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:07:57 PM, on 1/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\DOCUME~1\Aaron\LOCALS~1\Temp\Google Toolbar\gtb985B.tmp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellTransferAgent] "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} (SmartAccess Ctl Class) - https://install.charter.com/diskless/bin/ssctlsma.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - https://antivirus.uwlax.edu/WebInst/WebInst.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 12706 bytes

km2357
2009-01-21, 07:38
Both the ESET and HJT logs look clean.

If there are no other problems, you are good to go. :)

To remove ComboFix, do the following:

Go to Start > Run - type in ComboFix /u & click OK

Empty your Recycle Bin.

Please take the time to read my All Clean Post.

Please follow these simple steps in order to keep your computer clean and secure:

This is a good time to clear your existing system restore points and establish a new clean restore point

Go to Start > All Programs > Accessories > System Tools > System Restore
Select Create a restore point, and Ok it.
Next, go to Start > Run and type in cleanmgr
Make sure the C:\ drive is selected and click OK. If your computer's Hard Drive is not located on C:, change it to the correct drive letter then click OK.
Select the More options tab
Choose the option to clean up system restore and OK it.
This will remove all restore points except the new one you just created..

Clearing your restore points is not something you should do on a regular basis. Normally, this process only needs to be done after clearing out an infestation of malware.


Make your Internet Explorer more secure This can be done by following these simple instructions: From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub frames across different domains to Prompt When all these settings have been made, click on the OK button.
If it asks you if you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Set correct settings for files that should be hidden in Windows XP
Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
If unchecked please checkHide protected operating system files (Recommended)
If necessary check "Display content of system folders"
If necessary Uncheck Hide file extensions for known file types.
Click OK

Use An Antivirus Software and Keep It Updated - It is very important that your computer has an antivirus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperative that you update your antivirus software at least once a day. If you do not update your antivirus software, then it will not be able to catch any of the new variants that may come out.
Visit Microsoft's Update Site Frequently It is important that you visit Microsoft Updates (http://update.microsoft.com/) regularly. This will ensure your computer has the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Install SpywareBlaster SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
Computer Safety on line Anti Malware (http://forum.malwareremoval.com/viewtopic.php?p=54#54)
Use the hosts file: Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate web pages. We can customize a hosts file so that it blocks certain web pages. However, it can slow down certain computers. This is why using a hosts file is optional. Download mvps hosts file (http://www.mvps.org/winhelp2002/hosts.htm) Make sure you read the instructions on how to install the hosts file. There is a good tutorial HERE (http://www.bleepingcomputer.com/forums/tutorial51.html) If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button on the task bar at the bottom of your screen Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then doubleclick it. On the dropdown box, change the setting from automatic to manual. Click ok..
Use an alternative instant messenger program.Trillian (http://www.trillian.cc/) and Miranda IM (http://www.miranda-im.com/) These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
Please read Tony Klein's excellent article: How I got Infected in the First Place (http://forums.subratam.org/index.php?showtopic=5931)
Please read Understanding Spyware, Browser Hijackers, and Dialers (http://www.bleepingcomputer.com/forums/tutorial41.html)
Please read Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/tutorial82.html)
If you are using Internet Explorer, please consider using an alternate browser: Mozilla's Firefox (http://www.mozilla.org/products/firefox) or
Opera (http://www.opera.com/download/).
If you decide to use either FireFox or Opera, it is very important that you keep them up to date and check frequently for updates of the browser of your choice.
Update all these programs regularly Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
If your computer was infected by a website, a program, IM, MSN, or p2p, check this site because it is Time To Fight Back (http://spyware-free.us/2006/01/time-to-fight-back.html). Follow these steps and your potential for being infected again will reduce dramatically.

Here's a good website to read about Malware prevention:

http://users.telenet.be/bluepatchy/miekiemoes/prevention.html

If your computer is running slow, click here (http://www.malwareremoval.com/tutorials/runningslowly.php) for instructions on how to help speed up your computer.

Good luck!


Please reply one last time so that I know you have read my post and this thread can be closed.

rhino52
2009-01-22, 01:42
Thank you for all your help getting rid of the crap off my computer. The steps were easy to follow and your explanations were great. Also, thanks for the great final post! This weekend, when I finally get some free time, I will read and install everything you have within your last post. I do have a few quick questions before you can close this thread.

Do you have any suggestions on which 'free' anti-virus software out there is the best. Once I graduate from grad school I will need to give up my anti-virus software I currently have, so I'm in the market for a good one. Cost may be an issue so if there are any good ones that are free or close to it then I would be interested in your opinion on them. In that same respect what are you opinions on the anti-spyware and malware software out there? I don't need a huge list of every one of them, but maybe just a suggestion as to what you would use.

Thanks in advance!

km2357
2009-01-22, 07:27
You're welcome, I'm glad I was able to help you out. :)

As for an Anti-Virus, here are a couple of free AV's I recommend to whomever I'm helping (if they need one or ask about one):

1)Antivir PersonalEdition Classic (http://www.free-av.com/)
2)avast! 4 Home Edition (http://www.avast.com/eng/avast_4_home.html)

Download and install only one!


On the Anti-Malware/Spyware side, besides what is listed in my "All-Clean" speech, there is MalwareBytes' Anti-Malware which I had you use during the fix. I would definitely keep it installed on your computer. Its very fast in its scanning and updated frequently, at least 2-3 times a day. Its a good compliment to Spybot S&D, which you already have. :) I would go ahead and uninstall Ad-Aware SE Personal as its an old version and out of date.


Another program is WinPatrol, more info on it below:

As a robust security monitor, WinPatrol will alert you to hijackings, malware attacks and critical changes made to your computer without your permission. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge. You can download it from this website:
WinPatrol (http://www.winpatrol.com/)
The developer is a well-known man in the MalWare Removal business. If you really like WinPatrol think about upgrading to the PLUS version. It will give you additional features and you will only have to pay once, for your whole malware-free life.


Good luck and safe surfing!