PDA

View Full Version : virtumonde strikes again



Miche
2009-03-02, 22:33
Having lots of trouble with this. Began with "Spyware2009" inserted in start tray and scanned part of my c drive before I stopped it. Running spybot s&d 1.6.2 and unable to completely remove.
Laptop boots in XP and immediately a Data Execution Prevention window opens, indicating WMI program has been closed. If wireless drive is on, "IE encountered an error" window pops-up every 60 seconds, no error codes listed. I rarely use IE, this happens without (me) running it.
Eventually a Generic Host process for Win32 Services window pops-up and system shuts down.
Please help!
Thanks, Miche


HJT log
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\EtmService.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\inf\rundll33.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\dumprep.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Panasonic\CHGBMODE\ChgBmode.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Panasonic\LANPSAVE\LanPsave.exe
C:\Program Files\Panasonic\OPDOFF\opdoff.exe
C:\Program Files\Panasonic\WheelPad\Touchpad.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://thewidercircle.org/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 195.245.119.131 browser-security.microsoft.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {0294B493-7B37-400A-B69E-66B5CC94E500} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {3E42326D-4562-4C7A-B88F-2F0D42A779B5} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {A3A8512F-FDF4-4B04-8C39-C5A3911EA5D3} - C:\WINDOWS\system32\fccaApMe.dll
O2 - BHO: {55e567ff-d6cb-25da-6884-bc25b398b8ac} - {ca8b893b-52cb-4886-ad52-bc6dff765e55} - C:\WINDOWS\system32\pqzixz.dll
O2 - BHO: (no name) - {F09522A2-54AF-4D80-886D-C3D65A99C8CD} - (no file)
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Cxiwugid] rundll32.exe "C:\WINDOWS\odunahuko.dll",e
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [rundll32.exe] rundll32.exe "C:\Documents and Settings\n\Application Data\Macromedia\Common\9ddc204a1.dll""
O4 - HKLM\..\Policies\Explorer\Run: [xccinit] C:\WINDOWS\system32\inf\rundll33.exe C:\WINDOWS\xccdf16_090131a.dll xccd16
O4 - HKUS\S-1-5-19\..\Run: [rundll32.exe] rundll32.exe "C:\Documents and Settings\LocalService\Application Data\Macromedia\Common\9ddc204a1.dll"" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [rundll32.exe] rundll32.exe "C:\Documents and Settings\NetworkService\Application Data\Macromedia\Common\9ddc204a1.dll"" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Economy Mode(ECO) Setting Utility.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: LAN Power-Saving Utility.lnk = ?
O4 - Global Startup: Optical Disc Drive Power-Saving Utility.lnk = ?
O4 - Global Startup: Touch Pad Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: pqzixz
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Intel(R) Extended Thermal Model Service Application (ETMService) - Intel Corporation - C:\WINDOWS\system32\EtmService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Panasonic Opdoff Utility (OPDOFFSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
O23 - Service: Panasonic PC Information Viewer Service 2 (PcInfoPi) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
O23 - Service: Panasonic PC Information Viewer (PcInfoSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 10839 bytes

km2357
2009-03-03, 20:21
Hello and welcome to Safer Networking.

My name is km2357 and I will be helping you to remove any infection(s) that you may have.

I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

If for any reason you do not understand an instruction or are just unsure then please do not guess, simply post back with your questions/concerns and we will go through it again.

Please do not start another thread or topic, I will assist you at this thread until we solve your problems.

Lastly the fix may take several attempts and my replies may take some time but I will stick with it if you do the same.

I will be back as soon as possible with your first instructions!

km2357
2009-03-03, 20:36
Does your Spyware Doctor have an Anti-Virus with it?


Step # 1 Download CCleaner

Download CCleaner from here (http://www.ccleaner.com/) to clean temp files from your computer.

Double click on the ccsetup.exe file to start the installation of the program.
Select your language and click OK, then next.
Read the license agreement and click I Agree.
Click next to use the default install location.
Under Install Options, choose all the default settings except I would recommend that you unclick/untick install the Yahoo! Toolbar, unless you want it. You can also Uncheck the 'Automatically check for updates' box.
Click Install then finish to complete installation.


Step # 2 Retrieve the Installed Programs List from CCleaner

Open CCleaner if it's not already running.
In the Left Pane, click Tools
Verify that Uninstall is highlighted in color, or click on it.
In the lower Right, click Save to Text File.
Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
You can leave the filename as install.txt
Click Save
Exit CCleaner by clicking on the X button in the upper right of the CCleaner window.


Step # 3: Download and Run ComboFix

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

*Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

* IMPORTANT !!! Save ComboFix.exe to your Desktop

When finished, it shall produce a log for you. Please include the CCleaner Install List,C:\ComboFix.txt and a fresh HiJackThis Log in your next reply.

Use multiple posts if you can't fit everything into one post.

Miche
2009-03-05, 00:56
I have this downloaded to desktop. Per instructions I am attempting to close all windows, but am having an issue. The data execution prevention window pops up saying, "To help protect your computer, Windows has closed this program. Name: WMI Publisher: Microsoft" When I click "close message" or the X, another popup states "WMI encountered a problem and needed to close. Error ocurred on 3/2/09 at 2:46:18pm" there is a click here for more information, listing error signature:
Event Type: BEX P1:wmiprvse.exe P2: 5.1.2600.2180 P3: 41107bbd
P4: unknown P5:0.0.0.0 P6: 00000000 P7: 00b09b2f
P8: c0000005 P9: 00000008
After closing error code window and WMI encountered problem window, the entire sequence starts again.

Should I run ComboFix with the first window open?

Miche
2009-03-05, 01:01
yes, I have Spyware Doctor with AntiVirus. Here is #2, installed programs list
I'll wait for reply before running ComboFix

2007 Microsoft Office system
3ivx D4 4.5.1 Decoder (remove only)
Acronis*True*Image
Adobe Digital Editions
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Photoshop 7.0
Adobe Reader 8.1.2
Apple Software Update
AVOne MP3 Ringtone Converter
Battery Recalibration
Business Contact Manager for Outlook 2007
CCleaner (remove only)
Compatibility Pack for the 2007 Office system
CPU Idle Setting
Dell Digital Jukebox Driver
Dell DJ Explorer
DMI Viewer
Economy Mode(ECO) Setting Utility
ERUNT 1.1j
FreeMind
HashTab 2.1.1
HDAUDIO Soft Data Fax Modem with SmartCP
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotkey Appendix
Hotkey Settings
HP Photo & Imaging 3.1
HP PSC & OfficeJet 3.0
HP Software Update
HP Unload DLL Patch
InfraRecorder
Intel(R) Extended Thermal Model
Intel(R) Graphics Media Accelerator Driver
Intel(R) Matrix Storage Manager
Intel(R) PROSet/Wireless Software
InterVideo WinDVD
Java(TM) 6 Update 4
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Juice 2.2
LAN Power-Saving Utility
Loupe Utility
Macromedia Dreamweaver MX
Macromedia Extension Manager
Memories Disc Creator 2.0
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0
Microsoft Kernel-Mode Driver Framework Feature Pack 1.1
Microsoft Office 2003 Web Components
Microsoft Office 2007 Primary Interop Assemblies
Microsoft Office Accounting 2007
Microsoft Office Accounting ADP Payroll Addin
Microsoft Office Accounting Equifax Addin
Microsoft Office Accounting Fixed Asset Manager
Microsoft Office Accounting PayPal Addin
Microsoft Office Small Business Connectivity Components
Microsoft Silverlight
Microsoft SQL Server 2005
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Mozilla Firefox (3.0.6)
Mozilla Thunderbird (2.0.0.19)
OpenOffice.org 3.0
Optical Disc Drive Letter-Setting Utility
Optical Disc Drive Power-Saving Utility
Panasonic Common Components
PC Information Viewer
Picasa 3
QuickTime
RealPlayer
RegCure 1.5.2.7
SD Utility
Skype™ 3.8
Sony USB Driver
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
Spyware Doctor 6.0
Synaptics Pointing Device Driver
TBS WMP Plug-in
Touch Pad Utility
USB Power Save Mode Switching Utility
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Wireless Switch Utility
Yahoo! Browser Services
Yahoo! Internet Mail
Yahoo! Messenger

km2357
2009-03-05, 07:49
Try booting your computer into Safe Mode (You can go in Safe Mode by restarting your computer, then continually tapping F8 until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.). Once in Safe Mode, does the WMI error messages/popups still occur? If not, then go ahead and run ComboFix in Safe Mode and post back its log and a fresh HiJackThis Log in your next post.

If the WMI errors occur in Safe Mode, then let me know and don't run ComboFix.

Miche
2009-03-05, 15:38
Good morning and thanks for your help.

Booted up this morning, and no WMI popups at all. Disabled antivirus and firewall and ran ComboFix.

I am being prompted to install WINDOWS RECOVERY CONSOLE, requiring active internet connection. I have wireless adapter turned off. When connection is established, I receive Explorer error popups (IE enountered a problem and needs to close...) every 60 seconds, even without any browser open.

Please advise. Connect and install Windows Recovery Console before continuing?

Miche
2009-03-05, 15:50
Acronis True Image is installed on my machine.

km2357
2009-03-05, 20:11
When ComboFix asks you if you want to install Recovery Console, click No and let ComboFix run. I'll show you a different way of installing the Recovery Console once ComboFix has finished running.

Please post the ComboFix Log and a fresh HiJackThis Log in your next post. :)

Miche
2009-03-05, 20:59
Thanks for your patience km2357!

When running ComboFix, it food some rootkit problem and asked me to write down 6 file names in case they are needed later. I will attach in separate post. It rebooted. Then ran again and rebooted windows after the scan, but this seemed normal. While preparing the log report another error popup related to C:\Documents and Settings\n\Application\macromedia\common\9ddc20a1.dll

Here is ComboFix log
ComboFix 09-03-03.01 - n 2009-03-05 13:35:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1526.951 [GMT -6:00]
Running from: c:\documents and settings\n\Desktop\ComboFix.exe
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
c:\program files\\setup.exe
c:\windows\sysguard.exe
c:\windows\system32\config\systemprofile\Application Data\Macromedia\Common
c:\windows\system32\config\systemprofile\Application Data\Macromedia\Common\9ddc204a1.dll
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekabiwionff.sys
c:\windows\system32\eMpAaccf.ini
c:\windows\system32\eMpAaccf.ini2
c:\windows\system32\iehelper.dll
c:\windows\system32\inf\rundll33.exe
c:\windows\system32\inf\xccdfb16_090131.dll
c:\windows\system32\inf\xccefb090131.scr
c:\windows\system32\kaouyfkh.dll
c:\windows\system32\pqzixz.dll
c:\windows\system32\senekabmpfuhud.dll
c:\windows\system32\senekakkllrmhs.dat
c:\windows\system32\senekaqphcwkuv.dll
c:\windows\system32\senekaqvrrdyud.dat
c:\windows\system32\senekarrjixeto.dll
c:\windows\system32\wofbblhp.dll_old
c:\windows\xccdf16_090131a.dll
c:\windows\xccdf32_090131a.dll
c:\windows\xccwinsys.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_SENEKA


((((((((((((((((((((((((( Files Created from 2009-02-05 to 2009-03-05 )))))))))))))))))))))))))))))))
.

2009-03-04 17:44 . 2009-03-04 17:44 <DIR> d-------- c:\program files\CCleaner
2009-03-02 16:22 . 2009-03-02 16:22 <DIR> d-------- c:\program files\ERUNT
2009-03-02 15:01 . 2009-03-02 15:01 <DIR> d-------- c:\program files\RegCure
2009-03-02 14:35 . 2009-03-02 14:35 <DIR> d-------- c:\program files\Trend Micro
2009-03-02 11:59 . 2009-03-05 13:40 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-03-02 11:58 . 2009-03-05 13:39 <DIR> d-------- c:\program files\Spyware Doctor
2009-03-02 11:58 . 2009-03-02 12:01 <DIR> d-------- c:\program files\Common Files\PC Tools
2009-03-02 11:58 . 2009-03-02 11:58 <DIR> d-------- c:\documents and settings\n\Application Data\PC Tools
2009-03-02 11:58 . 2009-03-02 11:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Tools
2009-03-02 11:58 . 2008-07-28 11:29 160,792 --a------ c:\windows\system32\drivers\pctfw2.sys
2009-03-02 11:58 . 2009-03-02 12:02 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys
2009-03-02 11:58 . 2009-03-02 12:02 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys
2009-03-02 11:58 . 2009-03-02 12:02 40,840 --a------ c:\windows\system32\drivers\ikfilesec.sys
2009-03-02 11:58 . 2008-06-02 15:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys
2009-03-02 10:59 . 2009-03-02 10:59 <DIR> d-------- c:\documents and settings\All Users\Application Data\Acronis
2009-03-02 10:53 . 2004-08-04 00:56 116,224 --a--c--- c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-02 10:53 . 2001-08-17 22:36 23,040 --a--c--- c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-02 10:51 . 2001-08-17 13:28 765,884 --a--c--- c:\windows\system32\dllcache\usrti.sys
2009-03-02 10:50 . 2001-08-17 13:28 794,654 --a--c--- c:\windows\system32\dllcache\usr1801.sys
2009-03-02 10:49 . 2001-08-17 22:36 525,568 --a--c--- c:\windows\system32\dllcache\tridxp.dll
2009-03-02 10:48 . 2001-08-17 12:18 285,760 --a--c--- c:\windows\system32\dllcache\stlnata.sys
2009-03-02 10:47 . 2001-08-17 22:36 114,688 --a--c--- c:\windows\system32\dllcache\sonypi.dll
2009-03-02 10:46 . 2004-08-03 22:41 404,990 --a--c--- c:\windows\system32\dllcache\slntamr.sys
2009-03-02 10:45 . 2001-08-17 22:36 386,560 --a--c--- c:\windows\system32\dllcache\sgiul50.dll
2009-03-02 10:44 . 2001-08-17 22:36 495,616 --a--c--- c:\windows\system32\dllcache\sblfx.dll
2009-03-02 10:43 . 2001-08-17 13:28 899,146 --a--c--- c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-02 10:42 . 2004-08-04 00:56 363,520 --a--c--- c:\windows\system32\dllcache\psisdecd.dll
2009-03-02 10:42 . 2001-08-17 22:36 35,328 --a--c--- c:\windows\system32\dllcache\psisload.dll
2009-03-02 10:42 . 2004-08-04 00:56 33,280 --a--c--- c:\windows\system32\dllcache\psisrndr.ax
2009-03-02 10:42 . 2001-08-17 13:53 17,792 --a--c--- c:\windows\system32\dllcache\ppa.sys
2009-03-02 10:42 . 2004-08-03 23:00 17,664 --a--c--- c:\windows\system32\dllcache\ppa3.sys
2009-03-02 10:42 . 2001-08-17 13:51 16,128 --a--c--- c:\windows\system32\dllcache\pscr.sys
2009-03-02 10:42 . 2001-08-17 13:53 7,552 --a--c--- c:\windows\system32\dllcache\powerfil.sys
2009-03-02 10:42 . 2001-08-17 13:53 7,168 --a--c--- c:\windows\system32\dllcache\pnrmc.sys
2009-03-02 10:42 . 2001-08-17 22:36 5,632 --a--c--- c:\windows\system32\dllcache\ptpusb.dll
2009-03-02 10:36 . 2004-08-04 00:56 4,274,816 --a--c--- c:\windows\system32\dllcache\nv4_disp.dll
2009-03-02 10:35 . 2004-08-03 23:00 28,672 --a--c--- c:\windows\system32\dllcache\nscirda.sys
2009-03-02 10:35 . 2001-08-17 13:47 9,344 --a--c--- c:\windows\system32\dllcache\ntapm.sys
2009-03-02 10:35 . 2001-08-17 13:53 7,552 --a--c--- c:\windows\system32\dllcache\nsmmc.sys
2009-03-02 10:33 . 2004-08-04 00:56 1,737,856 --a--c--- c:\windows\system32\dllcache\mtxparhd.dll
2009-03-02 10:32 . 2001-08-17 22:36 58,880 --a--c--- c:\windows\system32\dllcache\m3092dc.dll
2009-03-02 10:32 . 2001-08-17 22:36 58,368 --a--c--- c:\windows\system32\dllcache\m3091dc.dll
2009-03-02 10:32 . 2001-08-17 12:19 48,768 --a--c--- c:\windows\system32\dllcache\maestro.sys
2009-03-02 10:32 . 2001-08-17 12:49 22,848 --a--c--- c:\windows\system32\dllcache\lwusbhid.sys
2009-03-02 10:32 . 2004-08-03 22:39 20,864 --a--c--- c:\windows\system32\dllcache\lwadihid.sys
2009-03-02 10:21 . 2004-08-04 00:56 152,576 --a--c--- c:\windows\system32\dllcache\irftp.exe
2009-03-02 10:21 . 2001-08-17 22:36 90,200 --a--c--- c:\windows\system32\dllcache\io8ports.dll
2009-03-02 10:21 . 2004-08-03 23:00 87,424 --a--c--- c:\windows\system32\dllcache\irda.sys
2009-03-02 10:21 . 2001-08-17 12:12 45,632 --a--c--- c:\windows\system32\dllcache\ip5515.sys
2009-03-02 10:21 . 2004-08-03 23:08 40,832 --a--c--- c:\windows\system32\dllcache\irbus.sys
2009-03-02 10:21 . 2001-08-17 13:50 38,784 --a--c--- c:\windows\system32\dllcache\io8.sys
2009-03-02 10:21 . 2004-08-04 00:56 27,136 --a--c--- c:\windows\system32\dllcache\irmon.dll
2009-03-02 10:21 . 2001-08-17 13:49 26,624 --a--c--- c:\windows\system32\dllcache\irstusb.sys
2009-03-02 10:21 . 2001-08-17 13:49 23,552 --a--c--- c:\windows\system32\dllcache\irmk7.sys
2009-03-02 10:21 . 2001-08-17 13:51 18,688 --a--c--- c:\windows\system32\dllcache\irsir.sys
2009-03-02 10:21 . 2001-08-17 13:52 16,000 --a--c--- c:\windows\system32\dllcache\ini910u.sys
2009-03-02 10:21 . 2001-08-17 13:47 13,056 --a--c--- c:\windows\system32\dllcache\inport.sys
2009-03-02 10:21 . 2004-08-03 22:59 5,504 --a--c--- c:\windows\system32\dllcache\intelide.sys
2009-03-02 10:19 . 2001-08-17 13:28 542,879 --a--c--- c:\windows\system32\dllcache\hsf_msft.sys
2009-03-02 10:18 . 2001-08-17 14:56 1,733,120 --a--c--- c:\windows\system32\dllcache\g400d.dll
2009-03-02 10:17 . 2001-08-17 13:28 595,647 --a--c--- c:\windows\system32\dllcache\es56cvmp.sys
2009-03-02 10:16 . 2001-08-17 12:14 952,007 --a--c--- c:\windows\system32\dllcache\diwan.sys
2009-03-02 10:15 . 2001-08-17 22:36 614,429 --a--c--- c:\windows\system32\dllcache\digiview.exe
2009-03-02 10:14 . 2001-08-17 12:13 980,034 --a--c--- c:\windows\system32\dllcache\cicap.sys
2009-03-02 10:13 . 2004-08-04 00:56 1,888,992 --a--c--- c:\windows\system32\dllcache\ati3duag.dll
2009-03-02 10:12 . 2001-08-17 13:28 762,780 --a--c--- c:\windows\system32\dllcache\3cwmcru.sys
2009-03-01 11:56 . 2009-03-01 11:56 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2009-03-01 11:56 . 2009-03-01 11:56 131,072 --a------ c:\windows\odunahuko.dll
2009-03-01 11:55 . 2009-03-05 13:36 <DIR> d-------- c:\windows\system32\inf
2009-03-01 11:55 . 2009-03-01 11:55 155,175 --a------ c:\windows\system32\icv.exe
2009-03-01 11:55 . 2009-03-01 11:55 155,175 --a------ c:\windows\system\xccef090131.exe
2009-03-01 11:44 . 2009-03-01 11:44 39,424 --a------ c:\windows\Tsavuqejako.dll
2009-03-01 11:28 . 2009-03-05 13:38 2,204 --a------ c:\windows\lcwrcdos

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-02 20:55 --------- d-----w c:\documents and settings\n\Application Data\Skype
2009-03-02 15:53 --------- d-----w c:\program files\Mozilla Thunderbird
2009-03-02 15:16 --------- d-----w c:\documents and settings\n\Application Data\Yahoo!
2009-03-01 21:14 --------- d-----w c:\program files\Yahoo!
2009-03-01 17:40 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-01 17:40 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-15 21:46 --------- d-----w c:\program files\FreeMind
2009-01-15 20:26 --------- d-----w c:\documents and settings\n\Application Data\Move Networks
2009-01-15 01:38 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-15 01:38 --------- d-----w c:\program files\Sony_usb
2009-01-09 16:53 --------- d-----w c:\documents and settings\n\Application Data\InfraRecorder
2009-01-09 15:52 --------- d-----w c:\program files\InfraRecorder
2009-01-09 15:48 --------- d-----w c:\program files\HashTab Shell Extension
2009-01-06 20:41 --------- d-----w c:\program files\Juice
2008-09-30 17:06 128,535,711 ----a-w c:\program files\openofficeorg1.cab
2008-09-30 16:29 9,772,544 ----a-w c:\program files\openofficeorg30.msi
2008-09-30 16:29 217 ----a-w c:\program files\setup.ini
2002-03-11 09:06 1,822,520 ----a-w c:\program files\instmsiw.exe
2002-03-11 08:45 1,708,856 ----a-w c:\program files\instmsia.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21757224]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-17 185872]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-03-15 868352]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-12 138008]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-12 138008]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-08-11 188416]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-12 162584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-04-23 149024]
"Cxiwugid"="c:\windows\odunahuko.dll" [2009-03-01 131072]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-03-02 1168264]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\n\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-04-19 113664]
Economy Mode(ECO) Setting Utility.lnk - c:\program files\Panasonic\CHGBMODE\ChgBmode.exe [2007-12-01 321168]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 233472]
LAN Power-Saving Utility.lnk - c:\program files\Panasonic\LANPSAVE\LanPsave.exe [2007-12-01 181904]
Optical Disc Drive Power-Saving Utility.lnk - c:\program files\Panasonic\OPDOFF\opdoff.exe [2007-12-01 1513104]
Touch Pad Utility.lnk - c:\program files\Panasonic\WheelPad\Touchpad.exe [2007-12-01 456336]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2009-03-02 160792]
R2 ETMService;Intel(R) Extended Thermal Model Service Application;c:\windows\system32\etmservice.exe [2007-12-01 217088]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2006-04-14 28933976]
R2 OPDOFFSV;Panasonic Opdoff Utility;c:\program files\Panasonic\OPDOFF\opdoffsv.exe [2007-12-01 206480]
R2 PcInfoPi;Panasonic PC Information Viewer Service 2;c:\program files\Panasonic\pcinfo\PCInfoPi.exe [2007-12-01 54928]
R2 PcInfoSV;Panasonic PC Information Viewer;c:\program files\Panasonic\pcinfo\PCInfoSV.exe [2007-12-01 186000]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-03-02 356920]
R2 SDKEY;Panasonic SD Misc. Function Driver;c:\program files\Panasonic\SDKEY\SDKEY.sys [2007-12-01 8192]
R3 Etm;Etm;c:\windows\system32\drivers\EtmDrvMgr.sys [2007-12-01 38528]
R3 EtmCpu;EtmCpu;c:\windows\system32\drivers\EtmDevCpu.sys [2007-12-01 19456]
R3 EtmFan;EtmFan;c:\windows\system32\drivers\EtmDevFan.sys [2007-12-01 9472]
R3 EtmGmch;EtmGmch;c:\windows\system32\drivers\EtmDevGmch.sys [2007-12-01 34304]
R3 EtmTempSense;EtmTempSense;c:\windows\system32\drivers\EtmTempSense.sys [2007-12-01 12160]
R3 HOTKEY;Panasonic Hotkey Driver;c:\windows\system32\drivers\hotkey.sys [2007-11-30 19840]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2007-11-30 36608]
R3 NewMisc;Panasonic Misc Driver;c:\windows\system32\drivers\newmisc.sys [2007-11-30 42624]
S0 lcwrcdos;lcwrcdos;c:\windows\system32\drivers\dewlywzj.sys []

--- Other Services/Drivers In Memory ---

*Deregistered* - mchInjDrv

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae60f2a6-4911-11dd-91a6-000b97dcaa47}]
\Shell\AutoRun\command - e:\system\viewer\FlipVideoforPC.exe
\Shell\Flip Video for PC\command - e:\system\viewer\FlipVideoforPC.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0d7c4f9-0fc8-11dd-913b-000b97dcaa47}]
\Shell\AutoRun\command - t.com
\Shell\explore\Command - t.com
\Shell\open\Command - t.com
.
Contents of the 'Scheduled Tasks' folder

2008-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]

2008-04-21 c:\windows\Tasks\HP DArC Task #Hewlett-Packard#hp psc 2400 series#1208782125.job
- c:\program files\HP\hpcoretech\comp\hpdarc.exe [2004-05-12 15:18]

2009-03-05 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 11:58]

2009-03-02 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 11:58]

2008-05-19 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-01-26 15:31]
.
- - - - ORPHANS REMOVED - - - -

BHO-{0294B493-7B37-400A-B69E-66B5CC94E500} - (no file)
BHO-{3E42326D-4562-4C7A-B88F-2F0D42A779B5} - (no file)
BHO-{BA233343-9EC9-4E18-89ED-5E1F13837671} - c:\windows\system32\fccaApMe.dll
BHO-{ca8b893b-52cb-4886-ad52-bc6dff765e55} - c:\windows\system32\pqzixz.dll
BHO-{F09522A2-54AF-4D80-886D-C3D65A99C8CD} - (no file)
HKCU-Run-rundll32.exe - c:\documents and settings\n\Application Data\Macromedia\Common\9ddc204a1.dll
HKLM-Run-DXDllRegExe - dxdllreg.exe
HKLM-Explorer_Run-xccinit - c:\windows\system32\inf\rundll33.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://thewidercircle.org/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
FF - ProfilePath - c:\documents and settings\n\Application Data\Mozilla\Firefox\Profiles\w67m6jac.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\n\Application Data\Mozilla\Firefox\Profiles\w67m6jac.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071301000019.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-05 13:39:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\system32\drivers\dewlywzj.sys 25088 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(996)
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-05 13:44:39 - machine was rebooted [n]
ComboFix-quarantined-files.txt 2009-03-05 19:44:35

Pre-Run: 134,198,788,096 bytes free
Post-Run: 134,150,397,952 bytes free

289

Miche
2009-03-05, 21:00
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:49:36 PM, on 3/5/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\EtmService.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Panasonic\CHGBMODE\ChgBmode.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Panasonic\LANPSAVE\LanPsave.exe
C:\Program Files\Panasonic\OPDOFF\opdoff.exe
C:\Program Files\Panasonic\WheelPad\Touchpad.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://thewidercircle.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Cxiwugid] rundll32.exe "C:\WINDOWS\odunahuko.dll",e
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Economy Mode(ECO) Setting Utility.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: LAN Power-Saving Utility.lnk = ?
O4 - Global Startup: Optical Disc Drive Power-Saving Utility.lnk = ?
O4 - Global Startup: Touch Pad Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Intel(R) Extended Thermal Model Service Application (ETMService) - Intel Corporation - C:\WINDOWS\system32\EtmService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Panasonic Opdoff Utility (OPDOFFSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
O23 - Service: Panasonic PC Information Viewer Service 2 (PcInfoPi) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
O23 - Service: Panasonic PC Information Viewer (PcInfoSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 9758 bytes

Miche
2009-03-05, 21:01
ComboFix requested I write these down . . .

c:\windows\system32\drivers\senekabiwionff.sys
c:\windows\system32\senekarrjixeto.dll
c:\windows\system32\senekaqvrrdyud.dat
c:\windows\system32\senekabmpfuhud.dll
c:\windows\system32\senekaqphcwkuv.dll
c:\windows\system32\senekakkllrmhs.dat

km2357
2009-03-05, 21:35
Ok, let's install the Recovery Console now:

Seems your missing an important part of your operating system. Let's get it reinstalled in case you ever need it.
Nothing is going to change on your computer other than we are going to reinstall the Recovery Console.


Go to Microsoft's website => http://support.microsoft.com/kb/310994

At that page, scroll down and click on the appropriate download for your version of Windows XP (Home or Professional) and the service pack level that you have installed. When you click on the link to download the file, make sure you save it directly to your desktop. If you are using Windows XP Service Pack 3 (SP3), then select the Service Pack 2 download. If you are using Windows XP Media Center, then you should select the Windows XP Pro Service Pack 2 download. If you are unsure what version of Windows you have and what Service Pack is installed, you can follow these instructions to gain that information.

Click on the Start button.

Click on the Run menu option.

In the Open: field type the following: sysdm.cpl and then click on the OK button.

A screen will appear showing information about your installation. Under the System: category you should see your Windows version and the installed Service Pack.

Now close all open windows and programs, including all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


Click and drag the setup package onto ComboFix.exe and drop it.


Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.


At the next prompt, click 'No'.

http://img.photobucket.com/albums/v706/ried7/RC_whatnext.gif


When the tool is finished, it will produce a report for you.


Step # 1: Download and Run Flash_Disinfector

Download Flash_Disinfector from here (http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe) and save it to your desktop.
Doubleclick on Flash_Disinfector.exe to run it and follow the prompts.
Wait until it has finished scanning and then exit the program.
The utility may ask you to insert your flash drive and/or other removable drives. This may include your mobile phone.
Please do so and allow the utility to clean up those drives as well.


Step # 2: Run CFScript


Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


KILLALL::

Driver::

lcwrcdos

File::

c:\windows\odunahuko.dll
c:\windows\system32\icv.exe
c:\windows\system\xccef090131.exe
c:\windows\Tsavuqejako.dll
c:\windows\lcwrcdos

RootKit::

c:\windows\system32\drivers\dewlywzj.sys

Registry::

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cxiwugid"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae60f2a6-4911-11dd-91a6-000b97dcaa47}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0d7c4f9-0fc8-11dd-913b-000b97dcaa47}]


Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.




http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif


Note: This CFScript is for use on Miche's computer only! Do not use it on your computer.


Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

In your next post/reply, I need to see the following:

1. Recovery Console Log
2. The ComboFix Log that appears after Step 2 has been completed.
3. A fresh HiJackThis Log taken after Step 2 has been completed.

Miche
2009-03-05, 21:51
I've been offline and doing installs via external drive from another (clean) laptop. Just want to double check that I should be connecting to the internet. Currently all firewall and antivirus is turned off.

thanks again!!

km2357
2009-03-06, 08:14
You can keep your computer disconnected from the Internet for now and keep downloading files/tools and transferring them over via the clean laptop and external drive. I'll let you know when to reconnect your computer back to the Internet.

Miche
2009-03-06, 16:47
I downloaded the Windows XP ProSP2 boot disk from the website you sent. I transferred to my machine via external drive and after dragging to ComboFix, that program began to run. An alert popup stated that Recovery Console was not installed, recommended doing so, and that requires internet connection.
ComboFix did the scan and then abruptly shut down, program failed to initialize. After reboot, ComboFix was preparing log report.

I did this twice, the first time selecting "yes, install Recovery Console" (which produced error box that I was not connected to internet) and the second time selecting "no" as I was not connected.

Both times there was an abrupt shut down. Attached is the last log report, I have the one run right before it too, if you need it.

ComboFix 09-03-03.01 - n 2009-03-06 9:35:04.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1526.911 [GMT -6:00]
Running from: c:\documents and settings\n\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\n\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2009-02-06 to 2009-03-06 )))))))))))))))))))))))))))))))
.

2009-03-04 17:44 . 2009-03-04 17:44 <DIR> d-------- c:\program files\CCleaner
2009-03-02 16:22 . 2009-03-02 16:22 <DIR> d-------- c:\program files\ERUNT
2009-03-02 15:01 . 2009-03-02 15:01 <DIR> d-------- c:\program files\RegCure
2009-03-02 14:35 . 2009-03-02 14:35 <DIR> d-------- c:\program files\Trend Micro
2009-03-02 11:59 . 2009-03-06 09:39 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-03-02 11:58 . 2009-03-06 09:38 <DIR> d-------- c:\program files\Spyware Doctor
2009-03-02 11:58 . 2009-03-02 12:01 <DIR> d-------- c:\program files\Common Files\PC Tools
2009-03-02 11:58 . 2009-03-02 11:58 <DIR> d-------- c:\documents and settings\n\Application Data\PC Tools
2009-03-02 11:58 . 2009-03-02 11:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Tools
2009-03-02 11:58 . 2008-07-28 11:29 160,792 --a------ c:\windows\system32\drivers\pctfw2.sys
2009-03-02 11:58 . 2009-03-02 12:02 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys
2009-03-02 11:58 . 2009-03-02 12:02 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys
2009-03-02 11:58 . 2009-03-02 12:02 40,840 --a------ c:\windows\system32\drivers\ikfilesec.sys
2009-03-02 11:58 . 2008-06-02 15:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys
2009-03-02 10:59 . 2009-03-02 10:59 <DIR> d-------- c:\documents and settings\All Users\Application Data\Acronis
2009-03-02 10:53 . 2004-08-04 00:56 116,224 --a--c--- c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-02 10:53 . 2001-08-17 22:36 23,040 --a--c--- c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-02 10:51 . 2001-08-17 13:28 765,884 --a--c--- c:\windows\system32\dllcache\usrti.sys
2009-03-02 10:50 . 2001-08-17 13:28 794,654 --a--c--- c:\windows\system32\dllcache\usr1801.sys
2009-03-02 10:49 . 2001-08-17 22:36 525,568 --a--c--- c:\windows\system32\dllcache\tridxp.dll
2009-03-02 10:48 . 2001-08-17 12:18 285,760 --a--c--- c:\windows\system32\dllcache\stlnata.sys
2009-03-02 10:47 . 2001-08-17 22:36 114,688 --a--c--- c:\windows\system32\dllcache\sonypi.dll
2009-03-02 10:46 . 2004-08-03 22:41 404,990 --a--c--- c:\windows\system32\dllcache\slntamr.sys
2009-03-02 10:45 . 2001-08-17 22:36 386,560 --a--c--- c:\windows\system32\dllcache\sgiul50.dll
2009-03-02 10:44 . 2001-08-17 22:36 495,616 --a--c--- c:\windows\system32\dllcache\sblfx.dll
2009-03-02 10:43 . 2001-08-17 13:28 899,146 --a--c--- c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-02 10:42 . 2004-08-04 00:56 363,520 --a--c--- c:\windows\system32\dllcache\psisdecd.dll
2009-03-02 10:42 . 2001-08-17 22:36 35,328 --a--c--- c:\windows\system32\dllcache\psisload.dll
2009-03-02 10:42 . 2004-08-04 00:56 33,280 --a--c--- c:\windows\system32\dllcache\psisrndr.ax
2009-03-02 10:42 . 2001-08-17 13:53 17,792 --a--c--- c:\windows\system32\dllcache\ppa.sys
2009-03-02 10:42 . 2004-08-03 23:00 17,664 --a--c--- c:\windows\system32\dllcache\ppa3.sys
2009-03-02 10:42 . 2001-08-17 13:51 16,128 --a--c--- c:\windows\system32\dllcache\pscr.sys
2009-03-02 10:42 . 2001-08-17 13:53 7,552 --a--c--- c:\windows\system32\dllcache\powerfil.sys
2009-03-02 10:42 . 2001-08-17 13:53 7,168 --a--c--- c:\windows\system32\dllcache\pnrmc.sys
2009-03-02 10:42 . 2001-08-17 22:36 5,632 --a--c--- c:\windows\system32\dllcache\ptpusb.dll
2009-03-02 10:36 . 2004-08-04 00:56 4,274,816 --a--c--- c:\windows\system32\dllcache\nv4_disp.dll
2009-03-02 10:35 . 2004-08-03 23:00 28,672 --a--c--- c:\windows\system32\dllcache\nscirda.sys
2009-03-02 10:35 . 2001-08-17 13:47 9,344 --a--c--- c:\windows\system32\dllcache\ntapm.sys
2009-03-02 10:35 . 2001-08-17 13:53 7,552 --a--c--- c:\windows\system32\dllcache\nsmmc.sys
2009-03-02 10:33 . 2004-08-04 00:56 1,737,856 --a--c--- c:\windows\system32\dllcache\mtxparhd.dll
2009-03-02 10:32 . 2001-08-17 22:36 58,880 --a--c--- c:\windows\system32\dllcache\m3092dc.dll
2009-03-02 10:32 . 2001-08-17 22:36 58,368 --a--c--- c:\windows\system32\dllcache\m3091dc.dll
2009-03-02 10:32 . 2001-08-17 12:19 48,768 --a--c--- c:\windows\system32\dllcache\maestro.sys
2009-03-02 10:32 . 2001-08-17 12:49 22,848 --a--c--- c:\windows\system32\dllcache\lwusbhid.sys
2009-03-02 10:32 . 2004-08-03 22:39 20,864 --a--c--- c:\windows\system32\dllcache\lwadihid.sys
2009-03-02 10:21 . 2004-08-04 00:56 152,576 --a--c--- c:\windows\system32\dllcache\irftp.exe
2009-03-02 10:21 . 2001-08-17 22:36 90,200 --a--c--- c:\windows\system32\dllcache\io8ports.dll
2009-03-02 10:21 . 2004-08-03 23:00 87,424 --a--c--- c:\windows\system32\dllcache\irda.sys
2009-03-02 10:21 . 2001-08-17 12:12 45,632 --a--c--- c:\windows\system32\dllcache\ip5515.sys
2009-03-02 10:21 . 2004-08-03 23:08 40,832 --a--c--- c:\windows\system32\dllcache\irbus.sys
2009-03-02 10:21 . 2001-08-17 13:50 38,784 --a--c--- c:\windows\system32\dllcache\io8.sys
2009-03-02 10:21 . 2004-08-04 00:56 27,136 --a--c--- c:\windows\system32\dllcache\irmon.dll
2009-03-02 10:21 . 2001-08-17 13:49 26,624 --a--c--- c:\windows\system32\dllcache\irstusb.sys
2009-03-02 10:21 . 2001-08-17 13:49 23,552 --a--c--- c:\windows\system32\dllcache\irmk7.sys
2009-03-02 10:21 . 2001-08-17 13:51 18,688 --a--c--- c:\windows\system32\dllcache\irsir.sys
2009-03-02 10:21 . 2001-08-17 13:52 16,000 --a--c--- c:\windows\system32\dllcache\ini910u.sys
2009-03-02 10:21 . 2001-08-17 13:47 13,056 --a--c--- c:\windows\system32\dllcache\inport.sys
2009-03-02 10:21 . 2004-08-03 22:59 5,504 --a--c--- c:\windows\system32\dllcache\intelide.sys
2009-03-02 10:19 . 2001-08-17 13:28 542,879 --a--c--- c:\windows\system32\dllcache\hsf_msft.sys
2009-03-02 10:18 . 2001-08-17 14:56 1,733,120 --a--c--- c:\windows\system32\dllcache\g400d.dll
2009-03-02 10:17 . 2001-08-17 13:28 595,647 --a--c--- c:\windows\system32\dllcache\es56cvmp.sys
2009-03-02 10:16 . 2001-08-17 12:14 952,007 --a--c--- c:\windows\system32\dllcache\diwan.sys
2009-03-02 10:15 . 2001-08-17 22:36 614,429 --a--c--- c:\windows\system32\dllcache\digiview.exe
2009-03-02 10:14 . 2001-08-17 12:13 980,034 --a--c--- c:\windows\system32\dllcache\cicap.sys
2009-03-02 10:13 . 2004-08-04 00:56 1,888,992 --a--c--- c:\windows\system32\dllcache\ati3duag.dll
2009-03-02 10:12 . 2001-08-17 13:28 762,780 --a--c--- c:\windows\system32\dllcache\3cwmcru.sys
2009-03-01 11:56 . 2009-03-01 11:56 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2009-03-01 11:56 . 2009-03-01 11:56 131,072 --a------ c:\windows\odunahuko.dll
2009-03-01 11:55 . 2009-03-05 13:36 <DIR> d-------- c:\windows\system32\inf
2009-03-01 11:55 . 2009-03-01 11:55 155,175 --a------ c:\windows\system32\icv.exe
2009-03-01 11:55 . 2009-03-01 11:55 155,175 --a------ c:\windows\system\xccef090131.exe
2009-03-01 11:44 . 2009-03-01 11:44 39,424 --a------ c:\windows\Tsavuqejako.dll
2009-03-01 11:28 . 2009-03-06 09:37 2,204 --a------ c:\windows\lcwrcdos

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-06 15:05 --------- d-----w c:\documents and settings\n\Application Data\Skype
2009-03-02 15:53 --------- d-----w c:\program files\Mozilla Thunderbird
2009-03-02 15:16 --------- d-----w c:\documents and settings\n\Application Data\Yahoo!
2009-03-01 21:14 --------- d-----w c:\program files\Yahoo!
2009-03-01 17:40 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-01 17:40 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-15 21:46 --------- d-----w c:\program files\FreeMind
2009-01-15 20:26 --------- d-----w c:\documents and settings\n\Application Data\Move Networks
2009-01-15 01:38 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-15 01:38 --------- d-----w c:\program files\Sony_usb
2009-01-09 16:53 --------- d-----w c:\documents and settings\n\Application Data\InfraRecorder
2009-01-09 15:52 --------- d-----w c:\program files\InfraRecorder
2009-01-09 15:48 --------- d-----w c:\program files\HashTab Shell Extension
2009-01-06 20:41 --------- d-----w c:\program files\Juice
2008-09-30 17:06 128,535,711 ----a-w c:\program files\openofficeorg1.cab
2008-09-30 16:29 9,772,544 ----a-w c:\program files\openofficeorg30.msi
2008-09-30 16:29 217 ----a-w c:\program files\setup.ini
2002-03-11 09:06 1,822,520 ----a-w c:\program files\instmsiw.exe
2002-03-11 08:45 1,708,856 ----a-w c:\program files\instmsia.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-03-05_13.42.46.95 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-06\ERDNT.EXE
+ 2009-03-06 15:29:05 7,286,784 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-06\Users\00000001\NTUSER.DAT
+ 2009-03-06 15:29:05 319,488 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-06\Users\00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21757224]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-17 185872]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-03-15 868352]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-12 138008]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-12 138008]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-08-11 188416]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-12 162584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-04-23 149024]
"Cxiwugid"="c:\windows\odunahuko.dll" [2009-03-01 131072]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-03-02 1168264]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\n\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-04-19 113664]
Economy Mode(ECO) Setting Utility.lnk - c:\program files\Panasonic\CHGBMODE\ChgBmode.exe [2007-12-01 321168]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 233472]
LAN Power-Saving Utility.lnk - c:\program files\Panasonic\LANPSAVE\LanPsave.exe [2007-12-01 181904]
Optical Disc Drive Power-Saving Utility.lnk - c:\program files\Panasonic\OPDOFF\opdoff.exe [2007-12-01 1513104]
Touch Pad Utility.lnk - c:\program files\Panasonic\WheelPad\Touchpad.exe [2007-12-01 456336]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2009-03-02 160792]
R2 ETMService;Intel(R) Extended Thermal Model Service Application;c:\windows\system32\etmservice.exe [2007-12-01 217088]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2006-04-14 28933976]
R2 OPDOFFSV;Panasonic Opdoff Utility;c:\program files\Panasonic\OPDOFF\opdoffsv.exe [2007-12-01 206480]
R2 PcInfoPi;Panasonic PC Information Viewer Service 2;c:\program files\Panasonic\pcinfo\PCInfoPi.exe [2007-12-01 54928]
R2 PcInfoSV;Panasonic PC Information Viewer;c:\program files\Panasonic\pcinfo\PCInfoSV.exe [2007-12-01 186000]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-03-02 356920]
R2 SDKEY;Panasonic SD Misc. Function Driver;c:\program files\Panasonic\SDKEY\SDKEY.sys [2007-12-01 8192]
R3 Etm;Etm;c:\windows\system32\drivers\EtmDrvMgr.sys [2007-12-01 38528]
R3 EtmCpu;EtmCpu;c:\windows\system32\drivers\EtmDevCpu.sys [2007-12-01 19456]
R3 EtmFan;EtmFan;c:\windows\system32\drivers\EtmDevFan.sys [2007-12-01 9472]
R3 EtmGmch;EtmGmch;c:\windows\system32\drivers\EtmDevGmch.sys [2007-12-01 34304]
R3 EtmTempSense;EtmTempSense;c:\windows\system32\drivers\EtmTempSense.sys [2007-12-01 12160]
R3 HOTKEY;Panasonic Hotkey Driver;c:\windows\system32\drivers\hotkey.sys [2007-11-30 19840]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2007-11-30 36608]
R3 NewMisc;Panasonic Misc Driver;c:\windows\system32\drivers\newmisc.sys [2007-11-30 42624]
S0 lcwrcdos;lcwrcdos;c:\windows\system32\drivers\dewlywzj.sys []

--- Other Services/Drivers In Memory ---

*Deregistered* - mchInjDrv

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae60f2a6-4911-11dd-91a6-000b97dcaa47}]
\Shell\AutoRun\command - e:\system\viewer\FlipVideoforPC.exe
\Shell\Flip Video for PC\command - e:\system\viewer\FlipVideoforPC.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0d7c4f9-0fc8-11dd-913b-000b97dcaa47}]
\Shell\AutoRun\command - t.com
\Shell\explore\Command - t.com
\Shell\open\Command - t.com
.
Contents of the 'Scheduled Tasks' folder

2008-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]

2008-04-21 c:\windows\Tasks\HP DArC Task #Hewlett-Packard#hp psc 2400 series#1208782125.job
- c:\program files\HP\hpcoretech\comp\hpdarc.exe [2004-05-12 15:18]

2009-03-06 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 11:58]

2009-03-02 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 11:58]

2008-05-19 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-01-26 15:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://thewidercircle.org/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
FF - ProfilePath - c:\documents and settings\n\Application Data\Mozilla\Firefox\Profiles\w67m6jac.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\n\Application Data\Mozilla\Firefox\Profiles\w67m6jac.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071301000019.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-06 09:38:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\system32\drivers\dewlywzj.sys 25088 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(996)
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\wscntfy.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
.
**************************************************************************
.
Completion time: 2009-03-06 9:44:02 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-06 15:43:59
ComboFix2.txt 2009-03-06 15:32:18
ComboFix3.txt 2009-03-05 19:44:50

Pre-Run: 134,004,142,080 bytes free
Post-Run: 133,988,028,416 bytes free

260

km2357
2009-03-06, 20:19
Let's hold off on installing the Recovery Console for now, we still have some cleaning to do with ComboFix. Go ahead and keep the Windows XP ProSP2 boot disk file you downloaded earlier on your Desktop as we'll be coming back to it.

Then go ahead and do Steps 1 and 2 from post 13 (http://forums.spybot.info/showpost.php?p=295134&postcount=13) of this thread. You can stay offline during these steps and remember to click No when it asks if you want to install the Recovery Console.

Post back a new ComboFix Log and a fresh HiJackThis Log in your next post.

Miche
2009-03-07, 18:27
ComboFix 09-03-03.01 - n 2009-03-07 11:13:31.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1526.956 [GMT -6:00]
Running from: c:\documents and settings\n\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\n\Desktop\CFScript.txt
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
c:\windows\lcwrcdos
c:\windows\odunahuko.dll
c:\windows\system\xccef090131.exe
c:\windows\system32\icv.exe
c:\windows\Tsavuqejako.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\lcwrcdos
c:\windows\odunahuko.dll
c:\windows\system\xccef090131.exe
c:\windows\system32\drivers\dewlywzj.sys
c:\windows\system32\icv.exe
c:\windows\Tsavuqejako.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_LCWRCDOS
-------\Service_lcwrcdos


((((((((((((((((((((((((( Files Created from 2009-02-07 to 2009-03-07 )))))))))))))))))))))))))))))))
.

2009-03-04 17:44 . 2009-03-04 17:44 <DIR> d-------- c:\program files\CCleaner
2009-03-02 16:22 . 2009-03-02 16:22 <DIR> d-------- c:\program files\ERUNT
2009-03-02 15:01 . 2009-03-02 15:01 <DIR> d-------- c:\program files\RegCure
2009-03-02 14:35 . 2009-03-02 14:35 <DIR> d-------- c:\program files\Trend Micro
2009-03-02 11:59 . 2009-03-07 11:18 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-03-02 11:58 . 2009-03-07 11:17 <DIR> d-------- c:\program files\Spyware Doctor
2009-03-02 11:58 . 2009-03-02 12:01 <DIR> d-------- c:\program files\Common Files\PC Tools
2009-03-02 11:58 . 2009-03-02 11:58 <DIR> d-------- c:\documents and settings\n\Application Data\PC Tools
2009-03-02 11:58 . 2009-03-02 11:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Tools
2009-03-02 11:58 . 2008-07-28 11:29 160,792 --a------ c:\windows\system32\drivers\pctfw2.sys
2009-03-02 11:58 . 2009-03-02 12:02 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys
2009-03-02 11:58 . 2009-03-02 12:02 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys
2009-03-02 11:58 . 2009-03-02 12:02 40,840 --a------ c:\windows\system32\drivers\ikfilesec.sys
2009-03-02 11:58 . 2008-06-02 15:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys
2009-03-02 10:59 . 2009-03-02 10:59 <DIR> d-------- c:\documents and settings\All Users\Application Data\Acronis
2009-03-02 10:53 . 2004-08-04 00:56 116,224 --a--c--- c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-02 10:53 . 2001-08-17 22:36 23,040 --a--c--- c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-02 10:51 . 2001-08-17 13:28 765,884 --a--c--- c:\windows\system32\dllcache\usrti.sys
2009-03-02 10:50 . 2001-08-17 13:28 794,654 --a--c--- c:\windows\system32\dllcache\usr1801.sys
2009-03-02 10:49 . 2001-08-17 22:36 525,568 --a--c--- c:\windows\system32\dllcache\tridxp.dll
2009-03-02 10:48 . 2001-08-17 12:18 285,760 --a--c--- c:\windows\system32\dllcache\stlnata.sys
2009-03-02 10:47 . 2001-08-17 22:36 114,688 --a--c--- c:\windows\system32\dllcache\sonypi.dll
2009-03-02 10:46 . 2004-08-03 22:41 404,990 --a--c--- c:\windows\system32\dllcache\slntamr.sys
2009-03-02 10:45 . 2001-08-17 22:36 386,560 --a--c--- c:\windows\system32\dllcache\sgiul50.dll
2009-03-02 10:44 . 2001-08-17 22:36 495,616 --a--c--- c:\windows\system32\dllcache\sblfx.dll
2009-03-02 10:43 . 2001-08-17 13:28 899,146 --a--c--- c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-02 10:42 . 2004-08-04 00:56 363,520 --a--c--- c:\windows\system32\dllcache\psisdecd.dll
2009-03-02 10:42 . 2001-08-17 22:36 35,328 --a--c--- c:\windows\system32\dllcache\psisload.dll
2009-03-02 10:42 . 2004-08-04 00:56 33,280 --a--c--- c:\windows\system32\dllcache\psisrndr.ax
2009-03-02 10:42 . 2001-08-17 13:53 17,792 --a--c--- c:\windows\system32\dllcache\ppa.sys
2009-03-02 10:42 . 2004-08-03 23:00 17,664 --a--c--- c:\windows\system32\dllcache\ppa3.sys
2009-03-02 10:42 . 2001-08-17 13:51 16,128 --a--c--- c:\windows\system32\dllcache\pscr.sys
2009-03-02 10:42 . 2001-08-17 13:53 7,552 --a--c--- c:\windows\system32\dllcache\powerfil.sys
2009-03-02 10:42 . 2001-08-17 13:53 7,168 --a--c--- c:\windows\system32\dllcache\pnrmc.sys
2009-03-02 10:42 . 2001-08-17 22:36 5,632 --a--c--- c:\windows\system32\dllcache\ptpusb.dll
2009-03-02 10:36 . 2004-08-04 00:56 4,274,816 --a--c--- c:\windows\system32\dllcache\nv4_disp.dll
2009-03-02 10:35 . 2004-08-03 23:00 28,672 --a--c--- c:\windows\system32\dllcache\nscirda.sys
2009-03-02 10:35 . 2001-08-17 13:47 9,344 --a--c--- c:\windows\system32\dllcache\ntapm.sys
2009-03-02 10:35 . 2001-08-17 13:53 7,552 --a--c--- c:\windows\system32\dllcache\nsmmc.sys
2009-03-02 10:33 . 2004-08-04 00:56 1,737,856 --a--c--- c:\windows\system32\dllcache\mtxparhd.dll
2009-03-02 10:32 . 2001-08-17 22:36 58,880 --a--c--- c:\windows\system32\dllcache\m3092dc.dll
2009-03-02 10:32 . 2001-08-17 22:36 58,368 --a--c--- c:\windows\system32\dllcache\m3091dc.dll
2009-03-02 10:32 . 2001-08-17 12:19 48,768 --a--c--- c:\windows\system32\dllcache\maestro.sys
2009-03-02 10:32 . 2001-08-17 12:49 22,848 --a--c--- c:\windows\system32\dllcache\lwusbhid.sys
2009-03-02 10:32 . 2004-08-03 22:39 20,864 --a--c--- c:\windows\system32\dllcache\lwadihid.sys
2009-03-02 10:21 . 2004-08-04 00:56 152,576 --a--c--- c:\windows\system32\dllcache\irftp.exe
2009-03-02 10:21 . 2001-08-17 22:36 90,200 --a--c--- c:\windows\system32\dllcache\io8ports.dll
2009-03-02 10:21 . 2004-08-03 23:00 87,424 --a--c--- c:\windows\system32\dllcache\irda.sys
2009-03-02 10:21 . 2001-08-17 12:12 45,632 --a--c--- c:\windows\system32\dllcache\ip5515.sys
2009-03-02 10:21 . 2004-08-03 23:08 40,832 --a--c--- c:\windows\system32\dllcache\irbus.sys
2009-03-02 10:21 . 2001-08-17 13:50 38,784 --a--c--- c:\windows\system32\dllcache\io8.sys
2009-03-02 10:21 . 2004-08-04 00:56 27,136 --a--c--- c:\windows\system32\dllcache\irmon.dll
2009-03-02 10:21 . 2001-08-17 13:49 26,624 --a--c--- c:\windows\system32\dllcache\irstusb.sys
2009-03-02 10:21 . 2001-08-17 13:49 23,552 --a--c--- c:\windows\system32\dllcache\irmk7.sys
2009-03-02 10:21 . 2001-08-17 13:51 18,688 --a--c--- c:\windows\system32\dllcache\irsir.sys
2009-03-02 10:21 . 2001-08-17 13:52 16,000 --a--c--- c:\windows\system32\dllcache\ini910u.sys
2009-03-02 10:21 . 2001-08-17 13:47 13,056 --a--c--- c:\windows\system32\dllcache\inport.sys
2009-03-02 10:21 . 2004-08-03 22:59 5,504 --a--c--- c:\windows\system32\dllcache\intelide.sys
2009-03-02 10:19 . 2001-08-17 13:28 542,879 --a--c--- c:\windows\system32\dllcache\hsf_msft.sys
2009-03-02 10:18 . 2001-08-17 14:56 1,733,120 --a--c--- c:\windows\system32\dllcache\g400d.dll
2009-03-02 10:17 . 2001-08-17 13:28 595,647 --a--c--- c:\windows\system32\dllcache\es56cvmp.sys
2009-03-02 10:16 . 2001-08-17 12:14 952,007 --a--c--- c:\windows\system32\dllcache\diwan.sys
2009-03-02 10:15 . 2001-08-17 22:36 614,429 --a--c--- c:\windows\system32\dllcache\digiview.exe
2009-03-02 10:14 . 2001-08-17 12:13 980,034 --a--c--- c:\windows\system32\dllcache\cicap.sys
2009-03-02 10:13 . 2004-08-04 00:56 1,888,992 --a--c--- c:\windows\system32\dllcache\ati3duag.dll
2009-03-02 10:12 . 2001-08-17 13:28 762,780 --a--c--- c:\windows\system32\dllcache\3cwmcru.sys
2009-03-01 11:56 . 2009-03-01 11:56 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2009-03-01 11:55 . 2009-03-05 13:36 <DIR> d-------- c:\windows\system32\inf
2009-03-01 11:28 . 2009-03-01 11:28 301,056 --a------ c:\windows\system32\fccaApMe.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-07 16:58 --------- d-----w c:\documents and settings\n\Application Data\Skype
2009-03-06 18:00 --------- d-----w c:\program files\Mozilla Thunderbird
2009-03-02 15:16 --------- d-----w c:\documents and settings\n\Application Data\Yahoo!
2009-03-01 21:14 --------- d-----w c:\program files\Yahoo!
2009-03-01 17:40 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-01 17:40 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-15 21:46 --------- d-----w c:\program files\FreeMind
2009-01-15 20:26 --------- d-----w c:\documents and settings\n\Application Data\Move Networks
2009-01-15 01:38 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-15 01:38 --------- d-----w c:\program files\Sony_usb
2009-01-09 16:53 --------- d-----w c:\documents and settings\n\Application Data\InfraRecorder
2009-01-09 15:52 --------- d-----w c:\program files\InfraRecorder
2009-01-09 15:48 --------- d-----w c:\program files\HashTab Shell Extension
2008-09-30 17:06 128,535,711 ----a-w c:\program files\openofficeorg1.cab
2008-09-30 16:29 9,772,544 ----a-w c:\program files\openofficeorg30.msi
2008-09-30 16:29 217 ----a-w c:\program files\setup.ini
2002-03-11 09:06 1,822,520 ----a-w c:\program files\instmsiw.exe
2002-03-11 08:45 1,708,856 ----a-w c:\program files\instmsia.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-03-05_13.42.46.95 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-06\ERDNT.EXE
+ 2009-03-06 15:29:05 7,286,784 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-06\Users\00000001\NTUSER.DAT
+ 2009-03-06 15:29:05 319,488 ----a-w c:\windows\ERDNT\AutoBackup\2009-03-06\Users\00000002\UsrClass.dat
+ 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-7-2009\ERDNT.EXE
+ 2009-03-07 15:58:45 7,286,784 ----a-w c:\windows\ERDNT\AutoBackup\3-7-2009\Users\00000001\NTUSER.DAT
+ 2009-03-07 15:58:46 319,488 ----a-w c:\windows\ERDNT\AutoBackup\3-7-2009\Users\00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21757224]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-17 185872]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-03-15 868352]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-12 138008]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-12 138008]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-08-11 188416]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-12 162584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-04-23 149024]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-03-02 1168264]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\n\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-04-19 113664]
Economy Mode(ECO) Setting Utility.lnk - c:\program files\Panasonic\CHGBMODE\ChgBmode.exe [2007-12-01 321168]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 233472]
LAN Power-Saving Utility.lnk - c:\program files\Panasonic\LANPSAVE\LanPsave.exe [2007-12-01 181904]
Optical Disc Drive Power-Saving Utility.lnk - c:\program files\Panasonic\OPDOFF\opdoff.exe [2007-12-01 1513104]
Touch Pad Utility.lnk - c:\program files\Panasonic\WheelPad\Touchpad.exe [2007-12-01 456336]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2009-03-02 160792]
R2 ETMService;Intel(R) Extended Thermal Model Service Application;c:\windows\system32\etmservice.exe [2007-12-01 217088]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2006-04-14 28933976]
R2 OPDOFFSV;Panasonic Opdoff Utility;c:\program files\Panasonic\OPDOFF\opdoffsv.exe [2007-12-01 206480]
R2 PcInfoPi;Panasonic PC Information Viewer Service 2;c:\program files\Panasonic\pcinfo\PCInfoPi.exe [2007-12-01 54928]
R2 PcInfoSV;Panasonic PC Information Viewer;c:\program files\Panasonic\pcinfo\PCInfoSV.exe [2007-12-01 186000]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-03-02 356920]
R2 SDKEY;Panasonic SD Misc. Function Driver;c:\program files\Panasonic\SDKEY\SDKEY.sys [2007-12-01 8192]
R3 Etm;Etm;c:\windows\system32\drivers\EtmDrvMgr.sys [2007-12-01 38528]
R3 EtmCpu;EtmCpu;c:\windows\system32\drivers\EtmDevCpu.sys [2007-12-01 19456]
R3 EtmFan;EtmFan;c:\windows\system32\drivers\EtmDevFan.sys [2007-12-01 9472]
R3 EtmGmch;EtmGmch;c:\windows\system32\drivers\EtmDevGmch.sys [2007-12-01 34304]
R3 EtmTempSense;EtmTempSense;c:\windows\system32\drivers\EtmTempSense.sys [2007-12-01 12160]
R3 HOTKEY;Panasonic Hotkey Driver;c:\windows\system32\drivers\hotkey.sys [2007-11-30 19840]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2007-11-30 36608]
R3 NewMisc;Panasonic Misc Driver;c:\windows\system32\drivers\newmisc.sys [2007-11-30 42624]

--- Other Services/Drivers In Memory ---

*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2008-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]

2008-04-21 c:\windows\Tasks\HP DArC Task #Hewlett-Packard#hp psc 2400 series#1208782125.job
- c:\program files\HP\hpcoretech\comp\hpdarc.exe [2004-05-12 15:18]

2009-03-07 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 11:58]

2009-03-02 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 11:58]

2008-05-19 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-01-26 15:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://thewidercircle.org/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
FF - ProfilePath - c:\documents and settings\n\Application Data\Mozilla\Firefox\Profiles\w67m6jac.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\n\Application Data\Mozilla\Firefox\Profiles\w67m6jac.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071301000019.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-07 11:17:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(1012)
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-07 11:21:44 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-07 17:21:41
ComboFix2.txt 2009-03-06 15:44:09
ComboFix3.txt 2009-03-06 15:32:18
ComboFix4.txt 2009-03-05 19:44:50

Pre-Run: 133,882,703,872 bytes free
Post-Run: 133,812,600,832 bytes free

268

Miche
2009-03-07, 18:28
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:22:38 AM, on 3/7/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\EtmService.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Panasonic\CHGBMODE\ChgBmode.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Panasonic\LANPSAVE\LanPsave.exe
C:\Program Files\Panasonic\OPDOFF\opdoff.exe
C:\Program Files\Panasonic\WheelPad\Touchpad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://thewidercircle.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Economy Mode(ECO) Setting Utility.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: LAN Power-Saving Utility.lnk = ?
O4 - Global Startup: Optical Disc Drive Power-Saving Utility.lnk = ?
O4 - Global Startup: Touch Pad Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Intel(R) Extended Thermal Model Service Application (ETMService) - Intel Corporation - C:\WINDOWS\system32\EtmService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Panasonic Opdoff Utility (OPDOFFSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
O23 - Service: Panasonic PC Information Viewer Service 2 (PcInfoPi) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
O23 - Service: Panasonic PC Information Viewer (PcInfoSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 9776 bytes

km2357
2009-03-07, 20:16
Reconfigure Windows XP to show hidden files:
To enable the viewing of Hidden files follow these steps:


Close all programs so that you are at your desktop.
Double-click on the My Computer icon.
Select the Tools menu and click Folder Options.
After the new window appears select the View tab.
Put a checkmark in the checkbox labeled Display the contents of system folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.
Press the Apply button and then the OK button and shutdown My Computer.
Now your computer is configured to show all hidden files.


Be sure to re-hide your files once you are finished cleaning your computer.



Registry Cleaners

Re. RegCure 1.5.2.7

I don't personally recommend the use of ANY registry cleaners.
Here is an excerpt from a discussion on regcleaners:


Most reg cleaners aren't "bad" as such, but they aren't perfect and even the best have been known to cause problems. The point we are trying to make is that the risk of using one far outweighs any benefit. If it does work perfectly you will not see any difference. If it doesn't work properly you may end up with an expensive doorstop.

http://forums.whatthetech.com/Regcleaner_t42862.html

I recommend that you uninstall RegCure 1.5.2.7 from your computer.


Step # 1 Update Java

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Please follow these steps to remove older version Java components and update.

Updating Java:

Download the latest version of Java Runtime Environment (JRE) 6u12 (http://www.java.com/en/download/manual.jsp).
Click on the link to download Windows Offline Installation and save to your desktop. Do NOT use the Sun Download Manager.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Remove the following old versions of Java:


Java(TM) 6 Update 4

Java(TM) 6 Update 5

Java(TM) 6 Update 7


Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.

From your desktop double-click on the download to install the newest version.


Step # 2 Run CCleaner

CCleaner will remove everything from the temp/temporary folders but please note that it will not make back ups!


Before first use, select Options > Advanced and UNCHECK Only delete files in Windows Temp folder older than 48 hours
Then select the items you wish to clean up.

In the Windows Tab:

Clean all entries in the Internet Explorer section except Cookies
Clean all the entries in the Windows Explorer section
Clean all entries in the System section
Clean all entries in the Advanced section
Clean any others that you choose

In the Applications Tab:

Clean all except cookies in the Firefox/Mozilla section if you use it
Clean all in the Opera section if you use it
Clean Sun Java in the Internet Section
Clean any others that you choose

Click the Run Cleaner button.
A pop up box will appear advising this process will permanently delete files from your system.
Click OK and it will scan and clean your system.
Click exit when done.
If it asks you to reboot at the end, click NO



Step # 3: Remove Hijackthis Entries


Run HijackThis
Click on the Scan button
Put a check beside all of the items listed below (if present):


O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)


Close all open windows and browsers/email, etc...
Click on the "Fix Checked" button
When completed, close the application.



Step # 4: Deleting Files/Folders

I need you to delete the file I have marked in Red(if found):

c:\windows\system32\fccaApMe.dll


Step # 5 Download and Run Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware (http://www.besttechie.net/tools/mbam-setup.exe) to your desktop.

Double-click mbam-setup.exe and follow the prompts to install the program.
Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Before running a scan, click the Update tab, next click Check for Updates to download any updates, if available.
Next click the Scanner tab and select Perform Quick Scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location.
You can also access the log by doing the following:

Click on the Malwarebytes' Anti-Malware icon to launch the program.
Click on the Logs tab.
Click on the log at the bottom of those listed to highlight it.
Click Open.


In your next post/reply, I need to see the following:

1. MalwareBytes' Log
2. A fresh HiJackThis Log

Miche
2009-03-08, 20:31
Followed all instructions. Attached are latest logs. THANKS!


Malwarebytes' Anti-Malware 1.34
Database version: 1827
Windows 5.1.2600 Service Pack 2

3/8/2009 1:19:37 PM
mbam-log-2009-03-08 (13-19-37).txt

Scan type: Quick Scan
Objects scanned: 64084
Time elapsed: 2 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\LocalService\Application Data\Macromedia\Common\9ddc204a1.dll (Hijack.Sound) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\Macromedia\Common\9ddc204a1.dll (Hijack.Sound) -> Quarantined and deleted successfully.

*****************************************************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:21:41 PM, on 3/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\EtmService.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Panasonic\CHGBMODE\ChgBmode.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Panasonic\LANPSAVE\LanPsave.exe
C:\Program Files\Panasonic\OPDOFF\opdoff.exe
C:\Program Files\Panasonic\WheelPad\Touchpad.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://thewidercircle.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Economy Mode(ECO) Setting Utility.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: LAN Power-Saving Utility.lnk = ?
O4 - Global Startup: Optical Disc Drive Power-Saving Utility.lnk = ?
O4 - Global Startup: Touch Pad Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Intel(R) Extended Thermal Model Service Application (ETMService) - Intel Corporation - C:\WINDOWS\system32\EtmService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Panasonic Opdoff Utility (OPDOFFSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
O23 - Service: Panasonic PC Information Viewer Service 2 (PcInfoPi) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
O23 - Service: Panasonic PC Information Viewer (PcInfoSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 9788 bytes

km2357
2009-03-08, 21:52
You can now reconnect your computer to the Internet.

Try installing the Recovery Console again (by dragging and dropping the setup file you downloaded into ComboFix.exe). If you're able to install Recovery Console that way then click No ComboFix asks you if you want it to scan. A log will then popup, post that in your next reponse.

If the Recovery Console doesn't install that way, just click Yes when ComboFix asks you to download/install Recovery Console and then let ComboFix run and post that log in your next response.



Step # 1 Update Adobe Acrobat Reader

There is a newer version of Adobe Acrobat Reader available. (See Note below)


First, go to Add/Remove Programs and uninstall all previous versions.
Please go to this link Adobe Acrobat Reader Download Link (http://www.adobe.com/products/acrobat/readstep2.html)
On the right Untick Adobe Phototshop Album Starter Edition if you do not wish to include this in the installation.
Click the Continue button
Click Run, and click Run again
Next click the Install Now button and follow the on screen prompts

Note: Adobe 9 is a large program and if you prefer a smaller program you can get Foxit 3.0 instead from http://www.foxitsoftware.com/pdf/rd_intro.php

If you decide to install Foxit 3.0 instead of Adobe, do the following during Foxit's Setup/Installation process:

Uncheck the following boxes:

I accept the License Terms and want to install Foxit Toolbar

Make Ask.com my default search

Create desktop, quick launch and start menu icon to eBay


Step # 2: Run Kaspersky Online Scan

Please go to Kaspersky website (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) and perform an online antivirus scan.

Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Mail databases Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply.


In your next post/reply, I need to see the following:

1. Recovery Console Log or ComboFix Log
2. Kaspersky Log
3. A fresh HiJackThis Log
4. How is your computer doing, any problems?

Miche
2009-03-09, 17:37
My computer is working great. Thanks so much. Running the Kaspersky updates took over an hour as did the actual scan, but since then everything is running smoothly. Here are the requested logs:

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect


--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, March 9, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, March 09, 2009 14:07:40
Records in database: 1882807
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\

Scan statistics:
Files scanned: 66991
Threat name: 14
Infected objects: 17
Suspicious objects: 1
Duration of the scan: 01:44:29


File name / Threat name / Threats count
C:\Documents and Settings\n\Application Data\Thunderbird\Profiles\4bpn6h9h.default\Mail\ssomail.charter.net\Inbox Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Qoobox\Quarantine\C\autorun.inf.vir Infected: Trojan-GameThief.Win32.OnLineGames.zll 1
C:\Qoobox\Quarantine\C\WINDOWS\sysguard.exe.vir Infected: Backdoor.Win32.Hupigon.gfse 1
C:\Qoobox\Quarantine\C\WINDOWS\system\xccef090131.exe.vir Infected: Trojan.Win32.Buzus.aocw 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\senekabiwionff.sys.vir Infected: Rootkit.Win32.TDSS.phm 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_dewlywzj_.sys.zip Infected: Rootkit.Win32.Agent.hqh 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\icv.exe.vir Infected: Trojan.Win32.Buzus.aocw 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\iehelper.dll.vir Infected: Trojan.Win32.FraudPack.kho 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\inf\xccdfb16_090131.dll.vir Infected: Trojan-Spy.Win32.Pophot.gzv 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\inf\xccefb090131.scr.vir Infected: Trojan.Win32.Buzus.aocw 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\kaouyfkh.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.kgx 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\pqzixz.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.kgx 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekabmpfuhud.dll.vir Infected: Rootkit.Win32.Agent.hcr 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekaqphcwkuv.dll.vir Infected: Rootkit.Win32.Agent.hcq 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekarrjixeto.dll.vir Infected: Rootkit.Win32.TDSS.cf 1
C:\Qoobox\Quarantine\C\WINDOWS\Tsavuqejako.dll.vir Infected: Trojan-Downloader.Win32.Agent.bkaf 1
C:\Qoobox\Quarantine\C\WINDOWS\xccdf16_090131a.dll.vir Infected: Trojan-Spy.Win32.Pophot.gzv 1
C:\Qoobox\Quarantine\C\WINDOWS\xccdf32_090131a.dll.vir Infected: Trojan-Spy.Win32.Pophot.gzu 1

The selected area was scanned.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:31:53 AM, on 3/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\EtmService.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Panasonic\CHGBMODE\ChgBmode.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Panasonic\LANPSAVE\LanPsave.exe
C:\Program Files\Panasonic\OPDOFF\opdoff.exe
C:\Program Files\Panasonic\WheelPad\Touchpad.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://thewidercircle.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Uninstall getPlus(R) for Adobe] "C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1noarp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Economy Mode(ECO) Setting Utility.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: LAN Power-Saving Utility.lnk = ?
O4 - Global Startup: Optical Disc Drive Power-Saving Utility.lnk = ?
O4 - Global Startup: Touch Pad Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Intel(R) Extended Thermal Model Service Application (ETMService) - Intel Corporation - C:\WINDOWS\system32\EtmService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Panasonic Opdoff Utility (OPDOFFSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
O23 - Service: Panasonic PC Information Viewer Service 2 (PcInfoPi) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
O23 - Service: Panasonic PC Information Viewer (PcInfoSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 9932 bytes

Miche
2009-03-09, 17:41
when we're all through, I definitely have questions about:
1. Uninstalling SpyDoctor and using Avira
2. WD Passport external drive. How to stop autorun and scan first.
3. which of the threads on anti virus/malware best practices you recommend.

Thanks again. Miche

km2357
2009-03-09, 19:22
The majority of files Kaspersky found were in the Qoobox folder which is where ComboFix keeps its quarantined files. I'll be having you remove those files and ComboFix shortly.

Open up Mozilla Thunderbird and delete any e-mails you no longer need that are in your Inbox. Also delete e-mails in your Junk/Bulk/Spam Folder as well.



when we're all through, I definitely have questions about:
1. Uninstalling SpyDoctor and using Avira
2. WD Passport external drive. How to stop autorun and scan first.
3. which of the threads on anti virus/malware best practices you recommend.

Go ahead and ask your questions. :)

Miche
2009-03-09, 21:52
Thunderbird all nice and clean now.

I would like to know your recommendations for general housekeeping, as well as best anti-virus and firewalls to use. Reading through the forums, there are different programs being recommended. With this machine I have had SpyDoctor antivirus running and then running Spybot S&D every couple of weeks. Another one I use regularly, I run Avira and then S&D every so often. Both have the windows firewall enabled. My thought is to dump SpyDoctor (I have the free version) and use Avira. Others have suggested a stand alone firewall (ZoneAlarm). What do you think? Are there others to consider? Also, what maintenance, cleaning tasks do you suggest?

I thought I was being careful, however . . .

I use an external hard drive all of the time and plug it in all over the place. Most recently I have been traveling for 6 weeks, using it in a variety of Mexican internet cafes. An issue I have is the Autoplay feature zips through before I have a chance to scan it. Is that a problem (can bad things be transferred that way) or is it enough to scan it before opening any files?

I have a 15 year old who uses one of my machines; not this one that got infected however. I know I only have so much control over what he does. I do not know much about the parental control stuff, having only thought of it in terms of spying on your kids. Now of course I think about it from a different stand point - protecting our computer. Any advice there? How do you take into account others who have access?

I have read and shared the "how did I get infected" thread. Anything else we should be keeping in mind?

Thanks and look forward to your thoughts!
miche

km2357
2009-03-10, 07:40
I would like to know your recommendations for general housekeeping, as well as best anti-virus and firewalls to use. Reading through the forums, there are different programs being recommended. With this machine I have had SpyDoctor antivirus running and then running Spybot S&D every couple of weeks. Another one I use regularly, I run Avira and then S&D every so often. Both have the windows firewall enabled. My thought is to dump SpyDoctor (I have the free version) and use Avira. Others have suggested a stand alone firewall (ZoneAlarm). What do you think? Are there others to consider? Also, what maintenance, cleaning tasks do you suggest?

Avira is a good Anti-Virus to use. It is one that I recommend to those I help that don't have an Anti-Virus program installed on their computer. Another one I recommend is Avast (http://www.avast.com/eng/avast_4_home.html). I would visit each companies website and compare the two AVs and see which one you like best. Once you have decided on which you want, download it. Then disconnect from the Internet and uninstall Spyware Doctor with AV. Then install your new AV, then reconnect to the Internet to update it.

As for firewalls, here are some of that I recommend to those I help:


Jetico Personal Firewall (http://www.jetico.com/jpf2.htm)
Soft perfect (http://www.softperfect.com/products/firewall/)
Sunbelt Kerio Firewall (http://www.sunbelt-software.com/Kerio-Download.cfm)

Please download and install only one!

If you choose to go with one of these Firewalls, then you'll need to disable Windows's Firewall. You can do that by doing the following:

1. Click Start, click Run, type Firewall.cpl, and then click OK.
2. On the General tab, check to see if Off (not recommended) is checkmarked/ticked, if it is not, then checkmark/tick the box and click OK

As for maintenance/cleanup, I would run CCleaner at least every 2 weeks to help keep your computer clean of junk/temp files. I would run MalwareBytes' (in conjuction with Spybot) every 2 weeks as well. Be sure to update it before each Quick Scan. I would also defrag your computer if you haven't already (since you got it) and then defrag it once every 6 months or so.

I'll also be giving you some other programs to download and tips to follow in my "All-Clean" speech, which will be at the bottom of this post.



I use an external hard drive all of the time and plug it in all over the place. Most recently I have been traveling for 6 weeks, using it in a variety of Mexican internet cafes. An issue I have is the Autoplay feature zips through before I have a chance to scan it. Is that a problem (can bad things be transferred that way) or is it enough to scan it before opening any files?

Yes, if you plug your external hard drive into an infected machine, malicious infected files can and often will infect your Hard Drive. In order to stop that from happening, you need to stop Autorun when plugging in your external HD. To do that, press and hold down the Shift Key before you plug your external HD and that will disable Autorun. You can then scan your external HD with Spybot, MalwareBytes' and your AV program. And once you are done using it, I would scan the HD again (especially the files you transfered to it) incase something got through. That way you can stop anything/something bad from happening when you plug the external HD into your own computer.


I have a 15 year old who uses one of my machines; not this one that got infected however. I know I only have so much control over what he does. I do not know much about the parental control stuff, having only thought of it in terms of spying on your kids. Now of course I think about it from a different stand point - protecting our computer. Any advice there? How do you take into account others who have access?

Its up to you if you want to install parental controls on your computer. Here's a google search (http://www.google.com/search?hl=en&q=parental+control+software&aq=1&oq=parental+con) of some of them for you to look over and do some research on them.

Using them is based on your son. After he uses the computer is it still clean? Or do you have to clean it (run AV, run Spybot, etc) after everytime he uses it? A good idea if you don't want to install parental control software is to share some of the information you'll find in the links below in my All-Clean speech. Talk to him about computer security and why its important not to visit certain websites or click on every pop-up/link you see on the Internet. If you instill good Internet surfing habits into him now, it will pay off in the future. :)


I have read and shared the "how did I get infected" thread. Anything else we should be keeping in mind?

I will be posting some links for you to read through in my All-Clean speech will help you keep your computer clean.

-----------------------------------------

Since there are no other problems, you are good to go. :)

To remove ComboFix, do the following:

Go to Start > Run - type in ComboFix /u & click OK


You can also delete Flash_Disinfector.exe off of your computer.


Empty your Recycle Bin.


Please take the time to read my All Clean Post.

Please follow these simple steps in order to keep your computer clean and secure:

This is a good time to clear your existing system restore points and establish a new clean restore point

Go to Start > All Programs > Accessories > System Tools > System Restore
Select Create a restore point, and Ok it.
Next, go to Start > Run and type in cleanmgr
Make sure the C:\ drive is selected and click OK. If your computer's Hard Drive is not located on C:, change it to the correct drive letter then click OK.
Select the More options tab
Choose the option to clean up system restore and OK it.
This will remove all restore points except the new one you just created..

Clearing your restore points is not something you should do on a regular basis. Normally, this process only needs to be done after clearing out an infestation of malware.


Make your Internet Explorer more secure This can be done by following these simple instructions: From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub frames across different domains to Prompt When all these settings have been made, click on the OK button.
If it asks you if you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Set correct settings for files that should be hidden in Windows XP
Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
If unchecked please checkHide protected operating system files (Recommended)
If necessary check "Display content of system folders"
If necessary Uncheck Hide file extensions for known file types.
Click OK

Use An Antivirus Software and Keep It Updated - It is very important that your computer has an antivirus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperative that you update your antivirus software at least once a day. If you do not update your antivirus software, then it will not be able to catch any of the new variants that may come out.
Visit Microsoft's Update Site Frequently It is important that you visit Microsoft Updates (http://update.microsoft.com/) regularly. This will ensure your computer has the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Install SpywareBlaster SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
Computer Safety on line Anti Malware (http://forum.malwareremoval.com/viewtopic.php?p=54#54)
Use the hosts file: Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate web pages. We can customize a hosts file so that it blocks certain web pages. However, it can slow down certain computers. This is why using a hosts file is optional. Download mvps hosts file (http://www.mvps.org/winhelp2002/hosts.htm) Make sure you read the instructions on how to install the hosts file. There is a good tutorial HERE (http://www.bleepingcomputer.com/forums/tutorial51.html) If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button on the task bar at the bottom of your screen Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then doubleclick it. On the dropdown box, change the setting from automatic to manual. Click ok..
Use an alternative instant messenger program.Trillian (http://www.trillian.cc/) and Miranda IM (http://www.miranda-im.com/) These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
Please read Tony Klein's excellent article: How I got Infected in the First Place (http://forums.subratam.org/index.php?showtopic=5931)
Please read Understanding Spyware, Browser Hijackers, and Dialers (http://www.bleepingcomputer.com/forums/tutorial41.html)
Please read Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/tutorial82.html)
If you are using Internet Explorer, please consider using an alternate browser: Mozilla's Firefox (http://www.mozilla.org/products/firefox) or
Opera (http://www.opera.com/download/).
If you decide to use either FireFox or Opera, it is very important that you keep them up to date and check frequently for updates of the browser of your choice.
Update all these programs regularly Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
If your computer was infected by a website, a program, IM, MSN, or p2p, check this site because it is Time To Fight Back (http://spyware-free.us/2006/01/time-to-fight-back.html). Follow these steps and your potential for being infected again will reduce dramatically.

Here's a good website to read about Malware prevention:

http://users.telenet.be/bluepatchy/miekiemoes/prevention.html

If your computer is running slow, click here (http://www.malwareremoval.com/tutorials/runningslowly.php) for instructions on how to help speed up your computer.

Good luck!


Please reply one last time so that I know you have read my post and this thread can be closed.

Miche
2009-03-10, 15:51
Thank you so much for all of your time, quick responses, and ideas. I'm just finishing up with the all clean steps. My machine is singing along.

I'll make a donation to support the work you all do, and hope you can think of it as a great batch of chocolate chip cookies.

Thanks again!
Miche

Miche
2009-03-10, 17:52
I was working my way through the list of final steps. After updating IE security and XP settings, I brought up IE in order to look for updates.

I use Mozilla Firefox 99% of the time. I do have the Windows automatic updates set to the prompt me setting. I have downloaded some of the updates today, but as I understand it, the automatic updates won't install until 3am. I thought I would go ahead and download and install from the microsoft site, and was prompted to do this from IE browser.

I opened up IE which brought up my homepage. When I enter a different web address in, I get a cascade of IE browser windows that can only be interrupted by the task manager.

Is this a conflict by having Firefox as the default browser?

In getting latest microsoft updates, do I need all of them? I have IE6, do I need the IE7? Likewise am running XP sp2, do I need the sp1 related updates AND/OR updates to sp3?

km2357
2009-03-10, 19:17
Is this a conflict by having Firefox as the default browser?

Having Firefox as your default browser shouldn't have caused the multiple IE windows popping up. Has this ever happened before or is the first time? Do these cascade of windows say anything in the Address Bar?



In getting latest microsoft updates, do I need all of them? I have IE6, do I need the IE7? Likewise am running XP sp2, do I need the sp1 related updates AND/OR updates to sp3?

When updating you want to make sure you get all the critical updates. I would go ahead and update to IE7 and update to SP3. Once you've updated those, reboot your computer and go back to Windows Update and install any critical updates that are found. After those are done, reboot your computer and repeat the process until there are no more critical updates left to download.

Once everything is updated, do you still get the cascade of windows? If so, then post back a fresh HJT log in your next post.

Miche
2009-03-11, 03:00
All critical updates, IE7 and XPsp3 installed. (I don't see the automatic updates shield in the start tray anymore, so I think everything is updated.) No more cascading windows, but a weird thing. When I click on the IE icon, the browser window comes up displaying my homepage. If I enter any web address or even click the homepage icon, the page is brought up in a Firefox window.

just in case, a fresh HJT log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:54:57 PM, on 3/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\EtmService.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Panasonic\CHGBMODE\ChgBmode.exe
C:\Program Files\Panasonic\LANPSAVE\LanPsave.exe
C:\Program Files\Panasonic\OPDOFF\opdoff.exe
C:\Program Files\Panasonic\WheelPad\Touchpad.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://thewidercircle.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Economy Mode(ECO) Setting Utility.lnk = ?
O4 - Global Startup: LAN Power-Saving Utility.lnk = ?
O4 - Global Startup: Optical Disc Drive Power-Saving Utility.lnk = ?
O4 - Global Startup: Touch Pad Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Intel(R) Extended Thermal Model Service Application (ETMService) - Intel Corporation - C:\WINDOWS\system32\EtmService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Panasonic Opdoff Utility (OPDOFFSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
O23 - Service: Panasonic PC Information Viewer Service 2 (PcInfoPi) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
O23 - Service: Panasonic PC Information Viewer (PcInfoSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

--
End of file - 8609 bytes

km2357
2009-03-11, 06:13
When I click on the IE icon, the browser window comes up displaying my homepage. If I enter any web address or even click the homepage icon, the page is brought up in a Firefox window.

That is weird. Might be a glitch with Firefox? You say FF is your default browser, try making IE your default browser to see if a webpage is still brought up in a Firefox window. You can also update Firefox to version 3.0.7 if you haven't already to see if that fixes it. Finally, you can try uninstalling and reinstalling Firefox to see if that helps.

Miche
2009-03-12, 17:33
I have reinstalled Firefox and did not make it the default browser.

When IE is launched, my homepage comes up (thewidercircle.org) and interestingly, I can navigate webpages using the links on the homepage website. I can smoothly bring up other pages on the website as well as link to other imbedded website links (google check out, a Picassa slideshow, for example.) All open within the same IE browser window (no separate tab or window openning).

If, however, I enter an address in the address bar or click the home icon in the toolbar, another IE browser window opens, but never displays anything. The addressbar remains blank, everything is whitespace. To close the window, the end program window pops up after attempting normal shut down. At least the cascade of multiple windows has stopped. The original browser window continues to display the homepage and can be refreshed.

Miche
2009-03-12, 17:37
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:34:03 AM, on 3/12/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\EtmService.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Panasonic\CHGBMODE\ChgBmode.exe
C:\Program Files\Panasonic\LANPSAVE\LanPsave.exe
C:\Program Files\Panasonic\OPDOFF\opdoff.exe
C:\Program Files\Panasonic\WheelPad\Touchpad.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://thewidercircle.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Economy Mode(ECO) Setting Utility.lnk = ?
O4 - Global Startup: LAN Power-Saving Utility.lnk = ?
O4 - Global Startup: Optical Disc Drive Power-Saving Utility.lnk = ?
O4 - Global Startup: Touch Pad Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Intel(R) Extended Thermal Model Service Application (ETMService) - Intel Corporation - C:\WINDOWS\system32\EtmService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Panasonic Opdoff Utility (OPDOFFSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\OPDOFF\opdoffsv.exe
O23 - Service: Panasonic PC Information Viewer Service 2 (PcInfoPi) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe
O23 - Service: Panasonic PC Information Viewer (PcInfoSV) - Matsushita Electric Industrial Co., Ltd. - C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

--
End of file - 8673 bytes

km2357
2009-03-12, 19:16
Your latest HiJackThis Log looks good, though it says you still Windows XP SP2 and IE 6 SP2 and you did say you did update to SP3 and IE7.

Let's do some scans to see if anything may be hiding.


Step # 1 Run Malwarebytes' Anti-Malware

Launch Malwarebytes' Anti-Malware.
Before running a scan, click the Update tab, next click Check for Updates to download any updates, if available.
Next click the Scanner tab and select Perform Quick Scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location.
You can also access the log by doing the following:

Click on the Malwarebytes' Anti-Malware icon to launch the program.
Click on the Logs tab.
Click on the log at the bottom of those listed to highlight it.
Click Open.


Step # 2: Download and Run Gmer

Please download gmer.zip (http://www.gmer.net/gmer.zip) from Gmer and save it to your desktop.

***Please close any open programs ***

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised by a trained Security Analyst

If possible rootkit activity is found, you will be asked if you would like to perform a full scan. Click Yes.

Once the scan is complete, you may receive another notice about rootkit activity.
Click OK.

GMER will produce a log. Click on the Save button, and save the log as gmer.txt somewhere you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked. Click the Scan button and let the program do its work. GMER will produce a log.
Click on the Save button, and save the log as gmer.txt somewhere you can easily find it, such as your desktop.

DO NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc !

Please post the results from the GMER scan in your reply.

Miche
2009-03-13, 04:41
Nothing detected on the mbam scan. I did check under add/remove programs, IE7 is listed.

GMER 1.0.15.14878 - http://www.gmer.net
Rootkit scan 2009-03-12 22:29:32
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0x9F2AD6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0x9F2AD574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0x9F2ADA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0x9F2AD14C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0x9F2AD64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0x9F2AD08C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0x9F2AD0F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0x9F2AD76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0x9F2AD72E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0x9F2AD8AE]

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\services.exe[972] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[972] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

---- EOF - GMER 1.0.15 ----

km2357
2009-03-13, 07:02
I don't see anything bad in the GMER Log. I'm gonna ask some of my fellow malware fighters to see if they have any ideas on what happening with your IE and Firefox.

Be back ASAP.

Miche
2009-03-13, 14:41
Thanks. My issues all began with IE problems. Before contacting you I ran spybot S&D and upgraded to IE7, thinking that would resolve things. Maybe remove the IE7 upgrade? (I won't do anything 'til you tell me :red:)

km2357
2009-03-13, 20:05
No need to remove the upgrade to IE7 just yet. I'll let you know if you need to. :)

km2357
2009-03-14, 18:26
I'd like for you to reset IE7.

To do so, do the following:

1. Start Internet Explorer 7.
2. Click the Tools menu, choose Internet Options.
3. On the Advanced tab, click Reset.
4. In the Reset Internet Explorer Settings dialog box, click Reset.

Let me know if that fixes the problem with the blank IE window showing up.

Miche
2009-03-15, 14:35
The homepage was reset, so now the IE window opens with MSN. When I enter another web address, a separate window pops up with all white space, however the address bar now lists msn.com (which is a slight change).

km2357
2009-03-16, 19:20
Hi Miche,

Try uninstalling IE7 which will roll you back to IE6. Once you have IE6 back, see if the problem with the blank window popping up persists with IE6.

If you're having troubles uninstalling IE7, here are a few links to help you out:

http://support.microsoft.com/kb/927177

http://support.microsoft.com/kb/950719

Miche
2009-03-17, 01:30
All is well! Removed IE7 and it is working fine. I have completed most of the steps in thread#27 and just need to get spyware blaster.

Now do I try and do IE7 again? I also think that the sp3 update may have failed as I don't see that anywhere and the IE7 removal went very smooth. Do I go ahead with critical updates for windows which I presume includes these updates?

Other than that things are working well.

km2357
2009-03-17, 07:10
Since IE7 doesn't seem to be working on your computer, I'd go ahead and stay with IE6 for now.

I would go ahead though and try to get SP3 again through Windows Update. If you're still having troubles downloading it through Windows Update, here's the direct link to it. It says its for IT professionals and developers. However, you can safely download the SP3 update:

http://www.microsoft.com/downloads/details.aspx?FamilyId=5B33B5A8-5E76-401F-BE08-1E1555D4F3D4&displaylang=en

Miche
2009-03-17, 15:49
Hey there, km2357

I have everything updated at this point and my machine is happily zipping along again. I did not follow your instructions and went ahead and installed IE7. I did the original update while I was infected with those virtumonde, sendak files and they seemed to take over IE at the start. Since we've been cleaning, I noticed the icons for IE were different in the toolbar from on the desktop. Anyway, everything seems to be working. Thanks!

km2357
2009-03-17, 19:15
You're welcome. I'm glad I was able to help you out. :)

Good luck and safe surfing!