Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 25

Thread: Virtumonde help!

  1. #11
    Junior Member
    Join Date
    Nov 2008
    Posts
    14

    Default

    okay. when i right click, there isn't an exit option

    also, i haven't disabled anything yet because i just wanted to make sure i knew how to disable them all.

    right now, im trying to install the recovery thing and when i dragged it over combofix, it didn't install.

  2. #12
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    If there is none, you should be able to disable it via program itself.

    You can skip that recovery console step.

    ComboFix will prompt if it isn't installed and ask permission to download and install it.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #13
    Junior Member
    Join Date
    Nov 2008
    Posts
    14

    Default

    okay i ran combofix, but i didn't get the "please wait. combofix is preparing to run" on my blue screen

  4. #14
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Please check if there is c:\ComboFix.txt.

    If so, please post back its contents here along with a fresh HijackThis log.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  5. #15
    Junior Member
    Join Date
    Nov 2008
    Posts
    14

    Default

    okay:

    ComboFix 08-11-09.01 - Grace Peng 2008-11-09 14:47:00.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1556 [GMT -6:00]
    Running from: c:\documents and settings\Grace Peng\Desktop\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Grace Peng\Application Data\p4p
    c:\windows\a3kebook.ini
    c:\windows\akebook.ini
    c:\windows\ANS2000.INI
    c:\windows\Downloaded Program Files\setup.inf
    c:\windows\system32\dkrbjy.dll
    c:\windows\system32\mcrh.tmp
    c:\windows\system32\nprabjvi.dll
    c:\windows\system32\thfqxqil.dll
    c:\windows\wiaserviv.log

    .
    ((((((((((((((((((((((((( Files Created from 2008-10-09 to 2008-11-09 )))))))))))))))))))))))))))))))
    .

    2008-11-07 12:55 . 2008-11-07 12:55 <DIR> d-------- c:\program files\Trend Micro
    2008-11-04 23:34 . 2008-11-04 23:34 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
    2008-11-02 17:52 . 2008-11-02 17:52 <DIR> d-------- c:\program files\Lavasoft
    2008-11-02 17:52 . 2008-11-04 23:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
    2008-10-27 17:41 . 2008-10-27 17:41 <DIR> d-------- c:\windows\system32\scripting
    2008-10-27 17:41 . 2008-10-27 17:41 <DIR> d-------- c:\windows\system32\en
    2008-10-27 17:41 . 2008-10-27 17:41 <DIR> d-------- c:\windows\l2schemas
    2008-10-27 16:55 . 2008-10-15 10:34 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
    2008-10-18 15:15 . 2008-10-18 15:15 <DIR> d-------- c:\documents and settings\Kyle Peng\Application Data\acccore
    2008-10-14 14:25 . 2008-09-08 04:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
    2008-10-14 14:24 . 2008-08-14 04:11 2,189,184 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
    2008-10-14 14:24 . 2008-08-14 04:09 2,145,280 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
    2008-10-14 14:24 . 2008-08-14 03:33 2,066,048 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
    2008-10-14 14:24 . 2008-08-14 03:33 2,023,936 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
    2008-10-14 14:24 . 2008-09-15 06:12 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys
    2008-10-11 14:06 . 2008-10-11 14:06 <DIR> d-------- c:\documents and settings\Kyle Peng\Application Data\HP
    2008-10-11 14:06 . 2008-10-11 14:06 <DIR> d-------- c:\documents and settings\Kyle Peng\Application Data\Apple Computer

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-11-09 20:57 16,502,816 --sha-w c:\windows\system32\drivers\fidbox.dat
    2008-11-09 20:52 194,300 --sha-w c:\windows\system32\drivers\fidbox.idx
    2008-11-09 19:50 --------- d-----w c:\program files\AIMTunes
    2008-11-09 19:10 4,571 ----a-w c:\program files\uninstall_list.txt
    2008-11-09 19:00 --------- d-----w c:\program files\LimeWire
    2008-11-09 03:36 --------- d-----w c:\documents and settings\Grace Peng\Application Data\dvdcss
    2008-11-09 03:36 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
    2008-11-07 19:59 --------- d-----w c:\documents and settings\Grace Peng\Application Data\LimeWire
    2008-11-07 18:56 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2008-11-07 16:37 --------- d-----w c:\program files\Spybot - Search & Destroy
    2008-11-05 07:09 --------- d-----w c:\program files\Google
    2008-11-04 04:14 9,546,765 ----a-w c:\windows\Internet Logs\tvDebug.zip
    2008-11-04 04:11 --------- d--h--w c:\program files\InstallShield Installation Information
    2008-11-04 04:11 --------- d-----w c:\program files\Outspark
    2008-11-04 04:11 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
    2008-11-04 01:22 1,772,032 ----a-w c:\windows\Internet Logs\xDBE.tmp
    2008-11-03 06:27 169,472 ----a-w c:\windows\Internet Logs\xDBD.tmp
    2008-11-02 15:20 1,755,648 ----a-w c:\windows\Internet Logs\xDBC.tmp
    2008-11-02 05:10 --------- d--h--r c:\documents and settings\Grace Peng\Application Data\yahoo!
    2008-11-01 08:10 1,731,584 ----a-w c:\windows\Internet Logs\xDBB.tmp
    2008-10-29 00:07 --------- d-----w c:\program files\MSN Messenger
    2008-10-21 23:48 180,224 ----a-w c:\windows\Internet Logs\xDBA.tmp
    2008-10-21 00:34 --------- d-----w c:\program files\BitComet
    2008-10-19 07:37 141,312 ----a-w c:\windows\Internet Logs\xDB7.tmp
    2008-10-19 07:37 1,696,256 ----a-w c:\windows\Internet Logs\xDB8.tmp
    2008-10-15 01:17 1,683,968 ----a-w c:\windows\Internet Logs\xDB6.tmp
    2008-10-15 01:17 1,448,448 ----a-w c:\windows\Internet Logs\xDB5.tmp
    2008-10-14 22:08 1,683,968 ----a-w c:\windows\Internet Logs\xDB9.tmp
    2008-10-14 22:08 1,683,968 ----a-w c:\windows\Internet Logs\xDB4.tmp
    2008-10-09 01:51 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore
    2008-10-09 01:47 --------- d-----w c:\program files\McAfee
    2008-10-09 01:44 --------- d-----w c:\documents and settings\All Users\Application Data\SiteAdvisor
    2008-10-09 01:43 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
    2008-10-05 23:38 1,658,880 ----a-w c:\windows\Internet Logs\xDB3.tmp
    2008-10-05 18:25 1,658,880 ----a-w c:\windows\Internet Logs\xDB2.tmp
    2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
    2008-09-10 05:36 --------- d-----w c:\program files\Common Files\Adobe
    2008-08-26 07:24 826,368 ----a-w c:\windows\system32\wininet.dll
    2008-08-14 10:09 2,145,280 ----a-w c:\windows\system32\ntoskrnl.exe
    2008-08-14 09:33 2,023,936 ----a-w c:\windows\system32\ntkrnlpa.exe
    2003-07-16 20:48 94,784 -csh--w c:\windows\twain.dll
    2008-04-14 00:12 50,688 --sh--w c:\windows\twain_32.dll
    2008-04-14 00:11 1,028,096 --sha-w c:\windows\system32\mfc42.dll
    2008-04-14 00:12 57,344 --sha-w c:\windows\system32\msvcirt.dll
    2008-04-14 00:12 413,696 --sha-w c:\windows\system32\msvcp60.dll
    2008-04-14 00:12 343,040 --sha-w c:\windows\system32\msvcrt.dll
    2008-04-14 00:12 551,936 --sh--w c:\windows\system32\oleaut32.dll
    2008-04-14 00:12 84,992 --sha-w c:\windows\system32\olepro32.dll
    2008-04-14 00:12 11,776 --sh--w c:\windows\system32\regsvr32.exe
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SB Audigy 2 Startup Menu"="/L:ENG" [X]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
    "Aim6"="c:\program files\AIM6\aim6.exe" [2008-06-19 50528]
    "MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
    "Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-04-01 3587120]
    "MsgCenterExe"="c:\program files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" [2007-10-27 69632]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
    "CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
    "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
    "YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
    "Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 49263]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
    "MSPY2002"="c:\windows\System32\IME\PINTLGNT\ImScInst.exe" [2003-07-16 59392]
    "PHIME2002ASync"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2003-07-16 455168]
    "PHIME2002A"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2003-07-16 455168]
    "YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2006-07-21 407032]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
    "UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-05-26 257088]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-10-27 185632]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
    "ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
    "CTHelper"="CTHELPER.EXE" [2003-02-20 c:\windows\system32\CTHELPER.EXE]
    "AsioReg"="CTASIO.DLL" [2003-02-20 c:\windows\system32\CTASIO.DLL]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-10-17 113664]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
    HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 73728]
    HPAiODevice(hp officejet k series) - 1.lnk - c:\program files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe [2002-05-23 151552]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=dkrbjy.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\Yahoo!\\Messenger\\yserver.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"=
    "c:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\Photoshop Album Starter Edition.exe"=
    "c:\\Program Files\\Canon\\CameraWindow\\CameraWindowDVC6\\CameraLauncher.exe"=
    "c:\\Program Files\\Creative\\SBAudigy2\\Surround Mixer\\SurMixer.exe"=
    "c:\\Program Files\\Gpotato\\Flyff\\Flyff.exe"=
    "c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
    "c:\\Program Files\\McAfee\\MSC\\mcshell.exe"=
    "c:\\Program Files\\NJStar Communicator\\Njcom32.exe"=
    "c:\\Program Files\\THQ\\Titan Quest Immortal Throne\\Tqit.exe"=
    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
    "c:\\Program Files\\WinRAR\\WinRAR.exe"=
    "c:\\Program Files\\7-Zip\\7zFM.exe"=
    "c:\\WINDOWS\\System32\\freecell.exe"=
    "c:\\Trickster Online\\Splash.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
    "c:\\Program Files\\AIM6\\aim6.exe"=
    "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\MSN Messenger\\livecall.exe"=
    "c:\\Program Files\\Yahoo!\\browser\\ybrowser.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Yahoo!\\YOP\\yop.exe"=
    "c:\\Program Files\\MSN\\MSNCoreFiles\\msn6.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "12626:TCP"= 12626:TCP:BitComet 12626 TCP
    "12626:UDP"= 12626:UDP:BitComet 12626 UDP
    "19080:TCP"= 19080:TCP:BitComet 19080 TCP
    "19080:UDP"= 19080:UDP:BitComet 19080 UDP
    "19660:TCP"= 19660:TCP:BitComet 19660 TCP
    "19660:UDP"= 19660:UDP:BitComet 19660 UDP
    "10854:TCP"= 10854:TCP:BitComet 10854 TCP
    "10854:UDP"= 10854:UDP:BitComet 10854 UDP
    "8679:TCP"= 8679:TCP:BitComet 8679 TCP
    "8679:UDP"= 8679:UDP:BitComet 8679 UDP

    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-09-08 198944]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
    S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\DRIVERS\gan_adapter.sys [2006-10-19 10664]
    S3 XDva005;XDva005;c:\windows\system32\XDva005.sys [ ]
    S3 XDva011;XDva011;c:\windows\system32\XDva011.sys [ ]
    S3 XDva014;XDva014;c:\windows\system32\XDva014.sys [ ]
    S3 XDva015;XDva015;c:\windows\system32\XDva015.sys [ ]
    S3 XDva022;XDva022;c:\windows\system32\XDva022.sys [ ]
    S3 XDva024;XDva024;c:\windows\system32\XDva024.sys [ ]
    S3 XDva030;XDva030;c:\windows\system32\XDva030.sys [ ]
    S3 XDva031;XDva031;c:\windows\system32\XDva031.sys [ ]
    S3 XDva064;XDva064;c:\windows\system32\XDva064.sys [ ]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{121c8253-9f62-11db-ac67-000cf1aa6a4b}]
    \Shell\AutoRun\command - H:\LaunchU3.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{121c8254-9f62-11db-ac67-000cf1aa6a4b}]
    \Shell\AutoRun\command - J:\setupSNK.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{458f4ade-d02c-11db-ac99-000cf1aa6a4b}]
    \Shell\AutoRun\command - I:\Autorun.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{625a660d-6c86-11dc-ad83-000cf1aa6a4b}]
    \Shell\AutoRun\command - G:\Autorun.exe
    .
    Contents of the 'Scheduled Tasks' folder

    2008-11-02 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 14:42]

    2008-11-09 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
    - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]

    2008-06-15 c:\windows\Tasks\McDefragTask.job
    - c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

    2008-11-01 c:\windows\Tasks\McQcTask.job
    - c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{9bc2d029-d0c3-4094-ac09-0e055b040d18} - c:\windows\system32\dkrbjy.dll
    HKCU-Run-BitComet - c:\program files\BitComet\BitComet.exe
    HKCU-Run-Sonic RecordNow! Deluxe - (no file)


    .
    ------- Supplementary Scan -------
    .
    FireFox -: Profile - c:\documents and settings\Grace Peng\Application Data\Mozilla\Firefox\Profiles\obkepvu7.default\
    FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll
    FF -: plugin - c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_08\bin\NPJava11.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_08\bin\NPJava12.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_08\bin\NPJava13.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_08\bin\NPJava14.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_08\bin\NPJava32.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_08\bin\NPJPI150_08.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_08\bin\NPOJI610.dll
    FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmozax.dll
    FF -: plugin - c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
    FF -: plugin - c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
    FF -: plugin - c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-11-09 14:54:45
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSSdk23]
    "ImagePath"="\??\c:\windows\system32\Drivers\PsSdk23.drv"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    PROCESS: c:\windows\system32\winlogon.exe
    -> c:\windows\system32\Ati2evxx.dll

    PROCESS: c:\windows\explorer.exe
    -> c:\program files\McAfee\SiteAdvisor\saHook.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\ZoneLabs\vsmon.exe
    c:\program files\Lavasoft\Ad-Aware\aawservice.exe
    c:\progra~1\Yahoo!\browser\ycommon.exe
    c:\progra~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
    c:\windows\system32\CTSVCCDA.EXE
    c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
    c:\progra~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\Common Files\McAfee\MNA\McNASvc.exe
    c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
    c:\program files\McAfee\VirusScan\Mcshield.exe
    c:\windows\system32\HPZipm12.exe
    c:\windows\system32\MsPMSPSv.exe
    c:\program files\Canon\CAL\CALMAIN.exe
    c:\program files\AIM6\aolsoftware.exe
    c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
    c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\program files\HP\Digital Imaging\bin\hpqste08.exe
    c:\windows\system32\wscntfy.exe
    c:\progra~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
    c:\program files\Hewlett-Packard\AiO\Shared\Bin\hposts07.exe
    c:\program files\Hewlett-Packard\AiO\Shared\Bin\hpofxm07.exe
    c:\progra~1\McAfee\MSC\mcuimgr.exe
    c:\program files\Java\jre1.5.0_08\bin\jucheck.exe
    c:\windows\system32\imapi.exe
    .
    **************************************************************************
    .
    Completion time: 2008-11-09 15:00:57 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-11-09 21:00:42

    Pre-Run: 95,528,517,632 bytes free
    Post-Run: 96,042,688,512 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect

    311 --- E O F --- 2008-10-29 05:22:07





    and




    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:05:08 PM, on 11/9/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
    C:\PROGRA~1\Yahoo!\YOP\yop.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    C:\WINDOWS\system32\ctfmon.exe
    c:\program files\common files\mcafee\mna\mcnasvc.exe
    C:\Program Files\AIM6\aim6.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\Program Files\McAfee\VirusScan\McShield.exe
    C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
    C:\Program Files\Java\jre1.5.0_08\bin\jucheck.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1033
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
    O4 - HKCU\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: HPAiODevice(hp officejet k series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
    O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10...I.cab55579.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10...y.cab55579.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
    O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10...t.cab55579.cab
    O16 - DPF: {809A6301-7B40-4436-A02C-87B8D3D7D9E3} (ZPA_DMNO Object) - http://zone.msn.com/bingame/zpagames...o.cab55579.cab
    O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames...1.cab60096.cab
    O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_USAv1001 Class) - http://ares.netgame.com/download/mglaunch_USAv1002.cab
    O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://dist.globalgamecdn.com/dist/n...fyLauncher.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
    O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.gamengame.com/KALogoutComponent.cab
    O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10...y.cab55579.cab
    O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
    O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames...A.cab55579.cab
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O20 - AppInit_DLLs: dkrbjy.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
    O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

    --
    End of file - 14304 bytes

  6. #16
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Open notepad and copy/paste the text in the codebox below into it:

    Code:
    Folder::
    c:\documents and settings\Grace Peng\Application Data\LimeWire
    c:\program files\LimeWire
    c:\program files\BitComet
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-
    
    
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "12626:TCP"=-
    "12626:UDP"=-
    "19080:TCP"=-
    "19080:UDP"=-
    "19660:TCP"=-
    "19660:UDP"=-
    "10854:TCP"=-
    "10854:UDP"=-
    "8679:TCP"=-
    "8679:UDP"=-
    Save this as "CFScript"

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  7. #17
    Junior Member
    Join Date
    Nov 2008
    Posts
    14

    Default

    ComboFix 08-11-11.01 - Grace Peng 2008-11-12 22:18:35.2 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1471 [GMT -6:00]
    Running from: c:\documents and settings\Grace Peng\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Grace Peng\Desktop\CFScript.txt
    * Created a new restore point
    * Resident AV is active

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Grace Peng\Application Data\LimeWire
    c:\documents and settings\Grace Peng\Application Data\LimeWire\.NetworkShare\teams.txt
    c:\documents and settings\Grace Peng\Application Data\LimeWire\412splashfree.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\414splashfree.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\active.mojito
    c:\documents and settings\Grace Peng\Application Data\LimeWire\certificate\limewire.keystore
    c:\documents and settings\Grace Peng\Application Data\LimeWire\createtimes.cache
    c:\documents and settings\Grace Peng\Application Data\LimeWire\data.ser
    c:\documents and settings\Grace Peng\Application Data\LimeWire\downloads.dat
    c:\documents and settings\Grace Peng\Application Data\LimeWire\fileurns.bak
    c:\documents and settings\Grace Peng\Application Data\LimeWire\fileurns.cache
    c:\documents and settings\Grace Peng\Application Data\LimeWire\filters.props
    c:\documents and settings\Grace Peng\Application Data\LimeWire\gnutella.net
    c:\documents and settings\Grace Peng\Application Data\LimeWire\installation.props
    c:\documents and settings\Grace Peng\Application Data\LimeWire\library.dat
    c:\documents and settings\Grace Peng\Application Data\LimeWire\limewire.props
    c:\documents and settings\Grace Peng\Application Data\LimeWire\mojito.props
    c:\documents and settings\Grace Peng\Application Data\LimeWire\passive.mojito
    c:\documents and settings\Grace Peng\Application Data\LimeWire\promotion\promodb.backup
    c:\documents and settings\Grace Peng\Application Data\LimeWire\promotion\promodb.data
    c:\documents and settings\Grace Peng\Application Data\LimeWire\promotion\promodb.lck
    c:\documents and settings\Grace Peng\Application Data\LimeWire\promotion\promodb.properties
    c:\documents and settings\Grace Peng\Application Data\LimeWire\promotion\promodb.script
    c:\documents and settings\Grace Peng\Application Data\LimeWire\pub1.key
    c:\documents and settings\Grace Peng\Application Data\LimeWire\public.key
    c:\documents and settings\Grace Peng\Application Data\LimeWire\questions.props
    c:\documents and settings\Grace Peng\Application Data\LimeWire\responses.cache
    c:\documents and settings\Grace Peng\Application Data\LimeWire\secureMessage.key
    c:\documents and settings\Grace Peng\Application Data\LimeWire\simpp.xml
    c:\documents and settings\Grace Peng\Application Data\LimeWire\spam.dat
    c:\documents and settings\Grace Peng\Application Data\LimeWire\tables.props
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme.lwtp
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\01_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\02_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\03_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\04_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\05_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\chat.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\dir_closed.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\dir_open.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\forward_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\forward_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\kill.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\kill_on.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\lime.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\logo.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\notsearching.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\pause_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\pause_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\play_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\play_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\question.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\rewind_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\rewind_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\searching.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\splash.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\splashpro.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\stop_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\stop_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\theme.txt
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\version.txt
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\black_theme\warning.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme.lwtp
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\01_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\02_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\03_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\04_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\05_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\chat.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\dir_closed.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\dir_open.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\forward_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\forward_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\kill.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\logo.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\notsearching.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\pause_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\pause_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\play_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\play_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\question.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\rewind_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\rewind_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\search.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\searching.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\splash.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\splashpro.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\stop_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\stop_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\theme.txt
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\version.txt
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\classic_theme\warning.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme.lwtp
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\01_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\02_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\03_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\04_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\05_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\chat.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\dir_closed.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\dir_open.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\forward_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\forward_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\kill.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\kill_on.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\lime.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\logo.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\notsearching.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\pause_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\pause_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\play_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\play_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\question.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\rewind_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\rewind_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\searching.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\splash.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\splashpro.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\stop_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\stop_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\theme.txt
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\version.txt
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\limewire_theme\warning.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme.lwtp
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\01_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\02_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\03_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\04_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\05_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\chat.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\forward_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\forward_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\kill.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\kill_on.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\logo.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\name.txt
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\notsearching.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\pause_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\pause_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\play_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\play_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\question.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\rewind_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\rewind_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\searching.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\splash.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\splashpro.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\stop_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\stop_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\theme.txt
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\version.txt
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\other_theme\warning.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme.lwtp
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\01_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\02_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\03_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\04_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\05_star.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\chat.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\forward_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\kill.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\kill_on.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\logo.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\notsearching.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\pause_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\play_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\play_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\question.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\searching.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\splash.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\splashpro.png
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\stop_up.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\theme.txt
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\version.txt
    c:\documents and settings\Grace Peng\Application Data\LimeWire\themes\windows_theme\warning.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\ttree.cache
    c:\documents and settings\Grace Peng\Application Data\LimeWire\ttrees.cache
    c:\documents and settings\Grace Peng\Application Data\LimeWire\ttroot.cache
    c:\documents and settings\Grace Peng\Application Data\LimeWire\update.xml
    c:\documents and settings\Grace Peng\Application Data\LimeWire\version.key
    c:\documents and settings\Grace Peng\Application Data\LimeWire\version.xml
    c:\documents and settings\Grace Peng\Application Data\LimeWire\versions.props
    c:\documents and settings\Grace Peng\Application Data\LimeWire\xml\data\delete_me
    c:\documents and settings\Grace Peng\Application Data\LimeWire\xml\misc\application.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\xml\misc\audio.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\xml\misc\document.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\xml\misc\image.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\xml\misc\video.gif
    c:\documents and settings\Grace Peng\Application Data\LimeWire\xml\schemas\application.xsd
    c:\documents and settings\Grace Peng\Application Data\LimeWire\xml\schemas\audio.xsd
    c:\documents and settings\Grace Peng\Application Data\LimeWire\xml\schemas\document.xsd
    c:\documents and settings\Grace Peng\Application Data\LimeWire\xml\schemas\image.xsd
    c:\documents and settings\Grace Peng\Application Data\LimeWire\xml\schemas\video.xsd
    c:\program files\BitComet
    c:\program files\BitComet\BitComet.xml
    c:\program files\BitComet\Downloads.xml
    c:\program files\BitComet\fav\fav_en_us.xml
    c:\program files\BitComet\fav\passport_info_en_us.mht
    c:\program files\BitComet\fav\passport_info_zh_cn.mht
    c:\program files\BitComet\Favourite.xml
    c:\program files\BitComet\lang\lang_en_us.xml
    c:\program files\BitComet\rules\dhtnodes.dat
    c:\program files\BitComet\share\my_shares.xml
    c:\program files\BitComet\tools\bitcomet_extension_signed.xpi
    c:\program files\BitComet\torrents\[0125]Faster Than a Kiss Manga.rar.torrent
    c:\program files\BitComet\torrents\[0125]Faster Than a Kiss Manga.rar.xml
    c:\program files\BitComet\torrents\[aarinfantasy]_Junjou_Romantica_DVD_-_02_[0FD4D603].avi.torrent
    c:\program files\BitComet\torrents\[aarinfantasy]_Junjou_Romantica_DVD_-_02_[0FD4D603].avi.xml
    c:\program files\BitComet\torrents\132894-Special A Vol10 Ch054.rar.xml
    c:\program files\BitComet\torrents\mvtapp.exe.xml
    c:\program files\LimeWire
    c:\program files\LimeWire\aopalliance.jar.tmp
    c:\program files\LimeWire\clink.jar.tmp
    c:\program files\LimeWire\commons-codec-1.3.jar.tmp
    c:\program files\LimeWire\commons-logging.jar.tmp
    c:\program files\LimeWire\commons-net.jar.tmp
    c:\program files\LimeWire\daap.jar.tmp
    c:\program files\LimeWire\dnsjava.jar.tmp
    c:\program files\LimeWire\forms.jar.tmp
    c:\program files\LimeWire\foxtrot.jar.tmp
    c:\program files\LimeWire\gettext-commons.jar.tmp
    c:\program files\LimeWire\guice-1.0.jar.tmp
    c:\program files\LimeWire\hs_err_pid2768.log
    c:\program files\LimeWire\hs_err_pid4864.log
    c:\program files\LimeWire\hs_err_pid920.log
    c:\program files\LimeWire\hsqldb.jar.tmp
    c:\program files\LimeWire\httpclient-4.0-alpha5-20080522.192134-5.jar.tmp
    c:\program files\LimeWire\httpcore-4.0-beta2-20080510.140437-10.jar.tmp
    c:\program files\LimeWire\httpcore-nio-4.0-beta2-20080510.140437-10.jar.tmp
    c:\program files\LimeWire\icu4j.jar.tmp
    c:\program files\LimeWire\jaudiotagger.jar.tmp
    c:\program files\LimeWire\jcraft.jar.tmp
    c:\program files\LimeWire\jdic.jar.tmp
    c:\program files\LimeWire\jdic_stub.jar.tmp
    c:\program files\LimeWire\jflac.jar.tmp
    c:\program files\LimeWire\jl.jar.tmp
    c:\program files\LimeWire\jmdns.jar.tmp
    c:\program files\LimeWire\jogg.jar.tmp
    c:\program files\LimeWire\jorbis.jar.tmp
    c:\program files\LimeWire\lib\UnpackedJars.7z
    c:\program files\LimeWire\LimeWire.jar.tmp
    c:\program files\LimeWire\log4j.jar.tmp
    c:\program files\LimeWire\looks.jar.tmp
    c:\program files\LimeWire\messages.jar.tmp
    c:\program files\LimeWire\mp3spi.jar.tmp
    c:\program files\LimeWire\onion-common.jar.tmp
    c:\program files\LimeWire\onion-fec.jar.tmp
    c:\program files\LimeWire\ProgressTabs.jar.tmp
    c:\program files\LimeWire\swt.jar.tmp
    c:\program files\LimeWire\themes.jar.tmp
    c:\program files\LimeWire\tritonus.jar.tmp
    c:\program files\LimeWire\vorbisspi.jar.tmp

    .
    ((((((((((((((((((((((((( Files Created from 2008-10-13 to 2008-11-13 )))))))))))))))))))))))))))))))
    .

    2008-11-12 22:13 . 2008-11-12 22:13 389,120 --a------ c:\windows\system32\CF31239.exe.vir
    2008-11-12 20:51 . 2008-10-24 05:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
    2008-11-12 20:50 . 2008-09-04 11:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
    2008-11-10 21:42 . 2008-11-10 21:43 <DIR> d-------- c:\program files\iTunes
    2008-11-10 21:42 . 2008-11-10 21:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
    2008-11-10 21:37 . 2008-11-10 21:37 <DIR> d-------- c:\program files\Bonjour
    2008-11-10 21:33 . 2008-11-10 21:35 <DIR> d-------- c:\program files\QuickTime
    2008-11-10 21:29 . 2008-11-10 21:29 <DIR> d-------- c:\program files\Apple Software Update
    2008-11-10 21:27 . 2008-10-01 13:01 32,000 --a------ c:\windows\system32\drivers\usbaapl.sys
    2008-11-10 21:26 . 2008-11-10 21:34 <DIR> d-------- c:\program files\Common Files\Apple
    2008-11-10 21:26 . 2008-11-10 21:26 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
    2008-11-10 20:48 . 2008-11-10 21:07 54,156 --ah----- c:\windows\QTFont.qfn
    2008-11-10 20:48 . 2008-11-10 20:48 1,409 --a------ c:\windows\QTFont.for
    2008-11-07 12:55 . 2008-11-07 12:55 <DIR> d-------- c:\program files\Trend Micro
    2008-11-04 23:34 . 2008-11-04 23:34 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
    2008-11-02 17:52 . 2008-11-02 17:52 <DIR> d-------- c:\program files\Lavasoft
    2008-11-02 17:52 . 2008-11-04 23:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
    2008-10-27 17:41 . 2008-10-27 17:41 <DIR> d-------- c:\windows\system32\scripting
    2008-10-27 17:41 . 2008-10-27 17:41 <DIR> d-------- c:\windows\system32\en
    2008-10-27 17:41 . 2008-10-27 17:41 <DIR> d-------- c:\windows\l2schemas
    2008-10-27 16:55 . 2008-10-15 10:34 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
    2008-10-18 15:15 . 2008-10-18 15:15 <DIR> d-------- c:\documents and settings\Kyle Peng\Application Data\acccore
    2008-10-14 14:25 . 2008-09-08 04:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
    2008-10-14 14:24 . 2008-08-14 04:11 2,189,184 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
    2008-10-14 14:24 . 2008-08-14 04:09 2,145,280 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
    2008-10-14 14:24 . 2008-08-14 03:33 2,066,048 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
    2008-10-14 14:24 . 2008-08-14 03:33 2,023,936 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
    2008-10-14 14:24 . 2008-09-15 06:12 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-11-13 04:28 17,135,648 --sha-w c:\windows\system32\drivers\fidbox.dat
    2008-11-13 04:06 --------- d-----w c:\program files\AIMTunes
    2008-11-13 04:00 200,876 --sha-w c:\windows\system32\drivers\fidbox.idx
    2008-11-13 03:50 1,798,144 ----a-w c:\windows\Internet Logs\xDBF.tmp
    2008-11-13 02:56 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
    2008-11-11 03:42 --------- d-----w c:\program files\iPod
    2008-11-09 19:10 4,571 ----a-w c:\program files\uninstall_list.txt
    2008-11-09 03:36 --------- d-----w c:\documents and settings\Grace Peng\Application Data\dvdcss
    2008-11-07 18:56 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2008-11-07 16:37 --------- d-----w c:\program files\Spybot - Search & Destroy
    2008-11-05 07:09 --------- d-----w c:\program files\Google
    2008-11-04 04:14 9,546,765 ----a-w c:\windows\Internet Logs\tvDebug.zip
    2008-11-04 04:11 --------- d--h--w c:\program files\InstallShield Installation Information
    2008-11-04 04:11 --------- d-----w c:\program files\Outspark
    2008-11-04 04:11 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
    2008-11-04 01:22 1,772,032 ----a-w c:\windows\Internet Logs\xDBE.tmp
    2008-11-03 06:27 169,472 ----a-w c:\windows\Internet Logs\xDBD.tmp
    2008-11-02 15:20 1,755,648 ----a-w c:\windows\Internet Logs\xDBC.tmp
    2008-11-02 05:10 --------- d--h--r c:\documents and settings\Grace Peng\Application Data\yahoo!
    2008-11-01 08:10 1,731,584 ----a-w c:\windows\Internet Logs\xDBB.tmp
    2008-10-29 00:07 --------- d-----w c:\program files\MSN Messenger
    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-10-21 23:48 180,224 ----a-w c:\windows\Internet Logs\xDBA.tmp
    2008-10-19 07:37 141,312 ----a-w c:\windows\Internet Logs\xDB7.tmp
    2008-10-19 07:37 1,696,256 ----a-w c:\windows\Internet Logs\xDB8.tmp
    2008-10-15 01:17 1,683,968 ----a-w c:\windows\Internet Logs\xDB6.tmp
    2008-10-15 01:17 1,448,448 ----a-w c:\windows\Internet Logs\xDB5.tmp
    2008-10-14 22:08 1,683,968 ----a-w c:\windows\Internet Logs\xDB9.tmp
    2008-10-14 22:08 1,683,968 ----a-w c:\windows\Internet Logs\xDB4.tmp
    2008-10-11 20:06 --------- d-----w c:\documents and settings\Kyle Peng\Application Data\HP
    2008-10-11 20:06 --------- d-----w c:\documents and settings\Kyle Peng\Application Data\Apple Computer
    2008-10-09 01:51 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore
    2008-10-09 01:47 --------- d-----w c:\program files\McAfee
    2008-10-09 01:44 --------- d-----w c:\documents and settings\All Users\Application Data\SiteAdvisor
    2008-10-09 01:43 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
    2008-10-05 23:38 1,658,880 ----a-w c:\windows\Internet Logs\xDB3.tmp
    2008-10-05 18:25 1,658,880 ----a-w c:\windows\Internet Logs\xDB2.tmp
    2008-09-30 22:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
    2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
    2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
    2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
    2008-08-29 16:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
    2008-08-29 15:53 61,440 ----a-w c:\windows\system32\dnssd.dll
    2008-08-26 07:24 826,368 ----a-w c:\windows\system32\wininet.dll
    2008-08-14 10:09 2,145,280 ----a-w c:\windows\system32\ntoskrnl.exe
    2008-08-14 09:33 2,023,936 ----a-w c:\windows\system32\ntkrnlpa.exe
    2003-07-16 20:48 94,784 -csh--w c:\windows\twain.dll
    2008-04-14 00:12 50,688 --sh--w c:\windows\twain_32.dll
    2008-04-14 00:11 1,028,096 --sha-w c:\windows\system32\mfc42.dll
    2008-04-14 00:12 57,344 --sha-w c:\windows\system32\msvcirt.dll
    2008-04-14 00:12 413,696 --sha-w c:\windows\system32\msvcp60.dll
    2008-04-14 00:12 343,040 --sha-w c:\windows\system32\msvcrt.dll
    2008-04-14 00:12 551,936 --sh--w c:\windows\system32\oleaut32.dll
    2008-04-14 00:12 84,992 --sha-w c:\windows\system32\olepro32.dll
    2008-04-14 00:12 11,776 --sh--w c:\windows\system32\regsvr32.exe
    .

    ((((((((((((((((((((((((((((( snapshot@2008-11-09_14.59.56.12 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-10-24 11:21:09 455,296 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
    + 2008-11-11 03:29:47 27,136 ----a-r c:\windows\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
    + 2008-11-13 03:56:49 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
    + 2008-11-11 03:37:35 86,016 ----a-r c:\windows\Installer\{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}\PrntWzrdIco.exe
    + 2008-11-11 03:44:25 102,400 ----a-r c:\windows\Installer\{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}\iTunesIco.exe
    - 2008-11-09 18:11:17 32,768 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
    + 2008-11-13 02:48:26 32,768 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
    - 2008-11-09 18:11:17 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    + 2008-11-13 02:48:26 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    - 2008-11-09 18:11:17 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    + 2008-11-13 02:48:26 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    - 2008-04-14 00:12:01 1,306,624 -c----w c:\windows\system32\dllcache\msxml6.dll
    + 2008-09-10 01:14:56 1,307,648 -c----w c:\windows\system32\dllcache\msxml6.dll
    - 2006-09-19 19:44:04 15,664 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
    + 2008-04-17 19:12:54 15,464 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
    + 2008-04-17 19:12:54 107,368 -c--a-w c:\windows\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspi.dll
    + 2008-04-17 19:12:54 15,464 -c--a-w c:\windows\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspiWDM.sys
    + 2008-10-01 19:01:28 32,000 -c--a-w c:\windows\system32\DRVSTORE\usbaapl_246F92BBD6449C86FC3F3F28C40D59AC1F69C558\usbaapl.sys
    - 2006-10-04 00:47:52 109,360 ----a-w c:\windows\system32\GEARAspi.dll
    + 2008-04-17 19:12:54 107,368 ----a-w c:\windows\system32\GEARAspi.dll
    - 2008-10-07 19:19:40 16,721,856 ----a-w c:\windows\system32\MRT.exe
    + 2008-11-04 00:10:25 17,318,336 ----a-w c:\windows\system32\MRT.exe
    + 2008-04-13 18:45:38 26,368 ----a-w c:\windows\system32\ReinstallBackups\0011\DriverFiles\i386\USBSTOR.SYS
    - 2007-11-30 12:39:22 17,272 ------w c:\windows\system32\spmsg.dll
    + 2008-07-08 13:02:01 17,272 ------w c:\windows\system32\spmsg.dll
    + 2008-09-30 22:42:08 1,286,152 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
    + 2008-09-30 22:45:12 91,656 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SB Audigy 2 Startup Menu"="/L:ENG" [X]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
    "Aim6"="c:\program files\AIM6\aim6.exe" [2008-06-19 50528]
    "MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
    "Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-04-01 3587120]
    "MsgCenterExe"="c:\program files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" [2007-10-27 69632]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
    "CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
    "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
    "YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
    "Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 49263]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
    "MSPY2002"="c:\windows\System32\IME\PINTLGNT\ImScInst.exe" [2003-07-16 59392]
    "PHIME2002ASync"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2003-07-16 455168]
    "PHIME2002A"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2003-07-16 455168]
    "YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2006-07-21 407032]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
    "UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-10-27 185632]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
    "ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
    "CTHelper"="CTHELPER.EXE" [2003-02-20 c:\windows\system32\CTHELPER.EXE]
    "AsioReg"="CTASIO.DLL" [2003-02-20 c:\windows\system32\CTASIO.DLL]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-10-17 113664]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
    HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 73728]
    HPAiODevice(hp officejet k series) - 1.lnk - c:\program files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe [2002-05-23 151552]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\Yahoo!\\Messenger\\yserver.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"=
    "c:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\Photoshop Album Starter Edition.exe"=
    "c:\\Program Files\\Canon\\CameraWindow\\CameraWindowDVC6\\CameraLauncher.exe"=
    "c:\\Program Files\\Creative\\SBAudigy2\\Surround Mixer\\SurMixer.exe"=
    "c:\\Program Files\\Gpotato\\Flyff\\Flyff.exe"=
    "c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
    "c:\\Program Files\\McAfee\\MSC\\mcshell.exe"=
    "c:\\Program Files\\NJStar Communicator\\Njcom32.exe"=
    "c:\\Program Files\\THQ\\Titan Quest Immortal Throne\\Tqit.exe"=
    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
    "c:\\Program Files\\WinRAR\\WinRAR.exe"=
    "c:\\Program Files\\7-Zip\\7zFM.exe"=
    "c:\\WINDOWS\\System32\\freecell.exe"=
    "c:\\Trickster Online\\Splash.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
    "c:\\Program Files\\AIM6\\aim6.exe"=
    "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\MSN Messenger\\livecall.exe"=
    "c:\\Program Files\\Yahoo!\\browser\\ybrowser.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Yahoo!\\YOP\\yop.exe"=
    "c:\\Program Files\\MSN\\MSNCoreFiles\\msn6.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-09-08 198944]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
    S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\DRIVERS\gan_adapter.sys [2006-10-19 10664]
    S3 XDva005;XDva005;c:\windows\system32\XDva005.sys [ ]
    S3 XDva011;XDva011;c:\windows\system32\XDva011.sys [ ]
    S3 XDva014;XDva014;c:\windows\system32\XDva014.sys [ ]
    S3 XDva015;XDva015;c:\windows\system32\XDva015.sys [ ]
    S3 XDva022;XDva022;c:\windows\system32\XDva022.sys [ ]
    S3 XDva024;XDva024;c:\windows\system32\XDva024.sys [ ]
    S3 XDva030;XDva030;c:\windows\system32\XDva030.sys [ ]
    S3 XDva031;XDva031;c:\windows\system32\XDva031.sys [ ]
    S3 XDva064;XDva064;c:\windows\system32\XDva064.sys [ ]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{121c8253-9f62-11db-ac67-000cf1aa6a4b}]
    \Shell\AutoRun\command - H:\LaunchU3.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{121c8254-9f62-11db-ac67-000cf1aa6a4b}]
    \Shell\AutoRun\command - J:\setupSNK.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{458f4ade-d02c-11db-ac99-000cf1aa6a4b}]
    \Shell\AutoRun\command - I:\Autorun.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{625a660d-6c86-11dc-ad83-000cf1aa6a4b}]
    \Shell\AutoRun\command - G:\Autorun.exe
    .
    Contents of the 'Scheduled Tasks' folder

    2008-11-11 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

    2008-11-13 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
    - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]

    2008-06-15 c:\windows\Tasks\McDefragTask.job
    - c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

    2008-11-01 c:\windows\Tasks\McQcTask.job
    - c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-11-12 22:27:51
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PSSdk23]
    "ImagePath"="\??\c:\windows\system32\Drivers\PsSdk23.drv"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    PROCESS: c:\windows\system32\winlogon.exe
    -> c:\windows\system32\Ati2evxx.dll
    .
    Completion time: 2008-11-12 22:30:37
    ComboFix-quarantined-files.txt 2008-11-13 04:30:26
    ComboFix2.txt 2008-11-09 21:01:01

    Pre-Run: 92,599,324,672 bytes free
    Post-Run: 92,821,737,472 bytes free

    532 --- E O F --- 2008-11-13 04:00:21



    and



    7-Zip 4.44 beta
    Acrobat.com
    Acrobat.com
    Ad-Aware
    Address Bar Express
    Adobe AIR
    Adobe AIR
    Adobe Flash Player ActiveX
    Adobe Flash Player Plugin
    Adobe Photoshop 7.0
    Adobe Reader 9
    Adobe Shockwave Player
    Adobe® Photoshop® Album Starter Edition 3.0
    AIM 6
    AIM Toolbar 5.0
    AIMTunes
    AOL Uninstaller (Choose which Products to Remove)
    Apple Mobile Device Support
    Apple Software Update
    AT&T Yahoo! Applications
    ATI - Software Uninstall Utility
    ATI Display Driver
    ATT-AACE
    Bonjour
    Canon Camera Access Library
    Canon Camera Support Core Library
    Canon Camera Window DC_DV 5 for ZoomBrowser EX
    Canon Camera Window DC_DV 6 for ZoomBrowser EX
    Canon Camera Window MC 6 for ZoomBrowser EX
    Canon G.726 WMP-Decoder
    Canon MovieEdit Task for ZoomBrowser EX
    Canon RAW Image Task for ZoomBrowser EX
    Canon RemoteCapture Task for ZoomBrowser EX
    Canon Utilities EOS Utility
    Canon Utilities PhotoStitch
    Canon Utilities ZoomBrowser EX
    CorumOnline
    Creative MediaSource
    Dell ResourceCD
    DellConnect
    DivX Codec
    DivX Content Uploader
    DivX Converter
    DivX Player
    DivX Web Player
    FlashPlayer Plus 2.6(Trial version)
    Google Updater
    HijackThis 2.0.2
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    HP Customer Participation Program 7.0
    HP Document Viewer 7.0
    HP Imaging Device Functions 7.0
    hp officejet k series
    HP Photo Printing Software
    HP Photosmart Premier Software 6.5
    HP Photosmart, Officejet and Deskjet 7.0.A
    HP Share-to-Web
    HP Solution Center 7.0
    HP Update
    Intel(R) PRO Network Adapters and Drivers
    iTunes
    J2SE Runtime Environment 5.0 Update 8
    KSignAccessToolkit v1.0
    McAfee SecurityCenter
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office 2000 SR-1 Disc 2
    Microsoft Office 2000 SR-1 Small Business
    Microsoft Office PowerPoint Viewer 2003
    Microsoft Visual C++ 2005 Redistributable
    Mozilla Firefox (3.0.4)
    MSN Music Assistant
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    Neffy 1,2,0,12
    NJStar Communicator
    OCR Software by I.R.I.S 7.0
    Outspark Launcher
    PlayLinc
    QuickTime
    RealPlayer
    SBC Yahoo! DSL Activation
    Security Update for Windows Internet Explorer 7 (KB933566)
    Security Update for Windows Internet Explorer 7 (KB937143)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB939653)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Shop for HP Supplies
    Sonic RecordNow! Deluxe
    Sonic Update Manager
    Sound Blaster Audigy 2
    Spybot - Search & Destroy
    Titan Quest
    Titan Quest Immortal Throne
    Trickster Online
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    VeohTV BETA
    VideoLAN VLC media player 0.8.6a
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Toolbar
    Windows Live Toolbar
    Windows Media Format 11 runtime
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Media Player 11
    Windows XP Service Pack 3
    WinRAR archiver
    ZoneAlarm

  8. #18
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    You posted now uninstall list.

    Please post a fresh HijackThis log
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  9. #19
    Junior Member
    Join Date
    Nov 2008
    Posts
    14

    Default

    ohhh sorry i thought you meant the uninstall list :P

    here:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:53:55 PM, on 11/16/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
    C:\PROGRA~1\Yahoo!\YOP\yop.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\common files\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\Program Files\McAfee\VirusScan\McShield.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Java\jre1.5.0_08\bin\jucheck.exe
    C:\WINDOWS\system32\dwwin.exe
    C:\WINDOWS\system32\dwwin.exe
    c:\program files\aol\aim toolbar 5.0\AolTbServer.exe
    C:\WINDOWS\system32\dwwin.exe
    C:\WINDOWS\system32\dwwin.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\iTunes\iTunes.exe
    C:\WINDOWS\system32\dumprep.exe
    C:\WINDOWS\system32\dwwin.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1033
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
    O4 - HKCU\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: HPAiODevice(hp officejet k series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
    O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10...I.cab55579.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10...y.cab55579.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
    O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10...t.cab55579.cab
    O16 - DPF: {809A6301-7B40-4436-A02C-87B8D3D7D9E3} (ZPA_DMNO Object) - http://zone.msn.com/bingame/zpagames...o.cab55579.cab
    O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames...1.cab60096.cab
    O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_USAv1001 Class) - http://ares.netgame.com/download/mglaunch_USAv1002.cab
    O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://dist.globalgamecdn.com/dist/n...fyLauncher.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
    O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.gamengame.com/KALogoutComponent.cab
    O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10...y.cab55579.cab
    O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
    O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames...A.cab55579.cab
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
    O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

    --
    End of file - 15029 bytes

  10. #20
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Please go to Kaspersky website and perform an online antivirus scan.

    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

    1. Read through the requirements and privacy statement and click on Accept button.
    2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    3. When the downloads have finished, click on Settings.
    4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      • Spyware, Adware, Dialers, and other potentially dangerous programs
        Archives
    5. Click on My Computer under Scan.
    6. Once the scan is complete, it will display the results. Click on View Scan Report.
    7. You will see a list of infected items there. Click on Save Report As....
    8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
    9. Please post this log in your next reply along with a fresh HijackThis log.


    If you need a tutorial, see here
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •