charlieric Posted June 6, 2008 Report Share Posted June 6, 2008 Need help please! Teen surfer loaded something nasty, and we have lost control of our computer. Here's an HJT log, we would LOVE some help. (Yeah, when you see this log you're probably going to laugh. This computer gets used by gamers, I-tuners, and who knows what. We parents are ready to clean some stuff off here, seriously!) Thanks in advance.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 7:24:47 PM, on 6/5/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16640)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Kontiki\KService.exeC:\Program Files\Softex\OmniPass\Omniserv.exeC:\Program Files\Trend Micro\Internet Security\SfCtlCom.exeC:\Program Files\Softex\OmniPass\OPXPApp.exeC:\Program Files\Trend Micro\BM\TMBMSRV.exeC:\WINDOWS\Explorer.EXEC:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exeC:\windows\system\hpsysdrv.exeC:\WINDOWS\system32\hkcmd.exeC:\HP\KBD\KBD.EXEC:\WINDOWS\ALCXMNTR.EXEC:\WINDOWS\system32\igfxtray.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Java\jre1.6.0_03\bin\jusched.exeC:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exeC:\Program Files\iTunes\iTunesHelper.exeC:\WINDOWS\system32\lphc5lnj0eaat.exeC:\WINDOWS\system32\sysrest32.exeC:\Program Files\Messenger\msmsgs.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exeC:\Program Files\Trend Micro\Internet Security\TmProxy.exeC:\Program Files\interMute\SpamSubtract\SpamSubtract.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\Java\jre1.6.0_03\bin\jucheck.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus9.hpwis.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus9.hpwis.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www6.comcast.net/a/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus9.hpwis.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,;localhostO2 - BHO: ICOOExternal Class - {0519A9C9-064A-4cbc-BC47-D0EACD581477} - C:\Program Files\ICOO Loader\addons\icooue.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: ICOODManager Class - {465A59EC-20E5-4fca-A38A-E5EC3C480218} - C:\Program Files\ICOO Loader\addons\icoou.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetectO4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exeO4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXEO4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [updateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKLM\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -schedulerO4 - HKLM\..\Run: [ProfileWatcher] C:\Program Files\ProfileWatcher\profilewatcher.exeO4 - HKLM\..\Run: [uFC Media Manager Tray] "C:\Program Files\Entriq\MediaSphere\Bin\EntriqMediaTray.exe" /CustomId:UFCO4 - HKLM\..\Run: [ufSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [lphc5lnj0eaat] C:\WINDOWS\system32\lphc5lnj0eaat.exeO4 - HKLM\..\Run: [sysrest32.exe] C:\WINDOWS\system32\sysrest32.exeO4 - HKLM\..\Run: [AXPDefender] C:\Program Files\AXPDefender\AXPDefender.exeO4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHookO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1O4 - S-1-5-18 Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')O4 - .DEFAULT Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exeO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\All Users\Documents\AIM\aim.exeO9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exeO9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exeO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cabO16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.miniclip.com/games/ricochet-los...bGameLoader.cabO16 - DPF: {5A9D4578-6649-4692-921B-ACA9ADAB007C} (UFC Class) - http://evideo.ufc.com/ufc/cabfiles/UFC_3_6_0_6.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cabO16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxoramun...mjolauncher.cabO16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} (MediaControl Class) - http://evideo.ufc.com/ufc/cabfiles/Entriq_...0_15_Silent.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/heavyweap...aploader_v6.cabO18 - Protocol: icoo - {86FE362E-74FA-4F71-8B69-B94D28880628} - C:\Program Files\ICOO Loader\addons\icoou.dllO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exeO23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exeO23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exeO23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exeO23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeO23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exeO23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exeO23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe--End of file - 10986 bytes Link to post Share on other sites
Andro1d Posted June 6, 2008 Report Share Posted June 6, 2008 Hello and Welcome to BT. I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today.Looking at your system now, one or more of the identified infections is a backdoor application which can allow attackers to access your computer, stealing passwords and personal data.If this computer is ever used for on-line banking, I suggest you do the following immediately:1. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.2. From a clean computer, change ALL your on-line passwords for email, for banks, financial accounts, PayPal, eBay, on-line companies, any on-line forums or groups you belong to.Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.Please visit this web page for instructions for downloading and running ComboFix:http://www.bleepingcomputer.com/combofix/how-to-use-combofixThis includes installing the Windows XP Recovery Console in case you have not installed it yet. For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058. Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.Once you have finished installing the Windows Recovery Console, please continue with the rest of the tutorial at the above link.Post the log from ComboFix when you've accomplished that, along with a new HijackThis log. Link to post Share on other sites
charlieric Posted June 7, 2008 Author Report Share Posted June 7, 2008 Thanks for the start. I'll get on in and repost after I follow your instruction. Link to post Share on other sites
Andro1d Posted June 7, 2008 Report Share Posted June 7, 2008 I will await the logs. Link to post Share on other sites
charlieric Posted June 7, 2008 Author Report Share Posted June 7, 2008 I will await the logs. I trust your advice because my Trend Anti-virus hasn't been able to help me get rid of this yet, but why do they try to block my download of Combo Fix? Link to post Share on other sites
Andro1d Posted June 7, 2008 Report Share Posted June 7, 2008 Hello again,First, Trend-Micro isn't a very good AV program in my opinion. I have previsouly used it, and wasn't impressed at all with it in general. Missed a lot of malware on my pc, slow updates, etc. Now to answer your questions, ComboFix uses many advanced procedures that are used to stop system processes and do other important activities. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. Link to post Share on other sites
charlieric Posted June 7, 2008 Author Report Share Posted June 7, 2008 Hello again,First, Trend-Micro isn't a very good AV program in my opinion. I have previsouly used it, and wasn't impressed at all with it in general. Missed a lot of malware on my pc, slow updates, etc. Now to answer your questions, ComboFix uses many advanced procedures that are used to stop system processes and do other important activities. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.That's what I would have guessed, and I think I'm about done with Trend.In following the directions, I hit a small snag. When I drag the file I downloaded from Microsoft onto the ComboFix file, it asks me if I want to run ComboFix instead of seeming to set up Windows Recovery Console. Is this normal? Link to post Share on other sites
charlieric Posted June 7, 2008 Author Report Share Posted June 7, 2008 Hello again,First, Trend-Micro isn't a very good AV program in my opinion. I have previsouly used it, and wasn't impressed at all with it in general. Missed a lot of malware on my pc, slow updates, etc. Now to answer your questions, ComboFix uses many advanced procedures that are used to stop system processes and do other important activities. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.That's what I would have guessed, and I think I'm about done with Trend.In following the directions, I hit a small snag. When I drag the file I downloaded from Microsoft onto the ComboFix file, it asks me if I want to run ComboFix instead of seeming to set up Windows Recovery Console. Is this normal?OK, no matter, I ran everything just fine and here's the ComboFix log. It deleted one program, but there's still a bunch of junk left. Awaiting your next instructions:ComboFix 08-06-06.4 - Owner 2008-06-06 20:15:22.1 - NTFSx86Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.398 [GMT -6:00]Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).C:\Documents and Settings\All Users\Desktop\AXPDefender.lnkC:\Documents and Settings\All Users\Start Menu\Programs\Advanced XP DefenderC:\Documents and Settings\All Users\Start Menu\Programs\Advanced XP Defender.lnkC:\Documents and Settings\All Users\Start Menu\Programs\Advanced XP Defender\Advanced XP Defender.lnkC:\Documents and Settings\All Users\Start Menu\Programs\Advanced XP Defender\How to register.lnkC:\Documents and Settings\All Users\Start Menu\Programs\Advanced XP Defender\License Agreement.lnkC:\Documents and Settings\All Users\Start Menu\Programs\Advanced XP Defender\Register.lnkC:\Documents and Settings\All Users\Start Menu\Programs\Advanced XP Defender\Uninstall.lnkC:\Documents and Settings\Nickz folder\Application Data\AXPDefenderC:\Documents and Settings\Nickz folder\Application Data\FunWebProductsC:\Documents and Settings\Nickz folder\Application Data\FunWebProducts\Data\Nickz folder\avatar.datC:\Documents and Settings\Owner\Application Data\AXPDefenderC:\Program Files\AXPDefenderC:\Program Files\AXPDefender\AXPDefender.exeC:\Program Files\AXPDefender\AXPDefender.exe.localC:\Program Files\AXPDefender\AXPDefenderSkin.dllC:\Program Files\AXPDefender\database.datC:\Program Files\AXPDefender\license.txtC:\Program Files\AXPDefender\MFC71.dllC:\Program Files\AXPDefender\MFC71ENU.DLLC:\Program Files\AXPDefender\msvcp71.dllC:\Program Files\AXPDefender\msvcr71.dllC:\Program Files\AXPDefender\Uninstall.exeC:\WINDOWS\system32\sysrest32.exeD:\Autorun.inf.((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))).-------\Service_sysrest.sys((((((((((((((((((((((((( Files Created from 2008-05-07 to 2008-06-07 ))))))))))))))))))))))))))))))).2008-06-06 15:27 . 2008-06-06 15:31 <DIR> d-------- C:\Program Files\Wrath of the Lich King Alpha2008-06-06 10:48 . 2008-06-05 17:57 52,736 --a------ C:\WINDOWS\system32\18.tmp2008-06-04 18:33 . 2008-06-04 18:33 <DIR> d-------- C:\Program Files\Spyware Doctor2008-06-04 18:33 . 2008-06-04 18:33 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\PC Tools2008-06-04 18:33 . 2007-12-10 13:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys2008-06-04 18:33 . 2007-12-10 13:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys2008-06-04 18:33 . 2008-02-01 11:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys2008-06-04 18:33 . 2007-12-10 13:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys2008-06-04 00:28 . 2008-06-04 00:28 <DIR> d-------- C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat2008-06-03 22:28 . 2008-06-03 22:28 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat2008-06-03 21:05 . 2008-06-03 21:05 93,184 --a------ C:\WINDOWS\system32\lphc5lnj0eaat.exe2008-06-03 21:05 . 2008-06-06 20:50 90,838 --a------ C:\WINDOWS\system32\phc5lnj0eaat.bmp2008-05-24 16:08 . 2008-06-04 12:57 <DIR> d-------- C:\Program Files\Cheat Engine2008-05-19 16:28 . 2008-06-06 15:25 <DIR> d----c--- C:\Patch's (sams game folder! dont delete plz).(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2008-06-06 23:24 --------- d-----w C:\Program Files\Quicken2008-06-06 21:27 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment2008-06-06 00:10 --------- d-----w C:\Program Files\Trend Micro2008-06-04 14:42 --------- d-----w C:\Program Files\LimeWire2008-05-26 02:01 --------- d-----w C:\Program Files\World of Warcraft2008-05-17 00:15 --------- d-----w C:\Documents and Settings\Owner\Application Data\AdobeUM2008-05-14 16:07 --------- d-----w C:\Program Files\Apple Software Update2008-05-14 15:55 --------- d-----w C:\Program Files\iTunes2008-05-14 15:53 --------- d-----w C:\Program Files\iPod2008-05-14 15:44 --------- d-----w C:\Program Files\QuickTime2008-05-10 00:42 --------- d-----w C:\Documents and Settings\Nickz folder\Application Data\Apple Computer2008-05-02 22:22 205,328 ----a-w C:\WINDOWS\system32\drivers\tmxpflt.sys2008-05-02 22:21 36,368 ----a-w C:\WINDOWS\system32\drivers\tmpreflt.sys2008-05-02 22:17 1,169,240 ----a-w C:\WINDOWS\system32\drivers\vsapint.sys2008-04-25 15:08 --------- d-----w C:\Program Files\Bodog Poker2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys2004-05-16 02:04 2,142,279 -c--a-w C:\Documents and Settings\The Boyz\gosetup.exe.<pre>-c--a-w 212,212 2008-05-24 22:25:31 C:\Patch's (sams game folder! dont delete plz)\2.4.1jumphack\ .exe</pre>((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0519A9C9-064A-4cbc-BC47-D0EACD581477}]2004-09-25 17:05 28672 --a--c--- C:\Program Files\ICOO Loader\addons\icooue.dll[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{465A59EC-20E5-4fca-A38A-E5EC3C480218}]2004-09-22 16:36 68096 --a--c--- C:\Program Files\ICOO Loader\addons\icoou.dll[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"NVIEW"="nview.dll" [2003-05-03 00:19 835654 C:\WINDOWS\system32\nview.dll]"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 19:27 68856]"OE"="C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2007-09-18 01:30 488712]"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45 313472][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04 52736]"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-20 16:51 118784]"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 21:02 61440]"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 22:42 212992]"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-05-03 00:19 4640768]"nwiz"="nwiz.exe" [2003-05-03 00:19 323584 C:\WINDOWS\system32\nwiz.exe]"PS2"="C:\WINDOWS\system32\ps2.exe" [ ]"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 14:47 57344 C:\WINDOWS\ALCXMNTR.EXE]"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 16:55 155648]"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01 110592]"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-02-25 21:29 180269]"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [ ]"ProfileWatcher"="C:\Program Files\ProfileWatcher\profilewatcher.exe" [ ]"UFC Media Manager Tray"="C:\Program Files\Entriq\MediaSphere\Bin\EntriqMediaTray.exe" [2007-03-12 23:15 387152]"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-02-16 00:56 1398024]"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]"lphc5lnj0eaat"="C:\WINDOWS\system32\lphc5lnj0eaat.exe" [2008-06-03 21:05 93184]"sysrest32.exe"="C:\WINDOWS\system32\sysrest32.exe" [ ]C:\Documents and Settings\Default User\Start Menu\Programs\Startup\mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 08:11:14 27136]C:\Documents and Settings\Nickz folder\Start Menu\Programs\Startup\hc_tray.lnk - C:\Program Files\Kuma Games\hcsystray\hc_tray.exe [2007-04-26 13:49:20 31944]C:\Documents and Settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe [2003-07-26 02:57:44 552960]C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]"NoDispBackgroundPage"= 1 (0x1)"NoDispScrSavPage"= 1 (0x1)[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]C:\Program Files\Softex\OmniPass\opxpgina.dll 2003-02-21 04:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll[HKEY_LOCAL_MACHINE\software\microsoft\security center]"AntiVirusOverride"=dword:00000001[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]"DisableMonitoring"=dword:00000001[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]"DisableMonitoring"=dword:00000001[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="C:\\Documents and Settings\\All Users\\Documents\\iTunes\\iTunes.exe"="C:\\Program Files\\World of Warcraft\\WoW.exe"="C:\\Program Files\\World of Warcraft\\Repair.exe"="C:\\Program Files\\AIM\\aim.exe"="C:\\StubInstaller.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\Maxis\\SimCity 3000 Unlimited\\Apps\\Updater\\UPDATER.EXE"="C:\\Program Files\\Real\\RealOne Player\\realplay.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\Kuma Games\\KumaClientHCnet.exe"="C:\\WINDOWS\\Installer\\{047882CA-975E-41FC-BE02-6D6396106C4E}\\ACDSee_PM_Shtcut.exe"="C:\\Program Files\\Warcraft III\\Warcraft III.exe"="C:\\Program Files\\Warcraft III\\World Editor.exe"="C:\\Program Files\\Kontiki\\KService.exe"="C:\\Program Files\\Warcraft III\\Frozen Throne.exe"="C:\\Program Files\\iTunes\\iTunes.exe"=[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"3724:TCP"= 3724:TCP:Blizzard Downloader"6112:TCP"= 6112:TCP:Blizzard Downloader"6112:UDP"= 6112:UDP:warcraft.Contents of the 'Scheduled Tasks' folder"2008-06-05 19:57:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"- C:\Program Files\Apple Software Update\SoftwareUpdate.exe"2008-06-06 23:26:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE.**************************************************************************catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2008-06-06 20:51:26Windows 5.1.2600 Service Pack 2 NTFSscanning hidden processes ... scanning hidden autostart entries ...scanning hidden files ... scan completed successfullyhidden files: 0**************************************************************************.--------------------- DLLs Loaded Under Running Processes ---------------------PROCESS: C:\WINDOWS\system32\winlogon.exe-> C:\Program Files\Softex\OmniPass\opxpgina.dll.------------------------ Other Running Processes ------------------------.C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Kontiki\KService.exeC:\Program Files\Softex\OmniPass\omniServ.exeC:\Program Files\Trend Micro\Internet Security\SfCtlCom.exeC:\Program Files\Trend Micro\BM\TMBMSRV.exeC:\Program Files\Softex\OmniPass\OPXPApp.exeC:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exeC:\Program Files\Trend Micro\Internet Security\TmProxy.exeC:\Program Files\Entriq\MediaSphere\Bin\EntriqMediaServer.exeC:\Program Files\iPod\bin\iPodService.exeC:\WINDOWS\system32\wscript.exeC:\Documents and Settings\Owner\Local Settings\temp\.ttA.tmpC:\Program Files\Java\jre1.6.0_03\bin\jucheck.exeC:\WINDOWS\system32\imapi.exe.**************************************************************************.Completion time: 2008-06-06 21:06:20 - machine was rebooted [Owner]ComboFix-quarantined-files.txt 2008-06-07 03:05:41Pre-Run: 17,470,369,792 bytes freePost-Run: 20,852,535,296 bytes free201 --- E O F --- 2008-05-28 23:57:26 Link to post Share on other sites
Andro1d Posted June 7, 2008 Report Share Posted June 7, 2008 (edited) Hello again,Please download RogueRemover by RubberDucky here.Double-click rr-free-setup.exe to begin installing the program.Follow the setup instructions for installation.Double-click the RogueRemover icon on your desktop.Once the program runs, select Check for Updates.When prompted, select Check for Updates.If prompted again, click Download to receive the latest updates.When completed, close the update window.Next, click ScanIf it detects anything, select to remove all objects found.Close RogueRemover Edited June 7, 2008 by MoNsTeReNeRgY22 Link to post Share on other sites
charlieric Posted June 7, 2008 Author Report Share Posted June 7, 2008 Hello again,Please download RogueRemover by RubberDucky here.Double-click rr-free-setup.exe to begin installing the program.Follow the setup instructions for installation.Double-click the RogueRemover icon on your desktop.Once the program runs, select Check for Updates.When prompted, select Check for Updates.If prompted again, click Download to receive the latest updates.When completed, close the update window.Next, click ScanIf it detects anything, select to remove all objects found.Close RogueRemoverI downloaded and ran Rogue Remover after updating it. It said "nothing found". Link to post Share on other sites
Andro1d Posted June 7, 2008 Report Share Posted June 7, 2008 Ok, well scan and pleae post the log it gives. Link to post Share on other sites
charlieric Posted June 8, 2008 Author Report Share Posted June 8, 2008 Ok, well scan and pleae post the log it gives.Monster, there's no log option given to me when I run RogueRemover. It also takes about three seconds for it to scan my computer, so I don't know if it is really working right. Am I doing something wrong? Link to post Share on other sites
Andro1d Posted June 8, 2008 Report Share Posted June 8, 2008 Hey Charlie,Mhmm, lets try a different tool if you don't mind.NOTE: You will need to temporarily disable any programs you have running that will block attempts to edit the registry. As FixIEDef calls REGEDIT to delete registry keys added by Zlob, Trojan.Downloader.Delf, AntiSpyPro, and IE Defender.Download FixIEDef.exe by ShadowPuterDude to the Desktop.Note: FixIEDef now supports Non-English Language SystemsDouble-click FixIEDef.exe:That will open the About FixIEDef screen. Click OK to continue:Next, press the Scan! button:FixIEDef needs to run as Administrator to perform correctly. This message simply confirms it was able to run with admin privileges. Click OK to continue:Wait for the scan to finish. It shouldn't take very long:WARNING: FixIEDef will kill all copies of Internet Explorer and Explorer that are running, during removal of malicious files. The icons and Start Menu on your Desktop will not be visible while FixIEDef is removing malicious files. This is necessary to remove parts of the infection that would otherwise not be removed.After the !!! All Finished !!! message is displayed, click Exit:Post the FixIEDef log file, located on the Desktop.Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool". It is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.See: http://www.beyondlogic.org/consulting/proc...processutil.htm Link to post Share on other sites
charlieric Posted June 8, 2008 Author Report Share Posted June 8, 2008 Hey Charlie,Mhmm, lets try a different tool if you don't mind.NOTE: You will need to temporarily disable any programs you have running that will block attempts to edit the registry. As FixIEDef calls REGEDIT to delete registry keys added by Zlob, Trojan.Downloader.Delf, AntiSpyPro, and IE Defender.Download FixIEDef.exe by ShadowPuterDude to the Desktop.Note: FixIEDef now supports Non-English Language SystemsDouble-click FixIEDef.exe:That will open the About FixIEDef screen. Click OK to continue:Next, press the Scan! button:FixIEDef needs to run as Administrator to perform correctly. This message simply confirms it was able to run with admin privileges. Click OK to continue:Wait for the scan to finish. It shouldn't take very long:WARNING: FixIEDef will kill all copies of Internet Explorer and Explorer that are running, during removal of malicious files. The icons and Start Menu on your Desktop will not be visible while FixIEDef is removing malicious files. This is necessary to remove parts of the infection that would otherwise not be removed.After the !!! All Finished !!! message is displayed, click Exit:Post the FixIEDef log file, located on the Desktop.Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool". It is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.See: http://www.beyondlogic.org/consulting/proc...processutil.htmHere's the log, Monster. I should also note that I ran Trend virus scan this morning, and deleted or quarantined at least two infected viruses called Troj_Generic.ADV (or something like that). Since yesterday, I haven't had an instance of that pop-up box coming up warning me of malware, which then tries to install the bogus XP Defender 2008 or Malware Protector 2008 that was one of the original problems, so maybe some of this is now fixed. I do still have a set desktop background that has a spyware warning, and am unable to change the wallpaper or work our normal screensaver, which I found out today was due to changes that the malware made on those options in the registry. Anyway, FYI, and I'll await further instructions from you....********************************************************************************* ** FixIEDef Log ** Version 1.4.16.4411 ** *********************************************************************************Created at 21:27:55 on Saturday, June 07, 2008Time Zone : (GMT-07:00) Mountain Time (US & Canada)Operating System : Microsoft Windows XP Home EditionService Pack Level: Service Pack 2System Langauge : English (United States)Processor : X86Boot State : Normal boot--------------------------------------------------------------------------------!!! Files that have been deleted !!!C:\WINDOWS\SwSys1.bmpC:\WINDOWS\SwSys2.bmpC:\WINDOWS\system32\Desktop.icoC:\WINDOWS\system32\Help.icoC:\WINDOWS\system32\IE.icoC:\WINDOWS\system32\Open.icoC:\WINDOWS\system32\Quick.icoC:\WINDOWS\system32\Uninstall.ico--------------------------------------------------------------------------------!!! Directories that have been removed !!!No malicious directories to be removed--------------------------------------------------------------------------------!!! Registry entries that have been removed !!!No malicious Registry entries found================================================================================All Done ShadowPuterDudeSafe Surfing!!! Link to post Share on other sites
Andro1d Posted June 8, 2008 Report Share Posted June 8, 2008 Hello again,Step 1Please download SmitfraudFix (by S!Ri) to your Desktop.Next, please reboot your computer in Safe Mode by doing the following.Restart your computerAfter hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;Instead of Windows loading as normal, a menu with options should appear;Select the first option, to run Windows in Safe Mode, then press "Enter".Choose your usual account.Once in Safe Mode, double-click on SmitfraudFix.exeSelect option #2 - Clean by typing 2 and press "Enter" to delete infected files.You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.The report can also be found at the root of the system drive, usually at C:\rapport.txtWarning : running option #2 on a non infected computer will remove your Desktop background.Step 2Please download Deckard's System Scanner (DSS) to your desktop.Close all applications and windows.Double-click on dss.exe to run it, and follow the prompts.When the scan is complete, a text file will open - Main.txtCopy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of Main.txt into your thread.An additional text file, Extra.txt,will also be available (by default) in the following FOLDER, C:\Deckard\System Scanner.Please go to that folder and also copy the contents of Extra.txt to your post as well.Note: Some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so. Link to post Share on other sites
charlieric Posted June 8, 2008 Author Report Share Posted June 8, 2008 Hi again. Here are the new logs. Also, my Trend anti-virus is identifying a file in Smitfraudfix I downloaded as containing a virus, again the same Troj_Generic.ADV variety. I assume it is a false identification, so I didn't do anything. Another reason to get a different anti-virus program?Rapport:SmitFraudFix v2.323Scan done at 8:31:31.93, Sun 06/08/2008Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFixOS: Microsoft Windows XP [Version 5.1.2600] - Windows_NTThe filesystem type is NTFSFix run in safe mode»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix!!!Attention, following keys are not inevitably infected!!!SrchSTS.exe by S!RiSearch SharedTaskScheduler's .dll»»»»»»»»»»»»»»»»»»»»»»»» Killing process»»»»»»»»»»»»»»»»»»»»»»»» hosts127.0.0.1 localhost»»»»»»»»»»»»»»»»»»»»»»»» VACFixVACFixCredits: Malware Analysis & DiagnosticCode: S!Ri»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 FixS!Ri's WS2Fix: LSP not Found.»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos FixGenericRenosFix by S!Ri»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files»»»»»»»»»»»»»»»»»»»»»»»» IEDFixIEDFixCredits: Malware Analysis & DiagnosticCode: S!Ri»»»»»»»»»»»»»»»»»»»»»»»» 404Fix404FixCredits: Malware Analysis & DiagnosticCode: S!Ri»»»»»»»»»»»»»»»»»»»»»»»» DNSHKLM\SYSTEM\CCS\Services\Tcpip\..\{E4642448-E7D1-47A5-BE6A-E7F27CB79F02}: DhcpNameServer=68.87.85.98 68.87.69.146HKLM\SYSTEM\CS1\Services\Tcpip\..\{E4642448-E7D1-47A5-BE6A-E7F27CB79F02}: DhcpNameServer=68.87.85.98 68.87.69.146HKLM\SYSTEM\CS2\Services\Tcpip\..\{E4642448-E7D1-47A5-BE6A-E7F27CB79F02}: DhcpNameServer=68.87.85.98 68.87.69.146HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=68.87.85.98 68.87.69.146HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=68.87.85.98 68.87.69.146HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=68.87.85.98 68.87.69.146»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System!!!Attention, following keys are not inevitably infected!!![HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]"System"=""»»»»»»»»»»»»»»»»»»»»»»»» Registry CleaningRegistry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix!!!Attention, following keys are not inevitably infected!!!SrchSTS.exe by S!RiSearch SharedTaskScheduler's .dll»»»»»»»»»»»»»»»»»»»»»»»» EndAnd the logs from Deckard:Deckard's System Scanner v20071014.68Run by Owner on 2008-06-08 09:19:05Computer is in Normal Mode.---------------------------------------------------------------------------------- System Restore --------------------------------------------------------------Successfully created a Deckard's System Scanner Restore Point.-- Last 4 Restore Point(s) --4: 2008-06-08 15:19:16 UTC - RP4 - Deckard's System Scanner Restore Point3: 2008-06-08 02:58:56 UTC - RP3 - System Checkpoint2: 2008-06-07 02:10:34 UTC - RP2 - ComboFix created restore point1: 2008-06-07 02:09:31 UTC - RP1 - System CheckpointBacked up registry hives.Performed disk cleanup.-- HijackThis (run as Owner.exe) -----------------------------------------------Logfile of Trend Micro HijackThis v2.0.2Scan saved at 09:20:05, on 6/8/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16640)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Kontiki\KService.exeC:\Program Files\Softex\OmniPass\Omniserv.exeC:\Program Files\Trend Micro\Internet Security\SfCtlCom.exeC:\Program Files\Softex\OmniPass\OPXPApp.exeC:\Program Files\Trend Micro\BM\TMBMSRV.exeC:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exeC:\Program Files\Trend Micro\Internet Security\TmProxy.exeC:\WINDOWS\Explorer.EXEC:\windows\system\hpsysdrv.exeC:\WINDOWS\system32\hkcmd.exeC:\HP\KBD\KBD.EXEC:\WINDOWS\ALCXMNTR.EXEC:\WINDOWS\system32\igfxtray.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Java\jre1.6.0_03\bin\jusched.exeC:\Program Files\Entriq\MediaSphere\Bin\EntriqMediaTray.exeC:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exeC:\Program Files\iTunes\iTunesHelper.exeC:\WINDOWS\system32\lphc5lnj0eaat.exeC:\Program Files\Entriq\MediaSphere\Bin\EntriqMediaServer.exeC:\Program Files\Messenger\msmsgs.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\interMute\SpamSubtract\SpamSubtract.exeC:\Program Files\Java\jre1.6.0_03\bin\jucheck.exeC:\Documents and Settings\Owner\Desktop\dss.exeC:\PROGRA~1\TRENDM~1\HIJACK~1\Owner.exeR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus9.hpwis.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,;localhostO2 - BHO: ICOOExternal Class - {0519A9C9-064A-4cbc-BC47-D0EACD581477} - C:\Program Files\ICOO Loader\addons\icooue.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: ICOODManager Class - {465A59EC-20E5-4fca-A38A-E5EC3C480218} - C:\Program Files\ICOO Loader\addons\icoou.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dllO3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetectO4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exeO4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXEO4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [updateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKLM\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -schedulerO4 - HKLM\..\Run: [ProfileWatcher] C:\Program Files\ProfileWatcher\profilewatcher.exeO4 - HKLM\..\Run: [uFC Media Manager Tray] "C:\Program Files\Entriq\MediaSphere\Bin\EntriqMediaTray.exe" /CustomId:UFCO4 - HKLM\..\Run: [ufSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [lphc5lnj0eaat] C:\WINDOWS\system32\lphc5lnj0eaat.exeO4 - HKLM\..\Run: [sysrest32.exe] C:\WINDOWS\system32\sysrest32.exeO4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHookO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1O4 - S-1-5-18 Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')O4 - .DEFAULT Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exeO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\All Users\Documents\AIM\aim.exeO9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exeO9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exeO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cabO16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.miniclip.com/games/ricochet-los...bGameLoader.cabO16 - DPF: {5A9D4578-6649-4692-921B-ACA9ADAB007C} (UFC Class) - http://evideo.ufc.com/ufc/cabfiles/UFC_3_6_0_6.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cabO16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxoramun...mjolauncher.cabO16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} (MediaControl Class) - http://evideo.ufc.com/ufc/cabfiles/Entriq_...0_15_Silent.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/heavyweap...aploader_v6.cabO18 - Protocol: icoo - {86FE362E-74FA-4F71-8B69-B94D28880628} - C:\Program Files\ICOO Loader\addons\icoou.dllO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exeO23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exeO23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exeO23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exeO23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeO23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exeO23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exeO23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe--End of file - 10266 bytes-- File Associations -----------------------------------------------------------All associations okay.-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------All drivers whitelisted.-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>-- Device Manager: Disabled ----------------------------------------------------No disabled devices found.-- Scheduled Tasks -------------------------------------------------------------2008-06-07 21:26:00 364 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job2008-06-05 13:57:10 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job-- Files created between 2008-05-08 and 2008-06-08 -----------------------------2008-06-08 08:31:43 4292 --a------ C:\WINDOWS\system32\tmp.reg2008-06-08 08:30:56 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe2008-06-08 08:30:56 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >2008-06-08 08:30:56 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>2008-06-08 08:30:56 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>2008-06-08 08:30:56 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>2008-06-08 08:30:56 82944 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>2008-06-08 08:30:56 51200 --a------ C:\WINDOWS\system32\dumphive.exe2008-06-08 08:30:56 82944 --a------ C:\WINDOWS\system32\404Fix.exe <Not Verified; S!Ri.URZ; IEDFix>2008-06-06 22:37:36 0 d-------- C:\Program Files\RogueRemover FREE2008-06-06 20:09:09 68096 --a------ C:\WINDOWS\zip.exe2008-06-06 20:09:09 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>2008-06-06 20:09:09 98816 --a------ C:\WINDOWS\sed.exe2008-06-06 20:09:09 80412 --a------ C:\WINDOWS\grep.exe2008-06-06 20:09:09 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >2008-06-06 20:09:08 49152 --a------ C:\WINDOWS\VFind.exe2008-06-06 20:09:08 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>2008-06-06 20:09:08 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>2008-06-06 15:27:23 0 d-------- C:\Program Files\Wrath of the Lich King Alpha2008-06-04 18:43:58 0 d-------- C:\Documents and Settings\Owner\Application Data\Mozilla2008-06-04 18:33:40 0 d-------- C:\Program Files\Spyware Doctor2008-06-04 18:33:40 0 d-------- C:\Documents and Settings\Owner\Application Data\PC Tools2008-06-04 00:28:00 0 d-------- C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat2008-06-03 22:28:07 0 d-------- C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat2008-06-03 21:05:54 93184 --a------ C:\WINDOWS\system32\lphc5lnj0eaat.exe2008-05-24 16:08:56 0 d-------- C:\Program Files\Cheat Engine2008-05-19 16:28:54 0 d------c- C:\Patch's (sams game folder! dont delete plz)-- Find3M Report ---------------------------------------------------------------2008-06-07 12:01:54 0 d-------- C:\Program Files\Quicken2008-06-07 08:47:31 0 d-------- C:\Program Files\ProfileWatcher2008-06-06 15:27:27 0 d-------- C:\Program Files\Common Files\Blizzard Entertainment2008-06-05 18:10:02 0 d-------- C:\Program Files\Trend Micro2008-06-04 08:42:31 0 d-------- C:\Program Files\LimeWire2008-05-26 10:07:19 0 d-------- C:\Documents and Settings\Owner\Application Data\Adobe2008-05-25 20:01:00 0 d-------- C:\Program Files\World of Warcraft2008-05-16 18:15:32 0 d-------- C:\Documents and Settings\Owner\Application Data\AdobeUM2008-05-14 10:07:05 0 d-------- C:\Program Files\Apple Software Update2008-05-14 09:55:33 0 d-------- C:\Program Files\iTunes2008-05-14 09:53:04 0 d-------- C:\Program Files\iPod2008-05-14 09:44:25 0 d-------- C:\Program Files\QuickTime2008-05-04 09:56:46 0 d-------- C:\Documents and Settings\Owner\Application Data\Real2008-04-25 09:08:24 0 d-------- C:\Program Files\Bodog Poker2008-03-30 21:00:17 664 --a----c- C:\WINDOWS\system32\d3d9caps.dat-- Registry Dump ---------------------------------------------------------------*Note* empty entries & legit default entries are not shown[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0519A9C9-064A-4cbc-BC47-D0EACD581477}]09/25/2004 17:05 28672 --a--c--- C:\Program Files\ICOO Loader\addons\icooue.dll[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{465A59EC-20E5-4fca-A38A-E5EC3C480218}]09/22/2004 16:36 68096 --a--c--- C:\Program Files\ICOO Loader\addons\icoou.dll[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [05/07/1998 17:04]"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [08/20/2004 16:51]"KBD"="C:\HP\KBD\KBD.EXE" [02/11/2003 21:02]"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [09/13/2002 22:42]"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [05/03/2003 00:19]"nwiz"="nwiz.exe" [05/03/2003 00:19 C:\WINDOWS\system32\nwiz.exe]"PS2"="C:\WINDOWS\system32\ps2.exe" []"AlcxMonitor"="ALCXMNTR.EXE" [09/07/2004 14:47 C:\WINDOWS\ALCXMNTR.EXE]"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [08/20/2004 16:55]"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [08/19/2003 01:01]"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [02/25/2006 21:29]"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 01:11]"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" []"ProfileWatcher"="C:\Program Files\ProfileWatcher\profilewatcher.exe" []"UFC Media Manager Tray"="C:\Program Files\Entriq\MediaSphere\Bin\EntriqMediaTray.exe" [03/12/2007 23:15]"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [02/16/2008 00:56]"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/28/2008 23:37]"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36]"lphc5lnj0eaat"="C:\WINDOWS\system32\lphc5lnj0eaat.exe" [06/03/2008 21:05]"sysrest32.exe"="C:\WINDOWS\system32\sysrest32.exe" [][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"NVIEW"="nview.dll,nViewLoadHook" []"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 10:24]"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56]"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [06/23/2007 19:27]"OE"="C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [09/18/2007 01:30]"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [03/30/2006 17:45]C:\Documents and Settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe [7/26/2003 2:57:44 AM]C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 11:05:26 PM][HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"HideLegacyLogonScripts"=0 (0x0)"HideLogoffScripts"=0 (0x0)"RunLogonScriptSync"=1 (0x1)"RunStartupScriptSync"=0 (0x0)"HideStartupScripts"=0 (0x0)[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]"HideLegacyLogonScripts"=0 (0x0)"HideLogoffScripts"=0 (0x0)"RunLogonScriptSync"=1 (0x1)"RunStartupScriptSync"=0 (0x0)"HideStartupScripts"=0 (0x0)"NoDispBackgroundPage"=1 (0x1)"NoDispScrSavPage"=1 (0x1)[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina] C:\Program Files\Softex\OmniPass\opxpgina.dll 02/21/2003 04:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]@="Service"[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]@="Volume shadow copy"-- End of Deckard's System Scanner: finished at 2008-06-08 09:21:58 ------------Deckard's System Scanner v20071014.68Extra logfile - please post this as an attachment with your post.---------------------------------------------------------------------------------- System Information ----------------------------------------------------------Microsoft Windows XP Home Edition (build 2600) SP 2.0Architecture: X86; Language: EnglishCPU 0: Intel® Pentium® 4 CPU 2.60GHzCPU 1: Intel® Pentium® 4 CPU 2.60GHzPercentage of Memory in Use: 53%Physical Memory (total/avail): 759.36 MiB / 350.97 MiBPagefile Memory (total/avail): 1860.02 MiB / 1512.47 MiBVirtual Memory (total/avail): 2047.88 MiB / 1923.88 MiBA: is Removable (No Media)C: is Fixed (NTFS) - 69.55 GiB total, 19.43 GiB free. D: is Fixed (FAT32) - 4.96 GiB total, 0.9 GiB free. E: is CDROM (No Media)F: is CDROM (No Media)\\.\PHYSICALDRIVE0 - WDC WD800EB-11DJF0 - 74.53 GiB - 2 partitions \PARTITION0 - Unknown - 4.97 GiB - D: \PARTITION1 (bootable) - Installable File System - 69.55 GiB - C:-- Security Center -------------------------------------------------------------AUOptions is scheduled to auto-install.Windows Internal Firewall is enabled.AntivirusOverride is set.FW: Trend Micro Personal Firewall v5.2 (Trend Micro Inc.)AV: Trend Micro Internet Security v16.10.1079 ()[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019""%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019""C:\\Documents and Settings\\All Users\\Documents\\iTunes\\iTunes.exe"="C:\\Documents and Settings\\All Users\\Documents\\iTunes\\iTunes.exe:*:Enabled:iTunes""C:\\Program Files\\World of Warcraft\\WoW.exe"="C:\\Program Files\\World of Warcraft\\WoW.exe:*:Enabled:World of Warcraft""C:\\Program Files\\World of Warcraft\\Repair.exe"="C:\\Program Files\\World of Warcraft\\Repair.exe:*:Enabled:World of Warcraft - Repair""C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger""C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer""C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent""C:\\Program Files\\Maxis\\SimCity 3000 Unlimited\\Apps\\Updater\\UPDATER.EXE"="C:\\Program Files\\Maxis\\SimCity 3000 Unlimited\\Apps\\Updater\\UPDATER.EXE:*:Enabled:SC3UpdaterMFC""C:\\Program Files\\Real\\RealOne Player\\realplay.exe"="C:\\Program Files\\Real\\RealOne Player\\realplay.exe:*:Enabled:RealPlayer""%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000""C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader""C:\\Program Files\\Kuma Games\\KumaClientHCnet.exe"="C:\\Program Files\\Kuma Games\\KumaClientHCnet.exe:*:Enabled:KumaClientHC""C:\\WINDOWS\\Installer\\{047882CA-975E-41FC-BE02-6D6396106C4E}\\ACDSee_PM_Shtcut.exe"="C:\\WINDOWS\\Installer\\{047882CA-975E-41FC-BE02-6D6396106C4E}\\ACDSee_PM_Shtcut.exe:*:Enabled:ACDSee 3.1 (SR-1)""C:\\Program Files\\Warcraft III\\Warcraft III.exe"="C:\\Program Files\\Warcraft III\\Warcraft III.exe:*:Enabled:Warcraft III""C:\\Program Files\\Warcraft III\\World Editor.exe"="C:\\Program Files\\Warcraft III\\World Editor.exe:*:Enabled:Warcraft III World Editor""C:\\Program Files\\Kontiki\\KService.exe"="C:\\Program Files\\Kontiki\\KService.exe:*:Enabled:Delivery Manager Service""C:\\Program Files\\Warcraft III\\Frozen Throne.exe"="C:\\Program Files\\Warcraft III\\Frozen Throne.exe:*:Enabled:Warcraft III - The Frozen Throne""C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"-- Environment Variables -------------------------------------------------------ALLUSERSPROFILE=C:\Documents and Settings\All UsersAPPDATA=C:\Documents and Settings\Owner\Application DataCLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zipCommonProgramFiles=C:\Program Files\Common FilesCOMPUTERNAME=STELLAComSpec=C:\WINDOWS\system32\cmd.exeFP_NO_HOST_CHECK=NOHOMEDRIVE=C:HOMEPATH=\Documents and Settings\OwnerLOGONSERVER=\\STELLANUMBER_OF_PROCESSORS=2OS=Windows_NTPath=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;c:\Python22;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\QuickTime\QTSystemPATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSHPROCESSOR_ARCHITECTURE=x86PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntelPROCESSOR_LEVEL=15PROCESSOR_REVISION=0209ProgramFiles=C:\Program FilesPROMPT=$P$GQTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zipSESSIONNAME=ConsoleSystemDrive=C:SystemRoot=C:\WINDOWSTEMP=C:\DOCUME~1\Owner\LOCALS~1\TempTMP=C:\DOCUME~1\Owner\LOCALS~1\TempUSERDOMAIN=STELLAUSERNAME=OwnerUSERPROFILE=C:\Documents and Settings\Ownerwindir=C:\WINDOWS-- User Profiles ---------------------------------------------------------------Owner (admin)Samz folder.STELLA (admin)Nickz folder (admin)Guest.STELLA (guest)-- Add/Remove Programs --------------------------------------------------------- --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 --> C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu --> C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature --> c:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19} --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\Setup.exe" --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\Setup.exe" --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\Setup.exe" --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.infAdobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlockAdobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exeAdobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~2\Install.logAGEIA PhysX v2.4.4 --> "C:\Program Files\AGEIA Technologies\uninstall.exe"AOL Instant Messenger --> C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}Apple Software Update --> MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}ASIO4ALL --> C:\Program Files\ASIO4ALL v2\uninstall.exeAspi Installer --> C:\temp\UNWISE.EXE C:\temp\INSTALL.LOGBattle Realms --> MsiExec.exe /I{9AA761E6-CA51-4FF2-A552-D51638BF0595}Bodog Poker Version 2.13.6.4 --> "C:\Program Files\Bodog Poker\unins000.exe"Collab --> C:\Program Files\Image-Line\Collab\uninstall.exeCompaq Connections --> C:\WINDOWS\BWUnin-6.2.3.66L.exe -AppId 1940576DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODECDivX Content Uploader --> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADERDivX Converter --> C:\Program Files\DivX\ConverterUninstall.exe /CONVERTERDivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYERDivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGINEntriq MediaSphere 3.6.0.15 --> "C:\Program Files\Entriq\MediaSphere\unins000.exe"EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /RGoogle Earth --> MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}Google Toolbar for Firefox --> MsiExec.exe /X{2CCBABCB-6427-4A55-B091-49864623C43F}Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstallHotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"ICOO Loader 2.5 --> "C:\Program Files\ICOO Loader\unins000.exe"Instant Support --> C:\PROGRA~1\INSTAN~1\UNWISE.EXE C:\PROGRA~1\INSTAN~1\INSTALL.LOGIntel® Extreme Graphics 2 Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572IntelliMover Data Transfer Demo --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{14589F05-C658-4594-9429-D437BA688686}\Setup.exe" -l0x9 InterVideo WinDVD Player --> "C:\Program Files\InstallShield Installation Information\{98E8A2EF-4EAE-43B8-A172-74842B764777}\setup.exe" REMOVEALLiPod for Windows 2005-11-17 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{8338BA06-E527-491B-9400-F51708FEE695} /l1033 iTunes --> MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}J2SE Runtime Environment 5.0 Update 11 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}J2SE Runtime Environment 5.0 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150030}J2SE Runtime Environment 5.0 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}Java 2 Runtime Environment, SE v1.4.1_02 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFCE5837-FC21-11D6-9D24-00010240CE95}\setup.exe" AnytextJava Web Start --> "C:\Program Files\Java Web Start\uninst-javaws.exe"Java 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}Java 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}Java SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}KBD --> C:\HP\KBD\KBD.EXE uninstalledLiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VcSetup.exe /REMOVELiveUpdate 2.6 (Symantec Corporation) --> C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /UMalwarebytes' RogueRemover --> "C:\Program Files\RogueRemover FREE\unins000.exe"Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"Microsoft Word 2000 --> MsiExec.exe /I{00170409-78E1-11D2-B60F-006097C998E7}Microsoft Works 7.0 --> MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}Mozilla Firefox (1.5) --> C:\Program Files\Mozilla Firefox\uninstall\uninstall.exe /ua "1.5 (en-US)"Netflix Movie Viewer --> MsiExec.exe /X{BCE72AED-3332-4863-9567-C5DCB9052CA2}Norton WMI Update --> MsiExec.exe /X{1526D87C-A955-4FAB-BF18-697BA457E352}NVIDIA Gart Driver --> C:\WINDOWS\System32\nvugart.exe Uninstall C:\WINDOWS\System32\Nvgart.nvu,NVIDIA Gart DriverNVIDIA Windows 2000/XP Display Drivers --> rundll32.exe C:\WINDOWS\System32\nvinstnt.dll,NvUninstallNT4 nvhp.infOmniPass --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F4E57F49-84B4-4CF2-B0A1-8CA1752BDF7E}\Setup.exe" -l0x9 OTOY --> RunDll32 C:\WINDOWS\DOWNLO~1\OTOYAX.dll,_RemoveGroove@16PC-Doctor for Windows --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\Setup.exe" PokerStars.net --> "C:\Program Files\PokerStars.NET\PokerStarsUninstall.exe" /u:PokerStars.netQuicken 2006 --> MsiExec.exe /X{2818095F-FB6C-42C8-827E-0A406CC9AFF5}QuickTime --> MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0RecordNow! --> MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}S3Display --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Display'S3Gamma2 --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Gamma2'S3Info2 --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Info2'S3Overlay --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Overlay'Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"SimCity 3000 Unlimited --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Maxis\SimCity 3000 Unlimited\DeIsL1.isu" -c"C:\Program Files\Maxis\SimCity 3000 Unlimited\_UnInstall.dll"Sonic Update Manager --> MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}SpamSubtract --> C:\PROGRA~1\INTERM~1\SPAMSU~1\UNWISE.EXE /U C:\PROGRA~1\INTERM~1\SPAMSU~1\INSTALL.LOGTES Construction Set --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Bethesda Softworks\Morrowind\CSUninstall\Setup.exe" -l0x9 Trend Micro Internet Security --> C:\Program Files\Trend Micro\Internet Security\remove.exeTrend Micro Internet Security --> MsiExec.exe /X{A621B45A-D138-4A95-BE10-7CABA05EF94E}UFC Media Manager 3.6.0.6 --> "C:\Program Files\UFC Media Manager\MediaSphere\unins000.exe"Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /uWarcraft III: All Products --> C:\WINDOWS\War3Unin.exe C:\WINDOWS\War3Unin.datWD Diagnostics --> MsiExec.exe /X{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}Weblink --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4FCC384C-18EA-4E25-9281-A06AE006D219}\setup.exe" -l0x9 Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"World of Warcraft --> C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exeWrath of the Lich King Alpha --> C:\Program Files\Common Files\Blizzard Entertainment\Wrath of the Lich King Alpha\Uninstall.exe-- Application Event Log -------------------------------------------------------Event Record #/Type2760 / ErrorEvent Submitted/Written: 06/06/2008 03:34:04 PMEvent ID/Source: 1512 / UserenvEvent Description:Windows cannot unload your registry file. The memory used by the registry has not been freed. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account. If this problem persists, contact your administrator. DETAIL - Insufficient system resources exist to complete the requested service.Event Record #/Type2759 / ErrorEvent Submitted/Written: 06/06/2008 00:42:34 PMEvent ID/Source: 1000 / Application ErrorEvent Description:Faulting application axpdefender.exe, version 2.1.0.1, faulting module , version 0.0.0.0, fault address 0x00000000.Processing media-specific event for [axpdefender.exe!ws!]Event Record #/Type2506 / ErrorEvent Submitted/Written: 06/03/2008 11:36:55 PMEvent ID/Source: 1505 / UserenvEvent Description:Windows cannot load the user's profile but has logged you on with the default profile for the system. DETAIL - Insufficient system resources exist to complete the requested service.Event Record #/Type2505 / ErrorEvent Submitted/Written: 06/03/2008 11:36:54 PMEvent ID/Source: 1508 / UserenvEvent Description:Windows was unable to load the registry. This is often caused by insufficient memory or insufficient security rights. DETAIL - Insufficient system resources exist to complete the requested service. for C:\Documents and Settings\Nickz folder\ntuser.datEvent Record #/Type2504 / ErrorEvent Submitted/Written: 06/03/2008 11:36:48 PMEvent ID/Source: 1505 / UserenvEvent Description:Windows cannot load the user's profile but has logged you on with the default profile for the system. DETAIL - Insufficient system resources exist to complete the requested service.-- Security Event Log ----------------------------------------------------------No Errors/Warnings found.-- System Event Log ------------------------------------------------------------Event Record #/Type93627 / ErrorEvent Submitted/Written: 06/08/2008 08:37:50 AMEvent ID/Source: 10005 / DCOMEvent Description:DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""in order to run the server:{1BE1F766-5536-11D1-B726-00C04FB926AF}Event Record #/Type93626 / ErrorEvent Submitted/Written: 06/08/2008 08:37:35 AMEvent ID/Source: 10005 / DCOMEvent Description:DCOM got error "%%1084" attempting to start the service netman with arguments ""in order to run the server:{BA126AE5-2166-11D1-B1D0-00805FC1270E}Event Record #/Type93625 / ErrorEvent Submitted/Written: 06/08/2008 08:35:09 AMEvent ID/Source: 10005 / DCOMEvent Description:DCOM got error "%%1084" attempting to start the service netman with arguments ""in order to run the server:{BA126AE5-2166-11D1-B1D0-00805FC1270E}Event Record #/Type93624 / ErrorEvent Submitted/Written: 06/08/2008 08:22:53 AMEvent ID/Source: 7026 / Service Control ManagerEvent Description:The following boot-start or system-start driver(s) failed to load: AFDFipsintelppmIPSecMRxSmbNetBIOSNetBTRasAcdRdbssTcpiptmtdiWS2IFSLEvent Record #/Type93623 / ErrorEvent Submitted/Written: 06/08/2008 08:22:53 AMEvent ID/Source: 7001 / Service Control ManagerEvent Description:The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: %%31-- End of Deckard's System Scanner: finished at 2008-06-08 09:21:58 ------------ Link to post Share on other sites
charlieric Posted June 8, 2008 Author Report Share Posted June 8, 2008 Hello again,Step 1Please download SmitfraudFix (by S!Ri) to your Desktop.Next, please reboot your computer in Safe Mode by doing the following.Restart your computerAfter hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;Instead of Windows loading as normal, a menu with options should appear;Select the first option, to run Windows in Safe Mode, then press "Enter".Choose your usual account.Once in Safe Mode, double-click on SmitfraudFix.exeSelect option #2 - Clean by typing 2 and press "Enter" to delete infected files.You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.The report can also be found at the root of the system drive, usually at C:\rapport.txtWarning : running option #2 on a non infected computer will remove your Desktop background.Step 2Please download Deckard's System Scanner (DSS) to your desktop.Close all applications and windows.Double-click on dss.exe to run it, and follow the prompts.When the scan is complete, a text file will open - Main.txtCopy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of Main.txt into your thread.An additional text file, Extra.txt,will also be available (by default) in the following FOLDER, C:\Deckard\System Scanner.Please go to that folder and also copy the contents of Extra.txt to your post as well.Note: Some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so.Hi again. I have posted the three new logs below. By the way, my Trend anti-virus is now warning me about a file in the Smitfraudfix that it identifies as being infected by Troj_Generic.ADV Since I have been getting this same warning about other files on the computer for the last few days, I am suspicious that Trend isn't identifying viruses correctly. What's up with that? Another reason to change to a different anti-virus?SmitFraudFix v2.323Scan done at 8:31:31.93, Sun 06/08/2008Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFixOS: Microsoft Windows XP [Version 5.1.2600] - Windows_NTThe filesystem type is NTFSFix run in safe mode»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix!!!Attention, following keys are not inevitably infected!!!SrchSTS.exe by S!RiSearch SharedTaskScheduler's .dll»»»»»»»»»»»»»»»»»»»»»»»» Killing process»»»»»»»»»»»»»»»»»»»»»»»» hosts127.0.0.1 localhost»»»»»»»»»»»»»»»»»»»»»»»» VACFixVACFixCredits: Malware Analysis & DiagnosticCode: S!Ri»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 FixS!Ri's WS2Fix: LSP not Found.»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos FixGenericRenosFix by S!Ri»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files»»»»»»»»»»»»»»»»»»»»»»»» IEDFixIEDFixCredits: Malware Analysis & DiagnosticCode: S!Ri»»»»»»»»»»»»»»»»»»»»»»»» 404Fix404FixCredits: Malware Analysis & DiagnosticCode: S!Ri»»»»»»»»»»»»»»»»»»»»»»»» DNSHKLM\SYSTEM\CCS\Services\Tcpip\..\{E4642448-E7D1-47A5-BE6A-E7F27CB79F02}: DhcpNameServer=68.87.85.98 68.87.69.146HKLM\SYSTEM\CS1\Services\Tcpip\..\{E4642448-E7D1-47A5-BE6A-E7F27CB79F02}: DhcpNameServer=68.87.85.98 68.87.69.146HKLM\SYSTEM\CS2\Services\Tcpip\..\{E4642448-E7D1-47A5-BE6A-E7F27CB79F02}: DhcpNameServer=68.87.85.98 68.87.69.146HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=68.87.85.98 68.87.69.146HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=68.87.85.98 68.87.69.146HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=68.87.85.98 68.87.69.146»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System!!!Attention, following keys are not inevitably infected!!![HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]"System"=""»»»»»»»»»»»»»»»»»»»»»»»» Registry CleaningRegistry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix!!!Attention, following keys are not inevitably infected!!!SrchSTS.exe by S!RiSearch SharedTaskScheduler's .dll»»»»»»»»»»»»»»»»»»»»»»»» EndDeckard's System Scanner v20071014.68Run by Owner on 2008-06-08 09:19:05Computer is in Normal Mode.---------------------------------------------------------------------------------- System Restore --------------------------------------------------------------Successfully created a Deckard's System Scanner Restore Point.-- Last 4 Restore Point(s) --4: 2008-06-08 15:19:16 UTC - RP4 - Deckard's System Scanner Restore Point3: 2008-06-08 02:58:56 UTC - RP3 - System Checkpoint2: 2008-06-07 02:10:34 UTC - RP2 - ComboFix created restore point1: 2008-06-07 02:09:31 UTC - RP1 - System CheckpointBacked up registry hives.Performed disk cleanup.-- HijackThis (run as Owner.exe) -----------------------------------------------Logfile of Trend Micro HijackThis v2.0.2Scan saved at 09:20:05, on 6/8/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16640)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Kontiki\KService.exeC:\Program Files\Softex\OmniPass\Omniserv.exeC:\Program Files\Trend Micro\Internet Security\SfCtlCom.exeC:\Program Files\Softex\OmniPass\OPXPApp.exeC:\Program Files\Trend Micro\BM\TMBMSRV.exeC:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exeC:\Program Files\Trend Micro\Internet Security\TmProxy.exeC:\WINDOWS\Explorer.EXEC:\windows\system\hpsysdrv.exeC:\WINDOWS\system32\hkcmd.exeC:\HP\KBD\KBD.EXEC:\WINDOWS\ALCXMNTR.EXEC:\WINDOWS\system32\igfxtray.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Java\jre1.6.0_03\bin\jusched.exeC:\Program Files\Entriq\MediaSphere\Bin\EntriqMediaTray.exeC:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exeC:\Program Files\iTunes\iTunesHelper.exeC:\WINDOWS\system32\lphc5lnj0eaat.exeC:\Program Files\Entriq\MediaSphere\Bin\EntriqMediaServer.exeC:\Program Files\Messenger\msmsgs.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\interMute\SpamSubtract\SpamSubtract.exeC:\Program Files\Java\jre1.6.0_03\bin\jucheck.exeC:\Documents and Settings\Owner\Desktop\dss.exeC:\PROGRA~1\TRENDM~1\HIJACK~1\Owner.exeR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus9.hpwis.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,;localhostO2 - BHO: ICOOExternal Class - {0519A9C9-064A-4cbc-BC47-D0EACD581477} - C:\Program Files\ICOO Loader\addons\icooue.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: ICOODManager Class - {465A59EC-20E5-4fca-A38A-E5EC3C480218} - C:\Program Files\ICOO Loader\addons\icoou.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dllO3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetectO4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exeO4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXEO4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [updateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKLM\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -schedulerO4 - HKLM\..\Run: [ProfileWatcher] C:\Program Files\ProfileWatcher\profilewatcher.exeO4 - HKLM\..\Run: [uFC Media Manager Tray] "C:\Program Files\Entriq\MediaSphere\Bin\EntriqMediaTray.exe" /CustomId:UFCO4 - HKLM\..\Run: [ufSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [lphc5lnj0eaat] C:\WINDOWS\system32\lphc5lnj0eaat.exeO4 - HKLM\..\Run: [sysrest32.exe] C:\WINDOWS\system32\sysrest32.exeO4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHookO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1O4 - S-1-5-18 Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')O4 - .DEFAULT Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exeO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\All Users\Documents\AIM\aim.exeO9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exeO9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exeO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cabO16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.miniclip.com/games/ricochet-los...bGameLoader.cabO16 - DPF: {5A9D4578-6649-4692-921B-ACA9ADAB007C} (UFC Class) - http://evideo.ufc.com/ufc/cabfiles/UFC_3_6_0_6.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cabO16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxoramun...mjolauncher.cabO16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} (MediaControl Class) - http://evideo.ufc.com/ufc/cabfiles/Entriq_...0_15_Silent.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/heavyweap...aploader_v6.cabO18 - Protocol: icoo - {86FE362E-74FA-4F71-8B69-B94D28880628} - C:\Program Files\ICOO Loader\addons\icoou.dllO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exeO23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exeO23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exeO23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exeO23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeO23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exeO23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exeO23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe--End of file - 10266 bytes-- File Associations -----------------------------------------------------------All associations okay.-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------All drivers whitelisted.-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>-- Device Manager: Disabled ----------------------------------------------------No disabled devices found.-- Scheduled Tasks -------------------------------------------------------------2008-06-07 21:26:00 364 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job2008-06-05 13:57:10 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job-- Files created between 2008-05-08 and 2008-06-08 -----------------------------2008-06-08 08:31:43 4292 --a------ C:\WINDOWS\system32\tmp.reg2008-06-08 08:30:56 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe2008-06-08 08:30:56 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >2008-06-08 08:30:56 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>2008-06-08 08:30:56 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>2008-06-08 08:30:56 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>2008-06-08 08:30:56 82944 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>2008-06-08 08:30:56 51200 --a------ C:\WINDOWS\system32\dumphive.exe2008-06-08 08:30:56 82944 --a------ C:\WINDOWS\system32\404Fix.exe <Not Verified; S!Ri.URZ; IEDFix>2008-06-06 22:37:36 0 d-------- C:\Program Files\RogueRemover FREE2008-06-06 20:09:09 68096 --a------ C:\WINDOWS\zip.exe2008-06-06 20:09:09 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>2008-06-06 20:09:09 98816 --a------ C:\WINDOWS\sed.exe2008-06-06 20:09:09 80412 --a------ C:\WINDOWS\grep.exe2008-06-06 20:09:09 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >2008-06-06 20:09:08 49152 --a------ C:\WINDOWS\VFind.exe2008-06-06 20:09:08 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>2008-06-06 20:09:08 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>2008-06-06 15:27:23 0 d-------- C:\Program Files\Wrath of the Lich King Alpha2008-06-04 18:43:58 0 d-------- C:\Documents and Settings\Owner\Application Data\Mozilla2008-06-04 18:33:40 0 d-------- C:\Program Files\Spyware Doctor2008-06-04 18:33:40 0 d-------- C:\Documents and Settings\Owner\Application Data\PC Tools2008-06-04 00:28:00 0 d-------- C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat2008-06-03 22:28:07 0 d-------- C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat2008-06-03 21:05:54 93184 --a------ C:\WINDOWS\system32\lphc5lnj0eaat.exe2008-05-24 16:08:56 0 d-------- C:\Program Files\Cheat Engine2008-05-19 16:28:54 0 d------c- C:\Patch's (sams game folder! dont delete plz)-- Find3M Report ---------------------------------------------------------------2008-06-07 12:01:54 0 d-------- C:\Program Files\Quicken2008-06-07 08:47:31 0 d-------- C:\Program Files\ProfileWatcher2008-06-06 15:27:27 0 d-------- C:\Program Files\Common Files\Blizzard Entertainment2008-06-05 18:10:02 0 d-------- C:\Program Files\Trend Micro2008-06-04 08:42:31 0 d-------- C:\Program Files\LimeWire2008-05-26 10:07:19 0 d-------- C:\Documents and Settings\Owner\Application Data\Adobe2008-05-25 20:01:00 0 d-------- C:\Program Files\World of Warcraft2008-05-16 18:15:32 0 d-------- C:\Documents and Settings\Owner\Application Data\AdobeUM2008-05-14 10:07:05 0 d-------- C:\Program Files\Apple Software Update2008-05-14 09:55:33 0 d-------- C:\Program Files\iTunes2008-05-14 09:53:04 0 d-------- C:\Program Files\iPod2008-05-14 09:44:25 0 d-------- C:\Program Files\QuickTime2008-05-04 09:56:46 0 d-------- C:\Documents and Settings\Owner\Application Data\Real2008-04-25 09:08:24 0 d-------- C:\Program Files\Bodog Poker2008-03-30 21:00:17 664 --a----c- C:\WINDOWS\system32\d3d9caps.dat-- Registry Dump ---------------------------------------------------------------*Note* empty entries & legit default entries are not shown[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0519A9C9-064A-4cbc-BC47-D0EACD581477}]09/25/2004 17:05 28672 --a--c--- C:\Program Files\ICOO Loader\addons\icooue.dll[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{465A59EC-20E5-4fca-A38A-E5EC3C480218}]09/22/2004 16:36 68096 --a--c--- C:\Program Files\ICOO Loader\addons\icoou.dll[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [05/07/1998 17:04]"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [08/20/2004 16:51]"KBD"="C:\HP\KBD\KBD.EXE" [02/11/2003 21:02]"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [09/13/2002 22:42]"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [05/03/2003 00:19]"nwiz"="nwiz.exe" [05/03/2003 00:19 C:\WINDOWS\system32\nwiz.exe]"PS2"="C:\WINDOWS\system32\ps2.exe" []"AlcxMonitor"="ALCXMNTR.EXE" [09/07/2004 14:47 C:\WINDOWS\ALCXMNTR.EXE]"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [08/20/2004 16:55]"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [08/19/2003 01:01]"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [02/25/2006 21:29]"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 01:11]"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" []"ProfileWatcher"="C:\Program Files\ProfileWatcher\profilewatcher.exe" []"UFC Media Manager Tray"="C:\Program Files\Entriq\MediaSphere\Bin\EntriqMediaTray.exe" [03/12/2007 23:15]"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [02/16/2008 00:56]"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/28/2008 23:37]"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36]"lphc5lnj0eaat"="C:\WINDOWS\system32\lphc5lnj0eaat.exe" [06/03/2008 21:05]"sysrest32.exe"="C:\WINDOWS\system32\sysrest32.exe" [][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"NVIEW"="nview.dll,nViewLoadHook" []"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 10:24]"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56]"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [06/23/2007 19:27]"OE"="C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [09/18/2007 01:30]"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [03/30/2006 17:45]C:\Documents and Settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe [7/26/2003 2:57:44 AM]C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 11:05:26 PM][HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"HideLegacyLogonScripts"=0 (0x0)"HideLogoffScripts"=0 (0x0)"RunLogonScriptSync"=1 (0x1)"RunStartupScriptSync"=0 (0x0)"HideStartupScripts"=0 (0x0)[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]"HideLegacyLogonScripts"=0 (0x0)"HideLogoffScripts"=0 (0x0)"RunLogonScriptSync"=1 (0x1)"RunStartupScriptSync"=0 (0x0)"HideStartupScripts"=0 (0x0)"NoDispBackgroundPage"=1 (0x1)"NoDispScrSavPage"=1 (0x1)[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina] C:\Program Files\Softex\OmniPass\opxpgina.dll 02/21/2003 04:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]@="Service"[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]@="Volume shadow copy"-- End of Deckard's System Scanner: finished at 2008-06-08 09:21:58 ------------Deckard's System Scanner v20071014.68Extra logfile - please post this as an attachment with your post.---------------------------------------------------------------------------------- System Information ----------------------------------------------------------Microsoft Windows XP Home Edition (build 2600) SP 2.0Architecture: X86; Language: EnglishCPU 0: Intel® Pentium® 4 CPU 2.60GHzCPU 1: Intel® Pentium® 4 CPU 2.60GHzPercentage of Memory in Use: 53%Physical Memory (total/avail): 759.36 MiB / 350.97 MiBPagefile Memory (total/avail): 1860.02 MiB / 1512.47 MiBVirtual Memory (total/avail): 2047.88 MiB / 1923.88 MiBA: is Removable (No Media)C: is Fixed (NTFS) - 69.55 GiB total, 19.43 GiB free. D: is Fixed (FAT32) - 4.96 GiB total, 0.9 GiB free. E: is CDROM (No Media)F: is CDROM (No Media)\\.\PHYSICALDRIVE0 - WDC WD800EB-11DJF0 - 74.53 GiB - 2 partitions \PARTITION0 - Unknown - 4.97 GiB - D: \PARTITION1 (bootable) - Installable File System - 69.55 GiB - C:-- Security Center -------------------------------------------------------------AUOptions is scheduled to auto-install.Windows Internal Firewall is enabled.AntivirusOverride is set.FW: Trend Micro Personal Firewall v5.2 (Trend Micro Inc.)AV: Trend Micro Internet Security v16.10.1079 ()[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019""%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019""C:\\Documents and Settings\\All Users\\Documents\\iTunes\\iTunes.exe"="C:\\Documents and Settings\\All Users\\Documents\\iTunes\\iTunes.exe:*:Enabled:iTunes""C:\\Program Files\\World of Warcraft\\WoW.exe"="C:\\Program Files\\World of Warcraft\\WoW.exe:*:Enabled:World of Warcraft""C:\\Program Files\\World of Warcraft\\Repair.exe"="C:\\Program Files\\World of Warcraft\\Repair.exe:*:Enabled:World of Warcraft - Repair""C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger""C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer""C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent""C:\\Program Files\\Maxis\\SimCity 3000 Unlimited\\Apps\\Updater\\UPDATER.EXE"="C:\\Program Files\\Maxis\\SimCity 3000 Unlimited\\Apps\\Updater\\UPDATER.EXE:*:Enabled:SC3UpdaterMFC""C:\\Program Files\\Real\\RealOne Player\\realplay.exe"="C:\\Program Files\\Real\\RealOne Player\\realplay.exe:*:Enabled:RealPlayer""%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000""C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader""C:\\Program Files\\Kuma Games\\KumaClientHCnet.exe"="C:\\Program Files\\Kuma Games\\KumaClientHCnet.exe:*:Enabled:KumaClientHC""C:\\WINDOWS\\Installer\\{047882CA-975E-41FC-BE02-6D6396106C4E}\\ACDSee_PM_Shtcut.exe"="C:\\WINDOWS\\Installer\\{047882CA-975E-41FC-BE02-6D6396106C4E}\\ACDSee_PM_Shtcut.exe:*:Enabled:ACDSee 3.1 (SR-1)""C:\\Program Files\\Warcraft III\\Warcraft III.exe"="C:\\Program Files\\Warcraft III\\Warcraft III.exe:*:Enabled:Warcraft III""C:\\Program Files\\Warcraft III\\World Editor.exe"="C:\\Program Files\\Warcraft III\\World Editor.exe:*:Enabled:Warcraft III World Editor""C:\\Program Files\\Kontiki\\KService.exe"="C:\\Program Files\\Kontiki\\KService.exe:*:Enabled:Delivery Manager Service""C:\\Program Files\\Warcraft III\\Frozen Throne.exe"="C:\\Program Files\\Warcraft III\\Frozen Throne.exe:*:Enabled:Warcraft III - The Frozen Throne""C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"-- Environment Variables -------------------------------------------------------ALLUSERSPROFILE=C:\Documents and Settings\All UsersAPPDATA=C:\Documents and Settings\Owner\Application DataCLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zipCommonProgramFiles=C:\Program Files\Common FilesCOMPUTERNAME=STELLAComSpec=C:\WINDOWS\system32\cmd.exeFP_NO_HOST_CHECK=NOHOMEDRIVE=C:HOMEPATH=\Documents and Settings\OwnerLOGONSERVER=\\STELLANUMBER_OF_PROCESSORS=2OS=Windows_NTPath=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;c:\Python22;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\QuickTime\QTSystemPATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSHPROCESSOR_ARCHITECTURE=x86PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntelPROCESSOR_LEVEL=15PROCESSOR_REVISION=0209ProgramFiles=C:\Program FilesPROMPT=$P$GQTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zipSESSIONNAME=ConsoleSystemDrive=C:SystemRoot=C:\WINDOWSTEMP=C:\DOCUME~1\Owner\LOCALS~1\TempTMP=C:\DOCUME~1\Owner\LOCALS~1\TempUSERDOMAIN=STELLAUSERNAME=OwnerUSERPROFILE=C:\Documents and Settings\Ownerwindir=C:\WINDOWS-- User Profiles ---------------------------------------------------------------Owner (admin)Samz folder.STELLA (admin)Nickz folder (admin)Guest.STELLA (guest)-- Add/Remove Programs --------------------------------------------------------- --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 --> C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu --> C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature --> c:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19} --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\Setup.exe" --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\Setup.exe" --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\Setup.exe" --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.infAdobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlockAdobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exeAdobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~2\Install.logAGEIA PhysX v2.4.4 --> "C:\Program Files\AGEIA Technologies\uninstall.exe"AOL Instant Messenger --> C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}Apple Software Update --> MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}ASIO4ALL --> C:\Program Files\ASIO4ALL v2\uninstall.exeAspi Installer --> C:\temp\UNWISE.EXE C:\temp\INSTALL.LOGBattle Realms --> MsiExec.exe /I{9AA761E6-CA51-4FF2-A552-D51638BF0595}Bodog Poker Version 2.13.6.4 --> "C:\Program Files\Bodog Poker\unins000.exe"Collab --> C:\Program Files\Image-Line\Collab\uninstall.exeCompaq Connections --> C:\WINDOWS\BWUnin-6.2.3.66L.exe -AppId 1940576DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODECDivX Content Uploader --> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADERDivX Converter --> C:\Program Files\DivX\ConverterUninstall.exe /CONVERTERDivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYERDivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGINEntriq MediaSphere 3.6.0.15 --> "C:\Program Files\Entriq\MediaSphere\unins000.exe"EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /RGoogle Earth --> MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}Google Toolbar for Firefox --> MsiExec.exe /X{2CCBABCB-6427-4A55-B091-49864623C43F}Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstallHotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"ICOO Loader 2.5 --> "C:\Program Files\ICOO Loader\unins000.exe"Instant Support --> C:\PROGRA~1\INSTAN~1\UNWISE.EXE C:\PROGRA~1\INSTAN~1\INSTALL.LOGIntel® Extreme Graphics 2 Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572IntelliMover Data Transfer Demo --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{14589F05-C658-4594-9429-D437BA688686}\Setup.exe" -l0x9 InterVideo WinDVD Player --> "C:\Program Files\InstallShield Installation Information\{98E8A2EF-4EAE-43B8-A172-74842B764777}\setup.exe" REMOVEALLiPod for Windows 2005-11-17 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{8338BA06-E527-491B-9400-F51708FEE695} /l1033 iTunes --> MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}J2SE Runtime Environment 5.0 Update 11 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}J2SE Runtime Environment 5.0 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150030}J2SE Runtime Environment 5.0 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}Java 2 Runtime Environment, SE v1.4.1_02 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFCE5837-FC21-11D6-9D24-00010240CE95}\setup.exe" AnytextJava Web Start --> "C:\Program Files\Java Web Start\uninst-javaws.exe"Java 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}Java 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}Java SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}KBD --> C:\HP\KBD\KBD.EXE uninstalledLiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VcSetup.exe /REMOVELiveUpdate 2.6 (Symantec Corporation) --> C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /UMalwarebytes' RogueRemover --> "C:\Program Files\RogueRemover FREE\unins000.exe"Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"Microsoft Word 2000 --> MsiExec.exe /I{00170409-78E1-11D2-B60F-006097C998E7}Microsoft Works 7.0 --> MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}Mozilla Firefox (1.5) --> C:\Program Files\Mozilla Firefox\uninstall\uninstall.exe /ua "1.5 (en-US)"Netflix Movie Viewer --> MsiExec.exe /X{BCE72AED-3332-4863-9567-C5DCB9052CA2}Norton WMI Update --> MsiExec.exe /X{1526D87C-A955-4FAB-BF18-697BA457E352}NVIDIA Gart Driver --> C:\WINDOWS\System32\nvugart.exe Uninstall C:\WINDOWS\System32\Nvgart.nvu,NVIDIA Gart DriverNVIDIA Windows 2000/XP Display Drivers --> rundll32.exe C:\WINDOWS\System32\nvinstnt.dll,NvUninstallNT4 nvhp.infOmniPass --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F4E57F49-84B4-4CF2-B0A1-8CA1752BDF7E}\Setup.exe" -l0x9 OTOY --> RunDll32 C:\WINDOWS\DOWNLO~1\OTOYAX.dll,_RemoveGroove@16PC-Doctor for Windows --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\Setup.exe" PokerStars.net --> "C:\Program Files\PokerStars.NET\PokerStarsUninstall.exe" /u:PokerStars.netQuicken 2006 --> MsiExec.exe /X{2818095F-FB6C-42C8-827E-0A406CC9AFF5}QuickTime --> MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0RecordNow! --> MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}S3Display --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Display'S3Gamma2 --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Gamma2'S3Info2 --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Info2'S3Overlay --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Overlay'Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"SimCity 3000 Unlimited --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Maxis\SimCity 3000 Unlimited\DeIsL1.isu" -c"C:\Program Files\Maxis\SimCity 3000 Unlimited\_UnInstall.dll"Sonic Update Manager --> MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}SpamSubtract --> C:\PROGRA~1\INTERM~1\SPAMSU~1\UNWISE.EXE /U C:\PROGRA~1\INTERM~1\SPAMSU~1\INSTALL.LOGTES Construction Set --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Bethesda Softworks\Morrowind\CSUninstall\Setup.exe" -l0x9 Trend Micro Internet Security --> C:\Program Files\Trend Micro\Internet Security\remove.exeTrend Micro Internet Security --> MsiExec.exe /X{A621B45A-D138-4A95-BE10-7CABA05EF94E}UFC Media Manager 3.6.0.6 --> "C:\Program Files\UFC Media Manager\MediaSphere\unins000.exe"Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /uWarcraft III: All Products --> C:\WINDOWS\War3Unin.exe C:\WINDOWS\War3Unin.datWD Diagnostics --> MsiExec.exe /X{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}Weblink --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4FCC384C-18EA-4E25-9281-A06AE006D219}\setup.exe" -l0x9 Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"World of Warcraft --> C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exeWrath of the Lich King Alpha --> C:\Program Files\Common Files\Blizzard Entertainment\Wrath of the Lich King Alpha\Uninstall.exe-- Application Event Log -------------------------------------------------------Event Record #/Type2760 / ErrorEvent Submitted/Written: 06/06/2008 03:34:04 PMEvent ID/Source: 1512 / UserenvEvent Description:Windows cannot unload your registry file. The memory used by the registry has not been freed. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account. If this problem persists, contact your administrator. DETAIL - Insufficient system resources exist to complete the requested service.Event Record #/Type2759 / ErrorEvent Submitted/Written: 06/06/2008 00:42:34 PMEvent ID/Source: 1000 / Application ErrorEvent Description:Faulting application axpdefender.exe, version 2.1.0.1, faulting module , version 0.0.0.0, fault address 0x00000000.Processing media-specific event for [axpdefender.exe!ws!]Event Record #/Type2506 / ErrorEvent Submitted/Written: 06/03/2008 11:36:55 PMEvent ID/Source: 1505 / UserenvEvent Description:Windows cannot load the user's profile but has logged you on with the default profile for the system. DETAIL - Insufficient system resources exist to complete the requested service.Event Record #/Type2505 / ErrorEvent Submitted/Written: 06/03/2008 11:36:54 PMEvent ID/Source: 1508 / UserenvEvent Description:Windows was unable to load the registry. This is often caused by insufficient memory or insufficient security rights. DETAIL - Insufficient system resources exist to complete the requested service. for C:\Documents and Settings\Nickz folder\ntuser.datEvent Record #/Type2504 / ErrorEvent Submitted/Written: 06/03/2008 11:36:48 PMEvent ID/Source: 1505 / UserenvEvent Description:Windows cannot load the user's profile but has logged you on with the default profile for the system. DETAIL - Insufficient system resources exist to complete the requested service.-- Security Event Log ----------------------------------------------------------No Errors/Warnings found.-- System Event Log ------------------------------------------------------------Event Record #/Type93627 / ErrorEvent Submitted/Written: 06/08/2008 08:37:50 AMEvent ID/Source: 10005 / DCOMEvent Description:DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""in order to run the server:{1BE1F766-5536-11D1-B726-00C04FB926AF}Event Record #/Type93626 / ErrorEvent Submitted/Written: 06/08/2008 08:37:35 AMEvent ID/Source: 10005 / DCOMEvent Description:DCOM got error "%%1084" attempting to start the service netman with arguments ""in order to run the server:{BA126AE5-2166-11D1-B1D0-00805FC1270E}Event Record #/Type93625 / ErrorEvent Submitted/Written: 06/08/2008 08:35:09 AMEvent ID/Source: 10005 / DCOMEvent Description:DCOM got error "%%1084" attempting to start the service netman with arguments ""in order to run the server:{BA126AE5-2166-11D1-B1D0-00805FC1270E}Event Record #/Type93624 / ErrorEvent Submitted/Written: 06/08/2008 08:22:53 AMEvent ID/Source: 7026 / Service Control ManagerEvent Description:The following boot-start or system-start driver(s) failed to load: AFDFipsintelppmIPSecMRxSmbNetBIOSNetBTRasAcdRdbssTcpiptmtdiWS2IFSLEvent Record #/Type93623 / ErrorEvent Submitted/Written: 06/08/2008 08:22:53 AMEvent ID/Source: 7001 / Service Control ManagerEvent Description:The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: %%31-- End of Deckard's System Scanner: finished at 2008-06-08 09:21:58 ------------ Link to post Share on other sites
Andro1d Posted June 8, 2008 Report Share Posted June 8, 2008 Hello again,Step 1Please download the OTMoveIt2 by OldTimer. Save it to your desktop. Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):[kill explorer]HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0519A9C9-064A-4cbc-BC47-D0EACD581477}HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{465A59EC-20E5-4fca-A38A-E5EC3C480218}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\lphc5lnj0eaatHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sysrest32.exeHKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\icooC:\Program Files\ICOO LoaderC:\WINDOWS\system32\tmp.regC:\WINDOWS\system32\d3d9caps.datC:\WINDOWS\sed.exeC:\WINDOWS\grep.exeC:\WINDOWS\fdsv.exeC:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaatC:\Documents and Settings\Owner\Application Data\shc3lnj0eaatC:\WINDOWS\system32\lphc5lnj0eaat.exeC:\Patch's (sams game folder! dont delete plz)C:\Program Files\Cheat EngineEmptyTemp[start explorer] Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the yellow bar) and choose Paste.Click the red Moveit! button.A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.Close OTMoveIt2If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.Step 2Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to infect your system. Please follow these steps to remove older version Java components and update:Download the latest version of Java Runtime Environment (JRE) 6 Update 6 and save it to your desktop.Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 6...allows end-users to run Java applications".Click the "Download" button to the right.Read the License Agreement and then check the box that says: "Accept License Agreement". The page will refresh.Click on the link to download Windows Offline Installation and save the file to your desktop.Close any programs you may have running - especially your web browser.Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.Click the Remove or Change/Remove button.Repeat as many times as necessary to remove each Java versions.Reboot your computer once all Java components are removed.Then from your desktop double-click on jre-6u6-windows-i586-p.exe to install the newest version.Step 3Lets run an F-Secure online scan for Viruses, Spyware and RootKits:Go to http://support.f-secure.com/enu/home/ols.shtmlScroll to the bottom of the page and click the Start scanning button. A window will pop up.Allow the Active X control to be installed on your computer, then click the Accept buttonClick Full System Scan and allow the components to download and the scan to complete.If malware is found, check Submit samples to F-Secure then select Automatic cleaningWhen cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this postIf Automatic cleaning with Submit samples hangs, click Cancel, then New ScanWhen the cleaning option is presented, Uncheck Submit samples to F-SecureClick Automatic cleaningWhen cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this postNotes: This scan will only work with Internet ExplorerYou must have administrator rights to run this scanThis scan can take several hours, so please be patient Link to post Share on other sites
charlieric Posted June 9, 2008 Author Report Share Posted June 9, 2008 Hello again,Step 1Please download the OTMoveIt2 by OldTimer. Save it to your desktop. Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):[kill explorer]HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0519A9C9-064A-4cbc-BC47-D0EACD581477}HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{465A59EC-20E5-4fca-A38A-E5EC3C480218}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\lphc5lnj0eaatHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sysrest32.exeHKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\icooC:\Program Files\ICOO LoaderC:\WINDOWS\system32\tmp.regC:\WINDOWS\system32\d3d9caps.datC:\WINDOWS\sed.exeC:\WINDOWS\grep.exeC:\WINDOWS\fdsv.exeC:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaatC:\Documents and Settings\Owner\Application Data\shc3lnj0eaatC:\WINDOWS\system32\lphc5lnj0eaat.exeC:\Patch's (sams game folder! dont delete plz)C:\Program Files\Cheat EngineEmptyTemp[start explorer] Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the yellow bar) and choose Paste.Click the red Moveit! button.A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.Close OTMoveIt2If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.Step 2Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to infect your system. Please follow these steps to remove older version Java components and update:Download the latest version of Java Runtime Environment (JRE) 6 Update 6 and save it to your desktop.Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 6...allows end-users to run Java applications".Click the "Download" button to the right.Read the License Agreement and then check the box that says: "Accept License Agreement". The page will refresh.Click on the link to download Windows Offline Installation and save the file to your desktop.Close any programs you may have running - especially your web browser.Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.Click the Remove or Change/Remove button.Repeat as many times as necessary to remove each Java versions.Reboot your computer once all Java components are removed.Then from your desktop double-click on jre-6u6-windows-i586-p.exe to install the newest version.Step 3Lets run an F-Secure online scan for Viruses, Spyware and RootKits:Go to http://support.f-secure.com/enu/home/ols.shtmlScroll to the bottom of the page and click the Start scanning button. A window will pop up.Allow the Active X control to be installed on your computer, then click the Accept buttonClick Full System Scan and allow the components to download and the scan to complete.If malware is found, check Submit samples to F-Secure then select Automatic cleaningWhen cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this postIf Automatic cleaning with Submit samples hangs, click Cancel, then New ScanWhen the cleaning option is presented, Uncheck Submit samples to F-SecureClick Automatic cleaningWhen cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this postNotes: This scan will only work with Internet ExplorerYou must have administrator rights to run this scanThis scan can take several hours, so please be patientOK, Monster. First, the results of the F-Secure scan:Result: 3 malware foundEmail-Worm.Win32.Zhelatin.vl (virus) C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\QUARANTINE\SYSREST.SYS (Renamed & Submitted) RiskTool.Win32.Reboot (spyware) System Tracking Cookie (spyware) System --------------------------------------------------------------------------------StatisticsScanned:Files: 55545 System: 4758 Not scanned: 8 Actions:Disinfected: 0 Renamed: 1 Deleted: 0 None: 2 Submitted: 1 Files not scanned:C:\HIBERFIL.SYS C:\PAGEFILE.SYS C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT C:\WINDOWS\SYSTEM32\CONFIG\SAM C:\WINDOWS\SYSTEM32\CONFIG\SECURITY C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM C:\DOCUMENTS AND SETTINGS\NICKZ FOLDER\LOCAL SETTINGS\TEMP\HSPERFDATA_NICKZ FOLDER\30224 Here is teh OTMoveIt2 log:Explorer killed successfully< HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0519A9C9-064A-4cbc-BC47-D0EACD581477} >Registry key HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0519A9C9-064A-4cbc-BC47-D0EACD581477}\\ not found.< HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{465A59EC-20E5-4fca-A38A-E5EC3C480218} >Registry key HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{465A59EC-20E5-4fca-A38A-E5EC3C480218}\\ not found.< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\lphc5lnj0eaat >Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\lphc5lnj0eaat deleted successfully.< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sysrest32.exe >Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sysrest32.exe deleted successfully.< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\icoo >Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\icoo\\ not found.C:\Program Files\ICOO Loader\skin moved successfully.C:\Program Files\ICOO Loader\My downloads moved successfully.C:\Program Files\ICOO Loader\logs moved successfully.C:\Program Files\ICOO Loader\Help moved successfully.C:\Program Files\ICOO Loader\downloads moved successfully.C:\Program Files\ICOO Loader\addons moved successfully.C:\Program Files\ICOO Loader moved successfully.C:\WINDOWS\system32\tmp.reg moved successfully.C:\WINDOWS\system32\d3d9caps.dat moved successfully.C:\WINDOWS\sed.exe moved successfully.C:\WINDOWS\grep.exe moved successfully.C:\WINDOWS\fdsv.exe moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\Packages moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\BrowserObjects moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\Autorun\StartMenuCurrentUser moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\Autorun\StartMenuAllUsers moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\Autorun\HKLM\RunOnce moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\Autorun\HKLM moved successfully. Link to post Share on other sites
Andro1d Posted June 9, 2008 Report Share Posted June 9, 2008 Hi,Please post the log from c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log) in your next reply. Link to post Share on other sites
charlieric Posted June 9, 2008 Author Report Share Posted June 9, 2008 Hi,Please post the log from c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log) in your next reply.I think I already did. The file is called: 06082008_203626.log and the results are again below. If there's another way you want me to post it, please let me know and I'll comply as best I can.Explorer killed successfully< HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0519A9C9-064A-4cbc-BC47-D0EACD581477} >Registry key HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0519A9C9-064A-4cbc-BC47-D0EACD581477}\\ not found.< HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{465A59EC-20E5-4fca-A38A-E5EC3C480218} >Registry key HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{465A59EC-20E5-4fca-A38A-E5EC3C480218}\\ not found.< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\lphc5lnj0eaat >Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\lphc5lnj0eaat deleted successfully.< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sysrest32.exe >Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\sysrest32.exe deleted successfully.< HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\icoo >Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\icoo\\ not found.C:\Program Files\ICOO Loader\skin moved successfully.C:\Program Files\ICOO Loader\My downloads moved successfully.C:\Program Files\ICOO Loader\logs moved successfully.C:\Program Files\ICOO Loader\Help moved successfully.C:\Program Files\ICOO Loader\downloads moved successfully.C:\Program Files\ICOO Loader\addons moved successfully.C:\Program Files\ICOO Loader moved successfully.C:\WINDOWS\system32\tmp.reg moved successfully.C:\WINDOWS\system32\d3d9caps.dat moved successfully.C:\WINDOWS\sed.exe moved successfully.C:\WINDOWS\grep.exe moved successfully.C:\WINDOWS\fdsv.exe moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\Packages moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\BrowserObjects moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\Autorun\StartMenuCurrentUser moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\Autorun\StartMenuAllUsers moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\Autorun\HKLM\RunOnce moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\Autorun\HKLM moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\Autorun\HKCU\RunOnce moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\Autorun\HKCU moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine\Autorun moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat\Quarantine moved successfully.C:\Documents and Settings\Nickz folder\Application Data\shc3lnj0eaat moved successfully.C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat\Quarantine\Packages moved successfully.C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat\Quarantine\BrowserObjects moved successfully.C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat\Quarantine\Autorun\StartMenuCurrentUser moved successfully.C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat\Quarantine\Autorun\StartMenuAllUsers moved successfully.C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat\Quarantine\Autorun\HKLM\RunOnce moved successfully.C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat\Quarantine\Autorun\HKLM moved successfully.C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat\Quarantine\Autorun\HKCU\RunOnce moved successfully.C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat\Quarantine\Autorun\HKCU moved successfully.C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat\Quarantine\Autorun moved successfully.C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat\Quarantine moved successfully.C:\Documents and Settings\Owner\Application Data\shc3lnj0eaat moved successfully.C:\WINDOWS\system32\lphc5lnj0eaat.exe moved successfully.C:\Patch's (sams game folder! dont delete plz)\Cheat Engine moved successfully.C:\Patch's (sams game folder! dont delete plz)\2.4.1jumphack moved successfully.C:\Patch's (sams game folder! dont delete plz) moved successfully.C:\Program Files\Cheat Engine moved successfully.< EmptyTemp >File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\.ttE.tmp scheduled to be deleted on reboot.Temp folders emptied.IE temp folders emptied.Explorer started successfullyOTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06082008_203626Files moved on Reboot...C:\DOCUME~1\Owner\LOCALS~1\Temp\.ttE.tmp moved successfully. Link to post Share on other sites
Andro1d Posted June 10, 2008 Report Share Posted June 10, 2008 Much better, some of the original log that you posted so I just wanted to make sure everything got moved to the right place.Other than that, nice job your log looks clean!Please use the following suggestions to help prevent reinfection.Make sure you have an Internet Connection.Double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")Click on the CleanUp! buttonA list of tool components used in the Cleanup of malware will be downloaded.If your Firewall or Real Time protection attempts to block OtMoveit2 to rech the Internet, please allow the application to do so.Click Yes to beging the Cleanup process and remove these components, including this application.You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.Clearing and Creating a new Restore Point to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. You will lose all previous Restore Points which are likely to be infected. Now we need to make a new Restore Point for your PC, please do the following:Click StartRight click My Computer and select PropertiesClick the System Restore tabCheck "Turn off System Restore" and click "Apply". Please give a moment as it will delete the old Restore pointsThen uncheck "Turn off System Restore" which will create a new Restore pointClick OKThe following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again. As a note, all of the tools and utilities mentioned are either free or have free versions available.Malwarebytes' Anti-Malware - A very powerful tool which searches and kills malware that infects your system. **Tutorial on installing & using this product can be found HERE**SpywareBlaster - Great prevention tool to keep malware from installing on your system.**Tutorial on installing & using this product can be found HERE**SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.**Tutorial on installing & using this product can be found HERE**IE-SpyAd - Puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.**Tutorial on installing & using this product can be found HERE**ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out malware that like to reside in the temp folders.It is important to run only one of each type of protection program in resident mode at a time since conflicts can make them less effective. This would mean only one resident antivirus, firewall and scanning type of anti-spyware. Programs like SpywareBlaster and IE-Spyads do not conflict with any of these since they don't have a real time scanning engine that would conflict.Windows Updates - It is highly recommend to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.It is also highly recommended to stay on top of your updates at all times, for Windows and all the above mentioned applications. This will ensure that you stay protected at the maximum level possible.Finally, I strongly recommend How did I get infected in the first place? (by Tony Klein)Good luck and safe surfing Link to post Share on other sites
charlieric Posted June 10, 2008 Author Report Share Posted June 10, 2008 Much better, some of the original log that you posted so I just wanted to make sure everything got moved to the right place.Other than that, nice job your log looks clean!Please use the following suggestions to help prevent reinfection.Make sure you have an Internet Connection.Double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")Click on the CleanUp! buttonA list of tool components used in the Cleanup of malware will be downloaded.If your Firewall or Real Time protection attempts to block OtMoveit2 to rech the Internet, please allow the application to do so.Click Yes to beging the Cleanup process and remove these components, including this application.You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.Clearing and Creating a new Restore Point to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. You will lose all previous Restore Points which are likely to be infected. Now we need to make a new Restore Point for your PC, please do the following:Click StartRight click My Computer and select PropertiesClick the System Restore tabCheck "Turn off System Restore" and click "Apply". Please give a moment as it will delete the old Restore pointsThen uncheck "Turn off System Restore" which will create a new Restore pointClick OKThe following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again. As a note, all of the tools and utilities mentioned are either free or have free versions available.Malwarebytes' Anti-Malware - A very powerful tool which searches and kills malware that infects your system. **Tutorial on installing & using this product can be found HERE**SpywareBlaster - Great prevention tool to keep malware from installing on your system.**Tutorial on installing & using this product can be found HERE**SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.**Tutorial on installing & using this product can be found HERE**IE-SpyAd - Puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.**Tutorial on installing & using this product can be found HERE**ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out malware that like to reside in the temp folders.It is important to run only one of each type of protection program in resident mode at a time since conflicts can make them less effective. This would mean only one resident antivirus, firewall and scanning type of anti-spyware. Programs like SpywareBlaster and IE-Spyads do not conflict with any of these since they don't have a real time scanning engine that would conflict.Windows Updates - It is highly recommend to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.It is also highly recommended to stay on top of your updates at all times, for Windows and all the above mentioned applications. This will ensure that you stay protected at the maximum level possible.Finally, I strongly recommend How did I get infected in the first place? (by Tony Klein)Good luck and safe surfing You've had Monster patience with me, as well as Energy. Thanks a million! Only a couple more things, it seems. When I go to system restore, the tab to turn it on and off is grayed out (unchecked) and it says "Disabled by Group Policy". I would also like quick instructions of how to restore the ability to set the wallpaper (background) and screen saver, which was turned off in the registry by one of the bugs when it put up the wallpaper telling me I have a spyware, as if I didn't know... Link to post Share on other sites
charlieric Posted June 11, 2008 Author Report Share Posted June 11, 2008 Much better, some of the original log that you posted so I just wanted to make sure everything got moved to the right place.Other than that, nice job your log looks clean!Please use the following suggestions to help prevent reinfection.Make sure you have an Internet Connection.Double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")Click on the CleanUp! buttonA list of tool components used in the Cleanup of malware will be downloaded.If your Firewall or Real Time protection attempts to block OtMoveit2 to rech the Internet, please allow the application to do so.Click Yes to beging the Cleanup process and remove these components, including this application.You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.Clearing and Creating a new Restore Point to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. You will lose all previous Restore Points which are likely to be infected. Now we need to make a new Restore Point for your PC, please do the following:Click StartRight click My Computer and select PropertiesClick the System Restore tabCheck "Turn off System Restore" and click "Apply". Please give a moment as it will delete the old Restore pointsThen uncheck "Turn off System Restore" which will create a new Restore pointClick OKThe following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again. As a note, all of the tools and utilities mentioned are either free or have free versions available.Malwarebytes' Anti-Malware - A very powerful tool which searches and kills malware that infects your system. **Tutorial on installing & using this product can be found HERE**SpywareBlaster - Great prevention tool to keep malware from installing on your system.**Tutorial on installing & using this product can be found HERE**SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.**Tutorial on installing & using this product can be found HERE**IE-SpyAd - Puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.**Tutorial on installing & using this product can be found HERE**ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out malware that like to reside in the temp folders.It is important to run only one of each type of protection program in resident mode at a time since conflicts can make them less effective. This would mean only one resident antivirus, firewall and scanning type of anti-spyware. Programs like SpywareBlaster and IE-Spyads do not conflict with any of these since they don't have a real time scanning engine that would conflict.Windows Updates - It is highly recommend to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.It is also highly recommended to stay on top of your updates at all times, for Windows and all the above mentioned applications. This will ensure that you stay protected at the maximum level possible.Finally, I strongly recommend How did I get infected in the first place? (by Tony Klein)Good luck and safe surfing You've had Monster patience with me, as well as Energy. Thanks a million! Only a couple more things, it seems. When I go to system restore, the tab to turn it on and off is grayed out (unchecked) and it says "Disabled by Group Policy". I would also like quick instructions of how to restore the ability to set the wallpaper (background) and screen saver, which was turned off in the registry by one of the bugs when it put up the wallpaper telling me I have a spyware, as if I didn't know...I figured out how to fix the background and screensaver problem. I also found a "System Restore Wizard" that seemed to allow me to set a restore point now that things are clean, but I still can't control the option from the tab in C drive properties. I am in an administrative user account. Any idea how I could find out whether the restore point was truly established? The other information you sent was very helpful. We're very happy to have control of our computer health again! Link to post Share on other sites
Andro1d Posted June 11, 2008 Report Share Posted June 11, 2008 Most likely System Restore was originally turned off. Not to big of a problem Link to post Share on other sites
Recommended Posts