Help - Search - Members - Calendar
Full Version: Is Something Hiding?
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
Wally
Hi All

I think I may have something running in the background which is causing my system to run slow, and my connection seems slow even when it is supposed to be ok

This is my HijackThis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:05:02, on 15/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Belkin\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Admin\My Documents\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.skybroadband.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://192.168.0.1/start.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided By Sky Broadband
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [EPSON Stylus DX6000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE /FU "C:\WINDOWS\TEMP\E_S342.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [EPSON Stylus DX6000 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE /FU "C:\WINDOWS\TEMP\E_SB5.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [ITWSS6_Suite] "C:\Program Files\IT Works Security Suite 6\itwss.exe" /booting (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [ITWSS6_SAFE] "C:\Program Files\IT Works Security Suite 6\safe.exe" /booting (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [ITWSS6_SPM] "C:\Program Files\IT Works Security Suite 6\spm.exe" /booting (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ITWSS6_Suite] "C:\Program Files\IT Works Security Suite 6\itwss.exe" /booting (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ITWSS6_Suite] "C:\Program Files\IT Works Security Suite 6\itwss.exe" /booting (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ITWSS6_Suite] "C:\Program Files\IT Works Security Suite 6\itwss.exe" /booting (User 'Default user')
O4 - Global Startup: 20-20 Shortcut Bar.lnk = C:\Program Files\2020V61\Mswin\60\SCBar.Exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1196283546250
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

--
End of file - 11639 bytes


Thanks in advance for your help

Wally
LoPhatPhuud
First:
Please download ATF Cleaner by Atribune.
    Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Second:
Download Combofix from any of the links below, and save it to your desktop. For information regarding this download, please visit this webpage: http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Link 1
Link 2
Link 3


**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
    When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall
Wally
Ok here are the log files

ComboFix 08-02-16.2 - Admin 2008-02-16 9:03:44.1 - NTFSx86

Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Admin\Application Data\inst.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\nm


((((((((((((((((((((((((( Files Created from 2008-01-16 to 2008-02-16 )))))))))))))))))))))))))))))))
.

2008-02-15 21:50 . 2008-02-15 21:50 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-02-15 21:50 . 2008-02-15 21:50 <DIR> d-------- C:\Program Files\Zone Labs
2008-02-15 21:49 . 2008-02-15 21:51 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-15 21:49 . 2008-02-15 21:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-15 21:49 . 2008-02-15 21:49 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\SUPERAntiSpyware.com
2008-02-15 21:48 . 2008-02-15 21:48 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-15 20:13 . 2008-02-15 20:13 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-15 20:13 . 2008-02-15 20:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-15 08:39 . 2008-02-15 15:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SlySoft
2008-02-15 08:37 . 2008-02-15 08:37 <DIR> d-------- C:\Program Files\SlySoft
2008-02-15 08:37 . 2008-02-15 08:39 24 ---hs---- C:\WINDOWS\SAE03C749.tmp
2008-02-13 18:30 . 2008-02-13 18:30 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\InstallShield
2008-02-13 18:30 . 2007-11-27 22:51 35,216 --a------ C:\WINDOWS\system32\drivers\TMPassthru.sys
2008-02-11 19:52 . 2008-02-11 19:52 <DIR> d-------- C:\Program Files\Rainbow Technologies
2008-02-11 19:51 . 2008-02-11 19:51 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2008-02-11 19:51 . 2008-02-11 19:51 <DIR> d-------- C:\Program Files\QuickTime
2008-02-11 19:51 . 2008-02-11 19:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-02-11 19:51 . 1999-11-10 11:05 86,016 --a------ C:\WINDOWS\unvise32qt.exe
2008-02-11 19:51 . 2008-02-11 19:51 388 --a------ C:\WINDOWS\system32\QuickTime.qtp
2008-02-11 19:41 . 1996-11-11 12:08 1,063,328 --------- C:\WINDOWS\system\WEBSTE16.OCX
2008-02-11 19:40 . 2008-02-11 19:40 <DIR> d-------- C:\WINDOWS\Rainbow Technologies
2008-02-11 19:40 . 2008-02-11 19:51 <DIR> d-------- C:\Program Files\2020V61
2008-02-11 19:40 . 1998-11-11 15:06 57,856 --a------ C:\WINDOWS\system32\CAITF32.DLL
2008-02-11 19:40 . 1998-11-11 15:07 56,832 --a------ C:\WINDOWS\system32\CALAUNCH.EXE
2008-02-06 19:54 . 2008-02-06 19:54 <DIR> d-------- C:\Program Files\avijoin
2008-02-06 19:37 . 2007-09-24 08:05 378,152 --a------ C:\WINDOWS\system32\ImageDrive.cpl
2008-02-05 19:15 . 2008-02-05 19:15 55,949 --a------ C:\WINDOWS\system32\x264-uninstall.exe
2008-02-03 15:06 . 2008-02-03 15:06 <DIR> d-------- C:\Program Files\Audio Editor Gold
2008-02-03 12:41 . 2008-02-03 12:41 <DIR> d-------- C:\Program Files\Belkin
2008-02-03 12:41 . 2003-07-01 12:18 51,848 --a------ C:\WINDOWS\system32\drivers\btwusb.sys
2008-02-03 12:41 . 2003-07-01 12:19 17,484 --a------ C:\WINDOWS\system32\drivers\frmupgr.sys
2008-02-03 12:40 . 2003-07-01 05:01 77,824 -ra------ C:\WINDOWS\system32\btw_ci.dll
2008-02-02 20:18 . 2008-02-13 18:30 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-02 17:43 . 2008-02-02 17:43 <DIR> d-------- C:\Program Files\Nero
2008-02-02 17:43 . 2008-02-02 17:46 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-02-02 12:37 . 2008-02-02 12:37 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-01-31 19:38 . 2008-01-31 19:48 <DIR> d-------- C:\Program Files\Microsoft AutoRoute
2008-01-28 20:03 . 2008-01-28 20:04 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\ISP Monitor
2008-01-28 20:02 . 2008-01-28 20:02 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-01-27 09:27 . 2008-01-27 09:27 <DIR> d-------- C:\Program Files\Boilsoft AVI Converter
2008-01-27 09:27 . 2008-01-27 09:27 67 --a------ C:\WINDOWS\AVIConverter.INI
2008-01-24 19:58 . 2008-01-24 19:58 <DIR> d-------- C:\Program Files\VSO
2008-01-24 19:58 . 2008-02-06 07:16 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\Vso
2008-01-24 19:58 . 2006-09-29 11:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll
2008-01-24 19:58 . 2006-09-29 11:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll
2008-01-24 19:58 . 2006-09-29 11:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll
2008-01-24 19:58 . 2008-01-24 19:58 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-01-24 19:58 . 2008-01-24 19:58 47,360 --a------ C:\Documents and Settings\Admin\Application Data\pcouffin.sys
2008-01-24 19:57 . 2008-01-24 19:57 <DIR> d-------- C:\Program Files\DVD Shrink
2008-01-24 19:57 . 2008-01-24 19:57 <DIR> d-------- C:\Program Files\DVD Decrypter
2008-01-24 19:57 . 2008-02-14 20:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-24 18:36 . 2008-01-24 18:36 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-01-23 19:03 . 2008-01-23 19:03 <DIR> d-------- C:\Program Files\ABBYY FineReader 6.0 Sprint
2008-01-23 19:03 . 2008-01-23 19:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\UDL
2008-01-23 18:59 . 2006-03-20 00:00 63,488 --a------ C:\WINDOWS\system32\escwiad.dll
2008-01-23 18:59 . 2008-01-23 18:59 25 --a------ C:\WINDOWS\CDE DX6000EFDG.ini
2008-01-23 18:29 . 2008-02-15 11:52 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-01-23 14:41 . 2008-01-23 14:41 97,216 --a------ C:\WINDOWS\system32\drivers\AnyDVD.sys
2008-01-22 21:39 . 2008-01-22 21:39 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-01-22 15:53 . 2008-02-01 19:01 <DIR> d-------- C:\Program Files\uTorrent
2008-01-22 15:53 . 2008-02-15 19:21 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\uTorrent
2008-01-20 14:37 . 2008-01-20 14:37 <DIR> dr-h----- C:\Documents and Settings\Admin\Application Data\SecuROM
2008-01-20 14:37 . 2008-01-20 14:37 98,304 --a------ C:\WINDOWS\system32CmdLineExt.dll
2008-01-20 12:22 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2008-01-20 12:03 . 2008-01-20 12:03 <DIR> d-------- C:\Program Files\Electronic Arts
2008-01-19 09:29 . 2007-07-02 15:02 3,073,320 --a------ C:\WINDOWS\system32\AdvrCntr2D6E0B790.dll
2008-01-19 09:29 . 2007-07-02 15:02 996,648 --a------ C:\WINDOWS\system32\ShellManager10E2D762.dll
2008-01-19 09:29 . 2007-07-02 14:19 638,976 --a------ C:\WINDOWS\system32\NEROINSTAEC43759.DB

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 06:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-02-13 18:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-05 21:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-05 20:28 --------- d-----w C:\Program Files\Java
2008-02-03 22:31 --------- d-----w C:\Program Files\MagicISO
2008-02-03 22:30 --------- d-----w C:\Documents and Settings\Admin\Application Data\AVG7
2008-02-02 17:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-02-02 12:34 --------- d-----w C:\Program Files\ACE Mega CoDecS Pack
2008-01-23 19:08 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-23 19:04 --------- d-----w C:\Program Files\epson
2008-01-22 18:26 --------- d-----w C:\Program Files\Azureus
2008-01-22 18:21 --------- d-----w C:\Documents and Settings\Admin\Application Data\Azureus
2008-01-09 23:21 --------- d-----w C:\Program Files\RegDoctor
2008-01-09 18:52 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 2
2008-01-08 22:04 --------- d-----w C:\Documents and Settings\Admin\Application Data\Ahead
2008-01-08 20:50 --------- d-----w C:\Program Files\Unlocker
2008-01-08 20:05 --------- d-----w C:\Documents and Settings\Admin\Application Data\Media Player Classic
2008-01-08 19:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-01-06 20:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\ALM
2008-01-06 20:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-06 15:43 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-06 15:43 --------- d-----w C:\Program Files\Bonjour
2008-01-04 22:43 --------- d-----w C:\Program Files\Virtual Hottie 2
2008-01-03 23:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-01-03 23:01 --------- d-----w C:\Program Files\Yahoo!
2008-01-03 22:34 --------- d-----w C:\Program Files\directx
2008-01-03 22:32 --------- d-----w C:\Program Files\Logitech
2008-01-03 22:30 --------- d-----w C:\Program Files\Common Files\Logitech
2008-01-03 20:05 --------- d-----w C:\Program Files\7-Zip
2008-01-03 18:53 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-01-02 02:12 43,520 ----a-w C:\WINDOWS\system32\drivers\fetnd5bv.sys
2007-12-18 23:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PinnacleDriverCheck"="C:\WINDOWS\System32\PSDrvCheck.exe" [2003-08-29 08:47 396800]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2007-10-05 01:14 8491008]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 07:25 579072]
"Adobe Version Cue CS2"="C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 18:58 856064]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52 483328]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2003-12-16 22:37 188416]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2003-12-16 22:39 77824]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2007-10-05 01:14 81920]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 14:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 08:51 1836328]
"TMRUBottedTray"="C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe" [2007-12-19 00:18 288088]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ITWSS6_Suite"="C:\Program Files\IT Works Security Suite 6\itwss.exe" [ ]
"ITWSS6_SAFE"="C:\Program Files\IT Works Security Suite 6\safe.exe" [ ]
"ITWSS6_SPM"="C:\Program Files\IT Works Security Suite 6\spm.exe" [ ]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-29 04:19 219136]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{165150E1-F45A-FBC5-F2F6-6FC44B59DC30}]
C:\WINDOWS\system32\lcass.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 09:11:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Belkin\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Trend Micro\RUBotted\TMRUBottedLite.exe
.
**************************************************************************
.
Completion time: 2008-02-16 9:17:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-16 09:17:21
.
2008-02-13 07:15:48 --- E O F ---









Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:18:36, on 16/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Belkin\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedLite.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://192.168.0.1/start.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [ITWSS6_Suite] "C:\Program Files\IT Works Security Suite 6\itwss.exe" /booting (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [ITWSS6_SAFE] "C:\Program Files\IT Works Security Suite 6\safe.exe" /booting (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [ITWSS6_SPM] "C:\Program Files\IT Works Security Suite 6\spm.exe" /booting (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ITWSS6_Suite] "C:\Program Files\IT Works Security Suite 6\itwss.exe" /booting (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ITWSS6_Suite] "C:\Program Files\IT Works Security Suite 6\itwss.exe" /booting (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ITWSS6_Suite] "C:\Program Files\IT Works Security Suite 6\itwss.exe" /booting (User 'Default user')
O4 - Global Startup: 20-20 Shortcut Bar.lnk = C:\Program Files\2020V61\Mswin\60\SCBar.Exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1196283546250
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

--
End of file - 10878 bytes



Hope these help, Wally
LoPhatPhuud
1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
File::
C:\WINDOWS\SAE03C749.tmp
C:\WINDOWS\system32\lcass.exe

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{165150E1-F45A-FBC5-F2F6-6FC44B59DC30}


Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Wally
Ok I Have done that and this is the new report generated



ComboFix 08-02-16.2 - Admin 2008-02-17 10:56:25.2 - NTFSx86

Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Admin\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\SAE03C749.tmp
C:\WINDOWS\system32\lcass.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\SAE03C749.tmp . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-01-17 to 2008-02-17 )))))))))))))))))))))))))))))))
.

2008-02-16 18:03 . 2008-02-16 18:03 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-02-16 18:03 . 2008-02-17 11:03 31,767 --ah----- C:\WINDOWS\system32\vsconfig.xml
2008-02-16 18:03 . 2008-02-16 18:05 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-02-15 21:50 . 2008-02-16 18:07 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-02-15 21:50 . 2008-02-15 21:50 <DIR> d-------- C:\Program Files\Zone Labs
2008-02-15 21:49 . 2008-02-15 21:51 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-15 21:49 . 2008-02-15 21:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-15 21:49 . 2008-02-15 21:49 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\SUPERAntiSpyware.com
2008-02-15 21:48 . 2008-02-15 21:48 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-15 20:13 . 2008-02-15 20:13 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-15 20:13 . 2008-02-15 20:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-15 08:39 . 2008-02-15 15:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SlySoft
2008-02-15 08:37 . 2008-02-15 08:37 <DIR> d-------- C:\Program Files\SlySoft
2008-02-15 08:37 . 2008-02-17 11:03 0 --a------ C:\WINDOWS\SAE03C749.tmp
2008-02-13 18:30 . 2008-02-13 18:30 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\InstallShield
2008-02-13 18:30 . 2007-11-27 22:51 35,216 --a------ C:\WINDOWS\system32\drivers\TMPassthru.sys
2008-02-11 19:52 . 2008-02-11 19:52 <DIR> d-------- C:\Program Files\Rainbow Technologies
2008-02-11 19:51 . 2008-02-11 19:51 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2008-02-11 19:51 . 2008-02-11 19:51 <DIR> d-------- C:\Program Files\QuickTime
2008-02-11 19:51 . 2008-02-11 19:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-02-11 19:51 . 1999-11-10 11:05 86,016 --a------ C:\WINDOWS\unvise32qt.exe
2008-02-11 19:51 . 2008-02-11 19:51 388 --a------ C:\WINDOWS\system32\QuickTime.qtp
2008-02-11 19:41 . 1996-11-11 12:08 1,063,328 --------- C:\WINDOWS\system\WEBSTE16.OCX
2008-02-11 19:40 . 2008-02-11 19:40 <DIR> d-------- C:\WINDOWS\Rainbow Technologies
2008-02-11 19:40 . 2008-02-11 19:51 <DIR> d-------- C:\Program Files\2020V61
2008-02-11 19:40 . 1998-11-11 15:06 57,856 --a------ C:\WINDOWS\system32\CAITF32.DLL
2008-02-11 19:40 . 1998-11-11 15:07 56,832 --a------ C:\WINDOWS\system32\CALAUNCH.EXE
2008-02-06 19:54 . 2008-02-06 19:54 <DIR> d-------- C:\Program Files\avijoin
2008-02-06 19:37 . 2007-09-24 08:05 378,152 --a------ C:\WINDOWS\system32\ImageDrive.cpl
2008-02-05 19:15 . 2008-02-05 19:15 55,949 --a------ C:\WINDOWS\system32\x264-uninstall.exe
2008-02-03 15:06 . 2008-02-03 15:06 <DIR> d-------- C:\Program Files\Audio Editor Gold
2008-02-03 12:41 . 2008-02-03 12:41 <DIR> d-------- C:\Program Files\Belkin
2008-02-03 12:41 . 2003-07-01 12:18 51,848 --a------ C:\WINDOWS\system32\drivers\btwusb.sys
2008-02-03 12:41 . 2003-07-01 12:19 17,484 --a------ C:\WINDOWS\system32\drivers\frmupgr.sys
2008-02-03 12:40 . 2003-07-01 05:01 77,824 -ra------ C:\WINDOWS\system32\btw_ci.dll
2008-02-02 20:18 . 2008-02-13 18:30 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-02 17:43 . 2008-02-02 17:43 <DIR> d-------- C:\Program Files\Nero
2008-02-02 17:43 . 2008-02-02 17:46 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-02-02 12:37 . 2008-02-02 12:37 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-01-31 19:38 . 2008-01-31 19:48 <DIR> d-------- C:\Program Files\Microsoft AutoRoute
2008-01-28 20:03 . 2008-01-28 20:04 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\ISP Monitor
2008-01-28 20:02 . 2008-01-28 20:02 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-01-27 09:27 . 2008-01-27 09:27 <DIR> d-------- C:\Program Files\Boilsoft AVI Converter
2008-01-27 09:27 . 2008-01-27 09:27 67 --a------ C:\WINDOWS\AVIConverter.INI
2008-01-24 19:58 . 2008-01-24 19:58 <DIR> d-------- C:\Program Files\VSO
2008-01-24 19:58 . 2008-02-06 07:16 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\Vso
2008-01-24 19:58 . 2006-09-29 11:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll
2008-01-24 19:58 . 2006-09-29 11:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll
2008-01-24 19:58 . 2006-09-29 11:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll
2008-01-24 19:58 . 2008-01-24 19:58 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-01-24 19:58 . 2008-01-24 19:58 47,360 --a------ C:\Documents and Settings\Admin\Application Data\pcouffin.sys
2008-01-24 19:57 . 2008-01-24 19:57 <DIR> d-------- C:\Program Files\DVD Shrink
2008-01-24 19:57 . 2008-01-24 19:57 <DIR> d-------- C:\Program Files\DVD Decrypter
2008-01-24 19:57 . 2008-02-14 20:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-24 18:36 . 2008-01-24 18:36 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-01-23 19:03 . 2008-01-23 19:03 <DIR> d-------- C:\Program Files\ABBYY FineReader 6.0 Sprint
2008-01-23 19:03 . 2008-01-23 19:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\UDL
2008-01-23 18:59 . 2006-03-20 00:00 63,488 --a------ C:\WINDOWS\system32\escwiad.dll
2008-01-23 18:59 . 2008-01-23 18:59 25 --a------ C:\WINDOWS\CDE DX6000EFDG.ini
2008-01-23 18:29 . 2008-02-15 11:52 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-01-23 14:41 . 2008-01-23 14:41 97,216 --a------ C:\WINDOWS\system32\drivers\AnyDVD.sys
2008-01-22 21:39 . 2008-01-22 21:39 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-01-22 15:53 . 2008-02-01 19:01 <DIR> d-------- C:\Program Files\uTorrent
2008-01-22 15:53 . 2008-02-16 18:13 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\uTorrent
2008-01-20 14:37 . 2008-01-20 14:37 <DIR> dr-h----- C:\Documents and Settings\Admin\Application Data\SecuROM
2008-01-20 14:37 . 2008-01-20 14:37 98,304 --a------ C:\WINDOWS\system32CmdLineExt.dll
2008-01-20 12:22 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2008-01-20 12:03 . 2008-01-20 12:03 <DIR> d-------- C:\Program Files\Electronic Arts
2008-01-19 09:29 . 2007-07-02 15:02 3,073,320 --a------ C:\WINDOWS\system32\AdvrCntr2D6E0B790.dll
2008-01-19 09:29 . 2007-07-02 15:02 996,648 --a------ C:\WINDOWS\system32\ShellManager10E2D762.dll
2008-01-19 09:29 . 2007-07-02 14:19 638,976 --a------ C:\WINDOWS\system32\NEROINSTAEC43759.DB

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-17 10:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-02-13 18:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-05 21:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-05 20:28 --------- d-----w C:\Program Files\Java
2008-02-03 22:31 --------- d-----w C:\Program Files\MagicISO
2008-02-03 22:30 --------- d-----w C:\Documents and Settings\Admin\Application Data\AVG7
2008-02-02 17:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-02-02 12:34 --------- d-----w C:\Program Files\ACE Mega CoDecS Pack
2008-01-23 19:08 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-23 19:04 --------- d-----w C:\Program Files\epson
2008-01-22 18:26 --------- d-----w C:\Program Files\Azureus
2008-01-22 18:21 --------- d-----w C:\Documents and Settings\Admin\Application Data\Azureus
2008-01-09 23:21 --------- d-----w C:\Program Files\RegDoctor
2008-01-09 18:52 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 2
2008-01-08 22:04 --------- d-----w C:\Documents and Settings\Admin\Application Data\Ahead
2008-01-08 20:50 --------- d-----w C:\Program Files\Unlocker
2008-01-08 20:05 --------- d-----w C:\Documents and Settings\Admin\Application Data\Media Player Classic
2008-01-08 19:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-01-06 20:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\ALM
2008-01-06 20:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-06 15:43 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-06 15:43 --------- d-----w C:\Program Files\Bonjour
2008-01-04 22:43 --------- d-----w C:\Program Files\Virtual Hottie 2
2008-01-03 23:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-01-03 23:01 --------- d-----w C:\Program Files\Yahoo!
2008-01-03 22:34 --------- d-----w C:\Program Files\directx
2008-01-03 22:32 --------- d-----w C:\Program Files\Logitech
2008-01-03 22:30 --------- d-----w C:\Program Files\Common Files\Logitech
2008-01-03 20:05 --------- d-----w C:\Program Files\7-Zip
2008-01-03 18:53 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-01-02 02:12 43,520 ----a-w C:\WINDOWS\system32\drivers\fetnd5bv.sys
2007-12-18 23:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PinnacleDriverCheck"="C:\WINDOWS\System32\PSDrvCheck.exe" [2003-08-29 08:47 396800]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2007-10-05 01:14 8491008]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 07:25 579072]
"Adobe Version Cue CS2"="C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 18:58 856064]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52 483328]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2003-12-16 22:37 188416]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2003-12-16 22:39 77824]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2007-10-05 01:14 81920]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 14:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 08:51 1836328]
"TMRUBottedTray"="C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe" [2007-12-19 00:18 288088]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2005-08-29 19:09 980736]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ITWSS6_Suite"="C:\Program Files\IT Works Security Suite 6\itwss.exe" [ ]
"ITWSS6_SAFE"="C:\Program Files\IT Works Security Suite 6\safe.exe" [ ]
"ITWSS6_SPM"="C:\Program Files\IT Works Security Suite 6\spm.exe" [ ]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-29 04:19 219136]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{165150E1-F45A-FBC5-F2F6-6FC44B59DC30}]
C:\WINDOWS\system32\lcass.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-17 11:06:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Belkin\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Completion time: 2008-02-17 11:11:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-17 11:11:44
ComboFix2.txt 2008-02-16 09:17:25
.
2008-02-13 07:15:48 --- E O F ---
LoPhatPhuud
Good so far. We are almost there. One file did not delete, but I specified it for cosmetic purposes anyway so it can be left. There was also a registry entry that did not delete so I want to try antoher way.

Launch Notepad, and copy/paste in the box below to a new text file.
Save it on your Desktop as fixme.reg

CODE
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{165150E1-F45A-FBC5-F2F6-6FC44B59DC30}]


Reboot into Safe Mode.

Locate fixme.reg on your Desktop and double-click on it.

You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".


Reboot into Normal Mode.

Run HiJackTHis again, and post a new log in this thread.
Wally
Ok doen that and here is the HJT Log file


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:41:51, on 17/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Belkin\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://192.168.0.1/start.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [ITWSS6_Suite] "C:\Program Files\IT Works Security Suite 6\itwss.exe" /booting (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [ITWSS6_SAFE] "C:\Program Files\IT Works Security Suite 6\safe.exe" /booting (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [ITWSS6_SPM] "C:\Program Files\IT Works Security Suite 6\spm.exe" /booting (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ITWSS6_Suite] "C:\Program Files\IT Works Security Suite 6\itwss.exe" /booting (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ITWSS6_Suite] "C:\Program Files\IT Works Security Suite 6\itwss.exe" /booting (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ITWSS6_Suite] "C:\Program Files\IT Works Security Suite 6\itwss.exe" /booting (User 'Default user')
O4 - Global Startup: 20-20 Shortcut Bar.lnk = C:\Program Files\2020V61\Mswin\60\SCBar.Exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1196283546250
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 11341 bytes
LoPhatPhuud
Now, unless there are still issues not reflected in your log(s), your system is clean and we are finished. Here are some simple steps you can take to reduce the chance of infection in the future. These are only suggestions, and not meant to be comprehensive, or mandatory. Take what you want, leave the rest.

1. Visit Windows Update:
Make sure that you have all the Critical Updates recommended for your operating system, Internet Explorer, and any Office Programs you have installed. Be sure to select the Microsoft Update option from the Windows Update Control Panel.

2. Check your Java Runtime version. (Current=1.6, aka Version 6 Update 3)
You can check the current version of the Java Runtime Modules installed by opening the Java Control Panel and selecting 'About' from the 'General' tab.
The current version can be downloaded from Sun here: http://java.sun.com/javase/downloads/index.jsp Scroll down the page to 'Java Runtime Environment (JRE) 6 ' and press the 'Download' button. On the new web page, click the 'Accept License Agreement' button. Then select 'Windows Offline Installation, Multi-language' in the Windows Platform area just below the Accept button.

Note: Be sure to remove all prior versions using Add/Remove Programs before you install the new one. Remember to reboot after removal.

3. Adjust your security settings for ActiveX:
Select Internet Options from the Control Panels, or from Internet Explorer (Tools -> Internet Options -> Security tab)
Click on Select Internet Zone (this is usually the default)
Press 'default level', then OK
Now press "Custom Level."

In the ActiveX controls and plug-ins section set these options:
'Download signed ActiveX controls' - Prompt
'Download unsigned ActiveX controls' - Disable
'Initialize and script ActiveX controls not maked as safe'- Disable
All other ActiveX options accept the default

4. Download and install the following free programs
a. SpywareBlaster (ActiveX protection): http://www.javacoolsoftware.com/spywareblaster.html
b. HostsXpert (HOSTS file manager): http://www.funkytoad.com

5. Install Spyware Detection and Removal Programs:
You may also want to consider installing one (or more) of the following in addition to Windows Defender:
a.Spybot S&D: http://security.kolla.de/index.php?lang=en&page=download
b. AdAware 2007 http://www.lavasoft.de/
c. AVG AntiSpyware, Free Edition:
http://free.grisoft.com/doc/20/lng/us/tpl/v5
d. SuperAntiSpyWare, Free Edition:
http://www.snapfiles.com/get/SuperAntiSpyware.html

6. Turn on the option to Detect Phishes in your browser
Internet Explorer v7 and FireFox v2 include have excellent built-in antiphishing capabilities. Make sure you have this option turned on. If you are using Windows XP and are still using Internet Explorer 6, upgrade to Internet Explorer 7. The added security features make this upgrade mandatory for browsing today.

7. Reset System Restore
Please reset your System Restore. See Windows help for information.

8. Clean Temporary Files and Folders
Download and scan with [URL=http://www.ccleaner.com/downloadbuilds.asp]CCleaner[/URL
a. Starting with v1.27.260, CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free Basic or Slim versions instead of the Standard Build.
b. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"
c. Then select the items you wish to clean up.
In the Windows Tab:
• Clean all entries in the "Internet Explorer" section except Cookies.
• Clean all the entries in the "Windows Explorer" section.
• Clean all entries in the "System" section.
• Clean all entries in the "Advanced" section.
• Clean any others that you choose.


In the Applications Tab:
• Clean all except cookies in the Firefox/Mozilla section if you use it.
• Clean all in the Opera section if you use it.
• Clean Sun Java in the Internet Section.
• Clean any others that you choose.

d. Click the "Run Cleaner" button.
e. A pop up box will appear advising this process will permanently delete files from your system.
f. Click "OK" and it will scan and clean your system.
g. Click "exit" when done.
Run the disk cleanup utility called Cleanup! that you have already downloaded and installed
Check the custom settings to your liking under options, but be sure to delete temporary files and temporary internet files for all user profiles. Also, cleanout the prefetch folder and the recycle bin.
Then reboot into normal mode to let it clean out the remaining files.

9. Rogue/Suspect Anti-Spyware
Before using or purchasing any Spyware/Malware protection/removal program, always check the Rogue/Suspect Spyware List. It will save you a lot of grief, as well as money if you are thinking of purchasing. Here is the link: http://www.spywarewarrior.com/rogue_anti-spyware.htm

10. Anti-Spyware Programs Compared
Want to know just how effective your anti-spyware program is? Wonder how well any of the "rogue" programs listed above work? Check this link for an independent comparison of several anti-spyware programs: http://www.spywarewarrior.com/asw-test-guide.htm

11. Alternate Browser
Consider using an alternate browser as your default. I recommend and use Firefox as my primary browser. It is still necessary to keep Internet Explorer current and protected in order to use Windows Update.

If you use FireFox as your primary browser, then I recommend installing the NoScirpt extension:
http://www.noscript.net



For more information about Spyware, the tools available, and other informative material, including information on how you may have been infected in the first place, please check out this link: http://forum.gladiator-antivirus.com/index...?showtopic=9857

"It is your responsibility to read and adhere to the End User Licensing Agreement (EULA) of all software and services mentioned."

Good luck, and thanks for coming to our forums for help with your security and malware issues.
Wally
Thanks for all your Help

yourock.gif

Wally
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.