Unsolved
This post is more than 5 years old
9 Posts
0
1574
November 5th, 2007 10:00
Please help, here's the Hijack This log
Below is my Hijack This log. I've already run an AVG scan in safe mode, still stuck with a white desktop due to Active Desktop failure, and get the Microsoft pop-up that the computer is at risk of spyware, etc.
Please let me know where to go from here!
Thanks,
Ken
Ken
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:44:30 AM, on 11/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Scan saved at 7:44:30 AM, on 11/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\mjjmkltj.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\regsvr32.exe
C:\Program Files\SecCenter\scprot4.exe
C:\WINDOWS\system32\regsvr32.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\mjjmkltj.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\regsvr32.exe
C:\Program Files\SecCenter\scprot4.exe
C:\WINDOWS\system32\regsvr32.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: r q$r
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2A8C2C57-93A7-0675-5A40-098909C6F6CC} - C:\Program Files\Frjfngrm\ezggxonw.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {55F4A5E8-FDF6-41E3-AA33-B99D66478C34} - C:\WINDOWS\system32\vturr.dll (file missing)
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\system32\negdofnb.dll (file missing)
O2 - BHO: BndDrive2 BHO Class - {8FB5B012-E8CB-46cd-B6D2-ED428FAE9043} - C:\Program Files\ISM\BndDrive5.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [winshow] "C:\WINDOWS\winshow.exe"
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu77.exe 61A847B5BBF72815358B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKLM\..\Run: [{60-0E-E7-74-ZN}] c:\windows\system32\dwdsrngt.exe CHD001
O4 - HKLM\..\Run: [mhadopev] rundll32.exe "C:\Program Files\hynupihc\dsrwhing.dll",Init
O4 - HKLM\..\Run: [bqxkzyhq] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\bqxkzyhq.dll"
O4 - HKLM\..\Run: [SC2] C:\Program Files\SecCenter\scprot4.exe
O4 - HKLM\..\Run: [nypexahm] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\nypexahm.dll"
O4 - HKLM\..\Run: [14160edb] rundll32.exe "C:\WINDOWS\system32\jmbvpwwj.dll",b
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partypoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partypoker\IEExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/176dc03795915f091103/netzip/RdxIE601.cab
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: DomainService - - C:\WINDOWS\system32\mjjmkltj.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: r q$r
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2A8C2C57-93A7-0675-5A40-098909C6F6CC} - C:\Program Files\Frjfngrm\ezggxonw.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {55F4A5E8-FDF6-41E3-AA33-B99D66478C34} - C:\WINDOWS\system32\vturr.dll (file missing)
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\system32\negdofnb.dll (file missing)
O2 - BHO: BndDrive2 BHO Class - {8FB5B012-E8CB-46cd-B6D2-ED428FAE9043} - C:\Program Files\ISM\BndDrive5.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [winshow] "C:\WINDOWS\winshow.exe"
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu77.exe 61A847B5BBF72815358B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKLM\..\Run: [{60-0E-E7-74-ZN}] c:\windows\system32\dwdsrngt.exe CHD001
O4 - HKLM\..\Run: [mhadopev] rundll32.exe "C:\Program Files\hynupihc\dsrwhing.dll",Init
O4 - HKLM\..\Run: [bqxkzyhq] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\bqxkzyhq.dll"
O4 - HKLM\..\Run: [SC2] C:\Program Files\SecCenter\scprot4.exe
O4 - HKLM\..\Run: [nypexahm] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\nypexahm.dll"
O4 - HKLM\..\Run: [14160edb] rundll32.exe "C:\WINDOWS\system32\jmbvpwwj.dll",b
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partypoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partypoker\IEExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/176dc03795915f091103/netzip/RdxIE601.cab
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: DomainService - - C:\WINDOWS\system32\mjjmkltj.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 8731 bytes
End of file - 8731 bytes
No Events found!


bamajim
10.4K Posts
0
November 5th, 2007 12:00
Please download Combofix and save to your desktop:
Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the contents of the C:\ComboFix.txt into your next reply.
Note: Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.
needhelp12
9 Posts
0
November 5th, 2007 16:00
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
.
.
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\ProductCode
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\Documents and Settings\Owner\Application Data.\Ultimate Fixer
C:\Documents and Settings\Owner\Application Data\WinAntiSpyware 2007
C:\Documents and Settings\Owner\Application Data\WinAntiSpyware 2007\Logs\update.log
C:\Program Files\Common Files\wnsxs~1
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe
C:\Program Files\SecCenter\scprot4.exe.bak
C:\Program Files\ucleaner_setup.exe
C:\WINDOWS\Casino.ico
C:\WINDOWS\cookies.ini
C:\WINDOWS\Free Online Dating.ico
C:\WINDOWS\hosts
C:\WINDOWS\Spyware Remover.ico
C:\WINDOWS\system32\batkkgvp.exe
C:\WINDOWS\system32\bcouklfh.ini
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\drvloxr.dll
C:\WINDOWS\system32\f10WtR
C:\WINDOWS\system32\fkmdvbtn
C:\WINDOWS\system32\fkmdvbtn\bg1.gif
C:\WINDOWS\system32\fkmdvbtn\bgtop.gif
C:\WINDOWS\system32\fkmdvbtn\bottom1.gif
C:\WINDOWS\system32\fkmdvbtn\essentials.gif
C:\WINDOWS\system32\fkmdvbtn\fkmdvbtn1.exe
C:\WINDOWS\system32\fkmdvbtn\fkmdvbtn2.exe
C:\WINDOWS\system32\fkmdvbtn\fkmdvbtn3.exe
C:\WINDOWS\system32\fkmdvbtn\icon1.ico
C:\WINDOWS\system32\fkmdvbtn\install1.gif
C:\WINDOWS\system32\fkmdvbtn\left1.gif
C:\WINDOWS\system32\fkmdvbtn\li.gif
C:\WINDOWS\system32\fkmdvbtn\logo.gif
C:\WINDOWS\system32\fkmdvbtn\main.htm
C:\WINDOWS\system32\fkmdvbtn\mainframe.htm
C:\WINDOWS\system32\fkmdvbtn\reinstall1.gif
C:\WINDOWS\system32\fkmdvbtn\right1.gif
C:\WINDOWS\system32\fkmdvbtn\s1.htm
C:\WINDOWS\system32\fkmdvbtn\s2.htm
C:\WINDOWS\system32\fkmdvbtn\s3.htm
C:\WINDOWS\system32\fkmdvbtn\SMTop1.gif
C:\WINDOWS\system32\fkmdvbtn\SMTop2.gif
C:\WINDOWS\system32\fkmdvbtn\SMTop3.gif
C:\WINDOWS\system32\fkmdvbtn\SMTop4.gif
C:\WINDOWS\system32\fkmdvbtn\soft1_off.gif
C:\WINDOWS\system32\fkmdvbtn\soft1_off_ext.gif
C:\WINDOWS\system32\fkmdvbtn\soft1_on.gif
C:\WINDOWS\system32\fkmdvbtn\soft1_on_ext.gif
C:\WINDOWS\system32\fkmdvbtn\soft2_off.gif
C:\WINDOWS\system32\fkmdvbtn\soft2_off_ext.gif
C:\WINDOWS\system32\fkmdvbtn\soft2_on.gif
C:\WINDOWS\system32\fkmdvbtn\soft2_on_ext.gif
C:\WINDOWS\system32\fkmdvbtn\soft3_off.gif
C:\WINDOWS\system32\fkmdvbtn\soft3_off_ext.gif
C:\WINDOWS\system32\fkmdvbtn\soft3_on.gif
C:\WINDOWS\system32\fkmdvbtn\soft3_on_ext.gif
C:\WINDOWS\system32\fkmdvbtn\softbottom_off.gif
C:\WINDOWS\system32\fkmdvbtn\softbottom_on.gif
C:\WINDOWS\system32\fkmdvbtn\softleft_off.gif
C:\WINDOWS\system32\fkmdvbtn\softleft_on.gif
C:\WINDOWS\system32\fkmdvbtn\top1.gif
C:\WINDOWS\system32\fkmdvbtn\top2.gif
C:\WINDOWS\system32\fkmdvbtn\turnoff1.gif
C:\WINDOWS\system32\fkmdvbtn\turnon1.gif
C:\WINDOWS\system32\hflkuocb.dll
C:\WINDOWS\system32\jjllm.bak1
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\llkkj.bak1
C:\WINDOWS\system32\llkkj.bak2
C:\WINDOWS\system32\mjjmkltj.exe
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\nuhrtujv.dll
C:\WINDOWS\system32\oTt06e
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\paqvjsar.dll
C:\WINDOWS\system32\rasjvqap.ini
C:\WINDOWS\system32\rrutv.bak2
C:\WINDOWS\system32\rrutv.ini
C:\WINDOWS\system32\rrutv.ini2
C:\WINDOWS\system32\rrutv.tmp
C:\WINDOWS\system32\vjutrhun.ini
C:\WINDOWS\system32\wqcntevi.exe
C:\WINDOWS\system32\yybeg.bak1
C:\WINDOWS\wr.txt
C:\x.txt
C:\z.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-10-05 to 2007-11-05 )))))))))))))))))))))))))))))))
.
2007-11-05 07:36
2007-11-05 02:54 85,568 --a------ C:\WINDOWS\system32\jmbvpwwj.dll
2007-11-05 02:51
2007-11-05 02:43
2007-11-05 02:41
2007-11-05 02:39
2007-11-05 02:39
2007-11-05 02:21 85,568 --a------ C:\WINDOWS\system32\wmjhtpev.dll
2007-11-05 01:53 85,568 --a------ C:\WINDOWS\system32\vshcyybr.dll
2007-11-05 00:40 85,568 --a------ C:\WINDOWS\system32\rcqusyrc.dll
2007-10-28 16:42
2007-10-28 07:23
2007-10-27 17:57 6,058,496 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-27 17:57 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-10-27 17:57 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-27 17:57 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-27 17:57 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-27 17:57 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-27 17:57 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-27 17:57 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-27 17:56 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2007-10-27 17:05 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-10-27 17:05 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2007-10-27 10:05
2007-10-27 10:02
2007-10-27 09:47
2007-10-27 06:54
2007-10-27 06:54 117 --a------ C:\Documents and Settings\Owner\mit.bat
2007-10-27 06:53
2007-10-27 06:53
2007-10-27 06:53 123,908 --a------ C:\WINDOWS\system32\vvgeowbv.exe
2007-10-27 06:52 41 --a------ C:\WINDOWS\plite731_uninstaller_.bat
2007-10-17 05:32
2007-10-16 10:21
2007-10-16 10:21
2007-10-16 10:20
2007-10-11 11:41 1,084,709 --a------ C:\Documents and Settings\Adrienne\PPPlus.dat
2007-10-10 05:42 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-05 06:13 --------- d--h--w C:\Documents and Settings\Owner\Application Data\Move Networks
2007-10-30 21:06 --------- d-----w C:\Program Files\PamperedPartnerPlus
2007-10-27 14:03 --------- d-----w C:\Program Files\EA SPORTS
2007-10-27 14:03 --------- d-----w C:\Program Files\DivX
2007-10-27 12:32 --------- d-----w C:\Program Files\Viewpoint
2007-10-27 12:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-18 03:17 --------- d-----w C:\Program Files\Yahoo!
2007-10-18 03:16 --------- d-----w C:\Program Files\Real
2007-10-18 03:15 --------- d-----w C:\Program Files\Cisco Systems
2007-10-18 03:15 --------- d-----w C:\Documents and Settings\Owner\Application Data\Cisco Systems
2007-10-04 02:48 --------- d-----w C:\Program Files\Common Files\Adobe
2005-03-22 04:55 42,184 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2005-09-28 02:35:50 423,169 --sha-w C:\WINDOWS\system32\kmllm.bak1
2005-10-07 19:35:27 339,734 --sha-w C:\WINDOWS\system32\kmllm.bak2
.
.
.
*Note* empty entries & legit default entries are not shown
C:\Program Files\Frjfngrm\ezggxonw.dll
C:\WINDOWS\system32\vturr.dll
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2006-01-19 11:06]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 00:00]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 C:\WINDOWS\BCMSMMSG.exe]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 07:59]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 07:59]
"diagent"="C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 00:01]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11:06]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 13:54]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 15:24]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-13 12:36]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-03 13:07]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" []
"{60-0E-E7-74-ZN}"="c:\windows\system32\dwdsrngt.exe" []
"14160edb"="C:\WINDOWS\system32\jmbvpwwj.dll" [2007-11-05 02:54]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-11-05 02:39]
"Sonic RecordNow!"="" []
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 11:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
@=
@=
**************************************************************************
Rootkit scan 2007-11-05 13:37:31
Windows 5.1.2600 Service Pack 2 NTFS
hidden files: 0
.
Completion time: 2007-11-05 13:40:30 - machine was rebooted
.
--- E O F ---
bamajim
10.4K Posts
0
November 5th, 2007 17:00
1. Open NotePad (not wordpad). Copy and paste the following into Notepad
File::
C:\WINDOWS\system32\jmbvpwwj.dll
C:\WINDOWS\system32\wmjhtpev.dll
C:\WINDOWS\system32\vshcyybr.dll
C:\WINDOWS\system32\rcqusyrc.dll
C:\Documents and Settings\Owner\mit.bat
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\plite731_uninstaller_.bat
C:\WINDOWS\system32\kmllm.bak1
C:\WINDOWS\system32\kmllm.bak2
C:\Program Files\Frjfngrm\ezggxonw.dll
C:\WINDOWS\system32\vturr.dll
C:\WINDOWS\system32\jmbvpwwj.dll
Folder::
C:\Program Files\Frjfngrm
C:\Program Files\Upuznvtt
C:\WINDOWS\S2VuIERvbm92YW4
C:\Program Files\hynupihc
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2A8C2C57-93A7-0675-5A40-098909C6F6CC}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{55F4A5E8-FDF6-41E3-AA33-B99D66478C34}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{60-0E-E7-74-ZN}"=-
"14160edb"=-
Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop
Using the Image as a reference, drag CFScript into ComboFix.exe
Following the same rules as indicated in my first post
Then post the contents of the C:\ComboFix.txt log in your reply
"The world is what you make of it"
needhelp12
9 Posts
0
November 6th, 2007 01:00
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
C:\Documents and Settings\Owner\mit.bat
C:\Program Files\Frjfngrm\ezggxonw.dll
C:\WINDOWS\plite731_uninstaller_.bat
C:\WINDOWS\system32\jmbvpwwj.dll
C:\WINDOWS\system32\kmllm.bak1
C:\WINDOWS\system32\kmllm.bak2
C:\WINDOWS\system32\rcqusyrc.dll
C:\WINDOWS\system32\vshcyybr.dll
C:\WINDOWS\system32\vturr.dll
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\system32\wmjhtpev.dll
.
.
C:\Program Files\Frjfngrm
C:\Program Files\hynupihc
C:\Program Files\Upuznvtt
C:\Program Files\Upuznvtt\bjsfbvxt.dll
C:\WINDOWS\plite731_uninstaller_.bat
C:\WINDOWS\S2VuIERvbm92YW4
C:\WINDOWS\system32\jmbvpwwj.dll
C:\WINDOWS\system32\kmllm.bak1
C:\WINDOWS\system32\kmllm.bak2
C:\WINDOWS\system32\rcqusyrc.dll
C:\WINDOWS\system32\vshcyybr.dll
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\system32\wmjhtpev.dll
((((((((((((((((((((((((( Files Created from 2007-10-06 to 2007-11-06 )))))))))))))))))))))))))))))))
.
2007-11-05 13:22 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-05 07:36
2007-11-05 02:51
2007-11-05 02:43
2007-11-05 02:41
2007-11-05 02:39
2007-11-05 02:39
2007-10-28 07:23
2007-10-27 17:57 6,058,496 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-27 17:57 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-10-27 17:57 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-27 17:57 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-27 17:57 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-27 17:57 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-27 17:57 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-27 17:57 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-27 17:56 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2007-10-27 17:05 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-10-27 17:05 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2007-10-27 10:05
2007-10-27 10:02
2007-10-27 09:47
2007-10-17 05:32
2007-10-16 10:21
2007-10-16 10:21
2007-10-16 10:20
2007-10-11 11:41 1,084,709 --a------ C:\Documents and Settings\Adrienne\PPPlus.dat
2007-10-10 05:42 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-05 23:48 --------- d-----w C:\Program Files\PamperedPartnerPlus
2007-11-05 06:13 --------- d--h--w C:\Documents and Settings\Owner\Application Data\Move Networks
2007-10-27 14:03 --------- d-----w C:\Program Files\EA SPORTS
2007-10-27 14:03 --------- d-----w C:\Program Files\DivX
2007-10-27 12:32 --------- d-----w C:\Program Files\Viewpoint
2007-10-27 12:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-18 03:17 --------- d-----w C:\Program Files\Yahoo!
2007-10-18 03:16 --------- d-----w C:\Program Files\Real
2007-10-18 03:15 --------- d-----w C:\Program Files\Cisco Systems
2007-10-18 03:15 --------- d-----w C:\Documents and Settings\Owner\Application Data\Cisco Systems
2007-10-04 02:48 --------- d-----w C:\Program Files\Common Files\Adobe
2005-03-22 04:55 42,184 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
.
.
.
*Note* empty entries & legit default entries are not shown
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2006-01-19 11:06]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 00:00]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 C:\WINDOWS\BCMSMMSG.exe]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 07:59]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 07:59]
"diagent"="C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 00:01]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11:06]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 13:54]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 15:24]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-13 12:36]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-03 13:07]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-11-05 02:39]
"Sonic RecordNow!"="" []
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 11:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
@=
@=
**************************************************************************
Rootkit scan 2007-11-05 22:12:03
Windows 5.1.2600 Service Pack 2 NTFS
hidden files: 0
.
Completion time: 2007-11-05 22:14:46 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-05 13:40
.
--- E O F ---
bamajim
10.4K Posts
0
November 6th, 2007 11:00
1. Please download ATF Cleaner by Atribune.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
This will remove all files from the items that are checked so if you have some cookies you'd like to save. please move them to a different directory first.
2. Run an online virus scan called Kaspersky from HERE.
2. A new smaller window will pop up. Press on " Accept". After reading the contents.
3. Now Kaspersky will update the anti-virus database. Let it run.
4. Click on " Next"->>" Scan Settings", and make sure the database is set to " extended". And check both the scan options. Then click OK.
5. Then click on " My Computer". And the scan will start.
6. When the scan is complete Select "Save error report as"
Then in the file name just type in kaspersky
Under "save as type" select text .txt
Save it to your Desktop.
Copy and post the results of the Kaspersky Online scan
==========
Note: The Kaspersky online scanner is not yet fully compatible with IE7. You may get returned to a window without the Accept/Decline buttons after allowing the ActiveX control. The buttons are there - you just can't see them! Click on the zoom button (bottom, right of the window) and change it from 100% to 75%. You should now see the buttons. Reset to 100% once the license has been accepted.
"The world is what you make of it"
needhelp12
9 Posts
0
November 7th, 2007 20:00
KASPERSKY ONLINE SCANNER REPORT
Wednesday, November 07, 2007 5:34:12 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 7/11/2007
Kaspersky Anti-Virus database records: 452764
-------------------------------------------------------------------------------
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
C:\
D:\
E:\
F:\
Total number of scanned objects: 78320
Number of viruses found: 20
Number of infected objects: 97
Number of suspicious objects: 0
Duration of the scan process: 01:21:44
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Musicmatch\Jukebox\mmjbaltlog.txt Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Musicmatch\Jukebox\mmjblog.txt Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Musicmatch\MIM\Database\Default.ldb Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Musicmatch\MIM\Database\Default.mdb Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temp\JET1B91.tmp Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\batkkgvp.exe.vir Infected: Trojan.Win32.Agent.bck skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\fkmdvbtn\fkmdvbtn2.exe.vir Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\mjjmkltj.exe.vir Infected: Trojan.Win32.Agent.bck skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\wqcntevi.exe.vir Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP619\A0108888.exe Infected: not-a-virus:AdWare.Win32.Rond.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP619\A0108903.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP619\A0108903.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP619\A0108936.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP619\A0108936.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP620\A0108955.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP620\A0108971.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP620\A0108971.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP620\A0109003.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP620\A0109008.exe Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP620\A0109018.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.b skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP620\A0109018.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP631\A0115241.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mb skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP631\A0115267.exe/file2 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP631\A0115267.exe Inno: infected - 1 skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP635\A0115657.exe Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP635\A0115681.exe/stream/data0002/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP635\A0115681.exe/stream/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP635\A0115681.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP635\A0115681.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP635\A0115681.exe NSIS: infected - 4 skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP635\A0115682.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP635\A0115688.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP635\A0115688.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP635\A0115688.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP635\A0115688.exe NSIS: infected - 3 skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP672\A0124050.exe Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP673\A0124071.dll Infected: not-a-virus:AdWare.Win32.BHO.je skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP673\A0124080.exe Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP674\A0124092.exe Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP674\A0124093.exe Infected: not-a-virus:AdWare.Win32.Agent.sw skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP674\A0124098.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.sw skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP674\A0124098.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP676\A0124186.exe Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP679\A0124341.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP681\A0124364.exe Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP694\A0124875.exe Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP694\A0124876.exe Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP695\A0124892.exe/stream/data0002 Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP695\A0124892.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.AdBand.a skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP695\A0124892.exe/stream Infected: not-a-virus:AdWare.Win32.AdBand.a skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP695\A0124892.exe NSIS: infected - 3 skipped
needhelp12
9 Posts
0
November 7th, 2007 20:00
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP700\A0125580.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP700\A0125581.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP701\A0125597.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP701\A0125598.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP701\A0125606.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP702\A0125616.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP702\A0125617.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP702\A0125618.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP703\A0125630.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP703\A0125631.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP703\A0125632.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP704\A0125646.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP704\A0125647.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP704\A0125648.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP705\A0125666.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP705\A0125667.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP705\A0125668.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP706\A0125685.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP706\A0125686.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP706\A0125687.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP706\A0125692.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP707\A0125700.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP707\A0125704.exe Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP707\A0125706.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP708\A0125714.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP709\A0126723.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP709\A0126728.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP710\A0126735.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP710\A0126742.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP711\A0126749.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP712\A0126758.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP713\A0126771.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP714\A0127777.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP715\A0127791.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP716\A0127804.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP716\A0127805.dll Infected: not-a-virus:AdWare.Win32.BHO.je skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP716\A0127808.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP717\A0127817.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP717\A0127822.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP718\A0127829.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP718\A0127836.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP719\A0127844.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP719\A0127847.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP719\A0127848.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP719\A0127857.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127866.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127896.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127905.exe Infected: Trojan.Win32.Small.oa skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127906.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127907.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127908.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127909.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127910.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127911.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127912.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127913.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127914.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127915.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127916.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127917.exe Infected: Trojan.Win32.Small.oa skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127918.exe Infected: Trojan.Win32.Small.oa skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127919.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127920.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127921.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127922.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127923.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127924.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127925.dll Infected: Trojan-Downloader.Win32.Small.gkg skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP720\A0127926.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP721\A0128030.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP721\A0128031.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP721\A0128032.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP721\A0128033.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP721\A0128043.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP721\A0128044.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP721\A0128045.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP722\A0128058.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP722\A0128059.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP722\A0128060.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP722\A0128062.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP722\A0128065.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP722\A0128066.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP722\A0128067.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP722\A0128082.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP723\A0128151.dll Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP723\A0128157.exe Object is locked skipped
C:\System Volume Information\_restore{10EFD0F0-6E50-4859-B010-2E06C3FF3E22}\RP724\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{F802ABF9-0259-4782-B769-144CEDCCA49D}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\Windows_OneCare_Evt.evt Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
bamajim
10.4K Posts
0
November 8th, 2007 11:00
"The world is what you make of it"
bamajim
10.4K Posts
0
November 9th, 2007 14:00
In your other thread, you indicated that you have no desktop background is that correct?
If so then do the following
Go HERE and Download System Repair Engine by smallfrogs
Rt Click sreng2.zip->>Extract all->>Extract it to your desktop
Open the sreng folder
Double click SREng->>Click Run
At the main Window, in the left Pane, Select System Repair
In the Rt pane under the Windows Shell /IE tab
Place checks beside the following entries
Enable using Control Panel
Show icons on desktop
Then Select the Repair button
Close SRE2
Reboot your PC. And give me an update on your PC's desktop
Do not run any other options with this tool unless instructed to do so.
"The world is what you make of it"
needhelp12
9 Posts
0
November 9th, 2007 14:00
Scan saved at 11:01:37 AM, on 11/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partypoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partypoker\IEExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/176dc03795915f091103/netzip/RdxIE601.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
End of file - 6993 bytes
needhelp12
9 Posts
0
November 9th, 2007 17:00
bamajim
10.4K Posts
0
November 9th, 2007 17:00
1. Using Windows Explorer
Locate and empty the following folder (But do not delete the folder itself)
2. Rerun Hijackthis (scan only) and place checks beside the following entries
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
Close all other open windows except Hijackthis and Select " Fix checked"
Close Hijackthis ->> Reboot your PC
You may now remove/delete/uninstall the tools we used to clean your PC
Now that your log is clean
There are some final notes:
Disable and Enable System Restore
the instructions are here
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
Updating Java:
- Download the latest version of
Update your Anti Virus SoftwareJava Runtime Environment (JRE) 6.u3.
Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
Click the " Download" button to the right.
Check the box that says: " Accept License Agreement".
The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u3-windowsi586-p.exe to install the newest version.
Use and maintain a Firewall There is a list HERE
- All of which are free
Download and install SiteHound by Firetrust for protection against malicious websites.Pick the version that matches your browser
Visit Microsoft's Windows Update Site Frequently for critical updates
Backup your Important Documents and Files on a regular basis
You may want to read this article" So how did I get infected in the first place" by Tony Klein
surf safe
"The world is what you make of it"