﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / Definately infectaed, but what ? / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Sat, 04 Jul 2009 00:33:07 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Definately infectaed, but what ?</title><link>http://tweaks.com/forum/Topic239501-29-1.aspx</link><description>[quote]I intend to delete the infected game emulators as well as the MAME frontends[/quote]&lt;br&gt;Delete those then do the following:&lt;br&gt;Run this online virus/spyware scan using [b]Internet Explorer[/b]:&lt;br&gt;[b][url=http://www.kaspersky.com/virusscanner][color="blue"]Kaspersky WebScanner[/color][/url][/b]&lt;br&gt;Next click [b]Kaspersky Online Scanner[/b]&lt;br&gt;You will be prompted to install an ActiveX component from Kaspersky, Click Yes.&lt;br&gt;•  The program will launch and then begin downloading the latest definition files: &lt;br&gt;•  Once the files have been downloaded click on NEXT &lt;br&gt;•  Now click on Scan Settings &lt;br&gt;•  In the scan settings make that the following are selected: &lt;br&gt;•  Scan using the following Anti-Virus database: &lt;br&gt;•  Standard &lt;br&gt;•  Scan Options: &lt;br&gt;•  Scan Archives&lt;br&gt;•  Scan Mail Bases&lt;br&gt;•  Click OK &lt;br&gt;•  Now under select a target to scan: &lt;br&gt;•  Select My Computer &lt;br&gt;•  This will start the program and scan your system. &lt;br&gt;•  The scan will take a while so be patient and let it run. &lt;br&gt;•  Once the scan is complete it will display if your system has been infected.It does not provide an option to clean/disinfect,[b]i need to see the scan results[/b]. &lt;br&gt;•  Now click on the Save as Text button.   &lt;br&gt;•  Save the file to your desktop. &lt;br&gt;•  [b]Copy and paste the contents of that file into your next reply[/b].&lt;br&gt;&lt;br&gt;If the above link doesn't work,try this:&lt;br&gt;[url]http://www.kaspersky.com/kos/english/kavwebscan.html[/url]</description><pubDate>Fri, 16 May 2008 06:54:50 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Definately infectaed, but what ?</title><link>http://tweaks.com/forum/Topic239501-29-1.aspx</link><description>Here are the results of the requested scans&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;//-----------------------------------------------------------------&lt;br&gt;//&lt;br&gt;//Product: BitDefender 8 Free Edition&lt;br&gt;//Version: 8.0&lt;br&gt;//&lt;br&gt;//Created on:16/05/200800:23:02&lt;br&gt;//&lt;br&gt;//-----------------------------------------------------------------&lt;br&gt;&lt;br&gt;&lt;br&gt;Statistics&lt;br&gt;&lt;br&gt;Scan path: C:\&lt;br&gt;D:\&lt;br&gt;E:\&lt;br&gt;F:\&lt;br&gt;G:\&lt;br&gt;H:\&lt;br&gt;Folders: 4759&lt;br&gt;Files:  249586&lt;br&gt;Archives: 2083 &lt;br&gt;Packed files: 7645&lt;br&gt;Identified viruses: 9&lt;br&gt;Infected files: 11&lt;br&gt;Warnings: 0&lt;br&gt;Suspect files: 0&lt;br&gt;Disinfected files: 0&lt;br&gt;Deleted files: 0&lt;br&gt;Copied files: 0&lt;br&gt;Moved files: 10&lt;br&gt;Renamed files: 0&lt;br&gt;I/O errors: 32&lt;br&gt;Scan time: 01:15:23&lt;br&gt;Scan speed (files/sec): 55&lt;br&gt;&lt;br&gt;Virus definitions: 1094044&lt;br&gt;Scan plugins: 14&lt;br&gt;Archive plugins: 39&lt;br&gt;Unpack plugins: 7&lt;br&gt;Mail plugins: 6&lt;br&gt;System plugins: 1&lt;br&gt;&lt;br&gt;Scan options&lt;br&gt;&lt;br&gt;Detection&lt;br&gt;[X] Scan boot sectors&lt;br&gt;[X] Scan archives&lt;br&gt;[X] Scan packed files&lt;br&gt;[X] Scan email&lt;br&gt;&lt;br&gt;File mask&lt;br&gt;[ ] Programs&lt;br&gt;[X] All files&lt;br&gt;[ ] User defined extensions: &lt;br&gt;[ ] Exclude extensions: ;&lt;br&gt;&lt;br&gt;Action&lt;br&gt;&lt;br&gt;Infected objects&lt;br&gt;[ ] Ignore&lt;br&gt;[X] Disinfect&lt;br&gt;[ ] Delete&lt;br&gt;[ ] Copy to quarantine&lt;br&gt;[ ] Move to quarantine&lt;br&gt;[ ] Rename&lt;br&gt;[ ] Prompt user&lt;br&gt;&lt;br&gt;Second action&lt;br&gt;[ ] Ignore&lt;br&gt;[ ] Delete&lt;br&gt;[ ] Copy to quarantine&lt;br&gt;[X] Move to quarantine&lt;br&gt;[ ] Rename&lt;br&gt;[ ] Prompt user&lt;br&gt;&lt;br&gt;Scan options&lt;br&gt;[X] Enable warnings&lt;br&gt;[X] Enable heuristics&lt;br&gt;[ ] Show all files in log&lt;br&gt;[X] Report file: vscan.log&lt;br&gt;[ ] Append to existing report&lt;br&gt;&lt;br&gt;Summary:&lt;br&gt;&lt;br&gt;C:\QooBox\Quarantine\C\0xf9.exe.virInfected Generic.Malware.dld!!.90566892&lt;br&gt;C:\QooBox\Quarantine\C\0xf9.exe.virDisinfection failed&lt;br&gt;C:\QooBox\Quarantine\C\0xf9.exe.virMoved&lt;br&gt;C:\SDFix\backups\backups.zip=&gt;backups/msdirect.sysInfected Backdoor.ForBot.M&lt;br&gt;C:\SDFix\backups\backups.zip=&gt;backups/msdirect.sysDisinfection failed&lt;br&gt;C:\SDFix\backups\backups.zipMoved&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\016RGT2B\cyber[1].wmfInfected Exploit.Win32.WMF-PFV&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\016RGT2B\cyber[1].wmfDisinfection failed&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\016RGT2B\cyber[1].wmfMoved&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\016RGT2B\dnlsvc[1].exeInfected Trojan.Hacktool.Rootkit.BR&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\016RGT2B\dnlsvc[1].exeDisinfection failed&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\016RGT2B\dnlsvc[1].exeMoved&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\016RGT2B\test[1].htmInfected Exploit.ADODB.Stream.BU&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\016RGT2B\test[1].htmDisinfection failed&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\016RGT2B\test[1].htmMoved&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0Z5U5S82\loader[1].exeInfected Generic.Malware.dld!!.90566892&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0Z5U5S82\loader[1].exeDisinfection failed&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0Z5U5S82\loader[1].exeMoved&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GL2F0D6B\2[1].aniInfected Exploit.Win32.MS05-002.Gen&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GL2F0D6B\2[1].aniDisinfection failed&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GL2F0D6B\2[1].aniMoved&lt;br&gt;C:\z_Drivers\svchost.exeInfected Trojan.Generic.163127&lt;br&gt;C:\z_Drivers\svchost.exeDisinfection failed&lt;br&gt;C:\z_Drivers\svchost.exeMoved&lt;br&gt;F:\EMULS\MAME\FrontENDS\MALA\MaLaKeyHook.dllInfected Backdoor.Bancodor.I&lt;br&gt;F:\EMULS\MAME\FrontENDS\MALA\MaLaKeyHook.dllDisinfection failed&lt;br&gt;F:\EMULS\MAME\FrontENDS\MALA\MaLaKeyHook.dllMoved&lt;br&gt;F:\EMULS\MAME\FrontENDS\MaLa.7z=&gt;MaLaKeyHook.dllInfected Backdoor.Bancodor.I&lt;br&gt;F:\EMULS\MAME\FrontENDS\MaLa.7z=&gt;MaLaKeyHook.dllDisinfection failed&lt;br&gt;F:\EMULS\MAME\FrontENDS\MaLa.7z=&gt;MaLaKeyHook.dllMove failed&lt;br&gt;F:\EMULS\N64\1964_099.exeInfected Trojan.Generic.79287&lt;br&gt;F:\EMULS\N64\1964_099.exeDisinfection failed&lt;br&gt;F:\EMULS\N64\1964_099.exeMoved&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;SUPERAntiSpyware Scan Log&lt;br&gt;http://www.superantispyware.com&lt;br&gt;&lt;br&gt;Generated 05/16/2008 at 02:27 AM&lt;br&gt;&lt;br&gt;Application Version : 4.0.1154&lt;br&gt;&lt;br&gt;Core Rules Database Version : 3462&lt;br&gt;Trace Rules Database Version: 1453&lt;br&gt;&lt;br&gt;Scan type       : Complete Scan&lt;br&gt;Total Scan Time : 00:25:28&lt;br&gt;&lt;br&gt;Memory items scanned      : 279&lt;br&gt;Memory threats detected   : 0&lt;br&gt;Registry items scanned    : 4166&lt;br&gt;Registry threats detected : 11&lt;br&gt;File items scanned        : 15458&lt;br&gt;File threats detected     : 7&lt;br&gt;&lt;br&gt;Trojan.Unknown Origin&lt;br&gt;c:\z_Drivers&lt;br&gt;C:\WINDOWS\..\z_Drivers&lt;br&gt;&lt;br&gt;Trojan.SystemDriver&lt;br&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#DriverLoad&lt;br&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#DriverCheck&lt;br&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#SystemDriverLoad&lt;br&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#Winhost&lt;br&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#Winhost1&lt;br&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#Winhost2&lt;br&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#Winhost3&lt;br&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#Winhost4&lt;br&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#ADriver&lt;br&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#FDriver&lt;br&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#SystemDriver&lt;br&gt;&lt;br&gt;Trojan.MSDirect&lt;br&gt;C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C8E56DE-8F65-4744-A90C-6E3BE24FA74E}\RP69\A0040205.SYS&lt;br&gt;C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C8E56DE-8F65-4744-A90C-6E3BE24FA74E}\RP69\A0040209.SYS&lt;br&gt;&lt;br&gt;Trojan.Downloader-DnlSvc&lt;br&gt;C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C8E56DE-8F65-4744-A90C-6E3BE24FA74E}\RP71\A0040319.EXE&lt;br&gt;&lt;br&gt;Trojan.Downloader-Gen/Searcher&lt;br&gt;C:\SYSTEM VOLUME INFORMATION\_RESTORE{7C8E56DE-8F65-4744-A90C-6E3BE24FA74E}\RP71\A0040390.EXE&lt;br&gt;&lt;br&gt;Adware.Tracking Cookie&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Cookies\system@www.cadelasexy[2].txt&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Logfile of HijackThis v1.99.1&lt;br&gt;Scan saved at 11:07:53, on 16/05/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16608)&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\Hotspot Shield\bin\openvpnas.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\WINDOWS\system32\wscntfy.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.0.1.20080130-2132\soffice.exe&lt;br&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;C:\WINDOWS\system32\notepad.exe&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\WINDOWS\system32\NOTEPAD.EXE&lt;br&gt;C:\Documents and Settings\Poi\Desktop\HijackThis.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://techwhims.blogspot.com/&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;O4 - HKCU\..\Run: [SODCPreLoad] C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.0.1.20080130-2132\preload.exe C:\PROGRA~1\IBM\Lotus\Symphony\data\.sodc\&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;br&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O11 - Options group: [INTERNATIONAL] International*&lt;br&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;br&gt;O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll&lt;br&gt;O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll&lt;br&gt;O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe&lt;br&gt;&lt;br&gt;----------------------------------------------------------------------&lt;br&gt;&lt;br&gt;I have deleted all the detected spyware using SUPERAntiSpyware, I did a second scan and nothing was detected.&lt;br&gt;I intend to delete the infected game emulators as well as the MAME frontends, is this this a good method of getting rid of those viruses or is it better to look for dedicated tools for each virus ?&lt;br&gt;&lt;br&gt;</description><pubDate>Fri, 16 May 2008 05:15:14 GMT</pubDate><dc:creator>Err</dc:creator></item><item><title>RE: Definately infectaed, but what ?</title><link>http://tweaks.com/forum/Topic239501-29-1.aspx</link><description>You can re-enable BitDefender,forget Avira and carry on with the remaining instructions then if you will.</description><pubDate>Thu, 15 May 2008 18:18:45 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Definately infectaed, but what ?</title><link>http://tweaks.com/forum/Topic239501-29-1.aspx</link><description>I have BitDefender 8 Free Edition, build 8.0.202&lt;br&gt;I disabled it because I did not want to disrupt the use of the anti malware programs.&lt;br&gt;I've used BitDefender for a few months and have not experienced any problems with it.</description><pubDate>Thu, 15 May 2008 18:15:14 GMT</pubDate><dc:creator>Err</dc:creator></item><item><title>RE: Definately infectaed, but what ?</title><link>http://tweaks.com/forum/Topic239501-29-1.aspx</link><description>[quote]I'm reluctant to switch from BitDefender, would a scan result from BitDefender be as reliable as&lt;br&gt;Avira AntiVir ?[/quote]&lt;br&gt;The reason i asked you to install and scan with Avira is because i cannot see any signs of virus protection installed in the latest Hijackthis log you posted,have you disabled BitDefender or is there a problem with it.</description><pubDate>Thu, 15 May 2008 18:01:41 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Definately infectaed, but what ?</title><link>http://tweaks.com/forum/Topic239501-29-1.aspx</link><description>I'm reluctant to switch from BitDefender, would a scan result from BitDefender be as reliable as &lt;br&gt;Avira AntiVir ?</description><pubDate>Thu, 15 May 2008 17:49:07 GMT</pubDate><dc:creator>Err</dc:creator></item><item><title>RE: Definately infectaed, but what ?</title><link>http://tweaks.com/forum/Topic239501-29-1.aspx</link><description>Please download/install [b]Avira AntiVir Personal - FREE Antivirus[/b]: &lt;br&gt;[url]http://www.free-av.com/en/download/1/download_avira_antivir_personal__free_antivirus.html[/url]&lt;br&gt;Perform a full scan with Avira and allow it to delete everything it detects.&lt;br&gt;[b]Restart your pc when you've done.[/b]&lt;br&gt;After restart,open Avira Antivirus and select "Reports".&lt;br&gt;Then double click the report from the full scan you have just completed. &lt;br&gt;Click the "Report File" button,then [b]copy and paste the report into your next reply[/b].&lt;br&gt;&lt;br&gt;&lt;br&gt;Download [b]ATF Cleaner[/b] by [b]Atribune[/b]:&lt;br&gt;[url]http://www.atribune.org/ccount/click.php?id=1[/url]&lt;br&gt;[b]Do not run it just yet.[/b]&lt;br&gt;&lt;br&gt;Download\install [b]'SuperAntiSpyware Free Version Home Users'[/b] from here:&lt;br&gt;[URL]http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE[/URL]&lt;br&gt;&lt;br&gt;Launch SuperAntiSpyware and click on 'Check for updates'.&lt;br&gt;If you encounter any error messages while downloading the updates,manually download them from [B][URL=http://www.superantispyware.com/definitions.html][COLOR="BLUE"]Here[/COLOR][/URL][/B].&lt;br&gt;Once the updates have been installed,[b]exit[/b] SuperAntiSpyware.&lt;br&gt;[b]Do not run it just yet.[/b]&lt;br&gt;&lt;br&gt;Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'. &lt;br&gt;Make sure all browser and all Windows Explorer windows are closed before fixing:&lt;br&gt;[b]O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)[/b]&lt;br&gt;Exit Hijackthis.&lt;br&gt;&lt;br&gt;[b]Now double-click ATF-Cleaner.exe to run the program.[/b]&lt;br&gt;Click 'Select All' found at the bottom of the list.&lt;br&gt;Click the 'Empty Selected' button.&lt;br&gt;If you use [b]Firefox[/b] browser, do this also:&lt;br&gt;Click Firefox at the top and choose 'Select All' from the list.&lt;br&gt;Click the 'Empty Selected' button.&lt;br&gt;[b][color="blue"]NOTE:[/color][/b] &lt;br&gt;[color="blue"]If you would like to keep your saved passwords,please click [b]'No'[/b] at the prompt.[/color]&lt;br&gt;If you use [b]Opera[/b] browser,do this also:&lt;br&gt;Click Opera at the top and choose 'Select All' from the list.&lt;br&gt;Click the 'Empty Selected' button.&lt;br&gt;[b][color="blue"]NOTE:[/color][/b] &lt;br&gt;[color="blue"]If you would like to keep your saved passwords,please click [b]'No'[/b] at the prompt.[/color]&lt;br&gt;Click 'Exit' on the Main menu to close the program.&lt;br&gt;&lt;br&gt;[b]Now Start SuperAntiSpyware.[/b]&lt;br&gt;On the main screen click on 'Scan your computer'.&lt;br&gt;Check: 'Perform Complete Scan'.&lt;br&gt;Click 'Next' to start the scan.&lt;br&gt;&lt;br&gt;Superantispyware will now scan your computer,when it's finished it will list all/any infections found.&lt;br&gt;Make sure everything found has a checkmark next to it,then press 'Next'.&lt;br&gt;Click on 'Finish' when you've done.&lt;br&gt;&lt;br&gt;It's possible that the program will ask you to reboot in order to delete some files.&lt;br&gt;&lt;br&gt;Obtain the SuperAntiSpyware log as follows:&lt;br&gt;Click on 'Preferences'.&lt;br&gt;Click on the 'Statistics/Logs' tab.&lt;br&gt;Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.&lt;br&gt;It will then open in your default text editor,such as Notepad.&lt;br&gt;[b]Copy and paste the contents of that report into your next reply.[/b]&lt;br&gt;&lt;br&gt;&lt;br&gt;Your version of [b]Sun Java[/b] is out of date.&lt;br&gt;Older versions have vulnerabilities that malware can use to infect your system.&lt;br&gt;Please follow these steps to remove older versions of Sun Java,and then update.&lt;br&gt;1. Download the latest version of [b][url=http://java.sun.com/javase/downloads/index.jsp][color="blue"]Java Runtime Environment (JRE)[/color][/url][/b]&lt;br&gt;2. Scroll down to where it says '[b]Java Runtime Environment (JRE) 6u6[/b]'.&lt;br&gt;3. Click the "Download" button to the right.&lt;br&gt;4. Select the Platform and Language for your download,then check the box that says: "Accept License Agreement".&lt;br&gt;5. The page will refresh.&lt;br&gt;6. Click on the link to download [b]'Windows Offline Installation, Multi-language - jre-6u6-windows-i586-p.exe'[/b] [15.21 MB] and save to your desktop.&lt;br&gt;7. Close any programs you may have running - especially your web browser.&lt;br&gt;8. Go to Start &gt; Control Panel double-click on Add/Remove programs and remove all older versions of Java.&lt;br&gt;9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.&lt;br&gt;10. Click the Change/Remove button.&lt;br&gt;11. Repeat as many times as necessary to remove each Java version.&lt;br&gt;12. Reboot your computer once all Java components are removed.&lt;br&gt;13. Then from your desktop double-click on [b]jre-6u6-windows-i586-p.exe[/b] to install the newest version.&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log,let me know how your pc is running now please.[/b]</description><pubDate>Thu, 15 May 2008 17:39:56 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Definately infectaed, but what ?</title><link>http://tweaks.com/forum/Topic239501-29-1.aspx</link><description>I had my headphones on because previous to this spyware problem, I was listening to a netcast.&lt;br&gt;Ran ComboFix and HijackThis without any noticeable problems.&lt;br&gt;The CPU Usage is back to normal, FireFox is responding well, no longer hanging and only one startup item enabled, ctfmon.exe&lt;br&gt;&lt;br&gt;Problems are fixed, your help is much appreciated, thank you.&lt;br&gt;&lt;br&gt;Here are the results&lt;br&gt;&lt;br&gt;ComboFix 08-05-12.1 - Poi 2008-05-15 23:05:39.2 - NTFSx86&lt;br&gt;Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.198 [GMT 1:00]&lt;br&gt;Running from: C:\Documents and Settings\Poi\Desktop\ComboFix.exe&lt;br&gt;Command switches used :: C:\Documents and Settings\Poi\Desktop\CFScript.txt&lt;br&gt; * Created a new restore point&lt;br&gt;&lt;br&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;br&gt;&lt;br&gt;FILE ::&lt;br&gt;C:\[u]0[/u]xf9.exe&lt;br&gt;C:\z_Drivers&lt;br&gt;.&lt;br&gt;&lt;br&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;&lt;br&gt;C:\[u]0[/u]xf9.exe&lt;br&gt;&lt;br&gt;.&lt;br&gt;(((((((((((((((((((((((((   Files Created from 2008-04-15 to 2008-05-15  )))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;&lt;br&gt;2008-05-15 21:49 . 2008-05-15 21:49&lt;DIR&gt;d--------C:\WINDOWS\ERUNT&lt;br&gt;2008-05-15 21:44 . 2008-05-15 22:05&lt;DIR&gt;d--------C:\SDFix&lt;br&gt;2008-05-15 11:38 . 2008-05-15 11:38&lt;DIR&gt;d--------C:\z_Drivers&lt;br&gt;2008-05-09 08:05 . 2008-05-09 08:05&lt;DIR&gt;d--------C:\Documents and Settings\Poi\Application Data\Talkback&lt;br&gt;2008-05-02 18:25 . 2008-05-02 18:25&lt;DIR&gt;d--------C:\Program Files\Rockstar Games&lt;br&gt;2008-04-28 22:23 . 2008-04-28 22:23&lt;DIR&gt;d--------C:\Program Files\Hotspot Shield&lt;br&gt;2008-04-26 22:02 . 2008-04-26 22:04&lt;DIR&gt;d--------C:\Documents and Settings\Poi\Application Data\Dimdim&lt;br&gt;2008-04-26 22:02 . 2005-11-27 19:2531,896--a------C:\WINDOWS\system32\drivers\dfmirage.sys&lt;br&gt;2008-04-26 22:02 . 2005-11-27 19:2530,360--a------C:\WINDOWS\system32\dfmirage.dll&lt;br&gt;2008-04-25 14:12 . 2004-08-30 14:25438,272--a------C:\WINDOWS\system32\vp6vfw.dll&lt;br&gt;2008-04-25 14:12 . 2004-12-10 10:06327,680--a------C:\WINDOWS\system32\vp6dec.ax&lt;br&gt;2008-04-25 14:12 . 2007-04-12 15:01118,832--a------C:\WINDOWS\system32\SHW32.DLL&lt;br&gt;2008-04-23 12:17 . 2008-04-23 13:06&lt;DIR&gt;d--------C:\Program Files\PeerGuardian2&lt;br&gt;2008-04-22 10:31 . 2008-04-22 10:31&lt;DIR&gt;dr-h-----C:\Documents and Settings\Poi\Application Data\SecuROM&lt;br&gt;2008-04-22 06:17 . 2008-04-22 08:42&lt;DIR&gt;d--------C:\Program Files\Desktop Activity Recorder&lt;br&gt;2008-04-20 12:51 . 2008-04-20 12:51&lt;DIR&gt;d--------C:\Program Files\OpenAL&lt;br&gt;2008-04-20 12:51 . 2008-04-20 12:51409,600--a------C:\WINDOWS\system32\wrap_oal.dll&lt;br&gt;2008-04-20 12:51 . 2008-04-20 12:51114,688--a------C:\WINDOWS\system32\OpenAL32.dll&lt;br&gt;2008-04-20 12:47 . 2008-04-20 12:47&lt;DIR&gt;d--------C:\Program Files\Paradox Interactive&lt;br&gt;2008-04-19 00:30 . 2008-04-19 00:30&lt;DIR&gt;d--------C:\Program Files\Network Stumbler&lt;br&gt;2008-04-18 20:04 . 2008-04-18 20:03737,280--a------C:\WINDOWS\iun6002.exe&lt;br&gt;2008-04-18 13:21 . 2008-04-18 13:21&lt;DIR&gt;d--------C:\Documents and Settings\All Users\Application Data\Default&lt;br&gt;2008-04-17 16:43 . 2008-04-17 16:43107,888--a------C:\WINDOWS\system32\CmdLineExt.dll&lt;br&gt;2008-04-17 08:42 . 2008-04-17 08:42&lt;DIR&gt;d--------C:\Program Files\BIGSPEED Peer-to-Peer SDK&lt;br&gt;&lt;br&gt;.&lt;br&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;2008-05-15 22:04---------d-----wC:\Documents and Settings\Poi\Application Data\OpenOffice.org2&lt;br&gt;2008-05-15 20:2014----a-wC:\Documents and Settings\Poi\getfile.dat&lt;br&gt;2008-05-15 17:08---------d-----wC:\Documents and Settings\All Users\Application Data\Spybot - Search &amp; Destroy&lt;br&gt;2008-05-15 16:28---------d-----wC:\Program Files\BOINC&lt;br&gt;2008-05-14 10:54---------d-----wC:\Documents and Settings\All Users\Application Data\Kontiki&lt;br&gt;2008-05-08 14:33---------d--h--wC:\Program Files\InstallShield Installation Information&lt;br&gt;2008-04-25 13:06---------d-----wC:\Program Files\EA Sports&lt;br&gt;2008-04-25 12:56---------d-----wC:\Program Files\Common Files\LogiShrd&lt;br&gt;2008-04-25 12:38---------d-----wC:\Documents and Settings\All Users\Application Data\Logishrd&lt;br&gt;2008-04-18 19:16---------d-----wC:\Program Files\Atheros&lt;br&gt;2008-04-18 19:1443,520----a-wC:\WINDOWS\system32\CmdLineExt03.dll&lt;br&gt;2008-04-17 13:40---------d-----wC:\Documents and Settings\Poi\Application Data\Hamachi&lt;br&gt;2008-04-13 18:51---------d-----wC:\Program Files\New Star Soccer 3&lt;br&gt;2008-04-11 00:44---------d-----wC:\Program Files\Project64 1.6&lt;br&gt;2008-04-10 13:19---------d-----wC:\Program Files\1964&lt;br&gt;2008-04-10 12:18---------d-----wC:\Program Files\mupen64 0.5&lt;br&gt;2008-04-09 20:07---------d-----wC:\Program Files\mupen64 0.4&lt;br&gt;2008-04-05 14:35---------d-----wC:\Program Files\Microsoft Silverlight&lt;br&gt;2008-03-28 12:13---------d-----wC:\Program Files\Safari&lt;br&gt;2008-03-28 12:13---------d-----wC:\Documents and Settings\Poi\Application Data\Apple Computer&lt;br&gt;2008-03-28 12:12---------d-----wC:\Program Files\Apple Software Update&lt;br&gt;2008-03-28 12:12---------d-----wC:\Documents and Settings\All Users\Application Data\Apple&lt;br&gt;2008-03-24 23:03---------d-----wC:\Documents and Settings\Poi\Application Data\Vso&lt;br&gt;2008-03-22 22:27---------d-----wC:\Program Files\VSO&lt;br&gt;2008-03-19 15:37---------d-----wC:\Documents and Settings\All Users\Application Data\Logitech&lt;br&gt;2008-03-19 15:07---------d-----wC:\Program Files\SiSoftware&lt;br&gt;2008-03-19 15:00---------d-----wC:\Program Files\Belarc&lt;br&gt;2008-03-18 17:32---------d--h--wC:\Documents and Settings\All Users\Application Data\{3DABBC31-9BB8-45D8-BE78-353E801E5DBA}&lt;br&gt;2008-03-18 17:32---------d-----wC:\Program Files\GGPO Client&lt;br&gt;2008-03-17 18:11---------d-----wC:\Program Files\mosaic&lt;br&gt;2008-03-16 21:05---------d-----wC:\Program Files\Windows Media Connect 2&lt;br&gt;2008-03-16 20:54---------d-----wC:\Program Files\Kontiki&lt;br&gt;2008-03-16 20:54---------d-----wC:\Program Files\Channel4&lt;br&gt;2008-03-16 20:54---------d-----wC:\Documents and Settings\All Users\Application Data\Channel4&lt;br&gt;2008-03-14 14:23415,096----a-wC:\WINDOWS\system32\pr2aqvlb.exe&lt;br&gt;2008-03-07 11:56920,088----a-wC:\WINDOWS\system32\igxpun.exe&lt;br&gt;2008-03-06 18:20691,545----a-wC:\WINDOWS\unins000.exe&lt;br&gt;2008-03-04 13:00811,776----a-wC:\WINDOWS\boinc.scr&lt;br&gt;2008-02-15 12:21147,456----a-wC:\WINDOWS\system32\igfxCoIn_v4926.dll&lt;br&gt;2008-02-15 12:1257,344----a-wC:\WINDOWS\system32\igxprd32.dll&lt;br&gt;2008-02-15 12:122,643,968----a-wC:\WINDOWS\system32\igxpdx32.dll&lt;br&gt;2008-02-15 12:12151,040----a-wC:\WINDOWS\system32\igxpgd32.dll&lt;br&gt;2008-02-15 12:121,670,144----a-wC:\WINDOWS\system32\igxpdv32.dll&lt;br&gt;2008-02-15 12:01294,912----a-wC:\WINDOWS\system32\igldev32.dll&lt;br&gt;2008-02-15 12:002,334,720----a-wC:\WINDOWS\system32\iglicd32.dll&lt;br&gt;2008-02-15 11:48524,288----a-wC:\WINDOWS\system32\igfxcfg.exe&lt;br&gt;2008-02-15 11:4648,128----a-wC:\WINDOWS\system32\igfxsrvc.dll&lt;br&gt;2008-02-15 11:46249,856----a-wC:\WINDOWS\system32\igfxsrvc.exe&lt;br&gt;2008-02-15 11:4624,576----a-wC:\WINDOWS\system32\igfxexps.dll&lt;br&gt;2008-02-15 11:46204,800----a-wC:\WINDOWS\system32\igfxpph.dll&lt;br&gt;2008-02-15 11:46163,840----a-wC:\WINDOWS\system32\igfxext.exe&lt;br&gt;2008-02-15 11:46159,744----a-wC:\WINDOWS\system32\hkcmd.exe&lt;br&gt;2008-02-15 11:46135,168----a-wC:\WINDOWS\system32\igfxtray.exe&lt;br&gt;2008-02-15 11:46135,168----a-wC:\WINDOWS\system32\igfxdo.dll&lt;br&gt;2008-02-15 11:46131,072----a-wC:\WINDOWS\system32\igfxpers.exe&lt;br&gt;2008-02-15 11:453,293,184----a-wC:\WINDOWS\system32\igfxress.dll&lt;br&gt;2008-02-15 11:45208,896----a-wC:\WINDOWS\system32\igfxdev.dll&lt;br&gt;2008-02-15 11:45172,032----a-wC:\WINDOWS\system32\igfxres.dll&lt;br&gt;2008-02-15 11:45163,840----a-wC:\WINDOWS\system32\igfxzoom.exe&lt;br&gt;2008-02-15 11:45102,400----a-wC:\WINDOWS\system32\hccutils.dll&lt;br&gt;.&lt;br&gt;&lt;br&gt;------- Sigcheck -------&lt;br&gt;&lt;br&gt;2007-12-21 00:32  359040  a14fafd66adbd55a86f17a37e5ec4263C:\WINDOWS\system32\drivers\tcpip.sys&lt;br&gt;.&lt;br&gt;(((((((((((((((((((((((((((((   snapshot@2008-05-15_22.20.07.51   )))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;- 2008-05-15 21:10:0360,934----a-wC:\WINDOWS\system32\perfc009.dat&lt;br&gt;+ 2008-05-15 21:25:5760,934----a-wC:\WINDOWS\system32\perfc009.dat&lt;br&gt;- 2008-05-15 21:10:03396,608----a-wC:\WINDOWS\system32\perfh009.dat&lt;br&gt;+ 2008-05-15 21:25:57396,608----a-wC:\WINDOWS\system32\perfh009.dat&lt;br&gt;.&lt;br&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;.&lt;br&gt;*Note* empty entries &amp; legit default entries are not shown &lt;br&gt;REGEDIT4&lt;br&gt;&lt;br&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"SODCPreLoad"="C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.0.1.20080130-2132\preload.exe" [2008-02-26 10:13 40960]&lt;br&gt;"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]&lt;br&gt;&lt;br&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56 15360]&lt;br&gt;&lt;br&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]&lt;br&gt;"nltide_3"="advpack.dll" [2007-12-07 03:21 124928 C:\WINDOWS\system32\advpack.dll]&lt;br&gt;&lt;br&gt;[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Launchy.lnk]&lt;br&gt;path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launchy.lnk&lt;br&gt;backup=C:\WINDOWS\pss\Launchy.lnkCommon Startup&lt;br&gt;&lt;br&gt;[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]&lt;br&gt;path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk&lt;br&gt;backup=C:\WINDOWS\pss\Ralink Wireless Utility.lnkCommon Startup&lt;br&gt;&lt;br&gt;[HKLM\~\startupfolder\C:^Documents and Settings^Poi^Start Menu^Programs^Startup^GameSpot Download Manager.lnk]&lt;br&gt;path=C:\Documents and Settings\Poi\Start Menu\Programs\Startup\GameSpot Download Manager.lnk&lt;br&gt;backup=C:\WINDOWS\pss\GameSpot Download Manager.lnkStartup&lt;br&gt;&lt;br&gt;[HKLM\~\startupfolder\C:^DOCUME~1^Poi^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]&lt;br&gt;path=C:\DOCUME~1\Poi\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk&lt;br&gt;backup=C:\WINDOWS\pss\OpenOffice.org 2.3.lnkStartup&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD]&lt;br&gt;--a------ 2007-04-23 12:23 1032640 C:\Program Files\Kontiki\KHost.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADriver]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]&lt;br&gt;--a------ 2005-12-13 22:50 88204 C:\WINDOWS\AGRSMMSG.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]&lt;br&gt;--a------ 2006-07-19 10:41 69632 C:\WINDOWS\Alcmtr.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]&lt;br&gt;--------- 2006-07-19 10:41 53248 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDMCon]&lt;br&gt;--a------ 2005-06-20 13:10 421888 c:\PROGRA~1\softwin\BITDEF~1\bdmcon.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDNewsAgent]&lt;br&gt;--a------ 2005-05-09 13:19 8192 c:\progra~1\softwin\bitdef~1\bdnagent.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]&lt;br&gt;--a------ 2004-08-03 23:56 15360 C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]&lt;br&gt;--a------ 2008-02-14 00:09 486856 C:\Program Files\DAEMON Tools Lite\daemon.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]&lt;br&gt;--a------ 2008-02-15 12:46 159744 C:\WINDOWS\system32\hkcmd.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]&lt;br&gt;--a------ 2008-02-15 12:46 159744 C:\WINDOWS\system32\hkcmd.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]&lt;br&gt;--a------ 2008-02-15 12:46 131072 C:\WINDOWS\system32\igfxpers.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]&lt;br&gt;--a------ 2008-02-15 12:46 135168 C:\WINDOWS\system32\igfxtray.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]&lt;br&gt;--a------ 2007-04-23 12:23 1032640 C:\Program Files\Kontiki\KHost.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]&lt;br&gt;C:\Program Files\Logitech\QuickCam\Quickcam.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]&lt;br&gt;--a------ 2008-02-15 12:46 131072 C:\WINDOWS\system32\igfxpers.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]&lt;br&gt;--a------ 2006-07-19 10:42 16248320 C:\WINDOWS\RTHDCPL.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]&lt;br&gt;--a------ 2006-07-19 10:42 2879488 C:\WINDOWS\SkyTel.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmcService]&lt;br&gt;--a------ 2004-10-15 20:40 2577632 C:\PROGRA~1\Sygate\SPF\smc.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]&lt;br&gt;-rahs---- 2008-01-28 12:43 2097488 C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]&lt;br&gt;--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]&lt;br&gt;C:\Program Files\Veoh Networks\Veoh\VeohClient.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMware hqtray]&lt;br&gt;--a------ 2007-10-08 10:21 55856 C:\Program Files\VMware\VMware Player\hqtray.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]&lt;br&gt;"uvnc_service"=2 (0x2)&lt;br&gt;"LexBceS"=2 (0x2)&lt;br&gt;"VMware NAT Service"=2 (0x2)&lt;br&gt;"vmount2"=2 (0x2)&lt;br&gt;"VMnetDHCP"=2 (0x2)&lt;br&gt;"VMAuthdService"=2 (0x2)&lt;br&gt;"ufad-p2v"=2 (0x2)&lt;br&gt;"ThreadMaster"=2 (0x2)&lt;br&gt;"rpcapd"=3 (0x3)&lt;br&gt;"WMPNetworkSvc"=3 (0x3)&lt;br&gt;"LVCOMSer"=2 (0x2)&lt;br&gt;"LVPrcSrv"=2 (0x2)&lt;br&gt;"LVSrvLauncher"=2 (0x2)&lt;br&gt;"SandraTheSrv"=3 (0x3)&lt;br&gt;"SandraDataSrv"=3 (0x3)&lt;br&gt;"pr2aqvlb"=2 (0x2)&lt;br&gt;"HotspotShieldService"=2 (0x2)&lt;br&gt;"dnlsvc"=2 (0x2)&lt;br&gt;"KService"=2 (0x2)&lt;br&gt;"XCOMM"=2 (0x2)&lt;br&gt;"SmcService"=2 (0x2)&lt;br&gt;"bdss"=2 (0x2)&lt;br&gt;&lt;br&gt;[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]&lt;br&gt;"SODCPreLoad"=C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.0.1.20080130-2132\preload.exe C:\PROGRA~1\IBM\Lotus\Symphony\data\.sodc\&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]&lt;br&gt;"EnableFirewall"= 0 (0x0)&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;br&gt;"%windir%\\system32\\sessmgr.exe"=&lt;br&gt;"C:\\Program Files\\UltraVNC\\vncviewer.exe"=&lt;br&gt;"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=&lt;br&gt;"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=&lt;br&gt;"C:\\Program Files\\Messenger\\msmsgs.exe"=&lt;br&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"=&lt;br&gt;"C:\\Program Files\\Kontiki\\KService.exe"=&lt;br&gt;"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\Win32\\RpcDataSrv.exe"=&lt;br&gt;"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\RpcSandraSrv.exe"=&lt;br&gt;"C:\\Program Files\\BIGSPEED Peer-to-Peer SDK\\bsP2pHubDemo.exe"=&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]&lt;br&gt;"5900:TCP"= 5900:TCP:vnc5900&lt;br&gt;"5800:TCP"= 5800:TCP:vnc5800&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]&lt;br&gt;"AllowInboundEchoRequest"= 1 (0x1)&lt;br&gt;&lt;br&gt;R0 pe3aqvlb;XIII Century Environment Driver (pe3aqvlb);C:\WINDOWS\system32\drivers\pe3aqvlb.sys [2008-03-14 15:22]&lt;br&gt;R0 ps7aqvlb;XIII Century Synchronization Driver (ps7aqvlb);C:\WINDOWS\system32\drivers\ps7aqvlb.sys [2008-03-14 15:21]&lt;br&gt;R2 vstor2-p2v30;Vstor2 P2V30 Virtual Storage Driver;C:\Program Files\VMware\VMware Converter\vstor2-p2v30.sys [2007-01-30 20:41]&lt;br&gt;R3 dfmirage;dfmirage;C:\WINDOWS\system32\DRIVERS\dfmirage.sys [2005-11-27 19:25]&lt;br&gt;R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2008-01-23 22:25]&lt;br&gt;S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\NSNDIS5.SYS [2004-03-24 03:12]&lt;br&gt;S3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys []&lt;br&gt;S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 00:01]&lt;br&gt;S4 pr2aqvlb;XIII Century Drivers Auto Removal (pr2aqvlb);C:\WINDOWS\system32\pr2aqvlb.exe svc []&lt;br&gt;S4 ThreadMaster;Thread Master;C:\WINDOWS\system32\ThreadMaster\ThreadMast.exe [2003-03-18 00:27]&lt;br&gt;S4 ufad-p2v;VMware Converter Service;"C:\Program Files\VMware\VMware Converter\vmware-ufad.exe" -d "C:\Program Files\VMware\VMware Converter\\" -s ufad-p2v.xml []&lt;br&gt;S4 uvnc_service;uvnc_service;"C:\Program Files\UltraVNC\WinVNC.exe" -service []&lt;br&gt;&lt;br&gt;.&lt;br&gt;**************************************************************************&lt;br&gt;&lt;br&gt;catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net&lt;br&gt;Rootkit scan 2008-05-15 23:07:43&lt;br&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;br&gt;&lt;br&gt;scanning hidden processes ... &lt;br&gt;&lt;br&gt;scanning hidden autostart entries ...&lt;br&gt;&lt;br&gt;scanning hidden files ... &lt;br&gt;&lt;br&gt;scan completed successfully&lt;br&gt;hidden files: 0&lt;br&gt;&lt;br&gt;**************************************************************************&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\OMSCAN]&lt;br&gt;"ImagePath"="\Sys"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]&lt;br&gt;"ImagePath"=""&lt;br&gt;.&lt;br&gt;Completion time: 2008-05-15 23:08:10&lt;br&gt;ComboFix-quarantined-files.txt  2008-05-15 22:08:06&lt;br&gt;ComboFix2.txt  2008-05-15 21:20:27&lt;br&gt;&lt;br&gt;Pre-Run: 7,603,470,336 bytes free&lt;br&gt;Post-Run: 7,817,502,720 bytes free&lt;br&gt;&lt;br&gt;263&lt;br&gt;&lt;br&gt;-----------------------------------------------------------------------------------------------------------------------------------------&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Logfile of HijackThis v1.99.1&lt;br&gt;Scan saved at 23:13:26, on 15/05/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16608)&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\wscntfy.exe&lt;br&gt;C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.0.1.20080130-2132\soffice.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\WINDOWS\system32\notepad.exe&lt;br&gt;C:\WINDOWS\explorer.exe&lt;br&gt;C:\WINDOWS\system32\taskmgr.exe&lt;br&gt;C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\Documents and Settings\Poi\Desktop\HijackThis.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://techwhims.blogspot.com/&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;O4 - HKCU\..\Run: [SODCPreLoad] C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.0.1.20080130-2132\preload.exe C:\PROGRA~1\IBM\Lotus\Symphony\data\.sodc\&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)&lt;br&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O11 - Options group: [INTERNATIONAL] International*&lt;br&gt;O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll&lt;br&gt;O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll&lt;br&gt;&lt;br&gt;</description><pubDate>Thu, 15 May 2008 17:33:30 GMT</pubDate><dc:creator>Err</dc:creator></item><item><title>RE: Definately infectaed, but what ?</title><link>http://tweaks.com/forum/Topic239501-29-1.aspx</link><description>Remove your headphones although i cannot understand why you had them on while running Combofix!!&lt;br&gt;&lt;br&gt;Copy and paste ALL the following text in the code box below into [b]Notepad[/b].&lt;br&gt;Click on File(in the menu at the top)&gt;Save as../Save as Type: 'All Files' /File name: [b]CFScript[/b] to your desktop.&lt;br&gt;[quote]File::&lt;br&gt;C:\z_Drivers&lt;br&gt;C:\0xf9.exe&lt;br&gt;Registry::&lt;br&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"DriverLoad"=-&lt;br&gt;"DriverCheck"=-&lt;br&gt;"SystemDriverLoad"=-&lt;br&gt;"alpha"=-&lt;br&gt;"beta"=-&lt;br&gt;"gamma"=-&lt;br&gt;"SystemDriver"=-&lt;br&gt;"FDriver"=-&lt;br&gt;"ADriver"=-&lt;br&gt;"CDriver"=-&lt;br&gt;"DDriver"=-&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]&lt;br&gt;"CDriver"=-&lt;br&gt;"DDriver"=-&lt;br&gt;"alpha"=-&lt;br&gt;"beta"=-&lt;br&gt;"gamma"=-&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\alpha]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\beta]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CDriver]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDriver]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverCheck]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverLoad]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FDriver]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gamma]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemDriver]&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemDriverLoad]&lt;br&gt;[/quote]&lt;br&gt;Now drag then drop the [b]CFScript[/b] file onto [b]ComboFix.exe[/b] as seen in the image below.&lt;br&gt;&lt;br&gt;[img]http://img.photobucket.com/albums/v624/29wood/CFScript.gif[/img]&lt;br&gt;&lt;br&gt;This will start ComboFix again. &lt;br&gt;After reboot, (in case it asks to reboot), [b]post the contents of Combofix.txt in your next reply along with a new HijackThis log.[/b]</description><pubDate>Thu, 15 May 2008 16:54:25 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Definately infectaed, but what ?</title><link>http://tweaks.com/forum/Topic239501-29-1.aspx</link><description>Followed the instructions, I disabled all startup items before using SDFix however svchost.exe is still enabled, all 5 entries plus the 6 blank entries.&lt;br&gt;&lt;br&gt;I ran both applications without any noticeable problems.&lt;br&gt;&lt;br&gt;Here are the results&lt;br&gt;&lt;br&gt;&lt;br&gt;[b]SDFix: Version 1.182 [/b]&lt;br&gt;Run by Poi on 15/05/2008 at 21:54&lt;br&gt;&lt;br&gt;Microsoft Windows XP [Version 5.1.2600]&lt;br&gt;Running From: C:\SDFix&lt;br&gt;&lt;br&gt;[b]Checking Services [/b]:&lt;br&gt;&lt;br&gt;[b]Name [/b]: &lt;br&gt;dnlsvc&lt;br&gt;msdirect&lt;br&gt;&lt;br&gt;[b]Path [/b]:&lt;br&gt;"C:\DOCUME~1\Poi\LOCALS~1\Temp\dnlsvc.exe" &lt;br&gt;\??\C:\WINDOWS\system32\msdirect.sys &lt;br&gt;&lt;br&gt;dnlsvc - Deleted&lt;br&gt;msdirect - Deleted&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Restoring Windows Registry Values&lt;br&gt;Restoring Windows Default Hosts File&lt;br&gt;&lt;br&gt;Rebooting&lt;br&gt;&lt;br&gt;&lt;br&gt;[b]Checking Files [/b]: &lt;br&gt;&lt;br&gt;Trojan Files Found:&lt;br&gt;&lt;br&gt;C:\WINDOWS\system32\msdirect.sys - Deleted&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Removing Temp Files&lt;br&gt;&lt;br&gt;[b]ADS Check [/b]:&lt;br&gt; &lt;br&gt;&lt;br&gt;&lt;br&gt;                                 [b]Final Check [/b]:&lt;br&gt;&lt;br&gt;catchme 0.3.1359.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net&lt;br&gt;Rootkit scan 2008-05-15 22:00:18&lt;br&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;br&gt;&lt;br&gt;scanning hidden processes ...&lt;br&gt;&lt;br&gt;scanning hidden services &amp; system hive ...&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]&lt;br&gt;"s1"=dword:2df9c43f&lt;br&gt;"s2"=dword:110480d0&lt;br&gt;"h0"=dword:00000001&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]&lt;br&gt;"p0"="C:\Program Files\DAEMON Tools Lite\"&lt;br&gt;"h0"=dword:00000000&lt;br&gt;"khjeh"=hex:73,77,9d,44,52,04,3a,96,64,2c,89,59,f4,05,3c,2c,b1,76,a7,38,16,..&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]&lt;br&gt;"a0"=hex:20,01,00,00,25,5d,36,3f,12,c8,45,c9,6d,c9,2b,96,e3,42,a1,87,db,..&lt;br&gt;"khjeh"=hex:91,6e,b0,e0,15,28,5d,87,f6,0a,45,2e,2f,5f,db,77,e8,a0,53,1a,89,..&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]&lt;br&gt;"khjeh"=hex:71,4f,4c,8a,c1,fc,63,1e,3d,c3,12,7f,71,99,fc,44,96,b4,cc,df,e3,..&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]&lt;br&gt;"p0"="C:\Program Files\DAEMON Tools Lite\"&lt;br&gt;"h0"=dword:00000000&lt;br&gt;"khjeh"=hex:73,77,9d,44,52,04,3a,96,64,2c,89,59,f4,05,3c,2c,b1,76,a7,38,16,..&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]&lt;br&gt;"a0"=hex:20,01,00,00,25,5d,36,3f,12,c8,45,c9,6d,c9,2b,96,e3,42,a1,87,db,..&lt;br&gt;"khjeh"=hex:91,6e,b0,e0,15,28,5d,87,f6,0a,45,2e,2f,5f,db,77,e8,a0,53,1a,89,..&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]&lt;br&gt;"khjeh"=hex:71,4f,4c,8a,c1,fc,63,1e,3d,c3,12,7f,71,99,fc,44,96,b4,cc,df,e3,..&lt;br&gt;&lt;br&gt;scanning hidden registry entries ...&lt;br&gt;&lt;br&gt;scanning hidden files ...&lt;br&gt;&lt;br&gt;scan completed successfully&lt;br&gt;hidden processes: 0&lt;br&gt;hidden services: 0&lt;br&gt;hidden files: 0&lt;br&gt;&lt;br&gt;&lt;br&gt;[b]Remaining Services [/b]:&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Authorized Application Key Export:&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]&lt;br&gt;"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"&lt;br&gt;"C:\\Program Files\\UltraVNC\\vncviewer.exe"="C:\\Program Files\\UltraVNC\\vncviewer.exe:*:Enabled:vncviewer.exe"&lt;br&gt;"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"="C:\\Program Files\\SmartFTP Client\\SmartFTP.exe:*:Enabled:SmartFTP Client 2.5"&lt;br&gt;"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"&lt;br&gt;"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"&lt;br&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"&lt;br&gt;"C:\\Program Files\\Kontiki\\KService.exe"="C:\\Program Files\\Kontiki\\KService.exe:*:Enabled:Delivery Manager Service"&lt;br&gt;"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\Win32\\RpcDataSrv.exe"="C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\Win32\\RpcDataSrv.exe:*:Enabled:SiSoftware Database Agent Service"&lt;br&gt;"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\RpcSandraSrv.exe"="C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service"&lt;br&gt;"C:\\Program Files\\BIGSPEED Peer-to-Peer SDK\\bsP2pHubDemo.exe"="C:\\Program Files\\BIGSPEED Peer-to-Peer SDK\\bsP2pHubDemo.exe:*:Enabled:bsP2pHubDemo"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]&lt;br&gt;"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"&lt;br&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"&lt;br&gt;&lt;br&gt;[b]Remaining Files [/b]:&lt;br&gt;&lt;br&gt;&lt;br&gt;File Backups: - C:\SDFix\backups\backups.zip&lt;br&gt;&lt;br&gt;[b]Files with Hidden Attributes [/b]:&lt;br&gt;&lt;br&gt;Mon 28 Jan 2008     1,404,240 A.SHR --- "C:\Program Files\Spybot - Search &amp; Destroy\SDUpdate.exe"&lt;br&gt;Mon 28 Jan 2008     5,146,448 A.SHR --- "C:\Program Files\Spybot - Search &amp; Destroy\SpybotSD.exe"&lt;br&gt;Mon 28 Jan 2008     2,097,488 A.SHR --- "C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe"&lt;br&gt;Sun 16 Mar 2008         4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"&lt;br&gt;Sun 16 Mar 2008             0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"&lt;br&gt;Wed 12 Mar 2008       165,232 A..H. --- "C:\Documents and Settings\Poi\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll"&lt;br&gt;&lt;br&gt;[b]Finished![/b]&lt;br&gt;&lt;br&gt;--------------------------------------------------------------------------&lt;br&gt;&lt;br&gt;ComboFix 08-05-12.1 - Poi 2008-05-15 22:13:22.1 - NTFSx86&lt;br&gt;Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.233 [GMT 1:00]&lt;br&gt;Running from: C:\Documents and Settings\Poi\Desktop\ComboFix.exe&lt;br&gt; * Created a new restore point&lt;br&gt;&lt;br&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;br&gt;.&lt;br&gt;&lt;br&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;&lt;br&gt;C:\WINDOWS\system32\Desktop_.ini&lt;br&gt;C:\WINDOWS\system32\drivers\npf.sys&lt;br&gt;C:\WINDOWS\system32\packet.dll&lt;br&gt;C:\WINDOWS\system32\pskill.exe&lt;br&gt;C:\WINDOWS\system32\pthreadVC.dll&lt;br&gt;C:\WINDOWS\system32\wanpacket.dll&lt;br&gt;C:\WINDOWS\system32\wpcap.dll&lt;br&gt;&lt;br&gt;.&lt;br&gt;(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;&lt;br&gt;-------\Legacy_MSDIRECT&lt;br&gt;-------\Legacy_NPF&lt;br&gt;-------\Service_NPF&lt;br&gt;&lt;br&gt;&lt;br&gt;(((((((((((((((((((((((((   Files Created from 2008-04-15 to 2008-05-15  )))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;&lt;br&gt;2008-05-15 21:49 . 2008-05-15 21:49&lt;DIR&gt;d--------C:\WINDOWS\ERUNT&lt;br&gt;2008-05-15 21:44 . 2008-05-15 22:05&lt;DIR&gt;d--------C:\SDFix&lt;br&gt;2008-05-15 11:38 . 2008-05-15 11:38&lt;DIR&gt;d--------C:\z_Drivers&lt;br&gt;2008-05-15 11:38 . 2008-05-15 14:43980--a------C:\[u]0[/u]xf9.exe&lt;br&gt;2008-05-09 08:05 . 2008-05-09 08:05&lt;DIR&gt;d--------C:\Documents and Settings\Poi\Application Data\Talkback&lt;br&gt;2008-05-02 18:25 . 2008-05-02 18:25&lt;DIR&gt;d--------C:\Program Files\Rockstar Games&lt;br&gt;2008-04-28 22:23 . 2008-04-28 22:23&lt;DIR&gt;d--------C:\Program Files\Hotspot Shield&lt;br&gt;2008-04-26 22:02 . 2008-04-26 22:04&lt;DIR&gt;d--------C:\Documents and Settings\Poi\Application Data\Dimdim&lt;br&gt;2008-04-26 22:02 . 2005-11-27 19:2531,896--a------C:\WINDOWS\system32\drivers\dfmirage.sys&lt;br&gt;2008-04-26 22:02 . 2005-11-27 19:2530,360--a------C:\WINDOWS\system32\dfmirage.dll&lt;br&gt;2008-04-25 14:12 . 2004-08-30 14:25438,272--a------C:\WINDOWS\system32\vp6vfw.dll&lt;br&gt;2008-04-25 14:12 . 2004-12-10 10:06327,680--a------C:\WINDOWS\system32\vp6dec.ax&lt;br&gt;2008-04-25 14:12 . 2007-04-12 15:01118,832--a------C:\WINDOWS\system32\SHW32.DLL&lt;br&gt;2008-04-23 12:17 . 2008-04-23 13:06&lt;DIR&gt;d--------C:\Program Files\PeerGuardian2&lt;br&gt;2008-04-22 10:31 . 2008-04-22 10:31&lt;DIR&gt;dr-h-----C:\Documents and Settings\Poi\Application Data\SecuROM&lt;br&gt;2008-04-22 06:17 . 2008-04-22 08:42&lt;DIR&gt;d--------C:\Program Files\Desktop Activity Recorder&lt;br&gt;2008-04-20 12:51 . 2008-04-20 12:51&lt;DIR&gt;d--------C:\Program Files\OpenAL&lt;br&gt;2008-04-20 12:51 . 2008-04-20 12:51409,600--a------C:\WINDOWS\system32\wrap_oal.dll&lt;br&gt;2008-04-20 12:51 . 2008-04-20 12:51114,688--a------C:\WINDOWS\system32\OpenAL32.dll&lt;br&gt;2008-04-20 12:47 . 2008-04-20 12:47&lt;DIR&gt;d--------C:\Program Files\Paradox Interactive&lt;br&gt;2008-04-19 00:30 . 2008-04-19 00:30&lt;DIR&gt;d--------C:\Program Files\Network Stumbler&lt;br&gt;2008-04-18 20:04 . 2008-04-18 20:03737,280--a------C:\WINDOWS\iun6002.exe&lt;br&gt;2008-04-18 13:21 . 2008-04-18 13:21&lt;DIR&gt;d--------C:\Documents and Settings\All Users\Application Data\Default&lt;br&gt;2008-04-17 16:43 . 2008-04-17 16:43107,888--a------C:\WINDOWS\system32\CmdLineExt.dll&lt;br&gt;2008-04-17 08:42 . 2008-04-17 08:42&lt;DIR&gt;d--------C:\Program Files\BIGSPEED Peer-to-Peer SDK&lt;br&gt;&lt;br&gt;.&lt;br&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;2008-05-15 20:2014----a-wC:\Documents and Settings\Poi\getfile.dat&lt;br&gt;2008-05-15 18:47---------d-----wC:\Documents and Settings\Poi\Application Data\OpenOffice.org2&lt;br&gt;2008-05-15 17:08---------d-----wC:\Documents and Settings\All Users\Application Data\Spybot - Search &amp; Destroy&lt;br&gt;2008-05-15 16:28---------d-----wC:\Program Files\BOINC&lt;br&gt;2008-05-14 10:54---------d-----wC:\Documents and Settings\All Users\Application Data\Kontiki&lt;br&gt;2008-05-08 14:33---------d--h--wC:\Program Files\InstallShield Installation Information&lt;br&gt;2008-04-25 13:06---------d-----wC:\Program Files\EA Sports&lt;br&gt;2008-04-25 12:56---------d-----wC:\Program Files\Common Files\LogiShrd&lt;br&gt;2008-04-25 12:38---------d-----wC:\Documents and Settings\All Users\Application Data\Logishrd&lt;br&gt;2008-04-18 19:16---------d-----wC:\Program Files\Atheros&lt;br&gt;2008-04-17 13:40---------d-----wC:\Documents and Settings\Poi\Application Data\Hamachi&lt;br&gt;2008-04-13 18:51---------d-----wC:\Program Files\New Star Soccer 3&lt;br&gt;2008-04-11 00:44---------d-----wC:\Program Files\Project64 1.6&lt;br&gt;2008-04-10 13:19---------d-----wC:\Program Files\1964&lt;br&gt;2008-04-10 12:18---------d-----wC:\Program Files\mupen64 0.5&lt;br&gt;2008-04-09 20:07---------d-----wC:\Program Files\mupen64 0.4&lt;br&gt;2008-04-05 14:35---------d-----wC:\Program Files\Microsoft Silverlight&lt;br&gt;2008-03-28 12:13---------d-----wC:\Program Files\Safari&lt;br&gt;2008-03-28 12:13---------d-----wC:\Documents and Settings\Poi\Application Data\Apple Computer&lt;br&gt;2008-03-28 12:12---------d-----wC:\Program Files\Apple Software Update&lt;br&gt;2008-03-28 12:12---------d-----wC:\Documents and Settings\All Users\Application Data\Apple&lt;br&gt;2008-03-24 23:03---------d-----wC:\Documents and Settings\Poi\Application Data\Vso&lt;br&gt;2008-03-22 22:27---------d-----wC:\Program Files\VSO&lt;br&gt;2008-03-19 15:37---------d-----wC:\Documents and Settings\All Users\Application Data\Logitech&lt;br&gt;2008-03-19 15:07---------d-----wC:\Program Files\SiSoftware&lt;br&gt;2008-03-19 15:00---------d-----wC:\Program Files\Belarc&lt;br&gt;2008-03-18 17:32---------d--h--wC:\Documents and Settings\All Users\Application Data\{3DABBC31-9BB8-45D8-BE78-353E801E5DBA}&lt;br&gt;2008-03-18 17:32---------d-----wC:\Program Files\GGPO Client&lt;br&gt;2008-03-17 18:11---------d-----wC:\Program Files\mosaic&lt;br&gt;2008-03-16 21:05---------d-----wC:\Program Files\Windows Media Connect 2&lt;br&gt;2008-03-16 20:54---------d-----wC:\Program Files\Kontiki&lt;br&gt;2008-03-16 20:54---------d-----wC:\Program Files\Channel4&lt;br&gt;2008-03-16 20:54---------d-----wC:\Documents and Settings\All Users\Application Data\Channel4&lt;br&gt;2008-03-06 18:20691,545----a-wC:\WINDOWS\unins000.exe&lt;br&gt;2008-03-04 13:00811,776----a-wC:\WINDOWS\boinc.scr&lt;br&gt;.&lt;br&gt;&lt;br&gt;------- Sigcheck -------&lt;br&gt;&lt;br&gt;2007-12-21 00:32  359040  a14fafd66adbd55a86f17a37e5ec4263C:\WINDOWS\system32\drivers\tcpip.sys&lt;br&gt;.&lt;br&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;br&gt;.&lt;br&gt;.&lt;br&gt;*Note* empty entries &amp; legit default entries are not shown &lt;br&gt;REGEDIT4&lt;br&gt;&lt;br&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"SODCPreLoad"="C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.0.1.20080130-2132\preload.exe" [2008-02-26 10:13 40960]&lt;br&gt;"DriverLoad"="" []&lt;br&gt;"DriverCheck"="" []&lt;br&gt;"SystemDriverLoad"="" []&lt;br&gt;"alpha"="c:\z_Drivers\svchost.exe" [2008-05-15 11:38 198144]&lt;br&gt;"beta"="c:\z_Drivers\svchost.exe" [2008-05-15 11:38 198144]&lt;br&gt;"gamma"="c:\z_Drivers\svchost.exe" [2008-05-15 11:38 198144]&lt;br&gt;"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]&lt;br&gt;"SystemDriver"="" []&lt;br&gt;"FDriver"="" []&lt;br&gt;"ADriver"="" []&lt;br&gt;"CDriver"="c:\z_Drivers\svchost.exe" [2008-05-15 11:38 198144]&lt;br&gt;"DDriver"="c:\z_Drivers\svchost.exe" [2008-05-15 11:38 198144]&lt;br&gt;&lt;br&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56 15360]&lt;br&gt;&lt;br&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]&lt;br&gt;"nltide_3"="advpack.dll" [2007-12-07 03:21 124928 C:\WINDOWS\system32\advpack.dll]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]&lt;br&gt;"CDriver"= c:\z_Drivers\svchost.exe&lt;br&gt;"DDriver"= c:\z_Drivers\svchost.exe&lt;br&gt;"alpha"= c:\z_Drivers\svchost.exe&lt;br&gt;"beta"= c:\z_Drivers\svchost.exe&lt;br&gt;"gamma"= c:\z_Drivers\svchost.exe&lt;br&gt;&lt;br&gt;[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Launchy.lnk]&lt;br&gt;path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launchy.lnk&lt;br&gt;backup=C:\WINDOWS\pss\Launchy.lnkCommon Startup&lt;br&gt;&lt;br&gt;[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]&lt;br&gt;path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk&lt;br&gt;backup=C:\WINDOWS\pss\Ralink Wireless Utility.lnkCommon Startup&lt;br&gt;&lt;br&gt;[HKLM\~\startupfolder\C:^Documents and Settings^Poi^Start Menu^Programs^Startup^GameSpot Download Manager.lnk]&lt;br&gt;path=C:\Documents and Settings\Poi\Start Menu\Programs\Startup\GameSpot Download Manager.lnk&lt;br&gt;backup=C:\WINDOWS\pss\GameSpot Download Manager.lnkStartup&lt;br&gt;&lt;br&gt;[HKLM\~\startupfolder\C:^DOCUME~1^Poi^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]&lt;br&gt;path=C:\DOCUME~1\Poi\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk&lt;br&gt;backup=C:\WINDOWS\pss\OpenOffice.org 2.3.lnkStartup&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD]&lt;br&gt;--a------ 2007-04-23 12:23 1032640 C:\Program Files\Kontiki\KHost.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADriver]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]&lt;br&gt;--a------ 2005-12-13 22:50 88204 C:\WINDOWS\AGRSMMSG.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]&lt;br&gt;--a------ 2006-07-19 10:41 69632 C:\WINDOWS\Alcmtr.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\alpha]&lt;br&gt;--a------ 2008-05-15 11:38 198144 c:\z_Drivers\svchost.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]&lt;br&gt;--------- 2006-07-19 10:41 53248 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDMCon]&lt;br&gt;--a------ 2005-06-20 13:10 421888 c:\PROGRA~1\softwin\BITDEF~1\bdmcon.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDNewsAgent]&lt;br&gt;--a------ 2005-05-09 13:19 8192 c:\progra~1\softwin\bitdef~1\bdnagent.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\beta]&lt;br&gt;--a------ 2008-05-15 11:38 198144 c:\z_Drivers\svchost.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CDriver]&lt;br&gt;--a------ 2008-05-15 11:38 198144 c:\z_Drivers\svchost.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]&lt;br&gt;--a------ 2004-08-03 23:56 15360 C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]&lt;br&gt;--a------ 2008-02-14 00:09 486856 C:\Program Files\DAEMON Tools Lite\daemon.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDriver]&lt;br&gt;--a------ 2008-05-15 11:38 198144 c:\z_Drivers\svchost.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverCheck]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverLoad]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FDriver]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gamma]&lt;br&gt;--a------ 2008-05-15 11:38 198144 c:\z_Drivers\svchost.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]&lt;br&gt;--a------ 2008-02-15 12:46 159744 C:\WINDOWS\system32\hkcmd.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]&lt;br&gt;--a------ 2008-02-15 12:46 159744 C:\WINDOWS\system32\hkcmd.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]&lt;br&gt;--a------ 2008-02-15 12:46 131072 C:\WINDOWS\system32\igfxpers.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]&lt;br&gt;--a------ 2008-02-15 12:46 135168 C:\WINDOWS\system32\igfxtray.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]&lt;br&gt;--a------ 2007-04-23 12:23 1032640 C:\Program Files\Kontiki\KHost.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]&lt;br&gt;C:\Program Files\Logitech\QuickCam\Quickcam.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]&lt;br&gt;--a------ 2008-02-15 12:46 131072 C:\WINDOWS\system32\igfxpers.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]&lt;br&gt;--a------ 2006-07-19 10:42 16248320 C:\WINDOWS\RTHDCPL.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]&lt;br&gt;--a------ 2006-07-19 10:42 2879488 C:\WINDOWS\SkyTel.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmcService]&lt;br&gt;--a------ 2004-10-15 20:40 2577632 C:\PROGRA~1\Sygate\SPF\smc.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]&lt;br&gt;-rahs---- 2008-01-28 12:43 2097488 C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]&lt;br&gt;--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemDriver]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemDriverLoad]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]&lt;br&gt;C:\Program Files\Veoh Networks\Veoh\VeohClient.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMware hqtray]&lt;br&gt;--a------ 2007-10-08 10:21 55856 C:\Program Files\VMware\VMware Player\hqtray.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]&lt;br&gt;"uvnc_service"=2 (0x2)&lt;br&gt;"LexBceS"=2 (0x2)&lt;br&gt;"VMware NAT Service"=2 (0x2)&lt;br&gt;"vmount2"=2 (0x2)&lt;br&gt;"VMnetDHCP"=2 (0x2)&lt;br&gt;"VMAuthdService"=2 (0x2)&lt;br&gt;"ufad-p2v"=2 (0x2)&lt;br&gt;"ThreadMaster"=2 (0x2)&lt;br&gt;"rpcapd"=3 (0x3)&lt;br&gt;"WMPNetworkSvc"=3 (0x3)&lt;br&gt;"LVCOMSer"=2 (0x2)&lt;br&gt;"LVPrcSrv"=2 (0x2)&lt;br&gt;"LVSrvLauncher"=2 (0x2)&lt;br&gt;"SandraTheSrv"=3 (0x3)&lt;br&gt;"SandraDataSrv"=3 (0x3)&lt;br&gt;"pr2aqvlb"=2 (0x2)&lt;br&gt;"HotspotShieldService"=2 (0x2)&lt;br&gt;"dnlsvc"=2 (0x2)&lt;br&gt;"KService"=2 (0x2)&lt;br&gt;"XCOMM"=2 (0x2)&lt;br&gt;"SmcService"=2 (0x2)&lt;br&gt;"bdss"=2 (0x2)&lt;br&gt;&lt;br&gt;[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]&lt;br&gt;"SODCPreLoad"=C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.0.1.20080130-2132\preload.exe C:\PROGRA~1\IBM\Lotus\Symphony\data\.sodc\&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]&lt;br&gt;"EnableFirewall"= 0 (0x0)&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;br&gt;"%windir%\\system32\\sessmgr.exe"=&lt;br&gt;"C:\\Program Files\\UltraVNC\\vncviewer.exe"=&lt;br&gt;"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=&lt;br&gt;"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=&lt;br&gt;"C:\\Program Files\\Messenger\\msmsgs.exe"=&lt;br&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"=&lt;br&gt;"C:\\Program Files\\Kontiki\\KService.exe"=&lt;br&gt;"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\Win32\\RpcDataSrv.exe"=&lt;br&gt;"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\RpcSandraSrv.exe"=&lt;br&gt;"C:\\Program Files\\BIGSPEED Peer-to-Peer SDK\\bsP2pHubDemo.exe"=&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]&lt;br&gt;"5900:TCP"= 5900:TCP:vnc5900&lt;br&gt;"5800:TCP"= 5800:TCP:vnc5800&lt;br&gt;&lt;br&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]&lt;br&gt;"AllowInboundEchoRequest"= 1 (0x1)&lt;br&gt;&lt;br&gt;R0 pe3aqvlb;XIII Century Environment Driver (pe3aqvlb);C:\WINDOWS\system32\drivers\pe3aqvlb.sys [2008-03-14 15:22]&lt;br&gt;R0 ps7aqvlb;XIII Century Synchronization Driver (ps7aqvlb);C:\WINDOWS\system32\drivers\ps7aqvlb.sys [2008-03-14 15:21]&lt;br&gt;R2 vstor2-p2v30;Vstor2 P2V30 Virtual Storage Driver;C:\Program Files\VMware\VMware Converter\vstor2-p2v30.sys [2007-01-30 20:41]&lt;br&gt;R3 dfmirage;dfmirage;C:\WINDOWS\system32\DRIVERS\dfmirage.sys [2005-11-27 19:25]&lt;br&gt;R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2008-01-23 22:25]&lt;br&gt;S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\NSNDIS5.SYS [2004-03-24 03:12]&lt;br&gt;S3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys []&lt;br&gt;S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 00:01]&lt;br&gt;S4 pr2aqvlb;XIII Century Drivers Auto Removal (pr2aqvlb);C:\WINDOWS\system32\pr2aqvlb.exe svc []&lt;br&gt;S4 ThreadMaster;Thread Master;C:\WINDOWS\system32\ThreadMaster\ThreadMast.exe [2003-03-18 00:27]&lt;br&gt;S4 ufad-p2v;VMware Converter Service;"C:\Program Files\VMware\VMware Converter\vmware-ufad.exe" -d "C:\Program Files\VMware\VMware Converter\\" -s ufad-p2v.xml []&lt;br&gt;S4 uvnc_service;uvnc_service;"C:\Program Files\UltraVNC\WinVNC.exe" -service []&lt;br&gt;&lt;br&gt;.&lt;br&gt;**************************************************************************&lt;br&gt;&lt;br&gt;catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net&lt;br&gt;Rootkit scan 2008-05-15 22:17:50&lt;br&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;br&gt;&lt;br&gt;scanning hidden processes ... &lt;br&gt;&lt;br&gt;scanning hidden autostart entries ...&lt;br&gt;&lt;br&gt;scanning hidden files ... &lt;br&gt;&lt;br&gt;scan completed successfully&lt;br&gt;hidden files: 0&lt;br&gt;&lt;br&gt;**************************************************************************&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OMSCAN]&lt;br&gt;"ImagePath"="\Sys"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]&lt;br&gt;"ImagePath"=""&lt;br&gt;.&lt;br&gt;------------------------ Other Running Processes ------------------------&lt;br&gt;.&lt;br&gt;C:\WINDOWS\system32\wscntfy.exe&lt;br&gt;C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.0.1.20080130-2132\soffice.exe&lt;br&gt;.&lt;br&gt;**************************************************************************&lt;br&gt;.&lt;br&gt;Completion time: 2008-05-15 22:20:25 - machine was rebooted&lt;br&gt;ComboFix-quarantined-files.txt  2008-05-15 21:20:21&lt;br&gt;&lt;br&gt;Pre-Run: 7,616,372,736 bytes free&lt;br&gt;Post-Run: 7,835,357,184 bytes free&lt;br&gt;&lt;br&gt;277&lt;br&gt;-----------------------------------------------------------------------------------&lt;br&gt;&lt;br&gt;In future please warn people to remove any headphones when using ComboFix, the two high pitch beeps at the start; are very unpleasant.</description><pubDate>Thu, 15 May 2008 16:37:37 GMT</pubDate><dc:creator>Err</dc:creator></item><item><title>RE: Definately infectaed, but what ?</title><link>http://tweaks.com/forum/Topic239501-29-1.aspx</link><description>Welcome:)&lt;br&gt;&lt;br&gt;[b]Please disable Spybot S&amp;D’s protection,or it will interfere.&lt;br&gt;You can enable it after you're clean.[/b]&lt;br&gt;Open Spybot and click on 'Mode' and check 'Advanced Mode'.&lt;br&gt;Click on 'Tools' in bottom left hand corner.&lt;br&gt;Click on the 'System Startup' icon.&lt;br&gt;Uncheck 'Teatimer' box and/or uncheck 'Resident'.&lt;br&gt;Click the 'Allow Change' box.&lt;br&gt;Then, check next to the computer clock to see if the icon for Spybot is still there.&lt;br&gt;If it is, right click it and choose 'exit Spybot-S&amp;D Resident'.&lt;br&gt;[b]Restart the computer.[/b]&lt;br&gt;If you find you're experiencing problems disabling Spybot's Tea-Timer,follow the info in the link below:&lt;br&gt;[url]http://www.russelltexas.com/malware/teatimer.htm[/url]&lt;br&gt;&lt;br&gt;&lt;br&gt;Download [b]SDFix.exe[/b] and save it to your desktop:&lt;br&gt;[url]http://downloads.andymanchesta.com/RemovalTools/SDFix.exe[/url]&lt;br&gt;&lt;br&gt;* Double click on SDFix on your desktop,and install the fix to [b]C:\[/b]&lt;br&gt;&lt;br&gt;* [COLOR="blue"][i]You might want to print/copy the following as you need to be in Safe Mode from here on.[/i][/color] &lt;br&gt;&lt;br&gt;* Please then reboot your computer into Safe Mode by doing the following:&lt;br&gt;* Restart your computer&lt;br&gt;* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;&lt;br&gt;* Instead of Windows loading as normal, a menu with options should appear;&lt;br&gt;* Select the first option, to run Windows in Safe Mode, then press "Enter".&lt;br&gt;* Choose your usual account.&lt;br&gt;&lt;br&gt;* In Safe Mode,go to and open the C:\[b]SDFix[/b] folder,then double click on [b]RunThis.bat[/b] to start the script.&lt;br&gt;* Type [b]Y[/b] to begin the script.&lt;br&gt;* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.&lt;br&gt;* Press any Key and it will restart the PC.&lt;br&gt;* Your system will take longer that normal to restart as the fixtool will be running and removing files.&lt;br&gt;* When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.&lt;br&gt;[b]* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt into your next reply.[/b]&lt;br&gt;&lt;br&gt;&lt;br&gt;Download [b][url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color="blue"]Combofix[/color][/url][/b] by [b]sUBs[/b] and save to your desktop.&lt;br&gt;Alternative Combofix download link [b][url=http://subs.geekstogo.com/ComboFix.exe][color="blue"]HERE[/color][/url][/b].&lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;It is important that it is saved directly to your desktop[/color]&lt;br&gt;&lt;br&gt;Now close any open browsers.&lt;br&gt;Double click on Combofix.exe and follow the prompts. &lt;br&gt;When it's finished it will produce a log. &lt;br&gt;[b]Post the entire contents of C:\ComboFix.txt into your next reply[/b]. &lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;Do not mouseclick combofix's window or do anything else on your pc while it's running. &lt;br&gt;That may cause the program/system to freeze/hang. [/color]&lt;br&gt;Do NOT post the ComboFix-quarantined-files.txt unless I ask.&lt;br&gt;[b][color="RED"][U]Note[/U][/color][/b]&lt;br&gt;In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.&lt;br&gt;Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log please.[/b]</description><pubDate>Thu, 15 May 2008 15:24:40 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>Definately infectaed, but what ?</title><link>http://tweaks.com/forum/Topic239501-29-1.aspx</link><description>XP PRO SP2&lt;br&gt;&lt;br&gt;I am using Sygate Personal Firewall 5.6 build 2808&lt;br&gt;I have Spybot - Search &amp; Destroy version 1.5.2.0&lt;br&gt;&lt;br&gt;Sygate Personal Firewall reports; Application Hijacking, Severity=Critical, Remote Host=77.232.91.127, The full path of &lt;br&gt;Spybot is listed.&lt;br&gt;Sygate displays Spybot as Application Hijacking for several minutes anywhere from 5 to 20 minutes, so far.&lt;br&gt;Sygate eventually list the Security Type for each previous Spybot entry as "Port Scan" and changes the Severity to Minor &lt;br&gt;and changes the Remote Host to 194.168.8.100&lt;br&gt;&lt;br&gt;In the past 60 minutes (while connected to the internet) Windows Media Player 11 has automatically launched 4 times.  &lt;br&gt;The first time WMP launched; I did not see the video, the second time; it played a pornographic video, the third time; &lt;br&gt;a blank 3 second video, the fourth time; a pornographic video. I disabled my network adapter and Windows media player &lt;br&gt;has not launched since.&lt;br&gt;&lt;br&gt;I have done a scan using Spybot Search and Destroy; it found nothing.&lt;br&gt;Task Manager, CPU Usage is fluctuating between 5% to 100%, the graph displays drastic peaks and troughs, at present I have &lt;br&gt;Firefox, Bitdefender, Spybot Search and Destroy and Sygate Personal Firewall running.  These applications when running &lt;br&gt;at the same time; usually do not consume more than 15% usage.&lt;br&gt;&lt;br&gt;Checked MSCONFIG - there are 5 entries for svchost, all enabled.&lt;br&gt;   there are 6 entries enabled but Startup item column is blank, the "location" for the blank items is &lt;br&gt;HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br&gt;&lt;br&gt;I am able to use all my usually applications with only one noticeable interruptions except whatever application I am &lt;br&gt;using; within a few seconds - the title bar will go grey and the application becomes inactive however no other &lt;br&gt;application launches.  Since I have disabled my network adapter; this has not happened.&lt;br&gt;&lt;br&gt;Another peculiarity - a dialogue bx appeared while I was connected to the net, it had not reference to any application &lt;br&gt;or website but it was clearly spyware because it display some text claiming that my computer is infected, which is true &lt;br&gt;because it's no doubt that vendor of that alert - has infected my PC.  I did not click on, I used Alt+Tab but it was not &lt;br&gt;listed, it disappeared without any action from me.&lt;br&gt;&lt;br&gt;About 45 minutes previous to all these things; my computer would play an alert similar to when you when you instruct a &lt;br&gt;computer to perform an action but it returns a message saying that action is not possible.  No dialogue box appear on &lt;br&gt;screen to accompany this alert.&lt;br&gt;&lt;br&gt;I have not recently installed any new software apart from a FireFox addon "BlockSite 0.7" however this was 2 days ago.&lt;br&gt;I have not installed any other browser plugins.&lt;br&gt;&lt;br&gt;I just enabled my network adapter and the CPU usage is even more sporadic and Firefox is hanging but not severely.&lt;br&gt;&lt;br&gt;I've used the ADS Spy tool in HijackThis but it found nothing.&lt;br&gt;Here is the result of HijackThis&lt;br&gt;&lt;br&gt;Logfile of HijackThis v1.99.1&lt;br&gt;Scan saved at 21:00:58, on 15/05/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16608)&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\Sygate\SPF\smc.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\progra~1\softwin\bitdef~1\bdnagent.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe&lt;br&gt;C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe&lt;br&gt;C:\WINDOWS\system32\wscntfy.exe&lt;br&gt;C:\WINDOWS\system32\taskmgr.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe&lt;br&gt;c:\progra~1\softwin\bitdef~1\bdmcon.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;F:\SFW\SECURE\HijackThis.exe&lt;br&gt;C:\Program Files\OpenOffice.org 2.3\program\soffice.exe&lt;br&gt;C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\WINDOWS\system32\notepad.exe&lt;br&gt;C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe&lt;br&gt;C:\WINDOWS\system32\NOTEPAD.EXE&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;C:\z_Drivers\svchost.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://techwhims.blogspot.com/&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui&lt;br&gt;O4 - HKLM\..\Run: [BDNewsAgent] "c:\progra~1\softwin\bitdef~1\bdnagent.exe"&lt;br&gt;O4 - HKLM\..\Run: [BDMCon] c:\PROGRA~1\softwin\BITDEF~1\bdmcon.exe&lt;br&gt;O4 - HKCU\..\Run: [SODCPreLoad] C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.0.1.20080130-2132\preload.exe C:\PROGRA~1\IBM\Lotus\Symphony\data\.sodc\&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe&lt;br&gt;O4 - HKCU\..\Run: [CDriver] c:\z_Drivers\svchost.exe&lt;br&gt;O4 - HKCU\..\Run: [DDriver] c:\z_Drivers\svchost.exe&lt;br&gt;O4 - HKCU\..\Run: [alpha] c:\z_Drivers\svchost.exe&lt;br&gt;O4 - HKCU\..\Run: [beta] c:\z_Drivers\svchost.exe&lt;br&gt;O4 - HKCU\..\Run: [gamma] c:\z_Drivers\svchost.exe&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)&lt;br&gt;O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O11 - Options group: [INTERNATIONAL] International*&lt;br&gt;O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll&lt;br&gt;O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll&lt;br&gt;O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)&lt;br&gt;O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe&lt;br&gt;O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)</description><pubDate>Thu, 15 May 2008 15:13:22 GMT</pubDate><dc:creator>Err</dc:creator></item></channel></rss>