Help - Search - Members - Calendar
Full Version: Browser has been hijacked by vmn.net
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive HijackThis Logs
jotrys
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:29:47 PM, on 6/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\ssoftsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\pdfforge Toolbar\SearchSettings.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\Program Files\Creative\Software Update 3\SoftAuto.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Documents and Settings\hp3pl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\GUI.exe
C:\Program Files\Notepad++\notepad++.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\ping.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - HKCU\..\Run: [SoftAuto.exe] "C:\Program Files\Creative\Software Update 3\SoftAuto.exe"
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\hp3pl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~1\VideoGet\Plugins\VIDEOG~1.DLL
O9 - Extra 'Tools' menuitem: Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~1\VideoGet\Plugins\VIDEOG~1.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - ftp://ftp.giskit.com/pub/mapguide/mgaxctrl.cab
O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - https://gto.postbank.nl/GTO/PBGNX.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...795/mcfscan.cab
O18 - Protocol: schmap-help - {2CF664A0-5EA6-47B5-884C-433A60145F78} - C:\Program Files\Schmap\Schmap Player\SchmapDocLib.dll
O22 - SharedTaskScheduler: Fences - {EC654325-1273-C2A9-2B7C-45A29BCE2FBD} - C:\Program Files\Stardock\Fences\DesktopDock.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: Insight Web Agent (cpqWebDmi) - Hewlett-Packard Company - C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: Creative Centrale Media Server (CTUPnPSv) - Creative Technology Ltd - C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Cryptainer service (ssoftservice) - Cypherix - C:\WINDOWS\SYSTEM32\ssoftsrv.exe
O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe

--
End of file - 8831 bytes
Blade81
Hi jotrys,

Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt
  • Save both reports to your desktop. Post them back to your topic.
  • jotrys
    Hi there blade81,

    As requested, I ran the script. The two files follow here.

    DDS.txt:


    DDS (Ver_09-05-14.01) - NTFSx86
    Run by HP3PL at 18:12:20.74 on Thu 06/04/2009
    Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_03
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1205 [GMT 2:00]


    ============== Running Processes ===============

    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
    C:\Program Files\Creative\Shared Files\CTDevSrv.exe
    C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\ssoftsrv.exe
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
    C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\pdfforge Toolbar\SearchSettings.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot\TeaTimer.exe
    C:\Program Files\Creative\Software Update 3\SoftAuto.exe
    C:\Program Files\Rainlendar2\Rainlendar2.exe
    C:\Documents and Settings\hp3pl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
    C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
    C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
    C:\Program Files\Linksys\Wireless-G Notebook Adapter\GUI.exe
    C:\Program Files\Notepad++\notepad++.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\ping.exe
    C:\Documents and Settings\hp3pl\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uSearch Bar =
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uInternet Settings,ProxyOverride = <local>
    mSearchAssistant =
    uURLSearchHooks: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\program files\pdfforge toolbar\SearchSettings.dll
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat

    7.0\activex\AcroIEHelper.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot\SDHelper.dll
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
    BHO: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\WidgiToolbarIE.dll
    BHO: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\program files\pdfforge toolbar\SearchSettings.dll
    TB: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\WidgiToolbarIE.dll
    TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [SpybotSD TeaTimer] c:\program files\spybot\TeaTimer.exe
    uRun: [SoftAuto.exe] "c:\program files\creative\software update 3\SoftAuto.exe"
    uRun: [Rainlendar2] c:\program files\rainlendar2\Rainlendar2.exe
    uRun: [Google Update] "c:\documents and settings\hp3pl\local settings\application data\google\update\GoogleUpdate.exe" /c
    uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\RegistryBooster.exe /S
    mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
    mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [AGRSMMSG] AGRSMMSG.exe
    mRun: [ChkAdmin] c:\progra~1\compaq\compaq~1\CHKADMIN.EXE
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
    mRun: [SearchSettings] c:\program files\pdfforge toolbar\SearchSettings.exe
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
    dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
    dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common

    files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\program files\linksys\wireless-g notebook

    adapter\Gcc.exe
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
    IE: {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - {17A84966-F1E9-4645-AA9E-5E771EE1C859} -

    c:\progra~1\videoget\plugins\VIDEOG~1.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot\SDHelper.dll
    DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} - hxxps://www.p3.postbank.nl/sesam/CAX.cab
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
    DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
    DPF: {62789780-B744-11D0-986B-00609731A21D} - ftp://ftp.giskit.com/pub/mapguide/mgaxctrl.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -

    hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} - hxxps://gto.postbank.nl/GTO/PBGNX.cab
    DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4795/mcfscan.cab
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
    Handler: schmap-help - {2CF664A0-5EA6-47B5-884C-433A60145F78} - c:\program files\schmap\schmap player\schmapdoclib.dll
    Notify: AtiExtEvent - Ati2evxx.dll
    Notify: NavLogon - c:\windows\system32\NavLogon.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    STS: Fences: {ec654325-1273-c2a9-2b7c-45a29bce2fbd} - c:\program files\stardock\fences\DesktopDock.dll
    SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\hp3pl\applic~1\mozilla\firefox\profiles\n3dc9n2k.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage -

    hxxp://www.google.com/|http://reddit.com/|https://login.yahoo.com/config/mail?.intl=us
    FF - component: c:\program files\mozilla

    firefox\extensions\{b922d405-6d13-4a2b-ae89-08a030da4402}\components\pdfforgeToolbarFF.dll
    FF - component: c:\program files\mozilla firefox\extensions\search@searchsettings.com\components\SearchSettingsFF.dll
    FF - plugin: c:\documents and settings\hp3pl\local settings\application data\google\update\1.2.145.5\npGoogleOneClick8.dll

    ============= SERVICES / DRIVERS ===============

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-3 64160]
    R1 ClntMgmt;HP Client Management Driver;c:\windows\system32\drivers\Clntmgmt.sys [2005-6-3 55336]
    R2 cpqWebDmi;Insight Web Agent;c:\progra~1\compaq\compaq~1\cpqweb~1\WebDmi.exe [2005-6-3 24576]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1005904]
    R2 ssoftnt4;ssoftnt4;c:\windows\system32\drivers\ssoftnt4.sys [2006-12-3 114944]
    R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
    R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [2004-4-16 182101]
    R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [2004-4-16 5689]
    R3 WPC54Gv3;Linksys Wireless Notebook Adapter WPC54Gv3 Driver;c:\windows\system32\drivers\WPC54Gv3.SYS [2006-11-30 610816]
    S2 RIOUSB;RioPort.Com Rio500 USB Driver;c:\windows\system32\drivers\RioUsb.sys [2007-4-16 15152]
    S3 Am772;AMD Alchemy™ Solutions Wireless 802.11 Adapter;c:\windows\system32\drivers\Am772.sys [2006-7-26 174278]
    S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [2005-6-3 17408]
    S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\creative\creative centrale\CTUPnPSv.exe [2008-5-21 64000]
    S3 TIACXLN;22M WLAN Adapter;c:\windows\system32\drivers\tiacxln.sys --> c:\windows\system32\drivers\tiacxln.sys [?]
    S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;c:\windows\system32\drivers\ar5211.sys [2004-2-25

    322560]

    =============== Created Last 30 ================

    2009-06-04 11:56 <DIR> --d----- c:\docume~1\hp3pl\applic~1\Uniblue
    2009-06-03 21:28 <DIR> --d----- c:\program files\Trend Micro
    2009-06-03 21:21 15,688 a------- c:\windows\system32\lsdelete.exe
    2009-06-03 20:19 64,160 a------- c:\windows\system32\drivers\Lbd.sys
    2009-06-03 20:01 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
    2009-06-02 20:26 17,542 a------- c:\windows\SothinkTree.ico
    2009-06-02 20:26 <DIR> --d----- c:\program files\SourceTec
    2009-05-28 15:33 <DIR> --d----- c:\program files\AutoIt3
    2009-05-28 14:32 <DIR> --d----- c:\program files\AutoHotkey
    2009-05-13 20:11 <DIR> --d----- c:\program files\xampp
    2009-05-10 11:27 <DIR> --d----- c:\program files\MSXML 4.0
    2009-05-10 10:58 284,160 -------- c:\windows\system32\dllcache\pdh.dll
    2009-05-10 10:58 473,600 -------- c:\windows\system32\dllcache\fastprox.dll
    2009-05-10 10:58 401,408 -------- c:\windows\system32\dllcache\rpcss.dll
    2009-05-10 10:58 227,840 -------- c:\windows\system32\dllcache\wmiprvse.exe
    2009-05-10 10:58 110,592 -------- c:\windows\system32\dllcache\services.exe
    2009-05-10 10:58 729,088 -------- c:\windows\system32\dllcache\lsasrv.dll
    2009-05-10 10:58 617,472 -------- c:\windows\system32\dllcache\advapi32.dll
    2009-05-10 10:58 453,120 -------- c:\windows\system32\dllcache\wmiprvsd.dll
    2009-05-10 10:58 714,752 -------- c:\windows\system32\dllcache\ntdll.dll
    2009-05-10 10:56 2,560 -------- c:\windows\system32\xpsp4res.dll
    2009-05-10 10:56 1,203,922 -------- c:\windows\system32\dllcache\sysmain.sdb
    2009-05-10 10:56 215,552 -------- c:\windows\system32\dllcache\wordpad.exe
    2009-05-10 10:15 <DIR> --d----- c:\windows\system32\scripting
    2009-05-10 10:15 <DIR> --d----- c:\windows\l2schemas
    2009-05-10 10:15 <DIR> --d----- c:\windows\system32\en
    2009-05-10 03:03 276,992 -------- c:\windows\system32\wmphoto.dll
    2009-05-10 03:02 397,312 -------- c:\windows\system32\mmcex.dll
    2009-05-08 22:56 <DIR> --d----- c:\docume~1\hp3pl\applic~1\Search Settings
    2009-05-08 22:56 <DIR> --d----- c:\docume~1\hp3pl\applic~1\pdfforge
    2009-05-08 22:52 <DIR> --d----- c:\program files\AVG
    2009-05-08 13:13 <DIR> --d----- c:\program files\pdfforge Toolbar
    2009-05-08 13:11 137,000 a------- c:\windows\system32\MSMAPI32.OCX
    2009-05-08 13:11 116,224 a------- c:\windows\system32\pdfcmnnt.dll
    2009-05-08 13:11 23,552 a------- c:\windows\system32\MSMPIDE.DLL
    2009-05-08 13:11 <DIR> --d----- c:\program files\PDFCreator
    2009-05-07 19:59 <DIR> --d----- c:\program files\oDesk
    2009-05-05 21:36 <DIR> --d----- c:\program files\common files\SourceTec
    2009-05-05 21:36 82,432 a------- c:\windows\system32\msxml4r.dll
    2009-05-05 21:36 44,544 a------- c:\windows\system32\msxml4a.dll
    2009-05-05 21:36 <DIR> --d----- c:\program files\Sothink DHTML Menu 9

    ==================== Find3M ====================

    2009-05-26 09:40 87,944 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
    2009-03-21 16:06 989,696 -------- c:\windows\system32\dllcache\kernel32.dll
    2009-03-10 22:18 934,792 -------- c:\windows\system32\dllcache\WgaTray.exe
    2009-03-10 22:18 239,496 -------- c:\windows\system32\dllcache\wgaLogon.dll
    2008-07-15 22:58 21,336 a------- c:\docume~1\hp3pl\applic~1\GDIPFONTCACHEV1.DAT

    ============= FINISH: 18:13:13.44 ===============



    Attach.txt:


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-05-14.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 4/16/2004 12:44:30 AM
    System Uptime: 6/4/2009 1:54:52 PM (5 hours ago)

    Motherboard: Hewlett-Packard | | 0890
    Processor: Intel® Pentium® M processor 1400MHz | U10 | 1395/100mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 28 GiB total, 4.11 GiB free.
    D: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP1098: 5/15/2009 1:47:15 AM - Software Distribution Service 3.0
    RP1099: 5/16/2009 11:27:39 AM - Software Distribution Service 3.0
    RP1100: 5/17/2009 12:28:19 PM - System Checkpoint
    RP1101: 5/18/2009 8:40:05 PM - System Checkpoint
    RP1102: 5/19/2009 2:21:48 AM - Software Distribution Service 3.0
    RP1103: 5/20/2009 1:10:54 PM - System Checkpoint
    RP1104: 5/21/2009 1:51:33 PM - System Checkpoint
    RP1105: 5/22/2009 2:18:10 PM - Software Distribution Service 3.0
    RP1106: 5/23/2009 8:47:35 PM - System Checkpoint
    RP1107: 5/24/2009 9:39:34 PM - System Checkpoint
    RP1108: 5/26/2009 11:43:03 AM - System Checkpoint
    RP1109: 5/27/2009 12:34:12 PM - Software Distribution Service 3.0
    RP1110: 5/28/2009 3:41:30 PM - Revo Uninstaller's restore point - AutoIt v3.3.0.0
    RP1111: 5/29/2009 1:48:15 AM - Software Distribution Service 3.0
    RP1112: 5/30/2009 7:27:57 PM - System Checkpoint
    RP1113: 6/1/2009 1:00:08 PM - System Checkpoint
    RP1114: 6/2/2009 1:55:40 AM - Software Distribution Service 3.0
    RP1115: 6/3/2009 1:13:48 PM - System Checkpoint
    RP1116: 6/3/2009 7:20:40 PM - Automatic Restore Point

    ==== Installed Programs ======================

    7-Zip 4.42
    Ad-Aware
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Photoshop 6.0
    Adobe Reader 7.1.0
    Adobe SVG Viewer
    Agent Ransack Version 1.7.3
    Agere Systems AC'97 Modem
    Apple Software Update
    ArcSoft PhotoBase 3
    ArcSoft PhotoStudio 5
    ATI Control Panel
    ATI Display Driver
    AudibleManager
    AutoHotkey 1.0.48.03
    Belarc Advisor 7.2
    Broadcom Gigabit Integrated Controller
    Canon CanoScan Toolbox 4.1
    CanoScan LiDE20,30 Manual
    CCleaner (remove only)
    CDisplay 1.8
    Consumentenbond Belasting cd-rom 2008
    Cover Commander 2.91 by Insofta Development
    Creative Centrale
    Creative Removable Disk Manager
    Creative Software Update
    Creative ZEN Mozaic User's Guide
    Critical Update for Windows Media Player 11 (KB959772)
    Diagnostics for Windows
    Driver Magician 3.4
    eCover Engineer 5.5
    EetMeter2002 update 1.4
    ERUNT 1.1j
    Fences
    FileZilla Client 3.2.1
    Folder Marker Home v 3.0
    FrostWire 4.13.5
    Google Chrome
    Google Video Player
    HijackThis 2.0.2
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    HP Integrated Wireless LAN W400-W500 Driver
    HpSdpAppCoreApp
    Image Mender 1.1
    Insight Management Agent
    Internet Explorer Q903235
    InterVideo WinDVD
    Introduction to Visual Basic 2005
    IrfanView (remove only)
    iTunes
    J2SE Runtime Environment 5.0 Update 8
    Java 2 Runtime Environment, SE v1.4.2
    Java™ 6 Update 3
    MalWhere (remove only)
    Microsoft .NET Framework 2.0 Service Pack 1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office XP Professional with FrontPage
    Microsoft Project Standard 2002
    Microsoft SQL Server 2005
    Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
    Microsoft SQL Server 2005 Tools Express Edition
    Microsoft SQL Server Native Client
    Microsoft SQL Server Setup Support Files (English)
    Microsoft SQL Server VSS Writer
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visio Standard 2002 [English]
    Microsoft Visual Basic 2005 Express Edition - ENU
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Windows Vista Upgrade Advisor
    Mozilla Firefox (3.0.10)
    Mozilla Thunderbird (2.0.0.21)
    MP3 Converter V4.6.0
    MSN Music Assistant
    MSXML 4.0 SP2 (KB954430)
    MSXML 6 Service Pack 2 (KB954459)
    Multi-Card Reader & Flash Disk
    NetMeter 0.8.6.0
    Network Stumbler 0.4.0 (remove only)
    Notepad++
    O2Micro MemoryCardBus Windows Driver
    O2Micro SmartCardBus Reader Windows Driver Installer
    oDesk Extras 2.0.66
    oDesk MiniCam 2.0.72
    oDesk ScreenSnap 2.0.111
    oDesk Share 2.0.69
    oDesk Team 2.0.121
    Odyssey SDK
    OmniPage SE
    Paint.NET 3.8
    PC Wizard 2008.1.85.2
    PDFCreator
    pdfforge Toolbar v1.0
    QuickTime
    QuizCreator
    Rainlendar2 (remove only)
    RealPlayer
    Remote Diagnostics Enabling Agent
    Remote Services Driver
    Remove Hidden Data Tool
    Revo Uninstaller 1.80
    Schmap 2.0 Beta
    SciTE4AutoIt3 21-5-2009
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB961373)
    SIW version 2008-10-28
    Sothink DHTML Menu 9
    Sothink Tree Menu
    SoundMAX
    SourceGear DiffMerge
    Spybot - Search & Destroy
    Spybot - Search & Destroy 1.5.2.20
    Sumatra PDF reader
    Synaptics Pointing Device Driver
    SyncBack
    The Guide
    The Regex Coach 0.9.2
    TrueCrypt
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    VideoGet
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    VLC media player 0.9.6
    WebFldrs XP
    Windows Defender
    Windows Defender Signatures
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Grep 2.3
    Windows Internet Explorer 7
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Media Player 9 Hotfix [See KB885492 for more information]
    Windows XP Service Pack 3
    WinZip
    Wireless-G Notebook Adapter
    Wondershare Flash Slideshow Builder Giveaway Edition (4.6.0)
    XAMPP 1.7.1

    ==== Event Viewer Messages From Past Week ========

    6/1/2009 12:44:01 PM, error: SideBySide [61] - Syntax error in manifest or policy file

    "C:\Program Files\Apple Software Update\Plugins\MSIInstallPlugin.dll.Manifest" on line 2.

    The required attribute version is missing from element assemblyIdentity.
    6/1/2009 12:44:01 PM, error: SideBySide [59] - Generate Activation Context failed for

    C:\Program Files\Apple Software Update\Plugins\MSIInstallPlugin.dll.Manifest. Reference

    error message: The operation completed successfully. .
    6/1/2009 12:44:01 PM, error: SideBySide [58] - Syntax error in manifest or policy file

    "C:\Program Files\Apple Software Update\Plugins\MSIInstallPlugin.dll.Manifest" on line 2.
    6/1/2009 12:44:00 PM, error: SideBySide [61] - Syntax error in manifest or policy file

    "C:\Program Files\Apple Software Update\Plugins\EXEInstallPlugin.dll.Manifest" on line 2.

    The required attribute version is missing from element assemblyIdentity.
    6/1/2009 12:44:00 PM, error: SideBySide [59] - Generate Activation Context failed for

    C:\Program Files\Apple Software Update\Plugins\EXEInstallPlugin.dll.Manifest. Reference

    error message: The operation completed successfully. .
    6/1/2009 12:44:00 PM, error: SideBySide [58] - Syntax error in manifest or policy file

    "C:\Program Files\Apple Software Update\Plugins\EXEInstallPlugin.dll.Manifest" on line 2.
    6/1/2009 11:43:59 AM, error: Service Control Manager [7000] - The RioPort.Com Rio500 USB

    Driver service failed to start due to the following error: The service cannot be started,

    either because it is disabled or because it has no enabled devices associated with it.
    5/31/2009 7:45:50 PM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the

    Network Card with network address 0016B64A22C1 has been denied by the DHCP server

    192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    5/30/2009 5:44:19 PM, error: Dhcp [1002] - The IP address lease 192.168.1.101 for the

    Network Card with network address 0016B64A22C1 has been denied by the DHCP server

    192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    5/28/2009 11:33:48 AM, error: Print [19] - Sharing printer failed + 1722, Printer NLBLE003P

    share name Printer.

    ==== End Of File ===========================


    Blade81
    Hi again,

    There seems to be P2P file sharing software installed. Since infections are received a lot from P2P networks nowadays, I recommend to uninstall such software to lower a risk getting infected.

    Uninstall pdfforge Toolbar v1.0 thru add/remove programs.


    Please visit this webpage for download links, and instructions for running ComboFix tool:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    Please ensure you read this guide carefully and install the Recovery Console first.

    The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    Once installed, you should see a blue screen prompt that says:

    The Recovery Console was successfully installed.

    Please continue as follows:
    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
      Remember to re-enable them afterwards.

    2. Click Yes to allow ComboFix to continue scanning for malware.

    When the tool is finished, it will produce a report for you.

    Please include the following reports for further review, and so we may continue cleansing the system:

    C:\ComboFix.txt
    New dds.txt log.


    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
    jotrys
    Hello there Balde81,

    As requested I removed the pdfforge toolbar.
    Ran Combofix and here are the two log files:


    ComboFix.txt:


    ComboFix 09-06-04.06 - HP3PL 06/05/2009 10:48.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1578 [GMT 2:00]
    Running from: c:\documents and settings\hp3pl\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((( Files Created from 2009-05-05 to 2009-06-05 )))))))))))))))))))))))))))))))
    .

    2009-06-04 22:28 . 2008-12-01 11:47 4244744 ----a-w- c:\windows\system32\qtp-mt334.dll
    2009-06-04 22:28 . 2008-12-01 11:47 40368 ----a-w- c:\windows\system32\drivers\hotcore3.sys
    2009-06-04 22:28 . 2008-12-01 11:46 247560 ----a-w- c:\windows\system32\prgiso.dll
    2009-06-04 22:28 . 2008-12-01 11:47 13576 ----a-w- c:\windows\system32\wnaspi32.dll
    2009-06-04 22:27 . 2009-06-04 22:27 -------- d-----w- c:\program files\Paragon Software
    2009-06-04 09:56 . 2009-06-04 09:56 -------- d-----w- c:\documents and settings\hp3pl\Application Data\Uniblue
    2009-06-03 19:28 . 2009-06-03 19:28 -------- d-----w- c:\program files\Trend Micro
    2009-06-03 19:21 . 2009-06-03 18:19 15688 ----a-w- c:\windows\system32\lsdelete.exe
    2009-06-03 18:19 . 2009-06-03 18:17 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2009-06-03 18:19 . 2009-06-03 18:19 -------- dc----w- c:\windows\system32\DRVSTORE
    2009-06-03 18:19 . 2009-06-03 18:19 314200 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
    2009-06-03 18:19 . 2009-06-03 18:19 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
    2009-06-03 18:19 . 2009-06-03 18:19 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
    2009-06-03 18:19 . 2009-06-03 18:19 169312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
    2009-06-03 18:19 . 2009-06-03 18:19 348496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
    2009-06-03 18:19 . 2009-06-03 18:19 294240 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
    2009-06-03 18:19 . 2009-06-03 18:19 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
    2009-06-03 18:18 . 2009-06-03 18:18 1630048 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
    2009-06-03 18:17 . 2009-06-03 18:17 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
    2009-06-03 18:17 . 2009-06-03 18:17 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
    2009-06-03 18:17 . 2009-06-03 18:17 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
    2009-06-03 18:17 . 2009-06-03 18:17 640360 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
    2009-06-03 18:17 . 2009-06-03 18:17 540536 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
    2009-06-03 18:17 . 2009-06-03 18:17 559464 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
    2009-06-03 18:17 . 2009-06-03 18:17 2352456 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
    2009-06-03 18:17 . 2009-06-03 18:17 627536 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
    2009-06-03 18:17 . 2009-06-03 18:17 518488 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
    2009-06-03 18:17 . 2009-06-03 18:17 1005904 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
    2009-06-03 18:01 . 2009-06-03 18:01 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
    2009-06-03 18:01 . 2009-03-12 08:17 2902048 -c--a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
    2009-06-03 18:01 . 2009-06-03 18:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2009-06-03 17:23 . 2009-06-03 17:24 -------- d-----w- c:\program files\ERUNT
    2009-06-02 18:26 . 2009-06-02 18:26 -------- d-----w- c:\program files\SourceTec
    2009-05-28 13:33 . 2009-05-28 13:41 -------- d-----w- c:\program files\AutoIt3
    2009-05-28 12:32 . 2009-05-28 12:32 -------- d-----w- c:\program files\AutoHotkey
    2009-05-13 18:11 . 2009-05-19 19:03 -------- d-----w- c:\program files\xampp
    2009-05-10 09:27 . 2009-05-10 09:27 -------- d-----w- c:\program files\MSXML 4.0
    2009-05-10 08:58 . 2009-03-06 14:22 284160 ------w- c:\windows\system32\dllcache\pdh.dll
    2009-05-10 08:58 . 2009-02-09 12:10 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
    2009-05-10 08:58 . 2009-02-09 12:10 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
    2009-05-10 08:58 . 2009-02-06 11:11 110592 ------w- c:\windows\system32\dllcache\services.exe
    2009-05-10 08:58 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
    2009-05-10 08:58 . 2009-02-09 12:10 729088 ------w- c:\windows\system32\dllcache\lsasrv.dll
    2009-05-10 08:58 . 2009-02-09 12:10 617472 ------w- c:\windows\system32\dllcache\advapi32.dll
    2009-05-10 08:58 . 2009-02-09 12:10 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
    2009-05-10 08:58 . 2009-02-09 12:10 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
    2009-05-10 08:56 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
    2009-05-10 08:56 . 2008-04-21 12:08 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
    2009-05-10 08:15 . 2009-05-10 08:15 -------- d-----w- c:\windows\system32\scripting
    2009-05-10 08:15 . 2009-05-10 08:15 -------- d-----w- c:\windows\l2schemas
    2009-05-10 08:15 . 2009-05-10 08:15 -------- d-----w- c:\windows\system32\en
    2009-05-10 01:02 . 2008-04-14 00:11 397312 ------w- c:\windows\system32\mmcex.dll
    2009-05-08 20:52 . 2009-05-08 20:52 -------- d-----w- c:\program files\AVG
    2009-05-08 11:11 . 2001-10-28 15:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
    2009-05-08 11:11 . 2009-05-08 11:14 -------- d-----w- c:\program files\PDFCreator
    2009-05-08 11:11 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
    2009-05-07 18:00 . 2009-05-07 18:00 -------- d-----w- c:\documents and settings\hp3pl\Local Settings\Application Data\oDesk
    2009-05-07 17:59 . 2009-05-07 18:00 -------- d-----w- c:\program files\oDesk

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-06-04 22:27 . 2004-04-15 21:28 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-06-04 21:58 . 2009-04-08 19:40 -------- d-----w- c:\program files\Mozilla Thunderbird
    2009-06-04 15:13 . 2007-02-07 21:51 -------- d-----w- c:\program files\IrfanView
    2009-06-03 18:01 . 2006-05-29 17:40 -------- d-----w- c:\program files\Lavasoft
    2009-06-03 13:41 . 2008-05-05 10:30 -------- d-----w- c:\documents and settings\hp3pl\Application Data\Canon
    2009-06-02 18:28 . 2009-02-09 20:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2009-05-26 07:40 . 2003-06-19 15:08 87944 ----a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
    2009-05-17 14:55 . 2006-10-23 21:19 -------- d-----w- c:\program files\HighJackThis
    2009-05-16 21:04 . 2008-04-16 19:19 -------- d-----w- c:\documents and settings\hp3pl\Application Data\FileZilla
    2009-05-13 20:24 . 2006-01-31 12:45 -------- d-----w- c:\program files\QuickTime
    2009-05-13 15:48 . 2008-06-27 22:55 -------- d-----w- c:\program files\Spybot
    2009-05-07 12:44 . 2006-05-29 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-05-05 19:36 . 2009-05-05 19:36 -------- d-----w- c:\program files\Sothink DHTML Menu 9
    2009-05-05 19:36 . 2009-05-05 19:36 -------- d-----w- c:\program files\Common Files\SourceTec
    2009-04-29 22:38 . 2009-04-29 22:38 -------- d-----w- c:\program files\Rainlendar2
    2009-04-26 20:34 . 2009-04-26 20:34 -------- d-----w- c:\program files\The Regex Coach
    2009-04-24 23:54 . 2006-05-29 17:40 -------- d-----w- c:\documents and settings\hp3pl\Application Data\Lavasoft
    2009-04-24 20:19 . 2008-10-12 18:17 -------- d-----w- c:\program files\Agent Ransack
    2009-04-11 21:45 . 2009-04-11 21:45 -------- d-----w- c:\program files\The Guide
    2009-04-09 20:01 . 2009-04-09 20:01 -------- d-----w- c:\program files\MP3 Converter
    2009-04-08 19:40 . 2009-04-08 19:40 -------- d-----w- c:\documents and settings\hp3pl\Application Data\Thunderbird
    2009-03-26 07:20 . 2009-05-05 19:36 82432 ----a-w- c:\windows\system32\msxml4r.dll
    2009-03-26 07:20 . 2009-05-05 19:36 44544 ----a-w- c:\windows\system32\msxml4a.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "SpybotSD TeaTimer"="c:\program files\Spybot\TeaTimer.exe" [2009-03-05 2260480]
    "SoftAuto.exe"="c:\program files\Creative\Software Update 3\SoftAuto.exe" [2008-08-13 405504]
    "Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2009-02-21 4333568]
    "Google Update"="c:\documents and settings\hp3pl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-24 133104]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-24 335872]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 688218]
    "ChkAdmin"="c:\progra~1\Compaq\COMPAQ~1\CHKADMIN.EXE" [2003-05-12 81920]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-01-10 180269]
    "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-03 518488]
    "AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2003-05-30 88267]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
    "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-3-28 113664]
    Wireless-G Notebook Adapter.lnk - c:\program files\Linksys\Wireless-G Notebook Adapter\Gcc.exe [2006-10-7 36864]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
    "{EC654325-1273-C2A9-2B7C-45A29BCE2FBD}"= "c:\program files\Stardock\Fences\DesktopDock.dll" [2009-02-25 517480]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "Irmon"=2 (0x2)
    "DefWatch"=2 (0x2)
    "btwdins"=2 (0x2)
    "MDM"=2 (0x2)
    "DfwWebAgent"=2 (0x2)
    "CPQALERT"=2 (0x2)
    "Avg7UpdSvc"=2 (0x2)
    "Avg7Alrt"=2 (0x2)
    "Ati HotKey Poller"=2 (0x2)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\WINDOWS\\system32\\sessmgr.exe"=
    "c:\\StubInstaller.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\ScanSoft\\OmniPageSE\\EregEng\\NAVBrowser.exe"=
    "c:\\Program Files\\FrostWire\\FrostWire.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\xampp\\apache\\bin\\httpd.exe"=
    "c:\\Program Files\\xampp\\mysql\\bin\\mysqld.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "1723:TCP"= 1723:TCP:*:Disabled:@xpsp2res.dll,-22015
    "1701:UDP"= 1701:UDP:*:Disabled:@xpsp2res.dll,-22016
    "500:UDP"= 500:UDP:@xpsp2res.dll,-22017

    R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [6/5/2009 12:28 AM 40368]
    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/3/2009 8:19 PM 64160]
    R1 ClntMgmt;HP Client Management Driver;c:\windows\system32\drivers\Clntmgmt.sys [6/3/2005 10:01 PM 55336]
    R2 cpqWebDmi;Insight Web Agent;c:\progra~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe [6/3/2005 10:06 PM 24576]
    R2 ssoftnt4;ssoftnt4;c:\windows\system32\drivers\ssoftnt4.sys [12/3/2006 5:37 PM 114944]
    R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
    R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [4/16/2004 12:47 AM 182101]
    R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [4/16/2004 12:47 AM 5689]
    R3 WPC54Gv3;Linksys Wireless Notebook Adapter WPC54Gv3 Driver;c:\windows\system32\drivers\WPC54Gv3.SYS [11/30/2006 11:54 PM 610816]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 9:06 PM 1005904]
    S2 RIOUSB;RioPort.Com Rio500 USB Driver;c:\windows\system32\drivers\RioUsb.sys [4/16/2007 11:42 PM 15152]
    S3 Am772;AMD Alchemy™ Solutions Wireless 802.11 Adapter;c:\windows\system32\drivers\Am772.sys [7/26/2006 1:20 PM 174278]
    S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [6/3/2005 9:40 PM 17408]
    S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\Creative\Creative Centrale\CTUPnPSv.exe [5/21/2008 1:42 PM 64000]
    S3 TIACXLN;22M WLAN Adapter;c:\windows\system32\DRIVERS\tiacxln.sys --> c:\windows\system32\DRIVERS\tiacxln.sys [?]
    S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;c:\windows\system32\drivers\ar5211.sys [2/25/2004 11:22 PM 322560]

    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - HOTCORE3
    .
    Contents of the 'Scheduled Tasks' folder

    2009-06-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:17]

    2009-06-01 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-10-10 16:13]

    2009-06-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1980588459-256428701-3204507890-1006.job
    - c:\documents and settings\hp3pl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-24 15:20]

    2009-06-05 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
    HKLM-Run-QuickTime Task - c:\program files\QuickTime\qttask.exe
    SafeBoot-procexp90.Sys


    .
    ------- Supplementary Scan -------
    .
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uInternet Settings,ProxyOverride = <local>
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
    IE: {{88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - {17A84966-F1E9-4645-AA9E-5E771EE1C859} - c:\progra~1\VideoGet\Plugins\VIDEOG~1.DLL
    Handler: schmap-help - {2CF664A0-5EA6-47B5-884C-433A60145F78} - c:\program files\Schmap\Schmap Player\schmapdoclib.dll
    DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} - hxxps://www.p3.postbank.nl/sesam/CAX.cab
    DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} - hxxps://gto.postbank.nl/GTO/PBGNX.cab
    FF - ProfilePath - c:\documents and settings\hp3pl\Application Data\Mozilla\Firefox\Profiles\n3dc9n2k.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/|http://reddit.com/|https://login.yahoo.com/config/mail?.intl=us
    FF - plugin: c:\documents and settings\hp3pl\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-06-05 10:50
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(824)
    c:\windows\system32\Ati2evxx.dll
    c:\program files\Funk Software\Funk Client\odLogin.dll

    - - - - - - - > 'explorer.exe'(3720)
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    c:\program files\Stardock\Fences\DesktopDock.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
    .
    Completion time: 2009-06-05 10:54
    ComboFix-quarantined-files.txt 2009-06-05 08:53

    Pre-Run: 4,159,889,408 bytes free
    Post-Run: 4,288,339,968 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

    231 --- E O F --- 2009-05-22 12:18



    dds.txt:


    DDS (Ver_09-05-14.01) - NTFSx86
    Run by HP3PL at 10:59:36.72 on Fri 06/05/2009
    Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_03
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1362 [GMT 2:00]


    ============== Running Processes ===============

    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
    C:\Program Files\Creative\Shared Files\CTDevSrv.exe
    C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\ssoftsrv.exe
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
    C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Rainlendar2\Rainlendar2.exe
    C:\Documents and Settings\hp3pl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
    C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Spybot\TeaTimer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\hp3pl\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uInternet Settings,ProxyOverride = <local>
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot\SDHelper.dll
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
    TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [SpybotSD TeaTimer] c:\program files\spybot\TeaTimer.exe
    uRun: [SoftAuto.exe] "c:\program files\creative\software update 3\SoftAuto.exe"
    uRun: [Rainlendar2] c:\program files\rainlendar2\Rainlendar2.exe
    uRun: [Google Update] "c:\documents and settings\hp3pl\local settings\application data\google\update\GoogleUpdate.exe" /c
    mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
    mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [AGRSMMSG] AGRSMMSG.exe
    mRun: [ChkAdmin] c:\progra~1\compaq\compaq~1\CHKADMIN.EXE
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
    dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
    dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\program files\linksys\wireless-g notebook adapter\Gcc.exe
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
    IE: {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - {17A84966-F1E9-4645-AA9E-5E771EE1C859} - c:\progra~1\videoget\plugins\VIDEOG~1.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot\SDHelper.dll
    DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} - hxxps://www.p3.postbank.nl/sesam/CAX.cab
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
    DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
    DPF: {62789780-B744-11D0-986B-00609731A21D} - ftp://ftp.giskit.com/pub/mapguide/mgaxctrl.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} - hxxps://gto.postbank.nl/GTO/PBGNX.cab
    DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4795/mcfscan.cab
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
    Handler: schmap-help - {2CF664A0-5EA6-47B5-884C-433A60145F78} - c:\program files\schmap\schmap player\schmapdoclib.dll
    Notify: AtiExtEvent - Ati2evxx.dll
    Notify: NavLogon - c:\windows\system32\NavLogon.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    STS: Fences: {ec654325-1273-c2a9-2b7c-45a29bce2fbd} - c:\program files\stardock\fences\DesktopDock.dll
    SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\hp3pl\applic~1\mozilla\firefox\profiles\n3dc9n2k.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/|http://reddit.com/|https://login.yahoo.com/config/mail?.intl=us
    FF - plugin: c:\documents and settings\hp3pl\local settings\application data\google\update\1.2.145.5\npGoogleOneClick8.dll

    ============= SERVICES / DRIVERS ===============

    R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2009-6-5 40368]
    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-3 64160]
    R1 ClntMgmt;HP Client Management Driver;c:\windows\system32\drivers\Clntmgmt.sys [2005-6-3 55336]
    R2 cpqWebDmi;Insight Web Agent;c:\progra~1\compaq\compaq~1\cpqweb~1\WebDmi.exe [2005-6-3 24576]
    R2 ssoftnt4;ssoftnt4;c:\windows\system32\drivers\ssoftnt4.sys [2006-12-3 114944]
    R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
    R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [2004-4-16 182101]
    R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [2004-4-16 5689]
    R3 WPC54Gv3;Linksys Wireless Notebook Adapter WPC54Gv3 Driver;c:\windows\system32\drivers\WPC54Gv3.SYS [2006-11-30 610816]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1005904]
    S2 RIOUSB;RioPort.Com Rio500 USB Driver;c:\windows\system32\drivers\RioUsb.sys [2007-4-16 15152]
    S3 Am772;AMD Alchemy™ Solutions Wireless 802.11 Adapter;c:\windows\system32\drivers\Am772.sys [2006-7-26 174278]
    S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [2005-6-3 17408]
    S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\creative\creative centrale\CTUPnPSv.exe [2008-5-21 64000]
    S3 TIACXLN;22M WLAN Adapter;c:\windows\system32\drivers\tiacxln.sys --> c:\windows\system32\drivers\tiacxln.sys [?]
    S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;c:\windows\system32\drivers\ar5211.sys [2004-2-25 322560]

    =============== Created Last 30 ================

    2009-06-05 10:46 <DIR> a-dshr-- C:\cmdcons
    2009-06-05 10:39 161,792 a------- c:\windows\SWREG.exe
    2009-06-05 10:39 154,624 a------- c:\windows\PEV.exe
    2009-06-05 10:39 98,816 a------- c:\windows\sed.exe
    2009-06-05 10:39 <DIR> --ds---- C:\ComboFix
    2009-06-05 00:28 4,244,744 a------- c:\windows\system32\qtp-mt334.dll
    2009-06-05 00:28 247,560 a------- c:\windows\system32\prgiso.dll
    2009-06-05 00:28 40,368 a------- c:\windows\system32\drivers\hotcore3.sys
    2009-06-05 00:28 13,576 a------- c:\windows\system32\wnaspi32.dll
    2009-06-05 00:27 <DIR> --d----- c:\program files\Paragon Software
    2009-06-04 11:56 <DIR> --d----- c:\docume~1\hp3pl\applic~1\Uniblue
    2009-06-03 21:28 <DIR> --d----- c:\program files\Trend Micro
    2009-06-03 21:21 15,688 a------- c:\windows\system32\lsdelete.exe
    2009-06-03 20:19 64,160 a------- c:\windows\system32\drivers\Lbd.sys
    2009-06-03 20:01 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
    2009-06-02 20:26 17,542 a------- c:\windows\SothinkTree.ico
    2009-06-02 20:26 <DIR> --d----- c:\program files\SourceTec
    2009-05-28 15:33 <DIR> --d----- c:\program files\AutoIt3
    2009-05-28 14:32 <DIR> --d----- c:\program files\AutoHotkey
    2009-05-13 20:11 <DIR> --d----- c:\program files\xampp
    2009-05-10 11:27 <DIR> --d----- c:\program files\MSXML 4.0
    2009-05-10 10:58 284,160 -------- c:\windows\system32\dllcache\pdh.dll
    2009-05-10 10:58 473,600 -------- c:\windows\system32\dllcache\fastprox.dll
    2009-05-10 10:58 401,408 -------- c:\windows\system32\dllcache\rpcss.dll
    2009-05-10 10:58 227,840 -------- c:\windows\system32\dllcache\wmiprvse.exe
    2009-05-10 10:58 110,592 -------- c:\windows\system32\dllcache\services.exe
    2009-05-10 10:58 729,088 -------- c:\windows\system32\dllcache\lsasrv.dll
    2009-05-10 10:58 617,472 -------- c:\windows\system32\dllcache\advapi32.dll
    2009-05-10 10:58 453,120 -------- c:\windows\system32\dllcache\wmiprvsd.dll
    2009-05-10 10:58 714,752 -------- c:\windows\system32\dllcache\ntdll.dll
    2009-05-10 10:56 2,560 -------- c:\windows\system32\xpsp4res.dll
    2009-05-10 10:56 1,203,922 -------- c:\windows\system32\dllcache\sysmain.sdb
    2009-05-10 10:56 215,552 -------- c:\windows\system32\dllcache\wordpad.exe
    2009-05-10 10:15 <DIR> --d----- c:\windows\system32\scripting
    2009-05-10 10:15 <DIR> --d----- c:\windows\l2schemas
    2009-05-10 10:15 <DIR> --d----- c:\windows\system32\en
    2009-05-10 03:03 276,992 -------- c:\windows\system32\wmphoto.dll
    2009-05-10 03:02 397,312 -------- c:\windows\system32\mmcex.dll
    2009-05-08 22:52 <DIR> --d----- c:\program files\AVG
    2009-05-08 13:11 137,000 a------- c:\windows\system32\MSMAPI32.OCX
    2009-05-08 13:11 116,224 a------- c:\windows\system32\pdfcmnnt.dll
    2009-05-08 13:11 23,552 a------- c:\windows\system32\MSMPIDE.DLL
    2009-05-08 13:11 <DIR> --d----- c:\program files\PDFCreator
    2009-05-07 19:59 <DIR> --d----- c:\program files\oDesk

    ==================== Find3M ====================

    2009-05-26 09:40 87,944 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
    2009-03-26 09:20 82,432 a------- c:\windows\system32\msxml4r.dll
    2009-03-26 09:20 44,544 a------- c:\windows\system32\msxml4a.dll
    2009-03-21 16:06 989,696 -------- c:\windows\system32\dllcache\kernel32.dll
    2009-03-10 22:18 934,792 -------- c:\windows\system32\dllcache\WgaTray.exe
    2009-03-10 22:18 239,496 -------- c:\windows\system32\dllcache\wgaLogon.dll
    2008-07-15 22:58 21,336 a------- c:\docume~1\hp3pl\applic~1\GDIPFONTCACHEV1.DAT

    ============= FINISH: 10:59:56.69 ===============


    Blade81
    Good. Now, let's do some updating for vulnerable software smile.gif


    Uninstall old Adobe Reader versions and get the latest one here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here.


    Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

    Updating Java:
    • Download the latest version of Java Runtime Environment (JRE) 6 Update 14.
    • Click the
      Download
      button to the right.
    • Select Windows on platform combobox and check the box that says:
      Accept License Agreement. Click continue.
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u14-windows-i586-p.exe to install the newest version. Uncheck MSN toolbar if it's offered there.

    Post a fresh dds.txt log and let me know if the original issue still exists
    jotrys
    Hi there Blade,

    Followed your instructions:
    - Uninstalled Adobe Reader versions and installed Foxit Reader (without toolbar)

    - Uninstalled all old Java and JRE versions, and installed the one you identified

    And I have not been getting hijacked by vmn.net when providing an unknown internet address. GOOD! smile.gif
    ( was this due to the pdfforge Toolbar?)

    And the latest dds.txt log:


    DDS (Ver_09-05-14.01) - NTFSx86
    Run by HP3PL at 20:15:15.62 on Fri 06/05/2009
    Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1344 [GMT 2:00]


    ============== Running Processes ===============

    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
    C:\Program Files\Creative\Shared Files\CTDevSrv.exe
    C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\ssoftsrv.exe
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
    C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot\TeaTimer.exe
    C:\Program Files\Creative\Software Update 3\SoftAuto.exe
    C:\Program Files\Rainlendar2\Rainlendar2.exe
    C:\Documents and Settings\hp3pl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
    C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
    C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
    C:\Program Files\Notepad++\notepad++.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\hp3pl\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uInternet Settings,ProxyOverride = <local>
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot\SDHelper.dll
    BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [SpybotSD TeaTimer] c:\program files\spybot\TeaTimer.exe
    uRun: [SoftAuto.exe] "c:\program files\creative\software update 3\SoftAuto.exe"
    uRun: [Rainlendar2] c:\program files\rainlendar2\Rainlendar2.exe
    uRun: [Google Update] "c:\documents and settings\hp3pl\local settings\application data\google\update\GoogleUpdate.exe" /c
    mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
    mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [AGRSMMSG] AGRSMMSG.exe
    mRun: [ChkAdmin] c:\progra~1\compaq\compaq~1\CHKADMIN.EXE
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
    dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\program files\linksys\wireless-g notebook adapter\Gcc.exe
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - {17A84966-F1E9-4645-AA9E-5E771EE1C859} - c:\progra~1\videoget\plugins\VIDEOG~1.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot\SDHelper.dll
    DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} - hxxps://www.p3.postbank.nl/sesam/CAX.cab
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
    DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
    DPF: {62789780-B744-11D0-986B-00609731A21D} - ftp://ftp.giskit.com/pub/mapguide/mgaxctrl.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} - hxxps://gto.postbank.nl/GTO/PBGNX.cab
    DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4795/mcfscan.cab
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
    Handler: schmap-help - {2CF664A0-5EA6-47B5-884C-433A60145F78} - c:\program files\schmap\schmap player\schmapdoclib.dll
    Notify: AtiExtEvent - Ati2evxx.dll
    Notify: NavLogon - c:\windows\system32\NavLogon.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    STS: Fences: {ec654325-1273-c2a9-2b7c-45a29bce2fbd} - c:\program files\stardock\fences\DesktopDock.dll
    SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\hp3pl\applic~1\mozilla\firefox\profiles\n3dc9n2k.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/|http://reddit.com/|https://login.yahoo.com/config/mail?.intl=us
    FF - plugin: c:\documents and settings\hp3pl\local settings\application data\google\update\1.2.145.5\npGoogleOneClick8.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll

    ============= SERVICES / DRIVERS ===============

    R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2009-6-5 40368]
    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-3 64160]
    R1 ClntMgmt;HP Client Management Driver;c:\windows\system32\drivers\Clntmgmt.sys [2005-6-3 55336]
    R2 cpqWebDmi;Insight Web Agent;c:\progra~1\compaq\compaq~1\cpqweb~1\WebDmi.exe [2005-6-3 24576]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1005904]
    R2 ssoftnt4;ssoftnt4;c:\windows\system32\drivers\ssoftnt4.sys [2006-12-3 114944]
    R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
    R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [2004-4-16 182101]
    R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [2004-4-16 5689]
    R3 WPC54Gv3;Linksys Wireless Notebook Adapter WPC54Gv3 Driver;c:\windows\system32\drivers\WPC54Gv3.SYS [2006-11-30 610816]
    S2 RIOUSB;RioPort.Com Rio500 USB Driver;c:\windows\system32\drivers\RioUsb.sys [2007-4-16 15152]
    S3 Am772;AMD Alchemy™ Solutions Wireless 802.11 Adapter;c:\windows\system32\drivers\Am772.sys [2006-7-26 174278]
    S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [2005-6-3 17408]
    S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\creative\creative centrale\CTUPnPSv.exe [2008-5-21 64000]
    S3 TIACXLN;22M WLAN Adapter;c:\windows\system32\drivers\tiacxln.sys --> c:\windows\system32\drivers\tiacxln.sys [?]
    S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;c:\windows\system32\drivers\ar5211.sys [2004-2-25 322560]

    =============== Created Last 30 ================

    2009-06-05 20:03 73,728 a------- c:\windows\system32\javacpl.cpl
    2009-06-05 19:58 410,984 a------- c:\windows\system32\deploytk.dll
    2009-06-05 19:38 <DIR> --d----- c:\program files\Foxit Software
    2009-06-05 19:38 <DIR> --d----- c:\docume~1\hp3pl\applic~1\Foxit
    2009-06-05 10:46 <DIR> a-dshr-- C:\cmdcons
    2009-06-05 10:39 161,792 a------- c:\windows\SWREG.exe
    2009-06-05 10:39 154,624 a------- c:\windows\PEV.exe
    2009-06-05 10:39 98,816 a------- c:\windows\sed.exe
    2009-06-05 10:39 <DIR> --ds---- C:\ComboFix
    2009-06-05 00:28 4,244,744 a------- c:\windows\system32\qtp-mt334.dll
    2009-06-05 00:28 247,560 a------- c:\windows\system32\prgiso.dll
    2009-06-05 00:28 40,368 a------- c:\windows\system32\drivers\hotcore3.sys
    2009-06-05 00:28 13,576 a------- c:\windows\system32\wnaspi32.dll
    2009-06-05 00:27 <DIR> --d----- c:\program files\Paragon Software
    2009-06-04 11:56 <DIR> --d----- c:\docume~1\hp3pl\applic~1\Uniblue
    2009-06-03 21:28 <DIR> --d----- c:\program files\Trend Micro
    2009-06-03 21:21 15,688 a------- c:\windows\system32\lsdelete.exe
    2009-06-03 20:19 64,160 a------- c:\windows\system32\drivers\Lbd.sys
    2009-06-03 20:01 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
    2009-06-02 20:26 17,542 a------- c:\windows\SothinkTree.ico
    2009-06-02 20:26 <DIR> --d----- c:\program files\SourceTec
    2009-05-28 15:33 <DIR> --d----- c:\program files\AutoIt3
    2009-05-28 14:32 <DIR> --d----- c:\program files\AutoHotkey
    2009-05-13 20:11 <DIR> --d----- c:\program files\xampp
    2009-05-10 11:27 <DIR> --d----- c:\program files\MSXML 4.0
    2009-05-10 10:58 284,160 -------- c:\windows\system32\dllcache\pdh.dll
    2009-05-10 10:58 473,600 -------- c:\windows\system32\dllcache\fastprox.dll
    2009-05-10 10:58 401,408 -------- c:\windows\system32\dllcache\rpcss.dll
    2009-05-10 10:58 227,840 -------- c:\windows\system32\dllcache\wmiprvse.exe
    2009-05-10 10:58 110,592 -------- c:\windows\system32\dllcache\services.exe
    2009-05-10 10:58 729,088 -------- c:\windows\system32\dllcache\lsasrv.dll
    2009-05-10 10:58 617,472 -------- c:\windows\system32\dllcache\advapi32.dll
    2009-05-10 10:58 453,120 -------- c:\windows\system32\dllcache\wmiprvsd.dll
    2009-05-10 10:58 714,752 -------- c:\windows\system32\dllcache\ntdll.dll
    2009-05-10 10:56 2,560 -------- c:\windows\system32\xpsp4res.dll
    2009-05-10 10:56 1,203,922 -------- c:\windows\system32\dllcache\sysmain.sdb
    2009-05-10 10:56 215,552 -------- c:\windows\system32\dllcache\wordpad.exe
    2009-05-10 10:15 <DIR> --d----- c:\windows\system32\scripting
    2009-05-10 10:15 <DIR> --d----- c:\windows\l2schemas
    2009-05-10 10:15 <DIR> --d----- c:\windows\system32\en
    2009-05-10 03:03 276,992 -------- c:\windows\system32\wmphoto.dll
    2009-05-10 03:02 397,312 -------- c:\windows\system32\mmcex.dll
    2009-05-08 22:52 <DIR> --d----- c:\program files\AVG
    2009-05-08 13:11 137,000 a------- c:\windows\system32\MSMAPI32.OCX
    2009-05-08 13:11 116,224 a------- c:\windows\system32\pdfcmnnt.dll
    2009-05-08 13:11 23,552 a------- c:\windows\system32\MSMPIDE.DLL
    2009-05-08 13:11 <DIR> --d----- c:\program files\PDFCreator
    2009-05-07 19:59 <DIR> --d----- c:\program files\oDesk

    ==================== Find3M ====================

    2009-05-26 09:40 87,944 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
    2009-03-26 09:20 82,432 a------- c:\windows\system32\msxml4r.dll
    2009-03-26 09:20 44,544 a------- c:\windows\system32\msxml4a.dll
    2009-03-21 16:06 989,696 -------- c:\windows\system32\dllcache\kernel32.dll
    2009-03-10 22:18 934,792 -------- c:\windows\system32\dllcache\WgaTray.exe
    2009-03-10 22:18 239,496 -------- c:\windows\system32\dllcache\wgaLogon.dll
    2008-07-15 22:58 21,336 a------- c:\docume~1\hp3pl\applic~1\GDIPFONTCACHEV1.DAT

    ============= FINISH: 20:16:09.52 ===============



    Blade81
    QUOTE
    ( was this due to the pdfforge Toolbar?)

    Yes, big part of toolbars are actually pretty sneaky.


    Well congrats, it appears your system is all clean Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions.


    THESE STEPS ARE VERY IMPORTANT

    Let's reset system restore
    Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

    1. Turn off System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.

    2. Reboot.

    3. Turn ON System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    UN-Check *Turn off System Restore*.
    Click Apply, and then click OK.
    NOTE: only do this ONCE,NOT on a regular basis



    Now lets uninstall ComboFix:
    • Click START then RUN
    • Now type Combofix /u in the runbox and click OK


    You may remove dds and related logs too.


    UPDATING WINDOWS AND INTERNET EXPLORER

    IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

    If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


    Make your Internet Explorer more secure

    This can be done by following these simple instructions:
    From within Internet Explorer click on the Tools menu and then click on Options.
    Click once on the Security tab
    Click once on the Internet icon so it becomes highlighted.
    Click once on the Custom Level button.
    Change the Download signed ActiveX controls to Prompt
    Change the Download unsigned ActiveX controls to Disable
    Change the Initialize and script ActiveX controls not marked as safe to Disable
    Change the Installation of desktop items to Prompt
    Change the Launching programs and files in an IFRAME to Prompt
    Change the Navigate sub-frames across different domains to Prompt
    When all these settings have been made, click on the OK button.
    If it prompts you as to whether or not you want to save the settings, press the Yes button.
    Next press the Apply button and then the OK to exit the Internet Properties page.



    The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.
    • hosts file:
      • Every version of windows has a hosts file as part of them.
      • In a very basic sense, they are used to locate webpages.
      • We can customize a hosts file so that it blocks certain webpages.
      • However, it can slow down certain computers.
      • This is why using a hosts file is optional!!
      Download it here. Make sure you read the instructions on how to install the hosts file. There is a good tutorial here
      If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
      1. Click the start button (at the lower left hand corner of your screen)
      2. Click run
      3. In the dialog box, type services.msc
      4. hit enter, then locate dns client
      5. Highlight it, then double-click it.
      6. On the dropdown box, change the setting from automatic to manual.
      7. Click ok
  • Get Anti Virus Software and keep it updated - Most AVs will update automatically, but if not I would recommend making updating the AV the first job every time the PC is connected to the internet. An AV that is using defs that are seven days old is not going to be much protection. If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out. Good free antivirus programs are:
    Antivir
    Avast!
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
    If you don't have a 3rd party firewall or a router behind NAT then I recommend getting one. I recommend either Online Armor Free or Comodo Firewall Pro (If you choose Comodo: Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and install firewall ONLY!). Both providers have support forums that help with configuration related questions.


  • Just a final reminder for you. I am trying to stress these two points.
    UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
    Make sure all of your security programs are up to date.
    Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


    Once again, please post and tell me how things are going with your system... problems etc.

    Have a great day,
    Blade cool.gif
    jotrys
    Thanks for your help Blade.

    cheers,
    jotrys
    Blade81
    Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. smile.gif

    If you're the topic starter, and need this topic reopened, please contact the staff member who was helping you with your issue.

    Everyone else please begin a New Topic.

    Thank you !
    This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
    Invision Power Board © 2001-2010 Invision Power Services, Inc.