WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptySpyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
I'm having some trouble with Spyware.Ispynow on my computer, It started last night when I was just using AIM, I was typing and then suddenly my computer began to close out apps and continued to restart itself. When it came back to desktop my internet explorer would not work. It would play an error sound and pop up a message from Windows Internet Explorer saying "Cannot find "http://go.mircosoft.com/fwlink/?LinkId=74005'. Make sure the path or internet address is correct." I was able to get firefox to work in safe mode allowing me to search around for awhile and now here i am. I also found a site suggesting to use Malwarebytes' Anti-Malware program, first time i tried downloading it my pc restarted again like it did last night, second time i was able to finish the download and install the program but it seems like it will not run. Any help would be appreciated.

Here is my Hijackthis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:42:19 PM, on 12/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\WINDOWS\system32\fppsys.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Documents and Settings\Eric\Desktop\inane.exe
C:\DOCUME~1\Eric\LOCALS~1\Temp\is-TM7CQ.tmp\inane.tmp
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Eric\Desktop\Hijack(GP)This.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Warning: do not remove it! (system)] fppsys.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [appdscapl] C:\WINDOWS\system32\lmzstafm.exe
O4 - HKCU\..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirelessUploadControl.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://www.playwhat.com/solidPlugin/solidstateion.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: karna.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: geBsqRlm - geBsqRlm.dll (file missing)
O20 - Winlogon Notify: pmnoPiHA - pmnoPiHA.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 9300 bytes

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
Here is the uninstall Log

7-Zip 4.58 beta
Ad-Aware
Adobe Common File Installer
Adobe Flash Player ActiveX
Adobe Help Center 1.0
Adobe Photoshop 7.0
Adobe Photoshop CS2
Adobe Reader 8.1.2
Adobe Shockwave Player
Adobe Stock Photos 1.0
AIM 6
AOL Instant Messenger
Apple Software Update
ArcSoft MediaImpression
ArcSoft PhotoImpression
AxCrypt (Remove Only)
Azureus Vuze
Command & Conquer 3
Command & Conquer The First Decade
ConvertXtoDVD 2.2.2.256
Creative System Information
DAEMON Tools
Diablo II
DivX
DivX Content Uploader
DivX Converter
DivX Converter
DivX Player
DivX Web Player
Download Updater (AOL LLC)
EPSON Copy Utility
EPSON Photo Print
EPSON Scanner Reference Guide
EPSON Smart Panel
EPSON TWAIN 5
ESET Online Scanner
Final Fantasy VII - Ultima Edition
FINAL FANTASY XI
FINAL FANTASY XI: Chains of Promathia
FINAL FANTASY XI: Rise of the Zilart
FINAL FANTASY XI: Treasures of Aht Urhgan
FINAL FANTASY XI: Wings of the Goddess
Folder Password Protect 2.7
Fraps (remove only)
Google Earth
Hamachi 0.9.9.9
HijackThis 2.0.2
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
HP Imaging Device Functions 7.0
HP Photosmart and Deskjet 7.0 Software
ijji - Gunz
ijji Auto Installer
iWheelWorks 7.72
J2SE Runtime Environment 5.0 Update 11
LG USB Drivers
LimeWire 4.18.8
Lock Folder XP 3.6
Logitech QuickCam
Logitech QuickCam Driver Package
Magic ISO Maker v5.5 (build 0272)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Silverlight
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (2.0.0.12)
MSN Music Assistant
MSXML 4.0 SP2 Parser and SDK
MSXML4 Parser
NASA World Wind 1.4
Nero 7 Essentials
NVIDIA Drivers
Oblivion
OpenMG Limited Patch 4.1-05-13-31-01
OpenMG Secure Module 4.1.00
Paint Shop Pro 7 ESD
Pinnacle Hollywood FX for Studio
Pinnacle Instant DVD Recorder
Pinnacle Studio LINX
Pinnacle USB device drivers
PlayOnline Viewer & Tetra Master
PowerDVD
QuickTime
RTPatch Update
ScanToWeb
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Skype 2.0
Solid State ION Internet Explorer Plugin
SonicStage 3.0
Sound Blaster Live!
SoundMAX
Spyware Doctor 6.0
Studio 11
Studio 9
SUPERAntiSpyware Free Edition
TeamSpeak 2 RC2
The Rosetta Stone
TomTom HOME
Tweakui Powertoy for Windows XP
Universal SCSI Controller
upapp
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB936357)
VC_MergeModuleToMSI
Ventrilo Client
VideoLAN VLC media player 0.8.1
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Virtual Desktop Manager Powertoy for Windows XP
WD Diagnostics
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
WinPcap 3.1
WinRAR archiver
Yahoo! Desktop Login
ZoneAlarm
ZoneAlarm Spy Blocker

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
Hello.


  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [Warning: do not remove it! (system)] fppsys.exe
    O4 - HKCU\..\Run: [appdscapl] C:\WINDOWS\system32\lmzstafm.exe
    O20 - AppInit_DLLs: karna.dat
    O20 - Winlogon Notify: geBsqRlm - geBsqRlm.dll (file missing)
    O20 - Winlogon Notify: pmnoPiHA - pmnoPiHA.dll (file missing)


  • Press "Fix Checked"
  • Close Hijack This.


Delete these files in bold:
C:\windows\system32\fppsys.exe
C:\windows\system32\lmzstafm.exe
C:\windows\system32\karna.dat



  • Download combofix from here, use the top links - combofix.exe
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.

    Spyware.Ispynow  Hijackthis log and uninstall log included. Please help Rcauto10

  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will this next prompt that asks if you want to continue the malware scan, select yes

    Spyware.Ispynow  Hijackthis log and uninstall log included. Please help Whatne10

  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help DXwU4
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help VvYDg

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
Combofix logfile.

ComboFix 08-12-01.01 - Eric 2008-12-01 16:14:40.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.721 [GMT -6:00]
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Eric\Application Data\DOBE~1
c:\documents and settings\Eric\Application Data\google\runhh6110411.exe
c:\documents and settings\Eric\Application Data\inst.exe
c:\documents and settings\Eric\Application Data\SKS~1
c:\documents and settings\Eric\nah_yyja.exe
c:\program files\Common Files\{7B5DF~1
c:\temp\vtmp2
c:\windows\a.bat
c:\windows\base64.tmp
c:\windows\bdn.com
c:\windows\Downloaded Program Files\setup.inf
c:\windows\FVProtect.exe
c:\windows\IE4 Error Log.txt
c:\windows\iTunesMusic.exe
c:\windows\mbols~1
c:\windows\mcroso~1.net
c:\windows\mcroso~1.net\M?crosoft.NET\
c:\windows\mslagent
c:\windows\mssecu.exe
c:\windows\system32\akttzn.exe
c:\windows\system32\anticipator.dll
c:\windows\system32\awtoolb.dll
c:\windows\system32\bdn.com
c:\windows\system32\dpcproxy.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\TDSSrfdc.sys
c:\windows\system32\fnts~1
c:\windows\system32\h@tkeysh@@k.dll
c:\windows\system32\hoproxy.dll
c:\windows\system32\hxiwlgpm.dat
c:\windows\system32\hxiwlgpm.exe
c:\windows\system32\IiSYJRqr.ini
c:\windows\system32\IiSYJRqr.ini2
c:\windows\system32\msgp.exe
c:\windows\system32\mssecu.exe
c:\windows\system32\mtr2.exe
c:\windows\system32\mwin32.exe
c:\windows\system32\netode.exe
c:\windows\system32\newsd32.exe
c:\windows\system32\packet.dll
c:\windows\system32\ppqss.ini2
c:\windows\system32\ps1.exe
c:\windows\system32\psoft1.exe
c:\windows\system32\pthreadVC.dll
c:\windows\system32\pYFOnnmp.ini
c:\windows\system32\pYFOnnmp.ini2
c:\windows\system32\regm64.dll
c:\windows\system32\Rundl1.exe
c:\windows\system32\smp
c:\windows\system32\smp\msrc.exe
c:\windows\system32\ssvchost.exe
c:\windows\system32\sysreq.exe
c:\windows\system32\taack.dat
c:\windows\system32\taack.exe
c:\windows\system32\TDSSblat.dat
c:\windows\system32\TDSSdlpb.dll
c:\windows\system32\TDSSkfkl.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSottp.dll
c:\windows\system32\TDSSqogd.log
c:\windows\system32\TDSSqshc.dll
c:\windows\system32\TDSSshbe.log
c:\windows\system32\TDSSurev.dll
c:\windows\system32\TDSSxnyq.dll
c:\windows\system32\temp#01.exe
c:\windows\system32\UuFgfMoq.ini
c:\windows\system32\UuFgfMoq.ini2
c:\windows\system32\VBIEWER.OCX
c:\windows\system32\wanpacket.dll
c:\windows\system32\winlogonpc.exe
c:\windows\system32\winsystem.exe
c:\windows\system32\WINWGPX.EXE
c:\windows\system32\wpcap.dll
c:\windows\userconfig9x.dll
c:\windows\zip1.tmp
c:\windows\zip2.tmp
c:\windows\zip3.tmp
c:\windows\zipped.tmp

Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\winlogon.exe


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
-------\Service_NPF


((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.

2008-12-01 15:07 . 2008-12-01 16:23 d-------- C:\-Combo-Fix-
2008-12-01 14:03 . 2008-12-01 14:32 d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-01 14:03 . 2008-12-01 14:03 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-01 14:03 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-01 14:03 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-01 01:07 . 2008-12-01 16:21 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-01 01:07 . 2008-12-01 16:12 1,409 --a------ c:\windows\QTFont.for
2008-11-23 20:36 . 2008-11-23 20:36 d-------- c:\program files\Common Files\Software Update Utility
2008-11-23 20:36 . 2008-11-23 20:36 d-------- c:\documents and settings\All Users\Application Data\acccore
2008-11-23 05:46 . 2008-11-23 05:47 d-------- c:\documents and settings\Eric\Application Data\Move Networks
2008-11-15 03:59 . 2008-11-15 03:59 d-------- c:\program files\Microsoft Silverlight

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-01 22:21 0 ----a-w c:\windows\system32\drivers\logiflt.iad
2008-12-01 22:19 502,272 ----a-w c:\windows\system32\winlogon.exe
2008-12-01 21:06 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-01 07:49 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2008-12-01 07:00 --------- d-----w c:\program files\Spyware Doctor
2008-12-01 05:17 44,312 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-01 05:17 3,600,416 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\ArcSoft
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\Ahead
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\AdobeUM
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\Acreon
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\acccore
2008-12-01 05:12 295,424 ----a-w c:\windows\system32\termsrv.dll
2008-11-27 11:33 --------- d-----w c:\documents and settings\Eric\Application Data\LimeWire
2008-11-24 04:06 --------- d-----w c:\documents and settings\Eric\Application Data\Azureus
2008-11-24 02:36 --------- d-----w c:\program files\Viewpoint
2008-11-24 02:36 --------- d-----w c:\program files\AIM6
2008-11-24 02:36 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2008-11-24 02:35 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-11-24 02:34 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-21 16:43 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-27 12:46 2,918,912 ----a-w c:\windows\Internet Logs\xDB2.tmp
2008-10-27 12:46 1,392,640 ----a-w c:\windows\Internet Logs\xDB3.tmp
2008-10-25 04:45 --------- d-----w c:\documents and settings\Eric\Application Data\Vso
2008-10-25 02:23 --------- d-----w c:\program files\LimeWire
2008-10-24 09:42 --------- d-----w c:\program files\Everstrike Software
2008-10-24 09:42 --------- d-----w c:\program files\Common Files\Everstrike Software
2008-10-24 09:38 --------- d-----w c:\program files\Folder Password Protect
2008-10-23 00:15 --------- d-----w c:\program files\Axon Data
2008-10-22 00:49 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle Studio
2008-10-22 00:49 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle
2008-10-22 00:44 --------- d-----w c:\program files\Pinnacle
2008-10-22 00:24 --------- d-----w c:\documents and settings\Eric\Application Data\InstallShield
2008-10-21 22:25 --------- d-----w c:\program files\MagicISO
2008-10-19 21:57 --------- d-----w c:\program files\Ventrilo
2008-10-19 21:57 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-17 21:27 2,946,048 ----a-w c:\windows\Internet Logs\xDB1.tmp
2008-10-14 03:58 --------- d-----w c:\program files\SUPERAntiSpyware
2008-10-14 03:55 --------- d-----w c:\program files\ZoneAlarmSB
2008-10-14 03:51 --------- d-----w c:\documents and settings\All Users\Application Data\MailFrontier
2008-10-14 03:50 --------- d-----w c:\program files\Zone Labs
2008-10-13 08:36 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-10-13 08:34 --------- d-----w c:\program files\Lavasoft
2008-10-13 08:19 --------- d-----w c:\documents and settings\Eric\Application Data\Lavasoft
2008-10-13 05:56 --------- d-----w c:\program files\AML Products
2008-10-13 04:53 --------- d-----w c:\program files\StreamCast
2008-10-13 03:44 --------- d-----w c:\documents and settings\Eric\Application Data\PC Tools
2008-10-13 03:11 --------- d-----w c:\program files\Microsoft AntiSpyware
2008-10-13 02:39 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-12 23:01 --------- d-----w c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition classic
2008-10-12 22:07 --------- d-----w c:\program files\fhuuifg
2008-10-12 22:07 --------- d-----w c:\documents and settings\All Users\Application Data\pkbwfgrq
2008-10-09 00:20 --------- d-----w c:\program files\Morpheus
2008-10-04 02:44 --------- d-----w c:\documents and settings\Eric\Application Data\dvdcss
2007-06-20 07:45 47,360 -c--a-w c:\documents and settings\Eric\Application Data\pcouffin.sys
2004-06-03 00:01 121,344 --sha-w c:\windows\system32\fppsys.exe
.

Continued...

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
------- Sigcheck -------

2008-11-30 23:12 295424 40ffc19a8d4875e9e19cecdc76ef9201 c:\windows\system32\termsrv.dll
2004-08-04 06:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\dllcache\termsrv.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 442,368 2008-10-02 04:06:05 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_1.db

----a-w 471,040 2008-10-11 03:25:46 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_10.db

----a-w 471,040 2008-10-11 03:25:46 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_12.db

----a-w 471,040 2008-10-25 04:22:46 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_24.db

----a-w 471,040 2008-10-27 04:00:19 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_26.db

----a-w 471,040 2008-11-23 19:13:20 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_11_23.db

----a-w 413,696 2008-09-28 19:19:19 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_9_28.db

----a-w 147,456 2006-04-13 03:44:48 c:\program files\A4Tech\Mouse\bak\Amoumain.exe

----a-w 585,728 2003-05-30 16:42:22 c:\program files\Analog Devices\SoundMAX\bak\Smax4.exe

----a-w 790,528 2003-05-29 23:28:32 c:\program files\Analog Devices\SoundMAX\bak\SMax4PNP.exe

-c--a-w 262,184 2007-01-13 22:46:02 c:\program files\AntiVir PersonalEdition Classic\bak\avgnt.exe

----a-w 81,920 2004-06-15 00:18:22 c:\program files\Common Files\InstallShield\UpdateService\bak\issch.exe

----a-w 28,672 2001-11-29 08:00:00 c:\program files\Creative\SBLive\Program\bak\ADGJDet.exe
----a-w 28,672 2001-11-29 07:00:00 c:\program files\Creative\SBLive\Program\ADGJDet.exe

----a-w 30,208 2005-12-08 06:57:00 c:\program files\CyberLink\PowerDVD\bak\PDVDServ.exe

----a-w 49,152 2006-05-18 19:29:00 c:\program files\CyberLink\PowerDVD\Language\bak\Language.exe

-c--a-w 473,928 2005-11-15 20:12:14 c:\program files\Microsoft AntiSpyware\bak\gcasServ.exe

----a-w 397,312 2005-07-22 01:03:24 c:\program files\SMCWUSBT-G EZ Connect TM g 108 Mbps 802.11g Wireless USB 2.0 Adapter\bak\ACU.exe

-c--a-w 111,816 2004-11-11 04:15:31 c:\program files\Viewpoint\Viewpoint Manager\bak\ViewMgr.exe

-c--a-w 1,580,032 2005-01-29 01:34:58 c:\program files\WebSTAR\WLAN Card Utilities\bak\Center.exe

----a-w 90,112 2000-05-11 08:00:00 c:\windows\bak\UpdReg.EXE

----a-w 155,648 2001-07-09 18:50:42 c:\windows\system32\bak\NeroCheck.exe

-c--a-w 406,016 2004-03-10 23:26:10 c:\windows\system32\bak\PSDrvCheck.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-10-13 1576176]
"LaunchList"="c:\program files\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 145496]
"Aim6"="" [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-04-01 5562368]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-04-01 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-08-18 77824]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-11-20 178688]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 c:\windows\system32\TWEAKUI.CPL]
"pdfSaver3"="" [N/A]
"CTHelper"="CTHELPER.EXE" [2003-08-28 c:\windows\system32\CTHELPER.EXE]
"nwiz"="nwiz.exe" [2005-04-01 c:\windows\system32\nwiz.exe]
"NWEReboot"="" [N/A]
"LFAgent"="" [N/A]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-27 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-10-13 21:58 352256 c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= vdrcodec.dll
"VIDC.MJPG"= Pvmjpg30.dll
"VIDC.PIM1"= pclepim1.dll
"VIDC.PIXL"= pclepixl.dll
"VIDC.NTN1"= Nuvision.ax
"msacm.ctmp3"= c:\windows\system32\ctmp3.acm
"VIDC.MJPX"= PICVideo MJPEG Codec

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AresChatServer"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Morpheus\\Morpheus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\umi.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"27693:TCP"= 27693:TCP:SolidNetworkManager
"27693:UDP"= 27693:UDP:SolidNetworkManager
"32397:TCP"= 32397:TCP:*:Disabled:SolidNetworkManager
"32397:UDP"= 32397:UDP:*:Disabled:SolidNetworkManager

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)

R1 SSHDRV65;SSHDRV65;\??\c:\windows\system32\drivers\SSHDRV65.sys [2005-06-15 120320]
R1 SSHDRV85;SSHDRV85;\??\c:\windows\system32\drivers\SSHDRV85.sys [2002-01-02 78848]
R2 ACDaemon;ArcSoft Connect Daemon;c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-09-23 109056]
R2 LF30FS;LF30FS;\??\c:\program files\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [2004-11-19 101488]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-11-23 24652]
R3 LVRS;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs.sys [2008-07-12 628760]
R3 uscbs109;uscbs109;c:\windows\system32\DRIVERS\uscbs109.sys [2005-12-05 8672]
R3 uscsc109;uscsc109;c:\windows\system32\DRIVERS\uscsc109.sys [2005-12-05 102336]
S2 VRDVC20;Sony VRD-VC20 [Video Capture];c:\windows\system32\Drivers\VRDVC20X.SYS [2006-02-14 02:25:02 31104]
S3 AR5523;Atheros USB Wireless Network Adapter Service;c:\windows\system32\DRIVERS\ar5523.sys []
S3 asbp2poa;asbp2poa; []
S3 ASNDIS5;ASNDIS5 Protocol Driver;\??\c:\windows\system32\ASNDIS5.SYS [2007-01-13 16269]
S3 ATHFMWDL;Atheros USB Wireless Adapter Bootloader driver;c:\windows\system32\Drivers\ATHFMWDL.sys []
S3 NUVision;Pinnacle LINX;c:\windows\system32\DRIVERS\NUVision.sys [2006-09-19 136352]
S3 SjyPkt;SjyPkt;\??\c:\windows\System32\Drivers\SjyPkt.sys [2007-05-10 13532]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17906ce3-fe56-11d5-99a5-806d6172696f}]
\Shell\AutoRun\command - rundll32.exe url.dll,FileProtocolHandler START.HTM
.
Contents of the 'Scheduled Tasks' folder

2008-09-30 c:\windows\Tasks\Best.job
- c:\documents and settings\Eric\Desktop\Shrek_1_and_2_dvd_rip_s_eng_XviD.torrent []

2008-11-30 c:\windows\Tasks\friday.job
- c:\documents and settings\Eric\My Documents\My Music\My Playlists\Country.wpl [2008-10-01 17:24]

2008-12-01 c:\windows\Tasks\one.job
- c:\documents and settings\Eric\My Documents\My Music\My Playlists\Now.wpl [2008-09-13 19:27]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Eric\Application Data\Mozilla\Firefox\Profiles\5t724z67.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.com/
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-01 16:21:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(892)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ZoneLabs\vsmon.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\MsPMSPSv.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\msiexec.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2008-12-01 16:28:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-01 22:27:51

Pre-Run: 51,267,923,968 bytes free
Post-Run: 51,440,910,336 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

358 --- E O F --- 2007-08-26 06:47:50

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
Hello.
A few leftovers to get.

Now open a new notepad file.
Input this into the notepad file:

File::
c:\windows\Internet Logs\xDB3.tmp
c:\windows\Internet Logs\xDB2.tmp
c:\windows\Internet Logs\xDB1.tmp
c:\windows\system32\fppsys.exe

Folder::
c:\program files\Viewpoint
c:\documents and settings\All Users\Application Data\Viewpoint

DirLook::
c:\program files\fhuuifg

AWF::
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_1.db
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_10.db
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_12.db
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_24.db
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_26.db
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_11_23.db
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_9_28.db
c:\program files\A4Tech\Mouse\bak\Amoumain.exe
c:\program files\Analog Devices\SoundMAX\bak\Smax4.exe
c:\program files\Analog Devices\SoundMAX\bak\SMax4PNP.exe
C:\program files\AntiVir PersonalEdition Classic\bak\avgnt.exe
c:\program files\Common Files\InstallShield\UpdateService\bak\issch.exe
c:\program files\Creative\SBLive\Program\bak\ADGJDet.exe
c:\program files\CyberLink\PowerDVD\bak\PDVDServ.exe
c:\program files\CyberLink\PowerDVD\Language\bak\Language.exe
c:\program files\Microsoft AntiSpyware\bak\gcasServ.exe
c:\program files\SMCWUSBT-G EZ Connect TM g 108 Mbps 802.11g Wireless USB 2.0 Adapter\bak\ACU.exe
c:\program files\Viewpoint\Viewpoint Manager\bak\ViewMgr.exe
c:\program files\WebSTAR\WLAN Card Utilities\bak\Center.exe
c:\windows\bak\UpdReg.EXE
c:\windows\system32\bak\NeroCheck.exe
c:\windows\system32\bak\PSDrvCheck.exe

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17906ce3-fe56-11d5-99a5-806d6172696f}]


Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help Sfxdaw

This will open combofix.exe again, agree to it's terms and allow it to run, it may want to reboot after it's done. Post the resulting log back here.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help DXwU4
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help VvYDg

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
Alright, I did that. Here is the log report.

ComboFix 08-12-01.01 - Eric 2008-12-01 16:50:40.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.637 [GMT -6:00]
Running from: c:\documents and settings\Eric\Desktop\-Combo-Fix-.exe
Command switches used :: c:\documents and settings\Eric\Desktop\CFscript.txt
* Created a new restore point

FILE ::
c:\windows\Internet Logs\xDB1.tmp
c:\windows\Internet Logs\xDB2.tmp
c:\windows\Internet Logs\xDB3.tmp
c:\windows\system32\fppsys.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Viewpoint
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\config.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\1370BA437EF5D05D058A24D054D8F5229852A4F4.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\25E530C0266043F06DDBF19083992C55D506A67D.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\38CBCADAB1DF0A74CD37BD40BFF0C3F43CC0E15A.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\5A5581E621F635409ED9BD1E1DB0228DD928E72D.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\5D77D966848120E827ECF25D743E9AEA6B68CC1D.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\85344854BEDF85C7E9F0C8F7AB68C9DF167143AA.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\ABBD43425986400A6FE8F86615469618A73E28D6.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\cache.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\D1A57250C5C318DC64EB161B38082AB72920FFF4.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\history.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\locate-akamai.mtx
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\locate.mtz
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\policy-akamai.mtx
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\ServicesRegistry.xml
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\updates-akamai.mtx
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\vdt.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\ComponentRegistry.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\DownLoadHist.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\HostRegistry.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\MetaStreamConfig.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\MTSDownloadSites.txt
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\-205313940.mtj&p2=1&p3=05924506146770111252716023524557&p4=50335505
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\-469794846.mtz
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\1808705174.swf
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\URLCache.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_01\-1930728742.swf
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_01\URLCache.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\-417622574.mts
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\1143604292.swf
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\1478937782.mtj&p2=0&p3=05924506146770111252716023524557&p4=0
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\243401297.swf
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\407034558.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\URLCache.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_03\-1670706830.mtj&p2=0&p3=05924506146770111252716023524557&p4=0
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_03\1888168788.swf
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_03\URLCache.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\UpdateVersionList_v2.mtx
c:\program files\Viewpoint
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\program files\Viewpoint\Common\VistaBoot.sdll
c:\program files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\ClassIDs.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\ComponentMgr.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\ComponentMgr_0305001C.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\ComponentRegistry.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLArt.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLShell.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\Cursors.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\DataTracking.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\GifReader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\LensFlares.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\MTS3Reader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ObjectMovie.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ServiceComponent.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\SWFView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VectorView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPAudio.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPExtras.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPVideo.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPVideo2.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\WaveletReader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ZoomView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\DownloadedComponents\SWFView_Win.mtj
c:\program files\Viewpoint\Viewpoint Experience Technology\DownLoadHist.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\HostRegistry.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\MtsAxInstaller.exe
c:\program files\Viewpoint\Viewpoint Experience Technology\MTSDownloadSites.txt
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\Cursors.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\JpegReader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\Mts3Reader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\SWFView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\VETscriptInterpreter.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPVideo2.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.xpt
c:\program files\Viewpoint\Viewpoint Manager\VETscriptInterpreter.dll
c:\program files\Viewpoint\Viewpoint Manager\ViewCP.cpl
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\s.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_av.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_cp.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_up.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bg.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bottom.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab_bg.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_off.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_on.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_off.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_on.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vwpt_logo.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\options.ini
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\viewpoint.ico
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\vmctrl.html
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgrCore.dll
c:\program files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream_.dll
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream_0302021C.dll
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream_0302021C_.dll
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream_0305000D.dll
c:\program files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
c:\program files\Viewpoint\Viewpoint Media Player\ComponentMgr_0305000D.dll
c:\program files\Viewpoint\Viewpoint Media Player\ComponentRegistry.ini
c:\program files\Viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\Cursors.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\JpegReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\Mts3Reader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SWFView.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMgr.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPVideo.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPVideo2.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\WaveletReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\DownLoadHist.ini
c:\program files\Viewpoint\Viewpoint Media Player\HostRegistry.ini
c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamConfig.ini
c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
c:\program files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
c:\program files\Viewpoint\Viewpoint Media Player\MTSDownloadSites.txt
c:\windows\Internet Logs\xDB1.tmp
c:\windows\Internet Logs\xDB2.tmp
c:\windows\Internet Logs\xDB3.tmp
c:\windows\system32\fppsys.exe

.
((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.

2008-12-01 16:49 . 2008-12-01 16:53 d-------- C:\-Combo-Fix-
2008-12-01 14:03 . 2008-12-01 14:32 d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-01 14:03 . 2008-12-01 14:03 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-01 14:03 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-01 14:03 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-01 01:07 . 2008-12-01 16:21 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-01 01:07 . 2008-12-01 16:12 1,409 --a------ c:\windows\QTFont.for
2008-11-23 20:36 . 2008-11-23 20:36 d-------- c:\program files\Common Files\Software Update Utility
2008-11-23 20:36 . 2008-11-23 20:36 d-------- c:\documents and settings\All Users\Application Data\acccore
2008-11-23 05:46 . 2008-11-23 05:47 d-------- c:\documents and settings\Eric\Application Data\Move Networks
2008-11-15 03:59 . 2008-11-15 03:59 d-------- c:\program files\Microsoft Silverlight

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

Continued...

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-01 22:50 --------- d-----w c:\program files\SMCWUSBT-G EZ Connect TM g 108 Mbps 802.11g Wireless USB 2.0 Adapter
2008-12-01 22:50 --------- d-----w c:\program files\Microsoft AntiSpyware
2008-12-01 22:21 0 ----a-w c:\windows\system32\drivers\logiflt.iad
2008-12-01 22:19 502,272 ----a-w c:\windows\system32\winlogon.exe
2008-12-01 21:06 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-01 07:49 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2008-12-01 07:00 --------- d-----w c:\program files\Spyware Doctor
2008-12-01 05:17 44,312 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-01 05:17 3,600,416 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\ArcSoft
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\Ahead
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\AdobeUM
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\Acreon
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\acccore
2008-12-01 05:12 295,424 ----a-w c:\windows\system32\termsrv.dll
2008-11-27 11:33 --------- d-----w c:\documents and settings\Eric\Application Data\LimeWire
2008-11-24 04:06 --------- d-----w c:\documents and settings\Eric\Application Data\Azureus
2008-11-24 02:36 --------- d-----w c:\program files\AIM6
2008-11-24 02:35 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-11-24 02:34 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-21 16:43 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-25 04:45 --------- d-----w c:\documents and settings\Eric\Application Data\Vso
2008-10-25 02:23 --------- d-----w c:\program files\LimeWire
2008-10-24 09:42 --------- d-----w c:\program files\Everstrike Software
2008-10-24 09:42 --------- d-----w c:\program files\Common Files\Everstrike Software
2008-10-24 09:38 --------- d-----w c:\program files\Folder Password Protect
2008-10-23 00:15 --------- d-----w c:\program files\Axon Data
2008-10-22 00:49 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle Studio
2008-10-22 00:49 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle
2008-10-22 00:44 --------- d-----w c:\program files\Pinnacle
2008-10-22 00:24 --------- d-----w c:\documents and settings\Eric\Application Data\InstallShield
2008-10-21 22:25 --------- d-----w c:\program files\MagicISO
2008-10-19 21:57 --------- d-----w c:\program files\Ventrilo
2008-10-19 21:57 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-14 03:58 --------- d-----w c:\program files\SUPERAntiSpyware
2008-10-14 03:55 --------- d-----w c:\program files\ZoneAlarmSB
2008-10-14 03:51 --------- d-----w c:\documents and settings\All Users\Application Data\MailFrontier
2008-10-14 03:50 --------- d-----w c:\program files\Zone Labs
2008-10-13 08:36 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-10-13 08:34 --------- d-----w c:\program files\Lavasoft
2008-10-13 08:19 --------- d-----w c:\documents and settings\Eric\Application Data\Lavasoft
2008-10-13 05:56 --------- d-----w c:\program files\AML Products
2008-10-13 04:53 --------- d-----w c:\program files\StreamCast
2008-10-13 03:44 --------- d-----w c:\documents and settings\Eric\Application Data\PC Tools
2008-10-13 02:39 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-12 23:01 --------- d-----w c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition classic
2008-10-12 22:07 --------- d-----w c:\program files\fhuuifg
2008-10-12 22:07 --------- d-----w c:\documents and settings\All Users\Application Data\pkbwfgrq
2008-10-09 00:20 --------- d-----w c:\program files\Morpheus
2008-10-04 02:44 --------- d-----w c:\documents and settings\Eric\Application Data\dvdcss
2007-06-20 07:45 47,360 -c--a-w c:\documents and settings\Eric\Application Data\pcouffin.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of c:\program files\fhuuifg ----

2008-10-12 16:07 106496 --a------ c:\program files\fhuuifg\procsys.dll


------- Sigcheck -------

2008-11-30 23:12 295424 40ffc19a8d4875e9e19cecdc76ef9201 c:\windows\system32\termsrv.dll
2004-08-04 06:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\dllcache\termsrv.dll
.
((((((((((((((((((((((((((((( snapshot@2008-12-01_16.25.36.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-07-09 18:50:42 155,648 ----a-w c:\windows\system32\NeroCheck.exe
- 2008-12-01 22:18:00 62,344 ----a-w c:\windows\system32\perfc009.dat
+ 2008-12-01 22:26:00 62,344 ----a-w c:\windows\system32\perfc009.dat
- 2008-12-01 22:18:00 401,064 ----a-w c:\windows\system32\perfh009.dat
+ 2008-12-01 22:26:00 401,064 ----a-w c:\windows\system32\perfh009.dat
+ 2004-03-10 23:26:10 406,016 -c--a-w c:\windows\system32\PSDrvCheck.exe
+ 2000-05-11 08:00:00 90,112 ----a-w c:\windows\UpdReg.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-10-13 1576176]
"LaunchList"="c:\program files\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 145496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-04-01 5562368]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-04-01 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-08-18 77824]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-11-20 178688]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 c:\windows\system32\TWEAKUI.CPL]
"CTHelper"="CTHELPER.EXE" [2003-08-28 c:\windows\system32\CTHELPER.EXE]
"nwiz"="nwiz.exe" [2005-04-01 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-27 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-10-13 21:58 352256 c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= vdrcodec.dll
"VIDC.MJPG"= Pvmjpg30.dll
"VIDC.PIM1"= pclepim1.dll
"VIDC.PIXL"= pclepixl.dll
"VIDC.NTN1"= Nuvision.ax
"msacm.ctmp3"= c:\windows\system32\ctmp3.acm
"VIDC.MJPX"= PICVideo MJPEG Codec

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AresChatServer"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Morpheus\\Morpheus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\umi.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"27693:TCP"= 27693:TCP:SolidNetworkManager
"27693:UDP"= 27693:UDP:SolidNetworkManager
"32397:TCP"= 32397:TCP:*:Disabled:SolidNetworkManager
"32397:UDP"= 32397:UDP:*:Disabled:SolidNetworkManager

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)

R1 SSHDRV65;SSHDRV65;\??\c:\windows\system32\drivers\SSHDRV65.sys [2005-06-15 120320]
R1 SSHDRV85;SSHDRV85;\??\c:\windows\system32\drivers\SSHDRV85.sys [2002-01-02 78848]
R2 ACDaemon;ArcSoft Connect Daemon;c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-09-23 109056]
R2 LF30FS;LF30FS;\??\c:\program files\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [2004-11-19 101488]
R3 LVRS;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs.sys [2008-07-12 628760]
R3 uscbs109;uscbs109;c:\windows\system32\DRIVERS\uscbs109.sys [2005-12-05 8672]
R3 uscsc109;uscsc109;c:\windows\system32\DRIVERS\uscsc109.sys [2005-12-05 102336]
S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" []
S2 VRDVC20;Sony VRD-VC20 [Video Capture];c:\windows\system32\Drivers\VRDVC20X.SYS [2006-02-14 02:25:02 31104]
S3 AR5523;Atheros USB Wireless Network Adapter Service;c:\windows\system32\DRIVERS\ar5523.sys []
S3 asbp2poa;asbp2poa; []
S3 ASNDIS5;ASNDIS5 Protocol Driver;\??\c:\windows\system32\ASNDIS5.SYS [2007-01-13 16269]
S3 ATHFMWDL;Atheros USB Wireless Adapter Bootloader driver;c:\windows\system32\Drivers\ATHFMWDL.sys []
S3 NUVision;Pinnacle LINX;c:\windows\system32\DRIVERS\NUVision.sys [2006-09-19 136352]
S3 SjyPkt;SjyPkt;\??\c:\windows\System32\Drivers\SjyPkt.sys [2007-05-10 13532]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17906ce3-fe56-11d5-99a5-806d6172696f}]
\Shell\AutoRun\command - rundll32.exe url.dll,FileProtocolHandler START.HTM
.
Contents of the 'Scheduled Tasks' folder

2008-09-30 c:\windows\Tasks\Best.job
- c:\documents and settings\Eric\Desktop\Shrek_1_and_2_dvd_rip_s_eng_XviD.torrent []

2008-11-30 c:\windows\Tasks\friday.job
- c:\documents and settings\Eric\My Documents\My Music\My Playlists\Country.wpl [2008-10-01 17:24]

2008-12-01 c:\windows\Tasks\one.job
- c:\documents and settings\Eric\My Documents\My Music\My Playlists\Now.wpl [2008-09-13 19:27]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Aim6 - (no file)
HKLM-Run-pdfSaver3 - (no file)
HKLM-Run-NWEReboot - (no file)
HKLM-Run-LFAgent - (no file)



**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-01 16:52:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...
scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(892)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Completion time: 2008-12-01 16:54:48
ComboFix-quarantined-files.txt 2008-12-01 22:53:56
ComboFix2.txt 2008-12-01 22:28:03

Pre-Run: 51,429,597,184 bytes free
Post-Run: 51,395,948,544 bytes free

370 --- E O F --- 2007-08-26 06:47:50

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
Hello.
Looking alot better.
One leftover I missed.

Now open a new notepad file.
Input this into the notepad file:

Driver::
Viewpoint Manager Service

Folder::
c:\program files\fhuuifg

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17906ce3-fe56-11d5-99a5-806d6172696f}]


Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help Sfxdaw

This will open combofix.exe again, agree to it's terms and allow it to run, it may want to reboot after it's done. Post the resulting log back here.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help DXwU4
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help VvYDg

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
ComboFix 08-12-01.01 - Eric 2008-12-01 17:08:19.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.654 [GMT -6:00]
Running from: c:\documents and settings\Eric\Desktop\-Combo-Fix-.exe
Command switches used :: c:\documents and settings\Eric\Desktop\CFscript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\fhuuifg
c:\program files\fhuuifg\procsys.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_VIEWPOINT_MANAGER_SERVICE
-------\Service_Viewpoint Manager Service


((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.

2008-12-01 17:07 . 2008-12-01 17:13 d-------- C:\-Combo-Fix-
2008-12-01 14:03 . 2008-12-01 14:32 d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-01 14:03 . 2008-12-01 14:03 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-01 14:03 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-01 14:03 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-01 01:07 . 2008-12-01 17:11 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-01 01:07 . 2008-12-01 17:10 1,409 --a------ c:\windows\QTFont.for
2008-11-23 20:36 . 2008-11-23 20:36 d-------- c:\program files\Common Files\Software Update Utility
2008-11-23 20:36 . 2008-11-23 20:36 d-------- c:\documents and settings\All Users\Application Data\acccore
2008-11-23 05:46 . 2008-11-23 05:47 d-------- c:\documents and settings\Eric\Application Data\Move Networks
2008-11-15 03:59 . 2008-11-15 03:59 d-------- c:\program files\Microsoft Silverlight

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-01 23:11 0 ----a-w c:\windows\system32\drivers\logiflt.iad
2008-12-01 22:53 --------- d-----w c:\program files\SMCWUSBT-G EZ Connect TM g 108 Mbps 802.11g Wireless USB 2.0 Adapter
2008-12-01 22:53 --------- d-----w c:\program files\Microsoft AntiSpyware
2008-12-01 22:19 502,272 ----a-w c:\windows\system32\winlogon.exe
2008-12-01 21:06 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-01 07:49 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2008-12-01 07:00 --------- d-----w c:\program files\Spyware Doctor
2008-12-01 05:17 44,312 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-01 05:17 3,600,416 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\ArcSoft
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\Ahead
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\AdobeUM
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\Acreon
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\acccore
2008-12-01 05:12 295,424 ----a-w c:\windows\system32\termsrv.dll
2008-11-27 11:33 --------- d-----w c:\documents and settings\Eric\Application Data\LimeWire
2008-11-24 04:06 --------- d-----w c:\documents and settings\Eric\Application Data\Azureus
2008-11-24 02:36 --------- d-----w c:\program files\AIM6
2008-11-24 02:35 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-11-24 02:34 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-21 16:43 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-25 04:45 --------- d-----w c:\documents and settings\Eric\Application Data\Vso
2008-10-25 02:23 --------- d-----w c:\program files\LimeWire
2008-10-24 09:42 --------- d-----w c:\program files\Everstrike Software
2008-10-24 09:42 --------- d-----w c:\program files\Common Files\Everstrike Software
2008-10-24 09:38 --------- d-----w c:\program files\Folder Password Protect
2008-10-23 00:15 --------- d-----w c:\program files\Axon Data
2008-10-22 00:49 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle Studio
2008-10-22 00:49 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle
2008-10-22 00:44 --------- d-----w c:\program files\Pinnacle
2008-10-22 00:24 --------- d-----w c:\documents and settings\Eric\Application Data\InstallShield
2008-10-21 22:25 --------- d-----w c:\program files\MagicISO
2008-10-19 21:57 --------- d-----w c:\program files\Ventrilo
2008-10-19 21:57 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-14 03:58 --------- d-----w c:\program files\SUPERAntiSpyware
2008-10-14 03:55 --------- d-----w c:\program files\ZoneAlarmSB
2008-10-14 03:51 --------- d-----w c:\documents and settings\All Users\Application Data\MailFrontier
2008-10-14 03:50 --------- d-----w c:\program files\Zone Labs
2008-10-13 08:36 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-10-13 08:34 --------- d-----w c:\program files\Lavasoft
2008-10-13 08:19 --------- d-----w c:\documents and settings\Eric\Application Data\Lavasoft
2008-10-13 05:56 --------- d-----w c:\program files\AML Products
2008-10-13 04:53 --------- d-----w c:\program files\StreamCast
2008-10-13 03:44 --------- d-----w c:\documents and settings\Eric\Application Data\PC Tools
2008-10-13 02:39 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-12 23:01 --------- d-----w c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition classic
2008-10-12 22:07 --------- d-----w c:\documents and settings\All Users\Application Data\pkbwfgrq
2008-10-09 00:20 --------- d-----w c:\program files\Morpheus
2008-10-04 02:44 --------- d-----w c:\documents and settings\Eric\Application Data\dvdcss
2007-06-20 07:45 47,360 -c--a-w c:\documents and settings\Eric\Application Data\pcouffin.sys
.

------- Sigcheck -------

2008-11-30 23:12 295424 40ffc19a8d4875e9e19cecdc76ef9201 c:\windows\system32\termsrv.dll
2004-08-04 06:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\dllcache\termsrv.dll
.
((((((((((((((((((((((((((((( snapshot@2008-12-01_16.25.36.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-07-09 18:50:42 155,648 ----a-w c:\windows\system32\NeroCheck.exe
- 2008-12-01 22:18:00 62,344 ----a-w c:\windows\system32\perfc009.dat
+ 2008-12-01 22:26:00 62,344 ----a-w c:\windows\system32\perfc009.dat
- 2008-12-01 22:18:00 401,064 ----a-w c:\windows\system32\perfh009.dat
+ 2008-12-01 22:26:00 401,064 ----a-w c:\windows\system32\perfh009.dat
+ 2004-03-10 23:26:10 406,016 -c--a-w c:\windows\system32\PSDrvCheck.exe
+ 2000-05-11 08:00:00 90,112 ----a-w c:\windows\UpdReg.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-10-13 1576176]
"LaunchList"="c:\program files\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 145496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-04-01 5562368]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-04-01 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-08-18 77824]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-11-20 178688]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 c:\windows\system32\TWEAKUI.CPL]
"CTHelper"="CTHELPER.EXE" [2003-08-28 c:\windows\system32\CTHELPER.EXE]
"nwiz"="nwiz.exe" [2005-04-01 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]

Continued...

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-27 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-10-13 21:58 352256 c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= vdrcodec.dll
"VIDC.MJPG"= Pvmjpg30.dll
"VIDC.PIM1"= pclepim1.dll
"VIDC.PIXL"= pclepixl.dll
"VIDC.NTN1"= Nuvision.ax
"msacm.ctmp3"= c:\windows\system32\ctmp3.acm
"VIDC.MJPX"= PICVideo MJPEG Codec

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AresChatServer"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Morpheus\\Morpheus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\umi.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"27693:TCP"= 27693:TCP:SolidNetworkManager
"27693:UDP"= 27693:UDP:SolidNetworkManager
"32397:TCP"= 32397:TCP:*:Disabled:SolidNetworkManager
"32397:UDP"= 32397:UDP:*:Disabled:SolidNetworkManager

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)

R1 SSHDRV65;SSHDRV65;\??\c:\windows\system32\drivers\SSHDRV65.sys [2005-06-15 120320]
R1 SSHDRV85;SSHDRV85;\??\c:\windows\system32\drivers\SSHDRV85.sys [2002-01-02 78848]
R2 ACDaemon;ArcSoft Connect Daemon;c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-09-23 109056]
R2 LF30FS;LF30FS;\??\c:\program files\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [2004-11-19 101488]
R3 LVRS;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs.sys [2008-07-12 628760]
R3 uscbs109;uscbs109;c:\windows\system32\DRIVERS\uscbs109.sys [2005-12-05 8672]
R3 uscsc109;uscsc109;c:\windows\system32\DRIVERS\uscsc109.sys [2005-12-05 102336]
S2 VRDVC20;Sony VRD-VC20 [Video Capture];c:\windows\system32\Drivers\VRDVC20X.SYS [2006-02-14 02:25:02 31104]
S3 AR5523;Atheros USB Wireless Network Adapter Service;c:\windows\system32\DRIVERS\ar5523.sys []
S3 asbp2poa;asbp2poa; []
S3 ASNDIS5;ASNDIS5 Protocol Driver;\??\c:\windows\system32\ASNDIS5.SYS [2007-01-13 16269]
S3 ATHFMWDL;Atheros USB Wireless Adapter Bootloader driver;c:\windows\system32\Drivers\ATHFMWDL.sys []
S3 NUVision;Pinnacle LINX;c:\windows\system32\DRIVERS\NUVision.sys [2006-09-19 136352]
S3 SjyPkt;SjyPkt;\??\c:\windows\System32\Drivers\SjyPkt.sys [2007-05-10 13532]
.
Contents of the 'Scheduled Tasks' folder

2008-09-30 c:\windows\Tasks\Best.job
- c:\documents and settings\Eric\Desktop\Shrek_1_and_2_dvd_rip_s_eng_XviD.torrent []

2008-11-30 c:\windows\Tasks\friday.job
- c:\documents and settings\Eric\My Documents\My Music\My Playlists\Country.wpl [2008-10-01 17:24]

2008-12-01 c:\windows\Tasks\one.job
- c:\documents and settings\Eric\My Documents\My Music\My Playlists\Now.wpl [2008-09-13 19:27]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-01 17:11:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(892)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ZoneLabs\vsmon.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\msiexec.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\AIM6\aim6.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2008-12-01 17:17:03 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-01 23:16:18
ComboFix2.txt 2008-12-01 22:54:49
ComboFix3.txt 2008-12-01 22:28:03

Pre-Run: 51,380,654,080 bytes free
Post-Run: 51,363,348,480 bytes free

245 --- E O F --- 2007-08-26 06:47:50

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
Looks good, how is the machine now?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help DXwU4
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help VvYDg

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
Its running fine now. Thanks for all the help. I really appreciate it. Thank You!

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
Glad to hear it. Smile...
Before I can let you go, we need to get you secured.

Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.
Updating Java:

  • Download the latest version of Java SE Runtime Environment (JRE) 6 Update 10.
  • Select the first option where it says "Java SE Runtime Environment (JRE) 6 Update 10".
  • Click the "Download" button to the right.
  • In the Window that opens, select your platform and language, check the "agree" box, and click Continue.
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add or Remove Programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    - Examples of older versions in Add or Remove Programs:
    - Java 2 Runtime Environment, SE v1.4.2
    - J2SE Runtime Environment 5.0
    - J2SE Runtime Environment 5.0 Update 2
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u10-windows-i586-p.exe that you downloaded to install the newest version.
Please make sure the new version of Java is installed before you run JavaRa.

Please download JavaRa from here

  • First, unzip it.
  • Then run JavaRa.
  • Select English from the drop down menu and press Select.
  • This will open JavaRa.
  • Press Remove older versions
  • Press yes to the prompt.
  • It will make a log file of what it's removed.
  • Copy and paste the log back here.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help DXwU4
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help VvYDg

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
JavaRa Logfile.


JavaRa 1.11 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Mon Dec 01 17:58:24 2008

Found and removed: C:\Program Files\Java\jre1.5.0_11

Found and removed: Software\JavaSoft\Java2D\1.5.0_02

Found and removed: Software\JavaSoft\Java2D\1.5.0_04

Found and removed: Software\JavaSoft\Java2D\1.5.0_11

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D511001

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D511001

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D511001

Found and removed: SOFTWARE\Classes\JavaPlugin.150_11

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_11

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_11

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D511001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D511001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150110}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_11

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_11\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core1.zip

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core2.zip

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core3.zip

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

------------------------------------

Finished reporting.

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
We need to make a new restore point.

To turn off System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (or the Turn off System Restore on all drives check box), and then click OK.
4. Click Yes when you receive the prompt to the turn off System Restore.

Now we need to make a new restore point.
To turn on System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (To turn on System Restore), and then click OK.


Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we are to help you, for your sake we would rather not have repeat customers. Goofy

1) Please navigate to http://windowsupdate.microsoft.com and download all the "critical updates" for Windows. This can patch many of the security holes through which attackers can gain access to your computer.

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates , or get into the habit of checking for Windows updates regularly. I cannot stress enough how important this is.

2) In order to protect yourself against spyware, you should consider installing and running the following free programs:

Ad-Aware SE
A tutorial on using Ad-Aware to remove spyware from your computer may be found here.

Spybot-Search & Destroy
A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

SpywareBlaster
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.

SpywareGuard
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found here.

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

3) Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
http://www.mozilla.org/products/firefox/

4) Also make sure to run your antivirus software regularly, and to keep it up-to-date.

5) Finally, consider maintaining a firewall. Some good free firewalls are Kerio, or
Outpost
A tutorial on understanding and using firewalls may be found here.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

Hopefully this should take care of your problems! Good luck. Big Grin

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help DXwU4
Spyware.Ispynow  Hijackthis log and uninstall log included. Please help VvYDg

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
Alrighty, all set, thanks again for all the help ^_^

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
Since this issue is resolved, this topic is closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

............................................................................................

Please be a GeekPolice fan on Facebook!

Spyware.Ispynow  Hijackthis log and uninstall log included. Please help Lambo-11

Have we helped you? Help us! | Doctor by day, ninja by night.

descriptionSpyware.Ispynow  Hijackthis log and uninstall log included. Please help EmptyRe: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum