Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Downloaded something bad from Isohunt...  (Read 21392 times)

0 Members and 1 Guest are viewing this topic.

ChevyDieselPride

    Topic Starter


    Rookie

    Downloaded something bad from Isohunt...
    « on: June 25, 2008, 07:10:45 PM »
    I download alot of stuff all the time and I believe i downloaded a file containing a virus. I have norton anti virus and norton system works which says everything is fine and system is secure.  I can get into the C drive and all the way to the file where everything is downloaded, but the second I open the file where everything is downloaded my computer closes out of every window and all that is shown is the desktop background picture. The icons, the taskbar and anything else is all gone and only my back ground picture is left. But i can still hit control alt delete and it will bring up the Windows Task Manager but it says no apps are being run when there are. I still have internet and everything functions the same as long as i dont go into My Computer. If i access my C drive i have to restart my computer to get everything back on my desktop... Any ideas?
    Thanks for your time

    Also i hooked up my external hard drive and it did the same to me as above...

    ChevyDieselPride

      Topic Starter


      Rookie

      Re: Downloaded something bad from Isohunt...
      « Reply #1 on: June 25, 2008, 07:51:10 PM »
      Anyone?

      Broni


        Mastermind
      • Kraków my love :)
      • Thanked: 614
        • Computer Help Forum
      • Computer: Specs
      • Experience: Experienced
      • OS: Windows 8
      Re: Downloaded something bad from Isohunt...
      « Reply #2 on: June 25, 2008, 07:52:01 PM »
      Can you operate My Computer from Safe Mode?

      ChevyDieselPride

        Topic Starter


        Rookie

        Re: Downloaded something bad from Isohunt...
        « Reply #3 on: June 25, 2008, 07:56:36 PM »
        yes i can.

        I was thinking just wipe out the file where everything is downloaded and that may help but then if its a virus its embedded somewhere else so it wouldnt do much...

        Broni


          Mastermind
        • Kraków my love :)
        • Thanked: 614
          • Computer Help Forum
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 8
        Re: Downloaded something bad from Isohunt...
        « Reply #4 on: June 25, 2008, 08:17:03 PM »
        Quote
        I was thinking just wipe out the file where everything is downloaded and that may help but then if its a virus its embedded somewhere else so it wouldnt do much...
        It won't work.

        Are you able to download, and install programs?

        ChevyDieselPride

          Topic Starter


          Rookie

          Re: Downloaded something bad from Isohunt...
          « Reply #5 on: June 25, 2008, 08:23:39 PM »
          I havent tried downloading a program and installing it. But i tried going to add/remove programs under controls and it did the same thing to me as if i went in my c drive.

          But i was downloading other stuff when this first started and the downloads have completed, just cant run winrar. to them or get to them.

          Think i should try downloading something and installing?

          Broni


            Mastermind
          • Kraków my love :)
          • Thanked: 614
            • Computer Help Forum
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 8
          Re: Downloaded something bad from Isohunt...
          « Reply #6 on: June 25, 2008, 08:26:06 PM »
          Give this a try...

          Print these instructions out.

          1. Download SUPERAntiSpyware Free for Home Users:
          http://www.superantispyware.com/

              * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
              * An icon will be created on your desktop. Double-click that icon to launch the program.
              * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
              * Close SUPERAntiSpyware.

          PHYSICALLY DISCONNECT  FROM THE INTERNET

          Restart computer in Safe Mode.
          To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

              * Open SUPERAntiSpyware.
              * Under "Configuration and Preferences", click the Preferences button.
              * Click the Scanning Control tab.
              * Under Scanner Options make sure the following are checked (leave all others unchecked):
                    o Close browsers before scanning.
                    o Scan for tracking cookies.
                    o Terminate memory threats before quarantining.
              * Click the "Close" button to leave the control center screen.
              * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
              * On the left, make sure you check C:\Fixed Drive.
              * On the right, under "Complete Scan", choose Perform Complete Scan.
              * Click "Next" to start the scan. Please be patient while it scans your computer.
              * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
              * Make sure everything has a checkmark next to it and click "Next".
              * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
              * If asked if you want to reboot, click "Yes".
              * To retrieve the removal information after reboot, launch SUPERAntispyware again.
                    o Click Preferences, then click the Statistics/Logs tab.
                    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
                    o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
                    o Please copy and paste the Scan Log results in your next reply.
              * Click Close to exit the program.
          Post SUPERAntiSpyware log.

          RECONNECT TO THE INTERNET

          RESTART COMPUTER!

          2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

              * Double-click mbam-setup.exe and follow the prompts to install the program.
              * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
              * If an update is found, it will download and install the latest version.
              * Once the program has loaded, select Perform full scan, then click Scan.
              * When the scan is complete, click OK, then Show Results to view the results.
              * Be sure that everything is checked, and click Remove Selected.
              * When completed, a log will open in Notepad.
              * Post the log back here.

          The log can also be found here:
          C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
          Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

          RESTART COMPUTER!

          3. Download HijackThis:
          http://www.snapfiles.com/get/hijackthis.html
          Post HijackThis log.

          ChevyDieselPride

            Topic Starter


            Rookie

            Re: Downloaded something bad from Isohunt...
            « Reply #7 on: June 25, 2008, 08:28:33 PM »
            Thanks for your help, hopefully it works

            ChevyDieselPride

              Topic Starter


              Rookie

              Re: Downloaded something bad from Isohunt...
              « Reply #8 on: June 26, 2008, 10:25:38 PM »
              So Broni,
              ran your advice and now its even worse than when i began... When my computer reboted, my computer got as far as the windows XP screen and then went to a blue screen saying i need to run a manufacturers diagnostic or uninstall recently installed programs, drivers...ect

              I made it through step one of what you told me to do, got to the end and this happened. Now i can only get on in safemode. Do i do the remaining steps in safemode?

              Here my report log:

              SUPERAntiSpyware Scan Log
              http://www.superantispyware.com

              Generated 06/26/2008 at 08:46 PM

              Application Version : 4.15.1000

              Core Rules Database Version : 3492
              Trace Rules Database Version: 1483

              Scan type       : Complete Scan
              Total Scan Time : 01:51:19

              Memory items scanned      : 169
              Memory threats detected   : 2
              Registry items scanned    : 5789
              Registry threats detected : 14
              File items scanned        : 54530
              File threats detected     : 30

              Trojan.Vundo-Variant/Small-GEN
                 C:\WINDOWS\SYSTEM32\MLJYOLKK.DLL
                 C:\WINDOWS\SYSTEM32\MLJYOLKK.DLL
                 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2215AD7-241D-4F05-B05F-AA7B9A16E18C}
                 HKCR\CLSID\{C2215AD7-241D-4F05-B05F-AA7B9A16E18C}
                 HKCR\CLSID\{C2215AD7-241D-4F05-B05F-AA7B9A16E18C}\InprocServer32
                 HKCR\CLSID\{C2215AD7-241D-4F05-B05F-AA7B9A16E18C}\InprocServer32#ThreadingModel
                 Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\mlJYolkk
                 C:\WINDOWS\SYSTEM32\CBXNDUKA.DLL
                 C:\WINDOWS\SYSTEM32\JKKIBRKL.DLL

              Adware.Vundo Variant/Resident
                 C:\WINDOWS\SYSTEM32\YAYYVUUN.DLL
                 C:\WINDOWS\SYSTEM32\YAYYVUUN.DLL

              Adware.Vundo Variant
                 HKLM\Software\Classes\CLSID\{57A52E74-004C-464B-96CC-4DFE5366EA02}
                 HKCR\CLSID\{57A52E74-004C-464B-96CC-4DFE5366EA02}
                 HKCR\CLSID\{57A52E74-004C-464B-96CC-4DFE5366EA02}\InprocServer32
                 HKCR\CLSID\{57A52E74-004C-464B-96CC-4DFE5366EA02}\InprocServer32#ThreadingModel
                 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57A52E74-004C-464B-96CC-4DFE5366EA02}
                 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{57A52E74-004C-464B-96CC-4DFE5366EA02}
                 HKCR\CLSID\{57A52E74-004C-464B-96CC-4DFE5366EA02}

              Adware.Tracking Cookie
                 C:\Documents and Settings\owner\Cookies\owner@advertising[1].txt
                 C:\Documents and Settings\owner\Cookies\owner@imrworldwide[2].txt
                 C:\Documents and Settings\owner\Cookies\owner@questionmarket[1].txt
                 C:\Documents and Settings\owner\Cookies\owner@media6degrees[2].txt
                 C:\Documents and Settings\owner\Cookies\owner@realmedia[1].txt
                 C:\Documents and Settings\owner\Cookies\owner@tacoda[2].txt
                 C:\Documents and Settings\owner\Cookies\[email protected][1].txt
                 C:\Documents and Settings\owner\Cookies\owner@tribalfusion[1].txt
                 C:\Documents and Settings\owner\Cookies\owner@zedo[2].txt
                 C:\Documents and Settings\owner\Cookies\owner@apmebf[2].txt
                 C:\Documents and Settings\owner\Cookies\owner@fastclick[2].txt
                 C:\Documents and Settings\owner\Cookies\[email protected][1].txt
                 C:\Documents and Settings\owner\Cookies\owner@interclick[2].txt
                 C:\Documents and Settings\owner\Cookies\owner@atdmt[2].txt
                 C:\Documents and Settings\owner\Cookies\owner@insightexpressai[2].txt
                 C:\Documents and Settings\owner\Cookies\owner@burstnet[2].txt
                 C:\Documents and Settings\owner\Cookies\[email protected][2].txt
                 C:\Documents and Settings\owner\Cookies\owner@trafficmp[2].txt
                 C:\Documents and Settings\owner\Cookies\owner@adrevolver[2].txt
                 C:\Documents and Settings\owner\Cookies\owner@mediaplex[1].txt
                 C:\Documents and Settings\owner\Cookies\owner@casalemedia[1].txt
                 C:\Documents and Settings\owner\Cookies\[email protected][2].txt
                 C:\Documents and Settings\owner\Cookies\owner@doubleclick[1].txt
                 C:\Documents and Settings\owner\Cookies\[email protected][1].txt
                 C:\Documents and Settings\owner\Cookies\[email protected][2].txt

              Adware.Vundo Variant/Rel
                 HKLM\SOFTWARE\Microsoft\FCOVM
                 HKLM\SOFTWARE\Microsoft\RemoveRP
                 C:\WINDOWS\SYSTEM32\MCRH.TMP


              HELP ME!!!

              Broni


                Mastermind
              • Kraków my love :)
              • Thanked: 614
                • Computer Help Forum
              • Computer: Specs
              • Experience: Experienced
              • OS: Windows 8
              Re: Downloaded something bad from Isohunt...
              « Reply #9 on: June 26, 2008, 10:33:14 PM »
              You couldn't operate in Normal Mode before, so I'm not sure what you mean by things getting worse.
              Your computer seems to be seriously infected, so there is no guarantee we'll be successful, but, please continue running next programs in Safe Mode.

              ChevyDieselPride

                Topic Starter


                Rookie

                Re: Downloaded something bad from Isohunt...
                « Reply #10 on: June 26, 2008, 10:39:44 PM »
                I could run in "normal mode" just not access my c drive... By the way i didnt mean to come off mad at you. Im frustrated with this *censored* thing. Ill try the rest, im very thankful for your help.

                ChevyDieselPride

                  Topic Starter


                  Rookie

                  Re: Downloaded something bad from Isohunt...
                  « Reply #11 on: June 26, 2008, 10:40:30 PM »
                  Also if this doesnt work, what should i do? Take it to best buy to get ripped off and pay 250$ to get it fixed?

                  ChevyDieselPride

                    Topic Starter


                    Rookie

                    Re: Downloaded something bad from Isohunt...
                    « Reply #12 on: June 27, 2008, 04:50:34 PM »
                    Heres the log from the second part:

                    Malwarebytes' Anti-Malware 1.18
                    Database version: 895

                    1:42:42 PM 6/27/2008
                    mbam-log-6-27-2008 (13-42-42).txt

                    Scan type: Full Scan (C:\|)
                    Objects scanned: 91852
                    Time elapsed: 17 minute(s), 22 second(s)

                    Memory Processes Infected: 0
                    Memory Modules Infected: 1
                    Registry Keys Infected: 2
                    Registry Values Infected: 0
                    Registry Data Items Infected: 2
                    Folders Infected: 0
                    Files Infected: 10

                    Memory Processes Infected:
                    (No malicious items detected)

                    Memory Modules Infected:
                    C:\WINDOWS\system32\yayyvuUn.dll (Trojan.Vundo) -> Unloaded module successfully.

                    Registry Keys Infected:
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dac37ffa-3b35-46f9-9218-2409e4d85af2} (Trojan.Vundo) -> Quarantined and deleted successfully.
                    HKEY_CLASSES_ROOT\CLSID\{dac37ffa-3b35-46f9-9218-2409e4d85af2} (Trojan.Vundo) -> Quarantined and deleted successfully.

                    Registry Values Infected:
                    (No malicious items detected)

                    Registry Data Items Infected:
                    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\yayyvuun -> Delete on reboot.
                    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\yayyvuun  -> Delete on reboot.

                    Folders Infected:
                    (No malicious items detected)

                    Files Infected:
                    C:\WINDOWS\system32\yayyvuUn.dll (Trojan.Vundo) -> Delete on reboot.
                    C:\WINDOWS\system32\nUuvyyay.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\WINDOWS\system32\nUuvyyay.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP94\A0014992.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP95\A0014993.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP95\A0014997.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP98\A0021284.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP98\A0021285.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP98\A0024288.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.


                    Theres no change either, still can only start in safemode. Any ideas?

                    Broni


                      Mastermind
                    • Kraków my love :)
                    • Thanked: 614
                      • Computer Help Forum
                    • Computer: Specs
                    • Experience: Experienced
                    • OS: Windows 8
                    Re: Downloaded something bad from Isohunt...
                    « Reply #13 on: June 27, 2008, 06:23:52 PM »
                    ChevyDieselPride
                    Quote
                    By the way i didnt mean to come off mad at you. Im frustrated with this *censored* thing.
                    I fully understand. It may be frustrating. We're trying.
                    Give me fresh HJT log from Safe Mode.

                    Broni


                      Mastermind
                    • Kraków my love :)
                    • Thanked: 614
                      • Computer Help Forum
                    • Computer: Specs
                    • Experience: Experienced
                    • OS: Windows 8
                    Re: Downloaded something bad from Isohunt...
                    « Reply #14 on: June 27, 2008, 06:25:43 PM »
                    Quote
                    what should i do? Take it to best buy to get ripped off and pay 250$ to get it fixed?
                    We're not done here, so hold your horses.

                    evilfantasy

                    • Malware Removal Specialist
                    • Moderator


                    • Genius
                    • Calm like a bomb
                    • Thanked: 493
                    • Experience: Experienced
                    • OS: Windows 11
                    Re: Downloaded something bad from Isohunt...
                    « Reply #15 on: June 27, 2008, 07:02:17 PM »
                    Briguy I have removed both of your posts. You are giving instructions that are inadequate. You have also been given links and instructions on how to join the Malware Removal team at Computer hope. Please respect our guidelines. Thanks.

                    ChevyDieselPride

                      Topic Starter


                      Rookie

                      Re: Downloaded something bad from Isohunt...
                      « Reply #16 on: June 27, 2008, 07:45:23 PM »
                      Briguy
                      http://www.computerhope.com/forum/index.php/topic,46313.0.html
                      Quote
                      If you receive advice from someone other than the approved Malware Removal Specialists, you do so at your own risk. We are not responsible if you take potentially inaccurate/harmful advice from someone who is not a designated helper. Anyone interested in joining the crew must have a good amount of experience and submit references to CBMatt (Chris) in a PM. References will be checked. Others posting advice without approval are subject to have their posts removed immediately as the wrong advice is too risky.


                      Are you wanting me to remove the Malware you had me install?

                      ChevyDieselPride

                        Topic Starter


                        Rookie

                        Re: Downloaded something bad from Isohunt...
                        « Reply #17 on: June 27, 2008, 07:48:53 PM »
                        ChevyDieselPride
                        Quote
                        By the way i didnt mean to come off mad at you. Im frustrated with this d**n thing.
                        I fully understand. It may be frustrating. We're trying.
                        Give me fresh HJT log from Safe Mode.

                        so you want me to download hijackthis?

                        evilfantasy

                        • Malware Removal Specialist
                        • Moderator


                        • Genius
                        • Calm like a bomb
                        • Thanked: 493
                        • Experience: Experienced
                        • OS: Windows 11
                        Re: Downloaded something bad from Isohunt...
                        « Reply #18 on: June 27, 2008, 08:26:51 PM »
                        ChevyDieselPride follow through with Bronis responses. He is an approved Computer Hope Malware Specialist.

                        A new Hijackthis log is what is needed next.

                        ChevyDieselPride

                          Topic Starter


                          Rookie

                          Re: Downloaded something bad from Isohunt...
                          « Reply #19 on: June 27, 2008, 08:39:10 PM »
                          Ok fellas here the Hijackthisreport:

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 7:37:27 PM, on 6/27/2008
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                          Boot mode: Safe mode with network support

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.asu.edu/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
                          O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                          O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                          O2 - BHO: (no name) - {A40C8CFE-B3A1-4431-B096-B8845A9BC573} - C:\WINDOWS\system32\yayyvuUn.dll
                          O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
                          O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
                          O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\ThinkVantage Fingerprint Software\ctlcntr.exe" /startup
                          O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
                          O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
                          O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                          O4 - HKLM\..\Run: [suScheduler] C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER
                          O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
                          O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
                          O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                          O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                          O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                          O4 - HKLM\..\Run: [cssauth] "C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe" silent
                          O4 - HKLM\..\Run: [PDService.exe] "C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe"
                          O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
                          O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
                          O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
                          O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
                          O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
                          O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
                          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                          O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
                          O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks\osCheck.exe"
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                          O4 - HKCU\..\Run: [amsg] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                          O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                          O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe
                          O4 - Global Startup: Bluetooth.lnk = ?
                          O4 - Global Startup: Digital Line Detect.lnk = ?
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                          O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
                          O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
                          O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                          O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
                          O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
                          O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                          O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O11 - Options group: [JAVA_IBM] Java (IBM)
                          O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                          O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
                          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1206561896640
                          O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                          O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
                          O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
                          O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
                          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                          O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                          O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
                          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                          O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                          O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: IPS Core Service (IPSSVC) - Lenovo Ltd. - C:\WINDOWS\system32\IPSSVC.EXE
                          O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                          O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
                          O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
                          O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                          O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                          O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
                          O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                          O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
                          O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
                          O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
                          O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
                          O23 - Service: TVT Scheduler - Unknown owner - C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
                          O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
                          O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe

                          --
                          End of file - 11380 bytes

                          Broni


                            Mastermind
                          • Kraków my love :)
                          • Thanked: 614
                            • Computer Help Forum
                          • Computer: Specs
                          • Experience: Experienced
                          • OS: Windows 8
                          Re: Downloaded something bad from Isohunt...
                          « Reply #20 on: June 27, 2008, 08:50:47 PM »
                          Open HJT, and checkmark:
                          - O2 - BHO: (no name) - {A40C8CFE-B3A1-4431-B096-B8845A9BC573} - C:\WINDOWS\system32\yayyvuUn.dll
                          - O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
                          Click "Fix checked" button.

                          Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

                          Delete yayyvuUn.dll file from C:\WINDOWS\system32

                          Try to restart in Normal Mode.

                          Do you have Windows XP CD?

                          ChevyDieselPride

                            Topic Starter


                            Rookie

                            Re: Downloaded something bad from Isohunt...
                            « Reply #21 on: June 27, 2008, 09:00:08 PM »
                            I believe i have it or have a friend i can get it from

                            Broni


                              Mastermind
                            • Kraków my love :)
                            • Thanked: 614
                              • Computer Help Forum
                            • Computer: Specs
                            • Experience: Experienced
                            • OS: Windows 8
                            Re: Downloaded something bad from Isohunt...
                            « Reply #22 on: June 27, 2008, 09:04:20 PM »
                            Good. Finish instructions from my previous post, first.

                            ChevyDieselPride

                              Topic Starter


                              Rookie

                              Re: Downloaded something bad from Isohunt...
                              « Reply #23 on: June 27, 2008, 09:11:10 PM »

                              Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

                              I cannot find this, i went to tools and there not a folder options. Would it be under something else?

                              Broni


                                Mastermind
                              • Kraków my love :)
                              • Thanked: 614
                                • Computer Help Forum
                              • Computer: Specs
                              • Experience: Experienced
                              • OS: Windows 8
                              Re: Downloaded something bad from Isohunt...
                              « Reply #24 on: June 27, 2008, 09:13:40 PM »
                              Most likely, because of your infection.
                              See, if you can find yayyvuUn.dll file in C:\WINDOWS\system32
                              If so, delete.
                              If not, try to restart in Normal Mode, anyway.

                              ChevyDieselPride

                                Topic Starter


                                Rookie

                                Re: Downloaded something bad from Isohunt...
                                « Reply #25 on: June 27, 2008, 09:19:27 PM »
                                Most likely, because of your infection.
                                See, if you can find yayyvuUn.dll file in C:\WINDOWS\system32
                                If so, delete.
                                If not, try to restart in Normal Mode, anyway.

                                I cant delete it i get a pop up box saying: "Access is denied: Make sure disk is not full, or write protected and that the file is not in use"

                                Broni


                                  Mastermind
                                • Kraków my love :)
                                • Thanked: 614
                                  • Computer Help Forum
                                • Computer: Specs
                                • Experience: Experienced
                                • OS: Windows 8
                                Re: Downloaded something bad from Isohunt...
                                « Reply #26 on: June 27, 2008, 09:24:26 PM »
                                That's fine. Get Unlocker: http://ccollomb.free.fr/unlocker/
                                It'll install under right click menu.
                                After installing Unlocker, right click on yayyvuUn.dll file, click Unlocker. Select Delete from drop-down menu. It won't let you delete, but it'll give you an option to delete on reboot. Select that option.
                                Restart computer, and see, if yayyvuUn.dll file is still there.

                                ChevyDieselPride

                                  Topic Starter


                                  Rookie

                                  Re: Downloaded something bad from Isohunt...
                                  « Reply #27 on: June 27, 2008, 09:41:50 PM »
                                  Well im writing in normal boot up and everything seems to be working fine, just a little lag. Anything else i need to do? Thank you so much for the time you took to help me!

                                  Broni


                                    Mastermind
                                  • Kraków my love :)
                                  • Thanked: 614
                                    • Computer Help Forum
                                  • Computer: Specs
                                  • Experience: Experienced
                                  • OS: Windows 8
                                  Re: Downloaded something bad from Isohunt...
                                  « Reply #28 on: June 27, 2008, 09:43:40 PM »
                                  Hold your horses!
                                  Were you able to delete that file?

                                  ChevyDieselPride

                                    Topic Starter


                                    Rookie

                                    Re: Downloaded something bad from Isohunt...
                                    « Reply #29 on: June 27, 2008, 09:46:06 PM »
                                    Hold your horses!
                                    Were you able to delete that file?

                                    yep i was able to delete the file

                                    Broni


                                      Mastermind
                                    • Kraków my love :)
                                    • Thanked: 614
                                      • Computer Help Forum
                                    • Computer: Specs
                                    • Experience: Experienced
                                    • OS: Windows 8
                                    Re: Downloaded something bad from Isohunt...
                                    « Reply #30 on: June 27, 2008, 09:49:35 PM »
                                    Good, but we're not done here, yet.
                                    At least, you're able to work in Normal Mode, now.
                                    However, some infections won't show in Safe Mode, so we have to re-run couple of programs.
                                    Re-run Malwarebytes. Post its log.
                                    When done, re-run HijackThis, and post its log.

                                    ChevyDieselPride

                                      Topic Starter


                                      Rookie

                                      Re: Downloaded something bad from Isohunt...
                                      « Reply #31 on: June 28, 2008, 03:59:35 PM »
                                      First log:

                                      Malwarebytes' Anti-Malware 1.18
                                      Database version: 895

                                      2:57:25 PM 6/28/2008
                                      mbam-log-6-28-2008 (14-57-21).txt

                                      Scan type: Full Scan (C:\|)
                                      Objects scanned: 95198
                                      Time elapsed: 35 minute(s), 11 second(s)

                                      Memory Processes Infected: 0
                                      Memory Modules Infected: 0
                                      Registry Keys Infected: 0
                                      Registry Values Infected: 0
                                      Registry Data Items Infected: 0
                                      Folders Infected: 0
                                      Files Infected: 4

                                      Memory Processes Infected:
                                      (No malicious items detected)

                                      Memory Modules Infected:
                                      (No malicious items detected)

                                      Registry Keys Infected:
                                      (No malicious items detected)

                                      Registry Values Infected:
                                      (No malicious items detected)

                                      Registry Data Items Infected:
                                      (No malicious items detected)

                                      Folders Infected:
                                      (No malicious items detected)

                                      Files Infected:
                                      C:\Documents and Settings\owner\Application Data\Desktopicon\eBayShortcuts.exe (Trojan.Agent) -> No action taken.
                                      C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP99\A0028502.dll (Trojan.Vundo) -> No action taken.
                                      C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP99\A0028503.dll (Trojan.Vundo) -> No action taken.
                                      C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP99\A0028504.dll (Trojan.Vundo) -> No action taken.

                                      ChevyDieselPride

                                        Topic Starter


                                        Rookie

                                        Re: Downloaded something bad from Isohunt...
                                        « Reply #32 on: June 28, 2008, 04:02:53 PM »
                                        hjtlog:

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 3:01:41 PM, on 6/28/2008
                                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\Program Files\Common Files\Virtual Token\vtserver.exe
                                        C:\WINDOWS\system32\ibmpmsvc.exe
                                        C:\WINDOWS\system32\Ati2evxx.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\system32\Ati2evxx.exe
                                        C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                        C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\WINDOWS\system32\IPSSVC.EXE
                                        C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
                                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                        C:\Program Files\Bonjour\mDNSResponder.exe
                                        C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
                                        C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
                                        C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                        C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\TPHDEXLG.EXE
                                        C:\WINDOWS\system32\TpKmpSVC.exe
                                        C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
                                        C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                        C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
                                        C:\WINDOWS\system32\TpShocks.exe
                                        C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
                                        C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
                                        C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
                                        C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
                                        C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
                                        C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
                                        C:\Program Files\ThinkVantage\AMSG\Amsg.exe
                                        C:\WINDOWS\system32\dla\tfswctrl.exe
                                        C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
                                        C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe
                                        C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe
                                        C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
                                        C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
                                        C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
                                        C:\WINDOWS\system32\rundll32.exe
                                        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                        C:\Program Files\iTunes\iTunesHelper.exe
                                        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                        C:\Program Files\Unlocker\UnlockerAssistant.exe
                                        C:\WINDOWS\system32\ctfmon.exe
                                        C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                        C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                        C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
                                        C:\Program Files\Digital Line Detect\DLG.exe
                                        C:\Program Files\iPod\bin\iPodService.exe
                                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                        C:\Program Files\IBM ThinkVantage\Client Security Solution\pwmgr.exe
                                        C:\Program Files\ThinkPad\ConnectUtilities\AcMurocHlpr.exe
                                        C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe
                                        C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
                                        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                        C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.asu.edu/
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                        O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
                                        O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                        O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                                        O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                                        O2 - BHO: (no name) - {A40C8CFE-B3A1-4431-B096-B8845A9BC573} - C:\WINDOWS\system32\yayyvuUn.dll (file missing)
                                        O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                        O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
                                        O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
                                        O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\ThinkVantage Fingerprint Software\ctlcntr.exe" /startup
                                        O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
                                        O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
                                        O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                                        O4 - HKLM\..\Run: [suScheduler] C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER
                                        O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
                                        O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
                                        O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                                        O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                                        O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                                        O4 - HKLM\..\Run: [cssauth] "C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe" silent
                                        O4 - HKLM\..\Run: [PDService.exe] "C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe"
                                        O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
                                        O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
                                        O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
                                        O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
                                        O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
                                        O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
                                        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                        O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
                                        O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks\osCheck.exe"
                                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                        O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
                                        O4 - HKCU\..\Run: [amsg] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
                                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                        O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                        O4 - Global Startup: Bluetooth.lnk = ?
                                        O4 - Global Startup: Digital Line Detect.lnk = ?
                                        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                                        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                        O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
                                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
                                        O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
                                        O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                                        O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
                                        O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
                                        O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                        O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
                                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O11 - Options group: [JAVA_IBM] Java (IBM)
                                        O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                                        O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
                                        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1206561896640
                                        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                        O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
                                        O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
                                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                        O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                        O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                        O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
                                        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                        O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                                        O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                        O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
                                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                        O23 - Service: IPS Core Service (IPSSVC) - Lenovo Ltd. - C:\WINDOWS\system32\IPSSVC.EXE
                                        O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                                        O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                        O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
                                        O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
                                        O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                        O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                        O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
                                        O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                                        O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
                                        O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
                                        O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
                                        O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
                                        O23 - Service: TVT Scheduler - Unknown owner - C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
                                        O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
                                        O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe

                                        --
                                        End of file - 14176 bytes

                                        ChevyDieselPride

                                          Topic Starter


                                          Rookie

                                          Re: Downloaded something bad from Isohunt...
                                          « Reply #33 on: June 28, 2008, 07:51:17 PM »
                                          Bump

                                          Broni


                                            Mastermind
                                          • Kraków my love :)
                                          • Thanked: 614
                                            • Computer Help Forum
                                          • Computer: Specs
                                          • Experience: Experienced
                                          • OS: Windows 8
                                          Re: Downloaded something bad from Isohunt...
                                          « Reply #34 on: June 28, 2008, 09:01:51 PM »
                                          Your Malwarebytes log shows "No action taken" after each line. You either posted the log from before the scan, or you did something wrong.
                                          Please, repost.

                                          No reason for "bump". We're all volunteers here. We have to work, eat, sleep, take care of kids, and kiss girlfriend/wife, once in a while.

                                          ChevyDieselPride

                                            Topic Starter


                                            Rookie

                                            Re: Downloaded something bad from Isohunt...
                                            « Reply #35 on: June 28, 2008, 09:17:16 PM »
                                            Your Malwarebytes log shows "No action taken" after each line. You either posted the log from before the scan, or you did something wrong.
                                            Please, repost.

                                            No reason for "bump". We're all volunteers here. We have to work, eat, sleep, take care of kids, and kiss girlfriend/wife, once in a while.

                                            I fixed the problems after i copied the log, ill re-run it and post it

                                            Broni


                                              Mastermind
                                            • Kraków my love :)
                                            • Thanked: 614
                                              • Computer Help Forum
                                            • Computer: Specs
                                            • Experience: Experienced
                                            • OS: Windows 8
                                            Re: Downloaded something bad from Isohunt...
                                            « Reply #36 on: June 28, 2008, 09:27:50 PM »
                                            Sounds good.
                                            ...and after you post new Malwarebytes log, I'll need fresh HJT log.

                                            ChevyDieselPride

                                              Topic Starter


                                              Rookie

                                              Re: Downloaded something bad from Isohunt...
                                              « Reply #37 on: June 28, 2008, 09:58:05 PM »
                                              Malware log:
                                              Said no malicious files found

                                              Malwarebytes' Anti-Malware 1.18
                                              Database version: 895

                                              8:57:05 PM 6/28/2008
                                              mbam-log-6-28-2008 (20-57-05).txt

                                              Scan type: Full Scan (C:\|)
                                              Objects scanned: 95408
                                              Time elapsed: 30 minute(s), 10 second(s)

                                              Memory Processes Infected: 0
                                              Memory Modules Infected: 0
                                              Registry Keys Infected: 0
                                              Registry Values Infected: 0
                                              Registry Data Items Infected: 0
                                              Folders Infected: 0
                                              Files Infected: 0

                                              Memory Processes Infected:
                                              (No malicious items detected)

                                              Memory Modules Infected:
                                              (No malicious items detected)

                                              Registry Keys Infected:
                                              (No malicious items detected)

                                              Registry Values Infected:
                                              (No malicious items detected)

                                              Registry Data Items Infected:
                                              (No malicious items detected)

                                              Folders Infected:
                                              (No malicious items detected)

                                              Files Infected:
                                              (No malicious items detected)

                                              ChevyDieselPride

                                                Topic Starter


                                                Rookie

                                                Re: Downloaded something bad from Isohunt...
                                                « Reply #38 on: June 28, 2008, 09:59:03 PM »
                                                HJT LOG:

                                                Logfile of Trend Micro HijackThis v2.0.2
                                                Scan saved at 8:58:22 PM, on 6/28/2008
                                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                                MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                                                Boot mode: Normal

                                                Running processes:
                                                C:\WINDOWS\System32\smss.exe
                                                C:\WINDOWS\system32\winlogon.exe
                                                C:\WINDOWS\system32\services.exe
                                                C:\WINDOWS\system32\lsass.exe
                                                C:\Program Files\Common Files\Virtual Token\vtserver.exe
                                                C:\WINDOWS\system32\ibmpmsvc.exe
                                                C:\WINDOWS\system32\Ati2evxx.exe
                                                C:\WINDOWS\system32\svchost.exe
                                                C:\WINDOWS\System32\svchost.exe
                                                C:\WINDOWS\system32\svchost.exe
                                                C:\WINDOWS\system32\Ati2evxx.exe
                                                C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                                C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                                C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                C:\WINDOWS\system32\spoolsv.exe
                                                C:\WINDOWS\system32\IPSSVC.EXE
                                                C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
                                                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                                C:\Program Files\Bonjour\mDNSResponder.exe
                                                C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
                                                C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                                                C:\WINDOWS\system32\svchost.exe
                                                C:\WINDOWS\Explorer.EXE
                                                C:\WINDOWS\System32\svchost.exe
                                                C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
                                                C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                                C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
                                                C:\WINDOWS\system32\svchost.exe
                                                C:\WINDOWS\System32\TPHDEXLG.EXE
                                                C:\WINDOWS\system32\TpKmpSVC.exe
                                                C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
                                                C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                                C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
                                                C:\WINDOWS\system32\TpShocks.exe
                                                C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
                                                C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
                                                C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
                                                C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
                                                C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
                                                C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
                                                C:\Program Files\ThinkVantage\AMSG\Amsg.exe
                                                C:\WINDOWS\system32\dla\tfswctrl.exe
                                                C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
                                                C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe
                                                C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe
                                                C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
                                                C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
                                                C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
                                                C:\WINDOWS\system32\rundll32.exe
                                                C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                C:\Program Files\iTunes\iTunesHelper.exe
                                                C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                                C:\Program Files\Unlocker\UnlockerAssistant.exe
                                                C:\WINDOWS\system32\ctfmon.exe
                                                C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                                C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                                C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
                                                C:\Program Files\Digital Line Detect\DLG.exe
                                                C:\Program Files\iPod\bin\iPodService.exe
                                                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                                C:\Program Files\IBM ThinkVantage\Client Security Solution\pwmgr.exe
                                                C:\Program Files\ThinkPad\ConnectUtilities\AcMurocHlpr.exe
                                                C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe
                                                C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
                                                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                                C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                                                C:\WINDOWS\System32\svchost.exe
                                                C:\Program Files\Internet Explorer\iexplore.exe
                                                C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
                                                C:\Program Files\Diskeeper Corporation\Diskeeper\DfrgNTFS.exe
                                                C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
                                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.asu.edu/
                                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                                O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
                                                O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                                O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                                                O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                                                O2 - BHO: (no name) - {A40C8CFE-B3A1-4431-B096-B8845A9BC573} - C:\WINDOWS\system32\yayyvuUn.dll (file missing)
                                                O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                                O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
                                                O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
                                                O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\ThinkVantage Fingerprint Software\ctlcntr.exe" /startup
                                                O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
                                                O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
                                                O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                                                O4 - HKLM\..\Run: [suScheduler] C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER
                                                O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
                                                O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
                                                O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                                                O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                                                O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                                                O4 - HKLM\..\Run: [cssauth] "C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe" silent
                                                O4 - HKLM\..\Run: [PDService.exe] "C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe"
                                                O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
                                                O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
                                                O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
                                                O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
                                                O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
                                                O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
                                                O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                                O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
                                                O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks\osCheck.exe"
                                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                                O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
                                                O4 - HKCU\..\Run: [amsg] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
                                                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                                O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                                O4 - Global Startup: Bluetooth.lnk = ?
                                                O4 - Global Startup: Digital Line Detect.lnk = ?
                                                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                                O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                                                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                                O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
                                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
                                                O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
                                                O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                                                O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
                                                O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
                                                O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                                                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                                O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
                                                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                                O11 - Options group: [JAVA_IBM] Java (IBM)
                                                O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                                                O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
                                                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1206561896640
                                                O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                                O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
                                                O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
                                                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                                O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                                O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                                O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
                                                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                                                O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                                O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
                                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                                O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                                O23 - Service: IPS Core Service (IPSSVC) - Lenovo Ltd. - C:\WINDOWS\system32\IPSSVC.EXE
                                                O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                                                O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
                                                O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
                                                O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                                O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                                O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
                                                O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                                                O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
                                                O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
                                                O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
                                                O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
                                                O23 - Service: TVT Scheduler - Unknown owner - C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
                                                O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
                                                O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe

                                                --
                                                End of file - 14408 bytes

                                                Broni


                                                  Mastermind
                                                • Kraków my love :)
                                                • Thanked: 614
                                                  • Computer Help Forum
                                                • Computer: Specs
                                                • Experience: Experienced
                                                • OS: Windows 8
                                                Re: Downloaded something bad from Isohunt...
                                                « Reply #39 on: June 28, 2008, 10:06:09 PM »
                                                Is your Norton subscription current, and is it up to date? It seems like it's only partially running.

                                                ChevyDieselPride

                                                  Topic Starter


                                                  Rookie

                                                  Re: Downloaded something bad from Isohunt...
                                                  « Reply #40 on: June 29, 2008, 03:42:12 PM »
                                                  Yes its up to date and i dont know about the partially running. But ive been reading on here that yall suggest to use another anti virus like AVT8 or something along those lines. did the logs look ok? Is the computer still infected?

                                                  Broni


                                                    Mastermind
                                                  • Kraków my love :)
                                                  • Thanked: 614
                                                    • Computer Help Forum
                                                  • Computer: Specs
                                                  • Experience: Experienced
                                                  • OS: Windows 8
                                                  Re: Downloaded something bad from Isohunt...
                                                  « Reply #41 on: June 29, 2008, 08:50:58 PM »
                                                  *** You need to update Java:
                                                  http://java.sun.com/javase/downloads/index.jsp
                                                  Java Runtime Environment (JRE) 6 Update 6
                                                  Uninstall all previous versions of Java through Add\Remove.

                                                  1. Print this post out, since you won't have an access to it, at some point.

                                                  2. Close all windows, except for HijackThis.

                                                  3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

                                                  - O2 - BHO: (no name) - {A40C8CFE-B3A1-4431-B096-B8845A9BC573} - C:\WINDOWS\system32\yayyvuUn.dll (file missing)
                                                  - *O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                                                  - *O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                                                  - *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                                  - *O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                                  - *O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                                  - *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                                  - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                                  - *O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                                  - O4 - Global Startup: Bluetooth.lnk = ?
                                                  - O4 - Global Startup: Digital Line Detect.lnk = ?
                                                  - *O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                                  - O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present (checkmark this entry if you did not activate the 'Lock homepage from changes' option in some kind of anti-spyware tool)
                                                  - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


                                                  4. Click on Fix checked button.

                                                  5. Restart computer.

                                                  6. Post new HijackThis log.

                                                  ChevyDieselPride

                                                    Topic Starter


                                                    Rookie

                                                    Re: Downloaded something bad from Isohunt...
                                                    « Reply #42 on: June 30, 2008, 07:16:38 PM »
                                                    Got the new java and here the HJT:

                                                    Logfile of Trend Micro HijackThis v2.0.2
                                                    Scan saved at 6:14:25 PM, on 6/30/2008
                                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                                    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                                                    Boot mode: Normal

                                                    Running processes:
                                                    C:\WINDOWS\System32\smss.exe
                                                    C:\WINDOWS\system32\winlogon.exe
                                                    C:\WINDOWS\system32\services.exe
                                                    C:\WINDOWS\system32\lsass.exe
                                                    C:\Program Files\Common Files\Virtual Token\vtserver.exe
                                                    C:\WINDOWS\system32\ibmpmsvc.exe
                                                    C:\WINDOWS\system32\Ati2evxx.exe
                                                    C:\WINDOWS\system32\svchost.exe
                                                    C:\WINDOWS\System32\svchost.exe
                                                    C:\WINDOWS\system32\svchost.exe
                                                    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                                    C:\WINDOWS\system32\Ati2evxx.exe
                                                    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                                    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                    C:\WINDOWS\system32\spoolsv.exe
                                                    C:\WINDOWS\system32\IPSSVC.EXE
                                                    C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
                                                    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                                    C:\Program Files\Bonjour\mDNSResponder.exe
                                                    C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
                                                    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                                                    C:\WINDOWS\system32\svchost.exe
                                                    C:\WINDOWS\System32\svchost.exe
                                                    C:\Program Files\Java\jre6\bin\jqs.exe
                                                    C:\WINDOWS\System32\svchost.exe
                                                    C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
                                                    C:\WINDOWS\System32\svchost.exe
                                                    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                                    C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
                                                    C:\WINDOWS\system32\svchost.exe
                                                    C:\WINDOWS\System32\TPHDEXLG.EXE
                                                    C:\WINDOWS\system32\TpKmpSVC.exe
                                                    C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
                                                    C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
                                                    C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
                                                    C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
                                                    C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe
                                                    C:\Program Files\ThinkPad\ConnectUtilities\AcMurocHlpr.exe
                                                    C:\WINDOWS\Explorer.EXE
                                                    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                                    C:\WINDOWS\system32\TpShocks.exe
                                                    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
                                                    C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
                                                    C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
                                                    C:\WINDOWS\system32\wuauclt.exe
                                                    C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
                                                    C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
                                                    C:\Program Files\ThinkVantage\AMSG\Amsg.exe
                                                    C:\WINDOWS\system32\dla\tfswctrl.exe
                                                    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
                                                    C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe
                                                    C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe
                                                    C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
                                                    C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
                                                    C:\WINDOWS\system32\rundll32.exe
                                                    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
                                                    C:\Program Files\Unlocker\UnlockerAssistant.exe
                                                    C:\Program Files\Java\jre6\bin\jusched.exe
                                                    C:\WINDOWS\system32\ctfmon.exe
                                                    C:\Program Files\IBM ThinkVantage\Client Security Solution\pwmgr.exe
                                                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.asu.edu/
                                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                                    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
                                                    O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                                                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                                    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                                                    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                                                    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                                                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                                    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                                    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                                    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
                                                    O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
                                                    O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\ThinkVantage Fingerprint Software\ctlcntr.exe" /startup
                                                    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
                                                    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
                                                    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                                                    O4 - HKLM\..\Run: [suScheduler] C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER
                                                    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
                                                    O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
                                                    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                                                    O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                                                    O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                                                    O4 - HKLM\..\Run: [cssauth] "C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe" silent
                                                    O4 - HKLM\..\Run: [PDService.exe] "C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe"
                                                    O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
                                                    O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
                                                    O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
                                                    O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
                                                    O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
                                                    O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
                                                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                                    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
                                                    O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks\osCheck.exe"
                                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                                    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
                                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                                    O4 - HKCU\..\Run: [amsg] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
                                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                                    O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
                                                    O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                                                    O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
                                                    O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
                                                    O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                                                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                                    O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
                                                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                                    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                                                    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
                                                    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1206561896640
                                                    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
                                                    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
                                                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                                    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                                    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                                    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
                                                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                                                    O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                                    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
                                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                                    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                                    O23 - Service: IPS Core Service (IPSSVC) - Lenovo Ltd. - C:\WINDOWS\system32\IPSSVC.EXE
                                                    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                                    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                                                    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                    O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
                                                    O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
                                                    O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                                    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                                    O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
                                                    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                                                    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
                                                    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
                                                    O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
                                                    O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
                                                    O23 - Service: TVT Scheduler - Unknown owner - C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
                                                    O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
                                                    O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe

                                                    --
                                                    End of file - 13209 bytes

                                                    Broni


                                                      Mastermind
                                                    • Kraków my love :)
                                                    • Thanked: 614
                                                      • Computer Help Forum
                                                    • Computer: Specs
                                                    • Experience: Experienced
                                                    • OS: Windows 8
                                                    Re: Downloaded something bad from Isohunt...
                                                    « Reply #43 on: June 30, 2008, 10:39:17 PM »
                                                    Your computer is clean

                                                    1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
                                                    Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
                                                    Run CCleaner.

                                                    2. Turn off System Restore:

                                                    - Windows XP:
                                                       1. Click Start.
                                                       2. Right-click the My Computer icon, and then click Properties.
                                                       3. Click the System Restore tab.
                                                       4. Check "Turn off System Restore".
                                                       5. Click Apply.   
                                                       6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
                                                       7. Click OK.
                                                    - Windows Vista:
                                                       1. Click Start.
                                                       2. Right-click the Computer icon, and then click Properties.
                                                       3. Click on System Protection under the Tasks column on the left side
                                                       4. Click on Continue on the "User Account Control" window that pops up
                                                       5. Under the System Protection tab, find Available Disks
                                                       6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                                                       7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                                                       8. Click OK

                                                    3. Restart computer.

                                                    4. Turn System Restore on.

                                                    5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

                                                    6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

                                                    7. Let me know, how your computer is doing.