Normal Mode: Checking Files: Trojan Files Found: C:\WINDOWS\SYSTEM32\WDMIFIL.DLL - Deleted C:\114258~1 - Deleted C:\Documents and Settings\Adam\Local Settings\Temp\winEE.tmp.exe - Deleted C:\Documents and Settings\Adam\Local Settings\Temp\winF0.tmp.exe - Deleted C:\Documents and Settings\Adam\Local Settings\Temp\~fi113.tmp.exe - Deleted Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\Common Files\DriveCleaner 2006 (Rogue.DriveCleaner) -> Quarantined and deleted successfully.

Contents of the 'Scheduled Tasks' folder "2007-06-29 15:47:49 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2007-08-17 19:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job" - C:\PROGRA~1\NORTON~1\NAVW32.exe "2004-06-17 22:50:00 C:\WINDOWS\Tasks\Registration reminder 2.job" - C:\WINDOWS\System32\OOBE\oobebaln.exe System was rebooted successfully.

Music Jukebox\ymetray.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll

Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process

Music Jukebox\ymetray.exe C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe C:\PROGRA~1\\PERSON~1\MpfAgent.exe c:\progra~1\\vso\mcvsftsn.exe C:\Program Files\MySpace\IM\MySpaceIM.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\HijackThis\hijackthis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = R3 - URLSearchHook: Yahoo!

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Does anyone know if Mcafee Virus Scan Enterprise will run scans wle a user is NOT logged into the computer? ...

aurareco.exe Horrible Stuff HJT Log posting prompted by Detective Windows Security Centre Firewall disable HELP REQ! "My Documents" folder opens when Computer is Start Help2Go Detective told me to post spyware/XP/help Hijacked homepage and pop ups galore gmail help Many Problems ActiveXControls/Add-Ons please help PartyPoker Icon on desktop. Attempting to delete C:\WINDOWS\system32\geeby.dllC:\WINDOWS\system32\geeby.dll Could not be deleted.Performing Repairs to the registry.Done!--------------------------------------------------------------------------------Logfile of HijackThis v1.99.1Scan saved at 4:48:32 PM, on 4/16/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running Network : Can I Connect Items To An Ups Unit After The Ups Is Powered On?

HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully. Older versions have vulnerabilities that malware can use to infect your system.

Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support)

When there are insecure or infected computers connected to the Internet, malware spreads faster and more extensively, distributed denial-of-service attacks are easier to launch, spammers have more platforms from which to

C:\WINDOWS\system32\ntoskrnl.exe No streams found. Final Check: Remaining Services: ------------------ Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\WinMX\\WinMX.exe"="C:\\Program Files\\WinMX\\WinMX.exe:*:Enabled:WinMX Application" "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire" "C:\\moove\\_adv.exe"="C:\\moove\\_adv.exe:*:Enabled:Roomancer - moove Online World Client" "C:\\WINDOWS\\system32\\otserv.exe"="C:\\WINDOWS\\system32\\otserv.exe:*:Enabled:otserv" "C:\\Program Files\\AIM95\\aim.exe"="C:\\Program Files\\AIM95\\aim.exe:*:Enabled:AOL Instant Messenger" "C:\\Documents Several functions may not work. C:\WINDOWS\cookies.ini C:\WINDOWS\system32\aprquwdu.dll C:\WINDOWS\system32\cnwymkci.exe C:\WINDOWS\system32\edeeg.bak2 C:\WINDOWS\system32\flgowcfq.exe C:\WINDOWS\system32\jwckhfur.dll C:\WINDOWS\system32\kuoaspgw.dll C:\WINDOWS\system32\nvhfawbe.exe C:\WINDOWS\system32\pnbwmifq.dll C:\WINDOWS\system32\rufhkcwj.ini C:\WINDOWS\system32\udwuqrpa.ini C:\WINDOWS\system32\yhsstvds.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_DOMAINSERVICE -------\DomainService ((((((((((((((((((((((((( Files Created from 2007-08-17 to 2007-09-17 ))))))))))))))))))))))))))))))) . 2007-09-16 19:06 51,200 --a------

Please analyze my Hijack this log.