Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
 
Closed TopicStart new topic
Problem with Virtumonde and Win32.WinFixer [RESOLVED]
TaterState
post Sep 9 2007, 09:12 PM
Post #1


Member
**
Posts: 26
From: Boise, ID
OS: Windows XP



Hi, I completed all tasks In the "Before Posting" section. Problem before arriving at your site: The kids formatted drive C: and loaded Windows XP. They failed to process any upgrades. System became sluggish with numerous pop-ups about every 30 seconds. I processed all Windows updates to SP2 then found this site which advises not to put SP2 on top of viruses. Sorry! The problem of pop-ups seems to be gone for now, but each step in your pre-post process identifies malware, viruses, or rootkits still in the system. Thanks in advance for all your help. FYI a Drive E: is present and has some infections. All scans were run on both drives. Home Network sharing currently enabled. Do you recommend stopping all shared files?

HJT:
Logfile of HijackThis v1.99.1
Scan saved at 9:01:41 PM, on 9/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Setup Files\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.EXE /FU "C:\WINDOWS\TEMP\E_S66.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1) on MAIN] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.EXE /FU "C:\WINDOWS\TEMP\E_S3.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1187927644452
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

KASPERSKI
Sunday, September 09, 2007 11:57:22 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 9/09/2007
Kaspersky Anti-Virus database records: 410615


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target Folders
C:\Documents and Settings\
C:\Program Files\
C:\System Volume Information\
C:\WINDOWS\

Scan Statistics
Total number of scanned objects 29784
Number of viruses found 4
Number of infected objects 11
Number of suspicious objects 0
Duration of the scan process 00:23:37

Infected Object Name Virus Name Last Action
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Sarah\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Sarah\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Sarah\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Sarah\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Sarah\Local Settings\History\History.IE5\MSHist012007090920070910\index.dat Object is locked skipped

C:\Documents and Settings\Sarah\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Sarah\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Sarah\NTUSER.DAT.LOG Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP36\A0009107.exe/file2 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped

C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP36\A0009107.exe Inno: infected - 1 skipped

C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP40\A0013313.exe/file05/file2 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped

C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP40\A0013313.exe/file05 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped

C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP40\A0013313.exe/file26 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped

C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP40\A0013313.exe/file39 Infected: not-a-virus:Downloader.Win32.WinFixer.x skipped

C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP40\A0013313.exe Inno: infected - 4 skipped

C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP40\A0013314.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped

C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP41\A0013923.exe/file2 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped

C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP41\A0013923.exe Inno: infected - 1 skipped

C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP41\A0013938.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped

C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP43\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{B653C56E-E8F9-45C7-8555-17CBF50D6CA9}.bin Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped

C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\Temp\Perflib_Perfdata_604.dat Object is locked skipped

C:\WINDOWS\Temp\Perflib_Perfdata_698.dat Object is locked skipped

C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


PANDA ACTIVESCAN

Incident Status Location

Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Sarah\Desktop\ComboFix.exe[nircmd.exe]
Virus:Generic Malware Disinfected C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\AsAgents.dll.vir
Virus:Generic Malware Disinfected C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\fopnl.dll.vir
Virus:Generic Malware Disinfected C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\InstUp.exe.vir
Virus:Generic Malware Disinfected C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\shellext.dll.vir
Spyware:Spyware/Virtumonde Not disinfected C:\qoobox\Quarantine\catchme2007-09-09_ 01126.07.zip[fccdcbc.dll]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\NirCmd.exe

Regards - TaterState
Go to the top of the page
 
+Quote Post
MoNsTeReNeRgY22
post Sep 13 2007, 04:50 PM
Post #2


GeekU Junior
Group Icon
Posts: 2,435
From: California
OS: Windows XP Media Center Editon SP3



Hello and Welcome to Geeks to Go. smile.gif

I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today.

Sorry for the delay, we have been quite busy around here.

Step 1
Download Deckard's System Scanner (DSS) to your Desktop.
  • Close all applications and windows.
  • Double-click on DSS.exe to run it, and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
Extra Note: When running DSS, some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so. Also, it may happen that your Antivirus flags DSS as suspicious. Please allow the Deckard's System Scanner to run and don't let your Antivirus delete it. (In this case, it may be better to temporary disable your Antivirus)


Step 2
Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply along with the DSS log.
  • Click Close to exit the program.
Go to the top of the page
 
+Quote Post
TaterState
post Sep 13 2007, 10:14 PM
Post #3


Member
**
Posts: 26
From: Boise, ID
OS: Windows XP



Thank you for replying. Step 1 and Step 2 ran smoothly, here are the results:
MAIN.TXT
Deckard's System Scanner v20070905.67
Run by Sarah on 2007-09-13 19:49:09
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
7: 2007-09-14 01:49:12 UTC - RP50 - Deckard's System Scanner Restore Point
6: 2007-09-13 03:17:18 UTC - RP49 - System Checkpoint
5: 2007-09-12 03:00:15 UTC - RP48 - Software Distribution Service 3.0
4: 2007-09-11 16:17:18 UTC - RP47 - System Checkpoint
3: 2007-09-10 15:37:25 UTC - RP46 - Installed Ad-Aware 2007


-- First Restore Point --
1: 2007-09-09 20:01:18 UTC - RP44 - With Virus pre Geeks To Go


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as Sarah.exe) -----------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 7:49:21 PM, on 9/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Sarah\Desktop\dss.exe
C:\SETUPF~1\HIJACK~1\Sarah.exe

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.EXE /FU "C:\WINDOWS\TEMP\E_S66.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1) on MAIN] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.EXE /FU "C:\WINDOWS\TEMP\E_S3.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1187927644452
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - c:\program files\superantispyware\saskutil.sys
R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>

S3 catchme - c:\docume~1\sarah\locals~1\temp\catchme.sys (file missing)
S3 SABProcEnum - c:\program files\internet explorer\sabprocenum.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

All services whitelisted.


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Camera
Device ID: USB\VID_046D&PID_08A6&MI_00\6&260B400A&0&0000
Manufacturer:
Name: Camera
PNP Device ID: USB\VID_046D&PID_08A6&MI_00\6&260B400A&0&0000
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Universal Serial Bus (USB) Controller
Device ID: PCI\VEN_1039&DEV_7002&SUBSYS_70021039&REV_00\3&267A616A&0&1B
Manufacturer:
Name: Universal Serial Bus (USB) Controller
PNP Device ID: PCI\VEN_1039&DEV_7002&SUBSYS_70021039&REV_00\3&267A616A&0&1B
Service:


-- Files created between 2007-08-13 and 2007-09-13 -----------------------------

2007-09-12 20:21:57 0 d-------- C:\WINDOWS\LastGood
2007-09-10 09:37:27 0 d-------- C:\Program Files\Lavasoft
2007-09-10 09:37:26 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-09-09 19:52:51 0 d-------- C:\WINDOWS\system32\ActiveScan
2007-09-09 17:34:29 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-09-09 17:34:22 0 d-------- C:\Program Files\SUPERAntiSpyware
2007-09-09 17:34:22 0 d-------- C:\Documents and Settings\Sarah\Application Data\SUPERAntiSpyware.com
2007-09-09 17:33:59 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-09-09 14:48:41 0 d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2007-09-09 14:07:38 0 d-------- C:\Documents and Settings\Sarah\Application Data\Grisoft
2007-09-09 14:07:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-09-09 14:03:20 0 d-------- C:\WINDOWS\pss
2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\Templates
2007-09-09 12:42:09 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2007-09-09 12:42:09 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\Recent
2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2007-09-09 12:42:09 0 d-------- C:\Documents and Settings\Administrator\My Documents
2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2007-09-09 12:42:09 0 d-------- C:\Documents and Settings\Administrator\Favorites
2007-09-09 12:42:09 0 d-------- C:\Documents and Settings\Administrator\Desktop
2007-09-09 12:42:09 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2007-09-09 12:42:09 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2007-09-09 12:42:09 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2007-09-09 12:42:08 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2007-09-09 00:32:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2007-09-09 00:31:47 0 d-------- C:\WINDOWS\system32\PreInstall
2007-09-09 00:31:45 0 d--h----- C:\WINDOWS\$hf_mig$
2007-09-09 00:01:00 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-09-09 00:00:55 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-09-08 23:10:22 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2007-09-08 23:07:22 0 d-------- C:\WINDOWS\Prefetch
2007-09-08 23:07:21 0 d---s---- C:\WINDOWS\system32\Microsoft
2007-09-08 23:03:49 0 d-------- C:\Program Files\Ace Utilities
2007-09-08 22:48:19 0 d-------- C:\WINDOWS\provisioning
2007-09-08 22:48:19 0 d-------- C:\WINDOWS\peernet
2007-09-08 22:46:44 0 d-------- C:\WINDOWS\ServicePackFiles
2007-09-08 22:41:57 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2007-09-08 22:38:56 0 d-------- C:\WINDOWS\EHome
2007-09-08 02:04:38 0 d-------- C:\Documents and Settings\Sarah\Application Data\WinRAR
2007-08-27 15:28:56 0 d-------- C:\Documents and Settings\Sarah\Contacts
2007-08-27 15:28:34 0 d------c- C:\WINDOWS\system32\DRVSTORE
2007-08-27 15:15:50 0 d-------- C:\Documents and Settings\Sarah\Application Data\Help
2007-08-26 21:00:29 26112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-26 21:00:29 0 d--h---c- C:\WINDOWS\$xpsp1hfm$
2007-08-25 23:16:38 0 d-------- C:\Documents and Settings\All Users\Application Data\EPSON
2007-08-25 23:04:21 0 d-------- C:\WINDOWS\system32\FxsTmp
2007-08-25 22:29:44 0 d-------- C:\WINDOWS\system32\bits
2007-08-25 22:11:59 0 d-------- C:\Program Files\EPSON
2007-08-24 15:51:22 0 d-------- C:\Program Files\Electronic Arts
2007-08-24 15:48:15 0 d-------- C:\WINDOWS\RegisteredPackages
2007-08-24 15:47:21 0 d--h----- C:\Program Files\win32Gl
2007-08-23 22:01:04 0 d-------- C:\WINDOWS\Sun
2007-08-23 22:01:04 0 d-------- C:\Documents and Settings\Sarah\Application Data\Sun
2007-08-23 22:00:25 0 d-------- C:\Program Files\Java
2007-08-23 21:58:47 0 d-------- C:\Program Files\Common Files\Java
2007-08-23 21:54:17 0 d-------- C:\WINDOWS\SoftwareDistribution
2007-08-23 21:51:24 0 d---s---- C:\Documents and Settings\Sarah\UserData
2007-08-23 12:05:05 0 d-------- C:\Documents and Settings\Sarah\Application Data\Adobe
2007-08-23 12:04:22 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2007-08-23 12:04:15 0 d-------- C:\Program Files\Common Files\Adobe
2007-08-23 11:27:07 0 d-------- C:\Program Files\uTorrent
2007-08-23 11:27:03 0 d-------- C:\Documents and Settings\Sarah\Application Data\uTorrent
2007-08-23 11:24:56 0 d-------- C:\Program Files\DAEMON Tools
2007-08-23 11:23:40 685816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-08-22 22:52:23 266240 --a------ C:\WINDOWS\CMIUninstall.exe <Not Verified; ; GeneralUninstall Application>
2007-08-22 22:52:23 225280 --a------ C:\WINDOWS\CmiRmRedundDir.exe <Not Verified; ; CmiRmRedundDir Application>
2007-08-22 22:52:23 28672 --a------ C:\WINDOWS\CMIRmDriver.dll
2007-08-22 22:52:23 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-08-22 22:52:23 0 d-------- C:\Program Files\C-Media 3D Audio
2007-08-22 22:43:30 984 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-08-20 00:56:37 315392 --a------ C:\WINDOWS\HideWin.exe <Not Verified; Realtek Semiconductor Corp.; HD Audio Hide windows program>
2007-08-20 00:24:30 0 d-------- C:\Documents and Settings\Sarah\Application Data\Google
2007-08-20 00:15:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Google
2007-08-20 00:15:18 0 d-------- C:\Program Files\Google
2007-08-20 00:15:07 0 d-------- C:\Documents and Settings\Sarah\Application Data\Macromedia
2007-08-19 22:29:46 0 d-------- C:\Program Files\MSN Messenger
2007-08-19 22:12:34 0 d-------- C:\WINDOWS\nview
2007-08-19 22:11:39 0 d-------- C:\Program Files\Common Files\InstallShield
2007-08-19 22:11:32 0 d-------- C:\NVIDIA
2007-08-19 21:45:05 0 d-------- C:\Program Files\Alwil Software
2007-08-19 21:43:31 0 d-------- C:\Setup Files
2007-08-19 21:30:20 0 d--hs---- C:\WINDOWS\Installer
2007-08-19 21:30:18 0 d-------- C:\Documents and Settings\Sarah\Application Data\Identities
2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\Templates
2007-08-19 21:30:11 0 dr------- C:\Documents and Settings\Sarah\Start Menu
2007-08-19 21:30:11 0 dr-h----- C:\Documents and Settings\Sarah\SendTo
2007-08-19 21:30:11 0 dr-h----- C:\Documents and Settings\Sarah\Recent
2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\PrintHood
2007-08-19 21:30:11 1835008 --ah----- C:\Documents and Settings\Sarah\NTUSER.DAT
2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\NetHood
2007-08-19 21:30:11 0 dr------- C:\Documents and Settings\Sarah\My Documents
2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\Local Settings
2007-08-19 21:30:11 0 dr------- C:\Documents and Settings\Sarah\Favorites
2007-08-19 21:30:11 0 d-------- C:\Documents and Settings\Sarah\Desktop
2007-08-19 21:30:11 0 d---s---- C:\Documents and Settings\Sarah\Cookies
2007-08-19 21:30:11 0 dr-h----- C:\Documents and Settings\Sarah\Application Data
2007-08-19 21:28:25 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2007-08-19 21:28:25 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2007-08-19 21:28:25 233472 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2007-08-19 21:28:25 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\LocalService\Cookies
2007-08-19 21:28:25 0 d-------- C:\Documents and Settings\LocalService\Application Data
2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2007-08-19 21:28:24 233472 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2007-08-19 21:25:47 0 d-------- C:\WINDOWS\system32\xircom
2007-08-19 21:25:47 0 d-------- C:\Program Files\microsoft frontpage
2007-08-19 21:25:46 233472 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2007-08-19 21:25:37 0 -rahs---- C:\MSDOS.SYS
2007-08-19 21:25:37 0 -rahs---- C:\IO.SYS
2007-08-19 21:25:37 0 --a------ C:\CONFIG.SYS
2007-08-19 21:25:37 0 --a------ C:\AUTOEXEC.BAT
2007-08-19 21:24:49 0 d--hs---- C:\Documents and Settings\All Users\DRM
2007-08-19 21:24:41 0 dr------- C:\WINDOWS\Offline Web Pages
2007-08-19 21:24:41 0 d---s---- C:\WINDOWS\Downloaded Program Files
2007-08-19 21:23:42 0 d-------- C:\WINDOWS\Registration
2007-08-19 20:41:45 0 d-------- C:\WINDOWS\srchasst
2007-08-19 20:41:40 0 d-------- C:\WINDOWS\system32\DirectX
2007-08-19 20:41:39 0 d-------- C:\WINDOWS\system32\Macromed
2007-08-19 20:41:30 0 d-------- C:\Program Files\Movie Maker
2007-08-19 20:41:09 0 d-------- C:\WINDOWS\system32\Restore
2007-08-19 20:41:04 0 d-------- C:\WINDOWS\PCHEALTH
2007-08-19 20:41:00 0 d---s---- C:\WINDOWS\Tasks
2007-08-19 20:40:57 0 d-------- C:\Program Files\Common Files\MSSoap
2007-08-19 20:40:48 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-08-19 20:40:03 0 d--h----- C:\Program Files\WindowsUpdate
2007-08-19 20:40:03 0 d-------- C:\Program Files\Online Services
2007-08-19 20:39:58 0 d-------- C:\Program Files\Messenger
2007-08-19 20:39:50 0 d-------- C:\Program Files\MSN Gaming Zone
2007-08-19 20:39:43 0 d-------- C:\Program Files\Windows NT
2007-08-19 20:39:35 0 d-------- C:\WINDOWS\system32\MsDtc
2007-08-19 20:39:33 0 d-------- C:\WINDOWS\system32\Com
2007-08-19 19:37:08 0 d--hs---- C:\System Volume Information
2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\Templates
2007-08-19 15:00:12 0 dr------- C:\Documents and Settings\Default User\Start Menu
2007-08-19 15:00:12 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\Recent
2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\NetHood
2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\Default User\My Documents
2007-08-19 15:00:12 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\Default User\Favorites
2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\Default User\Desktop
2007-08-19 15:00:12 0 d---s---- C:\Documents and Settings\Default User\Cookies
2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\All Users\Templates
2007-08-19 15:00:12 0 dr------- C:\Documents and Settings\All Users\Start Menu
2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\All Users\Favorites
2007-08-19 15:00:12 0 dr------- C:\Documents and Settings\All Users\Documents
2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\All Users\Desktop
2007-08-19 14:59:51 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2007-08-19 14:59:51 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2007-08-19 14:59:51 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2007-08-19 14:59:51 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2007-08-19 14:33:23 0 d-------- C:\Program Files\Common Files\ODBC
2007-08-19 14:33:21 0 d-------- C:\Program Files\Common Files\SpeechEngines
2007-08-19 14:33:20 0 dr------- C:\Program Files
2007-08-19 14:33:20 0 d-------- C:\Program Files\Common Files
2007-08-19 14:32:48 0 d-------- C:\WINDOWS\system32\CatRoot2
2007-08-19 14:32:48 0 d-------- C:\WINDOWS\system32\CatRoot
2007-08-19 14:32:27 0 d-------- C:\Documents and Settings
2007-08-19 14:28:02 0 d-------- C:\WINDOWS
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\WinSxS
2007-08-19 14:28:02 0 dr------- C:\WINDOWS\Web
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\twain_32
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\wins
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\wbem
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\usmt
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\spool
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\ShellExt
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\Setup
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\ras
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\oobe
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\npp
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\mui
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\inetsrv
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\IME
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\icsxml
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\ias
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\export
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\drivers
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\drivers\etc
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\drivers\disdn
2007-08-19 14:28:02 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\dhcp
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\config
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\3com_dmi
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\3076
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\2052
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1054
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1042
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1041
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1037
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1033
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1031
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1028
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1025
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\security
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Resources
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\repair
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\mui
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\msapps
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\msagent
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Media
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\java
2007-08-19 14:28:02 0 d--h----- C:\WINDOWS\inf
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\ime
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Help
2007-08-19 14:28:02 0 dr--s---- C:\WINDOWS\Fonts
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Driver Cache
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Debug
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Cursors
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Connection Wizard
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Config
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\AppPatch
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\addins


-- Find3M Report ---------------------------------------------------------------

2007-08-19 15:00:12 62 --ahs---- C:\Documents and Settings\Sarah\Application Data\desktop.ini
2007-06-29 00:43:00 1626112 --a------ C:\WINDOWS\system32\nwiz.exe
2007-06-29 00:43:00 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
2007-06-29 00:43:00 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2007-06-29 00:43:00 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2007-06-29 00:43:00 1474560 --a------ C:\WINDOWS\system32\nview.dll
2007-06-29 00:43:00 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2007-06-29 00:43:00 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
2007-06-29 00:43:00 425984 --a------ C:\WINDOWS\system32\keystone.exe


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [09/06/2007 04:06 AM]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [06/29/2007 12:43 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [07/12/2007 04:00 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 03:06 AM]
"nwiz"="nwiz.exe" [06/29/2007 12:43 AM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [06/29/2007 12:43 AM]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 03:25 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.exe" [05/23/2006 04:00 AM]
"Auto EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1) on MAIN"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.exe" [05/23/2006 04:00 AM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [09/09/2007 08:47 PM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [09/12/2007 08:22 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 09/09/2007 08:47 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\\WINDOWS\\System32\\jkhhe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

*Newly Created Service* - AAWSERVICE
*Newly Created Service* - USNJSVC

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7F991010-A396-8AFF-D343-9DD3B6A205D0}]
C:\Program Files\win32Gl\svhost.exe s



-- End of Deckard's System Scanner: finished at 2007-09-13 19:51:29 ------------



EXTRA.TXT
Deckard's System Scanner v20070905.67
Run by Sarah on 2007-09-13 19:49:09
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
7: 2007-09-14 01:49:12 UTC - RP50 - Deckard's System Scanner Restore Point
6: 2007-09-13 03:17:18 UTC - RP49 - System Checkpoint
5: 2007-09-12 03:00:15 UTC - RP48 - Software Distribution Service 3.0
4: 2007-09-11 16:17:18 UTC - RP47 - System Checkpoint
3: 2007-09-10 15:37:25 UTC - RP46 - Installed Ad-Aware 2007


-- First Restore Point --
1: 2007-09-09 20:01:18 UTC - RP44 - With Virus pre Geeks To Go


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as Sarah.exe) -----------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 7:49:21 PM, on 9/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Sarah\Desktop\dss.exe
C:\SETUPF~1\HIJACK~1\Sarah.exe

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.EXE /FU "C:\WINDOWS\TEMP\E_S66.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1) on MAIN] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.EXE /FU "C:\WINDOWS\TEMP\E_S3.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1187927644452
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - c:\program files\superantispyware\saskutil.sys
R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>

S3 catchme - c:\docume~1\sarah\locals~1\temp\catchme.sys (file missing)
S3 SABProcEnum - c:\program files\internet explorer\sabprocenum.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

All services whitelisted.


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Camera
Device ID: USB\VID_046D&PID_08A6&MI_00\6&260B400A&0&0000
Manufacturer:
Name: Camera
PNP Device ID: USB\VID_046D&PID_08A6&MI_00\6&260B400A&0&0000
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Universal Serial Bus (USB) Controller
Device ID: PCI\VEN_1039&DEV_7002&SUBSYS_70021039&REV_00\3&267A616A&0&1B
Manufacturer:
Name: Universal Serial Bus (USB) Controller
PNP Device ID: PCI\VEN_1039&DEV_7002&SUBSYS_70021039&REV_00\3&267A616A&0&1B
Service:


-- Files created between 2007-08-13 and 2007-09-13 -----------------------------

2007-09-12 20:21:57 0 d-------- C:\WINDOWS\LastGood
2007-09-10 09:37:27 0 d-------- C:\Program Files\Lavasoft
2007-09-10 09:37:26 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-09-09 19:52:51 0 d-------- C:\WINDOWS\system32\ActiveScan
2007-09-09 17:34:29 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-09-09 17:34:22 0 d-------- C:\Program Files\SUPERAntiSpyware
2007-09-09 17:34:22 0 d-------- C:\Documents and Settings\Sarah\Application Data\SUPERAntiSpyware.com
2007-09-09 17:33:59 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-09-09 14:48:41 0 d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2007-09-09 14:07:38 0 d-------- C:\Documents and Settings\Sarah\Application Data\Grisoft
2007-09-09 14:07:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-09-09 14:03:20 0 d-------- C:\WINDOWS\pss
2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\Templates
2007-09-09 12:42:09 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2007-09-09 12:42:09 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\Recent
2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2007-09-09 12:42:09 0 d-------- C:\Documents and Settings\Administrator\My Documents
2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2007-09-09 12:42:09 0 d-------- C:\Documents and Settings\Administrator\Favorites
2007-09-09 12:42:09 0 d-------- C:\Documents and Settings\Administrator\Desktop
2007-09-09 12:42:09 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2007-09-09 12:42:09 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2007-09-09 12:42:09 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2007-09-09 12:42:08 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2007-09-09 00:32:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2007-09-09 00:31:47 0 d-------- C:\WINDOWS\system32\PreInstall
2007-09-09 00:31:45 0 d--h----- C:\WINDOWS\$hf_mig$
2007-09-09 00:01:00 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-09-09 00:00:55 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-09-08 23:10:22 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2007-09-08 23:07:22 0 d-------- C:\WINDOWS\Prefetch
2007-09-08 23:07:21 0 d---s---- C:\WINDOWS\system32\Microsoft
2007-09-08 23:03:49 0 d-------- C:\Program Files\Ace Utilities
2007-09-08 22:48:19 0 d-------- C:\WINDOWS\provisioning
2007-09-08 22:48:19 0 d-------- C:\WINDOWS\peernet
2007-09-08 22:46:44 0 d-------- C:\WINDOWS\ServicePackFiles
2007-09-08 22:41:57 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2007-09-08 22:38:56 0 d-------- C:\WINDOWS\EHome
2007-09-08 02:04:38 0 d-------- C:\Documents and Settings\Sarah\Application Data\WinRAR
2007-08-27 15:28:56 0 d-------- C:\Documents and Settings\Sarah\Contacts
2007-08-27 15:28:34 0 d------c- C:\WINDOWS\system32\DRVSTORE
2007-08-27 15:15:50 0 d-------- C:\Documents and Settings\Sarah\Application Data\Help
2007-08-26 21:00:29 26112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-26 21:00:29 0 d--h---c- C:\WINDOWS\$xpsp1hfm$
2007-08-25 23:16:38 0 d-------- C:\Documents and Settings\All Users\Application Data\EPSON
2007-08-25 23:04:21 0 d-------- C:\WINDOWS\system32\FxsTmp
2007-08-25 22:29:44 0 d-------- C:\WINDOWS\system32\bits
2007-08-25 22:11:59 0 d-------- C:\Program Files\EPSON
2007-08-24 15:51:22 0 d-------- C:\Program Files\Electronic Arts
2007-08-24 15:48:15 0 d-------- C:\WINDOWS\RegisteredPackages
2007-08-24 15:47:21 0 d--h----- C:\Program Files\win32Gl
2007-08-23 22:01:04 0 d-------- C:\WINDOWS\Sun
2007-08-23 22:01:04 0 d-------- C:\Documents and Settings\Sarah\Application Data\Sun
2007-08-23 22:00:25 0 d-------- C:\Program Files\Java
2007-08-23 21:58:47 0 d-------- C:\Program Files\Common Files\Java
2007-08-23 21:54:17 0 d-------- C:\WINDOWS\SoftwareDistribution
2007-08-23 21:51:24 0 d---s---- C:\Documents and Settings\Sarah\UserData
2007-08-23 12:05:05 0 d-------- C:\Documents and Settings\Sarah\Application Data\Adobe
2007-08-23 12:04:22 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2007-08-23 12:04:15 0 d-------- C:\Program Files\Common Files\Adobe
2007-08-23 11:27:07 0 d-------- C:\Program Files\uTorrent
2007-08-23 11:27:03 0 d-------- C:\Documents and Settings\Sarah\Application Data\uTorrent
2007-08-23 11:24:56 0 d-------- C:\Program Files\DAEMON Tools
2007-08-23 11:23:40 685816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-08-22 22:52:23 266240 --a------ C:\WINDOWS\CMIUninstall.exe <Not Verified; ; GeneralUninstall Application>
2007-08-22 22:52:23 225280 --a------ C:\WINDOWS\CmiRmRedundDir.exe <Not Verified; ; CmiRmRedundDir Application>
2007-08-22 22:52:23 28672 --a------ C:\WINDOWS\CMIRmDriver.dll
2007-08-22 22:52:23 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-08-22 22:52:23 0 d-------- C:\Program Files\C-Media 3D Audio
2007-08-22 22:43:30 984 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-08-20 00:56:37 315392 --a------ C:\WINDOWS\HideWin.exe <Not Verified; Realtek Semiconductor Corp.; HD Audio Hide windows program>
2007-08-20 00:24:30 0 d-------- C:\Documents and Settings\Sarah\Application Data\Google
2007-08-20 00:15:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Google
2007-08-20 00:15:18 0 d-------- C:\Program Files\Google
2007-08-20 00:15:07 0 d-------- C:\Documents and Settings\Sarah\Application Data\Macromedia
2007-08-19 22:29:46 0 d-------- C:\Program Files\MSN Messenger
2007-08-19 22:12:34 0 d-------- C:\WINDOWS\nview
2007-08-19 22:11:39 0 d-------- C:\Program Files\Common Files\InstallShield
2007-08-19 22:11:32 0 d-------- C:\NVIDIA
2007-08-19 21:45:05 0 d-------- C:\Program Files\Alwil Software
2007-08-19 21:43:31 0 d-------- C:\Setup Files
2007-08-19 21:30:20 0 d--hs---- C:\WINDOWS\Installer
2007-08-19 21:30:18 0 d-------- C:\Documents and Settings\Sarah\Application Data\Identities
2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\Templates
2007-08-19 21:30:11 0 dr------- C:\Documents and Settings\Sarah\Start Menu
2007-08-19 21:30:11 0 dr-h----- C:\Documents and Settings\Sarah\SendTo
2007-08-19 21:30:11 0 dr-h----- C:\Documents and Settings\Sarah\Recent
2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\PrintHood
2007-08-19 21:30:11 1835008 --ah----- C:\Documents and Settings\Sarah\NTUSER.DAT
2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\NetHood
2007-08-19 21:30:11 0 dr------- C:\Documents and Settings\Sarah\My Documents
2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\Local Settings
2007-08-19 21:30:11 0 dr------- C:\Documents and Settings\Sarah\Favorites
2007-08-19 21:30:11 0 d-------- C:\Documents and Settings\Sarah\Desktop
2007-08-19 21:30:11 0 d---s---- C:\Documents and Settings\Sarah\Cookies
2007-08-19 21:30:11 0 dr-h----- C:\Documents and Settings\Sarah\Application Data
2007-08-19 21:28:25 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2007-08-19 21:28:25 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2007-08-19 21:28:25 233472 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2007-08-19 21:28:25 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\LocalService\Cookies
2007-08-19 21:28:25 0 d-------- C:\Documents and Settings\LocalService\Application Data
2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2007-08-19 21:28:24 233472 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2007-08-19 21:25:47 0 d-------- C:\WINDOWS\system32\xircom
2007-08-19 21:25:47 0 d-------- C:\Program Files\microsoft frontpage
2007-08-19 21:25:46 233472 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2007-08-19 21:25:37 0 -rahs---- C:\MSDOS.SYS
2007-08-19 21:25:37 0 -rahs---- C:\IO.SYS
2007-08-19 21:25:37 0 --a------ C:\CONFIG.SYS
2007-08-19 21:25:37 0 --a------ C:\AUTOEXEC.BAT
2007-08-19 21:24:49 0 d--hs---- C:\Documents and Settings\All Users\DRM
2007-08-19 21:24:41 0 dr------- C:\WINDOWS\Offline Web Pages
2007-08-19 21:24:41 0 d---s---- C:\WINDOWS\Downloaded Program Files
2007-08-19 21:23:42 0 d-------- C:\WINDOWS\Registration
2007-08-19 20:41:45 0 d-------- C:\WINDOWS\srchasst
2007-08-19 20:41:40 0 d-------- C:\WINDOWS\system32\DirectX
2007-08-19 20:41:39 0 d-------- C:\WINDOWS\system32\Macromed
2007-08-19 20:41:30 0 d-------- C:\Program Files\Movie Maker
2007-08-19 20:41:09 0 d-------- C:\WINDOWS\system32\Restore
2007-08-19 20:41:04 0 d-------- C:\WINDOWS\PCHEALTH
2007-08-19 20:41:00 0 d---s---- C:\WINDOWS\Tasks
2007-08-19 20:40:57 0 d-------- C:\Program Files\Common Files\MSSoap
2007-08-19 20:40:48 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-08-19 20:40:03 0 d--h----- C:\Program Files\WindowsUpdate
2007-08-19 20:40:03 0 d-------- C:\Program Files\Online Services
2007-08-19 20:39:58 0 d-------- C:\Program Files\Messenger
2007-08-19 20:39:50 0 d-------- C:\Program Files\MSN Gaming Zone
2007-08-19 20:39:43 0 d-------- C:\Program Files\Windows NT
2007-08-19 20:39:35 0 d-------- C:\WINDOWS\system32\MsDtc
2007-08-19 20:39:33 0 d-------- C:\WINDOWS\system32\Com
2007-08-19 19:37:08 0 d--hs---- C:\System Volume Information
2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\Templates
2007-08-19 15:00:12 0 dr------- C:\Documents and Settings\Default User\Start Menu
2007-08-19 15:00:12 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\Recent
2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\NetHood
2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\Default User\My Documents
2007-08-19 15:00:12 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\Default User\Favorites
2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\Default User\Desktop
2007-08-19 15:00:12 0 d---s---- C:\Documents and Settings\Default User\Cookies
2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\All Users\Templates
2007-08-19 15:00:12 0 dr------- C:\Documents and Settings\All Users\Start Menu
2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\All Users\Favorites
2007-08-19 15:00:12 0 dr------- C:\Documents and Settings\All Users\Documents
2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\All Users\Desktop
2007-08-19 14:59:51 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2007-08-19 14:59:51 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2007-08-19 14:59:51 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2007-08-19 14:59:51 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2007-08-19 14:33:23 0 d-------- C:\Program Files\Common Files\ODBC
2007-08-19 14:33:21 0 d-------- C:\Program Files\Common Files\SpeechEngines
2007-08-19 14:33:20 0 dr------- C:\Program Files
2007-08-19 14:33:20 0 d-------- C:\Program Files\Common Files
2007-08-19 14:32:48 0 d-------- C:\WINDOWS\system32\CatRoot2
2007-08-19 14:32:48 0 d-------- C:\WINDOWS\system32\CatRoot
2007-08-19 14:32:27 0 d-------- C:\Documents and Settings
2007-08-19 14:28:02 0 d-------- C:\WINDOWS
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\WinSxS
2007-08-19 14:28:02 0 dr------- C:\WINDOWS\Web
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\twain_32
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\wins
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\wbem
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\usmt
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\spool
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\ShellExt
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\Setup
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\ras
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\oobe
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\npp
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\mui
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\inetsrv
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\IME
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\icsxml
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\ias
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\export
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\drivers
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\drivers\etc
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\drivers\disdn
2007-08-19 14:28:02 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\dhcp
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\config
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\3com_dmi
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\3076
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\2052
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1054
2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1042
2007-08-19
Go to the top of the page
 
+Quote Post
TaterState
post Sep 13 2007, 10:20 PM
Post #4


Member
**
Posts: 26
From: Boise, ID
OS: Windows XP



Sorry, I didn't realize part of the first post got ignored. Here's the snipped file and the Scan log missing from above

EXTRA.TXT (complete file)
Deckard's System Scanner v20070905.67
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: AMD Athlon™ XP 3000+
Percentage of Memory in Use: 40%
Physical Memory (total/avail): 1023.36 MiB / 605.48 MiB
Pagefile Memory (total/avail): 2461.72 MiB / 2121.63 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1963.26 MiB

A: is Removable (Unformatted)
C: is Fixed (NTFS) - 27.95 GiB total, 17.18 GiB free.
D: is CDROM (No Media)
E: is Fixed (NTFS) - 232.88 GiB total, 136.72 GiB free.
F: is CDROM (No Media)
P: is Network (NTFS)

\\.\PHYSICALDRIVE1 - WDC WD2500JB-00REA0 - 232.88 GiB - 1 partition
\PARTITION0 - Installable File System - 232.88 GiB - E:

\\.\PHYSICALDRIVE0 - WDC WD300AB-00BVA0 - 27.95 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 27.95 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

AV: avast! antivirus 4.7.1043 [VPS 000774-5] v4.7.1043 (ALWIL Software) Disabled

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Sarah\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=UPSTAIRS
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Sarah
LOGONSERVER=\\UPSTAIRS
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0a00
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Sarah\LOCALS~1\Temp
TMP=C:\DOCUME~1\Sarah\LOCALS~1\Temp
USERDOMAIN=UPSTAIRS
USERNAME=Sarah
USERPROFILE=C:\Documents and Settings\Sarah
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

Sarah (admin)
Administrator (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
Ace Utilities --> "C:\Program Files\Ace Utilities\uninstall.exe"
Ad-Aware 2007 --> MsiExec.exe /X{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Flash Player ActiveX --> C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81000000003}
avast! Antivirus --> rundll32 C:\PROGRA~1\ALWILS~1\Avast4\Setup\setiface.dll,RunSetup
AVG Anti-Spyware 7.5 --> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
C-Media 3D Audio --> C:\WINDOWS\CMIUnInstall.exe
C-Media WDM Audio Driver --> C:\WINDOWS\system32\cmirmdrv.exe
EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
getPlus®_ocx --> rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\inf\GETPLUSo.INF, DefaultUninstall
Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
HijackThis 1.99.1 --> C:\DOCUME~1\Sarah\LOCALS~1\Temp\Rar$EX00.078\HijackThis.exe /uninstall
Java™ 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Kaspersky Online Scanner --> C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
Need for Speed™ Carbon --> C:\Program Files\Electronic Arts\Need for Speed Carbon\EAUninstall.exe
NVIDIA Drivers --> C:\WINDOWS\System32\nvudisp.exe UninstallGUI
Panda ActiveScan --> C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Windows Live Messenger --> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type264 / Success
Event Submitted/Written: 09/10/2007 08:54:48 AM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.

Event Record #/Type258 / Success
Event Submitted/Written: 09/10/2007 08:50:45 AM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.

Event Record #/Type257 / Warning
Event Submitted/Written: 09/10/2007 08:13:47 AM
Event ID/Source: 1015 / EvntAgnt
Event Description:
TraceLevel parameter not located in registry;
Default trace level used is 32.

Event Record #/Type256 / Warning
Event Submitted/Written: 09/10/2007 08:13:47 AM
Event ID/Source: 1003 / EvntAgnt
Event Description:
TraceFileName parameter not located in registry;
Default trace file used is .

Event Record #/Type255 / Warning
Event Submitted/Written: 09/10/2007 08:13:46 AM
Event ID/Source: 32068 / Microsoft Fax
Event Description:
The outgoing routing rule is not valid because it cannot find a valid device. The outgoing faxes that use this rule will not be routed. Verify that the targeted device or devices (if routed to a group of devices) is connected and installed correctly, and turned on. If routed to a group, verify that the group is configured correctly.
Country/region code: '*'
Area code: '*'



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type1294 / Error
Event Submitted/Written: 09/11/2007 00:15:29 PM
Event ID/Source: 59 / SideBySide
Event Description:
Generate Activation Context failed for C:\Program Files\Ace Utilities\MFC80.DLL.
Reference error message: The operation completed successfully.
.

Event Record #/Type1293 / Error
Event Submitted/Written: 09/11/2007 00:15:29 PM
Event ID/Source: 59 / SideBySide
Event Description:
Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC.
Reference error message: The referenced assembly is not installed on your system.
.

Event Record #/Type1292 / Error
Event Submitted/Written: 09/11/2007 00:15:29 PM
Event ID/Source: 32 / SideBySide
Event Description:
Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.

Event Record #/Type1291 / Error
Event Submitted/Written: 09/11/2007 00:15:29 PM
Event ID/Source: 59 / SideBySide
Event Description:
Generate Activation Context failed for C:\Program Files\Ace Utilities\MFC80.DLL.
Reference error message: The operation completed successfully.
.

Event Record #/Type1290 / Error
Event Submitted/Written: 09/11/2007 00:15:29 PM
Event ID/Source: 59 / SideBySide
Event Description:
Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC.
Reference error message: The referenced assembly is not installed on your system.
.



-- End of Deckard's System Scanner: finished at 2007-09-13 19:51:29 ------------


SUPERANTISPYWARE Scan Log
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/13/2007 at 09:26 PM

Application Version : 3.9.1008

Core Rules Database Version : 3306
Trace Rules Database Version: 1312

Scan type : Complete Scan
Total Scan Time : 01:30:03

Memory items scanned : 410
Memory threats detected : 0
Registry items scanned : 3618
Registry threats detected : 0
File items scanned : 100562
File threats detected : 0
Go to the top of the page
 
+Quote Post
MoNsTeReNeRgY22
post Sep 14 2007, 07:20 PM
Post #5


GeekU Junior
Group Icon
Posts: 2,435
From: California
OS: Windows XP Media Center Editon SP3



Well I only see one thing, and it is as follows.

I see you have µTorrent installed on your system.
While the program itself is legal, most of the files downloaded with it are not.
Also, quite often the files can be infected with viruses, malware, and other undesirable applications.
I highly recommend uninstalling µTorrent via Add or Remove Programs, but this program is optional for you if you choose to want to keep it.
See HERE for details on P2P file sharing programs.

Other than that, your log looks clean!
Nice job!
How is it running ?
Please use the following suggestion to help prevent reinfection.

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)Now we need to make a new System Restore Point for your PC, please do the following
  • Click Start, Settings, Control Panel
  • Double-click the System icon
  • Click the Performance tab, File System, Troubleshooting tab
  • Check "Turn off System Restore" and click "Apply". Please give a moment as it will delete the old System Restore points
  • Then uncheck "Turn off System Restore" which will create a new System Restore point
  • Click OK

I highly recommend downloading the following programs, to keep malware of your computer to begin with.
The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.

SUPERAntiSpyware - A very powerful tool which searches and kills malware that infect your system.

SpywareBlaster - Great prevention tool to keep malware from installing on your system.
**Tutorial on installing & using this product can be found HERE**

SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.
**Tutorial on installing & using this product can be found HERE**

IE-SpyAd - Puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
**Tutorial on installing & using this product can be found HERE**

ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out malware that like to reside in the temp folders.

AntiVirus Program An AntiVirus program is a must in today's digital world! I recommend avast! 4 Home Edition, AVG, or Anti-Vir.
DO NOT install more than one antivirus program. They will conflict, and provide less protection, not more.

Firewall A firewall is definitely a must have to protect your computer from hackers. I recommend Comodo, Zone Alarm, or Outpost.
**Tutorial on Firewalls can be found HERE**

Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

You must stay on top of your updates at all times, for the above mentioned applications.

It is vitally important to stay on top of your critical updates provided by microsoft.

And finally a little How did I get infected in the first place?(by Tony Klein)

Good luck and safe surfing smile.gif
Go to the top of the page
 
+Quote Post
TaterState
post Sep 15 2007, 10:13 AM
Post #6


Member
**
Posts: 26
From: Boise, ID
OS: Windows XP



MoNsTeReNeRgY22,
Thanks so much for helping with this issue. I deleted Torrent using Add or Remove after reviewing the file sharing sheet. I then ran Ad-Aware. which found viruses. On closer examination, they were in quarantine folders. From Add or Remove I deleted the programs uploaded during this suport cycle and there was an option to delete the quarantine folder and files. I selected yes. I rebooted and ran a full Ad-Aware scan. Clean!! I then cleaned the registry with a utility, deleted my restore points, and then created a new one. As you know, the difference is amazing. Currently, Ad-Aware will be run frequently, Avast 4 is running continuously, and the modem has a built-in firewall which is PW protected. I spent some time with the TaterTots reviewing some of the additional information you supplied.

Again, thanks to you personally and the entire staff at G2G.

fp in id
Go to the top of the page
 
+Quote Post
MoNsTeReNeRgY22
post Sep 15 2007, 10:32 AM
Post #7


GeekU Junior
Group Icon
Posts: 2,435
From: California
OS: Windows XP Media Center Editon SP3



No Problem!

Glad I could help!
Go to the top of the page
 
+Quote Post
MoNsTeReNeRgY22
post Sep 15 2007, 10:32 AM
Post #8


GeekU Junior
Group Icon
Posts: 2,435
From: California
OS: Windows XP Media Center Editon SP3



Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. smile.gif

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 21st November 2009 - 06:53 AM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising