Hello Snowhite,
When I gotten on the internet it already found more viruses trying to get in
but i dont know what going on right now, still when i surf on the internet to this page IE7 opens up and goes to this link
http://89.188.16.10/...m...p;lid=&url=or
http://www.winantivi...E365FD69798D1ABI really do appreciate you taking the time reading these reports and helping me getting rid of these viruses
also while surfing on the internet AVG and avast! found these trying to get in
Win32:Agent-EIE [Trj]
Win32:Adware-gen. [Adw] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\xqdmxofb.dll
Win32:Trojan-gen. {Other}
http://l.mezzicodec.....php?b=3024&m=1Win32:Trojan-gen. {Other} C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ET0TQCD0\xc42[1].exe C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ET0TQCD0\xc42[1].exe then it could not accessed it because its being used in another process
http://89.188.16.10/...m...p;lid=&url=Well when i ran Salku.exe (hijackthis.exe) it could not access c:\WINDOWS\system32\drivers\etc\hosts
then it had an error #75
Ok I did a system restore and also gotten to be able to get the log back on
SDFix: Version 1.65
Run by: HP_Administrator - Sat 02/17/2007 @ 19:56:06.65
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
COM+ Messages
MsaSvc
Path:
"C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000272
C:\WINDOWS\system32\msasvc.exe
COM+ Messages Deleted
MsaSvc Deleted
Restoring Windows Registry Entries
Restoring Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\WINDOWS\system32\unsvchosts.lzma - Deleted
C:\WINDOWS\Temp\win*.tmp - Deleted
ADS Check:
C:\WINDOWS\system32
No streams found.
Final Check:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Sierra\\FEARCombat\\FEARMP.exe"="C:\\Program Files\\Sierra\\FEARCombat\\FEARMP.exe:*:Enabled:FEAR Combat"
"C:\\Program Files\\Electronic Arts\\Battlefield 2142 Demo\\BF2142.exe"="C:\\Program Files\\Electronic Arts\\Battlefield 2142 Demo\\BF2142.exe:*:Enabled:Battlefield 2"
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"="C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe:*:Enabled:Battlefield 2"
"C:\\DOCUME~1\\HP_ADM~1\\LOCALS~1\\Temp\\win225.tmp.exe"="C:\\DOCUME~1\\HP_ADM~1\\LOCALS~1\\Temp\\win225.tmp.exe:*:Enabled:win225.tmp"
"C:\\Program Files\\Xfire\\xfire.exe"="C:\\Program Files\\Xfire\\xfire.exe:*:Enabled:Xfire"
"C:\\Program Files\\Wizet\\MapleStory\\Patcher.exe"="C:\\Program Files\\Wizet\\MapleStory\\Patcher.exe:*:Enabled:Patcher MFC ?? ????"
"C:\\Program Files\\BitLord\\BitLord.exe"="C:\\Program Files\\BitLord\\BitLord.exe:*:Enabled:BitLord"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Disabled:Run a DLL as an App"
"C:\\Program Files\\Common Files\\AOL\\1143959304\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1143959304\\ee\\aolsoftware.exe:*:Disabled:AOL Services"
"C:\\Program Files\\Miranda IM\\miranda32.exe"="C:\\Program Files\\Miranda IM\\miranda32.exe:*:Enabled:Miranda IM"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\\iTunes\\iTunes.exe"="%ProgramFiles%\\iTunes\\iTunes.exe:*:enabled:iTunes"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files:
---------------
Backups Folder: - C:\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes :
C:\Program Files\Microsoft Money 2005\mnysl05.dll
C:\Program Files\Microsoft Money 2005\mnysvc05.dll
C:\Program Files\Microsoft Money 2005\unicows.dll
C:\Program Files\Microsoft Money 2005\utilsurf.dll
C:\Program Files\Microsoft Money 2005\mnyupdate!@#@.exe
C:\Program Files\Outlook Express\msimn.exe
C:\swsetup\Monitors\vs15\INSTALL.EXE
C:\swsetup\Monitors\vs15\SETMON.EXE
C:\temp\HPCD.sys
C:\WINDOWS\SMINST\HPCD.sys
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\All Users\DRM\Cache\Indiv03.tmp
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Media Player\MTVN\Downloads\00164981\BIT6E.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL0003.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL0665.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL0854.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL1229.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL1315.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL1386.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL1515.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL2176.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL2320.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL2483.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL2607.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL3251.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL3458.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL3587.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\~WRL3994.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\English 101\~WRL1286.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\English 101\~WRL1889.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\English 101\~WRL2431.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\English 101\~WRL3102.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Fall 2005\English 101\~WRL3774.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Winter2006\ENGLISH 101\~WRL1091.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Winter2006\GEOG 155\~WRL1509.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Freshmen Year\Winter2006\GEOG 155\~WRL3409.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Phi Sigma Kappa\~WRL2551.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0003.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0005.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0038.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0293.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0341.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0683.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0747.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0826.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0955.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1013.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1237.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1256.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1306.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1380.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1483.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1685.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2000.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2291.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2303.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2534.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2620.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2815.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2993.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3173.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3206.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3269.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3355.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3411.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3567.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3608.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3692.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3809.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3823.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3911.tmp
C:\Documents and Settings\HP_Administrator\My Documents\CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3972.tmp
C:\Program Files\Google\BIT469.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\242de31122d71e92d2d0d6941af860fd\download\BIT74F.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\3ca4869d87c4751adb7f48eb66eedb79\BIT5F3.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\661357362ec49ac3cefe1deeadbb5e60\BIT5F8.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\7b49598ac3a72268839b21d372a08418\BIT5F9.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\af10ad1ba106dbeb814878bb0bf7578f\download\BIT758.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\b75a3f1ceb9b6c91137c6b793414016f\BIT5FA.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\bc8f95ed18f1b2993f869ea8fec0f085\BIT5FB.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\cf6034b9352dd852b280611a0edca27e\download\BIT74E.tmp
Finished
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\WINDOWS\Temp\winCC1.tmp.exe - Deleted
C:\WINDOWS\Temp\removalfile.bat - Deleted
C:\WINDOWS\Temp\win*.tmp - Deleted
ADS Check:
C:\WINDOWS\system32
No streams found.
Final Check:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Sierra\\FEARCombat\\FEARMP.exe"="C:\\Program Files\\Sierra\\FEARCombat\\FEARMP.exe:*:Enabled:FEAR Combat"
"C:\\Program Files\\Electronic Arts\\Battlefield 2142 Demo\\BF2142.exe"="C:\\Program Files\\Electronic Arts\\Battlefield 2142 Demo\\BF2142.exe:*:Enabled:Battlefield 2"
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"="C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe:*:Enabled:Battlefield 2"
"C:\\DOCUME~1\\HP_ADM~1\\LOCALS~1\\Temp\\win225.tmp.exe"="C:\\DOCUME~1\\HP_ADM~1\\LOCALS~1\\Temp\\win225.tmp.exe:*:Enabled:win225.tmp"
"C:\\Program Files\\Xfire\\xfire.exe"="C:\\Program Files\\Xfire\\xfire.exe:*:Enabled:Xfire"
"C:\\Program Files\\Wizet\\MapleStory\\Patcher.exe"="C:\\Program Files\\Wizet\\MapleStory\\Patcher.exe:*:Enabled:Patcher MFC ?? ????"
"C:\\Program Files\\BitLord\\BitLord.exe"="C:\\Program Files\\BitLord\\BitLord.exe:*:Enabled:BitLord"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Disabled:Run a DLL as an App"
"C:\\Program Files\\Common Files\\AOL\\1143959304\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1143959304\\ee\\aolsoftware.exe:*:Disabled:AOL Services"
"C:\\Program Files\\Miranda IM\\miranda32.exe"="C:\\Program Files\\Miranda IM\\miranda32.exe:*:Enabled:Miranda IM"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\\iTunes\\iTunes.exe"="%ProgramFiles%\\iTunes\\iTunes.exe:*:enabled:iTunes"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files:
---------------
Backups Folder: - C:\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes :
C:\Program Files\Microsoft Money 2005\mnysl05.dll
C:\Program Files\Microsoft Money 2005\mnysvc05.dll
C:\Program Files\Microsoft Money 2005\unicows.dll
C:\Program Files\Microsoft Money 2005\utilsurf.dll
C:\WINDOWS\system32\gebcd.dll
C:\WINDOWS\system32\wvutsrq.dll
C:\Program Files\Microsoft Money 2005\mnyupdate!@#@.exe
C:\Program Files\Outlook Express\msimn.exe
C:\swsetup\Monitors\vs15\INSTALL.EXE
C:\swsetup\Monitors\vs15\SETMON.EXE
C:\temp\HPCD.sys
C:\WINDOWS\SMINST\HPCD.sys
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\All Users\DRM\Cache\Indiv03.tmp
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Media Player\MTVN\Downloads\00164981\BIT6E.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL0003.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL0665.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL0854.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL1229.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL1315.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL1386.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL1515.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL2176.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL2320.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL2483.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL2607.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL3251.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL3458.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL3587.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\~WRL3994.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\English 101\~WRL1286.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\English 101\~WRL1889.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\English 101\~WRL2431.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\English 101\~WRL3102.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Fall 2005\English 101\~WRL3774.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Winter2006\ENGLISH 101\~WRL1091.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Winter2006\GEOG 155\~WRL1509.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Freshmen Year\Winter2006\GEOG 155\~WRL3409.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Phi Sigma Kappa\~WRL2551.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0003.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0005.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0038.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0293.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0341.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0683.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0747.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0826.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL0955.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1013.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1237.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1256.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1306.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1380.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1483.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL1685.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2000.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2291.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2303.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2534.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2620.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2815.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL2993.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3173.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3206.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3269.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3355.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3411.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3567.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3608.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3692.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3809.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3823.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3911.tmp
C:\Documents and Settings\HP_Administrator\My Documents\2. CSULA\Sophmore Year\Fall 2006\Philosophy 151\~WRL3972.tmp
C:\Program Files\Google\BIT469.tmp
Finished
Logfile of HijackThis v1.99.1
Scan saved at 7:55:14 AM, on 2/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\inKline Global\Modem Booster\ModemBtr.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\program files\common files\installshield\updateservice\issch.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\HJT\Salku.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.h...arm1=seconduserR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0BD2B228-F5E0-486C-A2B4-0646955D5583} - C:\WINDOWS\system32\ssqpq.dll (file missing)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - C:\WINDOWS\system32\lpdapllc.dll
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Modem Booster] C:\Program Files\inKline Global\Modem Booster\ModemBtr.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: MiniEYE-MiniREAD Launch.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone:
http://download.windowsupdate.comO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} -
http://www.fileplane...C_2.3.3.102.cabO16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) -
http://www.mathxl.co...InstallAsst.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebo...otoUploader.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1157093217132O20 - Winlogon Notify: efcyyvw - efcyyvw.dll (file missing)
O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\Stardock\OBJECT~2\WINDOW~1\wbsrv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winjee32 - C:\WINDOWS\SYSTEM32\winjee32.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Also the restore was back when i was using the program you sent me so it reloaded the program and still killed those viruses
Thank You For Reading This Report,
Edited by Salku69, 18 February 2007 - 10:09 AM.