I did everything you said and here are my logs, and may I say my cp is already acting much better. Thanks a lot and I will donate when this is done,,,,Dave ComboFix 07-10-20.5 - CUSTOMER #1 2007-10-20 19:04:02.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1499 [GMT -5:00]
Running from: C:\Documents and Settings\CUSTOMER #1\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\acdhovjl.dll
C:\WINDOWS\system32\acjyshbq.dll
C:\WINDOWS\system32\afydaiih.ini
C:\WINDOWS\system32\agcrqgnv.ini
C:\WINDOWS\system32\agwuksrq.dll
C:\WINDOWS\system32\ahhgkigc.dll
C:\WINDOWS\system32\ahllvlnm.dll
C:\WINDOWS\system32\ahubcoqc.dll
C:\WINDOWS\system32\ajpnchrv.dll
C:\WINDOWS\system32\aprovqrf.ini
C:\WINDOWS\system32\aqsvuwgr.dll
C:\WINDOWS\system32\asbyaddy.ini
C:\WINDOWS\system32\atqjjdfq.dll
C:\WINDOWS\system32\auivdnrx.ini
C:\WINDOWS\system32\auxkibto.ini
C:\WINDOWS\system32\axgoxmal.dll
C:\WINDOWS\system32\baxfrrxm.dll
C:\WINDOWS\system32\bbxwliog.dll
C:\WINDOWS\system32\bdryrcuk.ini
C:\WINDOWS\system32\beplgrhy.ini
C:\WINDOWS\system32\bhaofgrn.exe
C:\WINDOWS\system32\bhksyowg.dll
C:\WINDOWS\system32\bjulcxqb.ini
C:\WINDOWS\system32\bkwkmjbq.dll
C:\WINDOWS\system32\bmmieifj.dll
C:\WINDOWS\system32\bniwbptr.dll
C:\WINDOWS\system32\boesjedk.dll
C:\WINDOWS\system32\bpsfouqm.dll
C:\WINDOWS\system32\bqxclujb.dll
C:\WINDOWS\system32\bsfpkndo.dll
C:\WINDOWS\system32\bsnyxqcu.dll
C:\WINDOWS\system32\bukascle.dll
C:\WINDOWS\system32\bxqywkvq.dll
C:\WINDOWS\system32\caqikoqr.dll
C:\WINDOWS\system32\cbtfkhev.ini
C:\WINDOWS\system32\ccrahbrx.dll
C:\WINDOWS\system32\cdyplkyh.ini
C:\WINDOWS\system32\cekbbjfy.dll
C:\WINDOWS\system32\celgpito.ini
C:\WINDOWS\system32\cgabxhtw.ini
C:\WINDOWS\system32\cgikghha.tmp
C:\WINDOWS\system32\cgmkobvv.ini
C:\WINDOWS\system32\cguvvdis.dll
C:\WINDOWS\system32\cigjcwnq.dll
C:\WINDOWS\system32\cjvceyqc.ini
C:\WINDOWS\system32\ckppdftt.dll
C:\WINDOWS\system32\clmdfrvm.dll
C:\WINDOWS\system32\cneyntys.dll
C:\WINDOWS\system32\cnqjxfah.dll
C:\WINDOWS\system32\cowyykgw.dll
C:\WINDOWS\system32\cqhwpfle.dll
C:\WINDOWS\system32\cqyecvjc.dll
C:\WINDOWS\system32\cqyxbnty.dll
C:\WINDOWS\system32\crfpepql.ini
C:\WINDOWS\system32\csyluruy.dll
C:\WINDOWS\system32\cwykoife.ini
C:\WINDOWS\system32\cxejhdhh.exe
C:\WINDOWS\system32\cxkcacut.exe
C:\WINDOWS\system32\dbonfdqp.dll
C:\WINDOWS\system32\dcghjvtg.ini
C:\WINDOWS\system32\dcpcsfcy.dll
C:\WINDOWS\system32\ddauokbw.dll
C:\WINDOWS\system32\ddbyrceh.dll
C:\WINDOWS\system32\ddcyw.dll
C:\WINDOWS\system32\ddcyw.dll
C:\WINDOWS\system32\dkttgxtn.dll
C:\WINDOWS\system32\dlkbxnws.dll
C:\WINDOWS\system32\domuedoj.ini
C:\WINDOWS\system32\dpcendmm.ini
C:\WINDOWS\system32\dtetdrpw.dll
C:\WINDOWS\system32\dtxrtdpi.ini
C:\WINDOWS\system32\dwbumtqt.exe
C:\WINDOWS\system32\dwgynwth.dll
C:\WINDOWS\system32\dwjlvbmx.dll
C:\WINDOWS\system32\dxolbmnv.dll
C:\WINDOWS\system32\dyfvhpaj.ini
C:\WINDOWS\system32\ecikolqb.dll
C:\WINDOWS\system32\efgmgxhv.dll
C:\WINDOWS\system32\efiokywc.dll
C:\WINDOWS\system32\efvmqnbr.tmp
C:\WINDOWS\system32\ehdskwde.dll
C:\WINDOWS\system32\ehuubnck.ini
C:\WINDOWS\system32\ejijgecm.dll
C:\WINDOWS\system32\ejoyjxon.dll
C:\WINDOWS\system32\ekethvgl.dll
C:\WINDOWS\system32\elfpwhqc.ini
C:\WINDOWS\system32\emlwfyar.dll
C:\WINDOWS\system32\emquswxg.ini
C:\WINDOWS\system32\eotpston.dll
C:\WINDOWS\system32\eoysodbs.ini
C:\WINDOWS\system32\epbsgcry.exe
C:\WINDOWS\system32\escmnraa.exe
C:\WINDOWS\system32\euxinqok.dll
C:\WINDOWS\system32\evhpcusl.dll
C:\WINDOWS\system32\evljaeos.dll
C:\WINDOWS\system32\fabtfcdm.ini
C:\WINDOWS\system32\fbvmhuds.dll
C:\WINDOWS\system32\fdffoglt.dll
C:\WINDOWS\system32\fdgmdqss.ini
C:\WINDOWS\system32\fdttlcsi.dll
C:\WINDOWS\system32\feycgxyo.exe
C:\WINDOWS\system32\fiebswjb.dll
C:\WINDOWS\system32\fjcwghje.dll
C:\WINDOWS\system32\fknnwlru.dll
C:\WINDOWS\system32\fmubfcvk.dll
C:\WINDOWS\system32\fqcnlmnb.dll
C:\WINDOWS\system32\frhsvpix.dll
C:\WINDOWS\system32\frqvorpa.dll
C:\WINDOWS\system32\frvcddij.dll
C:\WINDOWS\system32\fsoxthtv.dll
C:\WINDOWS\system32\ftulythl.dll
C:\WINDOWS\system32\fukpuxpa.dll
C:\WINDOWS\system32\fwovbcvk.dll
C:\WINDOWS\system32\fwtnfrvn.dll
C:\WINDOWS\system32\fymreclr.dll
C:\WINDOWS\system32\gbufavam.ini
C:\WINDOWS\system32\geltxlar.dll
C:\WINDOWS\system32\ggrqqbbp.dll
C:\WINDOWS\system32\ghkqxwqu.ini
C:\WINDOWS\system32\ghlqfdnu.dll
C:\WINDOWS\system32\ghqurkmb.dll
C:\WINDOWS\system32\gialkswl.dll
C:\WINDOWS\system32\gjunsxqm.dll
C:\WINDOWS\system32\glwchhai.ini
C:\WINDOWS\system32\goilwxbb.ini
C:\WINDOWS\system32\gorcmqhy.dll
C:\WINDOWS\system32\goshceyi.ini
C:\WINDOWS\system32\gpjsmvmk.dll
C:\WINDOWS\system32\gpkfvitr.ini
C:\WINDOWS\system32\gtvjhgcd.dll
C:\WINDOWS\system32\gxwsuqme.dll
C:\WINDOWS\system32\hauqjwqx.dll
C:\WINDOWS\system32\haynamvs.dll
C:\WINDOWS\system32\hbxmynat.dll
C:\WINDOWS\system32\hdqmumkp.dll
C:\WINDOWS\system32\hdsyjgtx.dll
C:\WINDOWS\system32\hfhhvcnp.dll
C:\WINDOWS\system32\hfvkewhp.ini
C:\WINDOWS\system32\hhywljdk.dll
C:\WINDOWS\system32\hiiadyfa.dll
C:\WINDOWS\system32\hkbeanfw.dll
C:\WINDOWS\system32\hklfdwrg.dll
C:\WINDOWS\system32\hmhaijiq.dll
C:\WINDOWS\system32\hmhhxxjv.dll
C:\WINDOWS\system32\hqcttlem.ini
C:\WINDOWS\system32\hqicgyba.dll
C:\WINDOWS\system32\hspnvcsm.dll
C:\WINDOWS\system32\htwnygwd.ini
C:\WINDOWS\system32\huegvkrm.dll
C:\WINDOWS\system32\hvutuajd.dll
C:\WINDOWS\system32\hxoeveso.dll
C:\WINDOWS\system32\hyklpydc.dll
C:\WINDOWS\system32\hytocksq.ini
C:\WINDOWS\system32\iaecflin.dll
C:\WINDOWS\system32\iahhcwlg.dll
C:\WINDOWS\system32\iavtqsmo.ini2
C:\WINDOWS\system32\iavtqsmo.ini2
C:\WINDOWS\system32\iavtqsmo.tmp
C:\WINDOWS\system32\iavtqsmo.tmp
C:\WINDOWS\system32\ibrfieel.dll
C:\WINDOWS\system32\icgjberx.dll
C:\WINDOWS\system32\igubqnmw.ini
C:\WINDOWS\system32\iihfgarf.dll
C:\WINDOWS\system32\iiosjaki.dll
C:\WINDOWS\system32\iknlqget.ini
C:\WINDOWS\system32\ioojkuek.ini
C:\WINDOWS\system32\ioqlrcpj.ini
C:\WINDOWS\system32\ipdtrxtd.dll
C:\WINDOWS\system32\isehbsqe.dll
C:\WINDOWS\system32\itowgehu.dll
C:\WINDOWS\system32\ixjbqtbv.dll
C:\WINDOWS\system32\iyechsog.dll
C:\WINDOWS\system32\japhvfyd.dll
C:\WINDOWS\system32\jbhjhbrk.dll
C:\WINDOWS\system32\jdjrpfdp.dll
C:\WINDOWS\system32\jfieimmb.ini
C:\WINDOWS\system32\jgqbrwll.ini
C:\WINDOWS\system32\jhgvjcvm.exe
C:\WINDOWS\system32\jhrirdpp.ini
C:\WINDOWS\system32\jitwpfwn.ini
C:\WINDOWS\system32\jjnhyelk.dll
C:\WINDOWS\system32\jkfqfstq.dll
C:\WINDOWS\system32\jkhfntjr.dll
C:\WINDOWS\system32\jmlrmivv.ini
C:\WINDOWS\system32\jmtyofun.dll
C:\WINDOWS\system32\jnkvxyhq.ini
C:\WINDOWS\system32\jnraoehk.dll
C:\WINDOWS\system32\jnuwnswy.dll
C:\WINDOWS\system32\jodeumod.dll
C:\WINDOWS\system32\jpcrlqoi.dll
C:\WINDOWS\system32\jpuhtpbp.ini
C:\WINDOWS\system32\jrapbybn.dll
C:\WINDOWS\system32\jucxdfdq.dll
C:\WINDOWS\system32\jykutjmq.ini
C:\WINDOWS\system32\jyqyxfht.dll
C:\WINDOWS\system32\kbfvssdt.dll
C:\WINDOWS\system32\kbgbcbxw.dll
C:\WINDOWS\system32\kbpovhum.dll
C:\WINDOWS\system32\kcnbuuhe.dll
C:\WINDOWS\system32\kdhhmrjq.dll
C:\WINDOWS\system32\kdhyfgjg.exe
C:\WINDOWS\system32\keukjooi.dll
C:\WINDOWS\system32\kfkkgear.dll
C:\WINDOWS\system32\kiiowqbn.ini
C:\WINDOWS\system32\kkktixaq.ini
C:\WINDOWS\system32\klercvdx.ini
C:\WINDOWS\system32\kmoggkhn.dll
C:\WINDOWS\system32\kptgnavt.dll
C:\WINDOWS\system32\kqvjtvuq.dll
C:\WINDOWS\system32\krbhjhbj.ini
C:\WINDOWS\system32\krvcvabs.ini
C:\WINDOWS\system32\kucryrdb.dll
C:\WINDOWS\system32\kuockbll.dll
C:\WINDOWS\system32\kvcfbumf.ini
C:\WINDOWS\system32\kyjubmsp.dll
C:\WINDOWS\system32\lhtylutf.ini
C:\WINDOWS\system32\llbkcouk.ini
C:\WINDOWS\system32\llwrbqgj.dll
C:\WINDOWS\system32\lqpepfrc.dll
C:\WINDOWS\system32\lrllqqjg.dll
C:\WINDOWS\system32\lrororxl.exe
C:\WINDOWS\system32\lsucphve.ini
C:\WINDOWS\system32\lvtxbuqh.dll
C:\WINDOWS\system32\lwbiacnn.dll
C:\WINDOWS\system32\lwfbdilt.dll
C:\WINDOWS\system32\lwqlqyqf.dll
C:\WINDOWS\system32\lwsklaig.ini
C:\WINDOWS\system32\lydbckxl.dll
C:\WINDOWS\system32\lyhyplok.dll
C:\WINDOWS\system32\lyqbnyjt.dll
C:\WINDOWS\system32\mavafubg.dll
C:\WINDOWS\system32\mcdexjuu.dll
C:\WINDOWS\system32\mcegjije.ini
C:\WINDOWS\system32\mdcftbaf.dll
C:\WINDOWS\system32\mdjbotob.dll
C:\WINDOWS\system32\mejburbk.exe
C:\WINDOWS\system32\melttcqh.dll
C:\WINDOWS\system32\mfpkiwis.ini
C:\WINDOWS\system32\mlpgdgac.exe
C:\WINDOWS\system32\mmdnecpd.dll
C:\WINDOWS\system32\mmgvlmvy.dll
C:\WINDOWS\system32\mmllm.bak1
C:\WINDOWS\system32\mmllm.bak1
C:\WINDOWS\system32\mmllm.bak2
C:\WINDOWS\system32\mmllm.bak2
C:\WINDOWS\system32\mmllm.ini
C:\WINDOWS\system32\mmllm.ini
C:\WINDOWS\system32\mmllm.ini2
C:\WINDOWS\system32\mmllm.ini2
C:\WINDOWS\system32\mmllm.tmp
C:\WINDOWS\system32\mmllm.tmp
C:\WINDOWS\system32\mmyreqoy.dll
C:\WINDOWS\system32\mnlvllha.ini
C:\WINDOWS\system32\moachcvn.ini
C:\WINDOWS\system32\mqefhplv.ini
C:\WINDOWS\system32\mqkpqcxr.ini
C:\WINDOWS\system32\mqxsnujg.ini
C:\WINDOWS\system32\mrkvgeuh.ini
C:\WINDOWS\system32\mvhghsrp.dll
C:\WINDOWS\system32\nbqwoiik.dll
C:\WINDOWS\system32\ndgtyseq.dll
C:\WINDOWS\system32\nedjccat.ini
C:\WINDOWS\system32\ngytqaae.dll
C:\WINDOWS\system32\nihkjslb.dll
C:\WINDOWS\system32\nilfceai.ini
C:\WINDOWS\system32\nkvnusxv.ini
C:\WINDOWS\system32\nlwsqhqg.dll
C:\WINDOWS\system32\nolvlsva.dll
C:\WINDOWS\system32\noxjyoje.ini
C:\WINDOWS\system32\npfngbmu.dll
C:\WINDOWS\system32\npsxyfev.ini
C:\WINDOWS\system32\nrkbgrjn.dll
C:\WINDOWS\system32\nrmffnqp.ini
C:\WINDOWS\system32\nrmuwjaq.dll
C:\WINDOWS\system32\nrwxvcio.ini
C:\WINDOWS\system32\nsvdprhd.dll
C:\WINDOWS\system32\nufoytmj.ini
C:\WINDOWS\system32\nujbekdx.ini
C:\WINDOWS\system32\numthdus.exe
C:\WINDOWS\system32\nupriicy.ini
C:\WINDOWS\system32\nvchcaom.dll
C:\WINDOWS\system32\nwfpwtij.dll
C:\WINDOWS\system32\nymqyvrr.dll
C:\WINDOWS\system32\nypybrwv.ini
C:\WINDOWS\system32\oalshaci.dll
C:\WINDOWS\system32\odnkpfsb.ini
C:\WINDOWS\system32\ognrpgbt.dll
C:\WINDOWS\system32\ohufgsir.dll
C:\WINDOWS\system32\oicvxwrn.dll
C:\WINDOWS\system32\oklvmfkj.dll
C:\WINDOWS\system32\omsqtvai.dll
C:\WINDOWS\system32\onifxcwy.dll
C:\WINDOWS\system32\orixfpau.dll
C:\WINDOWS\system32\otbikxua.dll
C:\WINDOWS\system32\otenuvyp.dll
C:\WINDOWS\system32\otipglec.dll
C:\WINDOWS\system32\otuseetu.dll
C:\WINDOWS\system32\ovvbemce.exe
C:\WINDOWS\system32\pbbqqrgg.ini
C:\WINDOWS\system32\pbpthupj.dll
C:\WINDOWS\system32\pbxpatyu.ini
C:\WINDOWS\system32\pgvynhfd.dll
C:\WINDOWS\system32\phwekvfh.dll
C:\WINDOWS\system32\pkmumqdh.ini
C:\WINDOWS\system32\ppdrirhj.dll
C:\WINDOWS\system32\pqnffmrn.dll
C:\WINDOWS\system32\prshghvm.ini
C:\WINDOWS\system32\psmbujyk.ini
C:\WINDOWS\system32\pxbdbkyx.dll
C:\WINDOWS\system32\pyvuneto.ini
C:\WINDOWS\system32\qajwumrn.ini
C:\WINDOWS\system32\qaxitkkk.dll
C:\WINDOWS\system32\qbhsyjca.ini
C:\WINDOWS\system32\qbjmkwkb.ini
C:\WINDOWS\system32\qbujtcon.dll
C:\WINDOWS\system32\qdfdxcuj.ini
C:\WINDOWS\system32\qesytgdn.ini
C:\WINDOWS\system32\qflijmau.ini
C:\WINDOWS\system32\qgajtsvw.dll
C:\WINDOWS\system32\qgfqqejf.dll
C:\WINDOWS\system32\qgndvlbr.dll
C:\WINDOWS\system32\qgrjhwya.dll
C:\WINDOWS\system32\qhyxvknj.dll
C:\WINDOWS\system32\qijiahmh.ini
C:\WINDOWS\system32\qmjtukyj.dll
C:\WINDOWS\system32\qmnpelld.dll
C:\WINDOWS\system32\qnwcjgic.ini
C:\WINDOWS\system32\qrrfjxkm.dll
C:\WINDOWS\system32\qskcotyh.dll
C:\WINDOWS\system32\qtahfwle.dll
C:\WINDOWS\system32\qtxgxcfk.dll
C:\WINDOWS\system32\quvtjvqk.ini
C:\WINDOWS\system32\qvfnhwlt.ini
C:\WINDOWS\system32\qwqnkcsx.dll
C:\WINDOWS\system32\qyeqjicg.dll
C:\WINDOWS\system32\ralxtleg.ini
C:\WINDOWS\system32\rbekjriv.dll
C:\WINDOWS\system32\rbnqmvfe.dll
C:\WINDOWS\system32\rctxqbxc.dll
C:\WINDOWS\system32\rgtmfhww.ini
C:\WINDOWS\system32\rgwuvsqa.ini
C:\WINDOWS\system32\rhvxhmhf.dll
C:\WINDOWS\system32\rjurdwwg.dll
C:\WINDOWS\system32\rkdlsche.dll
C:\WINDOWS\system32\rkinyujn.dll
C:\WINDOWS\system32\rpwelsvr.exe
C:\WINDOWS\system32\rqokiqac.ini
C:\WINDOWS\system32\rrtidodr.dll
C:\WINDOWS\system32\rshpqbqw.dll
C:\WINDOWS\system32\rtivfkpg.dll
C:\WINDOWS\system32\rwaaepqv.dll
C:\WINDOWS\system32\rxcqpkqm.dll
C:\WINDOWS\system32\sbavcvrk.dll
C:\WINDOWS\system32\sbdosyoe.dll
C:\WINDOWS\system32\sfilhsax.exe
C:\WINDOWS\system32\shaiegrx.dll
C:\WINDOWS\system32\sidvvugc.ini
C:\WINDOWS\system32\siwikpfm.dll
C:\WINDOWS\system32\sncqbjnq.dll
C:\WINDOWS\system32\snnrtbot.dll
C:\WINDOWS\system32\soavedqv.dll
C:\WINDOWS\system32\soeajlve.ini
C:\WINDOWS\system32\ssqdmgdf.dll
C:\WINDOWS\system32\stapqojo.dll
C:\WINDOWS\system32\steymfdw.dll
C:\WINDOWS\system32\ststv.bak1
C:\WINDOWS\system32\ststv.bak2
C:\WINDOWS\system32\ststv.ini
C:\WINDOWS\system32\svmanyah.ini
C:\WINDOWS\system32\svpqbsef.dll
C:\WINDOWS\system32\swnxbkld.ini
C:\WINDOWS\system32\taccjden.dll
C:\WINDOWS\system32\tajmfkmh.dll
C:\WINDOWS\system32\tanymxbh.ini
C:\WINDOWS\system32\tbgprngo.ini
C:\WINDOWS\system32\tcibccdb.dll
C:\WINDOWS\system32\tckxfxqw.ini
C:\WINDOWS\system32\tdmbluow.dll
C:\WINDOWS\system32\tegqlnki.dll
C:\WINDOWS\system32\thftdjql.dll
C:\WINDOWS\system32\thfxyqyj.ini
C:\WINDOWS\system32\tjynbqyl.ini
C:\WINDOWS\system32\tlhyeccw.ini
C:\WINDOWS\system32\tlidbfwl.ini
C:\WINDOWS\system32\tlwhnfvq.dll
C:\WINDOWS\system32\trfiuewt.dll
C:\WINDOWS\system32\tstwa.bak1
C:\WINDOWS\system32\tstwa.bak1
C:\WINDOWS\system32\tstwa.bak2
C:\WINDOWS\system32\tstwa.bak2
C:\WINDOWS\system32\tstwa.ini
C:\WINDOWS\system32\tstwa.ini
C:\WINDOWS\system32\tstwa.ini2
C:\WINDOWS\system32\tstwa.ini2
C:\WINDOWS\system32\tstwa.tmp
C:\WINDOWS\system32\tstwa.tmp
C:\WINDOWS\system32\tsvslvyf.dll
C:\WINDOWS\system32\ttxwhlnv.dll
C:\WINDOWS\system32\tweuifrt.ini
C:\WINDOWS\system32\twksuxvs.dll
C:\WINDOWS\system32\uamjilfq.dll
C:\WINDOWS\system32\uapfxiro.ini
C:\WINDOWS\system32\ubrsvnuu.dll
C:\WINDOWS\system32\ubydewjw.ini
C:\WINDOWS\system32\uebbswqp.dll
C:\WINDOWS\system32\ufafnqjw.dll
C:\WINDOWS\system32\ufiekwmo.dll
C:\WINDOWS\system32\uhqebsbw.dll
C:\WINDOWS\system32\uiexgjyw.dll
C:\WINDOWS\system32\uincndck.dll
C:\WINDOWS\system32\ujlpxato.dll
C:\WINDOWS\system32\uleypoxs.dll
C:\WINDOWS\system32\umolkkny.dll
C:\WINDOWS\system32\uqhjqbyf.dll
C:\WINDOWS\system32\uqwxqkhg.dll
C:\WINDOWS\system32\usdjdipv.dll
C:\WINDOWS\system32\uujxedcm.ini
C:\WINDOWS\system32\uxejerlt.dll
C:\WINDOWS\system32\uyfsuhak.dll
C:\WINDOWS\system32\uytapxbp.dll
C:\WINDOWS\system32\vbtqbjxi.ini
C:\WINDOWS\system32\vbuwnwsy.ini
C:\WINDOWS\system32\vdanbxwd.dll
C:\WINDOWS\system32\vdvmhcak.dll
C:\WINDOWS\system32\vefyxspn.dll
C:\WINDOWS\system32\vehkftbc.dll
C:\WINDOWS\system32\vhxgmgfe.ini
C:\WINDOWS\system32\vlphfeqm.dll
C:\WINDOWS\system32\vlwiileu.dll
C:\WINDOWS\system32\vngqrcga.dll
C:\WINDOWS\system32\vnlhwxtt.ini
C:\WINDOWS\system32\vnluiabc.dll
C:\WINDOWS\system32\vnmbloxd.ini
C:\WINDOWS\system32\vodnpvqx.dll
C:\WINDOWS\system32\vpltrdjw.dll
C:\WINDOWS\system32\vqdevaos.ini
C:\WINDOWS\system32\vthtxosf.ini
C:\WINDOWS\system32\vvbokmgc.dll
C:\WINDOWS\system32\vvimrlmj.dll
C:\WINDOWS\system32\vwrbypyn.dll
C:\WINDOWS\system32\vxsunvkn.dll
C:\WINDOWS\system32\wcceyhlt.dll
C:\WINDOWS\system32\wjdrtlpv.ini
C:\WINDOWS\system32\wjwedybu.dll
C:\WINDOWS\system32\wmnqbugi.dll
C:\WINDOWS\system32\womrnfre.dll
C:\WINDOWS\system32\woulbmdt.ini
C:\WINDOWS\system32\woxpetar.exe
C:\WINDOWS\system32\wqxfxkct.dll
C:\WINDOWS\system32\wrmiehla.dll
C:\WINDOWS\system32\wscfkcrk.dll
C:\WINDOWS\system32\wtccudln.dll
C:\WINDOWS\system32\wthxbagc.dll
C:\WINDOWS\system32\wvstjagq.ini
C:\WINDOWS\system32\wwapmkbs.dll
C:\WINDOWS\system32\wwhfmtgr.dll
C:\WINDOWS\system32\wxbcbgbk.ini
C:\WINDOWS\system32\wxomlyce.dll
C:\WINDOWS\system32\wycdd.ini
C:\WINDOWS\system32\xbhuljwe.dll
C:\WINDOWS\system32\xdkebjun.dll
C:\WINDOWS\system32\xdvcrelk.dll
C:\WINDOWS\system32\xeqcewtf.dll
C:\WINDOWS\system32\xipvshrf.ini
C:\WINDOWS\system32\xmdwibgj.dll
C:\WINDOWS\system32\xnkhafjn.dll
C:\WINDOWS\system32\xojgaypx.dll
C:\WINDOWS\system32\xowkthrf.dll
C:\WINDOWS\system32\xplusfpf.dll
C:\WINDOWS\system32\xpyagjox.ini
C:\WINDOWS\system32\xrbharcc.ini
C:\WINDOWS\system32\xrebjgci.ini
C:\WINDOWS\system32\xrndviua.dll
C:\WINDOWS\system32\xtgjysdh.ini
C:\WINDOWS\system32\xuperblt.dll
C:\WINDOWS\system32\xykbdbxp.ini
C:\WINDOWS\system32\ycfscpcd.ini
C:\WINDOWS\system32\yciirpun.dll
C:\WINDOWS\system32\ycqvexmy.dll
C:\WINDOWS\system32\yddaybsa.dll
C:\WINDOWS\system32\ydufycgk.dll
C:\WINDOWS\system32\yefdmams.dll
C:\WINDOWS\system32\yekyjogl.exe
C:\WINDOWS\system32\yftsoosy.dll
C:\WINDOWS\system32\yhqmcrog.ini
C:\WINDOWS\system32\yhrglpeb.dll
C:\WINDOWS\system32\ymxevqcy.ini
C:\WINDOWS\system32\ynkklomu.ini
C:\WINDOWS\system32\yospkeeu.exe
C:\WINDOWS\system32\yrpdcqvu.exe
C:\WINDOWS\system32\ysoostfy.ini
C:\WINDOWS\system32\yswnwubv.dll
C:\WINDOWS\system32\yurulysc.ini
C:\WINDOWS\system32\ywqpsfui.dll
C:\WINDOWS\system32\yxlgjtws.dll
C:\WINDOWS\system32\zgurffci.dll
.
---- Previous Run -------
.
C:\Documents and Settings\CUSTOMER #1\Favorites\Online Security Guide.lnk
C:\Documents and Settings\CUSTOMER #1\Favorites\Online Security Guide.lnk
C:\Documents and Settings\CUSTOMER #1\Favorites\Online Security Guide.lnk
C:\Program Files\Hammer.dll
C:\Program Files\myglobalsearch
C:\Program Files\myglobalsearch\bar\History\search
C:\Program Files\myglobalsearch\bar\Settings\settings.dat
C:\Program Files\myglobalsearch\bar\Settings\settings.dat.bak
C:\Program Files\myglobalsearch\bar\Settings\settings.htm
C:\Program Files\myglobalsearch\bar\Settings\settings.htm.bak
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\xOe
C:\Temp\xOe\tOasF.log
C:\WINDOWS\b148.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\eppfyues.dllbox
C:\WINDOWS\system32\ihvlexwc.dllbox
C:\WINDOWS\system32\jfnjafag.dllbox
C:\WINDOWS\system32\jypkxwnp.dllbox
C:\WINDOWS\system32\ohufgsir.dllbox
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\q21
C:\WINDOWS\system32\qnrcpors.dllbox
C:\WINDOWS\system32\rckrvcpi.dllbox
C:\WINDOWS\system32\sudeqzuq.dllbox
C:\WINDOWS\system32\uacbjxmw.dllbox
C:\WINDOWS\system32\vblpcwtq.exe
C:\WINDOWS\system32\wartaede.dllbox
C:\WINDOWS\system32\wasuovdg.dllbox
C:\WINDOWS\system32\womrnfre.dllbox
C:\WINDOWS\system32\ydufycgk.dllbox
C:\WINDOWS\system32\yukifnzn.dllbox
C:\WINDOWS\system32\zgurffci.dllbox
C:\WINDOWS\system32\zmwkdpwu.dllbox
C:\WINDOWS\winshow.exe
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2007-09-21 to 2007-10-21 )))))))))))))))))))))))))))))))
.
2007-10-19 18:45 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-10-19 18:45 <DIR> d-------- C:\Documents and Settings\CUSTOMER #1\Application Data\SUPERAntiSpyware.com
2007-10-19 18:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-13 15:56 <DIR> d-------- C:\VundoFix Backups
2007-10-13 13:24 <DIR> d-------- C:\Program Files\RogueRemover FREE
2007-10-12 18:09 <DIR> d--h----- C:\Documents and Settings\All Users\Application Data\CanonBJ
2007-10-12 18:08 <DIR> d-------- C:\Program Files\Canon
2007-10-11 09:57 <DIR> d-------- C:\Documents and Settings\CUSTOMER #1\Application Data\Viewpoint
2007-10-09 11:05 <DIR> d-------- C:\Program Files\CONEXANT
2007-10-08 19:21 707,518 --a------ C:\TEMP\regit.exe
2007-10-08 18:04 <DIR> d-------- C:\Program Files\Alcohol Soft
2007-10-04 18:55 <DIR> d-------- C:\Program Files\Steam
2007-09-29 16:46 <DIR> d-------- C:\Program Files\Motherboard Monitor 5
2007-09-24 23:07 <DIR> d-------- C:\Program Files\Phase One
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-21 00:02 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-19 23:45 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-10-19 21:51 --------- d-----w C:\Program Files\Spyware Doctor
2007-10-18 00:12 --------- d-----w C:\Program Files\SpywareBlaster
2007-10-15 02:25 --------- d-----w C:\Program Files\Winamp
2007-10-15 02:25 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2007-10-15 02:25 --------- d-----w C:\Program Files\Intel Audio Studio
2007-10-15 02:25 --------- d-----w C:\Program Files\Digital Media Reader
2007-10-15 00:56 --------- d-----w C:\Program Files\Common Files\KAKE First Alert
2007-10-14 02:30 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-10-13 20:55 --------- d-----w C:\Program Files\Java
2007-10-13 20:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-13 19:50 --------- d-----w C:\Program Files\Google
2007-10-13 15:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-13 15:39 --------- d-----w C:\Program Files\SoundSpectrum
2007-10-13 02:03 --------- d-----w C:\Program Files\Gateway Games
2007-10-13 02:01 --------- d-----w C:\Program Files\WildTangent
2007-10-13 01:53 --------- d-----w C:\Program Files\Apple Software Update
2007-10-13 01:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-11 00:55 --------- d-----w C:\Program Files\Ricochet Infinity
2007-10-08 22:32 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-10-05 17:57 163,644 -c--a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-05 17:21 --------- d-----w C:\Program Files\Activision
2007-10-04 22:52 --------- d-----w C:\Program Files\Napster
2007-10-04 22:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Napster
2007-10-04 22:51 --------- d-----w C:\Program Files\Microsoft Games
2007-10-04 22:45 --------- d-----w C:\Program Files\BitTorrent
2007-10-04 22:11 29,000 ----a-w C:\WINDOWS\system32\drivers\kcom.sys
2007-10-04 22:10 79,688 ----a-w C:\WINDOWS\system32\drivers\iksyssec.sys
2007-10-04 22:10 62,280 ----a-w C:\WINDOWS\system32\drivers\iksysflt.sys
2007-10-04 22:10 41,288 ----a-w C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-09-21 02:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\NVIDIA
2007-09-20 03:21 --------- d-----w C:\Program Files\Electronic Arts
2007-09-17 17:01 --------- d-----w C:\Program Files\NVIDIA Corporation
2007-09-17 06:07 6,853,088 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-09-16 02:26 --------- d-----w C:\Program Files\GameSpy Arcade
2007-09-06 10:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-06 10:05 92,848 -c--a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-06 10:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-06 10:02 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-06 10:00 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2006-12-01 01:59 774,144 -c--a-w C:\Program Files\RngInterstitial.dll
2005-01-12 00:50:57 56 --sha-r C:\WINDOWS\system32\44566F3557.sys
2005-01-12 00:50:55 1,682 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 22:56]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2005-12-09 20:44]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 01:07]
"nwiz"="nwiz.exe" [2007-09-17 01:07 C:\WINDOWS\system32\nwiz.exe]
"SigmatelSysTrayApp"="sttray.exe" []
"IntelAudioStudio"="C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" [2006-07-13 15:34]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" []
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 09:15]
"CCUTRAYICON"="C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe" [2006-07-27 11:54]
"NMSSupport"="C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" [2006-03-29 21:10]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 18:19 C:\WINDOWS\arpwrmsg.exe]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2004-06-03 03:50]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 18:16]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 05:06]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-25 18:33]
"RegistryMechanic"="" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SideWinderTrayV4"="C:\PROGRA~1\MI948F~1\GAMECO~1\Common\SWTrayV4.exe" [2000-06-28 15:41]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"Phase One Media Reader"="C:\PROGRA~1\PHASEO~1\CAPTUR~1\DCIMImp.exe" [2007-04-25 07:41]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-09-17 01:07]
"PDUiP6220DMon"="C:\Program Files\Canon\Memory Card Utility\iP6220D\PDUiP6220DMon.exe" [2005-05-06 18:17]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-02-13 13:29]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 14:00]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 12:32]
"Steam"="c:\program files\steam\steam.exe" [2007-10-11 20:18]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
C:\Documents and Settings\CUSTOMER #1\Start Menu\Programs\Startup\
hc_tray.lnk - C:\Program Files\Kuma Games\hcsystray\hc_tray.exe [2007-04-26 13:49:20]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
KAKE First Alert.lnk - C:\Program Files\Common Files\KAKE First Alert\TrueWeather.exe [2006-11-25 19:14:30]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\eppfyues]
eppfyues.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ihvlexwc]
ihvlexwc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qnrcpors]
qnrcpors.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sudeqzuq]
sudeqzuq.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\uacbjxmw]
uacbjxmw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wartaede]
wartaede.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\zmwkdpwu]
zmwkdpwu.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ddcyw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmFilter;Logitech Gaming HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S3 cpuz128;cpuz128;\??\C:\DOCUME~1\CUSTOM~1\LOCALS~1\Temp\cpuz_x32.sys
S3 GcKernel;Microsoft SideWinder Value Add - Filter Driver;C:\WINDOWS\system32\DRIVERS\GcKernel.sys
S3 HIDSwvd;Microsoft SideWinder Virtual HID Device Mini-Driver;C:\WINDOWS\system32\DRIVERS\HIDSwvd.sys
S3 LLUSBFLT;LLUSBFLT;C:\WINDOWS\system32\drivers\llusbflt.sys
S3 PciCon;PciCon;\??\E:\PciCon.sys
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;C:\WINDOWS\system32\Drivers\usbbc2.sys
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;C:\WINDOWS\system32\DRIVERS\SWUSBFLT.sys
S3 TCCrystalCpuInfo;TCCrystalCpuInfo;\??\C:\DOCUME~1\CUSTOM~1\LOCALS~1\Temp\TCCpuInfo.sys
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e04d147-4803-11db-b9fe-806d6172696f}]
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
"2007-10-10 06:29:00 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\system32\cleanmgr.exe
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-10-20 19:10:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-20 19:14:55 - machine was rebooted
.
--- E O F ---
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 10/20/2007 at 08:28 PM
Application Version : 3.9.1008
Core Rules Database Version : 3327
Trace Rules Database Version: 1328
Scan type : Complete Scan
Total Scan Time : 01:10:32
Memory items scanned : 566
Memory threats detected : 0
Registry items scanned : 7135
Registry threats detected : 0
File items scanned : 91224
File threats detected : 21
Adware.Tracking Cookie
C:\Documents and Settings\CUSTOMER #1\Cookies\customer #
[email protected] C:\Documents and Settings\CUSTOMER #1\Cookies\customer_#1@customer_[5].txt
C:\Documents and Settings\CUSTOMER #1\Cookies\customer_#1@customer_[2].txt
C:\Documents and Settings\CUSTOMER #1\Cookies\customer_#1@customer_[11].txt
C:\Documents and Settings\CUSTOMER #1\Cookies\customer #
[email protected]BearShare File Sharing Client
C:\PROGRAM FILES\BEARSHARE\BEARSHARE.EXE
C:\PROGRAM FILES\BEARSHARE APPLICATIONS\BEARSHARE\BEARSHARE.EXE
Adware.Vundo Variant
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\HAMMER.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\OHUFGSIR.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\WOMRNFRE.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\YDUFYCGK.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\ZGURFFCI.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4E015214-6BB0-4181-B365-456CF1DEC069}\RP2\A0000009.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4E015214-6BB0-4181-B365-456CF1DEC069}\RP3\A0000251.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4E015214-6BB0-4181-B365-456CF1DEC069}\RP3\A0000353.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4E015214-6BB0-4181-B365-456CF1DEC069}\RP3\A0000377.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4E015214-6BB0-4181-B365-456CF1DEC069}\RP3\A0000387.DLL
C:\VUNDOFIX BACKUPS\RCKRVCPI.DLL.BAD
C:\VUNDOFIX BACKUPS\YUKIFNZN.DLL.BAD
C:\WINDOWS\SYSTEM32\RCKRVCPI.DLL.VIR
Worm.Evilbot-B
C:\WINEXEC.EXE
Logfile of HijackThis v1.99.1
Scan saved at 8:38:54 PM, on 10/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\rsvp.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\PROGRA~1\MI948F~1\GAMECO~1\Common\SWTrayV4.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Canon\Memory Card Utility\iP6220D\PDUiP6220DMon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\steam\steam.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
C:\Program Files\Common Files\KAKE First Alert\TrueWeather.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\CUSTOMER #1\Desktop\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MI948F~1\GAMECO~1\Common\SWTrayV4.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Phase One Media Reader] C:\PROGRA~1\PHASEO~1\CAPTUR~1\DCIMImp.exe /noscan /CheckAutoStart
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PDUiP6220DMon] C:\Program Files\Canon\Memory Card Utility\iP6220D\PDUiP6220DMon.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: hc_tray.lnk = C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
O4 - Global Startup: KAKE First Alert.lnk = C:\Program Files\Common Files\KAKE First Alert\TrueWeather.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload.ad...ash/swflash.cabO16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) -
http://acs.pandasoft...5/asproinst.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://download.game...aploader_v6.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: eppfyues - eppfyues.dll (file missing)
O20 - Winlogon Notify: ihvlexwc - ihvlexwc.dll (file missing)
O20 - Winlogon Notify: qnrcpors - qnrcpors.dll (file missing)
O20 - Winlogon Notify: sudeqzuq - sudeqzuq.dll (file missing)
O20 - Winlogon Notify: uacbjxmw - uacbjxmw.dll (file missing)
O20 - Winlogon Notify: wartaede - wartaede.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: zmwkdpwu - zmwkdpwu.dll (file missing)
O23 - Service: Intel® Alert Service (AlertService) - Intel Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Intel® Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel® Software Services Manager (ISSM) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: Intel® Viiv Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe