Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Trojandownloader.xs [Resolved]


  • This topic is locked This topic is locked

#1
Iborange

Iborange

    New Member

  • Member
  • Pip
  • 5 posts
Hello,

My desk top turned black with a purple hue surrounding all my icons. In red, there is a large text message saying my computer is infected and what my IP addres is further explaining I should seek antispyware assistance. I then started getting a little yellow triangle on my toolbar that when I clicked stated I have Trojandownloader.xs. When I click the link to go to the Microsoft web page for instructions on what to do Explorer opens up a page that is trying to sell me a spyware removal program. I also get alot of additional pop ups.

What I have tried so far is what you say to do in your before you post section. Here are my log files:


ActiveScan Report

Incident Status Location

Adware:Adware/SpywareDetect Not disinfected C:\WINDOWS\system32\vvgeowbv.exe
Adware:adware/eshopper Not disinfected c:\windows\system32\ESHOPEE.exe
Adware:adware/popuper Not disinfected c:\windows\system32\msole32.exe
Potentially unwanted tool:application/activitymon Not disinfected c:\program files\amsys
Adware:adware/activshopper Not disinfected c:\program files\e-zshopper
Adware:adware/adbars Not disinfected Windows Registry
Adware:adware/mirar Not disinfected Windows Registry
Dialer:dialer.xd Not disinfected HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}
Adware:adware/activesearch Not disinfected Windows Registry
Adware:adware/deskwizz Not disinfected Windows Registry
Adware:adware/404search Not disinfected Windows Registry
Adware:adware/adblaster Not disinfected Windows Registry
Adware:adware/adsincontext Not disinfected Windows Registry
Potentially unwanted tool:application/funweb Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Adware:Adware/Yazzle Not disinfected C:\1A01.tmp
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][3].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Lisa Lewis\Desktop\SmitfraudFix\Process.exe
Virus:Trj/Rebooter.J Disinfected C:\Documents and Settings\Lisa Lewis\Desktop\SmitfraudFix\Reboot.exe
Potentially unwanted tool:Application/SuperFast Not disinfected C:\Documents and Settings\Lisa Lewis\Desktop\SmitfraudFix\restart.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Lisa Lewis\Desktop\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Virus:Trj/Rebooter.J Disinfected C:\Documents and Settings\Lisa Lewis\Desktop\SmitfraudFix.zip[SmitfraudFix/Reboot.exe]
Potentially unwanted tool:Application/SuperFast Not disinfected C:\Documents and Settings\Lisa Lewis\Desktop\SmitfraudFix.zip[SmitfraudFix/restart.exe]
Adware:Adware/SpyAway Not disinfected C:\WINDOWS\fkwggshm.exe
Virus:Generic Trojan Disinfected C:\WINDOWS\system32\i8\taldrvr11.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
Virus:Generic Malware Disinfected C:\WINDOWS\tsitra72.exe
Spyware:Cookie/Cgi-bin Not disinfected E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
Spyware:Cookie/Cgi-bin Not disinfected E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][3].txt
Spyware:Cookie/did-it Not disinfected E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
Spyware:Cookie/Go Not disinfected E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
Spyware:Cookie/Target Not disinfected E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
Spyware:Cookie/Advnt Not disinfected E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
Spyware:Cookie/Affiliate fuel Not disinfected E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt

--------------------------------------------------------------------------------

SUPERAntiSpyware Scan Log
Generated 10/30/2007 at 06:25 PM

Application Version : 3.6.1000

Core Rules Database Version : 3333
Trace Rules Database Version: 1334

Scan type : Complete Scan
Total Scan Time : 01:00:49

Memory items scanned : 314
Memory threats detected : 0
Registry items scanned : 4162
Registry threats detected : 68
File items scanned : 67074
File threats detected : 82

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{696C6D97-CAC8-4961-B9B4-260C48A2DB5F}
HKCR\CLSID\{696C6D97-CAC8-4961-B9B4-260C48A2DB5F}
HKCR\CLSID\{696C6D97-CAC8-4961-B9B4-260C48A2DB5F}
HKCR\CLSID\{696C6D97-CAC8-4961-B9B4-260C48A2DB5F}\InProcServer32
HKCR\CLSID\{696C6D97-CAC8-4961-B9B4-260C48A2DB5F}\InProcServer32#ThreadingModel
C:\PROGRAM FILES\MSN GAMING ZONE\HOKE4444.DLL
HKLM\Software\Classes\CLSID\{6D720B5C-B835-45B1-A0C2-65C97BC7A0C9}
HKCR\CLSID\{6D720B5C-B835-45B1-A0C2-65C97BC7A0C9}
HKCR\CLSID\{6D720B5C-B835-45B1-A0C2-65C97BC7A0C9}
HKCR\CLSID\{6D720B5C-B835-45B1-A0C2-65C97BC7A0C9}\InProcServer32
HKCR\CLSID\{6D720B5C-B835-45B1-A0C2-65C97BC7A0C9}\InProcServer32#ThreadingModel
C:\PROGRAM FILES\MSN GAMING ZONE\HOKE83122.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{696C6D97-CAC8-4961-B9B4-260C48A2DB5F}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D720B5C-B835-45B1-A0C2-65C97BC7A0C9}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}

Adware.AdBreak
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}

411Ferret Toolbar
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{12F02779-6D88-4958-8AD3-83C12D86ADC7}

Adware.AdBlaster
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}

AdBars BHO
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}

Adware.404Search
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}

Adware.Accoona
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}

Trojan.PBar
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}

Adware.k8l
C:\PROGRAM FILES\UNINSTALL INFORMATION\PROFSYCY.HTML
HKU\S-1-5-21-602162358-1326574676-682003330-1004\Software\Microsoft\Internet Explorer\Desktop\Components\0
HKU\S-1-5-21-602162358-1326574676-682003330-1004\Software\Microsoft\Internet Explorer\Desktop\Components\0#Source
HKU\S-1-5-21-602162358-1326574676-682003330-1004\Software\Microsoft\Internet Explorer\Desktop\Components\0#SubscribedURL
HKU\S-1-5-21-602162358-1326574676-682003330-1004\Software\Microsoft\Internet Explorer\Desktop\Components\0#FriendlyName
HKU\S-1-5-21-602162358-1326574676-682003330-1004\Software\Microsoft\Internet Explorer\Desktop\Components\0#Flags
HKU\S-1-5-21-602162358-1326574676-682003330-1004\Software\Microsoft\Internet Explorer\Desktop\Components\0#Position
HKU\S-1-5-21-602162358-1326574676-682003330-1004\Software\Microsoft\Internet Explorer\Desktop\Components\0#CurrentState
HKU\S-1-5-21-602162358-1326574676-682003330-1004\Software\Microsoft\Internet Explorer\Desktop\Components\0#OriginalStateInfo
HKU\S-1-5-21-602162358-1326574676-682003330-1004\Software\Microsoft\Internet Explorer\Desktop\Components\0#RestoredStateInfo

Adware.Tracking Cookie
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
C:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][2].txt
E:\Documents and Settings\Lisa Lewis\Cookies\lisa [email protected][1].txt

Trojan.NetMon/DNSChange
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#DeviceDesc

Trojan.cmdService
HKLM\SYSTEM\CurrentControlSet\Services\cmdService
HKLM\SYSTEM\CurrentControlSet\Services\cmdService#Type
HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum
HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum#0
HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum#Count
HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#DeviceDesc

Adware.Mirar/NetNucleus
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}#SystemComponent
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}#Installer
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\Contains
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\Contains\Files
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\Contains\Files#C:\WINDOWS\system32\WinATS.dll
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\DownloadInformation
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\DownloadInformation#CODEBASE
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\DownloadInformation#INF
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\InstalledVersion
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\InstalledVersion#LastModified
C:\WINDOWS\Downloaded Program Files\WinATS.inf

Adware.AdSponsor/ISM
HKU\.DEFAULT\Software\BndDrive
HKU\S-1-5-18\Software\BndDrive

Trojan.Downloader-Gen/MobRules
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\UTCTETUB.DLL
C:\WINDOWS\TQRGDYPQ.DLL

Adware.ClickSpring/Yazzle
C:\PROGRAM FILES\COMMON FILES\YAZZLE1122OINUNINSTALLER.EXE

Trojan.Downloader-Gen/WinAble-Installer
C:\PROGRAM FILES\TEMPORARY\WININSTALL.EXE

Trojan.ZQuest
C:\SYSTEM VOLUME INFORMATION\_RESTORE{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP481\A0024057.DLL

Trojan.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP481\A0024058.VBS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP481\A0024059.VBS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP481\A0024060.EXE
C:\WINDOWS\SYSTEM32\E2\CAWS83122.EXE
C:\WINDOWS\TTC-4444.EXE

Trojan.Rootkit-TnCore
C:\SYSTEM VOLUME INFORMATION\_RESTORE{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP481\A0024062.SYS

Trojan.ZQuest-Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP481\A0024064.EXE

Trojan.Downloader-Gen/Installer
C:\WINDOWS\B111.EXE
C:\WINDOWS\B122.EXE

Trojan.Downloader-FakeRX
C:\WINDOWS\SYSTEM32\AIVSKURQ.DLL

Unclassified.Unknown Origin/System
C:\WINDOWS\SYSTEM32\ESHOPEE.EXE

Trojan.Fakespy-B
C:\WINDOWS\SYSTEM32\MSOLE32.EXE


--------------------------------------------------------------------


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:17:11 PM, on 10/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\PROGRA~1\BellSouth\File and Printer Sharing\BellSouthFPS\McciTrayApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Documents and Settings\Lisa Lewis\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\vvgeowbv.exe,C:\WINDOWS\system32\userinit.exe
O1 - Hosts: 194.54.90.238 google.com
O1 - Hosts: 194.54.90.238 google.ca
O1 - Hosts: 194.54.90.238 www.google.com
O1 - Hosts: 194.54.90.238 search.yahoo.com
O1 - Hosts: 194.54.90.238 search.msn.com
O1 - Hosts: 194.54.90.238 search.live.com
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: 0 - {47D951BA-607C-445A-2B86-41D51E6E7FB2} - C:\Program Files\Uninstall Information\lavuna.dll (file missing)
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: aivskurq.msdn_hlp - {A6E432B4-D4C2-43B3-BF55-C364F8F7362A} - C:\WINDOWS\system32\aivskurq.dll (file missing)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {c5c98920-1dd1-11b2-a3b4-8f5d84426fb7} - C:\WINDOWS\tqrgdypq.dll (file missing)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [BellSouthFPS_McciTrayApp] C:\PROGRA~1\BellSouth\File and Printer Sharing\BellSouthFPS\McciTrayApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CheckWinPerf] C:\DOCUME~1\LISALE~1\LOCALS~1\Temp\iowjwkem.exe
O4 - HKLM\..\Run: [utctetub] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\utctetub.dll"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Pxiq] "C:\Documents and Settings\Lisa Lewis\My Documents\s?stem\d?dplay.exe"
O4 - HKCU\..\Run: [Insider] C:\Program Files\Insider\Insider.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: hc_tray.lnk = C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast....wareControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1154400815757
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1154443889390
O16 - DPF: {7E9522CF-6B95-46D6-8E2F-7638F507313F} (BLS_SpeedOP.systemcheck) - http://www.fastacces...bls_speedop.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://pbells.broad...wActiveXCab.CAB
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 9079 bytes






I also tried the AVG Antispyware program but could not get a log along with the Panda online scan. I also updated all my windows updates available. Thank you in advance for any assistance you can give and If I need to send anything eles please just ask...


Thanks
IBOrange

Edited by Iborange, 31 October 2007 - 11:08 AM.

  • 0

Advertisements


#2
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hello Iborange

Welcome to G2Go. :)


Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall

In case you have used Combofix before, please delete the version you have and redownload it again, because Combofix is being updated everyday.

In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix, please disable your scanner and redownload Combofix again. Because some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.

  • 0

#3
Iborange

Iborange

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Thank You for taking the time to help... Here is the logs you requested.

Oh and BTW To keep you updated I just noticed earlier that when I try to enter Task Manager my computer states that it is blocked by the administrater... Even thogh I have only one user (the admin acount).


ComboFix 07-11-01.1** - Lisa Lewis 2007-10-31 21:44:12.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.279 [GMT -4:00]
Running from: C:\Documents and Settings\Lisa Lewis\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Lisa Lewis\Application Data\macromedia\Flash Player\#SharedObjects\PX6URRU9\www.broadcaster.com
C:\Documents and Settings\Lisa Lewis\Application Data\macromedia\Flash Player\#SharedObjects\PX6URRU9\www.broadcaster.com\played_list.sol
C:\Documents and Settings\Lisa Lewis\Application Data\macromedia\Flash Player\#SharedObjects\PX6URRU9\www.broadcaster.com\video_queue.sol
C:\Documents and Settings\Lisa Lewis\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Lisa Lewis\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\Lisa Lewis\Desktop\internet.lnk
C:\Documents and Settings\Lisa Lewis\My Documents\SSTEM~1
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\Common Files\stem~1
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\Insider
C:\Program Files\Insider\Insider.exe
C:\Program Files\Insider\UnInstall.exe
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\Program Files\Temporary
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\b147.exe
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\a13
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\e2
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\g1
C:\WINDOWS\system32\i8
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\nusrmgr.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\system32\x22
C:\WINDOWS\system32\x22\c124wvr.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_CORE
-------\core


((((((((((((((((((((((((( Files Created from 2007-10-01 to 2007-11-01 )))))))))))))))))))))))))))))))
.

2007-10-31 21:50 <DIR> d-------- C:\Program Files\p2pnetworks
2007-10-31 21:50 <DIR> d-------- C:\Program Files\e-zshopper
2007-10-31 21:50 <DIR> d-------- C:\Program Files\amsys
2007-10-31 21:50 <DIR> d-------- C:\Program Files\akl
2007-10-31 21:50 <DIR> d-------- C:\Program Files\Accoona
2007-10-31 21:50 <DIR> d-------- C:\Program Files\3721
2007-10-31 21:43 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-31 12:59 18,432 --a------ C:\WINDOWS\fkwggshm.exe
2007-10-30 20:42 6,058,496 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-30 20:42 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-10-30 20:42 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-30 20:42 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-30 20:42 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-30 20:42 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-30 20:42 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-30 20:42 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-30 20:36 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2007-10-30 18:34 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-10-30 17:28 0 --a------ C:\WINDOWS\system32\CMMGR32.EXE
2007-10-30 17:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-30 17:21 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-10-30 17:21 <DIR> d-------- C:\Documents and Settings\Lisa Lewis\Application Data\SUPERAntiSpyware.com
2007-10-30 14:14 <DIR> d-------- C:\Documents and Settings\Lisa Lewis\Application Data\Grisoft
2007-10-30 14:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-30 14:14 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-30 09:49 11,520 --a------ C:\WINDOWS\system32\ace16win.dll
2007-10-30 09:34 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-10-30 09:34 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-10-30 09:34 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-10-30 09:34 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-30 09:34 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-10-30 09:34 1,878 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-29 23:06 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-10-29 21:53 <DIR> d-------- C:\WINDOWS\system32\acespy
2007-10-29 21:52 4 --a------ C:\WINDOWS\system32\stfv.bin
2007-10-29 21:45 12 --a------ C:\WINDOWS\system32\dpqaqlqx.bin
2007-10-29 21:44 123,908 --a------ C:\WINDOWS\system32\vvgeowbv.exe
2007-10-29 21:43 <DIR> d-------- C:\WINDOWS\system32\Mz13r
2007-10-29 21:43 <DIR> d-------- C:\WINDOWS\PerfInfo
2007-10-29 21:43 <DIR> d-------- C:\Temp\mZOr
2007-10-29 21:43 <DIR> d-------- C:\Temp
2007-10-29 21:43 3,638 --a------ C:\info.exe
2007-10-29 17:16 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-10-28 22:40 <DIR> d--hs---- C:\WINDOWS\TGlzYQ
2007-10-09 18:28 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-01 01:50 9,216 ----a-w C:\WINDOWS\hcwprn.exe
2007-11-01 01:50 32,000 ----a-w C:\WINDOWS\hotporn.exe
2007-11-01 01:50 31,744 ----a-w C:\WINDOWS\vxddsk.exe
2007-11-01 01:50 31,488 ----a-w C:\WINDOWS\wbeInst$.exe
2007-11-01 01:50 31,488 ----a-w C:\WINDOWS\liqad$.exe
2007-11-01 01:50 31,232 ----a-w C:\WINDOWS\kvnab.exe
2007-11-01 01:50 29,696 ----a-w C:\WINDOWS\xadbrk.dll
2007-11-01 01:50 29,696 ----a-w C:\WINDOWS\liqad.dll
2007-11-01 01:50 29,696 ----a-w C:\WINDOWS\kvnab$.exe
2007-11-01 01:50 27,904 ----a-w C:\WINDOWS\jd2002.dll
2007-11-01 01:50 27,136 ----a-w C:\WINDOWS\xadbrk.exe
2007-11-01 01:50 26,624 ----a-w C:\WINDOWS\pbsysie.dll
2007-11-01 01:50 26,112 ----a-w C:\WINDOWS\wbeCheck.exe
2007-11-01 01:50 24,832 ----a-w C:\WINDOWS\7search.dll
2007-11-01 01:50 24,320 ----a-w C:\WINDOWS\liqad.exe
2007-11-01 01:50 24,320 ----a-w C:\WINDOWS\cbinst$.exe
2007-11-01 01:50 24,064 ----a-w C:\WINDOWS\spredirect.dll
2007-11-01 01:50 22,272 ----a-w C:\WINDOWS\ie_32.exe
2007-11-01 01:50 21,504 ----a-w C:\WINDOWS\fhfmm-Uninstaller.exe
2007-11-01 01:50 20,992 ----a-w C:\WINDOWS\pbar.dll
2007-11-01 01:50 20,480 ----a-w C:\WINDOWS\xxxvideo.exe
2007-11-01 01:50 20,480 ----a-w C:\WINDOWS\dp0.dll
2007-11-01 01:50 19,968 ----a-w C:\WINDOWS\kkcomp$.exe
2007-11-01 01:50 18,944 ----a-w C:\WINDOWS\kvnab.dll
2007-11-01 01:50 18,944 ----a-w C:\WINDOWS\iexplorr23.dll
2007-11-01 01:50 17,920 ----a-w C:\WINDOWS\liqui.exe
2007-11-01 01:50 17,664 ----a-w C:\WINDOWS\fhfmm.exe
2007-11-01 01:50 17,408 ----a-w C:\WINDOWS\xadbrk_.exe
2007-11-01 01:50 15,360 ----a-w C:\WINDOWS\aconti.exe
2007-11-01 01:50 14,848 ----a-w C:\WINDOWS\liqui.dll
2007-11-01 01:50 14,592 ----a-w C:\WINDOWS\wml.exe
2007-11-01 01:50 14,592 ----a-w C:\WINDOWS\settn.dll
2007-11-01 01:50 14,080 ----a-w C:\WINDOWS\kkcomp.dll
2007-11-01 01:50 14,080 ----a-w C:\WINDOWS\flt.dll
2007-11-01 01:50 13,056 ----a-w C:\WINDOWS\liqui-Uninstaller.exe
2007-11-01 01:50 12,800 ----a-w C:\WINDOWS\ngd.dll
2007-11-01 01:50 12,800 ----a-w C:\WINDOWS\eventlowg.dll
2007-11-01 01:50 12,288 ----a-w C:\WINDOWS\adbar.dll
2007-11-01 01:50 11,776 ----a-w C:\WINDOWS\daxtime.dll
2007-11-01 01:50 10,496 ----a-w C:\WINDOWS\kkcomp.exe
2007-11-01 01:48 30,464 ----a-w C:\WINDOWS\764.exe
2007-10-30 23:05 --------- d-----w C:\Program Files\blstoolbar
2007-10-30 21:21 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-10-30 21:20 --------- d-----w C:\Program Files\Kuma Games
2007-10-19 18:52 --------- d-----w C:\Program Files\World of Warcraft
2007-09-05 17:35 --------- d-----w C:\Program Files\EA GAMES
2007-09-03 13:42 --------- d-----w C:\Program Files\Activision Value
2007-09-02 02:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-02 02:11 --------- d-----w C:\Program Files\Cat Daddy Games
2007-09-02 02:10 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-09-02 01:14 --------- d-----w C:\Program Files\Disney Interactive
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-13 22:54 413,696 ----a-w C:\WINDOWS\system32\vbscript.dll
2007-08-13 22:54 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2007-08-13 22:45 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
2007-08-13 22:44 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-13 22:39 71,680 ----a-w C:\WINDOWS\system32\admparse.dll
2007-08-13 22:39 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
2007-08-13 22:36 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
2007-08-13 22:32 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2007-08-13 22:01 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{47D951BA-607C-445A-2B86-41D51E6E7FB2}]
C:\Program Files\Uninstall Information\lavuna.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6E432B4-D4C2-43B3-BF55-C364F8F7362A}]
C:\WINDOWS\system32\aivskurq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5c98920-1dd1-11b2-a3b4-8f5d84426fb7}]
C:\WINDOWS\tqrgdypq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 16:47 C:\WINDOWS\ALCXMNTR.EXE]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2006-08-05 02:23]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 14:24]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 21:50]
"DXDllRegExe"="dxdllreg.exe" []
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [2005-08-31 17:14]
"BellSouthFPS_McciTrayApp"="C:\PROGRA~1\BellSouth\File and Printer Sharing\BellSouthFPS\McciTrayApp.exe" [2006-03-08 16:38]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-18 18:58]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-08-23 19:11]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-07 14:08]
"Pxiq"="C:\Documents and Settings\Lisa Lewis\My Documents\s?stem\d?dplay.exe" []
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-10-30 20:21]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

C:\Documents and Settings\Lisa Lewis\Start Menu\Programs\Startup\
hc_tray.lnk - C:\Program Files\Kuma Games\hcsystray\hc_tray.exe [2007-04-26 13:49:20]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 01:05:26]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 04:20:40]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\\WINDOWS\\system32\\vvgeowbv.exe,C:\\WINDOWS\\system32\\userinit.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2007-10-30 20:21 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38a0cd12-6bc6-11dc-97ed-0040ca479173}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL http://www.mgae.com/...654266814864993

.
Contents of the 'Scheduled Tasks' folder
"2007-10-10 21:54:08 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1155257327.job"
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-31 21:54:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

**************************************************************************
.
Completion time: 2007-10-31 21:56:39 - machine was rebooted
.
--- E O F---






And my Hijack this Log


ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:28:31 PM, on 10/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\PROGRA~1\BellSouth\File and Printer Sharing\BellSouthFPS\McciTrayApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Documents and Settings\Lisa Lewis\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: 0 - {47D951BA-607C-445A-2B86-41D51E6E7FB2} - C:\Program Files\Uninstall Information\lavuna.dll (file missing)
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: aivskurq.msdn_hlp - {A6E432B4-D4C2-43B3-BF55-C364F8F7362A} - C:\WINDOWS\system32\aivskurq.dll (file missing)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {c5c98920-1dd1-11b2-a3b4-8f5d84426fb7} - C:\WINDOWS\tqrgdypq.dll (file missing)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [BellSouthFPS_McciTrayApp] C:\PROGRA~1\BellSouth\File and Printer Sharing\BellSouthFPS\McciTrayApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Pxiq] "C:\Documents and Settings\Lisa Lewis\My Documents\s?stem\d?dplay.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: hc_tray.lnk = C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast....wareControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1154400815757
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1154443889390
O16 - DPF: {7E9522CF-6B95-46D6-8E2F-7638F507313F} (BLS_SpeedOP.systemcheck) - http://www.fastacces...bls_speedop.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://pbells.broad...wActiveXCab.CAB
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 8005 bytes
  • 0

#4
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please rught click on your desktop and create a new folder and name it Hijackthis.
THen on your desktop look for thr Hijackthis icon right click on it and choose cut.
Then paste it inside of the new Hijackthis folder.
=================================
Please re-open Hijackthis and place a check mark next to these entries listed below:

O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: 0 - {47D951BA-607C-445A-2B86-41D51E6E7FB2} - C:\Program Files\Uninstall Information\lavuna.dll (file missing)
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: aivskurq.msdn_hlp - {A6E432B4-D4C2-43B3-BF55-C364F8F7362A} - C:\WINDOWS\system32\aivskurq.dll (file missing)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {c5c98920-1dd1-11b2-a3b4-8f5d84426fb7} - C:\WINDOWS\tqrgdypq.dll (file missing)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O4 - HKCU\..\Run: [Pxiq] "C:\Documents and Settings\Lisa Lewis\My Documents\s?stem\d?dplay.exe"

=====================================================================
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\fkwggshm.exe
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\kvnab.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\liqad.dll
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\spredirect.dll
C:\WINDOWS\ie_32.exe
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\pbar.dll
C:\WINDOWS\xxxvideo.exe
C:\WINDOWS\dp0.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\aconti.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\wml.exe
C:\WINDOWS\settn.dll
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\adbar.dll
C:\WINDOWS\daxtime.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\764.exe
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\system32\aivskurq.dll 

Folder::
C:\WINDOWS\system32\acespy
C:\WINDOWS\system32\Mz13r
C:\Temp\mZOr
C:\WINDOWS\TGlzYQ

Registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000000


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

  • 0

#5
Iborange

Iborange

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Allrighty, I have done those steps and here are the new Logs :)


omboFix 07-11-01.1** - Lisa Lewis 2007-11-01 9:36:15.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.293 [GMT -4:00]
Running from: C:\Documents and Settings\Lisa Lewis\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Lisa Lewis\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\fkwggshm.exe
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\aivskurq.dll
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\3721
C:\Program Files\Accoona
C:\Program Files\akl
C:\Program Files\amsys
C:\Program Files\e-zshopper
C:\Program Files\p2pnetworks
C:\Temp\mZOr
C:\Temp\mZOr\tOasF.log
C:\WINDOWS\fkwggshm.exe
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\acespy
C:\WINDOWS\system32\acespy\__acelog.ndx
C:\WINDOWS\system32\acespy\systune.exe
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\Mz13r
C:\WINDOWS\system32\Mz13r\Mz13r2218.exe
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\TGlzYQ

.
((((((((((((((((((((((((( Files Created from 2007-10-01 to 2007-11-01 )))))))))))))))))))))))))))))))
.

2007-10-31 21:43 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-30 20:42 6,058,496 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-30 20:42 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-10-30 20:42 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-30 20:42 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-30 20:42 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-30 20:42 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-30 20:42 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-30 20:42 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-30 20:36 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2007-10-30 18:34 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-10-30 17:28 0 --a------ C:\WINDOWS\system32\CMMGR32.EXE
2007-10-30 17:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-30 17:21 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-10-30 17:21 <DIR> d-------- C:\Documents and Settings\Lisa Lewis\Application Data\SUPERAntiSpyware.com
2007-10-30 14:14 <DIR> d-------- C:\Documents and Settings\Lisa Lewis\Application Data\Grisoft
2007-10-30 14:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-30 14:14 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-30 09:34 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-10-30 09:34 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-10-30 09:34 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-10-30 09:34 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-30 09:34 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-10-30 09:34 1,878 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-29 23:06 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-10-29 21:43 <DIR> d-------- C:\WINDOWS\PerfInfo
2007-10-29 21:43 <DIR> d-------- C:\Temp
2007-10-29 21:43 3,638 --a------ C:\info.exe
2007-10-29 17:16 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-10-09 18:28 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-30 23:05 --------- d-----w C:\Program Files\blstoolbar
2007-10-30 21:21 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-10-30 21:20 --------- d-----w C:\Program Files\Kuma Games
2007-10-19 18:52 --------- d-----w C:\Program Files\World of Warcraft
2007-09-05 17:35 --------- d-----w C:\Program Files\EA GAMES
2007-09-03 13:42 --------- d-----w C:\Program Files\Activision Value
2007-09-02 02:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-02 02:11 --------- d-----w C:\Program Files\Cat Daddy Games
2007-09-02 02:10 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-09-02 01:14 --------- d-----w C:\Program Files\Disney Interactive
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 16:47 C:\WINDOWS\ALCXMNTR.EXE]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2006-08-05 02:23]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 14:24]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 21:50]
"DXDllRegExe"="dxdllreg.exe" []
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [2005-08-31 17:14]
"BellSouthFPS_McciTrayApp"="C:\PROGRA~1\BellSouth\File and Printer Sharing\BellSouthFPS\McciTrayApp.exe" [2006-03-08 16:38]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-18 18:58]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-08-23 19:11]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-07 14:08]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-10-30 20:21]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

C:\Documents and Settings\Lisa Lewis\Start Menu\Programs\Startup\
hc_tray.lnk - C:\Program Files\Kuma Games\hcsystray\hc_tray.exe [2007-04-26 13:49:20]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 01:05:26]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 04:20:40]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\\WINDOWS\\system32\\vvgeowbv.exe,C:\\WINDOWS\\system32\\userinit.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2007-10-30 20:21 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38a0cd12-6bc6-11dc-97ed-0040ca479173}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL http://www.mgae.com/...654266814864993

.
Contents of the 'Scheduled Tasks' folder
"2007-10-10 21:54:08 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1155257327.job"
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-01 09:41:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

**************************************************************************
.
Completion time: 2007-11-01 9:44:13 - machine was rebooted
C:\ComboFix2.txt ... 2007-10-31 21:56
.
--- E O F ---









Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:47:10 AM, on 11/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\PROGRA~1\BellSouth\File and Printer Sharing\BellSouthFPS\McciTrayApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
C:\Documents and Settings\Lisa Lewis\Desktop\Hijackthis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [BellSouthFPS_McciTrayApp] C:\PROGRA~1\BellSouth\File and Printer Sharing\BellSouthFPS\McciTrayApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: hc_tray.lnk = C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast....wareControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1154400815757
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1154443889390
O16 - DPF: {7E9522CF-6B95-46D6-8E2F-7638F507313F} (BLS_SpeedOP.systemcheck) - http://www.fastacces...bls_speedop.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://pbells.broad...wActiveXCab.CAB
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 6026 bytes
  • 0

#6
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please do an online scan with Kaspersky WebScanner
(This scanner is for use with internet explorer only)
Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

  • 0

#7
Iborange

Iborange

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Here is the Kaspersky report you asked for. :)



-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, November 01, 2007 3:33:50 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 1/11/2007
Kaspersky Anti-Virus database records: 449761
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 112636
Number of viruses found: 11
Number of infected objects: 27
Number of suspicious objects: 0
Duration of the scan process: 01:29:34

Infected Object Name / Virus Name / Last Action
C:\1A01.tmp/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\1A01.tmp NSIS: infected - 1 skipped
C:\1A0D.tmp Infected: Trojan-Downloader.Win32.Small.gks skipped
C:\Documents and Settings\All Users\Application Data\Support.com\Profiles\Lisa Lewis\triggers.log Object is locked skipped
C:\Documents and Settings\Lisa Lewis\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Lisa Lewis\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Lisa Lewis\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Lisa Lewis\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Lisa Lewis\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Lisa Lewis\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Lisa Lewis\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Lisa Lewis\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lisa Lewis\Local Settings\History\History.IE5\MSHist012007110120071102\index.dat Object is locked skipped
C:\Documents and Settings\Lisa Lewis\Local Settings\Temp\Perflib_Perfdata_6b0.dat Object is locked skipped
C:\Documents and Settings\Lisa Lewis\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Lisa Lewis\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lisa Lewis\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Lisa Lewis\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\hpcmerr.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\billing_Lisa Lewis.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\client_Lisa Lewis.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\network_Lisa Lewis.log Object is locked skipped
C:\qoobox\Quarantine\C\WINDOWS\fkwggshm.exe.vir Infected: Trojan.Win32.VB.azo skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\Mz13r\Mz13r2218.exe.vir Infected: Trojan-Downloader.Win32.VB.bqc skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\nusrmgr.exe.vir Infected: Trojan-Dropper.Win32.VB.tg skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\vvgeowbv.exe.vir Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\x22\c124wvr.exe.vir Infected: Trojan-Downloader.Win32.Small.gks skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP482\A0024074.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP482\A0024075.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP482\A0024078.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP482\A0024078.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP482\A0024079.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP482\A0024079.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP482\A0024081.exe Infected: Trojan-Downloader.Win32.Agent.erf skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP482\A0024082.dll Infected: Trojan-Downloader.Win32.VB.bpt skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP482\A0024098.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP482\A0024100.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP485\A0024528.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP486\A0024549.exe Infected: Trojan-Downloader.Win32.Small.gks skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP486\A0024595.exe Infected: Trojan-Dropper.Win32.VB.tg skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP487\A0024718.exe Infected: Trojan-Downloader.Win32.VB.bqc skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP487\A0024719.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP487\A0024721.exe Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP487\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\ambient\frogBird.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\ambient\rabbitSquirrel.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\ambient\storyland.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\audio.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\bird\Bird_Flaps.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\bird\Bird_Hops.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\Bong.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\dollhouse\Erase_Room.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\dollhouse\Furniture_Anchored.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\dollhouse\Furniture_Drop.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\dollhouse\Princess_Placement.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\frog\Frog_Jump.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\frog\Heart_Reveal.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\frog\Spash.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\generic\Game_Begin.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\generic\Game_Over.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\generic\Heart_Capture_Gold.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\generic\Heart_Capture_Red.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\generic\Pop_up_Dialog.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\rabbit\Heart_Reveal.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\rabbit\Rabbit_hop_NPC.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\rabbit\Rabbit_hop_PC.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\rabbit\Shape_Circle.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\rabbit\Shape_Diamond.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\rabbit\Shape_Heart.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\rabbit\Shape_Square.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\rabbit\Wrong_Red.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\squirrel\Lateral_Move.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\squirrel\Running_Loop.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\storyland\NPC_Crystal_poof.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\storyland\NPC_Disappear_poof.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\storyland\NPC_Reappear_poof.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\storyland\Princess_Click_Crystal.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\storyland\Princess_Disappear_poof.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\storyland\Princess_Reappear_poof.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\fx\storyland\Storyland_Victory.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\ui\generic\Game_Rollover.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\ui\generic\Menu_Click.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\ui\generic\Menu_Rollover.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\ui\store\Scroll_Arrows.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_01.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_05.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_10.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_100.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_101.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_102.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_103.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_104.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_105.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_109.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_110.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_111.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_112.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_115.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_117.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_118.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_119.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_120.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_121.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_122.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_123.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_124.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_125.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_126.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_129.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_130.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_132.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_134.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_22.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_26.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_31.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_35.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_37.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_39.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_41.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_44.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_45.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_47.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_49.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_50.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_51.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_53.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_54.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_55.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_56.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_58.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_59.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_61.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_63.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_64.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_66.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_67.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_68.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_75.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_77.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_79.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_81.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_83.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_86.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_87.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_88.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_89.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_91.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_92.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_93.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_94.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_97.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_98.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\audio\voice\dgd_dpcp_99.mp3 Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\data\furniture.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\data\game v0.46.track Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\data\game.track Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\data\storyland.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\data\strings.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\DisneyPrincess.exe Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ICON_Cinderella_128x128.ico Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\INSTALL.LOG Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiButterflyAnim01.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiButtons.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiColors.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiCommonDlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiCreditsDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\Uicursoranim.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiCursorOff.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDlgBack.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDlgBackTrans50.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDlgBackTrans75.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDlgFurnitureBack.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDlgLine.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDlgWhite.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDollhouse01Dlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDollhouse02Dlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDollhouseBedDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDollhouseEraseDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDollhousePrintDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDollhouseSelectDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDollhouseSitDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDollhouseTeaDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiDollhouseThroneDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiEraseGameConfDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiEraseGameDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiFontAvantGarde18.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiFontAvantGarde18.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiFonts.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiFurnitureBuyDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiFurnitureMoneyDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiFurniturePartialDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiFurnitureShopDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiFurnObjects01Dlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiFurnObjects02Dlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame01aDlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame01Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame01FrogAnim.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame02aDlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame02Background.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame02Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame02SquirAnim.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame03aDlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame03BRabbitBack.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame03BRabbitClap.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame03BRabbitForw.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame03BRabbitLeft.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame03Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame03RabbitBack.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame03RabbitForw.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame03RabbitLeft.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame04aDlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame04Background.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame04BirdAnim.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGame04Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGameEnter01Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGameEnter02Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGameEnter03Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGameEnter04Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGameExit01Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGameExit02Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGameExit03Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGameExit04Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGameOverDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGameSelectDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiGameSignalsDlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpDollhouse02Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpDollhouseDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpDollhouseSelectDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpFurniture02Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpFurnitureDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpGame01Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpGame02Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpGame03Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpGame04Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpGameSelectDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpMainDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpPrincessDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpPurchaseDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpSave01Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpSave02Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpSave03Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpStoryland02Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpStorylandDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpTitle02Dlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiHelpTitleDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiInfoDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiLoadingScreen.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiMain01Dlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiMain02Dlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiMain03Dlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiMainDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiPopup01Dlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiPrincess01Dlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiPrincess02Dlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiPrincessSelectDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiPurchaseDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiQuitDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiRipple.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiSaveGameDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiScreens.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiStoryland01Dlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiStoryland02Dlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiStorylandAnim01.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiStorylandDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiStorylandVictoryDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiSysFileDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiSysGameEditDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiSysHitDistDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiSysMiniGameEditDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiSysSignalEditDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiSysSpawnEditDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiTextures.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiTitleDlg.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiTitleDlg.img Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\ui\uiWidgets.idb Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\UNWISE.EXE Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\users\user1.data Object is locked skipped
E:\Program Files\Disney\Disney Online\Princess Castle Party\users\user2.data Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{130EA137-3C0C-4E9E-8430-9C612C0168F7}\RP487\change.log Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\browser.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped

Scan process completed.
  • 0

#8
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please go to Start > My Computer >C:
and delete these files:

C:\1A01.tmp
C:\1A0D.tmp

Also delete SmitfraudFix from your desktop.
Empty your recycle bin.

Then go to Start > Run and type in Combofix /u
===============================
After that Your log is clean. :)

The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.

Spybot Search & Destroy-Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.

Ad-Aware-Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.

Spyware Blaster - Great prevention tool to keep nasties from installing on your system.

Spywareguard-Works as a Spyware "Shield" to protect your computer from getting malware in the first place.

IE-SPYAD- puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

Castle Cops To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.

If you have any further problems please feel free to contact G2Go.:)
  • 0

#9
Iborange

Iborange

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Done and Done.... All seems to be working well, Thanks so much for all your help :)
  • 0

#10
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
You are welcome. :)

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If your the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP