Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Problem installing HijackThis [RESOLVED]


  • This topic is locked This topic is locked

#1
cleanprophet

cleanprophet

    Member

  • Member
  • PipPip
  • 92 posts
The problem i am having with my computer is preventing me from downloading HijackThis. When i try to run the software i get an error message (win32 is not a valid application). The same problem i get when i try to run most virus scanning software. I tried to use the Panda scan, but had trouble there also.

I did use Trojan Remover and that removed the problem that was affecting my access to the internet. This the report i got from Trojan Remover (it shows some errors, such as the fact that i cannot use safe mode on my computer):

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
121: 2008-03-07 13:28:01 UTC - RP121 - Deckard's System Scanner Restore Point
120: 2008-03-07 12:39:05 UTC - RP120 - System Checkpoint
119: 2008-03-05 23:41:18 UTC - RP119 - System Checkpoint
118: 2008-03-04 22:47:25 UTC - RP118 - System Checkpoint
117: 2008-03-03 17:09:18 UTC - RP117 - System Checkpoint


-- First Restore Point --
1: 2007-12-18 12:15:57 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-03-07 13:30:20
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Ahead\InCD\incdsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\blueyonder IST\SmartBridge\MotiveSB.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
C:\Program Files\eMule\emule.exe
C:\Documents and Settings\Scott\Desktop\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.c...earch.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.c...earch.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.rd.yahoo.c...earch.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.c...earch.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R3 - URLSearchHook: SH Class - {23EF65E8-0D45-46a0-A994-B58CBEE373A9} - C:\WINDOWS\system32\MSACP32.dll
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BHOMSACP Class - {2CE97F9E-00B2-4d2f-BB15-8B36BDAE70E7} - C:\WINDOWS\system32\MSACP32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: The egodktf - {8D911181-10AA-4B3E-BC7F-8D4AD359921B} - C:\WINDOWS\egodktf.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BLUEYO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\blueyonder-istconfig.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager...unttracking.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_03) - http://javadl-esd.su...ows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\incdsrv.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\system32\slserv.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


--
End of file - 10351 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 srosa (Megadrv3) - c:\windows\system32\drivers\srosa.sys

S3 giveio - c:\windows\system32\giveio.sys
S3 PPDrv (Protector Plus Driver (UnRegistered)) - c:\protector plus\ppdrv.sys (file missing)
S3 PPEMSCAN (Protector Plus Email Scan Driver) - c:\protector plus\ppemscan.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

All services whitelisted.


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-03-07 13:31:00 254 --a------ C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job


-- Files created between 2008-02-07 and 2008-03-07 -----------------------------

2008-03-07 12:07:51 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-05 17:08:38 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-05 17:08:36 0 d-------- C:\Documents and Settings\Scott\Application Data\Mozilla
2008-03-04 23:31:05 58884 --a------ C:\WINDOWS\system32\mdelk.exe
2008-03-01 02:34:29 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-01 02:34:17 0 d-------- C:\Program Files\Windows Live
2008-03-01 02:34:05 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-14 20:13:37 0 d-------- C:\Documents and Settings\All Users\Application Data\TVU networks
2008-02-13 19:34:55 0 d-------- C:\Documents and Settings\Scott\Application Data\River Past G4
2008-02-13 19:33:48 161532 --a------ C:\WINDOWS\Audio Converter Pro Uninstaller.exe
2008-02-13 19:33:47 0 d-------- C:\Program Files\Common Files\River Past
2008-02-13 19:33:47 0 d-------- C:\Documents and Settings\All Users\Application Data\River Past G4
2008-02-13 18:25:29 1245184 --a------ C:\WINDOWS\system32\bkll.dll <Not Verified; NCT Company Ltd.; NCTRMFile ActiveX DLL>
2008-02-13 18:25:29 215552 --a------ C:\WINDOWS\system32\ALOWMVFile.dll <Not Verified; NCT Company Ltd.; NCTWMVFile ActiveX DLL>
2008-02-13 18:25:29 188416 --a------ C:\WINDOWS\system32\ALOVideoFile.dll <Not Verified; NCT Company Ltd.; NCTVideoFile ActiveX DLL>
2008-02-13 18:25:29 249856 --a------ C:\WINDOWS\system32\ALOQuickTimeFile.dll <Not Verified; Online Media Technologies Company Ltd.; NCTQuickTimeFile Module>
2008-02-13 18:25:28 495104 --a------ C:\WINDOWS\system32\ALOVideoCoreM.dll <Not Verified; NCT Company Ltd.; NCTVideoCoreM ActiveX DLL>
2008-02-13 18:25:28 382464 --a------ C:\WINDOWS\system32\ALOAVIFile.dll <Not Verified; NCT Company Ltd.; NCTAVIFile ActiveX DLL>
2008-02-13 18:25:27 780288 --a------ C:\WINDOWS\system32\ALOVideoCompress.dll <Not Verified; NCT Company Ltd.; NCTVideoCompress ActiveX DLL>
2008-02-13 18:25:27 90112 --a------ C:\WINDOWS\system32\ALOAudioFormatSettings3.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioFormatSettings3 Module>
2008-02-13 18:25:27 2846720 --a------ C:\WINDOWS\system32\ALOAudioCompress3.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioCompress3 Module>
2008-02-13 18:25:27 778240 --a------ C:\WINDOWS\system32\ALOAudioCompress2.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioCompress2 Module>
2008-02-13 18:25:26 403968 --a------ C:\WINDOWS\system32\ALOWMAFile2.dll <Not Verified; Online Media Technologies Ltd.; NCTWMAFile2 ActiveX DLL>
2008-02-13 18:25:26 877568 --a------ C:\WINDOWS\system32\ALOAudioFile2.dll <Not Verified; NCT Company Ltd.; NCTAudioFile2 ActiveX DLL>
2008-02-13 18:25:25 1 --a------ C:\WINDOWS\dedlat2.dll
2008-02-13 18:25:22 0 d-------- C:\WINDOWS\system32\RMBin
2008-02-13 18:24:54 12343516 ---h----- C:\WINDOWS\system32\temptime.exe <Not Verified; ALO SOFT, Inc.; >
2008-02-13 18:17:23 0 d-------- C:\Temp
2008-02-11 22:01:59 0 d-------- C:\Poker
2008-02-08 20:04:33 167936 --a------ C:\WINDOWS\system32\SpoonUninstall.exe
2008-02-08 19:28:59 0 d-------- C:\Program Files\Soulseek-Test


-- Find3M Report ---------------------------------------------------------------

2008-03-07 13:20:46 0 d-------- C:\Program Files\eMule
2008-03-07 13:04:13 0 d-------- C:\Documents and Settings\Scott\Application Data\Azureus
2008-03-07 11:50:12 4 --a------ C:\autoexec.bat
2008-03-05 09:02:47 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-05 09:02:46 0 d-------- C:\Program Files\Norton AntiVirus
2008-03-03 10:06:02 0 d-------- C:\Program Files\Symantec
2008-03-01 02:34:29 0 d-------- C:\Program Files\Common Files
2008-02-28 09:04:21 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-02-14 20:17:04 0 d-------- C:\Program Files\TVUPlayer
2008-02-07 23:29:47 0 d-------- C:\Program Files\Azureus
2008-01-29 17:27:51 0 d-------- C:\Program Files\TVAnts
2008-01-21 23:05:35 0 d-------- C:\Program Files\Enigma Software Group
2008-01-21 16:14:32 0 d-------- C:\Program Files\Printer
2008-01-21 16:09:45 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-21 16:09:35 0 d-------- C:\Program Files\EPSON
2008-01-21 16:07:02 0 d-------- C:\Program Files\EPSON Print CD
2008-01-21 15:46:40 5248 --a------ C:\WINDOWS\system32\giveio.sys
2008-01-21 15:36:09 0 d-------- C:\Program Files\SSC Service Utility
2008-01-21 07:13:11 0 d-------- C:\Program Files\Windows Desktop Search
2008-01-20 21:26:00 0 d-------- C:\Documents and Settings\Scott\Application Data\Real
2008-01-20 21:20:11 0 d-------- C:\Program Files\Common Files\xing shared
2008-01-20 21:20:09 0 d-------- C:\Program Files\Common Files\Real
2008-01-20 21:19:52 0 d-------- C:\Program Files\Real
2008-01-19 09:26:05 0 d-------- C:\Documents and Settings\Scott\Application Data\Adobe
2008-01-19 09:24:59 0 d-------- C:\Program Files\Common Files\Adobe
2008-01-18 13:41:59 0 d-------- C:\Program Files\coverXP
2008-01-13 15:14:25 0 d-------- C:\Program Files\CUEcards 2000
2008-01-13 01:43:38 0 d-------- C:\Program Files\Lavasoft
2008-01-08 15:30:06 135168 --a------ C:\WINDOWS\system32\MSACP32.dll <Not Verified; Matrix Technology Network, S.A.; MSACP32.dll>
2008-01-08 13:19:13 0 d-------- C:\Documents and Settings\Scott\Application Data\InstallShield
2008-01-07 15:37:19 0 d-------- C:\Documents and Settings\Scott\Application Data\CyberLink
2007-12-28 15:44:14 6211190 --a------ C:\Program Files\Combined-Community-Codec-Pack-2007-07-22.exe <Not Verified; CCCP Project; >
2007-12-20 23:11:52 81920 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2007-12-18 11:21:55 0 -rahs---- C:\MSDOS.SYS
2007-12-18 11:21:55 0 -rahs---- C:\IO.SYS
2007-12-18 11:21:55 0 --a------ C:\CONFIG.SYS
2007-12-18 11:19:34 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-12-18 10:43:06 62 --ahs---- C:\Documents and Settings\Scott\Application Data\desktop.ini


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2CE97F9E-00B2-4d2f-BB15-8B36BDAE70E7}]
08/01/2008 15:30 135168 --a------ C:\WINDOWS\system32\MSACP32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [13/01/2007 01:47]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [13/01/2007 01:47]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [13/01/2007 01:46]
"RTHDCPL"="RTHDCPL.EXE" [12/09/2006 08:58 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [16/05/2006 10:04 C:\WINDOWS\SkyTel.exe]
"Alcmtr"="ALCMTR.EXE" [03/05/2005 10:43 C:\WINDOWS\Alcmtr.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [31/10/2003 19:42]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [07/03/2008 13:20]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [07/03/2008 13:20]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [25/09/2007 01:11]
"Motive SmartBridge"="C:\PROGRA~1\BLUEYO~1\SMARTB~1\MotiveSB.exe" [21/04/2006 15:41]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [22/03/2005 09:39]
"DataLayer"="C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe" [31/03/2005 09:30]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [24/08/2007 07:00]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" []
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" []
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [07/03/2008 13:20]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [16/09/2004 16:15]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [03/06/2005 06:07]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [30/08/2007 17:43]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 12:00]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [20/04/2005 09:57]

C:\Documents and Settings\Scott\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [24/08/2007 04:45:42]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
blueyonder Instant Support Tool.lnk - C:\Program Files\blueyonder IST\bin\blueyonder-istconfig.exe [19/12/2007 01:31:22]

SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"




-- Hosts -----------------------------------------------------------------------

66.98.148.65 auto.search.msn.com


-- End of Deckard's System Scanner: finished at 2008-03-07 13:31:59 ------------
  • 0

Advertisements


#2
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hello cleanprophet

Welcome to G2Go. :)
=================
Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    Posted Image

    Posted Image

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\Combo-Fix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
  • 0

#3
cleanprophet

cleanprophet

    Member

  • Topic Starter
  • Member
  • PipPip
  • 92 posts
I wasn't able to change the name of Combofix. I had to click on run (rather than save it to the desktop) and once i did that i was unable to change the name.

It did complete a scan and seemed to delete a lot of files in system32. But, when it rebooted it never gave me a log report. The blue screen that said "preparing the log report" did not change. I waited about 25mins, but no report was forthcoming.

I have now been able to run HijackThis and here is the log report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:20, on 2008-03-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\BLUEYO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\blueyonder IST\bin\blueyonder-istupdate.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\PROGRA~1\Motive\ASSTCO~1\MOTIVE~1.EXE
C:\WINDOWS\explorer.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.c...earch.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.rd.yahoo.c...earch.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.c...earch.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.c...earch.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: SH Class - {23EF65E8-0D45-46a0-A994-B58CBEE373A9} - C:\WINDOWS\system32\MSACP32.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BHOMSACP Class - {2CE97F9E-00B2-4d2f-BB15-8B36BDAE70E7} - C:\WINDOWS\system32\MSACP32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: The egodktf - {8D911181-10AA-4B3E-BC7F-8D4AD359921B} - C:\WINDOWS\egodktf.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BLUEYO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\blueyonder-istconfig.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager...unttracking.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.su...ows-i586-jc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Unknown owner - C:\Program Files\Norton AntiVirus\isPwdSvc.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

--
End of file - 9576 bytes

Edited by cleanprophet, 07 March 2008 - 04:22 PM.

  • 0

#4
cleanprophet

cleanprophet

    Member

  • Topic Starter
  • Member
  • PipPip
  • 92 posts
Looks like Combofix has sorted the problem. After running that program i was able to install and run my other anti-virus software (ZoneAlarm, Norton etc). So, it looks like the problem has been fixed. Thanks for your help.
  • 0

#5
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Yep it looks as if it cleaned it can you please do one thing for me and look here>C:\Combofix\combofix.txt
Open that file and see if there is a report please and post the results here.
Thanks.
  • 0

#6
cleanprophet

cleanprophet

    Member

  • Topic Starter
  • Member
  • PipPip
  • 92 posts
No problem. Here's the ComboFix.txt (it's quite long though):

ComboFix 08-03-07.3 - Scott 2008-03-07 21:56:01.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.583 [GMT 0:00]
Running from: C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\NFI1SMCY\ComboFix[1].exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\adaway.lic
C:\WINDOWS\system32\drivers\down
C:\WINDOWS\system32\drivers\down\100281.exe
C:\WINDOWS\system32\drivers\down\100390.exe
C:\WINDOWS\system32\drivers\down\100437.exe
C:\WINDOWS\system32\drivers\down\100562.exe
C:\WINDOWS\system32\drivers\down\100640.exe
C:\WINDOWS\system32\drivers\down\100984.exe
C:\WINDOWS\system32\drivers\down\101031.exe
C:\WINDOWS\system32\drivers\down\101281.exe
C:\WINDOWS\system32\drivers\down\101625.exe
C:\WINDOWS\system32\drivers\down\101765.exe
C:\WINDOWS\system32\drivers\down\103109.exe
C:\WINDOWS\system32\drivers\down\103203.exe
C:\WINDOWS\system32\drivers\down\103218.exe
C:\WINDOWS\system32\drivers\down\103359.exe
C:\WINDOWS\system32\drivers\down\103687.exe
C:\WINDOWS\system32\drivers\down\103953.exe
C:\WINDOWS\system32\drivers\down\104343.exe
C:\WINDOWS\system32\drivers\down\104375.exe
C:\WINDOWS\system32\drivers\down\105281.exe
C:\WINDOWS\system32\drivers\down\105359.exe
C:\WINDOWS\system32\drivers\down\105453.exe
C:\WINDOWS\system32\drivers\down\105734.exe
C:\WINDOWS\system32\drivers\down\105765.exe
C:\WINDOWS\system32\drivers\down\106171.exe
C:\WINDOWS\system32\drivers\down\106343.exe
C:\WINDOWS\system32\drivers\down\106437.exe
C:\WINDOWS\system32\drivers\down\106671.exe
C:\WINDOWS\system32\drivers\down\106750.exe
C:\WINDOWS\system32\drivers\down\106828.exe
C:\WINDOWS\system32\drivers\down\107093.exe
C:\WINDOWS\system32\drivers\down\107171.exe
C:\WINDOWS\system32\drivers\down\107343.exe
C:\WINDOWS\system32\drivers\down\107828.exe
C:\WINDOWS\system32\drivers\down\108484.exe
C:\WINDOWS\system32\drivers\down\108531.exe
C:\WINDOWS\system32\drivers\down\108562.exe
C:\WINDOWS\system32\drivers\down\108593.exe
C:\WINDOWS\system32\drivers\down\108750.exe
C:\WINDOWS\system32\drivers\down\108953.exe
C:\WINDOWS\system32\drivers\down\109078.exe
C:\WINDOWS\system32\drivers\down\109796.exe
C:\WINDOWS\system32\drivers\down\110078.exe
C:\WINDOWS\system32\drivers\down\110406.exe
C:\WINDOWS\system32\drivers\down\110421.exe
C:\WINDOWS\system32\drivers\down\110453.exe
C:\WINDOWS\system32\drivers\down\111437.exe
C:\WINDOWS\system32\drivers\down\111750.exe
C:\WINDOWS\system32\drivers\down\111906.exe
C:\WINDOWS\system32\drivers\down\111937.exe
C:\WINDOWS\system32\drivers\down\112062.exe
C:\WINDOWS\system32\drivers\down\112140.exe
C:\WINDOWS\system32\drivers\down\112156.exe
C:\WINDOWS\system32\drivers\down\112500.exe
C:\WINDOWS\system32\drivers\down\112796.exe
C:\WINDOWS\system32\drivers\down\113125.exe
C:\WINDOWS\system32\drivers\down\113187.exe
C:\WINDOWS\system32\drivers\down\113500.exe
C:\WINDOWS\system32\drivers\down\113609.exe
C:\WINDOWS\system32\drivers\down\113828.exe
C:\WINDOWS\system32\drivers\down\113890.exe
C:\WINDOWS\system32\drivers\down\114171.exe
C:\WINDOWS\system32\drivers\down\114359.exe
C:\WINDOWS\system32\drivers\down\114718.exe
C:\WINDOWS\system32\drivers\down\114781.exe
C:\WINDOWS\system32\drivers\down\114796.exe
C:\WINDOWS\system32\drivers\down\114843.exe
C:\WINDOWS\system32\drivers\down\114906.exe
C:\WINDOWS\system32\drivers\down\115000.exe
C:\WINDOWS\system32\drivers\down\115046.exe
C:\WINDOWS\system32\drivers\down\115156.exe
C:\WINDOWS\system32\drivers\down\115281.exe
C:\WINDOWS\system32\drivers\down\115312.exe
C:\WINDOWS\system32\drivers\down\116062.exe
C:\WINDOWS\system32\drivers\down\116421.exe
C:\WINDOWS\system32\drivers\down\116468.exe
C:\WINDOWS\system32\drivers\down\116484.exe
C:\WINDOWS\system32\drivers\down\116625.exe
C:\WINDOWS\system32\drivers\down\116781.exe
C:\WINDOWS\system32\drivers\down\117171.exe
C:\WINDOWS\system32\drivers\down\117265.exe
C:\WINDOWS\system32\drivers\down\118375.exe
C:\WINDOWS\system32\drivers\down\118390.exe
C:\WINDOWS\system32\drivers\down\118781.exe
C:\WINDOWS\system32\drivers\down\118984.exe
C:\WINDOWS\system32\drivers\down\119765.exe
C:\WINDOWS\system32\drivers\down\119890.exe
C:\WINDOWS\system32\drivers\down\119906.exe
C:\WINDOWS\system32\drivers\down\120140.exe
C:\WINDOWS\system32\drivers\down\120281.exe
C:\WINDOWS\system32\drivers\down\120484.exe
C:\WINDOWS\system32\drivers\down\120515.exe
C:\WINDOWS\system32\drivers\down\120828.exe
C:\WINDOWS\system32\drivers\down\120906.exe
C:\WINDOWS\system32\drivers\down\121359.exe
C:\WINDOWS\system32\drivers\down\121500.exe
C:\WINDOWS\system32\drivers\down\121796.exe
C:\WINDOWS\system32\drivers\down\121812.exe
C:\WINDOWS\system32\drivers\down\121953.exe
C:\WINDOWS\system32\drivers\down\121984.exe
C:\WINDOWS\system32\drivers\down\122234.exe
C:\WINDOWS\system32\drivers\down\122406.exe
C:\WINDOWS\system32\drivers\down\122515.exe
C:\WINDOWS\system32\drivers\down\123406.exe
C:\WINDOWS\system32\drivers\down\123578.exe
C:\WINDOWS\system32\drivers\down\124234.exe
C:\WINDOWS\system32\drivers\down\124656.exe
C:\WINDOWS\system32\drivers\down\125046.exe
C:\WINDOWS\system32\drivers\down\125484.exe
C:\WINDOWS\system32\drivers\down\125500.exe
C:\WINDOWS\system32\drivers\down\125781.exe
C:\WINDOWS\system32\drivers\down\125812.exe
C:\WINDOWS\system32\drivers\down\126000.exe
C:\WINDOWS\system32\drivers\down\126328.exe
C:\WINDOWS\system32\drivers\down\126718.exe
C:\WINDOWS\system32\drivers\down\127312.exe
C:\WINDOWS\system32\drivers\down\127656.exe
C:\WINDOWS\system32\drivers\down\127828.exe
C:\WINDOWS\system32\drivers\down\128312.exe
C:\WINDOWS\system32\drivers\down\128375.exe
C:\WINDOWS\system32\drivers\down\128640.exe
C:\WINDOWS\system32\drivers\down\128968.exe
C:\WINDOWS\system32\drivers\down\129015.exe
C:\WINDOWS\system32\drivers\down\129031.exe
C:\WINDOWS\system32\drivers\down\129218.exe
C:\WINDOWS\system32\drivers\down\129796.exe
C:\WINDOWS\system32\drivers\down\130078.exe
C:\WINDOWS\system32\drivers\down\130234.exe
C:\WINDOWS\system32\drivers\down\130968.exe
C:\WINDOWS\system32\drivers\down\131109.exe
C:\WINDOWS\system32\drivers\down\131328.exe
C:\WINDOWS\system32\drivers\down\131578.exe
C:\WINDOWS\system32\drivers\down\131718.exe
C:\WINDOWS\system32\drivers\down\131812.exe
C:\WINDOWS\system32\drivers\down\132437.exe
C:\WINDOWS\system32\drivers\down\132484.exe
C:\WINDOWS\system32\drivers\down\132609.exe
C:\WINDOWS\system32\drivers\down\132625.exe
C:\WINDOWS\system32\drivers\down\132828.exe
C:\WINDOWS\system32\drivers\down\132890.exe
C:\WINDOWS\system32\drivers\down\133781.exe
C:\WINDOWS\system32\drivers\down\133843.exe
C:\WINDOWS\system32\drivers\down\134406.exe
C:\WINDOWS\system32\drivers\down\134765.exe
C:\WINDOWS\system32\drivers\down\134781.exe
C:\WINDOWS\system32\drivers\down\134968.exe
C:\WINDOWS\system32\drivers\down\135453.exe
C:\WINDOWS\system32\drivers\down\135640.exe
C:\WINDOWS\system32\drivers\down\135843.exe
C:\WINDOWS\system32\drivers\down\135875.exe
C:\WINDOWS\system32\drivers\down\136531.exe
C:\WINDOWS\system32\drivers\down\136625.exe
C:\WINDOWS\system32\drivers\down\136765.exe
C:\WINDOWS\system32\drivers\down\136843.exe
C:\WINDOWS\system32\drivers\down\137343.exe
C:\WINDOWS\system32\drivers\down\137375.exe
C:\WINDOWS\system32\drivers\down\137484.exe
C:\WINDOWS\system32\drivers\down\138015.exe
C:\WINDOWS\system32\drivers\down\138312.exe
C:\WINDOWS\system32\drivers\down\138328.exe
C:\WINDOWS\system32\drivers\down\138359.exe
C:\WINDOWS\system32\drivers\down\138765.exe
C:\WINDOWS\system32\drivers\down\138796.exe
C:\WINDOWS\system32\drivers\down\138953.exe
C:\WINDOWS\system32\drivers\down\138984.exe
C:\WINDOWS\system32\drivers\down\139109.exe
C:\WINDOWS\system32\drivers\down\139328.exe
C:\WINDOWS\system32\drivers\down\139375.exe
C:\WINDOWS\system32\drivers\down\139609.exe
C:\WINDOWS\system32\drivers\down\139640.exe
C:\WINDOWS\system32\drivers\down\140312.exe
C:\WINDOWS\system32\drivers\down\140406.exe
C:\WINDOWS\system32\drivers\down\140593.exe
C:\WINDOWS\system32\drivers\down\140671.exe
C:\WINDOWS\system32\drivers\down\140796.exe
C:\WINDOWS\system32\drivers\down\140984.exe
C:\WINDOWS\system32\drivers\down\141875.exe
C:\WINDOWS\system32\drivers\down\142031.exe
C:\WINDOWS\system32\drivers\down\142250.exe
C:\WINDOWS\system32\drivers\down\142500.exe
C:\WINDOWS\system32\drivers\down\142609.exe
C:\WINDOWS\system32\drivers\down\142968.exe
C:\WINDOWS\system32\drivers\down\143046.exe
C:\WINDOWS\system32\drivers\down\143125.exe
C:\WINDOWS\system32\drivers\down\143171.exe
C:\WINDOWS\system32\drivers\down\143218.exe
C:\WINDOWS\system32\drivers\down\143359.exe
C:\WINDOWS\system32\drivers\down\143578.exe
C:\WINDOWS\system32\drivers\down\143609.exe
C:\WINDOWS\system32\drivers\down\143687.exe
C:\WINDOWS\system32\drivers\down\144093.exe
C:\WINDOWS\system32\drivers\down\144671.exe
C:\WINDOWS\system32\drivers\down\144718.exe
C:\WINDOWS\system32\drivers\down\145140.exe
C:\WINDOWS\system32\drivers\down\145281.exe
C:\WINDOWS\system32\drivers\down\145359.exe
C:\WINDOWS\system32\drivers\down\145750.exe
C:\WINDOWS\system32\drivers\down\145765.exe
C:\WINDOWS\system32\drivers\down\145781.exe
C:\WINDOWS\system32\drivers\down\145843.exe
C:\WINDOWS\system32\drivers\down\146218.exe
C:\WINDOWS\system32\drivers\down\146359.exe
C:\WINDOWS\system32\drivers\down\147218.exe
C:\WINDOWS\system32\drivers\down\147484.exe
C:\WINDOWS\system32\drivers\down\14752453.exe
C:\WINDOWS\system32\drivers\down\14756078.exe
C:\WINDOWS\system32\drivers\down\14757015.exe
C:\WINDOWS\system32\drivers\down\14759031.exe
C:\WINDOWS\system32\drivers\down\14761546.exe
C:\WINDOWS\system32\drivers\down\14780140.exe
C:\WINDOWS\system32\drivers\down\14785093.exe
C:\WINDOWS\system32\drivers\down\147859.exe
C:\WINDOWS\system32\drivers\down\14791265.exe
C:\WINDOWS\system32\drivers\down\14793812.exe
C:\WINDOWS\system32\drivers\down\14801484.exe
C:\WINDOWS\system32\drivers\down\148078.exe
C:\WINDOWS\system32\drivers\down\14809093.exe
C:\WINDOWS\system32\drivers\down\14823453.exe
C:\WINDOWS\system32\drivers\down\14836375.exe
C:\WINDOWS\system32\drivers\down\148406.exe
C:\WINDOWS\system32\drivers\down\148671.exe
C:\WINDOWS\system32\drivers\down\14869703.exe
C:\WINDOWS\system32\drivers\down\149046.exe
C:\WINDOWS\system32\drivers\down\149515.exe
C:\WINDOWS\system32\drivers\down\149781.exe
C:\WINDOWS\system32\drivers\down\150375.exe
C:\WINDOWS\system32\drivers\down\150421.exe
C:\WINDOWS\system32\drivers\down\150687.exe
C:\WINDOWS\system32\drivers\down\151312.exe
C:\WINDOWS\system32\drivers\down\151531.exe
C:\WINDOWS\system32\drivers\down\151984.exe
C:\WINDOWS\system32\drivers\down\152062.exe
C:\WINDOWS\system32\drivers\down\152296.exe
C:\WINDOWS\system32\drivers\down\152718.exe
C:\WINDOWS\system32\drivers\down\152828.exe
C:\WINDOWS\system32\drivers\down\152875.exe
C:\WINDOWS\system32\drivers\down\153078.exe
C:\WINDOWS\system32\drivers\down\153875.exe
C:\WINDOWS\system32\drivers\down\154203.exe
C:\WINDOWS\system32\drivers\down\154359.exe
C:\WINDOWS\system32\drivers\down\154875.exe
C:\WINDOWS\system32\drivers\down\154921.exe
C:\WINDOWS\system32\drivers\down\154937.exe
C:\WINDOWS\system32\drivers\down\155140.exe
C:\WINDOWS\system32\drivers\down\155171.exe
C:\WINDOWS\system32\drivers\down\155484.exe
C:\WINDOWS\system32\drivers\down\155578.exe
C:\WINDOWS\system32\drivers\down\155593.exe
C:\WINDOWS\system32\drivers\down\156375.exe
C:\WINDOWS\system32\drivers\down\156500.exe
C:\WINDOWS\system32\drivers\down\156578.exe
C:\WINDOWS\system32\drivers\down\156625.exe
C:\WINDOWS\system32\drivers\down\156843.exe
C:\WINDOWS\system32\drivers\down\157250.exe
C:\WINDOWS\system32\drivers\down\157343.exe
C:\WINDOWS\system32\drivers\down\157625.exe
C:\WINDOWS\system32\drivers\down\158265.exe
C:\WINDOWS\system32\drivers\down\159093.exe
C:\WINDOWS\system32\drivers\down\159281.exe
C:\WINDOWS\system32\drivers\down\159593.exe
C:\WINDOWS\system32\drivers\down\159812.exe
C:\WINDOWS\system32\drivers\down\160234.exe
C:\WINDOWS\system32\drivers\down\160687.exe
C:\WINDOWS\system32\drivers\down\160812.exe
C:\WINDOWS\system32\drivers\down\160890.exe
C:\WINDOWS\system32\drivers\down\160906.exe
C:\WINDOWS\system32\drivers\down\161203.exe
C:\WINDOWS\system32\drivers\down\161296.exe
C:\WINDOWS\system32\drivers\down\161484.exe
C:\WINDOWS\system32\drivers\down\161515.exe
C:\WINDOWS\system32\drivers\down\161765.exe
C:\WINDOWS\system32\drivers\down\161812.exe
C:\WINDOWS\system32\drivers\down\161859.exe
C:\WINDOWS\system32\drivers\down\161890.exe
C:\WINDOWS\system32\drivers\down\162437.exe
C:\WINDOWS\system32\drivers\down\162515.exe
C:\WINDOWS\system32\drivers\down\164031.exe
C:\WINDOWS\system32\drivers\down\164968.exe
C:\WINDOWS\system32\drivers\down\165046.exe
C:\WINDOWS\system32\drivers\down\165109.exe
C:\WINDOWS\system32\drivers\down\165265.exe
C:\WINDOWS\system32\drivers\down\165765.exe
C:\WINDOWS\system32\drivers\down\166078.exe
C:\WINDOWS\system32\drivers\down\166375.exe
C:\WINDOWS\system32\drivers\down\167062.exe
C:\WINDOWS\system32\drivers\down\167453.exe
C:\WINDOWS\system32\drivers\down\168078.exe
C:\WINDOWS\system32\drivers\down\170781.exe
C:\WINDOWS\system32\drivers\down\171500.exe
C:\WINDOWS\system32\drivers\down\172031.exe
C:\WINDOWS\system32\drivers\down\172234.exe
C:\WINDOWS\system32\drivers\down\172515.exe
C:\WINDOWS\system32\drivers\down\172687.exe
C:\WINDOWS\system32\drivers\down\173343.exe
C:\WINDOWS\system32\drivers\down\173921.exe
C:\WINDOWS\system32\drivers\down\175031.exe
C:\WINDOWS\system32\drivers\down\175234.exe
C:\WINDOWS\system32\drivers\down\175625.exe
C:\WINDOWS\system32\drivers\down\175843.exe
C:\WINDOWS\system32\drivers\down\176015.exe
C:\WINDOWS\system32\drivers\down\176109.exe
C:\WINDOWS\system32\drivers\down\176703.exe
C:\WINDOWS\system32\drivers\down\176734.exe
C:\WINDOWS\system32\drivers\down\180109.exe
C:\WINDOWS\system32\drivers\down\180187.exe
C:\WINDOWS\system32\drivers\down\181500.exe
C:\WINDOWS\system32\drivers\down\181937.exe
C:\WINDOWS\system32\drivers\down\183265.exe
C:\WINDOWS\system32\drivers\down\184125.exe
C:\WINDOWS\system32\drivers\down\184796.exe
C:\WINDOWS\system32\drivers\down\185687.exe
C:\WINDOWS\system32\drivers\down\186328.exe
C:\WINDOWS\system32\drivers\down\186562.exe
C:\WINDOWS\system32\drivers\down\186671.exe
C:\WINDOWS\system32\drivers\down\188468.exe
C:\WINDOWS\system32\drivers\down\188812.exe
C:\WINDOWS\system32\drivers\down\189453.exe
C:\WINDOWS\system32\drivers\down\190500.exe
C:\WINDOWS\system32\drivers\down\191281.exe
C:\WINDOWS\system32\drivers\down\192390.exe
C:\WINDOWS\system32\drivers\down\192718.exe
C:\WINDOWS\system32\drivers\down\195843.exe
C:\WINDOWS\system32\drivers\down\196375.exe
C:\WINDOWS\system32\drivers\down\198500.exe
C:\WINDOWS\system32\drivers\down\200500.exe
C:\WINDOWS\system32\drivers\down\200562.exe
C:\WINDOWS\system32\drivers\down\202812.exe
C:\WINDOWS\system32\drivers\down\205500.exe
C:\WINDOWS\system32\drivers\down\206484.exe
C:\WINDOWS\system32\drivers\down\208546.exe
C:\WINDOWS\system32\drivers\down\209625.exe
C:\WINDOWS\system32\drivers\down\212468.exe
C:\WINDOWS\system32\drivers\down\213062.exe
C:\WINDOWS\system32\drivers\down\213843.exe
C:\WINDOWS\system32\drivers\down\215531.exe
C:\WINDOWS\system32\drivers\down\216203.exe
C:\WINDOWS\system32\drivers\down\216343.exe
C:\WINDOWS\system32\drivers\down\216359.exe
C:\WINDOWS\system32\drivers\down\217453.exe
C:\WINDOWS\system32\drivers\down\218328.exe
C:\WINDOWS\system32\drivers\down\222625.exe
C:\WINDOWS\system32\drivers\down\224125.exe
C:\WINDOWS\system32\drivers\down\224406.exe
C:\WINDOWS\system32\drivers\down\224437.exe
C:\WINDOWS\system32\drivers\down\226000.exe
C:\WINDOWS\system32\drivers\down\227765.exe
C:\WINDOWS\system32\drivers\down\228187.exe
C:\WINDOWS\system32\drivers\down\228265.exe
C:\WINDOWS\system32\drivers\down\228703.exe
C:\WINDOWS\system32\drivers\down\229390.exe
C:\WINDOWS\system32\drivers\down\229765.exe
C:\WINDOWS\system32\drivers\down\229796.exe
C:\WINDOWS\system32\drivers\down\231578.exe
C:\WINDOWS\system32\drivers\down\233421.exe
C:\WINDOWS\system32\drivers\down\234609.exe
C:\WINDOWS\system32\drivers\down\234796.exe
C:\WINDOWS\system32\drivers\down\236312.exe
C:\WINDOWS\system32\drivers\down\236609.exe
C:\WINDOWS\system32\drivers\down\238750.exe
C:\WINDOWS\system32\drivers\down\241453.exe
C:\WINDOWS\system32\drivers\down\241484.exe
C:\WINDOWS\system32\drivers\down\243796.exe
C:\WINDOWS\system32\drivers\down\244203.exe
C:\WINDOWS\system32\drivers\down\246125.exe
C:\WINDOWS\system32\drivers\down\247843.exe
C:\WINDOWS\system32\drivers\down\248312.exe
C:\WINDOWS\system32\drivers\down\249890.exe
C:\WINDOWS\system32\drivers\down\250937.exe
C:\WINDOWS\system32\drivers\down\251375.exe
C:\WINDOWS\system32\drivers\down\251578.exe
C:\WINDOWS\system32\drivers\down\256656.exe
C:\WINDOWS\system32\drivers\down\260078.exe
C:\WINDOWS\system32\drivers\down\260968.exe
C:\WINDOWS\system32\drivers\down\261531.exe
C:\WINDOWS\system32\drivers\down\266046.exe
C:\WINDOWS\system32\drivers\down\266234.exe
C:\WINDOWS\system32\drivers\down\267125.exe
C:\WINDOWS\system32\drivers\down\267625.exe
C:\WINDOWS\system32\drivers\down\276968.exe
C:\WINDOWS\system32\drivers\down\280468.exe
C:\WINDOWS\system32\drivers\down\283625.exe
C:\WINDOWS\system32\drivers\down\286171.exe
C:\WINDOWS\system32\drivers\down\287859.exe
C:\WINDOWS\system32\drivers\down\290625.exe
C:\WINDOWS\system32\drivers\down\293781.exe
C:\WINDOWS\system32\drivers\down\294984.exe
C:\WINDOWS\system32\drivers\down\298328.exe
C:\WINDOWS\system32\drivers\down\300156.exe
C:\WINDOWS\system32\drivers\down\301640.exe
C:\WINDOWS\system32\drivers\down\303843.exe
C:\WINDOWS\system32\drivers\down\310703.exe
C:\WINDOWS\system32\drivers\down\312218.exe
C:\WINDOWS\system32\drivers\down\312781.exe
C:\WINDOWS\system32\drivers\down\314859.exe
C:\WINDOWS\system32\drivers\down\317750.exe
C:\WINDOWS\system32\drivers\down\319359.exe
C:\WINDOWS\system32\drivers\down\323875.exe
C:\WINDOWS\system32\drivers\down\325515.exe
C:\WINDOWS\system32\drivers\down\329703.exe
C:\WINDOWS\system32\drivers\down\330109.exe
C:\WINDOWS\system32\drivers\down\331343.exe
C:\WINDOWS\system32\drivers\down\332640.exe
C:\WINDOWS\system32\drivers\down\333687.exe
C:\WINDOWS\system32\drivers\down\336921.exe
C:\WINDOWS\system32\drivers\down\337750.exe
C:\WINDOWS\system32\drivers\down\340687.exe
C:\WINDOWS\system32\drivers\down\353546.exe
C:\WINDOWS\system32\drivers\down\354171.exe
C:\WINDOWS\system32\drivers\down\357468.exe
C:\WINDOWS\system32\drivers\down\357484.exe
C:\WINDOWS\system32\drivers\down\360375.exe
C:\WINDOWS\system32\drivers\down\360687.exe
C:\WINDOWS\system32\drivers\down\363171.exe
C:\WINDOWS\system32\drivers\down\369234.exe
C:\WINDOWS\system32\drivers\down\371093.exe
C:\WINDOWS\system32\drivers\down\446328.exe
C:\WINDOWS\system32\drivers\down\452718.exe
C:\WINDOWS\system32\drivers\down\458640.exe
C:\WINDOWS\system32\drivers\down\461593.exe
C:\WINDOWS\system32\drivers\down\464421.exe
C:\WINDOWS\system32\drivers\down\467046.exe
C:\WINDOWS\system32\drivers\down\491281.exe
C:\WINDOWS\system32\drivers\down\567671.exe
C:\WINDOWS\system32\drivers\down\569062.exe
C:\WINDOWS\system32\drivers\down\58218.exe
C:\WINDOWS\system32\drivers\down\586562.exe
C:\WINDOWS\system32\drivers\down\589125.exe
C:\WINDOWS\system32\drivers\down\60109.exe
C:\WINDOWS\system32\drivers\down\610687.exe
C:\WINDOWS\system32\drivers\down\612234.exe
C:\WINDOWS\system32\drivers\down\61718.exe
C:\WINDOWS\system32\drivers\down\63546.exe
C:\WINDOWS\system32\drivers\down\636406.exe
C:\WINDOWS\system32\drivers\down\63859.exe
C:\WINDOWS\system32\drivers\down\63921.exe
C:\WINDOWS\system32\drivers\down\642640.exe
C:\WINDOWS\system32\drivers\down\65625.exe
C:\WINDOWS\system32\drivers\down\65687.exe
C:\WINDOWS\system32\drivers\down\66250.exe
C:\WINDOWS\system32\drivers\down\66296.exe
C:\WINDOWS\system32\drivers\down\67031.exe
C:\WINDOWS\system32\drivers\down\67359.exe
C:\WINDOWS\system32\drivers\down\67390.exe
C:\WINDOWS\system32\drivers\down\67437.exe
C:\WINDOWS\system32\drivers\down\67578.exe
C:\WINDOWS\system32\drivers\down\67812.exe
C:\WINDOWS\system32\drivers\down\68187.exe
C:\WINDOWS\system32\drivers\down\68843.exe
C:\WINDOWS\system32\drivers\down\68968.exe
C:\WINDOWS\system32\drivers\down\69312.exe
C:\WINDOWS\system32\drivers\down\69640.exe
C:\WINDOWS\system32\drivers\down\69734.exe
C:\WINDOWS\system32\drivers\down\69937.exe
C:\WINDOWS\system32\drivers\down\70406.exe
C:\WINDOWS\system32\drivers\down\70593.exe
C:\WINDOWS\system32\drivers\down\71187.exe
C:\WINDOWS\system32\drivers\down\71421.exe
C:\WINDOWS\system32\drivers\down\71562.exe
C:\WINDOWS\system32\drivers\down\71937.exe
C:\WINDOWS\system32\drivers\down\72484.exe
C:\WINDOWS\system32\drivers\down\72515.exe
C:\WINDOWS\system32\drivers\down\72718.exe
C:\WINDOWS\system32\drivers\down\73015.exe
C:\WINDOWS\system32\drivers\down\73375.exe
C:\WINDOWS\system32\drivers\down\73859.exe
C:\WINDOWS\system32\drivers\down\73921.exe
C:\WINDOWS\system32\drivers\down\74000.exe
C:\WINDOWS\system32\drivers\down\74031.exe
C:\WINDOWS\system32\drivers\down\74453.exe
C:\WINDOWS\system32\drivers\down\74703.exe
C:\WINDOWS\system32\drivers\down\74828.exe
C:\WINDOWS\system32\drivers\down\74921.exe
C:\WINDOWS\system32\drivers\down\75093.exe
C:\WINDOWS\system32\drivers\down\75250.exe
C:\WINDOWS\system32\drivers\down\75828.exe
C:\WINDOWS\system32\drivers\down\75859.exe
C:\WINDOWS\system32\drivers\down\75937.exe
C:\WINDOWS\system32\drivers\down\76187.exe
C:\WINDOWS\system32\drivers\down\76296.exe
C:\WINDOWS\system32\drivers\down\76343.exe
C:\WINDOWS\system32\drivers\down\76359.exe
C:\WINDOWS\system32\drivers\down\76531.exe
C:\WINDOWS\system32\drivers\down\76812.exe
C:\WINDOWS\system32\drivers\down\77187.exe
C:\WINDOWS\system32\drivers\down\77453.exe
C:\WINDOWS\system32\drivers\down\77890.exe
C:\WINDOWS\system32\drivers\down\78406.exe
C:\WINDOWS\system32\drivers\down\78437.exe
C:\WINDOWS\system32\drivers\down\78687.exe
C:\WINDOWS\system32\drivers\down\78703.exe
C:\WINDOWS\system32\drivers\down\79703.exe
C:\WINDOWS\system32\drivers\down\79734.exe
C:\WINDOWS\system32\drivers\down\80968.exe
C:\WINDOWS\system32\drivers\down\81109.exe
C:\WINDOWS\system32\drivers\down\81140.exe
C:\WINDOWS\system32\drivers\down\81187.exe
C:\WINDOWS\system32\drivers\down\81203.exe
C:\WINDOWS\system32\drivers\down\82078.exe
C:\WINDOWS\system32\drivers\down\82234.exe
C:\WINDOWS\system32\drivers\down\82921.exe
C:\WINDOWS\system32\drivers\down\83312.exe
C:\WINDOWS\system32\drivers\down\84109.exe
C:\WINDOWS\system32\drivers\down\84218.exe
C:\WINDOWS\system32\drivers\down\84750.exe
C:\WINDOWS\system32\drivers\down\85390.exe
C:\WINDOWS\system32\drivers\down\86093.exe
C:\WINDOWS\system32\drivers\down\86359.exe
C:\WINDOWS\system32\drivers\down\86578.exe
C:\WINDOWS\system32\drivers\down\86812.exe
C:\WINDOWS\system32\drivers\down\87281.exe
C:\WINDOWS\system32\drivers\down\88484.exe
C:\WINDOWS\system32\drivers\down\88734.exe
C:\WINDOWS\system32\drivers\down\89437.exe
C:\WINDOWS\system32\drivers\down\89671.exe
C:\WINDOWS\system32\drivers\down\89718.exe
C:\WINDOWS\system32\drivers\down\89937.exe
C:\WINDOWS\system32\drivers\down\89968.exe
C:\WINDOWS\system32\drivers\down\90328.exe
C:\WINDOWS\system32\drivers\down\90343.exe
C:\WINDOWS\system32\drivers\down\90468.exe
C:\WINDOWS\system32\drivers\down\90671.exe
C:\WINDOWS\system32\drivers\down\90718.exe
C:\WINDOWS\system32\drivers\down\90984.exe
C:\WINDOWS\system32\drivers\down\91937.exe
C:\WINDOWS\system32\drivers\down\92593.exe
C:\WINDOWS\system32\drivers\down\92656.exe
C:\WINDOWS\system32\drivers\down\92671.exe
C:\WINDOWS\system32\drivers\down\93156.exe
C:\WINDOWS\system32\drivers\down\94328.exe
C:\WINDOWS\system32\drivers\down\94406.exe
C:\WINDOWS\system32\drivers\down\94718.exe
C:\WINDOWS\system32\drivers\down\94984.exe
C:\WINDOWS\system32\drivers\down\95234.exe
C:\WINDOWS\system32\drivers\down\95765.exe
C:\WINDOWS\system32\drivers\down\96062.exe
C:\WINDOWS\system32\drivers\down\96109.exe
C:\WINDOWS\system32\drivers\down\96390.exe
C:\WINDOWS\system32\drivers\down\96609.exe
C:\WINDOWS\system32\drivers\down\96625.exe
C:\WINDOWS\system32\drivers\down\97250.exe
C:\WINDOWS\system32\drivers\down\97468.exe
C:\WINDOWS\system32\drivers\down\97531.exe
C:\WINDOWS\system32\drivers\down\97796.exe
C:\WINDOWS\system32\drivers\down\97875.exe
C:\WINDOWS\system32\drivers\down\98031.exe
C:\WINDOWS\system32\drivers\down\98609.exe
C:\WINDOWS\system32\drivers\down\98703.exe
C:\WINDOWS\system32\drivers\down\98875.exe
C:\WINDOWS\system32\drivers\down\99062.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\mdelk.exe
C:\WINDOWS\system32\wintems.exe

----- BITS: Possible infected sites -----

hxxp://77.91.227.194
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\LEGACY_SROSA
-------\srosa


((((((((((((((((((((((((( Files Created from 2008-02-07 to 2008-03-07 )))))))))))))))))))))))))))))))
.

2008-03-07 20:20 . 2008-03-07 20:23 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-07 20:20 . 2008-03-07 20:20 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\SUPERAntiSpyware.com
2008-03-07 20:20 . 2008-03-07 20:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-07 20:19 . 2008-03-07 20:19 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-07 19:50 . 2008-03-07 19:50 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-07 19:39 . 2008-03-07 19:48 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-03-07 19:39 . 2008-03-07 19:39 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-03-07 19:39 . 2008-03-07 19:39 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-03-07 19:39 . 2008-03-07 19:39 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-03-07 19:35 . 2008-03-07 19:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-07 16:21 . 2008-03-07 16:21 <DIR> d-------- C:\Program Files\Zone Labs
2008-03-07 15:20 . 2008-03-07 15:20 <DIR> d-------- C:\Program Files\Trojan Remover
2008-03-07 15:20 . 2008-03-07 15:54 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-07 15:11 . 2008-03-07 15:20 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\Simply Super Software
2008-03-07 15:11 . 2008-03-07 15:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-03-07 15:11 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-03-07 15:11 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\unrar3.dll
2008-03-07 15:11 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-03-07 15:11 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-03-07 15:11 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-03-07 12:07 . 2008-03-07 12:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-06 12:39 . 2008-03-06 20:06 29,352 --a------ C:\WINDOWS\_SETUPD_.EXE
2008-03-05 17:08 . 2008-03-05 17:08 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-01 02:34 . 2008-03-01 02:35 <DIR> d-------- C:\Program Files\Windows Live
2008-03-01 02:34 . 2008-03-01 02:34 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-01 02:34 . 2008-03-01 02:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-14 20:13 . 2008-02-14 20:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TVU networks
2008-02-13 19:34 . 2008-02-13 19:34 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\River Past G4
2008-02-13 19:33 . 2008-02-13 19:33 <DIR> d-------- C:\Program Files\Common Files\River Past
2008-02-13 19:33 . 2008-02-13 19:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\River Past G4
2008-02-13 19:33 . 2008-02-13 19:33 161,532 --a------ C:\WINDOWS\Audio Converter Pro Uninstaller.exe
2008-02-13 19:33 . 2008-02-13 19:33 0 --a------ C:\WINDOWS\system32\QuickTime.qtp
2008-02-13 18:24 . 2008-02-13 18:25 12,343,516 ---h----- C:\WINDOWS\system32\temptime.exe
2008-02-13 18:17 . 2008-02-13 18:17 <DIR> d-------- C:\Temp
2008-02-11 22:01 . 2008-02-11 22:01 <DIR> d-------- C:\Poker
2008-02-08 20:04 . 2008-02-08 20:04 167,936 --a------ C:\WINDOWS\system32\SpoonUninstall.exe
2008-02-08 19:28 . 2008-02-27 14:30 <DIR> d-------- C:\Program Files\Soulseek-Test

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-07 13:45 --------- d-----w C:\Program Files\eMule
2008-03-07 13:04 --------- d-----w C:\Documents and Settings\Scott\Application Data\Azureus
2008-03-05 18:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-05 09:02 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-03 10:06 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-03-03 10:06 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-03-03 10:06 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-03-03 10:06 --------- d-----w C:\Program Files\Symantec
2008-02-14 20:17 --------- d-----w C:\Program Files\TVUPlayer
2008-02-13 12:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-07 23:29 --------- d-----w C:\Program Files\Azureus
2008-01-29 17:27 --------- d-----w C:\Program Files\TVAnts
2008-01-21 23:05 --------- d-----w C:\Program Files\Enigma Software Group
2008-01-21 16:14 --------- d-----w C:\Program Files\Printer
2008-01-21 16:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-21 16:09 --------- d-----w C:\Program Files\EPSON
2008-01-21 16:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\UDL
2008-01-21 16:07 --------- d-----w C:\Program Files\EPSON Print CD
2008-01-21 15:36 --------- d-----w C:\Program Files\SSC Service Utility
2008-01-21 07:13 --------- d-----w C:\Program Files\Windows Desktop Search
2008-01-20 21:20 --------- d-----w C:\Program Files\Common Files\xing shared
2008-01-20 21:20 --------- d-----w C:\Program Files\Common Files\Real
2008-01-20 21:19 --------- d-----w C:\Program Files\Real
2008-01-19 09:24 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-18 13:41 --------- d-----w C:\Program Files\coverXP
2008-01-15 09:54 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-15 05:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-13 15:14 --------- d-----w C:\Program Files\CUEcards 2000
2008-01-13 01:43 --------- d-----w C:\Program Files\Lavasoft
2008-01-13 01:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-12 18:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-08 13:19 --------- d-----w C:\Documents and Settings\Scott\Application Data\InstallShield
2008-01-07 15:37 --------- d-----w C:\Documents and Settings\Scott\Application Data\CyberLink
2007-12-28 15:44 6,211,190 ----a-w C:\Program Files\Combined-Community-Codec-Pack-2007-07-22.exe
.
<pre>
----a-w		 2,889,336 2007-12-26 08:56:28  C:\Documents and Settings\Scott\Desktop\Footy\TvantsSetup__1.0.0.59_Build_0834_\TvantsSetup  1.0.0.59 Build 0834 .exe
</pre>


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2CE97F9E-00B2-4d2f-BB15-8B36BDAE70E7}]
2008-01-08 15:30 135168 --a------ C:\WINDOWS\system32\MSACP32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{8D911181-10AA-4B3E-BC7F-8D4AD359921B}"= "C:\WINDOWS\egodktf.dll" [ ]

[HKEY_CLASSES_ROOT\clsid\{8d911181-10aa-4b3e-bc7f-8d4ad359921b}]
[HKEY_CLASSES_ROOT\egodktf.ToolBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{BE255065-0B7F-4664-97FF-5D673600A858}]
[HKEY_CLASSES_ROOT\egodktf.ToolBar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2005-06-03 06:07 643072]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-04-20 09:57 847872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-01-13 01:47 131072]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-01-13 01:47 163840]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-01-13 01:46 135168]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 08:58 16264192 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 10:04 2879488 C:\WINDOWS\SkyTel.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-03-07 21:58 84640]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Motive SmartBridge"="C:\PROGRA~1\BLUEYO~1\SMARTB~1\MotiveSB.exe" [2006-04-21 15:41 438359]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-03-22 09:39 167936]
"DataLayer"="C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-03-31 09:30 1106944]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [ ]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [ ]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2004-09-16 16:15 538112]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 10:43 69632 C:\WINDOWS\Alcmtr.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 12:00 15360]

C:\Documents and Settings\Scott\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.
  • 0

#7
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
You will have to redownload Combofix to your desktop.
Then do the following:
1. Please open Notepad
  • Click Start , then Run
  • type in notepad in the Run Box then hit ok.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\MSACP32.dll
C:\WINDOWS\egodktf.dll
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2CE97F9E-00B2-4d2f-BB15-8B36BDAE70E7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{8D911181-10AA-4B3E-BC7F-8D4AD359921B}"=-
[-HKEY_CLASSES_ROOT\clsid\{8d911181-10aa-4b3e-bc7f-8d4ad359921b}]
[-HKEY_CLASSES_ROOT\egodktf.ToolBar.1]
[-HKEY_CLASSES_ROOT\TypeLib\{BE255065-0B7F-4664-97FF-5D673600A858}]
[-HKEY_CLASSES_ROOT\egodktf.ToolBar]
RenV::
C:\Documents and Settings\Scott\Desktop\Footy\TvantsSetup__1.0.0.59_Build_0834_\TvantsSetup  1.0.0.59 Build 0834 .exe


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Edited by kahdah, 08 March 2008 - 03:43 PM.

  • 0

#8
cleanprophet

cleanprophet

    Member

  • Topic Starter
  • Member
  • PipPip
  • 92 posts
Thanks for the help/advice. Here is the new combofix log:

ComboFix 08-03-08.2 - Scott 2008-03-09 10:07:41.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.443 [GMT 0:00]
Running from: C:\Documents and Settings\Scott\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Scott\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\egodktf.dll
C:\WINDOWS\system32\MSACP32.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\MSACP32.dll
.
---- Previous Run -------
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\adaway.lic
C:\WINDOWS\system32\drivers\down
C:\WINDOWS\system32\drivers\down\100281.exe
C:\WINDOWS\system32\drivers\down\100390.exe
C:\WINDOWS\system32\drivers\down\100437.exe
C:\WINDOWS\system32\drivers\down\100562.exe
C:\WINDOWS\system32\drivers\down\100640.exe
C:\WINDOWS\system32\drivers\down\100984.exe
C:\WINDOWS\system32\drivers\down\101031.exe
C:\WINDOWS\system32\drivers\down\101281.exe
C:\WINDOWS\system32\drivers\down\101625.exe
C:\WINDOWS\system32\drivers\down\101765.exe
C:\WINDOWS\system32\drivers\down\103109.exe
C:\WINDOWS\system32\drivers\down\103203.exe
C:\WINDOWS\system32\drivers\down\103218.exe
C:\WINDOWS\system32\drivers\down\103359.exe
C:\WINDOWS\system32\drivers\down\103687.exe
C:\WINDOWS\system32\drivers\down\103953.exe
C:\WINDOWS\system32\drivers\down\104343.exe
C:\WINDOWS\system32\drivers\down\104375.exe
C:\WINDOWS\system32\drivers\down\105281.exe
C:\WINDOWS\system32\drivers\down\105359.exe
C:\WINDOWS\system32\drivers\down\105453.exe
C:\WINDOWS\system32\drivers\down\105734.exe
C:\WINDOWS\system32\drivers\down\105765.exe
C:\WINDOWS\system32\drivers\down\106171.exe
C:\WINDOWS\system32\drivers\down\106343.exe
C:\WINDOWS\system32\drivers\down\106437.exe
C:\WINDOWS\system32\drivers\down\106671.exe
C:\WINDOWS\system32\drivers\down\106750.exe
C:\WINDOWS\system32\drivers\down\106828.exe
C:\WINDOWS\system32\drivers\down\107093.exe
C:\WINDOWS\system32\drivers\down\107171.exe
C:\WINDOWS\system32\drivers\down\107343.exe
C:\WINDOWS\system32\drivers\down\107828.exe
C:\WINDOWS\system32\drivers\down\108484.exe
C:\WINDOWS\system32\drivers\down\108531.exe
C:\WINDOWS\system32\drivers\down\108562.exe
C:\WINDOWS\system32\drivers\down\108593.exe
C:\WINDOWS\system32\drivers\down\108750.exe
C:\WINDOWS\system32\drivers\down\108953.exe
C:\WINDOWS\system32\drivers\down\109078.exe
C:\WINDOWS\system32\drivers\down\109796.exe
C:\WINDOWS\system32\drivers\down\110078.exe
C:\WINDOWS\system32\drivers\down\110406.exe
C:\WINDOWS\system32\drivers\down\110421.exe
C:\WINDOWS\system32\drivers\down\110453.exe
C:\WINDOWS\system32\drivers\down\111437.exe
C:\WINDOWS\system32\drivers\down\111750.exe
C:\WINDOWS\system32\drivers\down\111906.exe
C:\WINDOWS\system32\drivers\down\111937.exe
C:\WINDOWS\system32\drivers\down\112062.exe
C:\WINDOWS\system32\drivers\down\112140.exe
C:\WINDOWS\system32\drivers\down\112156.exe
C:\WINDOWS\system32\drivers\down\112500.exe
C:\WINDOWS\system32\drivers\down\112796.exe
C:\WINDOWS\system32\drivers\down\113125.exe
C:\WINDOWS\system32\drivers\down\113187.exe
C:\WINDOWS\system32\drivers\down\113500.exe
C:\WINDOWS\system32\drivers\down\113609.exe
C:\WINDOWS\system32\drivers\down\113828.exe
C:\WINDOWS\system32\drivers\down\113890.exe
C:\WINDOWS\system32\drivers\down\114171.exe
C:\WINDOWS\system32\drivers\down\114359.exe
C:\WINDOWS\system32\drivers\down\114718.exe
C:\WINDOWS\system32\drivers\down\114781.exe
C:\WINDOWS\system32\drivers\down\114796.exe
C:\WINDOWS\system32\drivers\down\114843.exe
C:\WINDOWS\system32\drivers\down\114906.exe
C:\WINDOWS\system32\drivers\down\115000.exe
C:\WINDOWS\system32\drivers\down\115046.exe
C:\WINDOWS\system32\drivers\down\115156.exe
C:\WINDOWS\system32\drivers\down\115281.exe
C:\WINDOWS\system32\drivers\down\115312.exe
C:\WINDOWS\system32\drivers\down\116062.exe
C:\WINDOWS\system32\drivers\down\116421.exe
C:\WINDOWS\system32\drivers\down\116468.exe
C:\WINDOWS\system32\drivers\down\116484.exe
C:\WINDOWS\system32\drivers\down\116625.exe
C:\WINDOWS\system32\drivers\down\116781.exe
C:\WINDOWS\system32\drivers\down\117171.exe
C:\WINDOWS\system32\drivers\down\117265.exe
C:\WINDOWS\system32\drivers\down\118375.exe
C:\WINDOWS\system32\drivers\down\118390.exe
C:\WINDOWS\system32\drivers\down\118781.exe
C:\WINDOWS\system32\drivers\down\118984.exe
C:\WINDOWS\system32\drivers\down\119765.exe
C:\WINDOWS\system32\drivers\down\119890.exe
C:\WINDOWS\system32\drivers\down\119906.exe
C:\WINDOWS\system32\drivers\down\120140.exe
C:\WINDOWS\system32\drivers\down\120281.exe
C:\WINDOWS\system32\drivers\down\120484.exe
C:\WINDOWS\system32\drivers\down\120515.exe
C:\WINDOWS\system32\drivers\down\120828.exe
C:\WINDOWS\system32\drivers\down\120906.exe
C:\WINDOWS\system32\drivers\down\121359.exe
C:\WINDOWS\system32\drivers\down\121500.exe
C:\WINDOWS\system32\drivers\down\121796.exe
C:\WINDOWS\system32\drivers\down\121812.exe
C:\WINDOWS\system32\drivers\down\121953.exe
C:\WINDOWS\system32\drivers\down\121984.exe
C:\WINDOWS\system32\drivers\down\122234.exe
C:\WINDOWS\system32\drivers\down\122406.exe
C:\WINDOWS\system32\drivers\down\122515.exe
C:\WINDOWS\system32\drivers\down\123406.exe
C:\WINDOWS\system32\drivers\down\123578.exe
C:\WINDOWS\system32\drivers\down\124234.exe
C:\WINDOWS\system32\drivers\down\124656.exe
C:\WINDOWS\system32\drivers\down\125046.exe
C:\WINDOWS\system32\drivers\down\125484.exe
C:\WINDOWS\system32\drivers\down\125500.exe
C:\WINDOWS\system32\drivers\down\125781.exe
C:\WINDOWS\system32\drivers\down\125812.exe
C:\WINDOWS\system32\drivers\down\126000.exe
C:\WINDOWS\system32\drivers\down\126328.exe
C:\WINDOWS\system32\drivers\down\126718.exe
C:\WINDOWS\system32\drivers\down\127312.exe
C:\WINDOWS\system32\drivers\down\127656.exe
C:\WINDOWS\system32\drivers\down\127828.exe
C:\WINDOWS\system32\drivers\down\128312.exe
C:\WINDOWS\system32\drivers\down\128375.exe
C:\WINDOWS\system32\drivers\down\128640.exe
C:\WINDOWS\system32\drivers\down\128968.exe
C:\WINDOWS\system32\drivers\down\129015.exe
C:\WINDOWS\system32\drivers\down\129031.exe
C:\WINDOWS\system32\drivers\down\129218.exe
C:\WINDOWS\system32\drivers\down\129796.exe
C:\WINDOWS\system32\drivers\down\130078.exe
C:\WINDOWS\system32\drivers\down\130234.exe
C:\WINDOWS\system32\drivers\down\130968.exe
C:\WINDOWS\system32\drivers\down\131109.exe
C:\WINDOWS\system32\drivers\down\131328.exe
C:\WINDOWS\system32\drivers\down\131578.exe
C:\WINDOWS\system32\drivers\down\131718.exe
C:\WINDOWS\system32\drivers\down\131812.exe
C:\WINDOWS\system32\drivers\down\132437.exe
C:\WINDOWS\system32\drivers\down\132484.exe
C:\WINDOWS\system32\drivers\down\132609.exe
C:\WINDOWS\system32\drivers\down\132625.exe
C:\WINDOWS\system32\drivers\down\132828.exe
C:\WINDOWS\system32\drivers\down\132890.exe
C:\WINDOWS\system32\drivers\down\133781.exe
C:\WINDOWS\system32\drivers\down\133843.exe
C:\WINDOWS\system32\drivers\down\134406.exe
C:\WINDOWS\system32\drivers\down\134765.exe
C:\WINDOWS\system32\drivers\down\134781.exe
C:\WINDOWS\system32\drivers\down\134968.exe
C:\WINDOWS\system32\drivers\down\135453.exe
C:\WINDOWS\system32\drivers\down\135640.exe
C:\WINDOWS\system32\drivers\down\135843.exe
C:\WINDOWS\system32\drivers\down\135875.exe
C:\WINDOWS\system32\drivers\down\136531.exe
C:\WINDOWS\system32\drivers\down\136625.exe
C:\WINDOWS\system32\drivers\down\136765.exe
C:\WINDOWS\system32\drivers\down\136843.exe
C:\WINDOWS\system32\drivers\down\137343.exe
C:\WINDOWS\system32\drivers\down\137375.exe
C:\WINDOWS\system32\drivers\down\137484.exe
C:\WINDOWS\system32\drivers\down\138015.exe
C:\WINDOWS\system32\drivers\down\138312.exe
C:\WINDOWS\system32\drivers\down\138328.exe
C:\WINDOWS\system32\drivers\down\138359.exe
C:\WINDOWS\system32\drivers\down\138765.exe
C:\WINDOWS\system32\drivers\down\138796.exe
C:\WINDOWS\system32\drivers\down\138953.exe
C:\WINDOWS\system32\drivers\down\138984.exe
C:\WINDOWS\system32\drivers\down\139109.exe
C:\WINDOWS\system32\drivers\down\139328.exe
C:\WINDOWS\system32\drivers\down\139375.exe
C:\WINDOWS\system32\drivers\down\139609.exe
C:\WINDOWS\system32\drivers\down\139640.exe
C:\WINDOWS\system32\drivers\down\140312.exe
C:\WINDOWS\system32\drivers\down\140406.exe
C:\WINDOWS\system32\drivers\down\140593.exe
C:\WINDOWS\system32\drivers\down\140671.exe
C:\WINDOWS\system32\drivers\down\140796.exe
C:\WINDOWS\system32\drivers\down\140984.exe
C:\WINDOWS\system32\drivers\down\141875.exe
C:\WINDOWS\system32\drivers\down\142031.exe
C:\WINDOWS\system32\drivers\down\142250.exe
C:\WINDOWS\system32\drivers\down\142500.exe
C:\WINDOWS\system32\drivers\down\142609.exe
C:\WINDOWS\system32\drivers\down\142968.exe
C:\WINDOWS\system32\drivers\down\143046.exe
C:\WINDOWS\system32\drivers\down\143125.exe
C:\WINDOWS\system32\drivers\down\143171.exe
C:\WINDOWS\system32\drivers\down\143218.exe
C:\WINDOWS\system32\drivers\down\143359.exe
C:\WINDOWS\system32\drivers\down\143578.exe
C:\WINDOWS\system32\drivers\down\143609.exe
C:\WINDOWS\system32\drivers\down\143687.exe
C:\WINDOWS\system32\drivers\down\144093.exe
C:\WINDOWS\system32\drivers\down\144671.exe
C:\WINDOWS\system32\drivers\down\144718.exe
C:\WINDOWS\system32\drivers\down\145140.exe
C:\WINDOWS\system32\drivers\down\145281.exe
C:\WINDOWS\system32\drivers\down\145359.exe
C:\WINDOWS\system32\drivers\down\145750.exe
C:\WINDOWS\system32\drivers\down\145765.exe
C:\WINDOWS\system32\drivers\down\145781.exe
C:\WINDOWS\system32\drivers\down\145843.exe
C:\WINDOWS\system32\drivers\down\146218.exe
C:\WINDOWS\system32\drivers\down\146359.exe
C:\WINDOWS\system32\drivers\down\147218.exe
C:\WINDOWS\system32\drivers\down\147484.exe
C:\WINDOWS\system32\drivers\down\14752453.exe
C:\WINDOWS\system32\drivers\down\14756078.exe
C:\WINDOWS\system32\drivers\down\14757015.exe
C:\WINDOWS\system32\drivers\down\14759031.exe
C:\WINDOWS\system32\drivers\down\14761546.exe
C:\WINDOWS\system32\drivers\down\14780140.exe
C:\WINDOWS\system32\drivers\down\14785093.exe
C:\WINDOWS\system32\drivers\down\147859.exe
C:\WINDOWS\system32\drivers\down\14791265.exe
C:\WINDOWS\system32\drivers\down\14793812.exe
C:\WINDOWS\system32\drivers\down\14801484.exe
C:\WINDOWS\system32\drivers\down\148078.exe
C:\WINDOWS\system32\drivers\down\14809093.exe
C:\WINDOWS\system32\drivers\down\14823453.exe
C:\WINDOWS\system32\drivers\down\14836375.exe
C:\WINDOWS\system32\drivers\down\148406.exe
C:\WINDOWS\system32\drivers\down\148671.exe
C:\WINDOWS\system32\drivers\down\14869703.exe
C:\WINDOWS\system32\drivers\down\149046.exe
C:\WINDOWS\system32\drivers\down\149515.exe
C:\WINDOWS\system32\drivers\down\149781.exe
C:\WINDOWS\system32\drivers\down\150375.exe
C:\WINDOWS\system32\drivers\down\150421.exe
C:\WINDOWS\system32\drivers\down\150687.exe
C:\WINDOWS\system32\drivers\down\151312.exe
C:\WINDOWS\system32\drivers\down\151531.exe
C:\WINDOWS\system32\drivers\down\151984.exe
C:\WINDOWS\system32\drivers\down\152062.exe
C:\WINDOWS\system32\drivers\down\152296.exe
C:\WINDOWS\system32\drivers\down\152718.exe
C:\WINDOWS\system32\drivers\down\152828.exe
C:\WINDOWS\system32\drivers\down\152875.exe
C:\WINDOWS\system32\drivers\down\153078.exe
C:\WINDOWS\system32\drivers\down\153875.exe
C:\WINDOWS\system32\drivers\down\154203.exe
C:\WINDOWS\system32\drivers\down\154359.exe
C:\WINDOWS\system32\drivers\down\154875.exe
C:\WINDOWS\system32\drivers\down\154921.exe
C:\WINDOWS\system32\drivers\down\154937.exe
C:\WINDOWS\system32\drivers\down\155140.exe
C:\WINDOWS\system32\drivers\down\155171.exe
C:\WINDOWS\system32\drivers\down\155484.exe
C:\WINDOWS\system32\drivers\down\155578.exe
C:\WINDOWS\system32\drivers\down\155593.exe
C:\WINDOWS\system32\drivers\down\156375.exe
C:\WINDOWS\system32\drivers\down\156500.exe
C:\WINDOWS\system32\drivers\down\156578.exe
C:\WINDOWS\system32\drivers\down\156625.exe
C:\WINDOWS\system32\drivers\down\156843.exe
C:\WINDOWS\system32\drivers\down\157250.exe
C:\WINDOWS\system32\drivers\down\157343.exe
C:\WINDOWS\system32\drivers\down\157625.exe
C:\WINDOWS\system32\drivers\down\158265.exe
C:\WINDOWS\system32\drivers\down\159093.exe
C:\WINDOWS\system32\drivers\down\159281.exe
C:\WINDOWS\system32\drivers\down\159593.exe
C:\WINDOWS\system32\drivers\down\159812.exe
C:\WINDOWS\system32\drivers\down\160234.exe
C:\WINDOWS\system32\drivers\down\160687.exe
C:\WINDOWS\system32\drivers\down\160812.exe
C:\WINDOWS\system32\drivers\down\160890.exe
C:\WINDOWS\system32\drivers\down\160906.exe
C:\WINDOWS\system32\drivers\down\161203.exe
C:\WINDOWS\system32\drivers\down\161296.exe
C:\WINDOWS\system32\drivers\down\161484.exe
C:\WINDOWS\system32\drivers\down\161515.exe
C:\WINDOWS\system32\drivers\down\161765.exe
C:\WINDOWS\system32\drivers\down\161812.exe
C:\WINDOWS\system32\drivers\down\161859.exe
C:\WINDOWS\system32\drivers\down\161890.exe
C:\WINDOWS\system32\drivers\down\162437.exe
C:\WINDOWS\system32\drivers\down\162515.exe
C:\WINDOWS\system32\drivers\down\164031.exe
C:\WINDOWS\system32\drivers\down\164968.exe
C:\WINDOWS\system32\drivers\down\165046.exe
C:\WINDOWS\system32\drivers\down\165109.exe
C:\WINDOWS\system32\drivers\down\165265.exe
C:\WINDOWS\system32\drivers\down\165765.exe
C:\WINDOWS\system32\drivers\down\166078.exe
C:\WINDOWS\system32\drivers\down\166375.exe
C:\WINDOWS\system32\drivers\down\167062.exe
C:\WINDOWS\system32\drivers\down\167453.exe
C:\WINDOWS\system32\drivers\down\168078.exe
C:\WINDOWS\system32\drivers\down\170781.exe
C:\WINDOWS\system32\drivers\down\171500.exe
C:\WINDOWS\system32\drivers\down\172031.exe
C:\WINDOWS\system32\drivers\down\172234.exe
C:\WINDOWS\system32\drivers\down\172515.exe
C:\WINDOWS\system32\drivers\down\172687.exe
C:\WINDOWS\system32\drivers\down\173343.exe
C:\WINDOWS\system32\drivers\down\173921.exe
C:\WINDOWS\system32\drivers\down\175031.exe
C:\WINDOWS\system32\drivers\down\175234.exe
C:\WINDOWS\system32\drivers\down\175625.exe
C:\WINDOWS\system32\drivers\down\175843.exe
C:\WINDOWS\system32\drivers\down\176015.exe
C:\WINDOWS\system32\drivers\down\176109.exe
C:\WINDOWS\system32\drivers\down\176703.exe
C:\WINDOWS\system32\drivers\down\176734.exe
C:\WINDOWS\system32\drivers\down\180109.exe
C:\WINDOWS\system32\drivers\down\180187.exe
C:\WINDOWS\system32\drivers\down\181500.exe
C:\WINDOWS\system32\drivers\down\181937.exe
C:\WINDOWS\system32\drivers\down\183265.exe
C:\WINDOWS\system32\drivers\down\184125.exe
C:\WINDOWS\system32\drivers\down\184796.exe
C:\WINDOWS\system32\drivers\down\185687.exe
C:\WINDOWS\system32\drivers\down\186328.exe
C:\WINDOWS\system32\drivers\down\186562.exe
C:\WINDOWS\system32\drivers\down\186671.exe
C:\WINDOWS\system32\drivers\down\188468.exe
C:\WINDOWS\system32\drivers\down\188812.exe
C:\WINDOWS\system32\drivers\down\189453.exe
C:\WINDOWS\system32\drivers\down\190500.exe
C:\WINDOWS\system32\drivers\down\191281.exe
C:\WINDOWS\system32\drivers\down\192390.exe
C:\WINDOWS\system32\drivers\down\192718.exe
C:\WINDOWS\system32\drivers\down\195843.exe
C:\WINDOWS\system32\drivers\down\196375.exe
C:\WINDOWS\system32\drivers\down\198500.exe
C:\WINDOWS\system32\drivers\down\200500.exe
C:\WINDOWS\system32\drivers\down\200562.exe
C:\WINDOWS\system32\drivers\down\202812.exe
C:\WINDOWS\system32\drivers\down\205500.exe
C:\WINDOWS\system32\drivers\down\206484.exe
C:\WINDOWS\system32\drivers\down\208546.exe
C:\WINDOWS\system32\drivers\down\209625.exe
C:\WINDOWS\system32\drivers\down\212468.exe
C:\WINDOWS\system32\drivers\down\213062.exe
C:\WINDOWS\system32\drivers\down\213843.exe
C:\WINDOWS\system32\drivers\down\215531.exe
C:\WINDOWS\system32\drivers\down\216203.exe
C:\WINDOWS\system32\drivers\down\216343.exe
C:\WINDOWS\system32\drivers\down\216359.exe
C:\WINDOWS\system32\drivers\down\217453.exe
C:\WINDOWS\system32\drivers\down\218328.exe
C:\WINDOWS\system32\drivers\down\222625.exe
C:\WINDOWS\system32\drivers\down\224125.exe
C:\WINDOWS\system32\drivers\down\224406.exe
C:\WINDOWS\system32\drivers\down\224437.exe
C:\WINDOWS\system32\drivers\down\226000.exe
C:\WINDOWS\system32\drivers\down\227765.exe
C:\WINDOWS\system32\drivers\down\228187.exe
C:\WINDOWS\system32\drivers\down\228265.exe
C:\WINDOWS\system32\drivers\down\228703.exe
C:\WINDOWS\system32\drivers\down\229390.exe
C:\WINDOWS\system32\drivers\down\229765.exe
C:\WINDOWS\system32\drivers\down\229796.exe
C:\WINDOWS\system32\drivers\down\231578.exe
C:\WINDOWS\system32\drivers\down\233421.exe
C:\WINDOWS\system32\drivers\down\234609.exe
C:\WINDOWS\system32\drivers\down\234796.exe
C:\WINDOWS\system32\drivers\down\236312.exe
C:\WINDOWS\system32\drivers\down\236609.exe
C:\WINDOWS\system32\drivers\down\238750.exe
C:\WINDOWS\system32\drivers\down\241453.exe
C:\WINDOWS\system32\drivers\down\241484.exe
C:\WINDOWS\system32\drivers\down\243796.exe
C:\WINDOWS\system32\drivers\down\244203.exe
C:\WINDOWS\system32\drivers\down\246125.exe
C:\WINDOWS\system32\drivers\down\247843.exe
C:\WINDOWS\system32\drivers\down\248312.exe
C:\WINDOWS\system32\drivers\down\249890.exe
C:\WINDOWS\system32\drivers\down\250937.exe
C:\WINDOWS\system32\drivers\down\251375.exe
C:\WINDOWS\system32\drivers\down\251578.exe
C:\WINDOWS\system32\drivers\down\256656.exe
C:\WINDOWS\system32\drivers\down\260078.exe
C:\WINDOWS\system32\drivers\down\260968.exe
C:\WINDOWS\system32\drivers\down\261531.exe
C:\WINDOWS\system32\drivers\down\266046.exe
C:\WINDOWS\system32\drivers\down\266234.exe
C:\WINDOWS\system32\drivers\down\267125.exe
C:\WINDOWS\system32\drivers\down\267625.exe
C:\WINDOWS\system32\drivers\down\276968.exe
C:\WINDOWS\system32\drivers\down\280468.exe
C:\WINDOWS\system32\drivers\down\283625.exe
C:\WINDOWS\system32\drivers\down\286171.exe
C:\WINDOWS\system32\drivers\down\287859.exe
C:\WINDOWS\system32\drivers\down\290625.exe
C:\WINDOWS\system32\drivers\down\293781.exe
C:\WINDOWS\system32\drivers\down\294984.exe
C:\WINDOWS\system32\drivers\down\298328.exe
C:\WINDOWS\system32\drivers\down\300156.exe
C:\WINDOWS\system32\drivers\down\301640.exe
C:\WINDOWS\system32\drivers\down\303843.exe
C:\WINDOWS\system32\drivers\down\310703.exe
C:\WINDOWS\system32\drivers\down\312218.exe
C:\WINDOWS\system32\drivers\down\312781.exe
C:\WINDOWS\system32\drivers\down\314859.exe
C:\WINDOWS\system32\drivers\down\317750.exe
C:\WINDOWS\system32\drivers\down\319359.exe
C:\WINDOWS\system32\drivers\down\323875.exe
C:\WINDOWS\system32\drivers\down\325515.exe
C:\WINDOWS\system32\drivers\down\329703.exe
C:\WINDOWS\system32\drivers\down\330109.exe
C:\WINDOWS\system32\drivers\down\331343.exe
C:\WINDOWS\system32\drivers\down\332640.exe
C:\WINDOWS\system32\drivers\down\333687.exe
C:\WINDOWS\system32\drivers\down\336921.exe
C:\WINDOWS\system32\drivers\down\337750.exe
C:\WINDOWS\system32\drivers\down\340687.exe
C:\WINDOWS\system32\drivers\down\353546.exe
C:\WINDOWS\system32\drivers\down\354171.exe
C:\WINDOWS\system32\drivers\down\357468.exe
C:\WINDOWS\system32\drivers\down\357484.exe
C:\WINDOWS\system32\drivers\down\360375.exe
C:\WINDOWS\system32\drivers\down\360687.exe
C:\WINDOWS\system32\drivers\down\363171.exe
C:\WINDOWS\system32\drivers\down\369234.exe
C:\WINDOWS\system32\drivers\down\371093.exe
C:\WINDOWS\system32\drivers\down\446328.exe
C:\WINDOWS\system32\drivers\down\452718.exe
C:\WINDOWS\system32\drivers\down\458640.exe
C:\WINDOWS\system32\drivers\down\461593.exe
C:\WINDOWS\system32\drivers\down\464421.exe
C:\WINDOWS\system32\drivers\down\467046.exe
C:\WINDOWS\system32\drivers\down\491281.exe
C:\WINDOWS\system32\drivers\down\567671.exe
C:\WINDOWS\system32\drivers\down\569062.exe
C:\WINDOWS\system32\drivers\down\58218.exe
C:\WINDOWS\system32\drivers\down\586562.exe
C:\WINDOWS\system32\drivers\down\589125.exe
C:\WINDOWS\system32\drivers\down\60109.exe
C:\WINDOWS\system32\drivers\down\610687.exe
C:\WINDOWS\system32\drivers\down\612234.exe
C:\WINDOWS\system32\drivers\down\61718.exe
C:\WINDOWS\system32\drivers\down\63546.exe
C:\WINDOWS\system32\drivers\down\636406.exe
C:\WINDOWS\system32\drivers\down\63859.exe
C:\WINDOWS\system32\drivers\down\63921.exe
C:\WINDOWS\system32\drivers\down\642640.exe
C:\WINDOWS\system32\drivers\down\65625.exe
C:\WINDOWS\system32\drivers\down\65687.exe
C:\WINDOWS\system32\drivers\down\66250.exe
C:\WINDOWS\system32\drivers\down\66296.exe
C:\WINDOWS\system32\drivers\down\67031.exe
C:\WINDOWS\system32\drivers\down\67359.exe
C:\WINDOWS\system32\drivers\down\67390.exe
C:\WINDOWS\system32\drivers\down\67437.exe
C:\WINDOWS\system32\drivers\down\67578.exe
C:\WINDOWS\system32\drivers\down\67812.exe
C:\WINDOWS\system32\drivers\down\68187.exe
C:\WINDOWS\system32\drivers\down\68843.exe
C:\WINDOWS\system32\drivers\down\68968.exe
C:\WINDOWS\system32\drivers\down\69312.exe
C:\WINDOWS\system32\drivers\down\69640.exe
C:\WINDOWS\system32\drivers\down\69734.exe
C:\WINDOWS\system32\drivers\down\69937.exe
C:\WINDOWS\system32\drivers\down\70406.exe
C:\WINDOWS\system32\drivers\down\70593.exe
C:\WINDOWS\system32\drivers\down\71187.exe
C:\WINDOWS\system32\drivers\down\71421.exe
C:\WINDOWS\system32\drivers\down\71562.exe
C:\WINDOWS\system32\drivers\down\71937.exe
C:\WINDOWS\system32\drivers\down\72484.exe
C:\WINDOWS\system32\drivers\down\72515.exe
C:\WINDOWS\system32\drivers\down\72718.exe
C:\WINDOWS\system32\drivers\down\73015.exe
C:\WINDOWS\system32\drivers\down\73375.exe
C:\WINDOWS\system32\drivers\down\73859.exe
C:\WINDOWS\system32\drivers\down\73921.exe
C:\WINDOWS\system32\drivers\down\74000.exe
C:\WINDOWS\system32\drivers\down\74031.exe
C:\WINDOWS\system32\drivers\down\74453.exe
C:\WINDOWS\system32\drivers\down\74703.exe
C:\WINDOWS\system32\drivers\down\74828.exe
C:\WINDOWS\system32\drivers\down\74921.exe
C:\WINDOWS\system32\drivers\down\75093.exe
C:\WINDOWS\system32\drivers\down\75250.exe
C:\WINDOWS\system32\drivers\down\75828.exe
C:\WINDOWS\system32\drivers\down\75859.exe
C:\WINDOWS\system32\drivers\down\75937.exe
C:\WINDOWS\system32\drivers\down\76187.exe
C:\WINDOWS\system32\drivers\down\76296.exe
C:\WINDOWS\system32\drivers\down\76343.exe
C:\WINDOWS\system32\drivers\down\76359.exe
C:\WINDOWS\system32\drivers\down\76531.exe
C:\WINDOWS\system32\drivers\down\76812.exe
C:\WINDOWS\system32\drivers\down\77187.exe
C:\WINDOWS\system32\drivers\down\77453.exe
C:\WINDOWS\system32\drivers\down\77890.exe
C:\WINDOWS\system32\drivers\down\78406.exe
C:\WINDOWS\system32\drivers\down\78437.exe
C:\WINDOWS\system32\drivers\down\78687.exe
C:\WINDOWS\system32\drivers\down\78703.exe
C:\WINDOWS\system32\drivers\down\79703.exe
C:\WINDOWS\system32\drivers\down\79734.exe
C:\WINDOWS\system32\drivers\down\80968.exe
C:\WINDOWS\system32\drivers\down\81109.exe
C:\WINDOWS\system32\drivers\down\81140.exe
C:\WINDOWS\system32\drivers\down\81187.exe
C:\WINDOWS\system32\drivers\down\81203.exe
C:\WINDOWS\system32\drivers\down\82078.exe
C:\WINDOWS\system32\drivers\down\82234.exe
C:\WINDOWS\system32\drivers\down\82921.exe
C:\WINDOWS\system32\drivers\down\83312.exe
C:\WINDOWS\system32\drivers\down\84109.exe
C:\WINDOWS\system32\drivers\down\84218.exe
C:\WINDOWS\system32\drivers\down\84750.exe
C:\WINDOWS\system32\drivers\down\85390.exe
C:\WINDOWS\system32\drivers\down\86093.exe
C:\WINDOWS\system32\drivers\down\86359.exe
C:\WINDOWS\system32\drivers\down\86578.exe
C:\WINDOWS\system32\drivers\down\86812.exe
C:\WINDOWS\system32\drivers\down\87281.exe
C:\WINDOWS\system32\drivers\down\88484.exe
C:\WINDOWS\system32\drivers\down\88734.exe
C:\WINDOWS\system32\drivers\down\89437.exe
C:\WINDOWS\system32\drivers\down\89671.exe
C:\WINDOWS\system32\drivers\down\89718.exe
C:\WINDOWS\system32\drivers\down\89937.exe
C:\WINDOWS\system32\drivers\down\89968.exe
C:\WINDOWS\system32\drivers\down\90328.exe
C:\WINDOWS\system32\drivers\down\90343.exe
C:\WINDOWS\system32\drivers\down\90468.exe
C:\WINDOWS\system32\drivers\down\90671.exe
C:\WINDOWS\system32\drivers\down\90718.exe
C:\WINDOWS\system32\drivers\down\90984.exe
C:\WINDOWS\system32\drivers\down\91937.exe
C:\WINDOWS\system32\drivers\down\92593.exe
C:\WINDOWS\system32\drivers\down\92656.exe
C:\WINDOWS\system32\drivers\down\92671.exe
C:\WINDOWS\system32\drivers\down\93156.exe
C:\WINDOWS\system32\drivers\down\94328.exe
C:\WINDOWS\system32\drivers\down\94406.exe
C:\WINDOWS\system32\drivers\down\94718.exe
C:\WINDOWS\system32\drivers\down\94984.exe
C:\WINDOWS\system32\drivers\down\95234.exe
C:\WINDOWS\system32\drivers\down\95765.exe
C:\WINDOWS\system32\drivers\down\96062.exe
C:\WINDOWS\system32\drivers\down\96109.exe
C:\WINDOWS\system32\drivers\down\96390.exe
C:\WINDOWS\system32\drivers\down\96609.exe
C:\WINDOWS\system32\drivers\down\96625.exe
C:\WINDOWS\system32\drivers\down\97250.exe
C:\WINDOWS\system32\drivers\down\97468.exe
C:\WINDOWS\system32\drivers\down\97531.exe
C:\WINDOWS\system32\drivers\down\97796.exe
C:\WINDOWS\system32\drivers\down\97875.exe
C:\WINDOWS\system32\drivers\down\98031.exe
C:\WINDOWS\system32\drivers\down\98609.exe
C:\WINDOWS\system32\drivers\down\98703.exe
C:\WINDOWS\system32\drivers\down\98875.exe
C:\WINDOWS\system32\drivers\down\99062.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\mdelk.exe
C:\WINDOWS\system32\wintems.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\LEGACY_SROSA
-------\srosa


((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
.

2008-03-09 09:56 . 2008-03-09 09:56 135,168 --a------ C:\WINDOWS\system32\MSACP32.dll.vir
2008-03-09 00:55 . 2008-03-09 09:33 2,197 --a------ C:\rollback.ini
2008-03-09 00:46 . 2008-03-09 00:46 <DIR> d-------- C:\Program Files\SonicWallES
2008-03-09 00:38 . 2008-03-09 00:46 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\MailFrontier
2008-03-09 00:34 . 2008-03-09 10:15 627,232 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-09 00:34 . 2008-03-09 10:12 9,452 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-08 23:49 . 2008-03-08 23:49 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\Symantec
2008-03-08 23:47 . 2008-03-08 23:47 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-03-08 23:45 . 2008-03-09 00:11 <DIR> d-------- C:\Program Files\Norton Internet Security
2008-03-08 23:44 . 2008-03-09 00:08 <DIR> d-------- C:\Program Files\Symantec
2008-03-08 23:44 . 2008-03-09 00:08 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-03-08 23:44 . 2008-03-09 00:08 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-03-08 10:13 . 2008-03-08 10:13 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-03-08 10:10 . 2008-03-08 10:10 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-03-08 10:10 . 2008-03-08 10:11 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-03-08 01:13 . 2008-03-08 01:13 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\PC Suite
2008-03-08 01:12 . 2008-03-08 01:12 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-03-08 01:12 . 2008-03-08 01:12 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-03-08 00:59 . 2008-03-08 00:59 19 --a------ C:\WINDOWS\SoundConverter.INI
2008-03-07 22:35 . 2008-03-09 00:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-03-07 22:35 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-03-07 22:34 . 2008-03-09 09:56 <DIR> d-------- C:\WINDOWS\system32\Zonelabs
2008-03-07 20:20 . 2008-03-07 20:23 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-07 20:20 . 2008-03-07 20:20 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\SUPERAntiSpyware.com
2008-03-07 20:20 . 2008-03-07 20:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-07 20:19 . 2008-03-07 20:19 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-07 19:50 . 2008-03-07 19:50 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-07 19:39 . 2008-03-07 19:48 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-03-07 19:39 . 2008-03-07 19:39 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-03-07 19:39 . 2008-03-07 19:39 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-03-07 19:39 . 2008-03-07 19:39 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-03-07 19:35 . 2008-03-08 22:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-07 16:21 . 2008-03-09 00:29 <DIR> d-------- C:\Program Files\Zone Labs
2008-03-07 15:20 . 2008-03-07 15:20 <DIR> d-------- C:\Program Files\Trojan Remover
2008-03-07 15:20 . 2008-03-07 15:54 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-07 15:11 . 2008-03-07 15:20 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\Simply Super Software
2008-03-07 15:11 . 2008-03-07 15:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-03-07 15:11 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-03-07 15:11 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\unrar3.dll
2008-03-07 15:11 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-03-07 15:11 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-03-07 15:11 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-03-07 13:27 . 2008-03-07 13:27 <DIR> d-------- C:\Deckard
2008-03-06 12:39 . 2008-03-06 20:06 29,352 --a------ C:\WINDOWS\_SETUPD_.EXE
2008-03-05 17:08 . 2008-03-05 17:08 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-01 02:34 . 2008-03-01 02:35 <DIR> d-------- C:\Program Files\Windows Live
2008-03-01 02:34 . 2008-03-01 02:34 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-01 02:34 . 2008-03-01 02:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-14 20:13 . 2008-02-14 20:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TVU networks
2008-02-13 19:34 . 2008-02-13 19:34 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\River Past G4
2008-02-13 19:33 . 2008-02-13 19:33 <DIR> d-------- C:\Program Files\Common Files\River Past
2008-02-13 19:33 . 2008-02-13 19:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\River Past G4
2008-02-13 19:33 . 2008-02-13 19:33 161,532 --a------ C:\WINDOWS\Audio Converter Pro Uninstaller.exe
2008-02-13 19:33 . 2008-02-13 19:33 0 --a------ C:\WINDOWS\system32\QuickTime.qtp
2008-02-13 18:24 . 2008-02-13 18:25 12,343,516 ---h----- C:\WINDOWS\system32\temptime.exe
2008-02-13 18:17 . 2008-02-13 18:17 <DIR> d-------- C:\Temp
2008-02-11 22:01 . 2008-02-11 22:01 <DIR> d-------- C:\Poker

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-09 00:11 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-09 00:08 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-03-09 00:08 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-03-09 00:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-08 23:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-08 01:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-08 01:13 --------- d-----w C:\Program Files\Nokia
2008-03-07 13:45 --------- d-----w C:\Program Files\eMule
2008-03-07 13:04 --------- d-----w C:\Documents and Settings\Scott\Application Data\Azureus
2008-02-27 14:30 --------- d-----w C:\Program Files\Soulseek-Test
2008-02-14 20:17 --------- d-----w C:\Program Files\TVUPlayer
2008-02-08 20:04 167,936 ----a-w C:\WINDOWS\system32\SpoonUninstall.exe
2008-02-07 23:29 --------- d-----w C:\Program Files\Azureus
2008-01-29 17:27 --------- d-----w C:\Program Files\TVAnts
2008-01-21 23:05 --------- d-----w C:\Program Files\Enigma Software Group
2008-01-21 16:14 --------- d-----w C:\Program Files\Printer
2008-01-21 16:09 --------- d-----w C:\Program Files\EPSON
2008-01-21 16:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\UDL
2008-01-21 16:07 --------- d-----w C:\Program Files\EPSON Print CD
2008-01-21 15:46 5,248 ----a-w C:\WINDOWS\system32\giveio.sys
2008-01-21 15:36 --------- d-----w C:\Program Files\SSC Service Utility
2008-01-21 07:13 --------- d-----w C:\Program Files\Windows Desktop Search
2008-01-20 21:20 --------- d-----w C:\Program Files\Common Files\xing shared
2008-01-20 21:20 --------- d-----w C:\Program Files\Common Files\Real
2008-01-20 21:19 --------- d-----w C:\Program Files\Real
2008-01-19 09:24 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-18 13:41 --------- d-----w C:\Program Files\coverXP
2008-01-15 09:54 10,537 ----a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-01-15 05:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-13 15:14 --------- d-----w C:\Program Files\CUEcards 2000
2008-01-13 01:43 --------- d-----w C:\Program Files\Lavasoft
2008-01-13 01:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-12 18:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-28 15:44 6,211,190 ----a-w C:\Program Files\Combined-Community-Codec-Pack-2007-07-22.exe
2007-12-20 23:11 81,920 ----a-w C:\WINDOWS\system32\IEDFix.exe
2007-12-18 15:20 155,995 ----a-w C:\WINDOWS\java\Packages\M7BVDB13.ZIP
2007-12-18 12:43 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2007-12-18 12:43 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
.

((((((((((((((((((((((((((((( snapshot_2008-03-09_ 9.57.50.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-09 09:22:40 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
+ 2008-03-09 10:14:57 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
- 2008-03-09 09:33:16 39,400 ----a-w C:\WINDOWS\system32\Zonelabs\avsys\bases\sfdb.dat
+ 2008-03-09 10:15:25 54,724 ----a-w C:\WINDOWS\system32\Zonelabs\avsys\bases\sfdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-24 19:51 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-03-09 00:06 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" [ ]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll" [2007-08-24 19:51 316784]

[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-04-20 09:57 847872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-01-13 01:47 131072]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-01-13 01:47 163840]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-01-13 01:46 135168]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 08:58 16264192 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 10:04 2879488 C:\WINDOWS\SkyTel.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Motive SmartBridge"="C:\PROGRA~1\BLUEYO~1\SMARTB~1\MotiveSB.exe" [2006-04-21 15:41 438359]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [ ]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-03-22 09:39 167936]
"DataLayer"="C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-03-31 09:30 1106944]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-14 11:01 51048]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 12:00 15360]

C:\Documents and Settings\Scott\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.






Here is the new HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:24, on 2008-03-09
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Zonelabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\BLUEYO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\blueyonder IST\bin\blueyonder-istupdate.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\PROGRA~1\Motive\ASSTCO~1\MOTIVE~1.EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.c...earch.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: SH Class - {23EF65E8-0D45-46a0-A994-B58CBEE373A9} - C:\WINDOWS\system32\MSACP32.dll (file missing)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (file missing)
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [IgfxTray] C:\W
  • 0

#9
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please do an online scan with Kaspersky WebScanner
(This scanner is for use with internet explorer only)
Click on "Accept"

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

  • 0

#10
cleanprophet

cleanprophet

    Member

  • Topic Starter
  • Member
  • PipPip
  • 92 posts
The scan seems to have stopped, but it still has the 'stop scan' button and nowhere can i see 'Save as Text' button. Any ideas?
  • 0

Advertisements


#11
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
It still may be running wait a few Minutes and see if another button comes up like Expand Log and Save Log file.
  • 0

#12
cleanprophet

cleanprophet

    Member

  • Topic Starter
  • Member
  • PipPip
  • 92 posts
I waited for about 10mins, but the page remained the same. Eventually, i lost the page and lost the scan. It took nearly 2 hours and says it found 1 virus and 2 infected objects.

I suspect the problem is in the WINDOWS folder, so i am scanning that alone and will see if i can get the report from that. I will also look to do the scan again and see if i can get the report this time.

Well, the problem was not in the WINDOWS folder, but it did end the scan and give me a report. I will try a full scan again.

Edited by cleanprophet, 09 March 2008 - 10:27 AM.

  • 0

#13
cleanprophet

cleanprophet

    Member

  • Topic Starter
  • Member
  • PipPip
  • 92 posts
The second scan worked and here is the report:

Scan Statistics
Total number of scanned objects 43541
Number of viruses found 1
Number of infected objects 2
Number of suspicious objects 0
Duration of the scan process 01:33:12

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\ccSubSDK\submissions.idx Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.DAT Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\volatile.DAT Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-03-09_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\index.qbs Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{7A509120-A5C0-4198-830B-4921CC5A5EC8}.ldb Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{7A509120-A5C0-4198-830B-4921CC5A5EC8}.sds Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\3A593DA9.TMP Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\4397479E.TMP Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\temp\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\temp\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Scott\Application Data\Lavasoft\Ad-Aware\Logs\AWEVLOG.txt Object is locked skipped

C:\Documents and Settings\Scott\Application Data\MailFrontier\ASD.log Object is locked skipped

C:\Documents and Settings\Scott\Application Data\Symantec\NPMDataStore\CIMStore.xml Object is locked skipped

C:\Documents and Settings\Scott\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Scott\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped

C:\Documents and Settings\Scott\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Scott\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Scott\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Scott\Local Settings\History\History.IE5\MSHist012008030920080310\index.dat Object is locked skipped

C:\Documents and Settings\Scott\Local Settings\temp\~DF1BC9.tmp Object is locked skipped

C:\Documents and Settings\Scott\Local Settings\temp\~DF8FCA.tmp Object is locked skipped

C:\Documents and Settings\Scott\Local Settings\temp\~DF9010.tmp Object is locked skipped

C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Scott\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Scott\ntuser.dat.LOG Object is locked skipped

C:\Program Files\blueyonder IST\log\mad.log Object is locked skipped

C:\Program Files\blueyonder IST\log\mpbtn.log Object is locked skipped

C:\Program Files\blueyonder IST\SmartBridge\AlertFilter.log Object is locked skipped

C:\Program Files\blueyonder IST\SmartBridge\log\httpclient.log Object is locked skipped

C:\Program Files\blueyonder IST\SmartBridge\SmartBridge.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped

C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped

C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped

C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped

C:\QooBox\Quarantine\catchme2008-03-09_101458.65.zip/MSACP32.dll Infected: not-a-virus:AdWare.Win32.123Mania.d skipped

C:\QooBox\Quarantine\catchme2008-03-09_101458.65.zip ZIP: infected - 1 skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{DD3E0B70-C7FE-4A09-A6ED-5B93CC1C1FF0}\RP142\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped

C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped

C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped

C:\WINDOWS\Internet Logs\SCOTT-932876640.ldb Object is locked skipped

C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{62B43052-3D1F-4873-AECB-DD5BDFB47275}.bin Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped

C:\WINDOWS\system32\config\OSession.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped

C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\TEMP\JETCCF4.tmp Object is locked skipped

C:\WINDOWS\TEMP\ZLT06caa.TMP Object is locked skipped

C:\WINDOWS\TEMP\ZLT06cae.TMP Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
  • 0

#14
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please update your Java:
Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Ugrading Java:After that
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
================================================
Great that item is already deleted and in quarantinec we will remove it now by doing the following:

Time for some housekeeping
  • Click START then RUN
  • Now type Combo-fix /u in the runbox and click OK
  • Make sure it has the - mark inbetween Combo and fix

  • Posted Image

The above procedure will delete and do the following:

  • ComboFix and its associated files and folders.
  • VundoFix backups, if present
  • The C:\Deckard folder, if present
  • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Clean System Restore points.

Also delete\uninstall anything that we used that is left over.
============================================
After that Your log is clean. :)

To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein ->Here
  • 0

#15
cleanprophet

cleanprophet

    Member

  • Topic Starter
  • Member
  • PipPip
  • 92 posts
Thanks once again for your help. Everything you have suggested has been done and, all being well, the problem has been sorted.

I've sent a donation as a thank you for your time and advice/help. thanks,
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP