Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

180 solutions [RESOLVED]


  • This topic is locked This topic is locked

#1
Cheap-o

Cheap-o

    Member

  • Member
  • PipPip
  • 33 posts
Alrighty. I was looking for a file to convert flash animations to mp4 format for my ipod, and it turns out that what I downloaded was loaded with spyware, among other nasty things. If it's not too much trouble, could somebody please help me fix my stupid mistake?

So, here's what happened. I opened the file, and right away, I got 5 or six warnings from my avast! (version 4.7 Professional) on access scanner about Trojan viruses, all of which I moved to the chest. I immediately closed the program that was the cause, and opened the avast! antivirus program, and was going to do a complete system scan with it to make sure there was nothing else. However, I never got that far. During the memory scan that avast! does when you start it, it detected a virus running in memory, and prompted me to schedule a boot time scan and restart my computer to scan it. So, I scheduled the scan, but avast! was unable to restart my computer. Closing avast!, I tried to delete the file that caused all this trouble, and it was in use, and could not be deleted.

So, I manually selected shut-down, restarted the computer, let avast! run it's boot scan, which found and fixed 2 problems.

So, after my computer finished starting (I run windows XP 32bit service pack 2) up and I had logged in, here are the things I noticed.

-A yellow caution icon in the system tray popping up various warnings about how my computer was infected with spyware, and wanting me to buy a spyware removal program.
-The yellow icon would occasionally pop-up an internet explorer window advertising spyware removal software
-A different type of window calling itself a "Windows Security Center System warning" would occasionally pop-up
-And, finally (and most notably) after pressing ctrl+alt+del, I found my Task Manager button to be grayed out and inaccessible to me.

After that, I decided to come here and have a look around to see if I would be able to fix it, but after looking for a little while, I'm not sure if I have just one infection, or more than one, and I would rather make sure that I get rid of everything by posting my own topic.

While running through your list of things to do before posting a Hijack This log on the forums, I noticed a few more things.

After restarting in safe mode to run a scan with AVG (I turned avast! completely off while I did the scan) I noticed

a. The little yellow icon still popped up messages in my system tray and opened the "Windows Security Center System Warning" pop-ups
and
b. I still could not access my Task Manager after pressing ctrl+alt+del

Before restarting in normal mode I deleted the .exe file that caused all of this to begin with. Neither avast! nor AVG flagged it.

AVG found and fixed a whole whack of things, mostly tracking cookies (I'll post a log below), but, after restarting back into normal mode, I noticed even more things.

-After logging in, it changed my background to a message reading "Warning: Spyware threat has been detected on your PC. Your compute has several fatal errors due to spyware activity etc." -.-
-While going through windows explorer to open SUPERAntiSpyware I happened to notice 3 lovely 180 solutions folders in my program files, containing several .exe files. I haven't touched these, as I have dealt with spyware that regenerates itself in different places with different filenames in the past before.

After installing, updating, and running SUPERAntiSpyware, then restarting my computer, several of the problems were fixed.

-I no longer the yellow caution icon in my system tray, and neither the internet explorer, or "security center" pop-up windows appear anymore.

After opening SUPERAntiSpyware to get the logfiles, it graciously informed me that there were further updates, on top of the ones that I had initially downloaded, available, so I downloaded and installed those, then ran the panda Activescan, then ran the SUPERAntiSpyware scan one more time to see if it would fix anything more, which it didn't.

So, the problems I still have are:

-Background changed to spyware warning each time I log in to my computer

-I have 180 solutions folders and files in my program files folder. Specifically:
-180search assistant, containing:
-180sa.exe
-sau.exe
-180searchassistant, Containing:
-saap.exe
-sac.exe
-180solutions
-sais.exe

-And, I still, sadly, cannot access my task manager.

So, here are my logfiles in the order that they were generated.

AVG:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 12:57:40 AM 30/03/2008

+ Scan result:



C:\Program Files\180search assistant -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Program Files\180search assistant\180sa.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Program Files\180search assistant\sau.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Program Files\180searchassistant -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Program Files\180searchassistant\saap.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Program Files\180searchassistant\sac.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5929cd6e-2062-44a4-b2c5-2c7e78fbab38} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1036893752-4074264256-4249479951-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : Cleaned with backup (quarantined).
C:\Program Files\MAIET\Gunz\XTrap\XTrapM2S.exe -> Backdoor.Rbot.bpq : Cleaned with backup (quarantined).
C:\Documents and Settings\Bradley\Local Settings\Temp\removalfile.bat -> Not-A-Virus.Adware.Virtumonde : Cleaned with backup (quarantined).
:mozilla.110:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.43:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.336:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.337:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.338:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.339:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.340:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.341:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.342:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.343:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.344:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.345:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.346:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.347:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.348:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.349:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.350:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.351:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.352:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.353:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.354:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.355:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.356:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.357:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.358:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.359:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.360:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.361:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.362:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.363:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.364:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.365:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.366:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.367:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.368:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.369:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.370:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.371:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.372:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.373:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.374:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.375:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.376:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.377:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.378:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.379:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.380:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.381:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.382:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.383:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.384:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.531:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.565:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.694:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.728:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.78:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.79:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.80:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.81:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.451:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.452:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.453:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.47:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.49:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.619:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.620:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.621:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.622:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.623:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.624:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.625:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.626:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.627:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.628:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.629:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.285:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.286:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.287:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.288:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.160:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Bradley\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.729:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.630:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.631:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.112:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.114:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.115:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.116:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.117:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.118:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.119:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.120:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.121:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Bradley\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.688:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.744:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.47:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.57:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Bradley\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.847:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.183:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.184:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.185:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.186:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.521:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned.
:mozilla.522:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned.
:mozilla.523:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned.
:mozilla.588:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.509:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.510:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.514:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.300:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.301:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.727:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Information : Cleaned.
:mozilla.35:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.440:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.445:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.7:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.635:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.636:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.720:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.721:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.722:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.424:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.425:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.426:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.427:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.428:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.429:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.430:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.431:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.432:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.433:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.54:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.55:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.56:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.57:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.58:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.645:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.646:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.632:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.633:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.634:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.483:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.484:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.485:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.486:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.487:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.488:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.489:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.490:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.491:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.492:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.493:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.494:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.495:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.617:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.404:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.410:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.312:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.313:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.314:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.315:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.316:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.317:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.318:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.850:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.851:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.201:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.205:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.206:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.207:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.208:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.209:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.210:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.211:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.214:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.215:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.216:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.217:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.218:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.219:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.220:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.221:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.222:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.223:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.224:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.225:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.226:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.227:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.228:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.229:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.230:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.231:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.232:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.233:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.234:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.235:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.236:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.237:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.238:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.239:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.240:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.241:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.242:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.243:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.244:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.245:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.246:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.247:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.248:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.249:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.250:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.252:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.253:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.254:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.255:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.256:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.407:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.408:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.409:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.416:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.417:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.18:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.19:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.20:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.21:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.22:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.23:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.24:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.48:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.51:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.52:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.56:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.41:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.601:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.44:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.50:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.51:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.12:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.13:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.14:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.15:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.63:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.65:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.66:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.67:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.68:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.69:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.6:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.70:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.71:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.8:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.9:C:\Documents and Settings\Shawn\Application Data\Mozilla\Firefox\Profiles\lu8o2w9k.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.161:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.162:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.163:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.164:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.165:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.166:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.167:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\7200ieve.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.


::Report end

SUPERAntiSpyware 1:

SUPERAntiSpyware Scan Log
Generated 03/30/2008 at 04:47 AM

Application Version : 3.6.1000

Core Rules Database Version : 3427
Trace Rules Database Version: 1419

Scan type : Complete Scan
Total Scan Time : 03:19:34

Memory items scanned : 657
Memory threats detected : 1
Registry items scanned : 5532
Registry threats detected : 6
File items scanned : 209206
File threats detected : 10

Unclassified.Unknown Origin/System
C:\WINDOWS\SYSTEM32\SBWLTBXA.EXE
C:\WINDOWS\SYSTEM32\SBWLTBXA.EXE

Transponder Variant BHO
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000250-0320-4dd4-be4f-7566d2314352}

Unclassified.Unknown Origin
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15651c7c-e812-44a2-a9ac-b467a2233e7d}

Adware.2020Search
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e1075f4-eec4-4a86-add7-cd5f52858c31}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e7bd74f-2b8d-469e-92c6-ce7eb590a94d}

Adware.180solutions/SurfAssistant
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5dafd089-24b1-4c5e-bd42-8ca72550717b}

Adware.Second Thought
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{965a592f-8efa-4250-8630-7960230792f1}
C:\WINDOWS\BOKJA.EXE
C:\WINDOWS\STCLOADER.EXE

Adware.180solutions/ZangoSearch
C:\Program Files\Zango\zango.exe
C:\Program Files\Zango

Adware.180solutions/Seekmo
C:\Program Files\Seekmo\seekmohook.dll
C:\Program Files\Seekmo

Adware.webHancer
C:\DOCUMENTS AND SETTINGS\BRADLEY\LOCAL SETTINGS\TEMP\SYSWCC32.EXE

Torjan.SecondThoughtInstaller
C:\WINDOWS\INSTALLER\ID53.EXE

Trojan.Unclassified/NTNut32
C:\WINDOWS\SYSTEM32\NTNUT32.EXE


Panda Activescan:


Incident Status Location

Spyware:spyware/fastsearchweb Not disinfected c:\windows\system32\shdocpe.dll
Adware:adware/123mania Not disinfected c:\windows\system32\SIPSPI32.dll
Adware:adware/tubby Not disinfected c:\windows\system32\WER8274.DLL
Adware:adware/ncase Not disinfected c:\windows\180ax.exe
Adware:adware/topconvert Not disinfected c:\windows\updatetc.exe
Adware:adware/portalscan Not disinfected c:\program files\stc
Adware:adware/surfassistant Not disinfected Windows Registry
  • 0

Advertisements


#2
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

Please download RUNSCANNER to your desktop and run it.
  • When the first page comes up select Beginner Mode
  • On the next page select Save a binary .Run file (Recommended) then click Start full scan at the top.
  • At this time Runscanner.exe may request access to the Internet through your firewall please allow it to do so, it will then run for two or three minutes.
  • On completion it will ask for a location to save the file and a name. It will do this for both the .run file and the log
  • Call the file "Select a file name here" and save it to your desktop. You will see the .run file on your desktop. Please zip the .run file by right clicking and selecting send to Zip file

Then upload that as an attachment in your next post.
  • 0

#3
Cheap-o

Cheap-o

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts
Thank you sir. Here is the run file.

Attached Files


  • 0

#4
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

Download the zipped attachment at the end of this post(this will be your runscanner as fixed by me)

  • Unzip it to your desktop then double click the runscanner icon this will run the program.
  • Click on the "Item Fixer" tab
  • You will notice several entries with a tick in red, click Fix checked.
  • Accept the warning then repeat until they are all gone.




Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    c:\program files\bat
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    purity
  • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


Reboot and do this

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

  • 0

#5
Cheap-o

Cheap-o

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts
Alright, I did the first two steps, but when I used OTMoveit2, a window popped up asking me to restart, and it wouldn't let me highlight and copy the results before clicking ok. Should I just continue, or is there some way to retrieve the log for you?
  • 0

#6
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Continue on, no need to see the log really. DSS will show whether it was successful or not
  • 0

#7
Cheap-o

Cheap-o

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts
Alright, here we go:

Deckard's System Scanner v20071014.68
Run by Bradley on 2008-03-31 15:53:46
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 4 Restore Point(s) --
4: 2008-03-31 21:53:50 UTC - RP705 - Deckard's System Scanner Restore Point
3: 2008-03-31 07:17:15 UTC - RP704 - System Checkpoint
2: 2008-03-30 07:16:51 UTC - RP703 - Installed SUPERAntiSpyware Free Edition
1: 2008-03-29 13:13:56 UTC - RP702 - Before spyware removal


Backed up registry hives.
Performed disk cleanup.

System Drive C: has 10.54 GiB (less than 15%) free.


-- HijackThis (run as Bradley.exe) ---------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:56:31 PM, on 31/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\libusbd-nt.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Systerac XP Tools 3\memoryo.exe
C:\Program Files\AIM Lite\aimlite.exe
C:\Program Files\QuickTime Alternative\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\Bradley\Desktop\dss.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Bradley.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Registry Compact] "C:\Program Files\Systerac XP Tools 3\regcomp.exe" /Auto
O4 - HKLM\..\Run: [Memory Optimizer] "C:\Program Files\Systerac XP Tools 3\memoryo.exe"
O4 - HKLM\..\Run: [laim] "C:\Program Files\AIM Lite\aimlite.exe" -autorun
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [iLike] C:\Program Files\iLike\1.1.27\ilikesidebar.exe /checkforupdate
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Bradley\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zon...wn.cab56986.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload....Plugin11USA.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0DBA1AEF-0E6E-4186-B165-3958A27D96B9}: NameServer = 4.2.2.2,4.2.2.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{0DBA1AEF-0E6E-4186-B165-3958A27D96B9}: NameServer = 4.2.2.2,4.2.2.3
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - http://libusb-win32.sourceforge.net - C:\WINDOWS\system32\libusbd-nt.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 9560 bytes

-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

backup-20080329-064842-640 O4 - HKLM\..\Run: [SdScansGK] rundll32.exe C:\WINDOWS\stup_tmp.#32,Ini

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys
R2 STEC3 - c:\windows\system32\stec3.sys <Not Verified; AntiCracking; SVKP driver for NT>
R3 Afc (PPdus ASPI Shell) - c:\windows\system32\drivers\afc.sys <Not Verified; Arcsoft, Inc.; Arcsoft® ASPI Shell>
R3 libusb0 (LibUsb-Win32 - Kernel Driver, Version 0.1.10.1) - c:\windows\system32\drivers\libusb0.sys
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus® ASPI Shell>
R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 libusbd (LibUsb-Win32 - Daemon, Version 0.1.10.1) - system32\libusbd-nt.exe <Not Verified; http://libusb-win32.sourceforge.net; LibUsb-Win32>
R2 StarWindServiceAE (StarWind AE Service) - c:\program files\alcohol soft\alcohol 120\starwind\starwindserviceae.exe


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-03-22 20:59:02 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


-- Files created between 2008-02-29 and 2008-03-31 -----------------------------

2008-03-30 05:04:54 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-03-30 01:16:57 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-30 01:16:52 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-03-30 01:16:52 0 d-------- C:\Documents and Settings\Bradley\Application Data\SUPERAntiSpyware.com
2008-03-30 00:58:21 0 d-------- C:\Program Files\180search assistant
2008-03-30 00:58:20 0 d-------- C:\Program Files\180searchassistant
2008-03-29 07:21:29 0 d-------- C:\Documents and Settings\Bradley\Application Data\Grisoft
2008-03-29 07:21:18 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-29 06:52:01 3232 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-29 06:51:46 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-03-29 06:51:46 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-03-29 06:51:46 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-03-29 06:51:46 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-03-29 06:51:46 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-03-29 06:51:46 82432 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-03-29 06:51:46 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-03-29 06:45:35 0 d-------- C:\Program Files\Trend Micro
2008-03-29 06:41:20 0 d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-29 06:39:07 0 d-------- C:\Program Files\stc
2008-03-29 06:39:06 12032 --a------ C:\WINDOWS\voiceip.dll
2008-03-29 06:39:06 11008 --a------ C:\WINDOWS\mssvr.exe
2008-03-29 06:39:06 9728 --a------ C:\WINDOWS\cdsm32.dll
2008-03-29 06:39:06 18944 --a------ C:\WINDOWS\bjam.dll
2008-03-29 06:39:03 17664 --a------ C:\WINDOWS\system32\WER8274.DLL
2008-03-29 06:39:03 9984 --a------ C:\WINDOWS\system32\MSIXU.DLL
2008-03-29 06:39:02 22016 --a------ C:\WINDOWS\salm.exe
2008-03-29 06:39:01 21504 --a------ C:\WINDOWS\updatetc.exe
2008-03-29 06:39:01 0 d-------- C:\Program Files\180solutions
2008-03-29 06:39:00 28928 --a------ C:\WINDOWS\system32\MSNSA32.dll
2008-03-29 06:39:00 0 d-------- C:\WINDOWS\FLEOK
2008-03-29 06:38:59 26880 --a------ C:\WINDOWS\msapasrc.dll
2008-03-29 06:38:59 22784 --a------ C:\WINDOWS\msa64chk.dll
2008-03-29 06:38:57 19968 --a------ C:\WINDOWS\system32\SIPSPI32.dll
2008-03-29 06:38:57 11776 --a------ C:\WINDOWS\system32\shdocpe.dll
2008-03-29 06:38:57 21760 --a------ C:\WINDOWS\shdocpl.dll
2008-03-29 06:38:57 32512 --a------ C:\WINDOWS\shdocpe.dll
2008-03-29 06:38:57 18944 --a------ C:\WINDOWS\ntnut.exe
2008-03-29 06:38:56 25600 --a------ C:\WINDOWS\winsb.dll
2008-03-29 06:38:56 0 d-------- C:\Program Files\Sysmnt
2008-03-29 06:38:55 25600 --a------ C:\WINDOWS\browserad.dll
2008-03-29 06:38:55 25856 --a------ C:\WINDOWS\aviwrap32.dll
2008-03-29 06:38:55 12288 --a------ C:\WINDOWS\avisynthex32.dll
2008-03-29 06:38:55 12800 --a------ C:\WINDOWS\avifile32.dll
2008-03-29 06:38:55 17408 --a------ C:\WINDOWS\autodisc32.dll
2008-03-29 06:38:54 12800 --a------ C:\WINDOWS\audiosrv32.dll
2008-03-29 06:38:54 8192 --a------ C:\WINDOWS\ati2dvag32.dll
2008-03-29 06:38:54 24832 --a------ C:\WINDOWS\ati2dvaa32.dll
2008-03-29 06:38:54 30464 --a------ C:\WINDOWS\athprxy32.dll
2008-03-29 06:38:54 32256 --a------ C:\WINDOWS\asycfilt32.dll
2008-03-29 06:38:53 27904 --a------ C:\WINDOWS\asferror32.dll
2008-03-29 06:38:52 18688 --a------ C:\WINDOWS\changeurl_30.dll
2008-03-29 06:38:52 26112 --a------ C:\WINDOWS\apphelp32.dll
2008-03-29 04:48:33 0 d-------- C:\Program Files\Bat
2008-03-29 04:48:22 4 --a------ C:\WINDOWS\system32\winfrun32.bin
2008-03-29 03:52:14 0 d-------- C:\Program Files\AnvSoft
2008-03-29 03:51:59 0 d-------- C:\Program Files\Common Files\Download Manager
2008-03-23 00:17:36 0 d-------- C:\Program Files\Safari
2008-03-16 18:51:23 0 d-------- C:\Documents and Settings\All Users\Application Data\Logishrd
2008-03-16 18:51:11 0 d-------- C:\Program Files\Logitech
2008-03-16 07:22:49 0 d-------- C:\Program Files\iPod
2008-03-14 06:02:53 0 d-------- C:\torrents
2008-03-14 03:44:39 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-13 12:27:14 13369344 --a------ C:\Documents and Settings\Bradley\ntuser.dat
2008-03-13 12:27:13 229376 --a------ C:\Documents and Settings\LocalService\ntuser.dat


-- Find3M Report ---------------------------------------------------------------

2008-03-31 15:51:50 0 d-------- C:\Program Files\Steam
2008-03-31 15:35:05 0 d-------- C:\Documents and Settings\Bradley\Application Data\Azureus
2008-03-31 04:55:04 0 d-------- C:\Program Files\eMule
2008-03-31 04:51:13 0 d-------- C:\Program Files\Hijack This
2008-03-30 06:21:40 0 d-------- C:\Program Files\Systerac XP Tools 3
2008-03-30 06:19:40 0 d-------- C:\Program Files\QuickTime Alternative
2008-03-30 06:14:49 0 d-------- C:\Program Files\iTunes
2008-03-30 06:11:52 0 d-------- C:\Program Files\FlashGet
2008-03-30 06:04:55 0 d-------- C:\Program Files\AIM Lite
2008-03-30 03:06:17 0 d-------- C:\Documents and Settings\Bradley\Application Data\Help
2008-03-30 01:16:30 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-29 03:51:59 0 d-------- C:\Program Files\Common Files
2008-03-28 04:15:59 0 d-------- C:\Program Files\Agent
2008-03-16 18:54:17 0 d-------- C:\Program Files\Common Files\logishrd
2008-03-14 05:49:39 0 d-------- C:\Program Files\Windows Live
2008-03-14 05:49:20 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-06 18:29:41 0 d-------- C:\Program Files\Azureus
2008-02-06 23:36:34 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-02-01 16:46:35 0 d-------- C:\Program Files\iLike
2008-01-31 15:23:33 0 d-------- C:\Program Files\mIRC


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [07/01/2005 06:07 PM C:\WINDOWS\system32\HdAShCut.exe]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [08/12/2003 06:35 PM]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [09/07/2001 12:50 PM]
"RTHDCPL"="RTHDCPL.EXE" [08/06/2005 12:42 AM C:\WINDOWS\RTHDCPL.EXE]
"Alcmtr"="ALCMTR.EXE" [03/05/2005 04:43 AM C:\WINDOWS\ALCMTR.EXE]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [04/08/2004 06:00 AM]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [04/08/2004 06:00 AM]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [04/08/2004 06:00 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [25/09/2007 01:11 AM]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [04/12/2007 07:00 AM]
"Registry Compact"="C:\Program Files\Systerac XP Tools 3\regcomp.exe" [17/02/2005 08:17 AM]
"Memory Optimizer"="C:\Program Files\Systerac XP Tools 3\memoryo.exe" [02/05/2005 10:10 PM]
"laim"="C:\Program Files\AIM Lite\aimlite.exe" [26/03/2007 02:54 PM]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [10/11/2006 12:35 PM]
"QuickTime Task"="C:\Program Files\QuickTime Alternative\QTTask.exe" [31/01/2008 11:13 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [19/02/2008 01:10 PM]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [25/10/2007 04:33 PM]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [25/10/2007 04:37 PM]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [11/06/2007 03:25 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18/10/2007 11:34 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 06:00 AM]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [16/09/2005 06:41 PM]
"PowerBar"="" []
"Steam"="c:\program files\steam\steam.exe" [29/03/2008 06:37 AM]
"iLike"="C:\Program Files\iLike\1.1.27\ilikesidebar.exe" [13/09/2007 12:34 PM]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [22/12/2007 01:23 AM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [30/03/2008 10:16 AM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [20/12/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 30/03/2008 10:16 AM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\svcWRSSSDK]
@="Service"




-- End of Deckard's System Scanner: finished at 2008-03-31 15:57:32 ------------

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: AMD Athlon™ 64 X2 Dual Core Processor 3800+
CPU 1: AMD Athlon™ 64 X2 Dual Core Processor 3800+
Percentage of Memory in Use: 17%
Physical Memory (total/avail): 3327.36 MiB / 2753.29 MiB
Pagefile Memory (total/avail): 4507.18 MiB / 3930.48 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1930.75 MiB

A: is Removable (Unformatted)
C: is Fixed (NTFS) - 232.88 GiB total, 10.54 GiB free.
D: is CDROM (CDFS)
E: is CDROM (No Media)
F: is Fixed (NTFS) - 931.52 GiB total, 801.28 GiB free.

\\.\PHYSICALDRIVE0 - ST3250823AS - 232.88 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 232.88 GiB - C:

\\.\PHYSICALDRIVE1 - WDC WD50 00AAKS-00YGA0 USB Device - 931.52 GiB - 1 partition
\PARTITION0 - Installable File System - 931.52 GiB - F:



-- Security Center -------------------------------------------------------------

AUOptions is set to notify before download.
Windows Internal Firewall is disabled.

FirstRunDisabled is set.
AntiVirusDisableNotify is set.
FirewallDisableNotify is set.

AV: avast! antivirus 4.7.1098 [VPS 080331-0] v4.7.1098 (ALWIL Software)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\sweaw.exe"="C:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\sweaw.exe:*:Enabled:Star Wars: Empire at War"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\FlashGet\\flashget.exe"="C:\\Program Files\\FlashGet\\flashget.exe:*:Enabled:Flashget"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Bradley\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=BRAD
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Bradley
LOGONSERVER=\\BRAD
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\Common Files\Ulead Systems\DVD;C:\Program Files\iTunes\Plug-Ins\Qloud\;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\QuickTime Alternative\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 43 Stepping 1, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=2b01
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Bradley\LOCALS~1\Temp
TMP=C:\DOCUME~1\Bradley\LOCALS~1\Temp
USERDOMAIN=BRAD
USERNAME=Bradley
USERPROFILE=C:\Documents and Settings\Bradley
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI


-- User Profiles ---------------------------------------------------------------

Bradley (admin)
Shawn (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
?????? --> MsiExec.exe /I{148E0B24-4757-45F5-9418-FC6879D9753B}
???????????-The Anime- --> F:\Games\[HentaiShare].Oneesan.Chuu.Dashi.Chikan.Ressha.The.Animated.Version\MBSTRUTH\TIKANANIME\Uninstall.exe
?????~?????~ --> MsiExec.exe /I{E6BD1D87-E072-4149-96E2-DDAB3F9D7116}
7-Zip 4.42 --> "C:\Program Files\7-Zip\Uninstall.exe"
Adobe Acrobat 5.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
AIM Lite 0.32 --> C:\Program Files\AIM Lite\laim-uninst.exe
AnvSoft Flash to iPod Converter 1.10 --> "C:\Program Files\AnvSoft\Flash to iPod Converter\unins000.exe"
AOL Instant Messenger --> C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=
Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
ArcSoft PhotoImpression 5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}\Setup.exe" -l0x9
ATI - Software Uninstall Utility --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x0
ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,[email protected] -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
ATI HYDRAVISION --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{083F79E4-6FE9-46FB-A6C6-4F8862742947}\setup.exe"
avast! Antivirus --> rundll32 C:\PROGRA~1\ALWILS~1\Avast4\Setup\setiface.dll,RunSetup
AVG Anti-Spyware 7.5 --> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
Avi2Dvd 0.4.3 beta --> C:\Program Files\Avi2Dvd\uninst.exe
AviSynth 2.5 --> "C:\Program Files\AviSynth 2.5\Uninstall.exe"
Azureus --> C:\Program Files\Azureus\Uninstall.exe
Bat --> "C:\Program Files\Bat\un_BatSetup_15041.exe"
Black & White 2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D9E52CD1-9DF1-4A8A-9BDC-1E5E53982F2B}\setup.exe" -l0x9 -removeonly
Bomberman Online Beta --> "C:\Program Files\BMO\unins000.exe"
CABAL Online --> "F:\Games\CABAL Online\unins000.exe"
Combined Community Codec Pack 2007-02-22 --> "C:\Program Files\Combined Community Codec Pack\unins000.exe"
Digicam Print (V2.0) --> "C:\Program Files\IPRINT\uninst.exe"
DVD Solution --> "C:\Program Files\Uninstall_CDS.exe"
EPSON Print CD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}\Setup.exe" -l0x9 -SYSTEM
EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON Stylus Photo R260 User's Guide --> C:\Program Files\epson\guide\spr260_e\uninstall.exe
EVE-ONLINE (remove only) --> C:\Program Files\CCP\EVE\Uninstall.exe
EVE Launcher 1.0.3 --> "C:\Program Files\EVE Launcher\unins000.exe"
FlashGet 1.8.6.1008 --> C:\Program Files\FlashGet\uninst.exe
FlashGet(JetCar) --> C:\PROGRA~1\FlashGet\UNWISE.EXE C:\PROGRA~1\FlashGet\INSTALL.LOG
Free iPod Video Converter 1.34 --> "C:\Program Files\Free iPod Video Converter\unins000.exe"
GameSpy Arcade --> C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG
Geometry Wars --> "C:\Program Files\Steam\steam.exe" steam://uninstall/8400
GunZ Mouse Re-Binder 1.14 --> "C:\Program Files\GunZ Mouse Re-Binder\unins000.exe"
High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HighMAT Extension to Microsoft Windows XP CD Writing Wizard --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format SDK (KB902344) --> "C:\WINDOWS\$NtUninstallKB902344$\spuninst\spuninst.exe"
ijji - Gunz --> C:\ijji\ENGLISH\Gunz\Uninstall.exe
ijji FireFox Launcher 1.0 --> C:\Documents and Settings\All Users\Application Data\IJJIGame\uninst.exe
iLike Sidebar --> MsiExec.exe /X{72D037A4-D311-4250-B987-7D854760452C}
ILLUSION ????3 --> MsiExec.exe /X{E4D02EF2-6F12-4BE9-9928-2F27DA01A915}
ILLUSION Sexy???3 --> MsiExec.exe /X{6E7F60B4-F1E9-473F-A6BA-1C1C73A63592}
ImgBurn (Remove Only) --> "C:\Program Files\ImgBurn\uninstall.exe"
IMVU Avatar Chat Software --> C:\Program Files\IMVU\Uninstall.exe
InterActual Player --> C:\Program Files\InterActual\InterActual Player\inuninst.exe
iTunes --> MsiExec.exe /I{80FD852F-5AAC-4129-B931-06AAFFA43138}
J2SE Runtime Environment 5.0 Update 10 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
J2SE Runtime Environment 5.0 Update 11 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
J2SE Runtime Environment 5.0 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
J2SE Runtime Environment 5.0 Update 9 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
Java™ 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
KSignAccessToolkit v1.0 --> C:\WINDOWS\system32\UnInstall_KAccess.exe
LibUSB-Win32-0.1.10.1 --> "C:\Program Files\LibUSB-Win32-0.1.10.1\unins000.exe"
Logitech Audio Echo Cancellation Component --> MsiExec.exe /X{BEF726DD-4037-4214-8C6A-E625C02D2870}
Logitech Legacy USB Camera Driver Package --> "C:\Program Files\Common Files\LogiShrd\LogiDriverStore\legacyqcam\10.51.2023\LgDrvInst.exe" -remove -instdir"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\legacyqcam\" -enumdelay=2000 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -promptuninstall -arpregkey"legacyqcam_10.51" /clone_wait /hide_progress
Logitech QuickCam --> MsiExec.exe /X{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}
Logitech QuickCam Driver Package --> "C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\11.50.1145\LgDrvInst.exe" -remove -instdir"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\" -enumdelay=2000 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -promptuninstall -arpregkey"lvdrivers_11.50" /clone_wait /hide_progress
Logitech Video Enumerator --> MsiExec.exe /X{EA516024-D84D-41F1-814F-83175A6188F2}
Microsoft AppLocale --> MsiExec.exe /I{394BE3D9-7F57-4638-A8D1-1D88671913B7}
Microsoft Base Smart Card Cryptographic Service Provider Package --> "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Windows Application Compatibility Database --> C:\WINDOWS\system32\sdbinst.exe -u "C:\WINDOWS\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb"
mIRC --> "C:\Program Files\mIRC\mirc.exe" -uninstall
Mozilla Firefox (2.0.0.13) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Multimedia Launcher --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
MVision --> MsiExec.exe /I{35725FBC-A136-4A46-9F29-091759D9BB93}
Nero OEM --> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
Oz Insight All-In-One Newsreader --> C:\PROGRA~1\Ozum\UNWISE.EXE C:\PROGRA~1\Ozum\INSTALL.LOG
PANDA-glGo --> "C:\Program Files\glGo\uninstall.exe"
Panda ActiveScan --> C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan
PC Camera (6029 CIF) --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{54DC27A1-2708-421E-8915-119955DB3B92}\setup.exe" -l0x9
PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
PowerProducer --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
Qloud Plug-in for iTunes --> C:\Program Files\iTunes\Plug-Ins\Qloud\iTunesQLoudSetup.exe /uninstall
QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
QuickTime Alternative 1.76 --> "C:\Program Files\QuickTime Alternative\unins000.exe"
RagnarokOnline --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{50C94E8B-D6DC-4B61-A948-B84B08D40496}\setup.exe" -l0x9 -removeonly
Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
RGSS-RTP Standard --> "F:\Games\RPG maker\Standard\unins000.exe"
Rise Of Legends --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{CADDE354-C78C-46CB-A006-E2B178EFC271}
RollerCoaster Tycoon 3 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\Setup.exe" -l0x9
RPG????2003 ???????????? --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0044AEC7-8924-4FB1-B4F7-FD14A5FEA9E4}\setup.exe"
RPGcN[VX RTP --> "F:\Games\RPG maker\RPGVX\unins000.exe"
Rumble Fighter --> "F:\Games\Rumble Fighter\RumbleFighter\uninstall.exe"
Safari --> MsiExec.exe /I{0AFC9710-5DD6-4C6A-BA52-91AE992B2C9D}
ScreenGrab 1.1 --> "C:\Program Files\ScreenGrab\unins000.exe"
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Smart DVD Creator --> "C:\Program Files\SmartDVDCreator\unins000.exe"
SpeechRedist --> MsiExec.exe /X{8795CBED-55E2-4693-9F14-84EC446935BE}
Star Wars Battlefront II --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3D374523-CFDE-461A-827E-2A102E2AB365}\Setup.exe" -l0x9 -removeonly
Star Wars Empire at War --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{99AE7207-8612-4DBA-A8F8-BAE5C633390D}\Setup.exe" -l0x9 -removeonly
Star Wars Republic Commando --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DFAE9340-E8BB-4433-9A08-C8334DAFE1B9}\Setup.exe" -l0x9
Steam --> MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
StepMania (remove only) --> "C:\Program Files\StepMania\uninstall.exe"
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Systerac XP Tools 3.0d --> MsiExec.exe /X{117C48E6-2D0A-4E93-99F8-16452EA3E300}
Ulead Photo Explorer 8.0 SE Basic --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D271DAE0-8D68-4C97-8356-A126D48A1D8C}\Setup.exe" -l0x9
Unreal Tournament 2004 --> C:\UT2004\System\Setup.exe uninstall "UT2004"
UT2004 Editor's Choice Edition Mod Installer --> MsiExec.exe /I{88D5B052-13BF-44FE-8C17-AC416B323BFE}
Ventrilo Client --> MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
VideoLAN VLC media player 0.8.4a --> C:\Program Files\VideoLAN\VLC\uninstall.exe
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Warcraft III: All Products --> C:\WINDOWS\War3Unin.exe C:\WINDOWS\War3Unin.dat
WinAce Archiver --> C:\Program Files\WinAce\SXUNINST.EXE C:\Program Files\WinAce\SXUNINST.INI
Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger --> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant --> MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
Windows Media Connect --> "C:\WINDOWS\$NtUninstallWMCSetup$\spuninst\spuninst.exe"
Windows Media Format SDK Hotfix - KB891122 --> "C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
Xfire (remove only) --> "C:\Program Files\Xfire\uninst.exe"
XviD MPEG-4 Video Codec --> "C:\Program Files\XviD\unins000.exe"


-- Application Event Log -------------------------------------------------------

Event Record #/Type14420 / Warning
Event Submitted/Written: 03/31/2008 03:51:36 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}', feature 'QuickCam' failed during request for component '{3BBB8098-03C8-48DC-AA83-9B2159E12E0D}'

Event Record #/Type14419 / Warning
Event Submitted/Written: 03/31/2008 03:51:36 PM
Event ID/Source: 1004 / MsiInstaller
Event Description:
Detection of product '{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}', feature 'QuickCam', component '{B52C7B4D-F46F-438C-ADF2-05A138C57757}' failed. The resource 'HKEY_CURRENT_USER\Software\Logitech\InstallerKeys\QCDesktopShortcutKey' does not exist.

Event Record #/Type14418 / Warning
Event Submitted/Written: 03/31/2008 03:51:36 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}', feature 'QuickCam' failed during request for component '{3BBB8098-03C8-48DC-AA83-9B2159E12E0D}'

Event Record #/Type14417 / Warning
Event Submitted/Written: 03/31/2008 03:51:36 PM
Event ID/Source: 1004 / MsiInstaller
Event Description:
Detection of product '{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}', feature 'QuickCam', component '{B52C7B4D-F46F-438C-ADF2-05A138C57757}' failed. The resource 'HKEY_CURRENT_USER\Software\Logitech\InstallerKeys\QCDesktopShortcutKey' does not exist.

Event Record #/Type14416 / Warning
Event Submitted/Written: 03/31/2008 03:51:33 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}', feature 'QuickCam' failed during request for component '{62BA7C13-20BB-41F7-A6A4-482632CE53D4}'



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type507463 / Error
Event Submitted/Written: 03/31/2008 03:54:25 PM
Event ID/Source: 8003 / MRxSmb
Event Description:
The master browser has received a server announcement from the computer NEC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{0DBA1AEF-0E6E-4186-B165.
The master browser is stopping or an election is being forced.

Event Record #/Type507436 / Error
Event Submitted/Written: 03/31/2008 03:39:26 PM
Event ID/Source: 8003 / MRxSmb
Event Description:
The master browser has received a server announcement from the computer NEC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{0DBA1AEF-0E6E-4186-B165.
The master browser is stopping or an election is being forced.

Event Record #/Type507409 / Error
Event Submitted/Written: 03/31/2008 02:54:25 PM
Event ID/Source: 8003 / MRxSmb
Event Description:
The master browser has received a server announcement from the computer NEC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{0DBA1AEF-0E6E-4186-B165.
The master browser is stopping or an election is being forced.

Event Record #/Type507408 / Error
Event Submitted/Written: 03/31/2008 01:39:25 PM
Event ID/Source: 8003 / MRxSmb
Event Description:
The master browser has received a server announcement from the computer NEC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{0DBA1AEF-0E6E-4186-B165.
The master browser is stopping or an election is being forced.

Event Record #/Type507407 / Error
Event Submitted/Written: 03/31/2008 00:39:25 PM
Event ID/Source: 8003 / MRxSmb
Event Description:
The master browser has received a server announcement from the computer NEC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{0DBA1AEF-0E6E-4186-B165.
The master browser is stopping or an election is being forced.



-- End of Deckard's System Scanner: finished at 2008-03-31 15:57:32 ------------
  • 0

#8
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\Program Files\180search assistant
    C:\Program Files\180searchassistant
    C:\Documents and Settings\All Users\Application Data\Rabio
    C:\Program Files\stc
    C:\WINDOWS\voiceip.dll
    C:\WINDOWS\mssvr.exe
    C:\WINDOWS\cdsm32.dll
    C:\WINDOWS\bjam.dll
    C:\WINDOWS\system32\WER8274.DLL
    C:\WINDOWS\system32\MSIXU.DLL
    C:\WINDOWS\salm.exe
    C:\WINDOWS\updatetc.exe
    C:\Program Files\180solutions
    C:\WINDOWS\system32\MSNSA32.dll
    C:\WINDOWS\FLEOK
    C:\WINDOWS\msapasrc.dll
    C:\WINDOWS\msa64chk.dll
    C:\WINDOWS\system32\SIPSPI32.dll
    C:\WINDOWS\system32\shdocpe.dll
    C:\WINDOWS\shdocpl.dll
    C:\WINDOWS\shdocpe.dll
    C:\WINDOWS\ntnut.exe
    C:\WINDOWS\winsb.dll
    C:\Program Files\Sysmnt
    C:\WINDOWS\browserad.dll
    C:\WINDOWS\aviwrap32.dll
    C:\WINDOWS\avisynthex32.dll
    C:\WINDOWS\avifile32.dll
    C:\WINDOWS\autodisc32.dll
    C:\WINDOWS\audiosrv32.dll
    C:\WINDOWS\ati2dvag32.dll
    C:\WINDOWS\ati2dvaa32.dll
    C:\WINDOWS\athprxy32.dll
    C:\WINDOWS\asycfilt32.dll
    C:\WINDOWS\asferror32.dll
    C:\WINDOWS\changeurl_30.dll
    C:\WINDOWS\apphelp32.dll
    C:\Program Files\Bat
    C:\WINDOWS\system32\winfrun32.bin
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    purity
  • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


Reboot and post a new DSS log
  • 0

#9
Cheap-o

Cheap-o

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts
OTMoveIt2 and DSS logs:

C:\Program Files\180search assistant moved successfully.
C:\Program Files\180searchassistant moved successfully.
C:\Documents and Settings\All Users\Application Data\Rabio\Search Enhancer moved successfully.
C:\Documents and Settings\All Users\Application Data\Rabio moved successfully.
C:\Program Files\stc moved successfully.
LoadLibrary failed for C:\WINDOWS\voiceip.dll
C:\WINDOWS\voiceip.dll NOT unregistered.
C:\WINDOWS\voiceip.dll moved successfully.
C:\WINDOWS\mssvr.exe moved successfully.
LoadLibrary failed for C:\WINDOWS\cdsm32.dll
C:\WINDOWS\cdsm32.dll NOT unregistered.
C:\WINDOWS\cdsm32.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\bjam.dll
C:\WINDOWS\bjam.dll NOT unregistered.
C:\WINDOWS\bjam.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\WER8274.DLL
C:\WINDOWS\system32\WER8274.DLL NOT unregistered.
C:\WINDOWS\system32\WER8274.DLL moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\MSIXU.DLL
C:\WINDOWS\system32\MSIXU.DLL NOT unregistered.
C:\WINDOWS\system32\MSIXU.DLL moved successfully.
C:\WINDOWS\salm.exe moved successfully.
C:\WINDOWS\updatetc.exe moved successfully.
C:\Program Files\180solutions moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\MSNSA32.dll
C:\WINDOWS\system32\MSNSA32.dll NOT unregistered.
C:\WINDOWS\system32\MSNSA32.dll moved successfully.
C:\WINDOWS\FLEOK moved successfully.
LoadLibrary failed for C:\WINDOWS\msapasrc.dll
C:\WINDOWS\msapasrc.dll NOT unregistered.
C:\WINDOWS\msapasrc.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\msa64chk.dll
C:\WINDOWS\msa64chk.dll NOT unregistered.
C:\WINDOWS\msa64chk.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\SIPSPI32.dll
C:\WINDOWS\system32\SIPSPI32.dll NOT unregistered.
C:\WINDOWS\system32\SIPSPI32.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\shdocpe.dll
C:\WINDOWS\system32\shdocpe.dll NOT unregistered.
C:\WINDOWS\system32\shdocpe.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\shdocpl.dll
C:\WINDOWS\shdocpl.dll NOT unregistered.
C:\WINDOWS\shdocpl.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\shdocpe.dll
C:\WINDOWS\shdocpe.dll NOT unregistered.
C:\WINDOWS\shdocpe.dll moved successfully.
C:\WINDOWS\ntnut.exe moved successfully.
LoadLibrary failed for C:\WINDOWS\winsb.dll
C:\WINDOWS\winsb.dll NOT unregistered.
C:\WINDOWS\winsb.dll moved successfully.
C:\Program Files\Sysmnt moved successfully.
LoadLibrary failed for C:\WINDOWS\browserad.dll
C:\WINDOWS\browserad.dll NOT unregistered.
C:\WINDOWS\browserad.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\aviwrap32.dll
C:\WINDOWS\aviwrap32.dll NOT unregistered.
C:\WINDOWS\aviwrap32.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\avisynthex32.dll
C:\WINDOWS\avisynthex32.dll NOT unregistered.
C:\WINDOWS\avisynthex32.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\avifile32.dll
C:\WINDOWS\avifile32.dll NOT unregistered.
C:\WINDOWS\avifile32.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\autodisc32.dll
C:\WINDOWS\autodisc32.dll NOT unregistered.
C:\WINDOWS\autodisc32.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\audiosrv32.dll
C:\WINDOWS\audiosrv32.dll NOT unregistered.
C:\WINDOWS\audiosrv32.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\ati2dvag32.dll
C:\WINDOWS\ati2dvag32.dll NOT unregistered.
C:\WINDOWS\ati2dvag32.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\ati2dvaa32.dll
C:\WINDOWS\ati2dvaa32.dll NOT unregistered.
C:\WINDOWS\ati2dvaa32.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\athprxy32.dll
C:\WINDOWS\athprxy32.dll NOT unregistered.
C:\WINDOWS\athprxy32.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\asycfilt32.dll
C:\WINDOWS\asycfilt32.dll NOT unregistered.
C:\WINDOWS\asycfilt32.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\asferror32.dll
C:\WINDOWS\asferror32.dll NOT unregistered.
C:\WINDOWS\asferror32.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\changeurl_30.dll
C:\WINDOWS\changeurl_30.dll NOT unregistered.
C:\WINDOWS\changeurl_30.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\apphelp32.dll
C:\WINDOWS\apphelp32.dll NOT unregistered.
C:\WINDOWS\apphelp32.dll moved successfully.
C:\Program Files\Bat moved successfully.
C:\WINDOWS\system32\winfrun32.bin moved successfully.
[Custom Input]
< purity >

OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03312008_161724


Deckard's System Scanner v20071014.68
Run by Bradley on 2008-03-31 16:32:22
Computer is in Normal Mode.
--------------------------------------------------------------------------------

System Drive C: has 10.55 GiB (less than 15%) free.


-- HijackThis (run as Bradley.exe) ---------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:32:27 PM, on 31/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\libusbd-nt.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Systerac XP Tools 3\memoryo.exe
C:\Program Files\AIM Lite\aimlite.exe
C:\Program Files\QuickTime Alternative\QTTask.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bradley\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Bradley.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Registry Compact] "C:\Program Files\Systerac XP Tools 3\regcomp.exe" /Auto
O4 - HKLM\..\Run: [Memory Optimizer] "C:\Program Files\Systerac XP Tools 3\memoryo.exe"
O4 - HKLM\..\Run: [laim] "C:\Program Files\AIM Lite\aimlite.exe" -autorun
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [iLike] C:\Program Files\iLike\1.1.27\ilikesidebar.exe /checkforupdate
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Bradley\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zon...wn.cab56986.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload....Plugin11USA.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0DBA1AEF-0E6E-4186-B165-3958A27D96B9}: NameServer = 4.2.2.2,4.2.2.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{0DBA1AEF-0E6E-4186-B165-3958A27D96B9}: NameServer = 4.2.2.2,4.2.2.3
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - http://libusb-win32.sourceforge.net - C:\WINDOWS\system32\libusbd-nt.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 9542 bytes

-- Files created between 2008-02-29 and 2008-03-31 -----------------------------

2008-03-30 05:04:54 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-03-30 01:16:57 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-30 01:16:52 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-03-30 01:16:52 0 d-------- C:\Documents and Settings\Bradley\Application Data\SUPERAntiSpyware.com
2008-03-29 07:21:29 0 d-------- C:\Documents and Settings\Bradley\Application Data\Grisoft
2008-03-29 07:21:18 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-29 06:52:01 3232 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-29 06:51:46 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-03-29 06:51:46 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-03-29 06:51:46 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-03-29 06:51:46 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-03-29 06:51:46 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-03-29 06:51:46 82432 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-03-29 06:51:46 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-03-29 06:45:35 0 d-------- C:\Program Files\Trend Micro
2008-03-29 03:52:14 0 d-------- C:\Program Files\AnvSoft
2008-03-29 03:51:59 0 d-------- C:\Program Files\Common Files\Download Manager
2008-03-23 00:17:36 0 d-------- C:\Program Files\Safari
2008-03-16 18:51:23 0 d-------- C:\Documents and Settings\All Users\Application Data\Logishrd
2008-03-16 18:51:11 0 d-------- C:\Program Files\Logitech
2008-03-16 07:22:49 0 d-------- C:\Program Files\iPod
2008-03-14 06:02:53 0 d-------- C:\torrents
2008-03-14 03:44:39 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-13 12:27:14 13369344 --a------ C:\Documents and Settings\Bradley\ntuser.dat
2008-03-13 12:27:13 229376 --a------ C:\Documents and Settings\LocalService\ntuser.dat


-- Find3M Report ---------------------------------------------------------------

2008-03-31 16:31:06 0 d-------- C:\Program Files\Steam
2008-03-31 15:35:05 0 d-------- C:\Documents and Settings\Bradley\Application Data\Azureus
2008-03-31 04:55:04 0 d-------- C:\Program Files\eMule
2008-03-31 04:51:13 0 d-------- C:\Program Files\Hijack This
2008-03-30 06:21:40 0 d-------- C:\Program Files\Systerac XP Tools 3
2008-03-30 06:19:40 0 d-------- C:\Program Files\QuickTime Alternative
2008-03-30 06:14:49 0 d-------- C:\Program Files\iTunes
2008-03-30 06:11:52 0 d-------- C:\Program Files\FlashGet
2008-03-30 06:04:55 0 d-------- C:\Program Files\AIM Lite
2008-03-30 03:06:17 0 d-------- C:\Documents and Settings\Bradley\Application Data\Help
2008-03-30 01:16:30 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-29 03:51:59 0 d-------- C:\Program Files\Common Files
2008-03-28 04:15:59 0 d-------- C:\Program Files\Agent
2008-03-16 18:54:17 0 d-------- C:\Program Files\Common Files\logishrd
2008-03-14 05:49:39 0 d-------- C:\Program Files\Windows Live
2008-03-14 05:49:20 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-06 18:29:41 0 d-------- C:\Program Files\Azureus
2008-02-06 23:36:34 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-02-01 16:46:35 0 d-------- C:\Program Files\iLike
2008-01-31 15:23:33 0 d-------- C:\Program Files\mIRC


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [07/01/2005 06:07 PM C:\WINDOWS\system32\HdAShCut.exe]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [08/12/2003 06:35 PM]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [09/07/2001 12:50 PM]
"RTHDCPL"="RTHDCPL.EXE" [08/06/2005 12:42 AM C:\WINDOWS\RTHDCPL.EXE]
"Alcmtr"="ALCMTR.EXE" [03/05/2005 04:43 AM C:\WINDOWS\ALCMTR.EXE]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [04/08/2004 06:00 AM]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [04/08/2004 06:00 AM]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [04/08/2004 06:00 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [25/09/2007 01:11 AM]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [04/12/2007 07:00 AM]
"Registry Compact"="C:\Program Files\Systerac XP Tools 3\regcomp.exe" [17/02/2005 08:17 AM]
"Memory Optimizer"="C:\Program Files\Systerac XP Tools 3\memoryo.exe" [02/05/2005 10:10 PM]
"laim"="C:\Program Files\AIM Lite\aimlite.exe" [26/03/2007 02:54 PM]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [10/11/2006 12:35 PM]
"QuickTime Task"="C:\Program Files\QuickTime Alternative\QTTask.exe" [31/01/2008 11:13 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [19/02/2008 01:10 PM]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [25/10/2007 04:33 PM]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [25/10/2007 04:37 PM]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [11/06/2007 03:25 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18/10/2007 11:34 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 06:00 AM]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [16/09/2005 06:41 PM]
"PowerBar"="" []
"Steam"="c:\program files\steam\steam.exe" [29/03/2008 06:37 AM]
"iLike"="C:\Program Files\iLike\1.1.27\ilikesidebar.exe" [13/09/2007 12:34 PM]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [22/12/2007 01:23 AM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [30/03/2008 10:16 AM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [20/12/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 30/03/2008 10:16 AM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\svcWRSSSDK]
@="Service"




-- End of Deckard's System Scanner: finished at 2008-03-31 16:32:47 ------------
  • 0

#10
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan. Check all the boxes and click Start Scan
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Also tell me how your PC is running
  • 0

Advertisements


#11
Cheap-o

Cheap-o

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts
Here is the MBAM logfile:

Malwarebytes' Anti-Malware 1.10
Database version: 581

Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|)
Objects scanned: 252286
Time elapsed: 1 hour(s), 47 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 11
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 13

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{f663b917-591f-4172-8d87-3d7d729007ca} (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bat.batbho (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bat.batbho.1 (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63f7460b-c831-4142-a4aa-5ec303ec4343} (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d279bc2b-a85b-4559-8fd9-ddc55f5d402d} (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{b80a3586-caa5-41c8-89bf-e617f0b6cfbf} (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\BATCO (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Batco (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\bat.DLL (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Bat (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bat (Adware.Batco) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{DD7ED82D-6963-44D1-B240-9C469809E934}\RP702\A0118588.exe (Adware.Batco) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DD7ED82D-6963-44D1-B240-9C469809E934}\RP703\A0118628.exe (Adware.Batco) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DD7ED82D-6963-44D1-B240-9C469809E934}\RP703\A0118670.exe (Adware.Batco) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{DD7ED82D-6963-44D1-B240-9C469809E934}\RP704\A0118703.exe (Adware.Batco) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\03312008_153418\program files\Bat\Bat.dll (Adware.Batco) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\03312008_153418\program files\Bat\Bat.exe (Adware.Batco) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\03312008_153418\program files\Bat\un_BatSetup_15041.exe (Adware.Rabio) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\03312008_153418\program files\Bat\X_Bat.exe (Adware.Batco) -> Quarantined and deleted successfully.
C:\WINDOWS\didduid.ini (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\123messenger.per (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\licencia.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\telefonos.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\textos.txt (Malware.Trace) -> Quarantined and deleted successfully.

Thank you for all your help so far. My computer seems to be running pretty good. I can at least use it for watching anime at the moment. I had to fix my catalyst control center which seemed to have been corrupted. Also, the spyware still replaces my desktop background, and many of the graphics for my icons seem to be missing. Those are the only things I've noticed so far.

Edit: Not that it probably makes any difference, but I just noticed that when I lock my computer, my normal background comes back, but the instant I unlock it, the spyware one is back.

Edited by Cheap-o, 02 April 2008 - 03:47 AM.

  • 0

#12
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Your logs are clean ! We need to do a few things

Now we need to create a new System Restore point.

Click Start Menu > Run > type (or copy and paste)

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it and click Create, when the confirmation screen shows the restore point has been created click Close.

Next goto Start Menu > Run > type

cleanmgr

Click OK, Disk Cleanup will open and start calculating the amount of space that can be freed, Once thats finished it will open the Disk Cleanup options screen, click the More Options tab then click Clean up on the system restore area and choose Yes at the confirmation window which will remove all the restore points except the one we just created.

To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.



You now need to update your Java and remove your older versions.

Please follow these steps to remove older version Java components.

* Click Start > Control Panel.
* Click Add/Remove Programs.
* Check any item with Java Runtime Environment (JRE) in the name.
* Click the Remove or Change/Remove button.

Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
here



  • Make sure you have an Internet Connection.
  • Double-click OTMoveIt2.exe to run it.
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OtMoveit2 to rech the Internet, please allow the application to do so.
  • Click Yes to beging the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
SpywareBlaster protects against bad ActiveX
IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here

* SpywareGuard offers realtime protection from spyware installation attempts.

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Kleins article 'How Did I Get Infected In The First Place'
Here

Thank you for your patience, and performing all of the procedures requested.
  • 0

#13
Cheap-o

Cheap-o

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts
My background continues to be replaced every time I log into windows, and many of the graphics for my icons are missing. Is there any way to fix these problems?
  • 0

#14
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
What is it changed to exactly ?

Are you having any problems besides that ?
  • 0

#15
Cheap-o

Cheap-o

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts
A screenshot of my desktop (I know it's a little messy ^^') is attached, it's warning me I'm infected with spyware, and links to a site to buy the one that the pop-ups I had to begin with, led to. But you can also see how many icons are missing graphics too. No problems besides that.

Attached Thumbnails

  • Desktop.JPG

Edited by Cheap-o, 02 April 2008 - 04:45 PM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP