Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Win32.Trojan.Yspy


  • This topic is locked This topic is locked

#91
kelkay

kelkay

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 423 posts
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: AMD Athlon™ 64 X2 Dual Core Processor 4200+
CPU 1: AMD Athlon™ 64 X2 Dual Core Processor 4200+
Percentage of Memory in Use: 55%
Physical Memory (total/avail): 958.48 MiB / 428.22 MiB
Pagefile Memory (total/avail): 2313.13 MiB / 1880.68 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1895.84 MiB

C: is Fixed (NTFS) - 224.03 GiB total, 127.97 GiB free.
D: is Fixed (FAT32) - 8.84 GiB total, 0.6 GiB free.
E: is CDROM (CDFS)
F: is Removable (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
I: is Removable (No Media)

\\.\PHYSICALDRIVE0 - WDC WD2500JS-60NCB1 - 232.88 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 224.03 GiB - C:
\PARTITION1 - Unknown - 8.85 GiB - D:

\\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device

\\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device

\\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device

\\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.

FirstRunDisabled is set.

FW: Norton Internet Worm Protection v2006 (Symantec) Disabled
FW: ZoneAlarm Pro Firewall v7.0.470.000 (Check Point, LTD.)
AV: Doctor Web Anti-Virus v4.44.4.03250 (Doctor Web, Ltd.)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Application Loader"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe:*:Enabled:AOLTsMon"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe:*:Enabled:AOLTopSpeed"
"C:\\Program Files\\Common Files\\AOL\\1164757353\\EE\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1164757353\\EE\\AOLServiceHost.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"="C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"="C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0a\\waol.exe"="C:\\Program Files\\America Online 9.0a\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe:*:Enabled:AOL"
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"="C:\\Program Files\\Paltalk Messenger\\paltalk.exe:*:Enabled:Paltalk 9 beta"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"="C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe:*:Enabled:Zoo Tycoon 2 Executable"
"C:\\Program Files\\Common Files\\AOL\\1164757353\\EE\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1164757353\\EE\\aolsoftware.exe:*:Enabled:AOL Shared Components"
"C:\\Program Files\\kontiki\\KService.exe"="C:\\Program Files\\kontiki\\KService.exe:*:Enabled:Delivery Manager Service"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe:*:Enabled:AOL TopSpeed"
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe:*:Enabled:MySpaceIM"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Kelly\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=YOUR-4DACD0EA75
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Kelly
LOGONSERVER=\\YOUR-4DACD0EA75
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22;C:\Program Files\Common Files\GTK\2.0\bin;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\;;C:\PROGRA~1\COMMON~1\MUVEET~1\030625;C:\PROGRA~1\COMMON~1\MUVEET~1\030625
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 75 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=4b02
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Kelly\LOCALS~1\Temp
TMP=C:\DOCUME~1\Kelly\LOCALS~1\Temp
tvdumpflags=8
USERDOMAIN=YOUR-4DACD0EA75
USERNAME=Kelly
USERPROFILE=C:\Documents and Settings\Kelly
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

Kelly (admin)
Kayla
Kyle
Administrator (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> "C:\Program Files\BZEdit1.6.5TankGame\uninstall.exe"
--> "C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /nolog/l0x0009
--> "C:\Program Files\Creative Installation Information\CTCMSGO\Setup.exe" /remove /nolog/l0x0009
--> "C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /nolog/l0x0009
--> "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_CDBURNER_U\Setup.exe" /remove /nolog/l0x0009
--> "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MINIDISC_U\Setup.exe" /remove /nolog/l0x0009
--> "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MTP_U\Setup.exe" /remove /nolog/l0x0009
--> "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MUSICPLAYER_MSS_U\Setup.exe" /remove /nolog/l0x0009
--> "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_NOMADJUKEBOXTYPE2_U\Setup.exe" /remove /nolog/l0x0009
--> "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe" /remove /nolog/l0x0009
--> "C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /nolog/l0x0009
--> C:\PROGRA~1\SBCSEL~1\CustomUninstall.exe SBC
--> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> c:\WINDOWS\system32\\MSIEXEC.EXE /x {F80239D8-7811-4D5E-B033-0D0BBFE32920}
--> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
--> C:\WINDOWS\UNNMP.exe /UNINSTALL
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8DF9BF77-7E10-4973-965E-3B7013ABEA6D}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8DF9BF77-7E10-4973-965E-3B7013ABEA6D}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98181885-5B28-4280-9B56-452FF877D5B9}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98181885-5B28-4280-9B56-452FF877D5B9}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A0B5225-B59B-4D72-B3FE-71AAA693A8E2}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A0B5225-B59B-4D72-B3FE-71AAA693A8E2}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A9BB081B-C020-4D02-A763-D32204D2563D}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A9BB081B-C020-4D02-A763-D32204D2563D}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C029DB0E-C59F-417A-90F8-88FD5B2C4AE7}\setup.exe" -l0x9
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
7-Zip 4.57 --> "C:\Program Files\7-Zip\Uninstall.exe"
Active Ports --> C:\WINDOWS\unvise32.exe C:\Program Files\Active Ports\uninstal.log
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
AOL Coach Version 2.0(Build:20041026.5 en) --> C:\Program Files\Common Files\AolCoach\en_en\AolCInUn.exe -lang=en_en -ext=UDP
AOL Toolbar --> "C:\Program Files\AOL Toolbar\UNWISE.EXE" /u "C:\Program Files\AOL Toolbar\INSTALL.LOG"
AOL Uninstaller (Choose which Products to Remove) --> C:\Program Files\Common Files\AOL\uninstaller.exe
Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update --> MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
ArcSoft PhotoImpression 5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{069364A0-8F64-4691-8719-B3CC728BFD6C}\Setup.exe" -l0x9
ArcSoft PhotoPrinter 5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{65D30520-CFB9-4E46-A101-68C0AADAE40C}\Setup.exe" -l0x9
Ashampoo Burning Studio 2007 --> "C:\Program Files\Ashampoo\Ashampoo Burning Studio 2007\Uninstall\1010_Uninstall.EXE"
Ashampoo Burning Studio 5 --> "C:\Program Files\Ashampoo\Ashampoo Burning Studio 5\Uninstall\BS5_Uninstall.EXE"
Ashampoo Burning Studio 6 --> "C:\Program Files\Ashampoo\Ashampoo Burning Studio 6\Uninstall\BS6_Uninstall.EXE"
Ashampoo Music Studio 3 --> "C:\Program Files\Ashampoo\Ashampoo Music Studio 3\Uninstall\0230_Uninstall.EXE"
Ashampoo PowerUP XP Platinum 2 --> C:\Program Files\Ashampoo\Ashampoo PowerUp XP Platinum 2\Uninstall\PowerUp_Uninstall.EXE
Ashampoo WinOptimizer Platinum 3 --> "C:\Program Files\Ashampoo\Ashampoo WinOptimizer Platinum 3\Uninstall\WOP3_Uninstall.exe"
AT&T Self Support Tool --> C:\WINDOWS\Motive\SBC\MCCUninst.exe
Audacity 1.2.6 --> "C:\Program Files\Audacity\unins000.exe"
AudibleManager --> C:\Program Files\Audible\Bin\Upgrade.exe /Uninstall
Camp Funshine: Carrie the Caregiver 3 --> C:\PROGRA~1\SHOCKW~1.COM\CAMPFU~1\UNWISE.EXE C:\PROGRA~1\SHOCKW~1.COM\CAMPFU~1\INSTALL.LOG
Career Direct --> C:\PROGRA~1\CAREER~1\UNWISE.EXE C:\PROGRA~1\CAREER~1\INSTALL.LOG
CCleaner (remove only) --> "C:\Program Files\CCleaner137\uninst.exe"
Click'N Design 3D (V5) --> C:\PROGRA~1\CLICK'~1\UNWISE.EXE C:\PROGRA~1\CLICK'~1\INSTALL.LOG
Coffee Rush --> C:\PROGRA~1\SHOCKW~1.COM\COFFEE~1\UNWISE.EXE C:\PROGRA~1\SHOCKW~1.COM\COFFEE~1\INSTALL.LOG
Creative MediaSource 5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\SETUP.EXE" -l0x9 /remove
Creative Removable Disk Manager --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9 /remove
Creative System Information --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9 /remove
Creative ZEN Vision M Series --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{31C44235-A613-4E95-B297-207BF6C6A8C1}\SETUP.EXE" -l0x9 /remove
Data Fax SoftModem with SmartCP --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1\HXFSETUP.EXE -U -ITrx200Ck.inf
DiskTools ImageMaker 1.1 Version 1.1 --> "C:\Program Files\DiskTools\ImageMaker\unins000.exe"
Dr.Web --> C:\Program Files\InstallShield Installation Information\{BBE2F69C-4338-11D7-8F0C-00A0244F4E2D}\setup.exe -runfromtemp -l0x0009 -removeonly
DropMyRights --> MsiExec.exe /I{E5B72007-07C9-4E67-B29E-696073F45704}
DVD Shrink 3.2 --> "C:\Program Files\DVD Shrink\unins000.exe"
e-Sword --> MsiExec.exe /I{87791AF4-4D4C-43DC-97BF-05EEEE5187F2}
Enhanced Multimedia Keyboard Solution --> C:\HP\KBD\Install.exe /u
Error Messages for Windows --> C:\WINDOWS\SDUnInst.exe c:\program files\software by design\mswinerr.uni
Fish Tycoon --> "C:\Program Files\Oberon Media\Fish Tycoon\Uninstall.exe" "C:\Program Files\Oberon Media\Fish Tycoon\install.log"
Free CD to MP3 Converter --> C:\PROGRA~1\CDTOMP~1\UNWISE.EXE C:\PROGRA~1\CDTOMP~1\INSTALL.LOG
Google Earth --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonly
Google Video Player --> "C:\Program Files\Google\Google Video Player\Uninstall.exe"
GTK+ 2.10.13 runtime environment --> "C:\Program Files\Common Files\GTK\2.0\setup\unins000.exe"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
HP Boot Optimizer --> MsiExec.exe /X{1341D838-719C-4A05-B50F-49420CA1B4BB}
HP Customer Participation Program 7.0 --> C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP DigitalMedia Archive --> MsiExec.exe /X{F80239D8-7811-4D5E-B033-0D0BBFE32920}
HP DVD Play 2.1 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
HP Imaging Device Functions 7.0 --> C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart and Deskjet 7.0 Software --> C:\Program Files\HP\Digital Imaging\{D2A3C9D5-0B56-4656-8277-7EDC65D62B6E}\setup\hpzscr01.exe -datfile hphscr12.dat -showdisconnect -forcereboot
HP Photosmart Essential --> MsiExec.exe /X{6994491D-D491-48F1-AE1F-E179C1FFFC2F}
HP Photosmart for Media Center PC --> c:\Program Files\HP\Digital Imaging\bin\mcpc\setupmcl.exe /u
HP Photosmart Premier Software 6.5 --> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Solution Center 7.0 --> C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update --> MsiExec.exe /X{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}
HP Web Helper --> regsvr32 /u /s "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll"
IObit SmartDefrag Beta1.1 --> "C:\Program Files\IObit\IObit SmartDefrag\unins000.exe"
iTunes --> MsiExec.exe /I{9F70BF98-003C-491D-81FC-FF9792206AF0}
iVocalize Web Conference 4 --> rundll32 C:\WINDOWS\system32\iv4.dll,uninstall
Java™ 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
JGsoft EditPad Lite 6.2.1 --> C:\WINDOWS\UnDeploy.exe "C:\Program Files\JGsoft\EditPadLite\Deploy.log"
Lame ACM MP3 Codec --> C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_LameMP3 132 C:\WINDOWS\INF\LameACM.inf
Legacy 6.0 --> C:\Legacy\UNWISE.EXE /U C:\Legacy\Install.log
Logitech MouseWare 9.79 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5809E7CF-4DCF-11D4-9875-00105ACE7734}\setup.exe" -l0x9 -l0009 UNINSTALL
Malware Immunizer 1.5 --> C:\PROGRA~1\MALWAR~1\MI.exe /remove /q0
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Media Center Karaoke Plug-in --> MsiExec.exe /I{348054A0-6F9A-4EF9-BBB0-827C14C20D86}
MediaCoder 0.5.1 --> C:\Program Files\MediaCoder\uninst.exe
MediaMonkey 2.5 --> "C:\Program Files\MediaMonkey\unins000.exe"
Microsoft ActiveSync --> MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
Microsoft Age of Empires II --> "C:\Program Files\Microsoft Games\Age of Empires II\UNINSTAL.EXE" /runtemp /uninstall
Microsoft Age of Empires II: The Conquerors Expansion --> "C:\Program Files\Microsoft Games\Age of Empires II\UNINSTALX.EXE" /runtemp /addremove
Microsoft Away Mode -->
Microsoft Base Smart Card Cryptographic Service Provider Package --> "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Outlook 2002 --> MsiExec.exe /I{911A0409-6000-11D3-8CFE-0050048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Works --> MsiExec.exe /I{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}
Moodflow.com Inspirational Screen Saver --> sstunst3.exe Moodflow.com Inspirational
Mozilla Firefox (2.0.0.14) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
muvee autoProducer 5.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB4740B3-2530-452D-A825-F7AB246CA7DF}\setup.exe" -l0x9
muvee autoProducer unPlugged 2.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5FDD0538-C67A-4F67-B3F8-09D1AAF04D99}\setup.exe" -l0x9
Napster --> C:\Program Files\InstallShield Installation Information\{BBBCAE4B-B416-4182-A6F2-438180894A81}\setup.exe -runfromtemp -l0x0009 -removeonly
Napster Burn Engine --> MsiExec.exe /I{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}
Napster Label Creator --> MsiExec.exe /X{16FD907B-FA72-4F3C-B959-E076C8238F80}
Navilog1 3.5.7 --> "C:\Program Files\Navilog1\unins000.exe"
Nero Suite --> C:\Program Files\Common Files\Nero\Uninstall\setupx.exe /uninstall ExtraUninstallID=""
NVIDIA Drivers --> C:\WINDOWS\system32\nvunrm.exe UninstallGUI
OMN --> MsiExec.exe /X{65150683-D155-485A-A037-690087DE2271}
OpenOffice.org 2.3 --> MsiExec.exe /I{83C03FBE-4492-4133-BBAB-421CD88ADA32}
OpenTalk v3.20 --> "C:\Program Files\OpenTalk\unins000.exe"
Otto --> "C:\Program Files\EnglishOtto\uninstallotto.exe"
PaltalkScene --> "C:\WINDOWS\Paltalk Messenger\uninstall.exe" "/U:C:\Program Files\Paltalk Messenger\irunin.xml"
PC-Doctor 5 for Windows --> C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
PortPeeker --> "C:\Program Files\PortPeeker\unins000.exe"
Python 2.2 pywin32 extensions (build 203) --> "C:\Python22\Removepywin32.exe" -u "C:\Python22\pywin32-wininst.log"
Python 2.2.3 --> C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG
QuickTime --> MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
REA's TESTware for CLEP Western Civilization I --> MsiExec.exe /I{1FCD61C5-E3A9-4B11-8651-ED29B35C1B9E}
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek High Definition Audio Driver --> RtlUpd.exe -r -m
Registry Mechanic 6.0 --> "C:\Program Files\Registry Mechanic\unins000.exe"
RootsMagic 3.2.5.0 --> "C:\Program Files\RootsMagic\unins000.exe"
Samsung Digital Camera --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B79684C-6DAC-438C-8F30-10DF65C2068F}\Setup.exe"
Samsung Master --> C:\Program Files\InstallShield Installation Information\{AEC0CEBC-0FC7-4716-8222-1C4A742719B1}\Setup.exe -runfromtemp -l0x0009 -removeonly
Sansa Media Converter --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D2A0F8F4-CE50-4857-A21C-3061682B2E87}\Setup.exe" -l0x9
Sansa Updater --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E2D7E05E-C8C7-45F4-8D89-D6696075E0B7}\setup.exe" -l0x9 -removeonly
SeaMonkey (1.1.9) --> C:\WINDOWS\SeaMonkeyUninstall.exe /ua "1.1.9 (en)"
SelectSoft Championship Chess --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{871EFABF-ED09-42A0-8C4C-000000000027}\Setup.exe"
Sophos Anti-Rootkit 1.3.1 --> C:\Program Files\Sophos\Sophos Anti-Rootkit\helper.exe remove
SpeedFan (remove only) --> "C:\Program Files\SpeedFan\uninstall.exe"
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins001.exe"
Spybot - Search & Destroy 1.5.2.20 --> "C:\WINDOWS\unins000.exe"
SpywareBlaster 4.1 --> "C:\Program Files\SpywareBlaster\unins000.exe"
SpywareGuard v2.2 --> "C:\Program Files\SpywareGuard\unins000.exe"
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
SureThing CD Labeler --> C:\WINDOWS\MVUNINST\App1\unwise.exe C:\WINDOWS\MVUNINST\APP1\INSTALL.LOG "SureThing CD Labeler Uninstall"
The GIMP 2.2.17 --> "C:\Program Files\GIMP-2.0\unins000.exe"
The Sims Deluxe Edition --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{10798AE3-DCBB-43C3-9C93-C23512427E25}\setup.exe" -l0009
TheSage --> "C:\Program Files\TheSage\uninstall.exe"
Time Zone Data Update Tool for Microsoft Office Outlook --> MsiExec.exe /X{95120000-0038-0409-0000-0000000FF1CE}
Traces Viewer --> "C:\Program Files\Traces Viewer\unins000.exe"
Unreal Streaming Media Player v 4.0 --> MsiExec.exe /I{ECB9FA96-3E03-411A-AFDB-1FC4686E5099}
Update Rollup 2 for Windows XP Media Center Edition 2005 -->
Updates from HP (remove only) --> C:\WINDOWS\HPCPCUninstall-9972322\HPBWSetup.exe -appid 9972322 -uninstall
WebFerret --> C:\WINDOWS\WebFerretUninstall.exe C:\Program Files\FerretSoft\WebFerret
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Mobile Daylight Saving Time 2007 Updates --> MsiExec.exe /X{AB46C238-3554-4D79-AB06-C393F87FF202}
Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
WinUpdatesList --> C:\WINDOWS\zipinst.exe /uninst "C:\Program Files\WinUpdatesList\uninst1~.nsu"
WordWeb --> C:\Program Files\WordWeb\uninst.exe
XML Paper Specification Shared Components Pack 1.0 -->
Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe
ZENcast Organizer --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C029DB0E-C59F-417A-90F8-88FD5B2C4AE7}\setup.exe" -l0x9 /remove
ZMatrix 1.5.2 --> "C:\Program Files\ZMatrix\unins000.exe"
ZoneAlarm Pro --> C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe
Zoo Tycoon 2 --> "C:\Program Files\Microsoft Games\Zoo Tycoon 2\UNINSTAL.EXE" /runtemp /uninstall
ZVUE Portable MP3 Player --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{05698A5C-23A7-4EC2-945C-66F1F0DE4856}\setup.exe" -l0x9


-- Application Event Log -------------------------------------------------------

Event Record #/Type8823 / Warning
Event Submitted/Written: 06/23/2008 05:01:33 PM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Event Record #/Type8777 / Warning
Event Submitted/Written: 06/19/2008 10:41:20 PM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Event Record #/Type8754 / Warning
Event Submitted/Written: 06/18/2008 01:31:30 AM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Event Record #/Type8711 / Warning
Event Submitted/Written: 06/16/2008 03:30:49 PM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Event Record #/Type8702 / Warning
Event Submitted/Written: 06/16/2008 08:52:15 AM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type14726 / Error
Event Submitted/Written: 06/23/2008 10:22:44 PM
Event ID/Source: 7 / Disk
Event Description:
The device, \Device\Harddisk0\D, has a bad block.

Event Record #/Type14725 / Error
Event Submitted/Written: 06/23/2008 10:22:40 PM
Event ID/Source: 7 / Disk
Event Description:
The device, \Device\Harddisk0\D, has a bad block.

Event Record #/Type14724 / Error
Event Submitted/Written: 06/23/2008 10:22:38 PM
Event ID/Source: 7 / Disk
Event Description:
The device, \Device\Harddisk0\D, has a bad block.

Event Record #/Type14723 / Error
Event Submitted/Written: 06/23/2008 10:22:37 PM
Event ID/Source: 7 / Disk
Event Description:
The device, \Device\Harddisk0\D, has a bad block.

Event Record #/Type14722 / Error
Event Submitted/Written: 06/23/2008 10:22:34 PM
Event ID/Source: 7 / Disk
Event Description:
The device, \Device\Harddisk0\D, has a bad block.



-- End of Deckard's System Scanner: finished at 2008-06-23 22:24:41 ------------
  • 0

Advertisements


#92
koko_crunch

koko_crunch

    Trusted Helper

  • Retired Staff
  • 1,751 posts
Hey,

Main.txt got cut off.
Could you please re-post.
File will be located in C:\DEckard.
  • 0

#93
kelkay

kelkay

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 423 posts
Deckard's System Scanner v20071014.68
Run by Kelly on 2008-06-23 22:18:34
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Kelly.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:19:09, on 6/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe
C:\PROGRA~1\DrWeb\spiderui.exe
C:\PROGRA~1\DrWeb\SpiderNT.exe
C:\Program Files\DrWeb\spiderml.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Kelly\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Kelly.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - (no file)
O3 - Toolbar: WebFerret - {A58686ED-FC46-44C3-95C6-4A812AB776F1} - C:\Program Files\FerretSoft\WebFerret\FerretBand.dll
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /startup
O4 - HKLM\..\Run: [SpIDerNT] C:\PROGRA~1\DrWeb\spiderui.exe /agent
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpIDerMail] "C:\Program Files\DrWeb\spiderml.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKUS\S-1-5-18\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (User 'Default user')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - S-1-5-18 Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\system32\wweb32.dll/lookup.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....030/CTSUEng.cab
O16 - DPF: {127CE7BA-AD89-4108-A913-C52EFC037C36} (OMN Player Support) - http://kdx.omn.org/s...ayerSupport.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewid...oOnlineScan.cab
O16 - DPF: {2776DDE9-D4B2-4BF7-9F98-ADC1A1B80AF5} (OMN Media Publisher) - http://kdx.omn.org/s...iaPublisher.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.shockwave...h2.1.0.0.67.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1165348971449
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -
O16 - DPF: {A7ECD556-D6F6-4F41-8C6B-14AB246801A0} (Secure Delivery) - http://kdx.omn.org/s...ery/omn/kdx.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15030/CTPID.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sansa Updater Service (SansaService) - Unknown owner - C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe
O23 - Service: SpIDer Guard for Windows NT (spidernt) - Doctor Web, Ltd. - C:\PROGRA~1\DrWeb\SpiderNT.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 10716 bytes

-- Files created between 2008-05-23 and 2008-06-23 -----------------------------

2008-06-23 21:55:03 0 d-------- C:\SmitfraudFix
2008-06-23 20:42:18 291328 --a------ C:\OTMoveIt2.exe <Not Verified; OldTimer Tools; OTMoveIt>
2008-06-23 17:52:34 1477906 --a------ C:\SmitfraudFix.exe
2008-06-23 17:06:15 0 d-------- C:\WINDOWS\ERUNT
2008-06-23 14:20:18 1441875 --a------ C:\SDFix.exe
2008-06-16 15:42:13 3322 --a------ C:\WINDOWS\system32\tmp.reg
2008-06-15 21:31:48 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-15 21:31:41 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-06-15 21:31:41 0 d-------- C:\Documents and Settings\Kelly\Application Data\SUPERAntiSpyware.com
2008-06-12 15:35:16 0 d-------- C:\Program Files\iPod
2008-06-12 15:35:06 0 d-------- C:\Program Files\iTunes
2008-06-12 15:34:02 0 d-------- C:\Program Files\QuickTime
2008-06-12 15:32:24 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-06-12 15:31:58 0 d-------- C:\Program Files\Common Files\Apple
2008-06-12 15:29:32 0 d-------- C:\Program Files\Apple Software Update
2008-06-12 15:29:32 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-06-06 17:04:15 21312 --a------ C:\WINDOWS\choice.exe
2008-06-06 16:59:37 0 d-------- C:\old
2008-06-06 16:59:37 0 d-------- C:\choice
2008-06-06 16:59:37 0 d-------- C:\adult
2008-06-06 16:59:00 0 d-------- C:\ie-spyad
2008-06-06 08:57:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-06-06 08:57:03 0 d-------- C:\Program Files\Common Files\Adobe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\winupie.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\winmuschi.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\updatewinlocator.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\zp.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\zeropopupbar.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winwsl.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\wintft.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\wintbpx.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\wintbp.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winshow.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winsb.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winrvl.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winpup32.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winpup.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winlocatorhelper.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winlocator.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winksl.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\systemout.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\sysdll32.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\servises.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\pup.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\pnp.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\per.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\norton update.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\[bleep].exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\df_kme.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\csm.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\botzor.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\axconfig.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\4ccc3cea.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\pnpasn32.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\hpsv.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\cdproxyserv.exe
2008-06-05 23:49:24 230 -r-h----- C:\Program Files\zsearch
2008-06-05 23:49:24 240 -r-h----- C:\Program Files\zeropopupbar
2008-06-05 23:49:24 226 -r-h----- C:\Program Files\zangoclient
2008-06-05 23:49:24 226 -r-h----- C:\Program Files\zango games
2008-06-05 23:49:24 228 -r-h----- C:\Program Files\xsoftware
2008-06-05 23:49:24 228 -r-h----- C:\Program Files\xpcspy
2008-06-05 23:49:24 232 -r-h----- C:\Program Files\winfixer 2005
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\windowsupd4.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\windowsupd2.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\windowsupd1.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\vx2.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\winntcreate.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\vx2.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\vwix32.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\uninmyad.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\tps108.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\tisa.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\tips.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\tippcls.dat
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\tipp.dat
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\ticont.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\ticads.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\tconini.dat
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\sysmonnt.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\spwgoc.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\rvreg.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\rulesak.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\myad.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\msview.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\msnavc32.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\lut.dat
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\lspak.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\localnrd.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\lcch.dat
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\ladchkr.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\host.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\gdu.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\dad.bat
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\cidrules.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\6fo4svc.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\psapi.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\kernellos.dll
2008-06-05 23:49:23 222 -r-h----- C:\WINDOWS\isrvs
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\iehelper.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\cleanhistories.dll
2008-06-05 23:49:23 240 -r-h----- C:\Program Files\winfavorites
2008-06-05 23:49:23 246 -r-h----- C:\Program Files\windows adtools
2008-06-05 23:49:23 250 -r-h----- C:\Program Files\windows adcontrol
2008-06-05 23:49:23 230 -r-h----- C:\Program Files\win comm
2008-06-05 23:49:23 226 -r-h----- C:\Program Files\whenu
2008-06-05 23:49:23 236 -r-h----- C:\Program Files\web_rebates
2008-06-05 23:49:23 236 -r-h----- C:\Program Files\web_cpr
2008-06-05 23:49:23 224 -r-h----- C:\Program Files\vvsn
2008-06-05 23:49:23 226 -r-h----- C:\Program Files\vvsdl
2008-06-05 23:49:23 226 -r-h----- C:\Program Files\vomba
2008-06-05 23:49:23 238 -r-h----- C:\Program Files\vmntoolbar
2008-06-05 23:49:23 232 -r-h----- C:\Program Files\ts trial
2008-06-05 23:49:23 222 -r-h----- C:\Program Files\hpdll
2008-06-05 23:49:23 232 -r-h----- C:\Program Files\Common Files\winsoftware
2008-06-05 23:49:23 226 -r-h----- C:\Program Files\Common Files\ucontrol
2008-06-05 23:49:23 222 -r-h----- C:\Program Files\autoupdate
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\t2serv.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\t2serv.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\wshtlprh.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\wshnseri.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\winftsap.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\winftsap.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\w3sskbda.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\vsxmpgpc.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\vnetsmme.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\vb5dmspo.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\v4pbpt51.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\trafracp.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\timesrv.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\snmpmssw.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\slbrmqtr.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\slbipsch.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\slbipsch.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\shfoxpob.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\secumsje.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\sd16win.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\scp3jgaw.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\rdpwmsjt.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\rcbdwmpd.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\qdvtscf.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\oebdfc.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\msstersv.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\msnsxole.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\msnsxole.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\mslsicwd.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\msexcred.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\msafiasn.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\messenger.lib.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\hook2.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\hook1.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\google.png.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\game3.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\game2.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\game1.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\adchkr.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\sserrvv.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\serrv.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\reggserv.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\msupdtwiz.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\cserv32.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\ccsserv.exe
2008-06-05 23:49:22 234 -r-h----- C:\temp_kl
2008-06-05 23:49:22 232 -r-h----- C:\Program Files\topmoxie
2008-06-05 23:49:22 244 -r-h----- C:\Program Files\sys detective+
2008-06-05 23:49:22 240 -r-h----- C:\Program Files\surfsidekick
2008-06-05 23:49:22 240 -r-h----- C:\Program Files\surfsidekick 2
2008-06-05 23:49:22 232 -r-h----- C:\Program Files\superbar
2008-06-05 23:49:22 232 -r-h----- C:\Program Files\netmeting
2008-06-05 23:49:22 234 -r-h----- C:\archivos de programa
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\unsocul.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\sodahk.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\socul.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\mqoacdmo.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\mqadscp3.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\mgmtmtxc.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\mcd3mscm.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\lmrtatkc.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\kbdpkbdr.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\kbdfwshe.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\jgsdrpcn.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\jgsdrpcn.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\jgdwadsn.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\jgdwadsn.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\iuennwcf.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\ir32racp.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\ipxwshel.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\ipxrmfc4.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\imesrdch.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\icmpdx3j.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\iaspdpus.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\i4n27vl.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\hhselz32.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\fltlauto.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\fileserv.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\dsseds32.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\dsseds32.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\dpugmswe.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\dnsrxpob.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\deskmcd3.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\ddemdmco.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\davctool.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\davctool.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\confbrw.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\comrkbdd.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\comploader.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\chkmfdep.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\camodpnm.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\brwstat.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\brwprf32.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\brwperf.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\brwmgr32.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\brwconf.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\avifipxr.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\admeiolo.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\actidmoc.exe
2008-06-05 23:49:21 234 -r-h----- C:\spedia
2008-06-05 23:49:21 244 -r-h----- C:\Program Files\swagent
2008-06-05 23:49:21 244 -r-h----- C:\Program Files\stealthwatcher200
2008-06-05 23:49:21 230 -r-h----- C:\Program Files\spytech software
2008-06-05 23:49:21 234 -r-h----- C:\Program Files\spyonthis
2008-06-05 23:49:21 232 -r-h----- C:\Program Files\spyblast
2008-06-05 23:49:21 226 -r-h----- C:\Program Files\p4p
2008-06-05 23:49:21 226 -r-h----- C:\Program Files\Common Files\sogou pxp
2008-06-05 23:49:20 236 -r-h----- C:\WINDOWS\winsecurity
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\waladhpr.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\wzhelper.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\webalize.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\somatic.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\smdnn05.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\servehost.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\seqsb.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\searchupdate33.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\searchupdate31.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\searchsquire33.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\searchsquire3.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\searchsquire2.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\searchsquire.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\seantb.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\s4helper.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\reg2.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\pqhelper.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\mygeek.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\msqsb.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\msplus4.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\msplus3.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\msplus2.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\mslspcg.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\mgeekremove.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\ifsomatic.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\ifhelper.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\iebrw.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\hotlink.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\homepage.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\hmepge.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\gsim.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\barbho.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\svrmgr.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\ssmsgr.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\ssls.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\ssdgt.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\sscrg.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\skynetave.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\napatch.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\gsim.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\cssswd.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\csssupd.exe
2008-06-05 23:49:20 236 -r-h----- C:\WINDOWS\connectionstatus
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\cfg32s.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\cfg32r.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\cfg32o.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\cfg32.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\avserve3.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\avserve2.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\adrsb.exe
2008-06-05 23:49:20 232 -r-h----- C:\Program Files\valintines day card
2008-06-05 23:49:20 234 -r-h----- C:\Program Files\softomate
2008-06-05 23:49:20 248 -r-h----- C:\Program Files\selectrebates
2008-06-05 23:49:20 234 -r-h----- C:\Program Files\searchnet
2008-06-05 23:49:20 240 -r-h----- C:\Program Files\searchlocate
2008-06-05 23:49:20 236 -r-h----- C:\Program Files\screenview
2008-06-05 23:49:20 230 -r-h----- C:\Program Files\savenow
2008-06-05 23:49:20 234 -r-h----- C:\Program Files\rxtoolbar
2008-06-05 23:49:20 234 -r-h----- C:\Program Files\ietoolbar
2008-06-05 23:49:20 230 -r-h----- C:\Program Files\ezthemes_whenusavenow_installer
2008-06-05 23:49:20 242 -r-h----- C:\Program Files\dynamic toolbar
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\wserver.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\winlogon.scr
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\visualguard.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\vlcx052.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\speeder.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\slpube03.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\rlvknlg.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\rkinstaller.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\rk.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\optserve.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\optserve.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\msplus1.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\msplus.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\mrkscr.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\lp.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\lp.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\auole4.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\sysmonxp.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\symav.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\switpb.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\switpa.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\rundil32.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\rundil.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\phantom.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\pandaavengine.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\netmedia.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\msnmsgrs.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\maja.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\lansas.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\kasperskyaveng.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\jammer2nd.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\infodll.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\fooding.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\firewallsvr.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\easyav.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\diskmonitor.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\comp.cpl
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\avprotect9x.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\avprotect.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\avpguard.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\avguard.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\avbgle.exe
2008-06-05 23:49:19 234 -r-h----- C:\Program Files\startup mechanic
2008-06-05 23:49:19 250 -r-h----- C:\Program Files\relevantknowledge
2008-06-05 23:49:19 234 -r-h----- C:\Program Files\rax search helper
2008-06-05 23:49:19 228 -r-h----- C:\Program Files\psupport
2008-06-05 23:49:19 234 -r-h----- C:\Program Files\need2find
2008-06-05 23:49:19 226 -r-h----- C:\Program Files\ncase
2008-06-05 23:49:19 232 -r-h----- C:\Program Files\navexcel
2008-06-05 23:49:19 232 -r-h----- C:\Program Files\navexcel search toolbar
2008-06-05 23:49:19 238 -r-h----- C:\Program Files\mywebsearch
2008-06-05 23:49:19 228 -r-h----- C:\Program Files\exolon
2008-06-05 23:49:19 234 -r-h----- C:\Program Files\ddr
2008-06-05 23:49:19 236 -r-h----- C:\Program Files\Common Files\nsis
2008-06-05 23:49:19 234 -r-h----- C:\Program Files\arcade!
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\xpfirewall.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wpwmgrs.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winvnc.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wintasker.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winsyscfg.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winsys.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winsvc32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winstart.pif
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winnt.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wininfo.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winhlpapi.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wingmt32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winds.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\windowsfirewall.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\windasz-updote.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\win24.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wid32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wfdmgr.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wfdgmr.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wdns33.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\w32ntupdt.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\w1nt5k.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\twunk_65.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\timemanager.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\taskgmr32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\taskgamr.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\tagmr.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\sysconf.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\sword.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\stagmr.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\sp2winfix.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\sp2fx.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\skybot.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\shell.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\service5.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\sd.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\scrigz.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\scalpe91.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\protection.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\plugnplay32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\picx.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\phantom.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\netcog.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\mtrnqs.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\mssck.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\msplus32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\msnl.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\msmgrxp.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\msgmr.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\msdev32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\mouse.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\microupdate.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\memloader.exe
2008-06-05 23:49:17 0 dr-hs---- C:\winssystem.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\unstall.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb60.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb58.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb57.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb56.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb52.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb51.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb42.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb41.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb40.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\windmy.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winats.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\patch31345.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\osalogbe.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\nn_bar31.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\nn_bar22.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\nn_bar21.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\nn_bar.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\myaccess.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\msapasrc.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\msa64chk.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\microsystem.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\mcscn.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\mailinfo.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\logitechwls.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\logic.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lienvdk.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lienvandekelder.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lientjeuh.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lien vd kelder.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lien vande kelder.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lien Van de kelderrr.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lien van de kelder.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lcd32.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\jusched32.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\itunegui.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\hostdrvxp.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\hbmail.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\gothica.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\fixupdattr.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\evil.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\ds.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\dcomuser.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\coolbot.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\ccsrs.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\avpr.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\abs.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\666.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\1hellbot.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\0.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\patch31345.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\msnarrator.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\mrhop.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\mpgcom.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\iempg2.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\iempg.dll
2008-06-05 23:49:17 236 -r-h----- C:\Program Files\support software
2008-06-05 23:49:17 236 -r-h----- C:\Program Files\network essentials
2008-06-05 23:49:17 236 -r-h----- C:\Program Files\medialoads
2008-06-05 23:49:17 236 -r-h----- C:\Program Files\medialoads enhanced
2008-06-05 23:49:17 0 dr-hs---- C:\hellmsn.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\xwrm.exe
2008-06-05 23:49:16 240 -r-h----- C:\WINDOWS\wintrim
2008-06-05 23:49:16 240 -r-h----- C:\WINDOWS\winmgts
2008-06-05 23:49:16 240 -r-h----- C:\WINDOWS\wincomp
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\vtlbar1.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\version.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\updtscheduler.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\tubby.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\toolbar.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\tbc.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\nas.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\msxml4r.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\msklive.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\mseggrpid.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\msegcompid.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\mscache.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\mapisvc32.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\madise.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\keyhost.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\keyactivex.ocx
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\jeired.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\ia.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\gcasctrl.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\egdial.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\egdhtml_1027.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\egdhtml_1026.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\duel.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\dll.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\aupdate_uninstall.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\aupdate.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\adv.dll
2008-06-05 23:49:16 240 -r-h----- C:\WINDOWS\navpmc
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\mscache.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\mscache.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\mmups.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\mm63.ocx
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\mm21.ocx
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\mm20.ocx
2008-06-05 23:49:16 240 -r-h----- C:\WINDOWS\mc
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\istsvc.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\imgurla.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\exedialer.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\a64sddd.exe
2008-06-05 23:49:16 234 -r-h----- C:\Program Files\powersearch
2008-06-05 23:49:16 234 -r-h----- C:\Program Files\perfectnav
2008-06-05 23:49:16 242 -r-h----- C:\Program Files\media gateway
2008-06-05 23:49:16 232 -r-h----- C:\Program Files\md
2008-06-05 23:49:16 228 -r-h----- C:\Program Files\lstsvc
2008-06-05 23:49:16 244 -r-h----- C:\Program Files\kuaiso toolsbar
2008-06-05 23:49:16 242 -r-h----- C:\Program Files\kgb keylogger
2008-06-05 23:49:16 266 -r-h----- C:\Program Files\invisible secrets toolbar
2008-06-05 23:49:16 240 -r-h----- C:\Program Files\instant buzz
2008-06-05 23:49:16 234 -r-h----- C:\Program Files\incredifind
2008-06-05 23:49:16 228 -r-h----- C:\Program Files\ebayshop
2008-06-05 23:49:16 234 -r-h----- C:\Program Files\Common Files\updmgr
2008-06-05 23:49:16 234 -r-h----- C:\Program Files\Common Files\updater
2008-06-05 23:49:16 234 -r-h----- C:\Program Files\Common Files\keenvalue
2008-06-05 23:49:15 232 -r-h----- C:\WINDOWS\wqzq
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\winobject.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\wdskctl.exe
2008-06-05 23:49:15 232 -r-h----- C:\WINDOWS\wcby
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\ts.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\winstart001.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\winstart.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\winsrm32.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\winenc32.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\windowsie.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\windec32.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\waeb.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\update_rsp.DLL
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\update_removeold.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\update_hosts.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\update_com.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\update_bho.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\sbus.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\rsp001.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\rsp.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\install_all.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\ineb.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr29.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr27.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr26.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr25.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr24.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr23.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr22.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr11.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iemsg.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\gws.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\egdhtml_1025.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\egdhtml_1024.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\egdhtml_1023.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\drbr.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\chgrgs.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\bundler_mpb_sb.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\bmeb.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\bho001.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\belop.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\absnro.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\abeb.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\systb.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\systb.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\ssk.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\snbho.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\rgrt.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\pxckdlauninstall.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\pxckdla.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\offerssk.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\invitessk.exe
2008-06-05 23:49:15 230 -r-h----- C:\WINDOWS\ilookup
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\id.exe
2008-06-05 23:49:15 258 -r-h----- C:\Program Files\instant access
2008-06-05 23:49:15 248 -r-h----- C:\Program Files\install provider
2008-06-05 23:49:15 240 -r-h----- C:\Program Files\instafink
2008-06-05 23:49:14 0 dr-hs---- C:\WINDOWS\system32\zopenssl.dll
2008-06-05 23:49:14 0 dr-hs---- C:\WINDOWS\system32\yvsvga.sys
2008-06-05 23:49:14 0 dr-hs---- C:\WINDOWS\system32\yvsvga.dll
2008-06-05 23:49:14 0 dr-hs---- C:\WINDOWS\system32\yvprgb.dll
2008-06-05 23:49:14 0 dr-hs---- C:\WINDOWS\system32\yvpp02.sys
2008-06-05 23:49:14 0 dr-hs--
  • 0

#94
kelkay

kelkay

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 423 posts
Deckard's System Scanner v20071014.68
Run by Kelly on 2008-06-23 22:13:30
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Kelly.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:14:09, on 6/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe
C:\PROGRA~1\DrWeb\spiderui.exe
C:\PROGRA~1\DrWeb\SpiderNT.exe
C:\Program Files\DrWeb\spiderml.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Kelly\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Kelly.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - (no file)
O3 - Toolbar: WebFerret - {A58686ED-FC46-44C3-95C6-4A812AB776F1} - C:\Program Files\FerretSoft\WebFerret\FerretBand.dll
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /startup
O4 - HKLM\..\Run: [SpIDerNT] C:\PROGRA~1\DrWeb\spiderui.exe /agent
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpIDerMail] "C:\Program Files\DrWeb\spiderml.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKUS\S-1-5-18\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (User 'Default user')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - S-1-5-18 Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\system32\wweb32.dll/lookup.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....030/CTSUEng.cab
O16 - DPF: {127CE7BA-AD89-4108-A913-C52EFC037C36} (OMN Player Support) - http://kdx.omn.org/s...ayerSupport.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewid...oOnlineScan.cab
O16 - DPF: {2776DDE9-D4B2-4BF7-9F98-ADC1A1B80AF5} (OMN Media Publisher) - http://kdx.omn.org/s...iaPublisher.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.shockwave...h2.1.0.0.67.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1165348971449
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -
O16 - DPF: {A7ECD556-D6F6-4F41-8C6B-14AB246801A0} (Secure Delivery) - http://kdx.omn.org/s...ery/omn/kdx.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15030/CTPID.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sansa Updater Service (SansaService) - Unknown owner - C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe
O23 - Service: SpIDer Guard for Windows NT (spidernt) - Doctor Web, Ltd. - C:\PROGRA~1\DrWeb\SpiderNT.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 10716 bytes

-- Files created between 2008-05-23 and 2008-06-23 -----------------------------

2008-06-23 21:55:03 0 d-------- C:\SmitfraudFix
2008-06-23 20:42:18 291328 --a------ C:\OTMoveIt2.exe <Not Verified; OldTimer Tools; OTMoveIt>
2008-06-23 17:52:34 1477906 --a------ C:\SmitfraudFix.exe
2008-06-23 17:06:15 0 d-------- C:\WINDOWS\ERUNT
2008-06-23 14:20:18 1441875 --a------ C:\SDFix.exe
2008-06-16 15:42:13 3322 --a------ C:\WINDOWS\system32\tmp.reg
2008-06-15 21:31:48 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-15 21:31:41 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-06-15 21:31:41 0 d-------- C:\Documents and Settings\Kelly\Application Data\SUPERAntiSpyware.com
2008-06-12 15:35:16 0 d-------- C:\Program Files\iPod
2008-06-12 15:35:06 0 d-------- C:\Program Files\iTunes
2008-06-12 15:34:02 0 d-------- C:\Program Files\QuickTime
2008-06-12 15:32:24 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-06-12 15:31:58 0 d-------- C:\Program Files\Common Files\Apple
2008-06-12 15:29:32 0 d-------- C:\Program Files\Apple Software Update
2008-06-12 15:29:32 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-06-06 17:04:15 21312 --a------ C:\WINDOWS\choice.exe
2008-06-06 16:59:37 0 d-------- C:\old
2008-06-06 16:59:37 0 d-------- C:\choice
2008-06-06 16:59:37 0 d-------- C:\adult
2008-06-06 16:59:00 0 d-------- C:\ie-spyad
2008-06-06 08:57:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-06-06 08:57:03 0 d-------- C:\Program Files\Common Files\Adobe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\winupie.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\winmuschi.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\updatewinlocator.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\zp.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\zeropopupbar.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winwsl.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\wintft.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\wintbpx.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\wintbp.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winshow.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winsb.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winrvl.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winpup32.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winpup.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winlocatorhelper.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winlocator.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\winksl.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\systemout.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\sysdll32.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\servises.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\pup.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\pnp.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\per.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\norton update.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\[bleep].exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\df_kme.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\csm.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\botzor.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\axconfig.dll
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\system32\4ccc3cea.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\pnpasn32.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\hpsv.exe
2008-06-05 23:49:24 0 dr-hs---- C:\WINDOWS\cdproxyserv.exe
2008-06-05 23:49:24 230 -r-h----- C:\Program Files\zsearch
2008-06-05 23:49:24 240 -r-h----- C:\Program Files\zeropopupbar
2008-06-05 23:49:24 226 -r-h----- C:\Program Files\zangoclient
2008-06-05 23:49:24 226 -r-h----- C:\Program Files\zango games
2008-06-05 23:49:24 228 -r-h----- C:\Program Files\xsoftware
2008-06-05 23:49:24 228 -r-h----- C:\Program Files\xpcspy
2008-06-05 23:49:24 232 -r-h----- C:\Program Files\winfixer 2005
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\windowsupd4.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\windowsupd2.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\windowsupd1.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\vx2.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\winntcreate.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\vx2.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\vwix32.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\uninmyad.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\tps108.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\tisa.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\tips.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\tippcls.dat
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\tipp.dat
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\ticont.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\ticads.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\tconini.dat
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\sysmonnt.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\spwgoc.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\rvreg.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\rulesak.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\myad.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\msview.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\msnavc32.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\lut.dat
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\lspak.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\localnrd.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\lcch.dat
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\ladchkr.exe
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\host.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\gdu.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\dad.bat
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\cidrules.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\system32\6fo4svc.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\psapi.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\kernellos.dll
2008-06-05 23:49:23 222 -r-h----- C:\WINDOWS\isrvs
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\iehelper.dll
2008-06-05 23:49:23 0 dr-hs---- C:\WINDOWS\cleanhistories.dll
2008-06-05 23:49:23 240 -r-h----- C:\Program Files\winfavorites
2008-06-05 23:49:23 246 -r-h----- C:\Program Files\windows adtools
2008-06-05 23:49:23 250 -r-h----- C:\Program Files\windows adcontrol
2008-06-05 23:49:23 230 -r-h----- C:\Program Files\win comm
2008-06-05 23:49:23 226 -r-h----- C:\Program Files\whenu
2008-06-05 23:49:23 236 -r-h----- C:\Program Files\web_rebates
2008-06-05 23:49:23 236 -r-h----- C:\Program Files\web_cpr
2008-06-05 23:49:23 224 -r-h----- C:\Program Files\vvsn
2008-06-05 23:49:23 226 -r-h----- C:\Program Files\vvsdl
2008-06-05 23:49:23 226 -r-h----- C:\Program Files\vomba
2008-06-05 23:49:23 238 -r-h----- C:\Program Files\vmntoolbar
2008-06-05 23:49:23 232 -r-h----- C:\Program Files\ts trial
2008-06-05 23:49:23 222 -r-h----- C:\Program Files\hpdll
2008-06-05 23:49:23 232 -r-h----- C:\Program Files\Common Files\winsoftware
2008-06-05 23:49:23 226 -r-h----- C:\Program Files\Common Files\ucontrol
2008-06-05 23:49:23 222 -r-h----- C:\Program Files\autoupdate
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\t2serv.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\t2serv.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\wshtlprh.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\wshnseri.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\winftsap.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\winftsap.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\w3sskbda.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\vsxmpgpc.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\vnetsmme.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\vb5dmspo.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\v4pbpt51.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\trafracp.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\timesrv.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\snmpmssw.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\slbrmqtr.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\slbipsch.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\slbipsch.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\shfoxpob.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\secumsje.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\sd16win.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\scp3jgaw.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\rdpwmsjt.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\rcbdwmpd.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\qdvtscf.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\oebdfc.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\msstersv.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\msnsxole.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\msnsxole.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\mslsicwd.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\msexcred.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\msafiasn.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\messenger.lib.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\hook2.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\hook1.dll
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\google.png.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\game3.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\game2.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\game1.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\system32\adchkr.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\sserrvv.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\serrv.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\reggserv.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\msupdtwiz.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\cserv32.exe
2008-06-05 23:49:22 0 dr-hs---- C:\WINDOWS\ccsserv.exe
2008-06-05 23:49:22 234 -r-h----- C:\temp_kl
2008-06-05 23:49:22 232 -r-h----- C:\Program Files\topmoxie
2008-06-05 23:49:22 244 -r-h----- C:\Program Files\sys detective+
2008-06-05 23:49:22 240 -r-h----- C:\Program Files\surfsidekick
2008-06-05 23:49:22 240 -r-h----- C:\Program Files\surfsidekick 2
2008-06-05 23:49:22 232 -r-h----- C:\Program Files\superbar
2008-06-05 23:49:22 232 -r-h----- C:\Program Files\netmeting
2008-06-05 23:49:22 234 -r-h----- C:\archivos de programa
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\unsocul.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\sodahk.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\socul.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\mqoacdmo.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\mqadscp3.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\mgmtmtxc.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\mcd3mscm.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\lmrtatkc.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\kbdpkbdr.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\kbdfwshe.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\jgsdrpcn.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\jgsdrpcn.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\jgdwadsn.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\jgdwadsn.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\iuennwcf.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\ir32racp.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\ipxwshel.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\ipxrmfc4.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\imesrdch.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\icmpdx3j.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\iaspdpus.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\i4n27vl.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\hhselz32.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\fltlauto.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\fileserv.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\dsseds32.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\dsseds32.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\dpugmswe.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\dnsrxpob.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\deskmcd3.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\ddemdmco.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\davctool.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\davctool.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\confbrw.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\comrkbdd.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\comploader.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\chkmfdep.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\camodpnm.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\brwstat.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\brwprf32.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\brwperf.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\brwmgr32.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\brwconf.exe
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\avifipxr.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\admeiolo.dll
2008-06-05 23:49:21 0 dr-hs---- C:\WINDOWS\system32\actidmoc.exe
2008-06-05 23:49:21 234 -r-h----- C:\spedia
2008-06-05 23:49:21 244 -r-h----- C:\Program Files\swagent
2008-06-05 23:49:21 244 -r-h----- C:\Program Files\stealthwatcher200
2008-06-05 23:49:21 230 -r-h----- C:\Program Files\spytech software
2008-06-05 23:49:21 234 -r-h----- C:\Program Files\spyonthis
2008-06-05 23:49:21 232 -r-h----- C:\Program Files\spyblast
2008-06-05 23:49:21 226 -r-h----- C:\Program Files\p4p
2008-06-05 23:49:21 226 -r-h----- C:\Program Files\Common Files\sogou pxp
2008-06-05 23:49:20 236 -r-h----- C:\WINDOWS\winsecurity
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\waladhpr.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\wzhelper.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\webalize.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\somatic.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\smdnn05.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\servehost.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\seqsb.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\searchupdate33.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\searchupdate31.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\searchsquire33.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\searchsquire3.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\searchsquire2.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\searchsquire.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\seantb.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\s4helper.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\reg2.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\pqhelper.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\mygeek.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\msqsb.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\msplus4.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\msplus3.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\msplus2.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\mslspcg.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\mgeekremove.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\ifsomatic.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\ifhelper.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\iebrw.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\hotlink.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\homepage.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\hmepge.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\gsim.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\system32\barbho.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\svrmgr.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\ssmsgr.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\ssls.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\ssdgt.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\sscrg.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\skynetave.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\napatch.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\gsim.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\cssswd.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\csssupd.exe
2008-06-05 23:49:20 236 -r-h----- C:\WINDOWS\connectionstatus
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\cfg32s.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\cfg32r.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\cfg32o.dll
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\cfg32.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\avserve3.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\avserve2.exe
2008-06-05 23:49:20 0 dr-hs---- C:\WINDOWS\adrsb.exe
2008-06-05 23:49:20 232 -r-h----- C:\Program Files\valintines day card
2008-06-05 23:49:20 234 -r-h----- C:\Program Files\softomate
2008-06-05 23:49:20 248 -r-h----- C:\Program Files\selectrebates
2008-06-05 23:49:20 234 -r-h----- C:\Program Files\searchnet
2008-06-05 23:49:20 240 -r-h----- C:\Program Files\searchlocate
2008-06-05 23:49:20 236 -r-h----- C:\Program Files\screenview
2008-06-05 23:49:20 230 -r-h----- C:\Program Files\savenow
2008-06-05 23:49:20 234 -r-h----- C:\Program Files\rxtoolbar
2008-06-05 23:49:20 234 -r-h----- C:\Program Files\ietoolbar
2008-06-05 23:49:20 230 -r-h----- C:\Program Files\ezthemes_whenusavenow_installer
2008-06-05 23:49:20 242 -r-h----- C:\Program Files\dynamic toolbar
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\wserver.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\winlogon.scr
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\visualguard.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\vlcx052.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\speeder.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\slpube03.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\rlvknlg.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\rkinstaller.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\rk.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\optserve.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\optserve.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\msplus1.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\msplus.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\mrkscr.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\lp.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\lp.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\system32\auole4.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\sysmonxp.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\symav.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\switpb.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\switpa.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\rundil32.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\rundil.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\phantom.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\pandaavengine.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\netmedia.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\msnmsgrs.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\maja.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\lansas.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\kasperskyaveng.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\jammer2nd.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\infodll.dll
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\fooding.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\firewallsvr.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\easyav.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\diskmonitor.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\comp.cpl
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\avprotect9x.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\avprotect.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\avpguard.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\avguard.exe
2008-06-05 23:49:19 0 dr-hs---- C:\WINDOWS\avbgle.exe
2008-06-05 23:49:19 234 -r-h----- C:\Program Files\startup mechanic
2008-06-05 23:49:19 250 -r-h----- C:\Program Files\relevantknowledge
2008-06-05 23:49:19 234 -r-h----- C:\Program Files\rax search helper
2008-06-05 23:49:19 228 -r-h----- C:\Program Files\psupport
2008-06-05 23:49:19 234 -r-h----- C:\Program Files\need2find
2008-06-05 23:49:19 226 -r-h----- C:\Program Files\ncase
2008-06-05 23:49:19 232 -r-h----- C:\Program Files\navexcel
2008-06-05 23:49:19 232 -r-h----- C:\Program Files\navexcel search toolbar
2008-06-05 23:49:19 238 -r-h----- C:\Program Files\mywebsearch
2008-06-05 23:49:19 228 -r-h----- C:\Program Files\exolon
2008-06-05 23:49:19 234 -r-h----- C:\Program Files\ddr
2008-06-05 23:49:19 236 -r-h----- C:\Program Files\Common Files\nsis
2008-06-05 23:49:19 234 -r-h----- C:\Program Files\arcade!
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\xpfirewall.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wpwmgrs.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winvnc.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wintasker.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winsyscfg.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winsys.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winsvc32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winstart.pif
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winnt.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wininfo.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winhlpapi.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wingmt32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\winds.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\windowsfirewall.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\windasz-updote.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\win24.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wid32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wfdmgr.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wfdgmr.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\wdns33.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\w32ntupdt.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\w1nt5k.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\twunk_65.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\timemanager.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\taskgmr32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\taskgamr.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\tagmr.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\sysconf.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\sword.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\stagmr.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\sp2winfix.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\sp2fx.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\skybot.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\shell.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\service5.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\sd.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\scrigz.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\scalpe91.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\protection.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\plugnplay32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\picx.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\phantom.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\netcog.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\mtrnqs.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\mssck.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\msplus32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\msnl.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\msmgrxp.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\msgmr.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\msdev32.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\mouse.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\microupdate.exe
2008-06-05 23:49:18 0 dr-hs---- C:\WINDOWS\system32\memloader.exe
2008-06-05 23:49:17 0 dr-hs---- C:\winssystem.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\unstall.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb60.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb58.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb57.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb56.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb52.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb51.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb42.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb41.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winnb40.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\windmy.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\winats.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\patch31345.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\osalogbe.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\nn_bar31.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\nn_bar22.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\nn_bar21.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\nn_bar.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\myaccess.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\msapasrc.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\msa64chk.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\microsystem.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\mcscn.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\mailinfo.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\logitechwls.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\logic.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lienvdk.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lienvandekelder.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lientjeuh.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lien vd kelder.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lien vande kelder.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lien Van de kelderrr.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lien van de kelder.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\lcd32.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\jusched32.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\itunegui.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\hostdrvxp.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\hbmail.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\gothica.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\fixupdattr.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\evil.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\ds.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\dcomuser.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\coolbot.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\ccsrs.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\avpr.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\abs.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\666.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\1hellbot.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\system32\0.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\patch31345.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\msnarrator.exe
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\mrhop.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\mpgcom.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\iempg2.dll
2008-06-05 23:49:17 0 dr-hs---- C:\WINDOWS\iempg.dll
2008-06-05 23:49:17 236 -r-h----- C:\Program Files\support software
2008-06-05 23:49:17 236 -r-h----- C:\Program Files\network essentials
2008-06-05 23:49:17 236 -r-h----- C:\Program Files\medialoads
2008-06-05 23:49:17 236 -r-h----- C:\Program Files\medialoads enhanced
2008-06-05 23:49:17 0 dr-hs---- C:\hellmsn.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\xwrm.exe
2008-06-05 23:49:16 240 -r-h----- C:\WINDOWS\wintrim
2008-06-05 23:49:16 240 -r-h----- C:\WINDOWS\winmgts
2008-06-05 23:49:16 240 -r-h----- C:\WINDOWS\wincomp
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\vtlbar1.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\version.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\updtscheduler.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\tubby.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\toolbar.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\tbc.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\nas.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\msxml4r.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\msklive.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\mseggrpid.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\msegcompid.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\mscache.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\mapisvc32.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\madise.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\keyhost.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\keyactivex.ocx
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\jeired.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\ia.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\gcasctrl.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\egdial.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\egdhtml_1027.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\egdhtml_1026.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\duel.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\dll.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\aupdate_uninstall.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\aupdate.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\system32\adv.dll
2008-06-05 23:49:16 240 -r-h----- C:\WINDOWS\navpmc
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\mscache.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\mscache.dll
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\mmups.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\mm63.ocx
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\mm21.ocx
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\mm20.ocx
2008-06-05 23:49:16 240 -r-h----- C:\WINDOWS\mc
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\istsvc.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\imgurla.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\exedialer.exe
2008-06-05 23:49:16 0 dr-hs---- C:\WINDOWS\a64sddd.exe
2008-06-05 23:49:16 234 -r-h----- C:\Program Files\powersearch
2008-06-05 23:49:16 234 -r-h----- C:\Program Files\perfectnav
2008-06-05 23:49:16 242 -r-h----- C:\Program Files\media gateway
2008-06-05 23:49:16 232 -r-h----- C:\Program Files\md
2008-06-05 23:49:16 228 -r-h----- C:\Program Files\lstsvc
2008-06-05 23:49:16 244 -r-h----- C:\Program Files\kuaiso toolsbar
2008-06-05 23:49:16 242 -r-h----- C:\Program Files\kgb keylogger
2008-06-05 23:49:16 266 -r-h----- C:\Program Files\invisible secrets toolbar
2008-06-05 23:49:16 240 -r-h----- C:\Program Files\instant buzz
2008-06-05 23:49:16 234 -r-h----- C:\Program Files\incredifind
2008-06-05 23:49:16 228 -r-h----- C:\Program Files\ebayshop
2008-06-05 23:49:16 234 -r-h----- C:\Program Files\Common Files\updmgr
2008-06-05 23:49:16 234 -r-h----- C:\Program Files\Common Files\updater
2008-06-05 23:49:16 234 -r-h----- C:\Program Files\Common Files\keenvalue
2008-06-05 23:49:15 232 -r-h----- C:\WINDOWS\wqzq
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\winobject.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\wdskctl.exe
2008-06-05 23:49:15 232 -r-h----- C:\WINDOWS\wcby
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\ts.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\winstart001.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\winstart.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\winsrm32.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\winenc32.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\windowsie.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\windec32.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\waeb.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\update_rsp.DLL
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\update_removeold.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\update_hosts.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\update_com.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\update_bho.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\sbus.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\rsp001.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\rsp.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\install_all.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\ineb.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr29.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr27.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr26.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr25.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr24.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr23.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr22.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iexplorr11.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\iemsg.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\gws.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\egdhtml_1025.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\egdhtml_1024.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\egdhtml_1023.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\drbr.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\chgrgs.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\bundler_mpb_sb.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\bmeb.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\bho001.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\belop.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\absnro.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\system32\abeb.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\systb.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\systb.dll
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\ssk.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\snbho.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\rgrt.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\pxckdlauninstall.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\pxckdla.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\offerssk.exe
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\invitessk.exe
2008-06-05 23:49:15 230 -r-h----- C:\WINDOWS\ilookup
2008-06-05 23:49:15 0 dr-hs---- C:\WINDOWS\id.exe
2008-06-05 23:49:15 258 -r-h----- C:\Program Files\instant access
2008-06-05 23:49:15 248 -r-h----- C:\Program Files\install provider
2008-06-05 23:49:15 240 -r-h----- C:\Program Files\instafink
2008-06-05 23:49:14 0 dr-hs---- C:\WINDOWS\system32\zopenssl.dll
2008-06-05 23:49:14 0 dr-hs---- C:\WINDOWS\system32\yvsvga.sys
2008-06-05 23:49:14 0 dr-hs---- C:\WINDOWS\system32\yvsvga.dll
2008-06-05 23:49:14 0 dr-hs---- C:\WINDOWS\system32\yvprgb.dll
2008-06-05 23:49:14 0 dr-hs---- C:\WINDOWS\system32\yvpp02.sys
2008-06-05 23:49:14 0 dr-hs--
  • 0

#95
kelkay

kelkay

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 423 posts
I copied and pasted all it had. Am I gonna have to redo this?
  • 0

#96
koko_crunch

koko_crunch

    Trusted Helper

  • Retired Staff
  • 1,751 posts
Nope that will fine.

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
  • 0

#97
kelkay

kelkay

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 423 posts
My downloads all go straight to the C: not to the desktop...I am trying to figure out how to change that.
  • 0

#98
kelkay

kelkay

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 423 posts
Okay I finally go that straight. Downloads now go to the desktop.
  • 0

#99
kelkay

kelkay

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 423 posts
ComboFix 08-06-20.4 - Kelly 2008-06-24 14:28:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.508 [GMT -5:00]
Running from: C:\Documents and Settings\Kelly\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Program Files\2search\
C:\Program Files\ClientMan\
C:\Program Files\Common Files\cpush\
C:\Program Files\Common Files\drivecleaner free\
C:\Program Files\Common Files\KeenValue\
C:\Program Files\Common Files\sogou pxp\
C:\Program Files\Common Files\WinSoftware\
C:\Program Files\CSBB\
C:\Program Files\data19
C:\Program Files\dialers\
C:\Program Files\DriveCleaner Free\
C:\Program Files\HbTools\
C:\Program Files\Hotbar\
C:\Program Files\IEToolbar\
C:\Program Files\install provider\
C:\Program Files\instant access\
C:\Program Files\Instant Buzz\
C:\Program Files\kuaiso toolsbar\
C:\Program Files\MyWebSearch\
C:\Program Files\p4p\
C:\Program Files\PerfectCleaner\
C:\Program Files\Spytech Software\
C:\setup.exe
C:\WINDOWS\mc\
C:\WINDOWS\system32\avload32.dll
C:\WINDOWS\system32\axdebugl.dll
C:\WINDOWS\system32\bt848rom.dll
C:\WINDOWS\system32\ddirectz.dll
C:\WINDOWS\system32\directpt.dll
C:\WINDOWS\system32\directut.dll
C:\WINDOWS\system32\Dll.dll
C:\WINDOWS\system32\docent0.dll
C:\WINDOWS\system32\docent2.dll
C:\WINDOWS\system32\dvd4free.dll
C:\WINDOWS\system32\emldvc.dll
C:\WINDOWS\system32\extfpu.dll
C:\WINDOWS\system32\extxerox.dll
C:\WINDOWS\system32\flashdrvr.dll
C:\WINDOWS\system32\gatexkey.dll
C:\WINDOWS\system32\gdiwxp.dll
C:\WINDOWS\system32\gdwxp3.dll
C:\WINDOWS\system32\hpprintx.dll
C:\WINDOWS\system32\ideusr50.dll
C:\WINDOWS\system32\ies4dll.dll
C:\WINDOWS\system32\iesdl4l.dll
C:\WINDOWS\system32\logon16x.dll
C:\WINDOWS\system32\lsd_f3.dll
C:\WINDOWS\system32\mcfCC4.dll
C:\WINDOWS\system32\mcfG7A.dll
C:\WINDOWS\system32\mdfpro.dll
C:\WINDOWS\system32\mmxeroxk.dll
C:\WINDOWS\system32\MSplg7.dll
C:\WINDOWS\system32\nclabydll.dll
C:\WINDOWS\system32\nkunpack.dll
C:\WINDOWS\system32\obbn13t.dll
C:\WINDOWS\system32\openglss.dll
C:\WINDOWS\system32\printpnp.dll
C:\WINDOWS\system32\prw76sks.sys
C:\WINDOWS\system32\prwsks.dll
C:\WINDOWS\system32\psksds.dll
C:\WINDOWS\system32\rdrVR2.dll
C:\WINDOWS\system32\rsdapi.dll
C:\WINDOWS\system32\satau320.dll
C:\WINDOWS\system32\satdll.dll
C:\WINDOWS\system32\satmmc.dll
C:\WINDOWS\system32\sdcard98.dll
C:\WINDOWS\system32\se500mdm.dll
C:\WINDOWS\system32\se633mxx.dll
C:\WINDOWS\system32\sks2drvr.sys
C:\WINDOWS\system32\sksdll.dll
C:\WINDOWS\system32\tcpG4T.dll
C:\WINDOWS\system32\tcpGDC.dll
C:\WINDOWS\system32\tcpwrk.dll
C:\WINDOWS\system32\wndtx1.dll
C:\WINDOWS\system32\xcdmfree.dll
C:\WINDOWS\system32\zopenssl.dll
C:\WINDOWS\wincomp\
C:\WINDOWS\winmgts\
C:\WINDOWS\wintrim\
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-05-24 to 2008-06-24 )))))))))))))))))))))))))))))))
.

2008-06-23 21:55 . 2008-06-23 21:57 <DIR> d-------- C:\SmitfraudFix
2008-06-23 20:48 . 2008-06-23 20:48 <DIR> d-------- C:\_OTMoveIt
2008-06-23 20:42 . 2008-06-23 20:41 291,328 --a------ C:\OTMoveIt2.exe
2008-06-23 17:52 . 2008-06-23 17:52 1,477,906 --a------ C:\SmitfraudFix.exe
2008-06-23 17:06 . 2008-06-23 17:06 <DIR> d-------- C:\WINDOWS\ERUNT
2008-06-23 17:00 . 2008-06-23 21:43 <DIR> d-------- C:\SDFix
2008-06-23 14:20 . 2008-06-23 14:20 1,441,875 --a------ C:\SDFix.exe
2008-06-22 19:09 . 2008-06-22 19:09 39,060 --a------ C:\fullross.jpg
2008-06-16 22:26 . 2008-06-16 22:26 <DIR> d-------- C:\Deckard
2008-06-16 15:42 . 2008-06-23 21:55 3,322 --a------ C:\WINDOWS\system32\tmp.reg
2008-06-16 15:01 . 2008-06-16 15:01 2,869,536 --a------ C:\spywareblastersetup41.exe
2008-06-15 21:31 . 2008-06-15 21:31 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-06-15 21:31 . 2008-06-15 21:31 <DIR> d-------- C:\Documents and Settings\Kelly\Application Data\SUPERAntiSpyware.com
2008-06-15 21:31 . 2008-06-15 21:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-12 15:35 . 2008-06-12 15:36 <DIR> d-------- C:\Program Files\iTunes
2008-06-12 15:35 . 2008-06-12 15:35 <DIR> d-------- C:\Program Files\iPod
2008-06-12 15:34 . 2008-06-12 15:34 <DIR> d-------- C:\Program Files\QuickTime
2008-06-12 15:32 . 2008-06-12 15:32 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-06-12 15:31 . 2008-06-12 15:31 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-06-12 15:29 . 2008-06-12 15:29 <DIR> d-------- C:\Program Files\Apple Software Update
2008-06-12 15:29 . 2008-06-12 15:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-06-11 07:04 . 2008-06-13 08:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 07:04 . 2008-06-13 08:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-06 17:04 . 1999-12-21 07:58 21,312 --a------ C:\WINDOWS\choice.exe
2008-06-06 16:59 . 2008-06-06 16:59 <DIR> d-------- C:\old
2008-06-06 16:59 . 2008-06-06 16:59 <DIR> d-------- C:\ie-spyad
2008-06-06 16:59 . 2008-06-06 16:59 <DIR> d-------- C:\choice
2008-06-06 16:59 . 2008-06-06 16:59 <DIR> d-------- C:\adult
2008-06-06 08:57 . 2008-06-06 08:57 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-06-06 08:54 . 2008-06-06 08:55 23,454,528 --a------ C:\AdbeRdr812_en_US.exe
2008-06-05 23:49 . 2008-06-05 23:49 242 -r-h----- C:\Program Files\vcom
2008-06-05 23:49 . 2008-06-05 23:49 242 -r-h----- C:\Program Files\scom
2008-06-05 23:49 . 2008-06-05 23:49 222 -r-h----- C:\Program Files\hpdll
2008-06-05 23:32 . 2008-06-15 21:19 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-05 23:32 . 2008-06-05 23:32 <DIR> d-------- C:\Documents and Settings\Kelly\Application Data\Malwarebytes
2008-06-05 23:32 . 2008-06-05 23:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-05 23:32 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-05 23:32 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-05 23:30 . 2008-06-05 23:30 1,756,760 --a------ C:\mbam-setup.exe
2008-06-04 20:57 . 2008-06-04 21:10 <DIR> d-------- C:\Program Files\Navilog1
2008-06-04 19:37 . 2008-06-04 19:37 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-04 19:25 . 2008-06-04 19:25 <DIR> d-------- C:\Program Files\7-Zip
2008-06-04 14:37 . 2008-06-04 14:37 <DIR> d-------- C:\Documents and Settings\Kelly\log
2008-06-04 14:37 . 2008-06-04 14:37 142,096 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-05-27 10:50 . 2008-05-27 10:50 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-05-27 10:50 . 2008-05-27 10:50 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-24 19:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-06-24 19:33 --------- d-----w C:\Program Files\DrWeb
2008-06-22 14:42 --------- d-----w C:\Program Files\SpywareBlaster
2008-06-19 14:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-16 23:42 --------- d-----w C:\Program Files\SpywareGuard
2008-06-16 20:05 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-16 19:02 --------- d-----w C:\Documents and Settings\Kelly\Application Data\OpenOffice.org2
2008-06-16 02:29 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-12 20:36 --------- d-----w C:\Documents and Settings\Kelly\Application Data\Apple Computer
2008-06-12 20:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-08 02:52 --------- d-----w C:\Program Files\Malware Immunizer
2008-06-08 00:14 --------- d-----w C:\Program Files\HP
2008-06-07 16:57 --------- d-----w C:\Program Files\MySpace
2008-06-06 13:53 --------- d-----w C:\Program Files\Java
2008-06-06 04:28 --------- d-----w C:\Program Files\WinUpdatesList
2008-06-03 15:48 --------- d-----w C:\Program Files\Shockwave.com
2008-05-29 04:22 --------- d-----w C:\Documents and Settings\Kelly\Application Data\AdobeUM
2008-05-28 19:39 --------- d-----w C:\Program Files\MTV Virtual World
2008-05-25 04:38 16,420 ----a-w C:\Documents and Settings\Kelly\Application Data\wklnhst.dat
2008-05-23 05:43 --------- d-----w C:\Documents and Settings\Kelly\Application Data\PlayFirst
2008-05-23 05:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-05-23 05:40 --------- d-----w C:\Program Files\Yahoo!
2008-05-21 14:39 --------- d-----w C:\Program Files\Napster
2008-05-21 14:38 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-05-21 14:38 --------- d-----w C:\Program Files\Common Files\Napster Shared
2008-05-08 12:28 202,752 ------w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-30 17:04 --------- d-----w C:\Documents and Settings\Kelly\Application Data\Yahoo!
2008-04-27 18:57 --------- d-----w C:\Documents and Settings\Kelly\Application Data\MySpace
2008-03-28 15:52 118,784 ----a-w C:\WINDOWS\SeaMonkeyUninstall.exe
2008-03-28 15:51 118,784 ----a-w C:\WINDOWS\GREUninstall.exe
2007-12-17 15:57 1,646 ----a-w C:\Documents and Settings\Kayla\Application Data\wklnhst.dat
2007-10-10 00:49 251 ----a-w C:\Program Files\wt3d.ini
2006-11-28 05:00 22 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 14:39 1289000]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmartDefrag"="C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2006-11-20 23:59 3920384]
"SpIDerNT"="C:\PROGRA~1\DrWeb\spiderui.exe" [2008-03-31 08:33 230936]
"SpIDerMail"="C:\Program Files\DrWeb\spiderml.exe" [2008-06-10 07:16 501080]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-09 17:50 7311360]
"Motive SmartBridge"="C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 08:51 442455]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-13 23:11 919016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 14:39 1289000]

C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-07-31 20:44:35 27136]
PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-07-31 20:44:35 27136]

C:\Documents and Settings\Kayla\Start Menu\Programs\Startup\
PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-07-31 20:44:35 27136]

C:\Documents and Settings\Kelly\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 20:05:35 360448]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AT&T Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2007-12-29 11:47:19 217088]
PI Monitor.lnk - C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe [2007-04-05 09:48:34 86016]
Updates From HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2006-07-31 21:36:54 36903]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP54"= SP5X_32.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates From HP.lnk]
backup=C:\WINDOWS\pss\Updates From HP.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlwaysReady Power Message APP]
--------- 2005-08-03 01:19 77312 C:\WINDOWS\arpwrmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
--------- 2006-11-23 17:12 851968 C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-11-13 14:39 1289000 C:\PROGRA~1\MICROS~2\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPBootOp]
--a------ 2006-02-16 00:34 249856 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
--a------ 2006-11-28 12:47 1040832 C:\Program Files\Kontiki\KHost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-05-09 17:50 7311360 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PwrUpTweakMe]
--a------ 2005-09-12 11:36 45056 C:\WINDOWS\system32\PuXpTwks.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
--a------ 2005-07-23 00:14 237568 C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-03-11 19:47 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Symantec Core LC"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SAVScan"=3 (0x3)
"NSCService"=3 (0x3)
"ccSetMgr"=2 (0x2)
"ccProxy"=2 (0x2)
"ccISPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1164757353\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"C:\\Program Files\\America Online 9.0a\\waol.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"C:\\Program Files\\kontiki\\KService.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20566:TCP"= 20566:TCP:BitComet 20566 TCP
"20566:UDP"= 20566:UDP:BitComet 20566 UDP
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R2 SPIDER;SpIDer FS Monitor for Windows NT;C:\PROGRA~1\DrWeb\spider.sys [2008-03-31 08:33]
R2 spidernt;SpIDer Guard for Windows NT;C:\PROGRA~1\DrWeb\SpiderNT.exe [2008-03-31 08:33]
R3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 00:01]
S3 MEMSWEEP2;MEMSWEEP2;C:\WINDOWS\system32\3.tmp []

.
Contents of the 'Scheduled Tasks' folder
"2008-06-13 20:40:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-24 19:37:30 C:\WINDOWS\Tasks\SmartDefrag.job"
- C:\Program Files\IObit\IObit SmartDefrag\schedule.exeA
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-24 14:36:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
"ImagePath"="\??\C:\WINDOWS\system32\3.tmp"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-06-24 14:43:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-24 19:43:19

Pre-Run: 136,998,129,664 bytes free
Post-Run: 136,964,665,344 bytes free

339 --- E O F --- 2008-06-20 12:59:34
  • 0

#100
kelkay

kelkay

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 423 posts
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:55:57, on 6/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe
C:\PROGRA~1\DrWeb\SpiderNT.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\PROGRA~1\DrWeb\spiderui.exe
C:\Program Files\DrWeb\spiderml.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\mozilla.org\SeaMonkey\seamonkey.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O3 - Toolbar: WebFerret - {A58686ED-FC46-44C3-95C6-4A812AB776F1} - C:\Program Files\FerretSoft\WebFerret\FerretBand.dll
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /startup
O4 - HKLM\..\Run: [SpIDerNT] C:\PROGRA~1\DrWeb\spiderui.exe /agent
O4 - HKLM\..\Run: [SpIDerMail] "C:\Program Files\DrWeb\spiderml.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKUS\S-1-5-18\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (User 'Default user')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - S-1-5-18 Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\system32\wweb32.dll/lookup.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....030/CTSUEng.cab
O16 - DPF: {127CE7BA-AD89-4108-A913-C52EFC037C36} (OMN Player Support) - http://kdx.omn.org/s...ayerSupport.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewid...oOnlineScan.cab
O16 - DPF: {2776DDE9-D4B2-4BF7-9F98-ADC1A1B80AF5} (OMN Media Publisher) - http://kdx.omn.org/s...iaPublisher.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.shockwave...h2.1.0.0.67.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1165348971449
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -
O16 - DPF: {A7ECD556-D6F6-4F41-8C6B-14AB246801A0} (Secure Delivery) - http://kdx.omn.org/s...ery/omn/kdx.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15030/CTPID.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sansa Updater Service (SansaService) - Unknown owner - C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe
O23 - Service: SpIDer Guard for Windows NT (spidernt) - Doctor Web, Ltd. - C:\PROGRA~1\DrWeb\SpiderNT.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 10829 bytes
  • 0

Advertisements


#101
kelkay

kelkay

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 423 posts
Zone Alarm did a scan and said I have two trojans. Kazaa lite goop 28, and P2P-worm.win32...
It recommends quarantine.


RegistryKey: HKEY_CURRENT_USER\Software\Kazaa
Directory: C:\WINDOWS\Downloaded Installations

RegistryKey: HKEY_CURRENT_USER\Software\Kazaa\LocalContent

I was afraid if I did quarantine them they would be harder to get rid of...unless they were a false positive. I never heard of that program.
  • 0

#102
koko_crunch

koko_crunch

    Trusted Helper

  • Retired Staff
  • 1,751 posts
I think that is a false postive same as earlier with yahoo.

Win32.trojan.yspy
File: C:\Program Files\Yahoo!\Messenger\yacscom.dll
GUID: {2B323CD9-50E3-11D3-9466-00A0C9700498}
RegistryKey:

Link: http://www.betanews....gain/1213210185

Kazaa is a p2p program bundled with a bunch of malware. On the otherhand, Kazaa Lite is a modified version of Kazaa that's free of malware.

Link: http://en.wikipedia.org/wiki/Kazaa

The C:\WINDOWS\Downloaded Installations is a folder containing installation files of downloaded programs. It's legit so I wouldn't quarantine that.

Funny thing is, Zonealarm detected those false postives and not the actual malware installed on your system.
With these numbers, I would have wished Zonealarm perform better. It would be nicer if it detected at least one identifiable malware, don't you agree?

No worries, I'll do my best to clean up your system.
Your latest log reveals that it's much cleaner.
Let's double check.

Please read this post completely before proceeding with the fix.

Next,

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\WINDOWS\winupie.exe
    C:\WINDOWS\winmuschi.exe
    C:\WINDOWS\updatewinlocator.exe
    C:\WINDOWS\system32\zp.dll
    C:\WINDOWS\system32\zeropopupbar.dll
    C:\WINDOWS\system32\winwsl.exe
    C:\WINDOWS\system32\wintft.dll
    C:\WINDOWS\system32\wintbpx.exe
    C:\WINDOWS\system32\wintbp.exe
    C:\WINDOWS\system32\winshow.dll
    C:\WINDOWS\system32\winsb.dll
    C:\WINDOWS\system32\winrvl.exe
    C:\WINDOWS\system32\winpup32.exe
    C:\WINDOWS\system32\winpup.exe
    C:\WINDOWS\system32\winlocatorhelper.dll
    C:\WINDOWS\system32\winlocator.dll
    C:\WINDOWS\system32\winksl.exe
    C:\WINDOWS\system32\systemout.exe
    C:\WINDOWS\system32\sysdll32.dll
    C:\WINDOWS\system32\servises.exe
    C:\WINDOWS\system32\pup.exe
    C:\WINDOWS\system32\pnp.exe
    C:\WINDOWS\system32\per.exe
    C:\WINDOWS\system32\norton update.exe
    C:\WINDOWS\system32\[bleep].exe
    C:\WINDOWS\system32\df_kme.exe
    C:\WINDOWS\system32\csm.exe
    C:\WINDOWS\system32\botzor.exe
    C:\WINDOWS\system32\axconfig.dll
    C:\WINDOWS\system32\4ccc3cea.exe
    C:\WINDOWS\pnpasn32.exe
    C:\WINDOWS\hpsv.exe
    C:\WINDOWS\cdproxyserv.exe
    C:\Program Files\zsearch
    C:\Program Files\zeropopupbar
    C:\Program Files\zangoclient
    C:\Program Files\zango games
    C:\Program Files\xsoftware
    C:\Program Files\xpcspy
    C:\Program Files\winfixer 2005
    C:\WINDOWS\windowsupd4.exe
    C:\WINDOWS\windowsupd2.exe
    C:\WINDOWS\windowsupd1.exe
    C:\WINDOWS\vx2.dll
    C:\WINDOWS\system32\winntcreate.exe
    C:\WINDOWS\system32\vx2.dll
    C:\WINDOWS\system32\vwix32.exe
    C:\WINDOWS\system32\uninmyad.exe
    C:\WINDOWS\system32\tps108.dll
    C:\WINDOWS\system32\tisa.dll
    C:\WINDOWS\system32\tips.exe
    C:\WINDOWS\system32\tippcls.dat
    C:\WINDOWS\system32\tipp.dat
    C:\WINDOWS\system32\ticont.dll
    C:\WINDOWS\system32\ticads.exe
    C:\WINDOWS\system32\tconini.dat
    C:\WINDOWS\system32\sysmonnt.exe
    C:\WINDOWS\system32\spwgoc.exe
    C:\WINDOWS\system32\rvreg.exe
    C:\WINDOWS\system32\rulesak.dll
    C:\WINDOWS\system32\myad.dll
    C:\WINDOWS\system32\msview.dll
    C:\WINDOWS\system32\msnavc32.exe
    C:\WINDOWS\system32\lut.dat
    C:\WINDOWS\system32\lspak.dll
    C:\WINDOWS\system32\localnrd.dll
    C:\WINDOWS\system32\lcch.dat
    C:\WINDOWS\system32\ladchkr.exe
    C:\WINDOWS\system32\host.dll
    C:\WINDOWS\system32\gdu.dll
    C:\WINDOWS\system32\dad.bat
    C:\WINDOWS\system32\cidrules.dll
    C:\WINDOWS\system32\6fo4svc.dll
    C:\WINDOWS\psapi.dll
    C:\WINDOWS\kernellos.dll
    C:\WINDOWS\isrvs
    C:\WINDOWS\iehelper.dll
    C:\WINDOWS\cleanhistories.dll
    C:\Program Files\winfavorites
    C:\Program Files\windows adtools
    C:\Program Files\windows adcontrol
    C:\Program Files\win comm
    C:\Program Files\whenu
    C:\Program Files\web_rebates
    C:\Program Files\web_cpr
    C:\Program Files\vvsn
    C:\Program Files\vvsdl
    C:\Program Files\vomba
    C:\Program Files\vmntoolbar
    C:\Program Files\ts trial
    C:\Program Files\hpdll
    C:\Program Files\Common Files\winsoftware
    C:\Program Files\Common Files\ucontrol
    C:\Program Files\autoupdate
    C:\WINDOWS\t2serv.exe
    C:\WINDOWS\t2serv.dll
    C:\WINDOWS\system32\wshtlprh.dll
    C:\WINDOWS\system32\wshnseri.exe
    C:\WINDOWS\system32\winftsap.exe
    C:\WINDOWS\system32\winftsap.dll
    C:\WINDOWS\system32\w3sskbda.dll
    C:\WINDOWS\system32\vsxmpgpc.dll
    C:\WINDOWS\system32\vnetsmme.dll
    C:\WINDOWS\system32\vb5dmspo.dll
    C:\WINDOWS\system32\v4pbpt51.dll
    C:\WINDOWS\system32\trafracp.dll
    C:\WINDOWS\system32\timesrv.exe
    C:\WINDOWS\system32\snmpmssw.exe
    C:\WINDOWS\system32\slbrmqtr.exe
    C:\WINDOWS\system32\slbipsch.exe
    C:\WINDOWS\system32\slbipsch.dll
    C:\WINDOWS\system32\shfoxpob.exe
    C:\WINDOWS\system32\secumsje.exe
    C:\WINDOWS\system32\sd16win.dll
    C:\WINDOWS\system32\scp3jgaw.dll
    C:\WINDOWS\system32\rdpwmsjt.exe
    C:\WINDOWS\system32\rcbdwmpd.dll
    C:\WINDOWS\system32\qdvtscf.dll
    C:\WINDOWS\system32\oebdfc.dll
    C:\WINDOWS\system32\msstersv.dll
    C:\WINDOWS\system32\msnsxole.exe
    C:\WINDOWS\system32\msnsxole.dll
    C:\WINDOWS\system32\mslsicwd.dll
    C:\WINDOWS\system32\msexcred.exe
    C:\WINDOWS\system32\msafiasn.dll
    C:\WINDOWS\system32\messenger.lib.exe
    C:\WINDOWS\system32\hook2.dll
    C:\WINDOWS\system32\hook1.dll
    C:\WINDOWS\system32\google.png.exe
    C:\WINDOWS\system32\game3.exe
    C:\WINDOWS\system32\game2.exe
    C:\WINDOWS\system32\game1.exe
    C:\WINDOWS\system32\adchkr.exe
    C:\WINDOWS\sserrvv.exe
    C:\WINDOWS\serrv.exe
    C:\WINDOWS\reggserv.exe
    C:\WINDOWS\msupdtwiz.exe
    C:\WINDOWS\cserv32.exe
    C:\WINDOWS\ccsserv.exe
    C:\temp_kl
    C:\Program Files\topmoxie
    C:\Program Files\sys detective+
    C:\Program Files\surfsidekick
    C:\Program Files\surfsidekick 2
    C:\Program Files\superbar
    C:\Program Files\netmeting
    C:\archivos de programa
    C:\WINDOWS\system32\unsocul.exe
    C:\WINDOWS\system32\sodahk.dll
    C:\WINDOWS\system32\socul.dll
    C:\WINDOWS\system32\mqoacdmo.dll
    C:\WINDOWS\system32\mqadscp3.exe
    C:\WINDOWS\system32\mgmtmtxc.exe
    C:\WINDOWS\system32\mcd3mscm.dll
    C:\WINDOWS\system32\lmrtatkc.dll
    C:\WINDOWS\system32\kbdpkbdr.exe
    C:\WINDOWS\system32\kbdfwshe.exe
    C:\WINDOWS\system32\jgsdrpcn.exe
    C:\WINDOWS\system32\jgsdrpcn.dll
    C:\WINDOWS\system32\jgdwadsn.exe
    C:\WINDOWS\system32\jgdwadsn.dll
    C:\WINDOWS\system32\iuennwcf.dll
    C:\WINDOWS\system32\ir32racp.exe
    C:\WINDOWS\system32\ipxwshel.exe
    C:\WINDOWS\system32\ipxrmfc4.dll
    C:\WINDOWS\system32\imesrdch.exe
    C:\WINDOWS\system32\icmpdx3j.dll
    C:\WINDOWS\system32\iaspdpus.dll
    C:\WINDOWS\system32\i4n27vl.exe
    C:\WINDOWS\system32\hhselz32.dll
    C:\WINDOWS\system32\fltlauto.exe
    C:\WINDOWS\system32\fileserv.dll
    C:\WINDOWS\system32\dsseds32.exe
    C:\WINDOWS\system32\dsseds32.dll
    C:\WINDOWS\system32\dpugmswe.dll
    C:\WINDOWS\system32\dnsrxpob.exe
    C:\WINDOWS\system32\deskmcd3.dll
    C:\WINDOWS\system32\ddemdmco.dll
    C:\WINDOWS\system32\davctool.exe
    C:\WINDOWS\system32\davctool.dll
    C:\WINDOWS\system32\confbrw.dll
    C:\WINDOWS\system32\comrkbdd.exe
    C:\WINDOWS\system32\comploader.dll
    C:\WINDOWS\system32\chkmfdep.exe
    C:\WINDOWS\system32\camodpnm.exe
    C:\WINDOWS\system32\brwstat.dll
    C:\WINDOWS\system32\brwprf32.dll
    C:\WINDOWS\system32\brwperf.exe
    C:\WINDOWS\system32\brwmgr32.dll
    C:\WINDOWS\system32\brwconf.exe
    C:\WINDOWS\system32\avifipxr.dll
    C:\WINDOWS\system32\admeiolo.dll
    C:\WINDOWS\system32\actidmoc.exe
    C:\spedia
    C:\Program Files\swagent
    C:\Program Files\stealthwatcher200
    C:\Program Files\spytech software
    C:\Program Files\spyonthis
    C:\Program Files\spyblast
    C:\Program Files\p4p
    C:\Program Files\Common Files\sogou pxp
    C:\WINDOWS\winsecurity
    C:\WINDOWS\waladhpr.exe
    C:\WINDOWS\system32\wzhelper.dll
    C:\WINDOWS\system32\webalize.dll
    C:\WINDOWS\system32\somatic.dll
    C:\WINDOWS\system32\smdnn05.dll
    C:\WINDOWS\system32\servehost.exe
    C:\WINDOWS\system32\seqsb.dll
    C:\WINDOWS\system32\searchupdate33.exe
    C:\WINDOWS\system32\searchupdate31.exe
    C:\WINDOWS\system32\searchsquire33.dll
    C:\WINDOWS\system32\searchsquire3.dll
    C:\WINDOWS\system32\searchsquire2.dll
    C:\WINDOWS\system32\searchsquire.dll
    C:\WINDOWS\system32\seantb.dll
    C:\WINDOWS\system32\s4helper.dll
    C:\WINDOWS\system32\reg2.exe
    C:\WINDOWS\system32\pqhelper.dll
    C:\WINDOWS\system32\mygeek.dll
    C:\WINDOWS\system32\msqsb.dll
    C:\WINDOWS\system32\msplus4.dll
    C:\WINDOWS\system32\msplus3.dll
    C:\WINDOWS\system32\msplus2.dll
    C:\WINDOWS\system32\mslspcg.exe
    C:\WINDOWS\system32\mgeekremove.exe
    C:\WINDOWS\system32\ifsomatic.dll
    C:\WINDOWS\system32\ifhelper.dll
    C:\WINDOWS\system32\iebrw.dll
    C:\WINDOWS\system32\hotlink.dll
    C:\WINDOWS\system32\homepage.dll
    C:\WINDOWS\system32\hmepge.dll
    C:\WINDOWS\system32\gsim.dll
    C:\WINDOWS\system32\barbho.dll
    C:\WINDOWS\svrmgr.exe
    C:\WINDOWS\ssmsgr.exe
    C:\WINDOWS\ssls.exe
    C:\WINDOWS\ssdgt.exe
    C:\WINDOWS\sscrg.exe
    C:\WINDOWS\skynetave.exe
    C:\WINDOWS\napatch.exe
    C:\WINDOWS\gsim.dll
    C:\WINDOWS\cssswd.exe
    C:\WINDOWS\csssupd.exe
    C:\WINDOWS\connectionstatus
    C:\WINDOWS\cfg32s.dll
    C:\WINDOWS\cfg32r.dll
    C:\WINDOWS\cfg32o.dll
    C:\WINDOWS\cfg32.exe
    C:\WINDOWS\avserve3.exe
    C:\WINDOWS\avserve2.exe
    C:\WINDOWS\adrsb.exe
    C:\Program Files\valintines day card
    C:\Program Files\softomate
    C:\Program Files\selectrebates
    C:\Program Files\searchnet
    C:\Program Files\searchlocate
    C:\Program Files\screenview
    C:\Program Files\savenow
    C:\Program Files\rxtoolbar
    C:\Program Files\ietoolbar
    C:\Program Files\ezthemes_whenusavenow_installer
    C:\Program Files\dynamic toolbar
    C:\WINDOWS\wserver.exe
    C:\WINDOWS\winlogon.scr
    C:\WINDOWS\visualguard.exe
    C:\WINDOWS\system32\vlcx052.dll
    C:\WINDOWS\system32\speeder.exe
    C:\WINDOWS\system32\slpube03.dll
    C:\WINDOWS\system32\rlvknlg.exe
    C:\WINDOWS\system32\rkinstaller.exe
    C:\WINDOWS\system32\rk.exe
    C:\WINDOWS\system32\optserve.exe
    C:\WINDOWS\system32\optserve.dll
    C:\WINDOWS\system32\msplus1.dll
    C:\WINDOWS\system32\msplus.dll
    C:\WINDOWS\system32\mrkscr.exe
    C:\WINDOWS\system32\lp.exe
    C:\WINDOWS\system32\lp.dll
    C:\WINDOWS\system32\auole4.dll
    C:\WINDOWS\sysmonxp.exe
    C:\WINDOWS\symav.exe
    C:\WINDOWS\switpb.exe
    C:\WINDOWS\switpa.exe
    C:\WINDOWS\rundil32.exe
    C:\WINDOWS\rundil.exe
    C:\WINDOWS\phantom.exe
    C:\WINDOWS\pandaavengine.exe
    C:\WINDOWS\netmedia.exe
    C:\WINDOWS\msnmsgrs.exe
    C:\WINDOWS\maja.exe
    C:\WINDOWS\lansas.exe
    C:\WINDOWS\kasperskyaveng.exe
    C:\WINDOWS\jammer2nd.exe
    C:\WINDOWS\infodll.dll
    C:\WINDOWS\fooding.exe
    C:\WINDOWS\firewallsvr.exe
    C:\WINDOWS\easyav.exe
    C:\WINDOWS\diskmonitor.exe
    C:\WINDOWS\comp.cpl
    C:\WINDOWS\avprotect9x.exe
    C:\WINDOWS\avprotect.exe
    C:\WINDOWS\avpguard.exe
    C:\WINDOWS\avguard.exe
    C:\WINDOWS\avbgle.exe
    C:\Program Files\startup mechanic
    C:\Program Files\relevantknowledge
    C:\Program Files\rax search helper
    C:\Program Files\psupport
    C:\Program Files\need2find
    C:\Program Files\ncase
    C:\Program Files\navexcel
    C:\Program Files\navexcel search toolbar
    C:\Program Files\mywebsearch
    C:\Program Files\exolon
    C:\Program Files\ddr
    C:\Program Files\Common Files\nsis
    C:\Program Files\arcade!
    C:\WINDOWS\system32\xpfirewall.exe
    C:\WINDOWS\system32\wpwmgrs.exe
    C:\WINDOWS\system32\winvnc.exe
    C:\WINDOWS\system32\wintasker.exe
    C:\WINDOWS\system32\winsyscfg.exe
    C:\WINDOWS\system32\winsys.exe
    C:\WINDOWS\system32\winsvc32.exe
    C:\WINDOWS\system32\winstart.pif
    C:\WINDOWS\system32\winnt.exe
    C:\WINDOWS\system32\wininfo.exe
    C:\WINDOWS\system32\winhlpapi.exe
    C:\WINDOWS\system32\wingmt32.exe
    C:\WINDOWS\system32\winds.exe
    C:\WINDOWS\system32\windowsfirewall.exe
    C:\WINDOWS\system32\windasz-updote.exe
    C:\WINDOWS\system32\win24.exe
    C:\WINDOWS\system32\wid32.exe
    C:\WINDOWS\system32\wfdmgr.exe
    C:\WINDOWS\system32\wfdgmr.exe
    C:\WINDOWS\system32\wdns33.exe
    C:\WINDOWS\system32\w32ntupdt.exe
    C:\WINDOWS\system32\w1nt5k.exe
    C:\WINDOWS\system32\twunk_65.exe
    C:\WINDOWS\system32\timemanager.exe
    C:\WINDOWS\system32\taskgmr32.exe
    C:\WINDOWS\system32\taskgamr.exe
    C:\WINDOWS\system32\tagmr.exe
    C:\WINDOWS\system32\sysconf.exe
    C:\WINDOWS\system32\sword.exe
    C:\WINDOWS\system32\stagmr.exe
    C:\WINDOWS\system32\sp2winfix.exe
    C:\WINDOWS\system32\sp2fx.exe
    C:\WINDOWS\system32\skybot.exe
    C:\WINDOWS\system32\shell.exe
    C:\WINDOWS\system32\service5.exe
    C:\WINDOWS\system32\sd.exe
    C:\WINDOWS\system32\scrigz.exe
    C:\WINDOWS\system32\scalpe91.exe
    C:\WINDOWS\system32\protection.exe
    C:\WINDOWS\system32\plugnplay32.exe
    C:\WINDOWS\system32\picx.exe
    C:\WINDOWS\system32\phantom.exe
    C:\WINDOWS\system32\netcog.exe
    C:\WINDOWS\system32\mtrnqs.exe
    C:\WINDOWS\system32\mssck.exe
    C:\WINDOWS\system32\msplus32.exe
    C:\WINDOWS\system32\msnl.exe
    C:\WINDOWS\system32\msmgrxp.exe
    C:\WINDOWS\system32\msgmr.exe
    C:\WINDOWS\system32\msdev32.exe
    C:\WINDOWS\system32\mouse.exe
    C:\WINDOWS\system32\microupdate.exe
    C:\WINDOWS\system32\memloader.exe
    C:\winssystem.exe
    C:\WINDOWS\unstall.exe
    C:\WINDOWS\system32\winnb60.dll
    C:\WINDOWS\system32\winnb58.dll
    C:\WINDOWS\system32\winnb57.dll
    C:\WINDOWS\system32\winnb56.dll
    C:\WINDOWS\system32\winnb52.dll
    C:\WINDOWS\system32\winnb51.dll
    C:\WINDOWS\system32\winnb42.dll
    C:\WINDOWS\system32\winnb41.dll
    C:\WINDOWS\system32\winnb40.dll
    C:\WINDOWS\system32\windmy.dll
    C:\WINDOWS\system32\winats.dll
    C:\WINDOWS\system32\patch31345.exe
    C:\WINDOWS\system32\osalogbe.exe
    C:\WINDOWS\system32\nn_bar31.dll
    C:\WINDOWS\system32\nn_bar22.dll
    C:\WINDOWS\system32\nn_bar21.dll
    C:\WINDOWS\system32\nn_bar.dll
    C:\WINDOWS\system32\myaccess.dll
    C:\WINDOWS\system32\msapasrc.dll
    C:\WINDOWS\system32\msa64chk.dll
    C:\WINDOWS\system32\microsystem.exe
    C:\WINDOWS\system32\mcscn.exe
    C:\WINDOWS\system32\mailinfo.exe
    C:\WINDOWS\system32\logitechwls.exe
    C:\WINDOWS\system32\logic.exe
    C:\WINDOWS\system32\lienvdk.exe
    C:\WINDOWS\system32\lienvandekelder.exe
    C:\WINDOWS\system32\lientjeuh.exe
    C:\WINDOWS\system32\lien vd kelder.exe
    C:\WINDOWS\system32\lien vande kelder.exe
    C:\WINDOWS\system32\lien Van de kelderrr.exe
    C:\WINDOWS\system32\lien van de kelder.exe
    C:\WINDOWS\system32\lcd32.exe
    C:\WINDOWS\system32\jusched32.exe
    C:\WINDOWS\system32\itunegui.exe
    C:\WINDOWS\system32\hostdrvxp.exe
    C:\WINDOWS\system32\hbmail.exe
    C:\WINDOWS\system32\gothica.exe
    C:\WINDOWS\system32\fixupdattr.exe
    C:\WINDOWS\system32\evil.exe
    C:\WINDOWS\system32\ds.exe
    C:\WINDOWS\system32\dcomuser.exe
    C:\WINDOWS\system32\coolbot.exe
    C:\WINDOWS\system32\ccsrs.exe
    C:\WINDOWS\system32\avpr.exe
    C:\WINDOWS\system32\abs.exe
    C:\WINDOWS\system32\666.exe
    C:\WINDOWS\system32\1hellbot.exe
    C:\WINDOWS\system32\0.exe
    C:\WINDOWS\patch31345.exe
    C:\WINDOWS\msnarrator.exe
    C:\WINDOWS\mrhop.dll
    C:\WINDOWS\mpgcom.dll
    C:\WINDOWS\iempg2.dll
    C:\WINDOWS\iempg.dll
    C:\Program Files\support software
    C:\Program Files\network essentials
    C:\Program Files\medialoads
    C:\Program Files\medialoads enhanced
    C:\hellmsn.exe
    C:\WINDOWS\xwrm.exe
    C:\WINDOWS\wintrim
    C:\WINDOWS\winmgts
    C:\WINDOWS\wincomp
    C:\WINDOWS\system32\vtlbar1.dll
    C:\WINDOWS\system32\version.exe
    C:\WINDOWS\system32\updtscheduler.exe
    C:\WINDOWS\system32\tubby.dll
    C:\WINDOWS\system32\toolbar.dll
    C:\WINDOWS\system32\tbc.dll
    C:\WINDOWS\system32\nas.dll
    C:\WINDOWS\system32\msxml4r.exe
    C:\WINDOWS\system32\msklive.dll
    C:\WINDOWS\system32\mseggrpid.dll
    C:\WINDOWS\system32\msegcompid.dll
    C:\WINDOWS\system32\mscache.dll
    C:\WINDOWS\system32\mapisvc32.exe
    C:\WINDOWS\system32\madise.dll
    C:\WINDOWS\system32\keyhost.exe
    C:\WINDOWS\system32\keyactivex.ocx
    C:\WINDOWS\system32\jeired.dll
    C:\WINDOWS\system32\ia.dll
    C:\WINDOWS\system32\gcasctrl.exe
    C:\WINDOWS\system32\egdial.dll
    C:\WINDOWS\system32\egdhtml_1027.dll
    C:\WINDOWS\system32\egdhtml_1026.dll
    C:\WINDOWS\system32\duel.exe
    C:\WINDOWS\system32\dll.dll
    C:\WINDOWS\system32\aupdate_uninstall.exe
    C:\WINDOWS\system32\aupdate.exe
    C:\WINDOWS\system32\adv.dll
    C:\WINDOWS\navpmc
    C:\WINDOWS\mscache.exe
    C:\WINDOWS\mscache.dll
    C:\WINDOWS\mmups.exe
    C:\WINDOWS\mm63.ocx
    C:\WINDOWS\mm21.ocx
    C:\WINDOWS\mm20.ocx
    C:\WINDOWS\mc
    C:\WINDOWS\istsvc.exe
    C:\WINDOWS\imgurla.exe
    C:\WINDOWS\exedialer.exe
    C:\WINDOWS\a64sddd.exe
    C:\Program Files\powersearch
    C:\Program Files\perfectnav
    C:\Program Files\media gateway
    C:\Program Files\md
    C:\Program Files\lstsvc
    C:\Program Files\kuaiso toolsbar
    C:\Program Files\kgb keylogger
    C:\Program Files\invisible secrets toolbar
    C:\Program Files\instant buzz
    C:\Program Files\incredifind
    C:\Program Files\ebayshop
    C:\Program Files\Common Files\updmgr
    C:\Program Files\Common Files\updater
    C:\Program Files\Common Files\keenvalue
    C:\WINDOWS\wqzq
    C:\WINDOWS\winobject.dll
    C:\WINDOWS\wdskctl.exe
    C:\WINDOWS\wcby
    C:\WINDOWS\ts.exe
    C:\WINDOWS\system32\winstart001.exe
    C:\WINDOWS\system32\winstart.exe
    C:\WINDOWS\system32\winsrm32.dll
    C:\WINDOWS\system32\winenc32.dll
    C:\WINDOWS\system32\windowsie.dll
    C:\WINDOWS\system32\windec32.dll
    C:\WINDOWS\system32\waeb.dll
    C:\WINDOWS\system32\update_rsp.DLL
    C:\WINDOWS\system32\update_removeold.dll
    C:\WINDOWS\system32\update_hosts.dll
    C:\WINDOWS\system32\update_com.dll
    C:\WINDOWS\system32\update_bho.dll
    C:\WINDOWS\system32\sbus.dll
    C:\WINDOWS\system32\rsp001.dll
    C:\WINDOWS\system32\rsp.dll
    C:\WINDOWS\system32\install_all.dll
    C:\WINDOWS\system32\ineb.dll
    C:\WINDOWS\system32\iexplorr29.dll
    C:\WINDOWS\system32\iexplorr27.dll
    C:\WINDOWS\system32\iexplorr26.dll
    C:\WINDOWS\system32\iexplorr25.dll
    C:\WINDOWS\system32\iexplorr24.dll
    C:\WINDOWS\system32\iexplorr23.dll
    C:\WINDOWS\system32\iexplorr22.dll
    C:\WINDOWS\system32\iexplorr11.dll
    C:\WINDOWS\system32\iemsg.dll
    C:\WINDOWS\system32\gws.dll
    C:\WINDOWS\system32\egdhtml_1025.dll
    C:\WINDOWS\system32\egdhtml_1024.dll
    C:\WINDOWS\system32\egdhtml_1023.dll
    C:\WINDOWS\system32\drbr.dll
    C:\WINDOWS\system32\chgrgs.dll
    C:\WINDOWS\system32\bundler_mpb_sb.exe
    C:\WINDOWS\system32\bmeb.dll
    C:\WINDOWS\system32\bho001.dll
    C:\WINDOWS\system32\belop.dll
    C:\WINDOWS\system32\absnro.dll
    C:\WINDOWS\system32\abeb.dll
    C:\WINDOWS\systb.exe
    C:\WINDOWS\systb.dll
    C:\WINDOWS\ssk.exe
    C:\WINDOWS\snbho.exe
    C:\WINDOWS\rgrt.exe
    C:\WINDOWS\pxckdlauninstall.exe
    C:\WINDOWS\pxckdla.exe
    C:\WINDOWS\offerssk.exe
    C:\WINDOWS\invitessk.exe
    C:\WINDOWS\ilookup
    C:\WINDOWS\id.exe
    C:\Program Files\instant access
    C:\Program Files\install provider
    C:\Program Files\instafink
    C:\WINDOWS\system32\zopenssl.dll
    C:\WINDOWS\system32\yvsvga.sys
    C:\WINDOWS\system32\yvsvga.dll
    C:\WINDOWS\system32\yvprgb.dll
    C:\WINDOWS\system32\yvpp02.sys

  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Edited by koko_crunch, 24 June 2008 - 05:48 PM.

  • 0

#103
kelkay

kelkay

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 423 posts
Well I never downloaded Kazaa in any form. (knowingly that is) My kids may of done that, but they aren't admitting it. As far as Zone Alarm Pro, I agree with you. I pay for that service, and I expect MORE. The same thing with the anti-virus programs I've had. I have tried Bit Defender, and Dr. Web fairly recently. I have used Norton many years ago. I would of thought that these programs alone would of kept my computer clean in the past. Also, I checked in my add/remove programs for Kazaa...and it is not there. Strange.

Alright on to the next step. Thank you.
  • 0

#104
kelkay

kelkay

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 423 posts
C:\WINDOWS\winupie.exe moved successfully.
C:\WINDOWS\winmuschi.exe moved successfully.
C:\WINDOWS\updatewinlocator.exe moved successfully.
C:\WINDOWS\system32\zp.dll moved successfully.
C:\WINDOWS\system32\zeropopupbar.dll moved successfully.
C:\WINDOWS\system32\winwsl.exe moved successfully.
C:\WINDOWS\system32\wintft.dll moved successfully.
C:\WINDOWS\system32\wintbpx.exe moved successfully.
C:\WINDOWS\system32\wintbp.exe moved successfully.
C:\WINDOWS\system32\winshow.dll moved successfully.
C:\WINDOWS\system32\winsb.dll moved successfully.
C:\WINDOWS\system32\winrvl.exe moved successfully.
C:\WINDOWS\system32\winpup32.exe moved successfully.
C:\WINDOWS\system32\winpup.exe moved successfully.
C:\WINDOWS\system32\winlocatorhelper.dll moved successfully.
C:\WINDOWS\system32\winlocator.dll moved successfully.
C:\WINDOWS\system32\winksl.exe moved successfully.
C:\WINDOWS\system32\systemout.exe moved successfully.
C:\WINDOWS\system32\sysdll32.dll moved successfully.
C:\WINDOWS\system32\servises.exe moved successfully.
C:\WINDOWS\system32\pup.exe moved successfully.
C:\WINDOWS\system32\pnp.exe moved successfully.
C:\WINDOWS\system32\per.exe moved successfully.
C:\WINDOWS\system32\norton update.exe moved successfully.
< C:\WINDOWS\system32\[bleep].exe >
File/Folder C:\WINDOWS\system32\[bleep].exe not found.
C:\WINDOWS\system32\df_kme.exe moved successfully.
C:\WINDOWS\system32\csm.exe moved successfully.
C:\WINDOWS\system32\botzor.exe moved successfully.
C:\WINDOWS\system32\axconfig.dll moved successfully.
C:\WINDOWS\system32\4ccc3cea.exe moved successfully.
C:\WINDOWS\pnpasn32.exe moved successfully.
C:\WINDOWS\hpsv.exe moved successfully.
C:\WINDOWS\cdproxyserv.exe moved successfully.
C:\Program Files\zsearch moved successfully.
C:\Program Files\zeropopupbar moved successfully.
C:\Program Files\zangoclient moved successfully.
C:\Program Files\zango games moved successfully.
C:\Program Files\xsoftware moved successfully.
C:\Program Files\xpcspy moved successfully.
C:\Program Files\winfixer 2005 moved successfully.
C:\WINDOWS\windowsupd4.exe moved successfully.
C:\WINDOWS\windowsupd2.exe moved successfully.
C:\WINDOWS\windowsupd1.exe moved successfully.
C:\WINDOWS\vx2.dll moved successfully.
C:\WINDOWS\system32\winntcreate.exe moved successfully.
C:\WINDOWS\system32\vx2.dll moved successfully.
C:\WINDOWS\system32\vwix32.exe moved successfully.
C:\WINDOWS\system32\uninmyad.exe moved successfully.
C:\WINDOWS\system32\tps108.dll moved successfully.
C:\WINDOWS\system32\tisa.dll moved successfully.
C:\WINDOWS\system32\tips.exe moved successfully.
C:\WINDOWS\system32\tippcls.dat moved successfully.
C:\WINDOWS\system32\tipp.dat moved successfully.
C:\WINDOWS\system32\ticont.dll moved successfully.
C:\WINDOWS\system32\ticads.exe moved successfully.
C:\WINDOWS\system32\tconini.dat moved successfully.
C:\WINDOWS\system32\sysmonnt.exe moved successfully.
C:\WINDOWS\system32\spwgoc.exe moved successfully.
C:\WINDOWS\system32\rvreg.exe moved successfully.
C:\WINDOWS\system32\rulesak.dll moved successfully.
C:\WINDOWS\system32\myad.dll moved successfully.
C:\WINDOWS\system32\msview.dll moved successfully.
C:\WINDOWS\system32\msnavc32.exe moved successfully.
C:\WINDOWS\system32\lut.dat moved successfully.
C:\WINDOWS\system32\lspak.dll moved successfully.
C:\WINDOWS\system32\localnrd.dll moved successfully.
C:\WINDOWS\system32\lcch.dat moved successfully.
C:\WINDOWS\system32\ladchkr.exe moved successfully.
C:\WINDOWS\system32\host.dll moved successfully.
C:\WINDOWS\system32\gdu.dll moved successfully.
C:\WINDOWS\system32\dad.bat moved successfully.
C:\WINDOWS\system32\cidrules.dll moved successfully.
C:\WINDOWS\system32\6fo4svc.dll moved successfully.
C:\WINDOWS\psapi.dll moved successfully.
C:\WINDOWS\kernellos.dll moved successfully.
C:\WINDOWS\isrvs moved successfully.
C:\WINDOWS\iehelper.dll moved successfully.
C:\WINDOWS\cleanhistories.dll moved successfully.
C:\Program Files\winfavorites moved successfully.
C:\Program Files\windows adtools moved successfully.
C:\Program Files\windows adcontrol moved successfully.
C:\Program Files\win comm moved successfully.
C:\Program Files\whenu moved successfully.
C:\Program Files\web_rebates moved successfully.
C:\Program Files\web_cpr moved successfully.
C:\Program Files\vvsn moved successfully.
C:\Program Files\vvsdl moved successfully.
C:\Program Files\vomba moved successfully.
C:\Program Files\vmntoolbar moved successfully.
C:\Program Files\ts trial moved successfully.
C:\Program Files\hpdll moved successfully.
C:\Program Files\Common Files\winsoftware moved successfully.
C:\Program Files\Common Files\ucontrol moved successfully.
C:\Program Files\autoupdate moved successfully.
C:\WINDOWS\t2serv.exe moved successfully.
C:\WINDOWS\t2serv.dll moved successfully.
C:\WINDOWS\system32\wshtlprh.dll moved successfully.
C:\WINDOWS\system32\wshnseri.exe moved successfully.
C:\WINDOWS\system32\winftsap.exe moved successfully.
C:\WINDOWS\system32\winftsap.dll moved successfully.
C:\WINDOWS\system32\w3sskbda.dll moved successfully.
C:\WINDOWS\system32\vsxmpgpc.dll moved successfully.
C:\WINDOWS\system32\vnetsmme.dll moved successfully.
C:\WINDOWS\system32\vb5dmspo.dll moved successfully.
C:\WINDOWS\system32\v4pbpt51.dll moved successfully.
C:\WINDOWS\system32\trafracp.dll moved successfully.
C:\WINDOWS\system32\timesrv.exe moved successfully.
C:\WINDOWS\system32\snmpmssw.exe moved successfully.
C:\WINDOWS\system32\slbrmqtr.exe moved successfully.
C:\WINDOWS\system32\slbipsch.exe moved successfully.
C:\WINDOWS\system32\slbipsch.dll moved successfully.
C:\WINDOWS\system32\shfoxpob.exe moved successfully.
C:\WINDOWS\system32\secumsje.exe moved successfully.
C:\WINDOWS\system32\sd16win.dll moved successfully.
C:\WINDOWS\system32\scp3jgaw.dll moved successfully.
C:\WINDOWS\system32\rdpwmsjt.exe moved successfully.
C:\WINDOWS\system32\rcbdwmpd.dll moved successfully.
C:\WINDOWS\system32\qdvtscf.dll moved successfully.
C:\WINDOWS\system32\oebdfc.dll moved successfully.
C:\WINDOWS\system32\msstersv.dll moved successfully.
C:\WINDOWS\system32\msnsxole.exe moved successfully.
C:\WINDOWS\system32\msnsxole.dll moved successfully.
C:\WINDOWS\system32\mslsicwd.dll moved successfully.
C:\WINDOWS\system32\msexcred.exe moved successfully.
C:\WINDOWS\system32\msafiasn.dll moved successfully.
C:\WINDOWS\system32\messenger.lib.exe moved successfully.
C:\WINDOWS\system32\hook2.dll moved successfully.
C:\WINDOWS\system32\hook1.dll moved successfully.
C:\WINDOWS\system32\google.png.exe moved successfully.
C:\WINDOWS\system32\game3.exe moved successfully.
C:\WINDOWS\system32\game2.exe moved successfully.
C:\WINDOWS\system32\game1.exe moved successfully.
C:\WINDOWS\system32\adchkr.exe moved successfully.
C:\WINDOWS\sserrvv.exe moved successfully.
C:\WINDOWS\serrv.exe moved successfully.
C:\WINDOWS\reggserv.exe moved successfully.
C:\WINDOWS\msupdtwiz.exe moved successfully.
C:\WINDOWS\cserv32.exe moved successfully.
C:\WINDOWS\ccsserv.exe moved successfully.
C:\temp_kl moved successfully.
C:\Program Files\topmoxie moved successfully.
C:\Program Files\sys detective+ moved successfully.
C:\Program Files\surfsidekick moved successfully.
C:\Program Files\surfsidekick 2 moved successfully.
C:\Program Files\superbar moved successfully.
C:\Program Files\netmeting moved successfully.
C:\archivos de programa moved successfully.
C:\WINDOWS\system32\unsocul.exe moved successfully.
C:\WINDOWS\system32\sodahk.dll moved successfully.
C:\WINDOWS\system32\socul.dll moved successfully.
C:\WINDOWS\system32\mqoacdmo.dll moved successfully.
C:\WINDOWS\system32\mqadscp3.exe moved successfully.
C:\WINDOWS\system32\mgmtmtxc.exe moved successfully.
C:\WINDOWS\system32\mcd3mscm.dll moved successfully.
C:\WINDOWS\system32\lmrtatkc.dll moved successfully.
C:\WINDOWS\system32\kbdpkbdr.exe moved successfully.
C:\WINDOWS\system32\kbdfwshe.exe moved successfully.
C:\WINDOWS\system32\jgsdrpcn.exe moved successfully.
C:\WINDOWS\system32\jgsdrpcn.dll moved successfully.
C:\WINDOWS\system32\jgdwadsn.exe moved successfully.
C:\WINDOWS\system32\jgdwadsn.dll moved successfully.
C:\WINDOWS\system32\iuennwcf.dll moved successfully.
C:\WINDOWS\system32\ir32racp.exe moved successfully.
C:\WINDOWS\system32\ipxwshel.exe moved successfully.
C:\WINDOWS\system32\ipxrmfc4.dll moved successfully.
C:\WINDOWS\system32\imesrdch.exe moved successfully.
C:\WINDOWS\system32\icmpdx3j.dll moved successfully.
C:\WINDOWS\system32\iaspdpus.dll moved successfully.
C:\WINDOWS\system32\i4n27vl.exe moved successfully.
C:\WINDOWS\system32\hhselz32.dll moved successfully.
C:\WINDOWS\system32\fltlauto.exe moved successfully.
C:\WINDOWS\system32\fileserv.dll moved successfully.
C:\WINDOWS\system32\dsseds32.exe moved successfully.
C:\WINDOWS\system32\dsseds32.dll moved successfully.
C:\WINDOWS\system32\dpugmswe.dll moved successfully.
C:\WINDOWS\system32\dnsrxpob.exe moved successfully.
C:\WINDOWS\system32\deskmcd3.dll moved successfully.
C:\WINDOWS\system32\ddemdmco.dll moved successfully.
C:\WINDOWS\system32\davctool.exe moved successfully.
C:\WINDOWS\system32\davctool.dll moved successfully.
C:\WINDOWS\system32\confbrw.dll moved successfully.
C:\WINDOWS\system32\comrkbdd.exe moved successfully.
C:\WINDOWS\system32\comploader.dll moved successfully.
C:\WINDOWS\system32\chkmfdep.exe moved successfully.
C:\WINDOWS\system32\camodpnm.exe moved successfully.
C:\WINDOWS\system32\brwstat.dll moved successfully.
C:\WINDOWS\system32\brwprf32.dll moved successfully.
C:\WINDOWS\system32\brwperf.exe moved successfully.
C:\WINDOWS\system32\brwmgr32.dll moved successfully.
C:\WINDOWS\system32\brwconf.exe moved successfully.
C:\WINDOWS\system32\avifipxr.dll moved successfully.
C:\WINDOWS\system32\admeiolo.dll moved successfully.
C:\WINDOWS\system32\actidmoc.exe moved successfully.
C:\spedia moved successfully.
C:\Program Files\swagent moved successfully.
C:\Program Files\stealthwatcher200 moved successfully.
C:\Program Files\spytech software moved successfully.
C:\Program Files\spyonthis moved successfully.
C:\Program Files\spyblast moved successfully.
C:\Program Files\p4p moved successfully.
C:\Program Files\Common Files\sogou pxp moved successfully.
C:\WINDOWS\winsecurity moved successfully.
C:\WINDOWS\waladhpr.exe moved successfully.
C:\WINDOWS\system32\wzhelper.dll moved successfully.
C:\WINDOWS\system32\webalize.dll moved successfully.
C:\WINDOWS\system32\somatic.dll moved successfully.
C:\WINDOWS\system32\smdnn05.dll moved successfully.
C:\WINDOWS\system32\servehost.exe moved successfully.
C:\WINDOWS\system32\seqsb.dll moved successfully.
C:\WINDOWS\system32\searchupdate33.exe moved successfully.
C:\WINDOWS\system32\searchupdate31.exe moved successfully.
C:\WINDOWS\system32\searchsquire33.dll moved successfully.
C:\WINDOWS\system32\searchsquire3.dll moved successfully.
C:\WINDOWS\system32\searchsquire2.dll moved successfully.
C:\WINDOWS\system32\searchsquire.dll moved successfully.
C:\WINDOWS\system32\seantb.dll moved successfully.
C:\WINDOWS\system32\s4helper.dll moved successfully.
C:\WINDOWS\system32\reg2.exe moved successfully.
C:\WINDOWS\system32\pqhelper.dll moved successfully.
C:\WINDOWS\system32\mygeek.dll moved successfully.
C:\WINDOWS\system32\msqsb.dll moved successfully.
C:\WINDOWS\system32\msplus4.dll moved successfully.
C:\WINDOWS\system32\msplus3.dll moved successfully.
C:\WINDOWS\system32\msplus2.dll moved successfully.
C:\WINDOWS\system32\mslspcg.exe moved successfully.
C:\WINDOWS\system32\mgeekremove.exe moved successfully.
C:\WINDOWS\system32\ifsomatic.dll moved successfully.
C:\WINDOWS\system32\ifhelper.dll moved successfully.
C:\WINDOWS\system32\iebrw.dll moved successfully.
C:\WINDOWS\system32\hotlink.dll moved successfully.
C:\WINDOWS\system32\homepage.dll moved successfully.
C:\WINDOWS\system32\hmepge.dll moved successfully.
C:\WINDOWS\system32\gsim.dll moved successfully.
C:\WINDOWS\system32\barbho.dll moved successfully.
C:\WINDOWS\svrmgr.exe moved successfully.
C:\WINDOWS\ssmsgr.exe moved successfully.
C:\WINDOWS\ssls.exe moved successfully.
C:\WINDOWS\ssdgt.exe moved successfully.
C:\WINDOWS\sscrg.exe moved successfully.
C:\WINDOWS\skynetave.exe moved successfully.
C:\WINDOWS\napatch.exe moved successfully.
C:\WINDOWS\gsim.dll moved successfully.
C:\WINDOWS\cssswd.exe moved successfully.
C:\WINDOWS\csssupd.exe moved successfully.
C:\WINDOWS\connectionstatus moved successfully.
C:\WINDOWS\cfg32s.dll moved successfully.
C:\WINDOWS\cfg32r.dll moved successfully.
C:\WINDOWS\cfg32o.dll moved successfully.
C:\WINDOWS\cfg32.exe moved successfully.
C:\WINDOWS\avserve3.exe moved successfully.
C:\WINDOWS\avserve2.exe moved successfully.
C:\WINDOWS\adrsb.exe moved successfully.
C:\Program Files\valintines day card moved successfully.
C:\Program Files\softomate moved successfully.
C:\Program Files\selectrebates moved successfully.
C:\Program Files\searchnet moved successfully.
C:\Program Files\searchlocate moved successfully.
C:\Program Files\screenview moved successfully.
C:\Program Files\savenow moved successfully.
C:\Program Files\rxtoolbar moved successfully.
C:\Program Files\ietoolbar moved successfully.
C:\Program Files\ezthemes_whenusavenow_installer moved successfully.
C:\Program Files\dynamic toolbar moved successfully.
C:\WINDOWS\wserver.exe moved successfully.
C:\WINDOWS\winlogon.scr moved successfully.
C:\WINDOWS\visualguard.exe moved successfully.
C:\WINDOWS\system32\vlcx052.dll moved successfully.
C:\WINDOWS\system32\speeder.exe moved successfully.
C:\WINDOWS\system32\slpube03.dll moved successfully.
C:\WINDOWS\system32\rlvknlg.exe moved successfully.
C:\WINDOWS\system32\rkinstaller.exe moved successfully.
C:\WINDOWS\system32\rk.exe moved successfully.
C:\WINDOWS\system32\optserve.exe moved successfully.
C:\WINDOWS\system32\optserve.dll moved successfully.
C:\WINDOWS\system32\msplus1.dll moved successfully.
C:\WINDOWS\system32\msplus.dll moved successfully.
C:\WINDOWS\system32\mrkscr.exe moved successfully.
C:\WINDOWS\system32\lp.exe moved successfully.
C:\WINDOWS\system32\lp.dll moved successfully.
C:\WINDOWS\system32\auole4.dll moved successfully.
C:\WINDOWS\sysmonxp.exe moved successfully.
C:\WINDOWS\symav.exe moved successfully.
C:\WINDOWS\switpb.exe moved successfully.
C:\WINDOWS\switpa.exe moved successfully.
C:\WINDOWS\rundil32.exe moved successfully.
C:\WINDOWS\rundil.exe moved successfully.
C:\WINDOWS\phantom.exe moved successfully.
C:\WINDOWS\pandaavengine.exe moved successfully.
C:\WINDOWS\netmedia.exe moved successfully.
C:\WINDOWS\msnmsgrs.exe moved successfully.
C:\WINDOWS\maja.exe moved successfully.
C:\WINDOWS\lansas.exe moved successfully.
C:\WINDOWS\kasperskyaveng.exe moved successfully.
C:\WINDOWS\jammer2nd.exe moved successfully.
C:\WINDOWS\infodll.dll moved successfully.
C:\WINDOWS\fooding.exe moved successfully.
C:\WINDOWS\firewallsvr.exe moved successfully.
C:\WINDOWS\easyav.exe moved successfully.
C:\WINDOWS\diskmonitor.exe moved successfully.
C:\WINDOWS\comp.cpl moved successfully.
C:\WINDOWS\avprotect9x.exe moved successfully.
C:\WINDOWS\avprotect.exe moved successfully.
C:\WINDOWS\avpguard.exe moved successfully.
C:\WINDOWS\avguard.exe moved successfully.
C:\WINDOWS\avbgle.exe moved successfully.
C:\Program Files\startup mechanic moved successfully.
C:\Program Files\relevantknowledge moved successfully.
C:\Program Files\rax search helper moved successfully.
C:\Program Files\psupport moved successfully.
C:\Program Files\need2find moved successfully.
C:\Program Files\ncase moved successfully.
C:\Program Files\navexcel moved successfully.
C:\Program Files\navexcel search toolbar moved successfully.
C:\Program Files\mywebsearch moved successfully.
C:\Program Files\exolon moved successfully.
C:\Program Files\ddr moved successfully.
C:\Program Files\Common Files\nsis moved successfully.
C:\Program Files\arcade! moved successfully.
C:\WINDOWS\system32\xpfirewall.exe moved successfully.
C:\WINDOWS\system32\wpwmgrs.exe moved successfully.
C:\WINDOWS\system32\winvnc.exe moved successfully.
C:\WINDOWS\system32\wintasker.exe moved successfully.
C:\WINDOWS\system32\winsyscfg.exe moved successfully.
C:\WINDOWS\system32\winsys.exe moved successfully.
C:\WINDOWS\system32\winsvc32.exe moved successfully.
C:\WINDOWS\system32\winstart.pif moved successfully.
C:\WINDOWS\system32\winnt.exe moved successfully.
C:\WINDOWS\system32\wininfo.exe moved successfully.
C:\WINDOWS\system32\winhlpapi.exe moved successfully.
C:\WINDOWS\system32\wingmt32.exe moved successfully.
C:\WINDOWS\system32\winds.exe moved successfully.
C:\WINDOWS\system32\windowsfirewall.exe moved successfully.
C:\WINDOWS\system32\windasz-updote.exe moved successfully.
C:\WINDOWS\system32\win24.exe moved successfully.
C:\WINDOWS\system32\wid32.exe moved successfully.
C:\WINDOWS\system32\wfdmgr.exe moved successfully.
C:\WINDOWS\system32\wfdgmr.exe moved successfully.
C:\WINDOWS\system32\wdns33.exe moved successfully.
C:\WINDOWS\system32\w32ntupdt.exe moved successfully.
C:\WINDOWS\system32\w1nt5k.exe moved successfully.
C:\WINDOWS\system32\twunk_65.exe moved successfully.
C:\WINDOWS\system32\timemanager.exe moved successfully.
C:\WINDOWS\system32\taskgmr32.exe moved successfully.
C:\WINDOWS\system32\taskgamr.exe moved successfully.
C:\WINDOWS\system32\tagmr.exe moved successfully.
C:\WINDOWS\system32\sysconf.exe moved successfully.
C:\WINDOWS\system32\sword.exe moved successfully.
C:\WINDOWS\system32\stagmr.exe moved successfully.
C:\WINDOWS\system32\sp2winfix.exe moved successfully.
C:\WINDOWS\system32\sp2fx.exe moved successfully.
C:\WINDOWS\system32\skybot.exe moved successfully.
C:\WINDOWS\system32\shell.exe moved successfully.
C:\WINDOWS\system32\service5.exe moved successfully.
C:\WINDOWS\system32\sd.exe moved successfully.
C:\WINDOWS\system32\scrigz.exe moved successfully.
C:\WINDOWS\system32\scalpe91.exe moved successfully.
C:\WINDOWS\system32\protection.exe moved successfully.
C:\WINDOWS\system32\plugnplay32.exe moved successfully.
C:\WINDOWS\system32\picx.exe moved successfully.
C:\WINDOWS\system32\phantom.exe moved successfully.
C:\WINDOWS\system32\netcog.exe moved successfully.
C:\WINDOWS\system32\mtrnqs.exe moved successfully.
C:\WINDOWS\system32\mssck.exe moved successfully.
C:\WINDOWS\system32\msplus32.exe moved successfully.
C:\WINDOWS\system32\msnl.exe moved successfully.
C:\WINDOWS\system32\msmgrxp.exe moved successfully.
C:\WINDOWS\system32\msgmr.exe moved successfully.
C:\WINDOWS\system32\msdev32.exe moved successfully.
C:\WINDOWS\system32\mouse.exe moved successfully.
C:\WINDOWS\system32\microupdate.exe moved successfully.
C:\WINDOWS\system32\memloader.exe moved successfully.
C:\winssystem.exe moved successfully.
C:\WINDOWS\unstall.exe moved successfully.
C:\WINDOWS\system32\winnb60.dll moved successfully.
C:\WINDOWS\system32\winnb58.dll moved successfully.
C:\WINDOWS\system32\winnb57.dll moved successfully.
C:\WINDOWS\system32\winnb56.dll moved successfully.
C:\WINDOWS\system32\winnb52.dll moved successfully.
C:\WINDOWS\system32\winnb51.dll moved successfully.
C:\WINDOWS\system32\winnb42.dll moved successfully.
C:\WINDOWS\system32\winnb41.dll moved successfully.
C:\WINDOWS\system32\winnb40.dll moved successfully.
C:\WINDOWS\system32\windmy.dll moved successfully.
C:\WINDOWS\system32\winats.dll moved successfully.
C:\WINDOWS\system32\patch31345.exe moved successfully.
C:\WINDOWS\system32\osalogbe.exe moved successfully.
C:\WINDOWS\system32\nn_bar31.dll moved successfully.
C:\WINDOWS\system32\nn_bar22.dll moved successfully.
C:\WINDOWS\system32\nn_bar21.dll moved successfully.
C:\WINDOWS\system32\nn_bar.dll moved successfully.
C:\WINDOWS\system32\myaccess.dll moved successfully.
C:\WINDOWS\system32\msapasrc.dll moved successfully.
C:\WINDOWS\system32\msa64chk.dll moved successfully.
C:\WINDOWS\system32\microsystem.exe moved successfully.
C:\WINDOWS\system32\mcscn.exe moved successfully.
C:\WINDOWS\system32\mailinfo.exe moved successfully.
C:\WINDOWS\system32\logitechwls.exe moved successfully.
C:\WINDOWS\system32\logic.exe moved successfully.
C:\WINDOWS\system32\lienvdk.exe moved successfully.
C:\WINDOWS\system32\lienvandekelder.exe moved successfully.
C:\WINDOWS\system32\lientjeuh.exe moved successfully.
C:\WINDOWS\system32\lien vd kelder.exe moved successfully.
C:\WINDOWS\system32\lien vande kelder.exe moved successfully.
C:\WINDOWS\system32\lien Van de kelderrr.exe moved successfully.
C:\WINDOWS\system32\lien van de kelder.exe moved successfully.
C:\WINDOWS\system32\lcd32.exe moved successfully.
C:\WINDOWS\system32\jusched32.exe moved successfully.
C:\WINDOWS\system32\itunegui.exe moved successfully.
C:\WINDOWS\system32\hostdrvxp.exe moved successfully.
C:\WINDOWS\system32\hbmail.exe moved successfully.
C:\WINDOWS\system32\gothica.exe moved successfully.
C:\WINDOWS\system32\fixupdattr.exe moved successfully.
C:\WINDOWS\system32\evil.exe moved successfully.
C:\WINDOWS\system32\ds.exe moved successfully.
C:\WINDOWS\system32\dcomuser.exe moved successfully.
C:\WINDOWS\system32\coolbot.exe moved successfully.
C:\WINDOWS\system32\ccsrs.exe moved successfully.
C:\WINDOWS\system32\avpr.exe moved successfully.
C:\WINDOWS\system32\abs.exe moved successfully.
C:\WINDOWS\system32\666.exe moved successfully.
C:\WINDOWS\system32\1hellbot.exe moved successfully.
C:\WINDOWS\system32\0.exe moved successfully.
C:\WINDOWS\patch31345.exe moved successfully.
C:\WINDOWS\msnarrator.exe moved successfully.
C:\WINDOWS\mrhop.dll moved successfully.
C:\WINDOWS\mpgcom.dll moved successfully.
C:\WINDOWS\iempg2.dll moved successfully.
C:\WINDOWS\iempg.dll moved successfully.
C:\Program Files\support software moved successfully.
C:\Program Files\network essentials moved successfully.
C:\Program Files\medialoads moved successfully.
C:\Program Files\medialoads enhanced moved successfully.
C:\hellmsn.exe moved successfully.
C:\WINDOWS\xwrm.exe moved successfully.
C:\WINDOWS\wintrim moved successfully.
C:\WINDOWS\winmgts moved successfully.
C:\WINDOWS\wincomp moved successfully.
C:\WINDOWS\system32\vtlbar1.dll moved successfully.
C:\WINDOWS\system32\version.exe moved successfully.
C:\WINDOWS\system32\updtscheduler.exe moved successfully.
C:\WINDOWS\system32\tubby.dll moved successfully.
C:\WINDOWS\system32\toolbar.dll moved successfully.
C:\WINDOWS\system32\tbc.dll moved successfully.
C:\WINDOWS\system32\nas.dll moved successfully.
C:\WINDOWS\system32\msxml4r.exe moved successfully.
C:\WINDOWS\system32\msklive.dll moved successfully.
C:\WINDOWS\system32\mseggrpid.dll moved successfully.
C:\WINDOWS\system32\msegcompid.dll moved successfully.
C:\WINDOWS\system32\mscache.dll moved successfully.
C:\WINDOWS\system32\mapisvc32.exe moved successfully.
C:\WINDOWS\system32\madise.dll moved successfully.
C:\WINDOWS\system32\keyhost.exe moved successfully.
C:\WINDOWS\system32\keyactivex.ocx moved successfully.
C:\WINDOWS\system32\jeired.dll moved successfully.
C:\WINDOWS\system32\ia.dll moved successfully.
C:\WINDOWS\system32\gcasctrl.exe moved successfully.
C:\WINDOWS\system32\egdial.dll moved successfully.
C:\WINDOWS\system32\egdhtml_1027.dll moved successfully.
C:\WINDOWS\system32\egdhtml_1026.dll moved successfully.
C:\WINDOWS\system32\duel.exe moved successfully.
File/Folder C:\WINDOWS\system32\dll.dll not found.
C:\WINDOWS\system32\aupdate_uninstall.exe moved successfully.
C:\WINDOWS\system32\aupdate.exe moved successfully.
C:\WINDOWS\system32\adv.dll moved successfully.
C:\WINDOWS\navpmc moved successfully.
C:\WINDOWS\mscache.exe moved successfully.
C:\WINDOWS\mscache.dll moved successfully.
C:\WINDOWS\mmups.exe moved successfully.
C:\WINDOWS\mm63.ocx moved successfully.
C:\WINDOWS\mm21.ocx moved successfully.
C:\WINDOWS\mm20.ocx moved successfully.
C:\WINDOWS\mc moved successfully.
C:\WINDOWS\istsvc.exe moved successfully.
C:\WINDOWS\imgurla.exe moved successfully.
C:\WINDOWS\exedialer.exe moved successfully.
C:\WINDOWS\a64sddd.exe moved successfully.
C:\Program Files\powersearch moved successfully.
C:\Program Files\perfectnav moved successfully.
C:\Program Files\media gateway moved successfully.
C:\Program Files\md moved successfully.
C:\Program Files\lstsvc moved successfully.
C:\Program Files\kuaiso toolsbar moved successfully.
C:\Program Files\kgb keylogger moved successfully.
C:\Program Files\invisible secrets toolbar moved successfully.
C:\Program Files\instant buzz moved successfully.
C:\Program Files\incredifind moved successfully.
C:\Program Files\ebayshop moved successfully.
C:\Program Files\Common Files\updmgr moved successfully.
C:\Program Files\Common Files\updater moved successfully.
C:\Program Files\Common Files\keenvalue moved successfully.
C:\WINDOWS\wqzq moved successfully.
C:\WINDOWS\winobject.dll moved successfully.
C:\WINDOWS\wdskctl.exe moved successfully.
C:\WINDOWS\wcby moved successfully.
C:\WINDOWS\ts.exe moved successfully.
C:\WINDOWS\system32\winstart001.exe moved successfully.
C:\WINDOWS\system32\winstart.exe moved successfully.
C:\WINDOWS\system32\winsrm32.dll moved successfully.
C:\WINDOWS\system32\winenc32.dll moved successfully.
C:\WINDOWS\system32\windowsie.dll moved successfully.
C:\WINDOWS\system32\windec32.dll moved successfully.
C:\WINDOWS\system32\waeb.dll moved successfully.
C:\WINDOWS\system32\update_rsp.DLL moved successfully.
C:\WINDOWS\system32\update_removeold.dll moved successfully.
C:\WINDOWS\system32\update_hosts.dll moved successfully.
C:\WINDOWS\system32\update_com.dll moved successfully.
C:\WINDOWS\system32\update_bho.dll moved successfully.
C:\WINDOWS\system32\sbus.dll moved successfully.
C:\WINDOWS\system32\rsp001.dll moved successfully.
C:\WINDOWS\system32\rsp.dll moved successfully.
C:\WINDOWS\system32\install_all.dll moved successfully.
C:\WINDOWS\system32\ineb.dll moved successfully.
C:\WINDOWS\system32\iexplorr29.dll moved successfully.
C:\WINDOWS\system32\iexplorr27.dll moved successfully.
C:\WINDOWS\system32\iexplorr26.dll moved successfully.
C:\WINDOWS\system32\iexplorr25.dll moved successfully.
C:\WINDOWS\system32\iexplorr24.dll moved successfully.
C:\WINDOWS\system32\iexplorr23.dll moved successfully.
C:\WINDOWS\system32\iexplorr22.dll moved successfully.
C:\WINDOWS\system32\iexplorr11.dll moved successfully.
C:\WINDOWS\system32\iemsg.dll moved successfully.
C:\WINDOWS\system32\gws.dll moved successfully.
C:\WINDOWS\system32\egdhtml_1025.dll moved successfully.
C:\WINDOWS\system32\egdhtml_1024.dll moved successfully.
C:\WINDOWS\system32\egdhtml_1023.dll moved successfully.
C:\WINDOWS\system32\drbr.dll moved successfully.
C:\WINDOWS\system32\chgrgs.dll moved successfully.
C:\WINDOWS\system32\bundler_mpb_sb.exe moved successfully.
C:\WINDOWS\system32\bmeb.dll moved successfully.
C:\WINDOWS\system32\bho001.dll moved successfully.
C:\WINDOWS\system32\belop.dll moved successfully.
C:\WINDOWS\system32\absnro.dll moved successfully.
C:\WINDOWS\system32\abeb.dll moved successfully.
C:\WINDOWS\systb.exe moved successfully.
C:\WINDOWS\systb.dll moved successfully.
C:\WINDOWS\ssk.exe moved successfully.
C:\WINDOWS\snbho.exe moved successfully.
C:\WINDOWS\rgrt.exe moved successfully.
C:\WINDOWS\pxckdlauninstall.exe moved successfully.
C:\WINDOWS\pxckdla.exe moved successfully.
C:\WINDOWS\offerssk.exe moved successfully.
C:\WINDOWS\invitessk.exe moved successfully.
C:\WINDOWS\ilookup moved successfully.
C:\WINDOWS\id.exe moved successfully.
C:\Program Files\instant access moved successfully.
C:\Program Files\install provider moved successfully.
C:\Program Files\instafink moved successfully.
File/Folder C:\WINDOWS\system32\zopenssl.dll not found.
C:\WINDOWS\system32\yvsvga.sys moved successfully.
C:\WINDOWS\system32\yvsvga.dll moved successfully.
C:\WINDOWS\system32\yvprgb.dll moved successfully.
C:\WINDOWS\system32\yvpp02.sys moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06242008_190823
  • 0

#105
koko_crunch

koko_crunch

    Trusted Helper

  • Retired Staff
  • 1,751 posts
It does sound strange doesn't it?
Ok next, I would need a list.

Open Notepad.
Copy and paste text in codeboxbelow
Type filename as seek.bat then Set Filetype to "all files"
Save to your Desktop then click Save.

cmd /c dir C:\WINDOWS\Downloaded Installations\*.* /o:n /s >> files.txt & notepad files.txt

Double-click on seek.bat.
Notepad will open with the results of the query.
Post the content on you next reply.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP