Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Please Help. winfixer virus? [CLOSED]


  • This topic is locked This topic is locked

#1
liebermojo

liebermojo

    Member

  • Member
  • PipPip
  • 17 posts
I've run AVG and its telling me that I have something called "winfixer.aty" infecting my computer.
I tried searching for this through google but no luck on a removal tool. I see that most people run a program called dss so I did that and here are the logs. If anyone can help I would greatly appreciate this.

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Pentium® D CPU 2.80GHz
CPU 1: Intel® Pentium® D CPU 2.80GHz
Percentage of Memory in Use: 53%
Physical Memory (total/avail): 1022.07 MiB / 478.76 MiB
Pagefile Memory (total/avail): 2456.34 MiB / 1829.73 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1922.99 MiB

C: is Fixed (NTFS) - 144.31 GiB total, 93.78 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - ST3160812AS - 149.01 GiB - 3 partitions
\PARTITION0 - Unknown - 54.88 MiB
\PARTITION1 (bootable) - Installable File System - 144.31 GiB - C:
\PARTITION2 - Unknown - 4.64 GiB



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.

FirstRunDisabled is set.
AntiVirusDisableNotify is set.
FirewallDisableNotify is set.
UpdatesDisableNotify is set.

FW: Windows Live OneCare Firewall v1.0.0 (Microsoft Corporation)
AV: AVG Anti-Virus Free v8.0 (AVG Technologies)
AV: Windows Live OneCare v1.0.0 (Microsoft Corporation)
AV: ESET NOD32 Antivirus 3.0 v3.0 (ESET, spol. s r. o.)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\a la mode\\Sched\\eSched.exe"="C:\\Program Files\\a la mode\\Sched\\eSched.exe:*:Enabled:a la mode Assistant"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Documents and Settings\\T.J\\Local Settings\\Temp\\.tt41.tmp"="C:\\Documents and Settings\\T.J\\Local Settings\\Temp\\.tt41.tmp:*:Enabled:enable"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\T.J\Application Data
CLASSPATH=.;C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=D9WP9T91
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\T.J
LOGONSERVER=\\D9WP9T91
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 4, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0404
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip
SESSIONNAME=Console
SonicCentral=C:\Program Files\Common Files\Sonic Shared\Sonic Central\
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\T.J\LOCALS~1\TEMP
TMP=C:\DOCUME~1\T.J\LOCALS~1\TEMP
USERDOMAIN=D9WP9T91
USERNAME=T.J
USERPROFILE=C:\Documents and Settings\T.J
windir=C:\WINDOWS
WT=w:


-- User Profiles ---------------------------------------------------------------

T.J (admin)
LogMeInRemoteUser (admin)
LogMeInRemoteUser.D9WP9T91 (admin)
Administrator (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
--> MsiExec.exe /I{219B0DA4-8F1A-499D-8795-4A07C632521E}
--> MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
--> MsiExec.exe /I{644B991F-B109-4360-9DA3-40CDAD13961C}
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Acrobat - Reader 6.0.2 Update --> MsiExec.exe /I{AC76BA86-0000-0000-0000-6028747ADE01}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 6.0.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A00000000001}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Adobe® Photoshop® Album Starter Edition 3.2 --> MsiExec.exe /I{A654A805-41D9-40C7-AA46-4AF04F044D61}
AdwareAlert --> MsiExec.exe /X{B7F778DB-0CCE-425F-BAD5-299F1AC2198C}
American Greetings® Art & More Store --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Mindscape\Art & More Store\Uninst.isu"
AOLIcon --> MsiExec.exe /I{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}
Apple Mobile Device Support --> MsiExec.exe /I{B5C209B1-8DDB-4642-A573-375B951514CB}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
Ask Toolbar --> rundll32 C:\PROGRA~1\AskSBar\bar\1.bin\AskSBar.dll,O
ATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,[email protected] -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
AVG Free 8.0 --> C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Conexant D850 56K V.9x DFVc Modem --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1\HXFSETUP.EXE -U -Idel200fk.inf
Corel Paint Shop Pro X --> MsiExec.exe /I{1A15507A-8551-4626-915D-3D5FA095CC1B}
Coupon Printer for Windows --> "C:\Program Files\Coupons\uninstall.exe" "/U:C:\Program Files\Coupons\Uninstall\uninstall.xml"
Deewoo Network Manager removal --> C:\WINDOWS\system32\lcntmtdm.exe -UPop
Dell CinePlayer --> MsiExec.exe /I{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}
Dell Digital Jukebox Driver --> C:\Program Files\Dell\Digital Jukebox Drivers\DrvUnins.exe /s
Dell Driver Reset Tool --> MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
Dell Support 3.1 --> MsiExec.exe /X{548EEA8E-8299-497F-8057-811D2D7097DC}
Digital Blue QX5 Microscope --> MsiExec.exe /X{08786A53-D98F-484A-867C-3302BC5AE30D}
Digital Content Portal --> MsiExec.exe /I{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}
Digital Line Detect --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
Dora Lost City --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{747C231B-062D-4586-8221-8E7870987D5B}\setup.exe" -l0x9 -uninst
DVD Decrypter (Remove Only) --> "C:\Program Files\DVD Decrypter\uninstall.exe"
DVD Shrink 3.2 --> "C:\Program Files\DVD Shrink\unins000.exe"
ELIcon --> MsiExec.exe /I{4667B940-BB01-428B-986E-A0CC46497BF7}
Enhancement Browser Tools Gooochi --> C:\WINDOWS\system32\dpbybkqyhvedhks.exe
ESET NOD32 Antivirus --> MsiExec.exe /I{86A6E235-C08F-4A14-B14C-793C7D8844A0}
GemMaster Mystic --> "C:\Program Files\GemMaster\uninstallgemmaster.exe"
Google Desktop --> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Talk (remove only) --> "C:\Program Files\Google\Google Talk\uninstall.exe"
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
GTOneCare --> MsiExec.exe /X{8B21B9EF-6DBF-4F63-8CC7-9F6A56D1EE8E}
High Definition Audio Driver Package - KB835221 --> C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
Intel® PRO Network Connections Drivers --> Prounstl.exe
Intel® PROSet for Wired Connections --> MsiExec.exe /I{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}
IRIS 2.2 --> C:\WINDOWS\UNWISE.EXE C:\WINDOWS\INSTALL.LOG
iTunes --> MsiExec.exe /I{18388EF8-E0A3-442B-8BFE-E2F1B3D05C91}
Java 2 Runtime Environment, SE v1.4.2_03 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
LogMeIn --> MsiExec.exe /I{BA2D4D22-0B99-4D63-BCEE-D2EA4736F27F}
MCU --> MsiExec.exe /I{D2988E9B-C73F-422C-AD4B-A66EBE257120}
MicroBase Plus --> C:\WINDOWS\st6unst.exe -n "C:\MBWPlus\ST6UNST.LOG" MicroBase Plus (C:\MBWPLUS\) --> C:\WINDOWS\st6unst.exe -n "C:\MBWPlus\ST6UNST.000" Microsoft English TTS Engine --> MsiExec.exe /I{94824ADD-8F26-43D2-84DB-22E11F377E5E}
Microsoft Office Standard Edition 2003 --> MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
Microsoft Plus! Digital Media Edition Installer --> MsiExec.exe /X{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}
Microsoft Protection Service --> MsiExec.exe /I{85CFDC2D-710E-49D5-B799-F3743CA506BA}
Microsoft Streets & Trips 2007 --> MsiExec.exe /I{C82185E8-C27B-4EF4-2007-4444BC2C2B6D}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Web Publishing Wizard 1.52 --> RunDll32 ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\wpie4x86.inf,WebPostUninstall
Microsoft Windows Live OneCare Resources v2.5.2900.03 --> MsiExec.exe /I{5660022E-F3F2-4126-8CC5-9726C47150EB}
Microsoft Windows OneCare Live AntiSpyware and AntiVirus --> MsiExec.exe /I{AB65455A-059F-41C3-AAD6-2EFAFB38B19B}
Microsoft Windows OneCare Live v2.5.2900.03 --> MsiExec.exe /I{D07A8E7E-D324-4945-BA8C-E532AD008FF3}
Microsoft Windows OneCare Live v2.5.2900.03 Idcrl Install --> MsiExec.exe /I{3851147E-5A91-4469-BA4D-13FFFCC8A920}
Minigolf Space --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{A2F6B63B-01BA-4D18-BBE2-31743427D8A3}
Modem Helper --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
Move Networks Media Player for Internet Explorer --> C:\Documents and Settings\T.J\Application Data\Move Networks\ie_bin\Uninst.exe
Move Networks Player for Internet Explorer --> "C:\Documents and Settings\T.J\Application Data\Move Networks\ie_bin\unins000.exe"
Mozilla Firefox (1.5.0.12) --> C:\Program Files\Mozilla Firefox\uninstall\uninstall.exe /ua "1.5.0.12 (en-US)"
Mozilla Thunderbird (2.0.0.14) --> C:\PROGRA~1\Mozilla Thunderbird\uninstall\helper.exe
Mr. Potato Head Uninstaller --> C:\WINDOWS\uninst.exe -fC:\mrpotato\DeIsL1.isu
MSXML4 Parser --> MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
MySidesearch Search Assistant Adzgalore --> C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll-uninst.exe
MySpaceIM --> C:\Program Files\MySpace\IM\Uninstall.exe
NetWaiting --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
OpenOffice.org 2.1 --> MsiExec.exe /I{43983EB4-43DC-4C3D-9712-1EF592A31CA8}
Otto --> "C:\Program Files\EnglishOtto\uninstallotto.exe"
PDF-XChange 3 --> "C:\Program Files\Tracker Software\PDF-XChange 3\unins000.exe"
PrintMaster 7.00 --> c:\PROGRA~1\MINDSC~1\PRINTM~1\uninst32.exe /IFirst
Profile Editor --> "C:\PROGRA~1\Freeze.com\Profile Editor\UNINSTAL.EXE"
PX Engine --> MsiExec.exe /I{6513E869-647F-40FD-A55D-CFC92579B9BA}
QuickTime --> MsiExec.exe /I{E0D51394-1D45-460A-B62D-383BC4F8B335}
RealPlayer Basic --> C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
Roxio DLA --> MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
Roxio MyDVD LE --> MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Roxio RecordNow Audio --> MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Roxio RecordNow Copy --> MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
Roxio RecordNow Data --> MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
Search Assist --> MsiExec.exe /X{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}
Serif DrawPlus 3.0 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Serif\dp30\DrawPlus_uninst.isu"
Sonic Activation Module --> MsiExec.exe /I{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}
Sonic Encoders --> MsiExec.exe /I{9941F0AA-B903-4AF4-A055-83A9815CC011}
Sonic Update Manager --> MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
The Land Before Time Kindergarten Adventure --> C:\Lbtkind\UNWISE.EXE C:\Lbtkind\INSTALL.LOG
The Weather Channel Desktop 6 --> C:\Program Files\The Weather Channel FW\Desktop\TheWeatherChannelCustomUninstall.exe
TTS Wrapper --> MsiExec.exe /I{97D0C0A1-7E64-4B05-A2EE-61D2CE23F154}
Update Rollup 2 for Windows XP Media Center Edition 2005 --> C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe
URL Assistant --> regsvr32 /u /s "c:\Program Files\BAE\BAE.dll"
Vuze --> C:\Program Files\Vuze\uninstall.exe
Weather Services --> C:\WINDOWS\system32\control.exe C:\PROGRA~1\THEWEA~1\FRAMEW~1\wxfw.cpl,4
WebCyberCoach 3.2 Dell --> "C:\Program Files\WebCyberCoach\b_Dell\WCC_Wipe.exe" "WebCyberCoach ext\wtrb" /inf "engine.inf,RealUninstallSection,,4" /infcfg "enginecf.inf,RealUninstallSection,,4"
Windows Driver Package - Digital Blue (marsqx5) Image (04/04/2007 1.0.0.0) --> C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\DPInst.exe /u C:\WINDOWS\system32\DRVSTORE\marsqx5_935523B763FD8C83A319DA72299E127DF607B108\marsqx5.inf
Windows Live OneCare --> "C:\Program Files\Microsoft Windows OneCare Live\OCSetup.exe" /u
Windows XP Media Center Edition 2005 KB908246 --> "C:\WINDOWS\$NtUninstallKB908246$\spuninst\spuninst.exe"
Windows XP Media Center Edition 2005 KB914548 --> "C:\WINDOWS\$NtUninstallKB914548$\spuninst\spuninst.exe"
WordPerfect Office 12 --> MsiExec.exe /I{AF19F291-F22F-4798-9662-525305AE9E48}


-- Application Event Log -------------------------------------------------------

Event Record #/Type3030 / Error
Event Submitted/Written: 07/09/2008 03:37:06 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application services.exe, version 5.1.2600.2180, faulting module services.exe, version 5.1.2600.2180, fault address 0x00008e40.
Processing media-specific event for [services.exe!ws!]

Event Record #/Type3011 / Warning
Event Submitted/Written: 07/09/2008 03:29:27 PM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Event Record #/Type2998 / Warning
Event Submitted/Written: 07/09/2008 09:59:09 AM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Event Record #/Type2984 / Error
Event Submitted/Written: 07/09/2008 03:33:46 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application services.exe, version 5.1.2600.2180, faulting module services.exe, version 5.1.2600.2180, fault address 0x00008e40.
Processing media-specific event for [services.exe!ws!]

Event Record #/Type2971 / Error
Event Submitted/Written: 07/09/2008 03:25:48 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application services.exe, version 5.1.2600.2180, faulting module services.exe, version 5.1.2600.2180, fault address 0x00008e40.
Processing media-specific event for [services.exe!ws!]



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type24264 / Error
Event Submitted/Written: 07/09/2008 05:04:01 PM
Event ID/Source: 10010 / DCOM
Event Description:
The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.

Event Record #/Type24244 / Warning
Event Submitted/Written: 07/09/2008 04:50:25 PM
Event ID/Source: 3004 / OneCareMP
Event Description:
%D9WP9T9129 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %D9WP9T9129 can't undo changes that you allow.

For more information please see the following:
%D9WP9T91295

Scan ID: {F453AA76-7921-4BBE-9EF4-F519606A7EE9}

Agent: %D9WP9T9143

User: D9WP9T91\T.J

Name: %D9WP9T91291

ID: %D9WP9T91292

Severity: 1.5.1955.05

Category: 1.5.1955.06

Path Found: %D9WP9T91296

Alert Type: %D9WP9T91298

Process Name: C:\PROGRA~1\AVG\AVG8\avgtray.exe

Detection Type: 1.5.1955.02

Status: 1.5.1955.00

Event Record #/Type24211 / Warning
Event Submitted/Written: 07/08/2008 07:31:05 PM
Event ID/Source: 3004 / OneCareMP
Event Description:
%D9WP9T9129 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %D9WP9T9129 can't undo changes that you allow.

For more information please see the following:
%D9WP9T91295

Scan ID: {394E3DBF-127B-4B6F-B11C-85ABF562260F}

Agent: %D9WP9T9143

User: D9WP9T91\T.J

Name: %D9WP9T91291

ID: %D9WP9T91292

Severity: 1.5.1955.05

Category: 1.5.1955.06

Path Found: %D9WP9T91296

Alert Type: %D9WP9T91298

Process Name: C:\WINDOWS\explorer.exe

Detection Type: 1.5.1955.02

Status: 1.5.1955.00

Event Record #/Type24209 / Error
Event Submitted/Written: 07/08/2008 07:31:05 PM
Event ID/Source: 3006 / OneCareMP
Event Description:
%D9WP9T9129 Real-Time Protection agent has encountered an error when taking action on spyware or other potentially unwanted software.

For more information please see the following:
%D9WP9T91295

Scan ID: {1B910C84-C788-4FEC-9A9F-E52574527B1E}

User: D9WP9T91\T.J

Name: %D9WP9T91291

ID: %D9WP9T91292

Severity: 1.5.1955.05

Category: 1.5.1955.06

Path: %D9WP9T91296

Alert Type: %D9WP9T91298

Action: 1.5.1955.00

Error Code: 1.5.1955.01

Error description: 1.5.1955.02

Event Record #/Type24208 / Warning
Event Submitted/Written: 07/08/2008 07:31:02 PM
Event ID/Source: 3004 / OneCareMP
Event Description:
%NT AUTHORITY29 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %NT AUTHORITY29 can't undo changes that you allow.

For more information please see the following:
%NT AUTHORITY295

Scan ID: {E1D32C97-4816-452D-BBD6-EF16BD41CA0F}

Agent: %NT AUTHORITY43

User: NT AUTHORITY\SYSTEM

Name: %NT AUTHORITY291

ID: %NT AUTHORITY292

Severity: 1.5.1955.05

Category: 1.5.1955.06

Path Found: %NT AUTHORITY296

Alert Type: %NT AUTHORITY298

Process Name: C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

Detection Type: 1.5.1955.02

Status: 1.5.1955.00



-- End of Deckard's System Scanner: finished at 2008-07-09 17:07:41 ------------




next one


Deckard's System Scanner v20071014.68
Run by T.J on 2008-07-09 17:04:11
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------



-- Last 4 Restore Point(s) --
4: 2008-07-09 20:25:22 UTC - RP7 - Deckard's System Scanner Restore Point
3: 2008-07-09 17:50:24 UTC - RP6 - Installed AVG Free 8.0
2: 2008-07-09 07:42:56 UTC - RP5 - Last good restore point
1: 2008-07-09 07:42:39 UTC - RP4 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-07-09 17:06:06
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Real\RealPlayer\realplay.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\LogMeIn\x86\ramaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.bin
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG8\avgemc.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AVG\AVG8\aAvgApi.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\T.J\Desktop\dss.exe
C:\WINDOWS\system32\svchost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co...l...&channel=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?linkid=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.co...l...&channel=us
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: (no name) - {00110011-4b0b-44d5-9718-90c88817369b} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {086ae192-23a6-48d6-96ec-715f53797e85} - (no file)
O2 - BHO: (no name) - {150fa160-130d-451f-b863-b655061432ba} - (no file)
O2 - BHO: (no name) - {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} - (no file)
O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} - (no file)
O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)
O2 - BHO: (no name) - {2d38a51a-23c9-48a1-a33c-48675aa2b494} - (no file)
O2 - BHO: (no name) - {2e9caff6-30c7-4208-8807-e79d4ec6f806} - (no file)
O2 - BHO: (no name) - {36953122-9f7c-4461-af35-e23242461fd7} - C:\WINDOWS\system32\xxyaxYqr.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {467faeb2-5f5b-4c81-bae0-2a4752ca7f4e} - (no file)
O2 - BHO: (no name) - {5321e378-ffad-4999-8c62-03ca8155f0b3} - (no file)
O2 - BHO: (no name) - {5350fcd9-5a0c-495f-8e97-fa925d68f5bd} - C:\WINDOWS\system32\yaywtULB.dll (file missing)
O2 - BHO: (no name) - {587dbf2d-9145-4c9e-92c2-1f953da73773} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL
O2 - BHO: (no name) - {6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} - (no file)
O2 - BHO: (no name) - {79369d5c-2903-4b7a-ade2-d5e0dee14d24} - (no file)
O2 - BHO: (no name) - {799a370d-5993-4887-9df7-0a4756a77d00} - (no file)
O2 - BHO: mysidesearch search enhancer - {942f9ded-e62a-0100-86ee-93e9d6be1fd5} - C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll
O2 - BHO: (no name) - {98dbbf16-ca43-4c33-be80-99e6694468a4} - (no file)
O2 - BHO: AVG Security Toolbar - {a057a204-bacc-4d26-9990-79a187e2698e} - C:\Program Files\AVG\AVG8\avgtoolbar.dll
O2 - BHO: (no name) - {a55581dc-2cdb-4089-8878-71a080b22342} - (no file)
O2 - BHO: (no name) - {a94c97a3-818a-48bc-9a1a-500f36eb445d} - C:\WINDOWS\system32\iifgFXQj.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar2.dll
O2 - BHO: (no name) - {acb17d13-44a2-4839-9499-46fa0459c0b2} - C:\WINDOWS\system32\ssqNFUNe.dll (file missing)
O2 - BHO: (no name) - {b847676d-72ac-4393-bfff-43a1eb979352} - (no file)
O2 - BHO: gooochi browser optimizer - {ba41c9e8-376e-11cc-b3bc-75607e242267} - C:\WINDOWS\system32\qqapnalwywl.dll
O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765721306} - (no file)
O2 - BHO: (no name) - {e2ddf680-9905-4dee-8c64-0a5de7fe133c} - (no file)
O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
O2 - BHO: (no name) - {e7afff2a-1b57-49c7-bf6b-e5123394c970} - (no file)
O2 - BHO: (no name) - {fcaddc14-bd46-408a-9842-cdbe1c6d37eb} - (no file)
O2 - BHO: (no name) - {fd9bc004-8331-4457-b830-4759ff704c22} - (no file)
O2 - BHO: (no name) - {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} - (no file)
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll
O4 - HKLM\..\Run: [{99fa2547-da8c-ffd6-5067-b94a415e033e}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\qqapnalwywl.dll" DllStart
O4 - HKLM\..\Run: [sysrest32.exe] C:\WINDOWS\system32\sysrest32.exe
O4 - HKLM\..\Run: [sunjavaupdatesched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [smrhcguqj0e92c] C:\Program Files\rhcguqj0e92c\rhcguqj0e92c.exe
O4 - HKLM\..\Run: [sigmatelsystrayapp] stsystra.exe
O4 - HKLM\..\Run: [realtray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [quicktime task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [onecareui] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [new.net startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,ClientStartup -s
O4 - HKLM\..\Run: [msserv] C:\WINDOWS\msserv.exe s
O4 - HKLM\..\Run: [mskdetectorexe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [lphcluqj0e92c] C:\WINDOWS\system32\lphcluqj0e92c.exe
O4 - HKLM\..\Run: [logmein gui] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [ituneshelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [isusscheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [isuspm startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [google desktop search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ehtray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [dmxlauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [brwdiag] C:\WINDOWS\system32\brwconf.exe
O4 - HKLM\..\Run: [audiag] C:\WINDOWS\system32\audconf.exe
O4 - HKLM\..\Run: [atipta] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [adobe photo downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [myspaceim] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [msmsgs] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [dw6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - Startup: Event Reminder.lnk = C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: https://online.musicmatch.com (HKLM)
O15 - Trusted Zone: *.amaena.com (HKCU)
O15 - ProtocolDefaults: Unknown 'pctools-rep' protocol is in My Computer Zone (HKLM)
O15 - ProtocolDefaults: Unknown 'pctools-rep' protocol is in My Computer Zone (HKCU)
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://mfr.mlxchange...ectComboBox.cab
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://mfr.mlxchange...ClientUtils.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://mfr.mlxchange...ol/IRCSharc.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai...5/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v6.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logme...trl.cab?lmi=100
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,confaud.dll,audstat.dll,wuapsecu.dll,confbrw.dll,brwstat.dll,a
vgrsstx.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: audmgr - C:\WINDOWS\system32\audmgr32.dll (file missing)
O20 - Winlogon Notify: cfgbrasr - C:\WINDOWS\system32\cfgbrasr.dll (file missing)
O20 - Winlogon Notify: osunuxth - C:\WINDOWS\system32\
O20 - Winlogon Notify: xxyaxyqr - C:\WINDOWS\system32\xxyaxYqr.dll (file missing)
O20 - Winlogon Notify: zlcocard - C:\WINDOWS\system32\zlcocard.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgwdsvc.exe
O23 - Service: Command Service (cmdservice) - Unknown owner - C:\WINDOWS\VC5K\command.exe
O23 - Service: Eset HTTP Server (ehttpsrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\ramaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O24 - Desktop Component 0: - http://images.google...-Hottest.jpgO24 - Desktop Component 1: - http://www.wwe.com/s...rphotos/999.jpg

--
End of file - 15974 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>

S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>

S2 cmdservice (Command Service) - c:\windows\vc5k\command.exe (file missing)


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-07-03 12:15:02 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


-- Files created between 2008-06-09 and 2008-07-09 -----------------------------

2008-07-09 13:56:07 0 d--h----- C:\$AVG8.VAULT$
2008-07-09 13:50:39 0 d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-09 13:50:39 0 d-------- C:\Documents and Settings\T.J\Application Data\AVGTOOLBAR
2008-07-09 13:50:25 0 d-------- C:\Program Files\AVG
2008-07-09 13:50:24 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-09 03:09:02 94208 --a------ C:\WINDOWS\system32\pphcluqj0e92c.exe
2008-07-08 19:19:24 0 d-------- C:\WINDOWS\system32\bits
2008-07-08 19:14:51 0 d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-07-08 00:21:40 0 d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-07-07 23:48:43 0 d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-07-07 23:48:39 0 d-------- C:\Documents and Settings\T.J\Application Data\Azureus
2008-07-07 20:36:50 0 d-------- C:\Program Files\Alwil Software
2008-07-07 20:27:55 617815 --ahs---- C:\WINDOWS\system32\eNUFNqss.ini2
2008-07-07 20:06:34 18176 --a------ C:\WINDOWS\y.exe
2008-07-07 20:06:34 14592 --a------ C:\WINDOWS\x.exe
2008-07-07 20:06:34 16640 --a------ C:\WINDOWS\winmgnt.exe
2008-07-07 20:06:34 20480 --a------ C:\WINDOWS\window.exe
2008-07-07 20:06:34 28160 --a------ C:\WINDOWS\winajbm.dll
2008-07-07 20:06:33 11008 --a------ C:\WINDOWS\win64.exe
2008-07-07 20:06:33 32768 --a------ C:\WINDOWS\win32e.exe
2008-07-07 20:06:33 22272 --a------ C:\WINDOWS\users32.exe
2008-07-07 20:06:33 10752 --a------ C:\WINDOWS\systemcritical.exe
2008-07-07 20:06:33 32000 --a------ C:\WINDOWS\systeem.exe
2008-07-07 20:06:32 19456 --a------ C:\WINDOWS\olehelp.exe
2008-07-07 20:06:32 9216 --a------ C:\WINDOWS\notepad32.exe
2008-07-07 20:06:32 11264 --a------ C:\WINDOWS\mtwirl32.dll
2008-07-07 20:06:32 30464 --a------ C:\WINDOWS\msupdate.exe
2008-07-07 20:06:32 17152 --a------ C:\WINDOWS\mssys.exe
2008-07-07 20:06:32 13824 --a------ C:\WINDOWS\loader.exe
2008-07-07 20:06:32 12800 --a------ C:\WINDOWS\iexplorer.exe
2008-07-07 20:06:32 31232 --a------ C:\WINDOWS\iedll.exe
2008-07-07 20:06:31 14080 --a------ C:\WINDOWS\clrssn.exe
2008-07-07 20:06:31 20224 --a------ C:\WINDOWS\avpcc.dll
2008-07-07 20:06:31 23040 --a------ C:\WINDOWS\accesss.exe
2008-07-07 18:40:59 613414 --ahs---- C:\WINDOWS\system32\jQXFgfii.ini2
2008-07-07 17:05:31 0 d-------- C:\ Program Files
2008-07-07 13:55:49 859 --a------ C:\WINDOWS\system32\winpfz33.sys
2008-07-07 13:53:10 18176 --a------ C:\WINDOWS\sistem.exe
2008-07-07 13:53:10 20480 --a------ C:\WINDOWS\rundll16.exe
2008-07-07 13:53:10 23296 --a------ C:\WINDOWS\quicken.exe
2008-07-07 13:53:10 30976 --a------ C:\WINDOWS\qttasks.exe
2008-07-07 13:53:09 24576 --a------ C:\WINDOWS\msconfd.dll
2008-07-07 13:53:08 32256 --a------ C:\WINDOWS\explore.exe
2008-07-07 13:53:07 13568 --a------ C:\WINDOWS\editpad.exe
2008-07-07 13:53:07 15872 --a------ C:\WINDOWS\ctrlpan.dll
2008-07-07 13:09:10 0 d-------- C:\WINDOWS\system32\4808
2008-07-07 12:38:52 64332 --a------ C:\WINDOWS\system32\dpbybkqyhvedhks.exe
2008-07-07 12:38:40 152184 --a------ C:\WINDOWS\system32\g87.exe
2008-07-07 12:26:20 9728 --a------ C:\WINDOWS\xplugin.dll
2008-07-07 12:26:19 8960 --a------ C:\WINDOWS\waol.exe
2008-07-07 12:26:19 14848 --a------ C:\WINDOWS\time.exe
2008-07-07 12:26:18 26880 --a------ C:\WINDOWS\svcinit.exe
2008-07-07 12:26:18 16640 --a------ C:\WINDOWS\svchost32.exe
2008-07-07 12:26:18 29952 --a------ C:\WINDOWS\searchword.dll
2008-07-07 12:26:16 30208 --a------ C:\WINDOWS\mswsc20.dll
2008-07-07 12:26:16 14848 --a------ C:\WINDOWS\mswsc10.dll
2008-07-07 12:26:15 32512 --a------ C:\WINDOWS\msspi.dll
2008-07-07 12:26:15 16128 --a------ C:\WINDOWS\internet.exe
2008-07-07 12:26:15 16640 --a------ C:\WINDOWS\inetinf.exe
2008-07-07 12:26:14 15616 --a------ C:\WINDOWS\helpcvs.exe
2008-07-07 12:26:14 25600 --a------ C:\WINDOWS\gfmnaaa.dll
2008-07-07 12:26:14 20224 --a------ C:\WINDOWS\funny.exe
2008-07-07 12:26:14 27136 --a------ C:\WINDOWS\funniest.exe
2008-07-07 12:26:13 13568 --a------ C:\WINDOWS\explorer32.exe
2008-07-07 12:26:13 26112 --a------ C:\WINDOWS\dnsrelay.dll
2008-07-07 12:26:13 17920 --a------ C:\WINDOWS\directx32.exe
2008-07-07 12:26:12 11776 --a------ C:\WINDOWS\ctfmon32.exe
2008-07-07 12:26:12 15616 --a------ C:\WINDOWS\cpan.dll
2008-07-07 12:11:19 0 d-------- C:\Program Files\AskSBar
2008-07-07 12:10:17 0 d-------- C:\Program Files\Vuze
2008-07-07 12:07:10 614550 --ahs---- C:\WINDOWS\system32\BLUtwyay.ini2
2008-07-07 12:05:43 0 d-------- C:\Program Files\AntiSpywareMaster
2008-07-07 12:02:20 0 d-------- C:\WINDOWS\S?mantec
2008-07-07 12:02:15 88961 --a------ C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
2008-07-07 12:02:09 0 d--hs---- C:\WINDOWS\VC5K
2008-07-07 12:02:04 0 d-------- C:\WINDOWS\system32\tfig
2008-07-07 12:02:04 0 d-------- C:\WINDOWS\system32\net
2008-07-07 12:02:04 0 d-------- C:\WINDOWS\system32\cREG
2008-07-07 12:02:04 0 d-------- C:\WINDOWS\system32\1030
2008-07-07 12:02:04 0 d-------- C:\Program Files\??crosoft
2008-07-07 12:02:00 0 d-------- C:\WINDOWS\system32\olixds01
2008-07-07 12:02:00 0 d-------- C:\Temp
2008-07-07 10:49:03 0 d-------- C:\ kav
2008-07-06 22:14:57 0 d-------- C:\Program Files\Spyware Doctor Enterprise Server
2008-07-06 22:13:41 0 d-------- C:\PC Tools Spyware Doctor Enterprise
2008-07-06 21:59:14 0 d-------- C:\Program Files\XoftSpySE
2008-07-06 21:35:24 0 d-------- C:\Program Files\CyberDefender
2008-07-06 21:30:46 0 d-------- C:\Documents and Settings\T.J\Application Data\rhcguqj0e92c
2008-07-06 21:19:56 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-07-06 21:18:59 0 d-------- C:\WINDOWS\system32\734914
2008-07-06 21:18:39 0 d-------- C:\Documents and Settings\LocalService\Application Data\rhcguqj0e92c
2008-07-06 21:18:25 58476 --a------ C:\WINDOWS\system32\drivers\cd2e4d3f.sys
2008-07-06 21:18:23 0 d-------- C:\Program Files\rhcguqj0e92c
2008-07-06 21:18:15 60928 --a------ C:\WINDOWS\system32\blphcluqj0e92c.scr <Not Verified; Sysinternals; Sysinternals Blue Screen>
2008-07-03 10:45:24 364544 --a------ C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll
2008-07-02 09:52:48 158208 --a------ C:\WINDOWS\system32\qqapnalwywl.dll
2008-07-02 09:52:48 158208 --a------ C:\WINDOWS\system32\_qqapnalwywl.dll
2008-06-26 11:20:17 0 d-------- C:\WINDOWS\Cache
2008-06-26 11:20:17 0 d-------- C:\Program Files\Coupons
2008-06-19 09:53:19 0 d-------- C:\Documents and Settings\All Users\Application Data\LogMeIn


-- Find3M Report ---------------------------------------------------------------

2008-07-09 17:02:48 0 d-------- C:\Documents and Settings\T.J\Application Data\OpenOffice.org2
2008-07-09 16:20:31 0 d-------- C:\Program Files\Mozilla Thunderbird
2008-07-09 03:08:06 0 d-------- C:\Program Files\LogMeIn
2008-07-08 17:21:33 0 d-------- C:\Documents and Settings\T.J\Application Data\AdobeUM
2008-07-08 02:52:10 0 d-------- C:\Program Files\Kodak
2008-07-08 02:51:42 0 d-------- C:\Program Files\Common Files
2008-07-08 00:14:03 0 d-------- C:\Program Files\Kaspersky Lab
2008-07-07 21:17:47 0 d-------- C:\Program Files\??crosoft
2008-06-29 15:54:19 6686 --a------ C:\WINDOWS\system32\KGyGaAvL.sys
2008-06-29 15:54:17 104 -rahs---- C:\WINDOWS\system32\DCD8B5840E.sys
2008-06-28 20:07:56 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-06-18 13:32:53 278528 -----n--- C:\WINDOWS\MBWSetup.exe <Not Verified; MicroDecisions, Inc.; MicroBase Setup>
2008-06-18 13:32:52 73216 --a------ C:\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2008-06-16 10:24:15 0 d-------- C:\Program Files\The Weather Channel FW


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00110011-4b0b-44d5-9718-90c88817369b}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{086ae192-23a6-48d6-96ec-715f53797e85}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{150fa160-130d-451f-b863-b655061432ba}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{17da0c9e-4a27-4ac5-bb75-5d24b8cdb972}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d38a51a-23c9-48a1-a33c-48675aa2b494}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2e9caff6-30c7-4208-8807-e79d4ec6f806}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{36953122-9f7c-4461-af35-e23242461fd7}]
C:\WINDOWS\system32\xxyaxYqr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{467faeb2-5f5b-4c81-bae0-2a4752ca7f4e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5321e378-ffad-4999-8c62-03ca8155f0b3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5350fcd9-5a0c-495f-8e97-fa925d68f5bd}]
C:\WINDOWS\system32\yaywtULB.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{587dbf2d-9145-4c9e-92c2-1f953da73773}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6cc1c91a-ae8b-4373-a5b4-28ba1851e39a}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79369d5c-2903-4b7a-ade2-d5e0dee14d24}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{799a370d-5993-4887-9df7-0a4756a77d00}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{942f9ded-e62a-0100-86ee-93e9d6be1fd5}]
07/03/2008 10:45 AM 364544 --a------ C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{98dbbf16-ca43-4c33-be80-99e6694468a4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a057a204-bacc-4d26-9990-79a187e2698e}]
07/09/2008 01:50 PM 2055960 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a55581dc-2cdb-4089-8878-71a080b22342}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a94c97a3-818a-48bc-9a1a-500f36eb445d}]
C:\WINDOWS\system32\iifgFXQj.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{acb17d13-44a2-4839-9499-46fa0459c0b2}]
C:\WINDOWS\system32\ssqNFUNe.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b847676d-72ac-4393-bfff-43a1eb979352}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba41c9e8-376e-11cc-b3bc-75607e242267}]
07/02/2008 09:52 AM 158208 --a------ C:\WINDOWS\system32\qqapnalwywl.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bc97b254-b2b9-4d40-971d-78e0978f5f26}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cf021f40-3e14-23a5-cba2-717765721306}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e2ddf680-9905-4dee-8c64-0a5de7fe133c}]

[HKEY_LOCAL_MACHINE
  • 0

Advertisements


#2
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
Hi liebermojo

welcome to geekstogo :)

if you have already downloaded combofix then could you delete the current version of combofix you have and then follow these instructions:

Please visit this web page for instructions for downloading and running ComboFix

http://www.bleepingc...to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet. (All the instructions for installing the Recovery Console are in the above link, but for more information on the Windows XP Recovery Console read http://support.micro...com/kb/314058.)

In your case, it is important that you install the recovery console

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

andrewuk
  • 0

#3
liebermojo

liebermojo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Wow you guys are fast. thank you in advance for your help.
for this post here is the hijack log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:00:59 PM, on 7/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?linkid=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 169.254.35.38
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: (no name) - {00110011-4b0b-44d5-9718-90c88817369b} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {086ae192-23a6-48d6-96ec-715f53797e85} - (no file)
O2 - BHO: (no name) - {150fa160-130d-451f-b863-b655061432ba} - (no file)
O2 - BHO: (no name) - {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} - (no file)
O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} - (no file)
O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)
O2 - BHO: (no name) - {2d38a51a-23c9-48a1-a33c-48675aa2b494} - (no file)
O2 - BHO: (no name) - {2e9caff6-30c7-4208-8807-e79d4ec6f806} - (no file)
O2 - BHO: (no name) - {36953122-9f7c-4461-af35-e23242461fd7} - C:\WINDOWS\system32\xxyaxYqr.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {467faeb2-5f5b-4c81-bae0-2a4752ca7f4e} - (no file)
O2 - BHO: (no name) - {5321e378-ffad-4999-8c62-03ca8155f0b3} - (no file)
O2 - BHO: (no name) - {5350fcd9-5a0c-495f-8e97-fa925d68f5bd} - C:\WINDOWS\system32\yaywtULB.dll (file missing)
O2 - BHO: (no name) - {587dbf2d-9145-4c9e-92c2-1f953da73773} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: (no name) - {6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} - (no file)
O2 - BHO: (no name) - {79369d5c-2903-4b7a-ade2-d5e0dee14d24} - (no file)
O2 - BHO: (no name) - {799a370d-5993-4887-9df7-0a4756a77d00} - (no file)
O2 - BHO: mysidesearch search enhancer - {942f9ded-e62a-0100-86ee-93e9d6be1fd5} - C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll
O2 - BHO: (no name) - {98dbbf16-ca43-4c33-be80-99e6694468a4} - (no file)
O2 - BHO: AVG Security Toolbar - {a057a204-bacc-4d26-9990-79a187e2698e} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {a55581dc-2cdb-4089-8878-71a080b22342} - (no file)
O2 - BHO: (no name) - {a94c97a3-818a-48bc-9a1a-500f36eb445d} - C:\WINDOWS\system32\iifgFXQj.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {acb17d13-44a2-4839-9499-46fa0459c0b2} - C:\WINDOWS\system32\ssqNFUNe.dll (file missing)
O2 - BHO: (no name) - {b847676d-72ac-4393-bfff-43a1eb979352} - (no file)
O2 - BHO: gooochi browser optimizer - {ba41c9e8-376e-11cc-b3bc-75607e242267} - C:\WINDOWS\system32\qqapnalwywl.dll
O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765721306} - (no file)
O2 - BHO: (no name) - {e2ddf680-9905-4dee-8c64-0a5de7fe133c} - (no file)
O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
O2 - BHO: (no name) - {e7afff2a-1b57-49c7-bf6b-e5123394c970} - (no file)
O2 - BHO: (no name) - {fcaddc14-bd46-408a-9842-cdbe1c6d37eb} - (no file)
O2 - BHO: (no name) - {fd9bc004-8331-4457-b830-4759ff704c22} - (no file)
O2 - BHO: (no name) - {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} - (no file)
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [{99fa2547-da8c-ffd6-5067-b94a415e033e}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\qqapnalwywl.dll" DllStart
O4 - HKLM\..\Run: [sysrest32.exe] C:\WINDOWS\system32\sysrest32.exe
O4 - HKLM\..\Run: [sunjavaupdatesched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [smrhcguqj0e92c] C:\Program Files\rhcguqj0e92c\rhcguqj0e92c.exe
O4 - HKLM\..\Run: [sigmatelsystrayapp] stsystra.exe
O4 - HKLM\..\Run: [realtray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [quicktime task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [onecareui] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [new.net startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,ClientStartup -s
O4 - HKLM\..\Run: [msserv] C:\WINDOWS\msserv.exe s
O4 - HKLM\..\Run: [mskdetectorexe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [lphcluqj0e92c] C:\WINDOWS\system32\lphcluqj0e92c.exe
O4 - HKLM\..\Run: [logmein gui] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [ituneshelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [isusscheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [isuspm startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [google desktop search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ehtray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [dmxlauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [brwdiag] C:\WINDOWS\system32\brwconf.exe
O4 - HKLM\..\Run: [audiag] C:\WINDOWS\system32\audconf.exe
O4 - HKLM\..\Run: [atipta] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [adobe photo downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [myspaceim] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [msmsgs] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [dw6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - Startup: Event Reminder.lnk = C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.amaena.com
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://mfr.mlxchange...ectComboBox.cab
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://mfr.mlxchange...ClientUtils.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://mfr.mlxchange...ol/IRCSharc.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai...5/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v6.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logme...trl.cab?lmi=100
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,confaud.dll,audstat.dll,wuapsecu.dll,confbrw.dll,brwstat.dll,a
vgrsstx.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: audmgr - audmgr32.dll (file missing)
O20 - Winlogon Notify: cfgbrasr - C:\WINDOWS\system32\cfgbrasr.dll (file missing)
O20 - Winlogon Notify: osunuxth - C:\WINDOWS\
O20 - Winlogon Notify: xxyaxyqr - xxyaxYqr.dll (file missing)
O20 - Winlogon Notify: zlcocard - C:\WINDOWS\system32\zlcocard.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Command Service (cmdservice) - Unknown owner - C:\WINDOWS\VC5K\command.exe (file missing)
O23 - Service: Eset HTTP Server (ehttpsrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O24 - Desktop Component 0: (no name) - http://images.google...0px-Hottest.jpg
O24 - Desktop Component 1: (no name) - http://www.wwe.com/s...rphotos/999.jpg

--
End of file - 14872 bytes
  • 0

#4
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
did you run the combofix program? if so, could you post the log? and once you have done that, please post a new hijackthis log

andrewuk

Edited by andrewuk, 09 July 2008 - 06:00 PM.

  • 0

#5
liebermojo

liebermojo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Andrewuk, thank you for all of your help. I had a distraction last night that prevented me from continuing to work on the computer. I am at work right now but I have set aside time to continue as soon as I get home. I wil run combofix and post the log as well as an updated Hijack This log.

Jon
  • 0

#6
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
no problem, i will be here :)
  • 0

#7
liebermojo

liebermojo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Here is the combofix log:

[email protected] wrote:ComboFix 08-07-09.5 - T.J 2008-07-10 17:44:24.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.410 [GMT -4:00]
Running from: C:\Documents and Settings\T.J\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\LocalService\Application Data\rhcguqj0e92c
C:\Documents and Settings\T.J\Application Data\rhcguqj0e92c
C:\Program Files\AntiSpywareMaster
C:\Program Files\crosof~1
C:\Program Files\crosof~1\??crosoft\
C:\Program Files\rhcguqj0e92c
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\accesss.exe
C:\WINDOWS\astctl32.ocx
C:\WINDOWS\avpcc.dll
C:\WINDOWS\clrssn.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\cpan.dll
C:\WINDOWS\ctfmon32.exe
C:\WINDOWS\ctrlpan.dll
C:\WINDOWS\default.htm
C:\WINDOWS\directx32.exe
C:\WINDOWS\dnsrelay.dll
C:\WINDOWS\editpad.exe
C:\WINDOWS\explore.exe
C:\WINDOWS\explorer32.exe
C:\WINDOWS\funniest.exe
C:\WINDOWS\funny.exe
C:\WINDOWS\gfmnaaa.dll
C:\WINDOWS\helpcvs.exe
C:\WINDOWS\iedll.exe
C:\WINDOWS\iexplorer.exe
C:\WINDOWS\inetinf.exe
C:\WINDOWS\internet.exe
C:\WINDOWS\loader.exe
C:\WINDOWS\mainms.vpi
C:\WINDOWS\megavid.cdt
C:\WINDOWS\msconfd.dll
C:\WINDOWS\msspi.dll
C:\WINDOWS\mssys.exe
C:\WINDOWS\msupdate.exe
C:\WINDOWS\mswsc10.dll
C:\WINDOWS\mswsc20.dll
C:\WINDOWS\mtwirl32.dll
C:\WINDOWS\notepad32.exe
C:\WINDOWS\olehelp.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\qttasks.exe
C:\WINDOWS\quicken.exe
C:\WINDOWS\rundll16.exe
C:\WINDOWS\rundll32.vbe
C:\WINDOWS\searchword.dll
C:\WINDOWS\sistem.exe
C:\WINDOWS\smante~1
C:\WINDOWS\svchost32.exe
C:\WINDOWS\svcinit.exe
C:\WINDOWS\systeem.exe
C:\WINDOWS\system32\_qqapnalwywl.dll
C:\WINDOWS\system32\asnvrtfj.ini
C:\WINDOWS\system32\BLUtwyay.ini
C:\WINDOWS\system32\BLUtwyay.ini2
C:\WINDOWS\system32\brsxbkhg.ini
C:\WINDOWS\system32\eNUFNqss.ini
C:\WINDOWS\system32\eNUFNqss.ini2
C:\WINDOWS\system32\jQXFgfii.ini
C:\WINDOWS\system32\jQXFgfii.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mouymjwe.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
C:\WINDOWS\system32\oeminfo.ini
C:\WINDOWS\system32\qqapnalwywl.dll
C:\WINDOWS\system32\SZComp5.dll
C:\WINDOWS\system32\winpfz33.sys
C:\WINDOWS\system32\xutwxofe.ini
C:\WINDOWS\system32\zxdnt3d.cfg
C:\WINDOWS\systemcritical.exe
C:\WINDOWS\time.exe
C:\WINDOWS\users32.exe
C:\WINDOWS\waol.exe
C:\WINDOWS\win32e.exe
C:\WINDOWS\win64.exe
C:\WINDOWS\winajbm.dll
C:\WINDOWS\window.exe
C:\WINDOWS\winmgnt.exe
C:\WINDOWS\x.exe
C:\WINDOWS\xplugin.dll
C:\WINDOWS\xxxvideo.hta
C:\WINDOWS\y.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_CBEVTSVC
-------\Legacy_mssecurity1.209.4
-------\Legacy_network_monitor


((((((((((((((((((((((((( Files Created from 2008-06-10 to 2008-07-10 )))))))))))))))))))))))))))))))
.

2008-07-10 17:15 . 2008-07-10 17:50 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-10 17:15 . 2008-07-10 17:15 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-10 17:14 . 2008-07-10 17:49 58,476 --ah----- C:\WINDOWS\system32\drivers\cd2e4d3f.sys.szcpf.szcpf
2008-07-09 19:53 . 2008-07-10 17:49 58,476 --ah----- C:\WINDOWS\system32\drivers\cd2e4d3f.sys.szcpf
2008-07-09 19:26 . 2008-07-10 17:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SITEguard
2008-07-09 19:26 . 2008-07-10 17:18 6,792 --a------ C:\WINDOWS\system32\drivers\kgpcpy.cfg
2008-07-09 19:25 . 2008-07-09 19:25 <DIR> d-------- C:\Program Files\STOPzilla!
2008-07-09 19:25 . 2008-07-09 19:25 <DIR> d-------- C:\Program Files\Common Files\iS3
2008-07-09 19:25 . 2008-07-10 17:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-07-09 19:00 . 2008-07-09 19:00 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-09 16:24 . 2008-07-09 16:24 <DIR> d-------- C:\Deckard
2008-07-09 13:56 . 2008-07-10 03:01 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-09 13:50 . 2008-07-10 08:53 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-09 13:50 . 2008-07-09 13:50 <DIR> d-------- C:\Program Files\AVG
2008-07-09 13:50 . 2008-07-10 17:37 <DIR> d-------- C:\Documents and Settings\T.J\Application Data\AVGTOOLBAR
2008-07-09 13:50 . 2008-07-09 13:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-09 13:50 . 2008-07-09 13:50 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-09 13:50 . 2008-07-09 13:50 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-09 13:50 . 2008-07-09 13:50 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-08 19:34 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-07-08 19:34 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-07-08 19:34 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-07-08 19:21 . 2007-11-27 22:56 116,416 --a------ C:\WINDOWS\system32\drivers\msfwhlpr.sys
2008-07-08 19:21 . 2007-11-27 22:56 91,328 --a------ C:\WINDOWS\system32\drivers\msfwdrv.sys
2008-07-08 19:19 . 2008-07-08 19:19 <DIR> d-------- C:\WINDOWS\system32\bits
2008-07-08 19:19 . 2007-03-29 08:56 409,600 --------- C:\WINDOWS\system32\dllcache\qmgr.dll
2008-07-08 19:19 . 2008-05-15 16:15 53,168 --a------ C:\WINDOWS\system32\drivers\MpFilter.sys
2008-07-08 19:19 . 2007-03-29 08:56 18,944 --------- C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2008-07-08 19:19 . 2007-03-29 08:56 8,192 --------- C:\WINDOWS\system32\dllcache\bitsprx2.dll
2008-07-08 19:19 . 2007-03-29 08:56 7,168 --------- C:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-07-08 19:19 . 2007-03-29 08:56 7,168 --------- C:\WINDOWS\system32\dllcache\bitsprx3.dll
2008-07-08 19:19 . 2007-03-29 08:56 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll
2008-07-08 19:14 . 2008-07-10 09:00 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-07-08 18:17 . 2008-07-08 18:17 36,079 --a------ C:\WINDOWS\alaredun.ini
2008-07-08 00:21 . 2008-07-08 00:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-07-07 23:48 . 2008-07-08 19:02 <DIR> d-------- C:\Documents and Settings\T.J\Application Data\Azureus
2008-07-07 23:48 . 2008-07-07 23:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-07-07 20:36 . 2008-07-07 20:36 <DIR> d-------- C:\Program Files\Alwil Software
2008-07-07 20:24 . 2008-07-07 20:24 2,879,724 --ahs---- C:\WINDOWS\system32\mouymjwe.tmp
2008-07-07 18:11 . 2008-07-08 19:34 110,463 --a------ C:\WINDOWS\BM9b2700e8.xml
2008-07-07 17:05 . 2008-07-10 17:47 <DIR> d-------- C:\Program Files
2008-07-07 13:09 . 2008-07-07 21:35 <DIR> d-------- C:\WINDOWS\system32\4808
2008-07-07 12:38 . 2008-07-07 12:38 152,184 --a------ C:\WINDOWS\system32\g87.exe
2008-07-07 12:38 . 2008-07-07 20:25 64,332 --a------ C:\WINDOWS\system32\dpbybkqyhvedhks.exe
2008-07-07 12:12 . 2008-07-07 12:12 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-07-07 12:11 . 2008-07-07 12:11 <DIR> d-------- C:\Program Files\AskSBar
2008-07-07 12:10 . 2008-07-07 23:51 <DIR> d-------- C:\Program Files\Vuze
2008-07-07 12:02 . 2008-07-07 21:28 <DIR> d-------- C:\WINDOWS\VC5K
2008-07-07 12:02 . 2008-07-07 21:28 <DIR> d-------- C:\WINDOWS\system32\tfig
2008-07-07 12:02 . 2008-07-08 19:02 <DIR> d-------- C:\WINDOWS\system32\olixds01
2008-07-07 12:02 . 2008-07-07 21:27 <DIR> d-------- C:\WINDOWS\system32\net
2008-07-07 12:02 . 2008-07-07 22:33 <DIR> d-------- C:\WINDOWS\system32\cREG
2008-07-07 12:02 . 2008-07-07 22:32 <DIR> d-------- C:\WINDOWS\system32\1030
2008-07-07 12:02 . 2008-07-07 12:02 <DIR> d-------- C:\Temp\stmpv4
2008-07-07 12:02 . 2008-07-10 17:45 <DIR> d-------- C:\Temp
2008-07-07 12:02 . 2008-07-07 12:02 167,976 --------- C:\WINDOWS\system32\drivers\core.cache.dsk
2008-07-07 12:02 . 2008-07-08 00:04 90,922 --a------ C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll-uninst.exe
2008-07-07 10:49 . 2008-07-07 10:39 <DIR> d-------- C:\kav
2008-07-06 22:14 . 2008-07-08 19:01 <DIR> d-------- C:\Program Files\Spyware Doctor Enterprise Server
2008-07-06 22:13 . 2008-07-06 22:13 <DIR> d-------- C:\PC Tools Spyware Doctor Enterprise
2008-07-06 21:59 . 2008-07-08 00:15 <DIR> d-------- C:\Program Files\XoftSpySE
2008-07-06 21:39 . 2008-07-06 21:39 75 --a------ C:\WINDOWS\st_affiliate.ini
2008-07-06 21:35 . 2008-07-07 10:42 <DIR> d-------- C:\Program Files\CyberDefender
2008-07-06 21:18 . 2008-07-07 21:25 <DIR> d-------- C:\WINDOWS\system32\734914
2008-07-06 21:18 . 2008-07-10 17:53 58,476 --a------ C:\WINDOWS\system32\drivers\cd2e4d3f.sys
2008-07-03 15:41 . 2008-07-03 15:41 258,048 -ra------ C:\WINDOWS\system32\SZBase5.dll
2008-07-03 10:45 . 2008-07-03 10:45 364,544 --a------ C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll
2008-06-29 17:25 . 2008-06-29 17:40 4,681,449,472 --a------ C:\SPIDERWICK _AC_D1_169.ISO
2008-06-28 21:49 . 2008-06-28 21:49 8,433 --a------ C:\SPIDERWICK_AC_D1_169.MDS
2008-06-28 21:34 . 2008-06-28 21:49 7,506,722,816 --a------ C:\SPIDERWICK_AC_D1_169.ISO
2008-06-26 11:20 . 2008-06-26 11:20 <DIR> d-------- C:\WINDOWS\Cache
2008-06-26 11:20 . 2008-06-26 11:20 <DIR> d-------- C:\Program Files\Coupons
2008-06-26 11:20 . 2008-06-26 11:20 206,168 -ra------ C:\WINDOWS\system32\cpnprt2.cid
2008-06-26 10:56 . 2008-06-26 10:56 364,544 -ra------ C:\WINDOWS\system32\IS3DBA5.dll
2008-06-26 10:56 . 2008-06-26 10:56 126,976 -ra------ C:\WINDOWS\system32\IS3HTUI5.dll
2008-06-26 10:55 . 2008-06-26 10:55 372,736 -ra------ C:\WINDOWS\system32\IS3UI5.dll
2008-06-26 10:55 . 2008-06-26 10:55 61,440 -ra------ C:\WINDOWS\system32\IS3Hks5.dll
2008-06-26 10:55 . 2008-06-26 10:55 23,040 -ra------ C:\WINDOWS\system32\IS3XDat5.dll
2008-06-26 10:54 . 2008-06-26 10:54 196,608 -ra------ C:\WINDOWS\system32\IS3Win325.dll
2008-06-26 10:54 . 2008-06-26 10:54 94,208 -ra------ C:\WINDOWS\system32\IS3Inet5.dll
2008-06-26 10:54 . 2008-06-26 10:54 90,112 -ra------ C:\WINDOWS\system32\IS3Svc5.dll
2008-06-26 10:50 . 2008-06-26 10:50 708,608 -ra------ C:\WINDOWS\system32\IS3Base5.dll
2008-06-20 13:41 . 2008-06-20 13:41 245,248 --------- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 06:44 . 2008-06-20 06:44 138,368 --------- C:\WINDOWS\system32\dllcache\afd.sys
2008-06-19 09:53 . 2008-06-19 09:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogMeIn
2008-06-11 05:38 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 05:38 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-10 21:52 --------- d-----w C:\Documents and Settings\T.J\Application Data\OpenOffice.org2
2008-07-10 21:39 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-07-10 19:02 6,686 ----a-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-07-10 18:05 --------- d-----w C:\Program Files\LogMeIn
2008-07-08 21:21 --------- d-----w C:\Documents and Settings\T.J\Application Data\AdobeUM
2008-07-08 12:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-07-08 06:52 --------- d-----w C:\Program Files\Kodak
2008-07-08 04:21 --------- d-----w C:\Program Files\ESET
2008-07-08 04:15 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-08 04:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-08 04:14 --------- d-----w C:\Program Files\Kaspersky Lab
2008-07-03 19:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\alamode
2008-06-29 21:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-18 17:32 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-06-18 17:32 278,528 ------w C:\WINDOWS\MBWSetup.exe
2008-06-16 17:48 849,144 ----a-w C:\WINDOWS\system32\auroraupgrade.dll
2008-06-16 14:24 --------- d-----w C:\Program Files\The Weather Channel FW
2008-06-02 14:52 849,144 ----a-w C:\WINDOWS\system32\wtapi.exe
2008-05-30 18:52 3,921,264 ----a-w C:\WINDOWS\system32\adbilling.dll
2008-05-28 16:33 83,288 ----a-w C:\WINDOWS\system32\LMIRfsClientNP.dll
2008-05-28 16:32 87,352 ----a-w C:\WINDOWS\system32\LMIinit.dll
2008-05-28 16:32 24,608 ----a-w C:\WINDOWS\system32\LMIport.dll
2008-05-28 16:32 23,736 ----a-w C:\WINDOWS\system32\lmimirr.dll
2008-05-28 16:32 10,040 ----a-w C:\WINDOWS\system32\lmimirr2.dll
2008-05-20 19:31 1,574,136 ----a-w C:\WINDOWS\system32\wtusers.dll
2008-05-20 17:16 500,984 ----a-w C:\WINDOWS\system32\alabilling.dll
2008-05-19 18:09 3,069,176 ----a-w C:\WINDOWS\system32\alacontacts.dll
2008-05-13 14:03 34,432 ----a-r C:\WINDOWS\system32\drivers\SZKG.sys
2008-05-08 17:12 1,398,008 ----a-w C:\WINDOWS\system32\wtfiles.dll
2008-05-08 12:28 202,752 ------w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 04:55 1,288,192 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-24 02:16 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:40 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 07:39 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-20 05:07 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-04-15 16:25 681,208 ----a-w C:\WINDOWS\system32\openreport.exe
2008-04-11 14:27 3,532,144 ----a-w C:\WINDOWS\system32\filecabinet5.dll
2006-05-11 13:52 630,784 ----a-w C:\Documents and Settings\T.J\chatlnk.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{942f9ded-e62a-0100-86ee-93e9d6be1fd5}]
2008-07-03 10:45 364544 --a------ C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 06:00 15360]
"myspaceim"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2006-11-16 17:42 1327104]
"msmsgs"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 17:22 3739648]
"dw6"="C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2008-06-10 16:18 785520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"sunjavaupdatesched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 18:48 32881]
"realtray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-04-17 08:12 26112]
"quicktime task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
"onecareui"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2008-06-25 06:48 67112]
"mskdetectorexe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 20:05 1117184]
"logmein gui"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03 63048]
"ituneshelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 13:10 267048]
"isusscheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"isuspm startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44 249856]
"google desktop search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-04-17 08:21 169472]
"ehtray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 15:01 67584]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072]
"dmxlauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 04:12 94208]
"dla"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"atipta"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 22:05 344064]
"adobe photo downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-09 13:50 1232152]
"sigmatelsystrayapp"="stsystra.exe" [2005-03-23 00:20 339968 C:\WINDOWS\stsystra.exe]

C:\Documents and Settings\T.J\Start Menu\Programs\Startup\
Event Reminder.lnk - C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE [2007-12-29 21:31:43 325632]
OpenOffice.org 2.1.lnk - C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe [2006-11-27 17:45:48 393216]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-17 08:10:11 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\lmiinit]
2008-05-28 12:32 87352 C:\WINDOWS\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\onecaremp]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"KodakCCS"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\a la mode\\Sched\\eSched.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

R0 szkg5;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys [2008-05-13 10:03]
R1 avgldx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-09 13:50]
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-09 13:50]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-09 13:50]
R2 avgtdix;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-09 13:50]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2008-02-28 15:31]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2008-03-07 13:39]
R2 ochealthmon;Windows Live OneCare Health Monitor;C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe [2008-06-25 06:47]
S3 marsqx5;Digital Blue QX5 V2 Microscope;C:\WINDOWS\system32\DRIVERS\marsqx5.sys [2007-04-02 16:02]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-07-10 16:15:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -

BHO-{36953122-9f7c-4461-af35-e23242461fd7} - C:\WINDOWS\system32\xxyaxYqr.dll
BHO-{5350fcd9-5a0c-495f-8e97-fa925d68f5bd} - C:\WINDOWS\system32\yaywtULB.dll
BHO-{a94c97a3-818a-48bc-9a1a-500f36eb445d} - C:\WINDOWS\system32\iifgFXQj.dll
BHO-{acb17d13-44a2-4839-9499-46fa0459c0b2} - C:\WINDOWS\system32\ssqNFUNe.dll
Toolbar-SITEguard - (no file)
WebBrowser-{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - (no file)
HKLM-Run-{99fa2547-da8c-ffd6-5067-b94a415e033e} - C:\WINDOWS\system32\qqapnalwywl.dll
HKLM-Run-msserv - C:\WINDOWS\msserv.exe
ShellExecuteHooks-{36953122-9F7C-4461-AF35-E23242461FD7} - C:\WINDOWS\system32\xxyaxYqr.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-10 17:50:39
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\LogMeIn\x86\ramaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.bin
C:\WINDOWS\system32\locator.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-07-10 17:56:40 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-10 21:56:30

Pre-Run: 100,430,950,400 bytes free
Post-Run: 100,418,985,984 bytes free

374 --- E O F --- 2008-07-09 07:02:35
  • 0

#8
liebermojo

liebermojo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Here is the Hijack log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:58:59 PM, on 7/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 169.254.35.38
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766b-9f49-4854-8034-f6ee26fcb1ec} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: mysidesearch search enhancer - {942f9ded-e62a-0100-86ee-93e9d6be1fd5} - C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll
O2 - BHO: AVG Security Toolbar - {a057a204-bacc-4d26-9990-79a187e2698e} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O2 - BHO: STOPzilla Browser Helper Object - {e3215f20-3212-11d6-9f8b-00d0b743919d} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [sunjavaupdatesched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [sigmatelsystrayapp] stsystra.exe
O4 - HKLM\..\Run: [realtray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [quicktime task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [onecareui] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [mskdetectorexe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [logmein gui] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [ituneshelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [isusscheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [isuspm startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [google desktop search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ehtray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [dmxlauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [atipta] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [adobe photo downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [myspaceim] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [msmsgs] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [dw6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - Startup: Event Reminder.lnk = C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O15 - Trusted Zone: *.amaena.com
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://mfr.mlxchange...ectComboBox.cab
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://mfr.mlxchange...ClientUtils.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://mfr.mlxchange...ol/IRCSharc.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai...5/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v6.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logme...trl.cab?lmi=100
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Eset HTTP Server (ehttpsrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O24 - Desktop Component 0: (no name) - http://images.google...0px-Hottest.jpg
O24 - Desktop Component 1: (no name) - http://www.wwe.com/s...rphotos/999.jpg

--
End of file - 12281 bytes
  • 0

#9
liebermojo

liebermojo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
sorry. I just realized that I did not recovery console installed. I just installed it and I'm getting ready to run combofix and hijakthis and post the logs
  • 0

#10
liebermojo

liebermojo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Okay here is the updated log for Combofix.

Here is the new combofix log:

ComboFix 08-07-09.5 - T.J 2008-07-10 18:50:59.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.494 [GMT -4:00]
Running from: C:\Documents and Settings\T.J\Desktop\ComboFix.exe
* Resident AV is active

.

((((((((((((((((((((((((( Files Created from 2008-06-10 to 2008-07-10 )))))))))))))))))))))))))))))))
.

2008-07-10 17:15 . 2008-07-10 18:56 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-10 17:15 . 2008-07-10 17:15 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-10 17:14 . 2008-07-10 18:56 58,476 --ah----- C:\WINDOWS\system32\drivers\cd2e4d3f.sys.szcpf.szcpf
2008-07-09 19:53 . 2008-07-10 18:56 58,476 --ah----- C:\WINDOWS\system32\drivers\cd2e4d3f.sys.szcpf
2008-07-09 19:26 . 2008-07-10 17:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SITEguard
2008-07-09 19:26 . 2008-07-10 17:18 6,792 --a------ C:\WINDOWS\system32\drivers\kgpcpy.cfg
2008-07-09 19:25 . 2008-07-09 19:25 <DIR> d-------- C:\Program Files\STOPzilla!
2008-07-09 19:25 . 2008-07-09 19:25 <DIR> d-------- C:\Program Files\Common Files\iS3
2008-07-09 19:25 . 2008-07-10 18:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-07-09 19:00 . 2008-07-09 19:00 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-09 16:24 . 2008-07-09 16:24 <DIR> d-------- C:\Deckard
2008-07-09 13:56 . 2008-07-10 03:01 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-09 13:50 . 2008-07-10 08:53 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-09 13:50 . 2008-07-09 13:50 <DIR> d-------- C:\Program Files\AVG
2008-07-09 13:50 . 2008-07-10 17:37 <DIR> d-------- C:\Documents and Settings\T.J\Application Data\AVGTOOLBAR
2008-07-09 13:50 . 2008-07-09 13:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-09 13:50 . 2008-07-09 13:50 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-09 13:50 . 2008-07-09 13:50 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-09 13:50 . 2008-07-09 13:50 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-08 19:34 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-07-08 19:34 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-07-08 19:34 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-07-08 19:21 . 2007-11-27 22:56 116,416 --a------ C:\WINDOWS\system32\drivers\msfwhlpr.sys
2008-07-08 19:21 . 2007-11-27 22:56 91,328 --a------ C:\WINDOWS\system32\drivers\msfwdrv.sys
2008-07-08 19:19 . 2008-07-08 19:19 <DIR> d-------- C:\WINDOWS\system32\bits
2008-07-08 19:19 . 2007-03-29 08:56 409,600 --------- C:\WINDOWS\system32\dllcache\qmgr.dll
2008-07-08 19:19 . 2008-05-15 16:15 53,168 --a------ C:\WINDOWS\system32\drivers\MpFilter.sys
2008-07-08 19:19 . 2007-03-29 08:56 18,944 --------- C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2008-07-08 19:19 . 2007-03-29 08:56 8,192 --------- C:\WINDOWS\system32\dllcache\bitsprx2.dll
2008-07-08 19:19 . 2007-03-29 08:56 7,168 --------- C:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-07-08 19:19 . 2007-03-29 08:56 7,168 --------- C:\WINDOWS\system32\dllcache\bitsprx3.dll
2008-07-08 19:19 . 2007-03-29 08:56 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll
2008-07-08 19:14 . 2008-07-10 09:00 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-07-08 18:17 . 2008-07-08 18:17 36,079 --a------ C:\WINDOWS\alaredun.ini
2008-07-08 00:21 . 2008-07-08 00:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-07-07 23:48 . 2008-07-08 19:02 <DIR> d-------- C:\Documents and Settings\T.J\Application Data\Azureus
2008-07-07 23:48 . 2008-07-07 23:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-07-07 20:36 . 2008-07-07 20:36 <DIR> d-------- C:\Program Files\Alwil Software
2008-07-07 20:24 . 2008-07-07 20:24 2,879,724 --ahs---- C:\WINDOWS\system32\mouymjwe.tmp
2008-07-07 18:11 . 2008-07-08 19:34 110,463 --a------ C:\WINDOWS\BM9b2700e8.xml
2008-07-07 17:05 . 2008-07-10 17:47 <DIR> d-------- C:\Program Files
2008-07-07 13:09 . 2008-07-07 21:35 <DIR> d-------- C:\WINDOWS\system32\4808
2008-07-07 12:38 . 2008-07-07 12:38 152,184 --a------ C:\WINDOWS\system32\g87.exe
2008-07-07 12:38 . 2008-07-07 20:25 64,332 --a------ C:\WINDOWS\system32\dpbybkqyhvedhks.exe
2008-07-07 12:12 . 2008-07-07 12:12 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-07-07 12:11 . 2008-07-07 12:11 <DIR> d-------- C:\Program Files\AskSBar
2008-07-07 12:10 . 2008-07-07 23:51 <DIR> d-------- C:\Program Files\Vuze
2008-07-07 12:02 . 2008-07-07 21:28 <DIR> d-------- C:\WINDOWS\VC5K
2008-07-07 12:02 . 2008-07-07 21:28 <DIR> d-------- C:\WINDOWS\system32\tfig
2008-07-07 12:02 . 2008-07-08 19:02 <DIR> d-------- C:\WINDOWS\system32\olixds01
2008-07-07 12:02 . 2008-07-07 21:27 <DIR> d-------- C:\WINDOWS\system32\net
2008-07-07 12:02 . 2008-07-07 22:33 <DIR> d-------- C:\WINDOWS\system32\cREG
2008-07-07 12:02 . 2008-07-07 22:32 <DIR> d-------- C:\WINDOWS\system32\1030
2008-07-07 12:02 . 2008-07-07 12:02 <DIR> d-------- C:\Temp\stmpv4
2008-07-07 12:02 . 2008-07-10 17:45 <DIR> d-------- C:\Temp
2008-07-07 12:02 . 2008-07-07 12:02 167,976 --------- C:\WINDOWS\system32\drivers\core.cache.dsk
2008-07-07 12:02 . 2008-07-08 00:04 90,922 --a------ C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll-uninst.exe
2008-07-07 10:49 . 2008-07-07 10:39 <DIR> d-------- C:\kav
2008-07-06 22:14 . 2008-07-08 19:01 <DIR> d-------- C:\Program Files\Spyware Doctor Enterprise Server
2008-07-06 22:13 . 2008-07-06 22:13 <DIR> d-------- C:\PC Tools Spyware Doctor Enterprise
2008-07-06 21:59 . 2008-07-08 00:15 <DIR> d-------- C:\Program Files\XoftSpySE
2008-07-06 21:39 . 2008-07-06 21:39 75 --a------ C:\WINDOWS\st_affiliate.ini
2008-07-06 21:35 . 2008-07-07 10:42 <DIR> d-------- C:\Program Files\CyberDefender
2008-07-06 21:18 . 2008-07-07 21:25 <DIR> d-------- C:\WINDOWS\system32\734914
2008-07-06 21:18 . 2008-07-10 19:00 58,476 --a------ C:\WINDOWS\system32\drivers\cd2e4d3f.sys
2008-07-03 15:41 . 2008-07-03 15:41 258,048 -ra------ C:\WINDOWS\system32\SZBase5.dll
2008-07-03 10:45 . 2008-07-03 10:45 364,544 --a------ C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll
2008-06-29 17:25 . 2008-06-29 17:40 4,681,449,472 --a------ C:\SPIDERWICK _AC_D1_169.ISO
2008-06-28 21:49 . 2008-06-28 21:49 8,433 --a------ C:\SPIDERWICK_AC_D1_169.MDS
2008-06-28 21:34 . 2008-06-28 21:49 7,506,722,816 --a------ C:\SPIDERWICK_AC_D1_169.ISO
2008-06-26 11:20 . 2008-06-26 11:20 <DIR> d-------- C:\WINDOWS\Cache
2008-06-26 11:20 . 2008-06-26 11:20 <DIR> d-------- C:\Program Files\Coupons
2008-06-26 11:20 . 2008-06-26 11:20 206,168 -ra------ C:\WINDOWS\system32\cpnprt2.cid
2008-06-26 10:56 . 2008-06-26 10:56 364,544 -ra------ C:\WINDOWS\system32\IS3DBA5.dll
2008-06-26 10:56 . 2008-06-26 10:56 126,976 -ra------ C:\WINDOWS\system32\IS3HTUI5.dll
2008-06-26 10:55 . 2008-06-26 10:55 372,736 -ra------ C:\WINDOWS\system32\IS3UI5.dll
2008-06-26 10:55 . 2008-06-26 10:55 61,440 -ra------ C:\WINDOWS\system32\IS3Hks5.dll
2008-06-26 10:55 . 2008-06-26 10:55 23,040 -ra------ C:\WINDOWS\system32\IS3XDat5.dll
2008-06-26 10:54 . 2008-06-26 10:54 196,608 -ra------ C:\WINDOWS\system32\IS3Win325.dll
2008-06-26 10:54 . 2008-06-26 10:54 94,208 -ra------ C:\WINDOWS\system32\IS3Inet5.dll
2008-06-26 10:54 . 2008-06-26 10:54 90,112 -ra------ C:\WINDOWS\system32\IS3Svc5.dll
2008-06-26 10:50 . 2008-06-26 10:50 708,608 -ra------ C:\WINDOWS\system32\IS3Base5.dll
2008-06-20 13:41 . 2008-06-20 13:41 245,248 --------- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 06:44 . 2008-06-20 06:44 138,368 --------- C:\WINDOWS\system32\dllcache\afd.sys
2008-06-19 09:53 . 2008-06-19 09:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogMeIn
2008-06-11 05:38 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 05:38 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-10 22:59 --------- d-----w C:\Documents and Settings\T.J\Application Data\OpenOffice.org2
2008-07-10 21:57 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-07-10 19:02 6,686 ----a-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-07-10 18:05 --------- d-----w C:\Program Files\LogMeIn
2008-07-08 21:21 --------- d-----w C:\Documents and Settings\T.J\Application Data\AdobeUM
2008-07-08 12:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-07-08 06:52 --------- d-----w C:\Program Files\Kodak
2008-07-08 04:21 --------- d-----w C:\Program Files\ESET
2008-07-08 04:15 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-08 04:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-08 04:14 --------- d-----w C:\Program Files\Kaspersky Lab
2008-07-03 19:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\alamode
2008-06-29 21:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-18 17:32 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-06-18 17:32 278,528 ------w C:\WINDOWS\MBWSetup.exe
2008-06-16 17:48 849,144 ----a-w C:\WINDOWS\system32\auroraupgrade.dll
2008-06-16 14:24 --------- d-----w C:\Program Files\The Weather Channel FW
2008-06-02 14:52 849,144 ----a-w C:\WINDOWS\system32\wtapi.exe
2008-05-30 18:52 3,921,264 ----a-w C:\WINDOWS\system32\adbilling.dll
2008-05-28 16:33 83,288 ----a-w C:\WINDOWS\system32\LMIRfsClientNP.dll
2008-05-28 16:32 87,352 ----a-w C:\WINDOWS\system32\LMIinit.dll
2008-05-28 16:32 24,608 ----a-w C:\WINDOWS\system32\LMIport.dll
2008-05-28 16:32 23,736 ----a-w C:\WINDOWS\system32\lmimirr.dll
2008-05-28 16:32 10,040 ----a-w C:\WINDOWS\system32\lmimirr2.dll
2008-05-20 19:31 1,574,136 ----a-w C:\WINDOWS\system32\wtusers.dll
2008-05-20 17:16 500,984 ----a-w C:\WINDOWS\system32\alabilling.dll
2008-05-19 18:09 3,069,176 ----a-w C:\WINDOWS\system32\alacontacts.dll
2008-05-13 14:03 34,432 ----a-r C:\WINDOWS\system32\drivers\SZKG.sys
2008-05-08 17:12 1,398,008 ----a-w C:\WINDOWS\system32\wtfiles.dll
2008-05-08 12:28 202,752 ------w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 04:55 1,288,192 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-24 02:16 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:40 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 07:39 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-20 05:07 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-04-15 16:25 681,208 ----a-w C:\WINDOWS\system32\openreport.exe
2008-04-11 14:27 3,532,144 ----a-w C:\WINDOWS\system32\filecabinet5.dll
2006-05-11 13:52 630,784 ----a-w C:\Documents and Settings\T.J\chatlnk.exe
.

((((((((((((((((((((((((((((( [email protected]_17.55.49.96 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-10 21:49:27 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-10 22:56:30 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{942f9ded-e62a-0100-86ee-93e9d6be1fd5}]
2008-07-03 10:45 364544 --a------ C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 06:00 15360]
"myspaceim"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2006-11-16 17:42 1327104]
"msmsgs"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 17:22 3739648]
"dw6"="C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2008-06-10 16:18 785520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"sunjavaupdatesched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 18:48 32881]
"realtray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-04-17 08:12 26112]
"quicktime task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
"onecareui"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2008-06-25 06:48 67112]
"mskdetectorexe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 20:05 1117184]
"logmein gui"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03 63048]
"ituneshelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 13:10 267048]
"isusscheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"isuspm startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44 249856]
"google desktop search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-04-17 08:21 169472]
"ehtray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 15:01 67584]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072]
"dmxlauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 04:12 94208]
"dla"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"atipta"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 22:05 344064]
"adobe photo downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-09 13:50 1232152]
"sigmatelsystrayapp"="stsystra.exe" [2005-03-23 00:20 339968 C:\WINDOWS\stsystra.exe]

C:\Documents and Settings\T.J\Start Menu\Programs\Startup\
Event Reminder.lnk - C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE [2007-12-29 21:31:43 325632]
OpenOffice.org 2.1.lnk - C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe [2006-11-27 17:45:48 393216]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-17 08:10:11 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\lmiinit]
2008-05-28 12:32 87352 C:\WINDOWS\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\onecaremp]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"KodakCCS"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\a la mode\\Sched\\eSched.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

R0 szkg5;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys [2008-05-13 10:03]
R1 avgldx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-09 13:50]
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-09 13:50]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-09 13:50]
R2 avgtdix;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-09 13:50]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2008-02-28 15:31]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2008-03-07 13:39]
R2 ochealthmon;Windows Live OneCare Health Monitor;C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe [2008-06-25 06:47]
S3 marsqx5;Digital Blue QX5 V2 Microscope;C:\WINDOWS\system32\DRIVERS\marsqx5.sys [2007-04-02 16:02]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-07-10 16:15:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-10 18:57:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe
-> C:\PROGRA~1\Google\GOOGLE~1\GOA66E~1.DLL
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\LogMeIn\x86\ramaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.bin
C:\WINDOWS\system32\locator.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\verclsid.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-07-10 19:03:35 - machine was rebooted [T.J]
ComboFix-quarantined-files.txt 2008-07-10 23:03:23
ComboFix2.txt 2008-07-10 21:56:42

Pre-Run: 100,387,332,096 bytes free
Post-Run: 100,369,707,008 bytes free

279 --- E O F --- 2008-07-09 07:02:35
  • 0

Advertisements


#11
liebermojo

liebermojo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
And here is the updated HijackThis log

The new hijack log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:07:01 PM, on 7/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 169.254.35.38
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766b-9f49-4854-8034-f6ee26fcb1ec} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: mysidesearch search enhancer - {942f9ded-e62a-0100-86ee-93e9d6be1fd5} - C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll
O2 - BHO: AVG Security Toolbar - {a057a204-bacc-4d26-9990-79a187e2698e} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O2 - BHO: STOPzilla Browser Helper Object - {e3215f20-3212-11d6-9f8b-00d0b743919d} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [sunjavaupdatesched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [sigmatelsystrayapp] stsystra.exe
O4 - HKLM\..\Run: [realtray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [quicktime task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [onecareui] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [mskdetectorexe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [logmein gui] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [ituneshelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [isusscheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [isuspm startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [google desktop search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ehtray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [dmxlauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [atipta] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [adobe photo downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [myspaceim] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [msmsgs] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [dw6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - Startup: Event Reminder.lnk = C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O15 - Trusted Zone: *.amaena.com
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://mfr.mlxchange...ectComboBox.cab
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://mfr.mlxchange...ClientUtils.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://mfr.mlxchange...ol/IRCSharc.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai...5/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v6.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logme...trl.cab?lmi=100
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Eset HTTP Server (ehttpsrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O24 - Desktop Component 0: (no name) - http://images.google...0px-Hottest.jpg
O24 - Desktop Component 1: (no name) - http://www.wwe.com/s...rphotos/999.jpg

--
End of file - 12281 bytes
  • 0

#12
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
ok, its past midnight here so in this post we will clear some of the malware i can see and run a couple of scans which should catch the vast majority of what is left and then do an online scan to see where we stand.

the scans will likely take 3 hours, quite possibly much longer. so just let them run.

firstly, do you recognise these which are on your desktop? if not, we can quite easily remove them.
O24 - Desktop Component 0: (no name) - http://images.google...0px-Hottest.jpg
O24 - Desktop Component 1: (no name) - http://www.wwe.com/s...rphotos/999.jpg



====STEP 1====
Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.



====STEP 2====
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



====STEP 3====
Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.



====STEP 4====
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll
C:\WINDOWS\system32\mouymjwe.tmp
C:\WINDOWS\BM9b2700e8.xml
C:\WINDOWS\system32\g87.exe
C:\WINDOWS\system32\dpbybkqyhvedhks.exe
C:\WINDOWS\system32\drivers\cd2e4d3f.sys

Folder::
C:\WINDOWS\system32\734914

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{942f9ded-e62a-0100-86ee-93e9d6be1fd5}]
[-HKEY_CLASSES_ROOT\CLSID\{942f9ded-e62a-0100-86ee-93e9d6be1fd5}]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.amaena.com]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}]
[-HKEY_CLASSES_ROOT\CLSID\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.



====STEP 5====
Please do an online scan with Kaspersky WebScanner

Click on Accept

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

In your next reply could i see:
1. the answer to the desktop question
2. the malwarebytes log
3. the SUPERantispyware log
4. the combofix log
5. a new hijackthis log
6. the kaspersky scan log

feel free to post the logs as you get them, i will wait until the kaspersky scan log is posted before i proceed.

The text from these files may exceed the maximum post length for this forum. Hence, you may need to post the information over 2 or more posts.

andrewuk
  • 0

#13
liebermojo

liebermojo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts

firstly, do you recognise these which are on your desktop? if not, we can quite easily remove them.
O24 - Desktop Component 0: (no name) - http://images.google...0px-Hottest.jpg
O24 - Desktop Component 1: (no name) - http://www.wwe.com/s...rphotos/999.jpg


I have no idea what those are soooooooo, I probably don't need them or want them.

I'm in florida it's 9:00pm here and my eyes are stating to burn so you must be tired. If it's alright with you, I'll let the first step run and pick up tomorrow after work. Thank you again for all your help.

Jon
  • 0

#14
liebermojo

liebermojo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
This is the Malwarebytes log:


Malwarebytes' Anti-Malware 1.20
Database version: 938
Windows 5.1.2600 Service Pack 2

12:03:45 AM 7/11/2008
mbam-log-7-11-2008 (00-03-45).txt

Scan type: Full Scan (C:\|)
Objects scanned: 120411
Time elapsed: 52 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 13
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 10

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet
Explorer\SearchScopes\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6}
(Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca}
(Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe}
(Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1}
(Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) ->
Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) ->
Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a}
(Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution
Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) ->
Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Installer\UpgradeCodes\7c673a5b871b8cd419f47dd0de5a6d18
(Rogue.AdwareAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCo
des\7c673a5b871b8cd419f47dd0de5a6d18
(Rogue.AdwareAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\e405.e405mgr (Trojan.Zlob) -> Quarantined and
deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\The Weather Channel (Adware.Hotbar) ->
Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Weather
Services (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c
:\program
files\adwarealert\ (Rogue.AdwareAlert) -> Quarantined and deleted
successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c
:\program
files\adwarealert\filterdrv\ (Rogue.AdwareAlert) -> Quarantined and
deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control
Panel\Cpls\wxfw.dll (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\system32\734914 (Trojan.BHO) -> Quarantined and deleted
successfully.
C:\Documents and Settings\All Users\Start
Menu\Programs\AntiSpywareMaster (Rogue.AntiSpywareMaster) -> Quarantined
and deleted successfully.

Files Infected:
C:\QooBox\Quarantine\C\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe.vir
(Adware.BHO) -> Quarantined and deleted successfully.
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP9\A0002399.exe
(Adware.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start
Menu\Programs\AntiSpywareMaster\AntiSpywareMaster.lnk
(Rogue.AntiSpywareMaster) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start
Menu\Programs\AntiSpywareMaster\Uninstall AntiSpywareMaster.lnk
(Rogue.AntiSpywareMaster) -> Quarantined and deleted successfully.
C:\WINDOWS\msserv.c (Worm.Zhelatin) -> Quarantined and deleted successfully.
C:\WINDOWS\msserv.s (Worm.Zhelatin) -> Quarantined and deleted successfully.
C:\WINDOWS\msserv.z (Worm.Zhelatin) -> Quarantined and deleted successfully.
C:\WINDOWS\BM9b2700e8.xml (Trojan.Vundo) -> Quarantined and deleted
successfully.
C:\WINDOWS\BM9b2700e8.txt (Trojan.Vundo) -> Quarantined and deleted
successfully.
C:\WINDOWS\system32\drivers\core.cache.dsk (Malware.Trace) ->
Quarantined and deleted successfully.
  • 0

#15
liebermojo

liebermojo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Here is the SUPERAntispyware log:



SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/11/2008 at 00:36 AM

Application Version : 4.15.1000

Core Rules Database Version : 3502
Trace Rules Database Version: 1493

Scan type : Complete Scan
Total Scan Time : 00:24:37

Memory items scanned : 569
Memory threats detected : 0
Registry items scanned : 6316
Registry threats detected : 6
File items scanned : 19910
File threats detected : 10

Browser Hijacker.Internet Explorer Zone Hijack

HKU\s-1-5-21-3408404406-10034920-175005908-1005\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Internet
Settings\ZoneMap\Domains\amaena.com

HKU\s-1-5-21-3408404406-10034920-175005908-1005\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Internet
Settings\ZoneMap\Domains\amaena.com#*

HKU\s-1-5-21-3408404406-10034920-175005908-1005\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Internet
Settings\ZoneMap\Domains\amaena.com\www

HKU\s-1-5-21-3408404406-10034920-175005908-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\Domains\amaena.com\www#*

Browser Hijacker.Internet Explorer Settings Hijack
HKU\.default\Software\Microsoft\Internet
Explorer\Main#Default_Search_URL [ http://internetsearchservice.com ]
HKU\s-1-5-18\Software\Microsoft\Internet
Explorer\Main#Default_Search_URL [ http://internetsearchservice.com ]

Worm.Spam-Strato
C:\WINDOWS\msserrv32.dat

Adware.Tracking Cookie
C:\Deckard\System
Scanner\20080709170350\backup\DOCUME~1\T.J\LOCALS~1\TEMP\Cookies\[email protected]
upromotes[1].txt
C:\Deckard\System
Scanner\20080709170350\backup\WINDOWS\temp\Cookies\[email protected][2].txt
C:\Deckard\System
Scanner\20080709170350\backup\WINDOWS\temp\Cookies\[email protected][1].txt
statse.webtrendslive.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.ad.yieldmanager.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.ad.yieldmanager.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.fastclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.fastclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.fastclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.fastclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.zedo.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
ads.revsci.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.atdmt.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.dealtime.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.zedo.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.zedo.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.zedo.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.dealtime.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.dealtime.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.dealtime.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.dealtime.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.dealtime.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.dealtime.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
stat.dealtime.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.doubleclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.overture.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.overture.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.overture.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.hitbox.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.hitbox.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.ehg-netquote.hitbox.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
data.coremetrics.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.realmedia.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.tribalfusion.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.realmedia.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.realmedia.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.realmedia.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.realmedia.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.adrevolver.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.adrevolver.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
media.adrevolver.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
media.adrevolver.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
media.adrevolver.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
media.adrevolver.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.adrevolver.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.adrevolver.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.avgtechnologies.112.2o7.net [ C:\Documents and
Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
www.findyour-replacementwindows.com [ C:\Documents and
Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
www.findyour-replacementwindows.com [ C:\Documents and
Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.countrywide.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
loans.countrywide.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.burstnet.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
ssl.clickfacts.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
loans.countrywide.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.questionmarket.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.questionmarket.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.questionmarket.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
www.directnetadvertising.net [ C:\Documents and
Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
www.directnetadvertising.net [ C:\Documents and
Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.247realmedia.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
anat.tacoda.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.apmebf.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.apmebf.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
sales.liveperson.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
sales.liveperson.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.atlas.entrepreneur.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.entrepreneur.122.2o7.net [ C:\Documents and
Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.statcounter.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.statcounter.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.statcounter.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
ads.bridgetrack.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
ads.bridgetrack.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
ads.bridgetrack.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
media.vlzserver.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
media.vlzserver.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
tremor.adbureau.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.tremor.adbureau.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
m.rmbclick.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.sixapart.adbureau.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
rotator.adjuggler.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
rotator.adjuggler.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.toplist.cz [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.adopt.euroclick.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.adopt.euroclick.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.ads.clicksor.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.atwola.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.blockbuster.112.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.bookspan.122.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.collective-media.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.collective-media.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.collective-media.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.collective-media.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.couponchief.122.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.directhomediscount.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.iacas.adbureau.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.interclick.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.interclick.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.interclick.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.interclick.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.interclick.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.interclick.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.kanoodle.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.levelwing.112.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.media6degrees.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.media6degrees.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.media6degrees.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.myroitracking.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.nielsen.112.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.partner2profit.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.partner2profit.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.partner2profit.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.partner2profit.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.partner2profit.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.rc2corp.112.2o7.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.redorbit.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.redorbit.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.redorbit.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.tracking.foxnews.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.tracking.foxnews.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.usenext.de [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.usenext.de [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.usenext.de [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
.usenext.de [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
anad.tacoda.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
citi.bridgetrack.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
optimize.indieclick.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
sec1.liveperson.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
sec1.liveperson.net [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
server.iad.liveperson.net [ C:\Documents and
Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
web4.realtracker.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
www.accountonline.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
www.accountonline.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
www.clickmanage.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
www.clickmanage.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
www.directhomediscount.com [ C:\Documents and
Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
www.googleadservices.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
www.googleadservices.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
www.googleadservices.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]
www.googleadservices.com [ C:\Documents and Settings\T.J\Application
Data\Mozilla\Firefox\Profiles\c1hop3zm.default\cookies.txt ]

NotHarmful.Sysinternals Bluescreen Screen Saver
C:\SYSTEM VOLUME
INFORMATION\_RESTORE{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP5\A0000179.SCR
C:\SYSTEM VOLUME
INFORMATION\_RESTORE{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP8\A0002260.SCR

Rogue.MalwareProtector/Variant
C:\SYSTEM VOLUME
INFORMATION\_RESTORE{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP7\A0002251.EXE

Adware.AdRotate/System
C:\SYSTEM VOLUME
INFORMATION\_RESTORE{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP9\A0002409.DLL
C:\SYSTEM VOLUME
INFORMATION\_RESTORE{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP9\A0002410.DLL

Rootkit.Rustock/Variant
C:\WINDOWS\SYSTEM32\DRIVERS\CD2E4D3F.SYS
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP