Thank you for your reply Crustyoldbloke...
I really appreciate your great help! I know some of you guys here are volunteers, so i am patient enough to wait for your reply... Im not a computer genius so im trying to understand your intstructions & reccomendations as far as i can & i hope i did the right thing on my part...
By the way, this PC im using is an Office PC & i am the only one who's using this... before there was somebody using this when i was not here in this company... And I never use this PC on any Online Banking...
You noted in your reply, when i perform the Killbox procedure... when I saw a Prompt "PendingFileRename Operations" i will tell you this thing... And When I accomplish it, i saw that prompt message when im done deleting those file you told me to delete...
One thing more... the Virtumonde Adware are still infecting my files... my NOD32 still detects that Adware in my PC...
Here are the Logs you needed to check (3 Logs in total):
____________________________________________________________
>> AVG Anti-spyware---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 9:23:36 PM 5/1/2007
+ Scan result:
C:\Program Files\Eset\infected\ZHEH0PDA.NQF -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1443\A0123158.dll -> Adware.Agent : Cleaned with backup (quarantined).
HKU\S-1-5-21-1259100097-596128907-3717492054-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{59879FA4-4790-461C-A1CC-4EC4DE4CA483} -> Adware.RXToolbar : Cleaned with backup (quarantined).
C:\Program Files\Yahoo!\Messenger\ycomp.dll -> Adware.Yahoo : Cleaned with backup (quarantined).
C:\Program Files\Foxit Software\PDF Editor\patch.exe -> Downloader.Harnig.bq : Cleaned with backup (quarantined).
C:\Program Files\bip\PROGRAMS\Foxit ( PDF reader,editor,creator) pack completo\Foxit PDF Editor 1.5\patch.exe -> Downloader.Harnig.bq : Cleaned with backup (quarantined).
C:\Program Files\bip\PROGRAMS\Norton Antivirus 2007 + KeyGen\Norton Antivirus 2007 + KeyGen.zip/Keygen.zip/Keygen.exe -> Dropper.Agent.bcw : Cleaned with backup (quarantined).
C:\Program Files\bip\PROGRAMS\Norton Antivirus 2007 + KeyGen\Norton Antivirus 2007 + KeyGen\Keygen\Keygen.exe -> Dropper.Agent.bcw : Cleaned with backup (quarantined).
C:\Program Files\bip\PROGRAMS\Norton Antivirus 2007 + KeyGen\Norton Antivirus 2007 + KeyGen\Keygen\Keygen.zip/Keygen.exe -> Dropper.Agent.bcw : Cleaned with backup (quarantined).
C:\Documents and Settings\Bahar\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Bahar\Cookies\
[email protected][1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Bahar\Cookies\bahar@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Bahar\Cookies\
[email protected][2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Bahar\Cookies\bahar@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Bahar\Cookies\bahar@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Bahar\Cookies\
[email protected][1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Bahar\Cookies\bahar@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Bahar\Cookies\bahar@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Bahar\Cookies\
[email protected][2].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Bahar\Cookies\
[email protected][1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Bahar\Cookies\bahar@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Bahar\Cookies\
[email protected][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Bahar\Cookies\
[email protected][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Bahar\Cookies\bahar@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Bahar\Cookies\bahar@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Bahar\Cookies\bahar@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Bahar\Cookies\
[email protected][1].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Bahar\Cookies\
[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1444\A0125207.exe -> Trojan.Agent : Cleaned with backup (quarantined).
::Report end
____________________________________________________________
>> Combofix"Bahar" - 07-05-01 21:40:27 Service Pack 2
ComboFix 07-04-28.V - Running from: "C:\Documents and Settings\Bahar\Desktop\GEEKS\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\install.log
C:\install.log
((((((((((((((((((((((((((((((( Files Created from 2007-04-01 to 2007-05-01 ))))))))))))))))))))))))))))))))))
2007-05-01 21:31 <DIR> d-------- C:\Program Files\CCleaner
2007-05-01 20:46 552 --a------ C:\WINDOWS\SYSTEM32\d3d8caps.dat
2007-05-01 09:50 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-05-01 07:12 <DIR> d-------- C:\!KillBox
2007-04-30 22:51 <DIR> d-------- C:\Program Files\DivX
2007-04-30 17:40 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2007-04-30 16:41 <DIR> d-------- C:\Program Files\Foxit Software
2007-04-30 16:38 0 --a------ C:\WINDOWS\SYSTEM32\CMMGR32.EXE
2007-04-30 16:38 0 --a------ C:\WINDOWS\ORUN32.EXE
2007-04-30 16:28 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-04-30 16:28 <DIR> d-------- C:\DOCUME~1\Bahar\APPLIC~1\SUPERAntiSpyware.com
2007-04-30 16:28 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-04-30 16:27 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-04-30 09:38 <DIR> d-------- C:\VundoFix Backups
2007-04-30 09:35 132,660 --a------ C:\WINDOWS\SYSTEM32\rcwaguol.dll
2007-04-30 09:35 123,972 --a------ C:\WINDOWS\SYSTEM32\pbpsrujg.dll
2007-04-29 11:57 684,032 --a------ C:\WINDOWS\SYSTEM32\libeay32.dll
2007-04-29 11:57 155,648 --a------ C:\WINDOWS\SYSTEM32\ssleay32.dll
2007-04-22 15:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
2007-04-21 15:26 <DIR> d-------- C:\Program Files\MTV Networks
2007-04-21 15:00 <DIR> d-------- C:\Program Files\iTunes
2007-04-21 15:00 <DIR> d-------- C:\Program Files\iPod
2007-04-21 15:00 <DIR> d-------- C:\DOCUME~1\Bahar\APPLIC~1\Apple Computer
2007-04-21 14:59 <DIR> d-------- C:\Program Files\QuickTime
2007-04-21 14:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-04-21 14:52 <DIR> d-------- C:\Program Files\Common Files\xing shared
2007-04-21 14:52 <DIR> d-------- C:\Program Files\Common Files\Real
2007-04-21 14:51 <DIR> d-------- C:\DOCUME~1\Bahar\APPLIC~1\Real
2007-04-18 15:57 512,096 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\amon.sys
2007-04-18 15:57 298,104 --a------ C:\WINDOWS\SYSTEM32\imon.dll
2007-04-18 15:57 15,424 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\nod32drv.sys
2007-04-18 14:03 <DIR> d-------- C:\WINDOWS\pss
2007-04-18 08:47 353 ---hs---- C:\WINDOWS\SYSTEM32\oqtss.ini2
2007-04-16 18:24 339,968 --a------ C:\WINDOWS\SYSTEM32\mpiwin32.dll
2007-04-16 18:24 15,840 --a------ C:\WINDOWS\SYSTEM32\Machnm1.exe
2007-04-16 18:24 <DIR> d-------- C:\Program Files\@Last Software
2007-04-10 20:59 <DIR> d-------- C:\Program Files\AutoCAD 2008
2007-04-05 08:25 <DIR> d-------- C:\Program Files\Nero
2007-04-05 08:16 <DIR> d-------- C:\Program Files\AskTBar
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-01 20:21 288 --a------ C:\WINDOWS\SYSTEM32\dvcstatebkp-{00000004-00000000-00000002-00001102-00000004-10031102}.dat
2007-05-01 20:21 288 --a------ C:\WINDOWS\SYSTEM32\dvcstate-{00000004-00000000-00000002-00001102-00000004-10031102}.dat
2007-05-01 06:21 -------- d-------- C:\DOCUME~1\Bahar\APPLIC~1\azureus
2007-04-30 21:35 -------- d-------- C:\Program Files\windows live toolbar
2007-04-30 21:34 -------- d--h----- C:\Program Files\poweriso
2007-04-30 21:34 -------- d-------- C:\Program Files\windows defender
2007-04-30 21:19 -------- d-------- C:\Program Files\bonjour
2007-04-30 21:19 -------- d-------- C:\Program Files\bit lord 1.1
2007-04-29 13:09 -------- d--h----- C:\Program Files\bip
2007-04-27 16:46 132660 --a------ C:\WINDOWS\SYSTEM32\rcwaguol.vdll
2007-04-27 07:26 -------- d-------- C:\Program Files\azureus
2007-04-25 09:39 123972 --a------ C:\WINDOWS\SYSTEM32\vbqrqvas.vdll
2007-04-25 09:39 123972 --a------ C:\WINDOWS\SYSTEM32\uvrdmdmi.vdll
2007-04-25 09:39 123972 --a------ C:\WINDOWS\SYSTEM32\ululeihj.vdll
2007-04-25 09:39 123972 --a------ C:\WINDOWS\SYSTEM32\thidmfgs.vdll
2007-04-25 09:37 123972 --a------ C:\WINDOWS\SYSTEM32\oufqeumu.vdll
2007-04-25 09:37 123972 --a------ C:\WINDOWS\SYSTEM32\msjhiiju.vdll
2007-04-25 09:37 123972 --a------ C:\WINDOWS\SYSTEM32\kkotkcsh.vdll
2007-04-25 09:37 123972 --a------ C:\WINDOWS\SYSTEM32\jyvvwxbb.vdll
2007-04-25 09:37 123972 --a------ C:\WINDOWS\SYSTEM32\jnfohvkt.vdll
2007-04-25 09:36 123972 --a------ C:\WINDOWS\SYSTEM32\hbmddhlq.vdll
2007-04-25 09:36 123972 --a------ C:\WINDOWS\SYSTEM32\gxelllek.vdll
2007-04-25 09:36 123972 --a------ C:\WINDOWS\SYSTEM32\gsuukmff.vdll
2007-04-25 09:36 123972 --a------ C:\WINDOWS\SYSTEM32\fqioivvm.vdll
2007-04-25 09:36 123972 --a------ C:\WINDOWS\SYSTEM32\dwrfplfw.vdll
2007-04-25 09:36 123972 --a------ C:\WINDOWS\SYSTEM32\dtdliepn.vdll
2007-04-25 09:36 123972 --a------ C:\WINDOWS\SYSTEM32\cevfljti.vdll
2007-04-25 09:36 123972 --a------ C:\WINDOWS\SYSTEM32\bfxaexdf.vdll
2007-04-21 14:52 -------- d-------- C:\Program Files\real
2007-04-18 15:16 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-04-18 15:16 -------- d-------- C:\DOCUME~1\Bahar\APPLIC~1\symantec
2007-04-18 15:14 -------- d-------- C:\Program Files\symantec
2007-04-16 18:24 -------- d--h----- C:\Program Files\installshield installation information
2007-04-14 08:36 -------- d-------- C:\DOCUME~1\Bahar\APPLIC~1\autodesk
2007-04-10 20:25 -------- d-------- C:\Program Files\autodesk
2007-03-30 22:09 -------- d-------- C:\DOCUME~1\Bahar\APPLIC~1\once send
2007-03-28 06:51 -------- d-------- C:\Program Files\microsoft works
2007-03-27 11:55 200704 --a------ C:\WINDOWS\SYSTEM32\ssldivx.dll
2007-03-27 11:55 1044480 --a------ C:\WINDOWS\SYSTEM32\libdivx.dll
2007-03-17 20:25 17801 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AegisP.sys
2007-03-17 17:43 292864 --a------ C:\WINDOWS\SYSTEM32\winsrv.dll
2007-03-08 19:36 577536 --a------ C:\WINDOWS\SYSTEM32\user32.dll
2007-03-08 19:36 40960 --a------ C:\WINDOWS\SYSTEM32\mf3216.dll
2007-03-08 19:36 281600 --a------ C:\WINDOWS\SYSTEM32\gdi32.dll
2007-03-08 17:47 1843584 --a------ C:\WINDOWS\SYSTEM32\win32k.sys
2007-03-01 23:09 230454 --a------ C:\StiImg.dat
2007-02-12 07:25 15976 --a------ C:\WINDOWS\SYSTEM32\acsignextres.dll
2007-02-12 07:12 54376 --a------ C:\WINDOWS\SYSTEM32\acsignopt.exe
2007-02-12 07:12 44648 --a------ C:\WINDOWS\SYSTEM32\acsignicon.dll
2007-02-12 07:12 30312 --a------ C:\WINDOWS\SYSTEM32\acsignext.dll
2007-02-06 00:17 185344 --a------ C:\WINDOWS\SYSTEM32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{02478D38-C3F9-4EFB-9B51-7695ECA05670}"="C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll"
"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"="C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll"
"{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}"="C:\Program Files\Yahoo!\Common\yiesrvc.dll"
"{5CA3D70E-1895-11CF-8E15-001234567890}"="C:\WINDOWS\system32\dla\tfswshx.dll"
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"="C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll"
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"="C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll"
"{B7154C4D-87C0-4A2C-AB64-DA132BAC2EE6}"="C:\Program Files\AnchorFree\bin\AFBho.dll"
"{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"="C:\Program Files\Windows Live Toolbar\msntb.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"IAAnotif"="\"C:\\Program Files\\Intel\\Intel Application Accelerator\\iaanotif.exe\""
"PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"IntelMeM"="\"C:\\Program Files\\Intel\\Modem Event Monitor\\IntelMEM.exe\""
"CTSysVol"="\"C:\\Program Files\\Creative\\SBAudigy2\\Surround Mixer\\CTSysVol.exe\""
"CTDVDDet"="\"C:\\Program Files\\Creative\\SBAudigy2\\DVDAudio\\CTDVDDet.EXE\""
"CTHelper"="CTHELPER.EXE"
"AsioReg"="\"REGSVR32.EXE\" /S CTASIO.DLL"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"DataLayer"="\"C:\\Program Files\\Common Files\\PCSuite\\DataLayer\\DataLayer.exe\""
"PCSuiteTrayApplication"="\"C:\\Program Files\\Nokia\\Nokia PC Suite 6\\LaunchApplication.exe\" -onlytray"
"NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"nod32kui"="\"C:\\Program Files\\Eset\\nod32kui.exe\" /WAITSERVICE"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"NeroFilterCheck"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe\""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"SB Audigy 2 Startup Menu"=" /L:ENG"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""
"SUPERAntiSpyware"="C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"{e57ce738-33e8-4c51-8354-bb4de9d215d1}"="C:\WINDOWS\system32\upnpui.dll"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7ec74f2e-bfe5-11db-99db-96eacd686393}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f016b2e2-bf62-11db-99d9-eac61f4d8eea}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-05-01 21:44:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-05-01 21:44:55
C:\ComboFix-quarantined-files.txt ... 07-05-01 21:44
05-06-27 15:16 1120 --a------ C:\Qoobox\Quarantine\C\INSTALL.LOG.vir
06-05-21 09:26 459 --a--c--- C:\Qoobox\Quarantine\C\Program Files\INSTALL.LOG.vir
Folder PATH listing
Volume serial number is 1C37-FB5B
C:\QOOBOX
\---Quarantine
+---C
| | INSTALL.LOG.vir
| |
| \---Program Files
| INSTALL.LOG.vir
|
\---Registry_backups
____________________________________________________________
>> HijackThisLogfile of HijackThis v1.99.1
Scan saved at 9:49:53 PM, on 5/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Documents and Settings\Bahar\Desktop\GEEKS\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AF BHO - {B7154C4D-87C0-4A2C-AB64-DA132BAC2EE6} - C:\Program Files\AnchorFree\bin\AFBho.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: AFToolbar - {1F385865-F3D4-41ff-960D-7B7D0A7A72F6} - C:\Program Files\AnchorFree\bin\AFToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [IntelMeM] "C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe"
O4 - HKLM\..\Run: [CTDVDDet] "C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] "REGSVR32.EXE" /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DataLayer] "C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] "C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" -onlytray
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?afdc4a8f81594853b2254498be87e4e6
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?afdc4a8f81594853b2254498be87e4e6
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) -
http://ernicole.mult...os/uploader.cabO16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Belkin High-Speed Mode Wireless G USB Driver (Belkin High-Speed Mode Wireless G USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\F5D7051\WLService.exe (file missing)
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
____________________________________________________________
Edited by twentysomething, 01 May 2007 - 12:24 PM.