This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HJT LOG

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:25:28 PM, on 2/23/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\npkcmsvc.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\ehome\McrdSvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\SMARTD~1\Messages\SDNotify.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Music Now\MusicNow.exe
C:\WINDOWS\system32\dlcjcoms.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\WebSearchBar\WebSearchBar.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CashOn\bin\ncservice07191451.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Gamevance\gamevance32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WebSearchBar\WebSearchShop.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
O2 - BHO: SPoint Class - {016D43D1-2EAD-4723-8579-88D8AB70433C} - C:\Program Files\rnic\SPBho.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Ezcashmall Class - {58881F3E-3B3B-4A7F-9413-B65E59B17060} - C:\WINDOWS\system32\ecashsave.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Gamevance Text - {7370F91F-6994-4595-9949-601FA2261C8D} - C:\Program Files\Gamevance\gvtl.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {A13E6D04-17B3-40FC-B69A-C47914BA377E} - C:\PROGRA~1\CashOn\bin\NCHO12~2.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O2 - BHO: ShopPoint Class - {DA18CDFC-11E1-48e4-BFEE-775890B9AE44} - C:\Program Files\ShopPoint\ShopPoint.dll
O2 - BHO: SideBar Class - {FC91E61A-BB5E-4c63-9E43-93C3201D0E1E} - C:\Program Files\rnic\SPSbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Music Now] C:\Program Files\Music Now\MusicNow.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [WebSearchBar.exe] C:\Program Files\WebSearchBar\WebSearchBar.exe
O4 - HKLM\..\Run: [WebSearchshopUpdater] C:\Program Files\WebSearchBar\WebSearchshopUpdater.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ncservice] C:\Program Files\CashOn\bin\ncservice07191451.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\3.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Gamevance] C:\Program Files\Gamevance\gamevance32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe" /m=2 /w
O4 - HKLM\..\Run: [NCUP] C:\WINDOWS\system32\NCUP12040848.exe
O4 - HKLM\..\Run: [SPUP] C:\WINDOWS\system32\SPUPDAT10180932.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [pgo.exe] C:\Program Files\pointgo\pgo.exe
O4 - HKLM\..\Run: [MRT] "C:\WINDOWS\system32\MRT.exe" /R
O4 - HKLM\..\Run: [Cashonupdate] C:\Program Files\CashOn\bin\CashOnUpdate10171035.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZKxdm021YYUS
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: CashOn - {731B4EB2-B447-4108-86EB-6F9B6A46E576} - C:\PROGRA~1\CashOn\bin\NCBUTT~1.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {FC91E61A-BB5E-4c63-9E43-93C3201D0E1E} - (no file)
O16 - DPF: {044123B5-35DF-4C4E-BAED-26B8ED964342} (HLiveRobotWeb Control) - http://fx.hauri.net/HProduct/livesuite/shi…iveRobotWeb.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.0.cab
O16 - DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} (Nexon Package Manager Control) - http://s.nx.com/activex/public_new/nxpm.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} (Auctiva Image Uploader Control) - http://www.auctiva.com/Aurigma/ImageUploader55.cab
O16 - DPF: {39FC0CF9-86F3-4502-B773-D16706EDEC83} (SCSK Control) - http://www.shinhancard.com/common/scsk4.cab
O16 - DPF: {5DAEF053-DEF0-4752-A963-CCE9B49B0B79} (Gogs Class) - http://blog.naver.com/common/item/nbgm.cab
O16 - DPF: {6FE760D3-7851-4879-8838-62D9881D7177} (IniMasHandler Class) - http://www.letskt.com/imas/IniMasPlugin.cab
O16 - DPF: {7E9FDB80-5316-11D4-B02C-00C04F0CD404} (XecureWeb 4.0 Client Control) - http://www.samsungcard.co.kr/XecureDemo/Xe…/xw_install.cab
O16 - DPF: {8BCAB742-72F8-4119-A4B4-8F639A6E27B3} (CNaverImageUploadCtl Object) - http://photolog.blog.naver.com/NIU.CAB
O16 - DPF: {92D0D610-A6FA-48D8-94CB-BD47FDF68655} (Launcher Class) - http://app.tubemusic.com/naver/naverx.cab
O16 - DPF: {9CDD57AC-CA86-464C-B920-3228A388CC78} (NaverFileControl Control) - http://file.naver.com/down/NaverFile.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A9DD5FE2-5567-4983-971F-C792375025A6} (PhoenixBody Class) - http://software.musicnow.com/musicnow/phoe…23/MusicNow.cab
O16 - DPF: {BD6BB450-7C69-43B8-96F3-689CAE57AB51} (SBSWebPlayer Class) - http://netv.sbs.co.kr/object/player/SBSWebPlayer.cab
O16 - DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} (HanSetupCtrl1009 Class) - http://flash.hangame.com/common/HanSetup1009.cab
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://update.nprotect.net/nprotect/module/npx.cab
O16 - DPF: {D26A941D-7E89-4098-B583-43291FC14218} (Pull0PlayerX Control) - http://image.pullbbang.com/images/Pull0Control.ocx
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} - http://update.nprotect.net/keycrypt/samsun…d/npkcx_log.cab
O16 - DPF: {D7602755-1F82-4EA4-B8F8-F0FA7E8A430D} (EgisBVMActiveX Control) - http://egis.onoffkorea.com/activex/EgisBVMActiveX.cab
O16 - DPF: {E75386B4-C629-11DB-8338-444553544200} (PcubeSet Class) - http://cyimg7.cyworld.nate.com/cymusic/package/cyinstal.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.auctiva.com/hostedimages/active…oad/XUpload.ocx
O16 - DPF: {F1F07506-6CB4-44AC-8615-66D1234EFD05} (WebCtl Class) - http://www.shinhancard.com/initech/plugin/down/INIS50.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: __c004B994 - C:\WINDOWS\system32\__c004B994.dat (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Desktop Manager 5.5.709.30344 (GoogleDesktopManager-093007-112848) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c98c63cdc65d30) (gupdate1c98c63cdc65d30) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwssvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcmsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O24 - Desktop Component 0: (no name) - http://www.bungie.net/images/themes/Defaul…nBackground.gif

–
End of file - 20038 bytes

Thank you for any help you can give - this PC has Limewire, Napster, ESTsoft software (think it was downloaded from Korea).
Hi bethk,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Limewire and Napster
You have Limewire and Napster, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm


I would recommend that you uninstall Limewire and Napster, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop



**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here is the log -ComboFix.txt
ComboFix 09-02-24.01 - Kum Bryant 2009-02-24 18:06:55.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.583 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: Norton Internet Worm Protection *disabled*
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Bryant Plumbing\Local Settings\Temporary Internet Files\ISa0004.exe
c:\documents and settings\Thomas Bryant\Local Settings\Temporary Internet Files\SKBGM.cfg
c:\documents and settings\Thomas Bryant\Local Settings\Temporary Internet Files\SKBGM0.che
c:\documents and settings\Thomas Bryant\Local Settings\Temporary Internet Files\SKBGM1.che
c:\documents and settings\Thomas Bryant\Local Settings\Temporary Internet Files\SKBGM2.che
c:\documents and settings\Thomas Bryant\Local Settings\Temporary Internet Files\SKBGM3.che
c:\documents and settings\Thomas Bryant\Local Settings\Temporary Internet Files\SKBGM4.che
c:\documents and settings\Thomas Bryant\Local Settings\Temporary Internet Files\SKBGM5.che
c:\documents and settings\Thomas Bryant\Local Settings\Temporary Internet Files\SKBGM6.che
c:\documents and settings\Thomas Bryant\Local Settings\Temporary Internet Files\SKBGM7.che
c:\documents and settings\Thomas Bryant\Local Settings\Temporary Internet Files\SKBGM8.che
c:\documents and settings\Thomas Bryant\Local Settings\Temporary Internet Files\SKBGM9.che
c:\program files\Gamevance\gvtl.dll
c:\windows\system32\5rqkCemn.exe.a_a
c:\windows\system32\QTWMCI32.DLL

—– BITS: Possible infected sites —–

hxxp://th50.photobucket.com
.
((((((((((((((((((((((((( Files Created from 2009-01-25 to 2009-02-25 )))))))))))))))))))))))))))))))
.

2009-02-23 20:42 . 2009-01-18 14:35 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-02-23 19:05 . 2009-01-18 14:30 64,160 –a—— c:\windows\system32\drivers\Lbd.sys
2009-02-23 19:03 . 2009-02-23 19:03 d——– c:\program files\Lavasoft
2009-02-23 19:03 . 2009-02-23 19:05 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-23 19:03 . 2009-02-23 19:03 d–h-c— c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-23 18:25 . 2009-02-23 18:25 d——– C:\HijackThis

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-25 01:13 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-02-25 01:09 ——— d—–w c:\program files\Gamevance
2009-02-24 04:07 ——— d—–w c:\program files\WebSearchBar
2009-02-24 03:51 ——— d—–w c:\program files\WildTangent
2009-02-24 03:49 ——— d—–w c:\program files\MUSICMATCH
2009-02-24 03:44 ——— d—–w c:\program files\ESTsoft
2009-02-24 03:44 ——— d—–w c:\documents and settings\Thomas Bryant\Application Data\ESTsoft
2009-02-24 03:42 ——— d—–w c:\program files\CashOn
2009-02-24 03:05 ——— d—–w c:\program files\LimeWire
2009-02-24 03:04 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-24 03:04 ——— d—–w c:\documents and settings\All Users\Application Data\Napster
2009-02-24 03:03 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-24 01:17 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-02-22 22:49 ——— d—–w c:\program files\Dl_cats
2009-02-21 17:06 ——— d—–w c:\documents and settings\NetworkService\Application Data\Yahoo!
2009-02-14 16:09 ——— d—–w c:\program files\pointgo
2009-02-12 02:20 ——— d—–w c:\program files\Google
2009-01-16 23:06 ——— d—–w c:\documents and settings\All Users\Application Data\Electronic Arts
2009-01-15 22:57 ——— d—–w c:\documents and settings\Kum Bryant\Application Data\LimeWire
2009-01-12 22:40 ——— d—–w c:\documents and settings\Kum Bryant\Application Data\Elluminate
2008-02-06 00:31 131,584 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{016D43D1-2EAD-4723-8579-88D8AB70433C}]
2007-11-29 17:14 53248 –a—— c:\program files\rnic\SPBho.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2006-04-02 389120]
"AIM"="c:\progra~1\AIM\aim.exe" [2006-08-01 67112]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-09 68856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2008-06-10 785520]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-05 29744]
"DLCJCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll" [2005-08-14 73728]
"dlcjmon.exe"="c:\program files\Dell Photo AIO Printer 964\dlcjmon.exe" [2005-08-11 430080]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 964\memcard.exe" [2005-08-09 286720]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Gamevance"="c:\program files\Gamevance\gamevance32.exe" [2008-09-04 91648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-27 185896]
"pgo.exe"="c:\program files\pointgo\pgo.exe" [2009-01-13 229888]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-18 506712]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\stsystra.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-06-09 24576]
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Nexon\\Common\\NGLC_Nexon.exe"=
"c:\\Program Files\\Nexon\\Common\\NMService.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Nexon\\NGM\\NGM.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Nexon\\Common\\NMService.exe"=
"c:\\WINDOWS\\system32\\skcbgm.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre1.6.0_01\\bin\\javaw.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\KartRider\\NMService.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Games\\Halo Custom Edition\\haloce.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-23 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 921936]
S2 gupdate1c98c63cdc65d30;Google Update Service (gupdate1c98c63cdc65d30);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-11 133104]
S3 dump_wmimmc;dump_wmimmc;\??\c:\nexon\KartRider\GameGuard\dump_wmimmc.sys –> c:\nexon\KartRider\GameGuard\dump_wmimmc.sys [?]
S3 GoogleDesktopManager-093007-112848;Google Desktop Manager 5.5.709.30344;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-06-09 29744]
S3 scskusbf;USB SCSK Filter Driver Service;c:\windows\system32\drivers\scskusbf.sys [2007-01-07 18316]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 14:34]

2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-02-24 c:\windows\Tasks\At100.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At101.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At102.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At103.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-01 c:\windows\Tasks\At104.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At105.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At106.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At107.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At108.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At109.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At110.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At111.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At112.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At113.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At114.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At115.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At116.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At117.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At118.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At119.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At120.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At121.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At122.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At123.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At124.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At125.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At126.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At127.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-01 c:\windows\Tasks\At128.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At129.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At130.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At131.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At132.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At133.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At134.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At135.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At136.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At137.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At138.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At139.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At140.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At141.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At142.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At143.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At144.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At145.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At146.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At147.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At148.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At149.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At150.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At151.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-01 c:\windows\Tasks\At152.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At153.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At154.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At155.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At156.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At157.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At158.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At159.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At160.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At161.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At162.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At163.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At164.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At165.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At166.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At167.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At168.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At169.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At170.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At171.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At172.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At173.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At174.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At175.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-01 c:\windows\Tasks\At176.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At177.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At178.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At179.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At180.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At181.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At182.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At183.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At184.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At185.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At186.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At187.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At188.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At189.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At190.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At191.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At192.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At193.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At194.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At195.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At196.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At197.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At198.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At199.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-01 c:\windows\Tasks\At200.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At201.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At202.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At203.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At204.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At205.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At206.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At207.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At208.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At209.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At210.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At211.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At212.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At213.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At214.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At215.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At216.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At25.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At26.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At27.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At28.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At29.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At30.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At31.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-01 c:\windows\Tasks\At32.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At33.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At34.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At35.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At36.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At37.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At38.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At39.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At40.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At41.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At42.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At43.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At44.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At45.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At46.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At47.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At48.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At49.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At50.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At51.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At52.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At53.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At54.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At55.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-01 c:\windows\Tasks\At56.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At57.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At58.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At59.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At60.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At61.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At62.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At63.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At64.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At65.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At66.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At67.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At68.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At69.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At70.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At71.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At72.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At73.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At74.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At75.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At76.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At77.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At78.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At79.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-01 c:\windows\Tasks\At80.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At81.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At82.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At83.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At84.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At85.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At86.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At87.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At88.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At89.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At90.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\At91.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At92.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At93.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At94.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At95.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At96.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At97.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At98.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-24 c:\windows\Tasks\At99.job
- c:\windows\system32\5rqkCemn.exe [2009-01-16 16:06]

2009-02-25 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-11 09:13]

2009-02-25 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-11 09:14]

2009-02-25 c:\windows\Tasks\SDMsgUpdate (TE).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2008-08-11 07:29]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-ncservice - c:\program files\CashOn\bin\ncservice.exe
HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\3.bin\M3PLUGIN.DLL
HKU-Default-Run-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
HKU-Default-RunOnce-FlashPlayerUpdate - c:\windows\system32\Macromed\Flash\FlashUtil9f.exe
Notify-__c004B994 - c:\windows\system32\__c004B994.dat
Notify-NavLogon - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZKxdm021YYUS
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
DPF: {044123B5-35DF-4C4E-BAED-26B8ED964342} - hxxp://fx.hauri.net/HProduct/livesuite/shinhancard/CLIENT/LiveSuite/web/HLiveRobotWeb.cab
DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} - hxxp://s.nx.com/activex/public_new/nxpm.cab
DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} - hxxp://www.auctiva.com/Aurigma/ImageUploader55.cab
DPF: {5DAEF053-DEF0-4752-A963-CCE9B49B0B79} - hxxp://blog.naver.com/common/item/nbgm.cab
DPF: {6FE760D3-7851-4879-8838-62D9881D7177} - hxxp://www.letskt.com/imas/IniMasPlugin.cab
DPF: {7E9FDB80-5316-11D4-B02C-00C04F0CD404} - hxxp://www.samsungcard.co.kr/XecureDemo/XecureObject/xw_install.cab
DPF: {8BCAB742-72F8-4119-A4B4-8F639A6E27B3} - hxxp://photolog.blog.naver.com/NIU.CAB
DPF: {92D0D610-A6FA-48D8-94CB-BD47FDF68655} - hxxp://app.tubemusic.com/naver/naverx.cab
DPF: {9CDD57AC-CA86-464C-B920-3228A388CC78} - hxxp://file.naver.com/down/NaverFile.cab
DPF: {A9DD5FE2-5567-4983-971F-C792375025A6} - hxxp://software.musicnow.com/musicnow/phoenix/5.0.0.23/MusicNow.cab
DPF: {BD6BB450-7C69-43B8-96F3-689CAE57AB51} - hxxp://netv.sbs.co.kr/object/player/SBSWebPlayer.cab
DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} - hxxp://flash.hangame.com/common/HanSetup1009.cab
DPF: {D26A941D-7E89-4098-B583-43291FC14218} - hxxp://image.pullbbang.com/images/Pull0Control.ocx
DPF: {D7602755-1F82-4EA4-B8F8-F0FA7E8A430D} - hxxp://egis.onoffkorea.com/activex/EgisBVMActiveX.cab
DPF: {E75386B4-C629-11DB-8338-444553544200} - hxxp://cyimg7.cyworld.nate.com/cymusic/package/cyinstal.cab
DPF: {F1F07506-6CB4-44AC-8615-66D1234EFD05} - hxxp://www.shinhancard.com/initech/plugin/down/INIS50.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-24 18:14:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCJCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Gamevance = c:\program files\Gamevance\gamevance32.exe?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-578257276-644222742-322493702-1005\Software\SecuROM\License information*]
"datasecu"=hex:fc,4a,27,7d,0e,fe,e6,ef,9f,a9,db,89,dd,24,e0,a3,ad,2b,e2,63,11,
93,0f,fc,1a,e8,ff,b6,eb,f5,01,86,15,23,38,c1,2f,01,11,f2,97,9b,ba,0c,67,58,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\windows\system32\npkcmsvc.exe
c:\windows\ehome\RMSvc.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\ehome\McrdSvc.exe
c:\windows\system32\fxssvc.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\dlcjcoms.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscript.exe
.
**************************************************************************
.
Completion time: 2009-02-24 18:19:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-25 01:19:08

Pre-Run: 172,188,250,112 bytes free
Post-Run: 176,089,501,696 bytes free

645 — E O F — 2009-02-24 01:22:05

Thank you for your assistance - ready for any next steps.

Beth Ann
bethk,

That makes it harder on you as you will have to transfer files until we get you running again. :wacko:

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Next

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    AtJob::
    
    File::
    c:\program files\rnic\SPBho.dll
    c:\nexon\KartRider\GameGuard\dump_wmimmc.sys
    c:\windows\system32\5rqkCemn.exe
    
    Folder::
    c:\program files\Gamevance
    c:\program files\WildTangent
    c:\program files\WebSearchBar
    c:\program files\CashOn
    c:\program files\pointgo
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{016D43D1-2EAD-4723-8579-88D8AB70433C}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "pgo.exe"=-
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
    
    Driver::
    dump_wmimmc
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Here are the logs you requested:

Rooter -

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Intel® Pentium® D CPU 3.20GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A05
USER : Kum Bryant ( Administrator )
BOOT : Normal boot


Firewall : Norton Internet Worm Protection 2006 (Not Activated)

C:\ (Local Disk) - NTFS - Total:228 Go (Free:164 Go)
D:\ (CD or DVD)
E:\ (USB) - FAT - Total:1935 Mo (Free:1 Go)

Tue 02/24/2009|19:43

———————-\\ Search..

Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe
Trojan ! .. C:\WINDOWS\system32\5rqkCemn.exe

———————-\\ Tasks

C:\WINDOWS\tasks\At25.job
C:\WINDOWS\tasks\At26.job
C:\WINDOWS\tasks\At27.job
C:\WINDOWS\tasks\At28.job
C:\WINDOWS\tasks\At29.job
C:\WINDOWS\tasks\At31.job
C:\WINDOWS\tasks\At32.job
C:\WINDOWS\tasks\At33.job
C:\WINDOWS\tasks\At34.job
C:\WINDOWS\tasks\At35.job
C:\WINDOWS\tasks\At36.job
C:\WINDOWS\tasks\At37.job
C:\WINDOWS\tasks\At38.job
C:\WINDOWS\tasks\At39.job
C:\WINDOWS\tasks\At41.job
C:\WINDOWS\tasks\At42.job
C:\WINDOWS\tasks\At43.job
C:\WINDOWS\tasks\At44.job
C:\WINDOWS\tasks\At45.job
C:\WINDOWS\tasks\At46.job
C:\WINDOWS\tasks\At47.job
C:\WINDOWS\tasks\At48.job
C:\WINDOWS\tasks\At49.job
C:\WINDOWS\tasks\At51.job
C:\WINDOWS\tasks\At52.job
C:\WINDOWS\tasks\At53.job
C:\WINDOWS\tasks\At54.job
C:\WINDOWS\tasks\At55.job
C:\WINDOWS\tasks\At56.job
C:\WINDOWS\tasks\At57.job
C:\WINDOWS\tasks\At58.job
C:\WINDOWS\tasks\At59.job
C:\WINDOWS\tasks\At61.job
C:\WINDOWS\tasks\At62.job
C:\WINDOWS\tasks\At63.job
C:\WINDOWS\tasks\At64.job
C:\WINDOWS\tasks\At65.job
C:\WINDOWS\tasks\At66.job
C:\WINDOWS\tasks\At67.job
C:\WINDOWS\tasks\At68.job
C:\WINDOWS\tasks\At69.job
C:\WINDOWS\tasks\At71.job
C:\WINDOWS\tasks\At72.job
C:\WINDOWS\tasks\At73.job
C:\WINDOWS\tasks\At74.job
C:\WINDOWS\tasks\At75.job
C:\WINDOWS\tasks\At76.job
C:\WINDOWS\tasks\At77.job
C:\WINDOWS\tasks\At78.job
C:\WINDOWS\tasks\At79.job
C:\WINDOWS\tasks\At81.job
C:\WINDOWS\tasks\At82.job
C:\WINDOWS\tasks\At83.job
C:\WINDOWS\tasks\At84.job
C:\WINDOWS\tasks\At85.job
C:\WINDOWS\tasks\At86.job
C:\WINDOWS\tasks\At87.job
C:\WINDOWS\tasks\At88.job
C:\WINDOWS\tasks\At89.job
C:\WINDOWS\tasks\At91.job
C:\WINDOWS\tasks\At92.job
C:\WINDOWS\tasks\At93.job
C:\WINDOWS\tasks\At94.job
C:\WINDOWS\tasks\At95.job
C:\WINDOWS\tasks\At96.job
C:\WINDOWS\tasks\At97.job
C:\WINDOWS\tasks\At98.job
C:\WINDOWS\tasks\At99.job


1 - "C:\Rooter$\Rooter_1.txt" - Tue 02/24/2009|19:45

———————-\\ Scan completed at 19:45

COMBOFIX.txt

ComboFix 09-02-24.01 - Kum Bryant 2009-02-24 19:51:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.542 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kum Bryant\Desktop\CFScript.txt
FW: Norton Internet Worm Protection *disabled*
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
c:\nexon\KartRider\GameGuard\dump_wmimmc.sys
c:\program files\rnic\SPBho.dll
c:\windows\system32\5rqkCemn.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\CashOn
c:\program files\CashOn\bin\CashOnUpdate02232042.exe
c:\program files\CashOn\bin\CashOnUpdate02232043.exe
c:\program files\CashOn\bin\CashOnUpdate02232044.exe
c:\program files\CashOn\bin\CashOnUpdate02232045.exe
c:\program files\CashOn\bin\CashOnUpdate02232046.exe
c:\program files\CashOn\bin\CashOnUpdate02232047.exe
c:\program files\CashOn\bin\CashOnUpdate02232048.exe
c:\program files\CashOn\bin\CashOnUpdate02232049.exe
c:\program files\CashOn\bin\CashOnUpdate02232050.exe
c:\program files\CashOn\bin\CashOnUpdate02232051.exe
c:\program files\CashOn\bin\CashOnUpdate02232052.exe
c:\program files\CashOn\bin\CashOnUpdate02232053.exe
c:\program files\CashOn\bin\CashOnUpdate02232054.exe
c:\program files\CashOn\bin\CashOnUpdate02232055.exe
c:\program files\CashOn\bin\CashOnUpdate02232056.exe
c:\program files\CashOn\bin\CashOnUpdate02232057.exe
c:\program files\CashOn\bin\CashOnUpdate02232058.exe
c:\program files\CashOn\bin\CashOnUpdate02232059.exe
c:\program files\CashOn\bin\CashOnUpdate02232100.exe
c:\program files\CashOn\bin\CashOnUpdate02232101.exe
c:\program files\CashOn\bin\CashOnUpdate02232102.exe
c:\program files\CashOn\bin\CashOnUpdate02232103.exe
c:\program files\CashOn\bin\CashOnUpdate02232104.exe
c:\program files\CashOn\bin\CashOnUpdate02232105.exe
c:\program files\CashOn\bin\CashOnUpdate02232106.exe
c:\program files\CashOn\bin\CashOnUpdate02232107.exe
c:\program files\CashOn\bin\CashOnUpdate02232108.exe
c:\program files\CashOn\bin\CashOnUpdate02232109.exe
c:\program files\CashOn\bin\CashOnUpdate02232110.exe
c:\program files\CashOn\bin\CashOnUpdate02232111.exe
c:\program files\CashOn\bin\CashOnUpdate02232112.exe
c:\program files\CashOn\bin\CashOnUpdate02232113.exe
c:\program files\CashOn\bin\CashOnUpdate02232114.exe
c:\program files\CashOn\bin\CashOnUpdate02232115.exe
c:\program files\CashOn\bin\CashOnUpdate02232116.exe
c:\program files\CashOn\bin\CashOnUpdate02232117.exe
c:\program files\CashOn\bin\CashOnUpdate02232118.exe
c:\program files\CashOn\bin\CashOnUpdate02232119.exe
c:\program files\CashOn\bin\CashOnUpdate02232120.exe
c:\program files\CashOn\bin\CashOnUpdate02232121.exe
c:\program files\CashOn\bin\CashOnUpdate02232122.exe
c:\program files\CashOn\bin\CashOnUpdate02232123.exe
c:\program files\CashOn\bin\CashOnUpdate02232124.exe
c:\program files\CashOn\bin\CashOnUpdate02232125.exe
c:\program files\CashOn\bin\CashOnUpdate02232126.exe
c:\program files\CashOn\bin\CashOnUpdate02232127.exe
c:\program files\CashOn\bin\CashOnUpdate02232128.exe
c:\program files\CashOn\bin\CashOnUpdate02232129.exe
c:\program files\CashOn\bin\CashOnUpdate02232130.exe
c:\program files\CashOn\bin\CashOnUpdate02232131.exe
c:\program files\CashOn\bin\CashOnUpdate02232132.exe
c:\program files\CashOn\bin\CashOnUpdate02232133.exe
c:\program files\CashOn\bin\CashOnUpdate02232134.exe
c:\program files\CashOn\bin\CashOnUpdate02232135.exe
c:\program files\CashOn\bin\CashOnUpdate02232136.exe
c:\program files\CashOn\bin\CashOnUpdate02232137.exe
c:\program files\CashOn\bin\CashOnUpdate02232138.exe
c:\program files\CashOn\bin\CashOnUpdate02232139.exe
c:\program files\CashOn\bin\CashOnUpdate02232140.exe
c:\program files\CashOn\bin\CashOnUpdate02232141.exe
c:\program files\CashOn\bin\CashOnUpdate02232142.exe
c:\program files\CashOn\bin\CashOnUpdate02232143.exe
c:\program files\CashOn\bin\CashOnUpdate02232144.exe
c:\program files\CashOn\bin\CashOnUpdate02232145.exe
c:\program files\CashOn\bin\CashOnUpdate02232146.exe
c:\program files\CashOn\bin\CashOnUpdate02232147.exe
c:\program files\CashOn\bin\CashOnUpdate02232148.exe
c:\program files\CashOn\bin\CashOnUpdate02232149.exe
c:\program files\CashOn\bin\CashOnUpdate02232150.exe
c:\program files\CashOn\bin\CashOnUpdate02232151.exe
c:\program files\CashOn\bin\CashOnUpdate02232152.exe
c:\program files\CashOn\bin\CashOnUpdate02232153.exe
c:\program files\CashOn\bin\CashOnUpdate02232154.exe
c:\program files\CashOn\bin\CashOnUpdate02232155.exe
c:\program files\CashOn\bin\CashOnUpdate02232156.exe
c:\program files\CashOn\bin\CashOnUpdate02232157.exe
c:\program files\CashOn\bin\CashOnUpdate02232158.exe
c:\program files\CashOn\bin\CashOnUpdate02232159.exe
c:\program files\CashOn\bin\CashOnUpdate02232200.exe
c:\program files\CashOn\bin\CashOnUpdate02232201.exe
c:\program files\CashOn\bin\CashOnUpdate02232202.exe
c:\program files\CashOn\bin\CashOnUpdate02232203.exe
c:\program files\CashOn\bin\CashOnUpdate02232204.exe
c:\program files\CashOn\bin\CashOnUpdate02232205.exe
c:\program files\CashOn\bin\CashOnUpdate02232206.exe
c:\program files\CashOn\bin\CashOnUpdate02232207.exe
c:\program files\CashOn\bin\CashOnUpdate02232208.exe
c:\program files\CashOn\bin\CashOnUpdate02232209.exe
c:\program files\CashOn\bin\CashOnUpdate02232210.exe
c:\program files\CashOn\bin\CashOnUpdate02232211.exe
c:\program files\CashOn\bin\CashOnUpdate02232212.exe
c:\program files\CashOn\bin\CashOnUpdate02232213.exe
c:\program files\CashOn\bin\CashOnUpdate02232214.exe
c:\program files\CashOn\bin\CashOnUpdate02232215.exe
c:\program files\CashOn\bin\CashOnUpdate02232216.exe
c:\program files\CashOn\bin\CashOnUpdate02232217.exe
c:\program files\CashOn\bin\CashOnUpdate02232218.exe
c:\program files\CashOn\bin\CashOnUpdate02232219.exe
c:\program files\CashOn\bin\CashOnUpdate02232220.exe
c:\program files\CashOn\bin\CashOnUpdate02232221.exe
c:\program files\CashOn\bin\CashOnUpdate02232222.exe
c:\program files\CashOn\bin\CashOnUpdate02232223.exe
c:\program files\CashOn\bin\CashOnUpdate02232224.exe
c:\program files\CashOn\bin\CashOnUpdate02232225.exe
c:\program files\CashOn\bin\CashOnUpdate02232226.exe
c:\program files\CashOn\bin\CashOnUpdate02232227.exe
c:\program files\CashOn\bin\CashOnUpdate02232228.exe
c:\program files\CashOn\bin\CashOnUpdate02232229.exe
c:\program files\CashOn\bin\CashOnUpdate02232230.exe
c:\program files\CashOn\bin\CashOnUpdate02232231.exe
c:\program files\CashOn\bin\CashOnUpdate02232232.exe
c:\program files\CashOn\bin\CashOnUpdate02232233.exe
c:\program files\CashOn\bin\CashOnUpdate02232234.exe
c:\program files\CashOn\bin\CashOnUpdate02232235.exe
c:\program files\CashOn\bin\CashOnUpdate02232236.exe
c:\program files\CashOn\bin\CashOnUpdate02232237.exe
c:\program files\CashOn\bin\CashOnUpdate02232238.exe
c:\program files\CashOn\bin\CashOnUpdate02232239.exe
c:\program files\CashOn\bin\CashOnUpdate02232240.exe
c:\program files\CashOn\bin\CashOnUpdate02232241.exe
c:\program files\CashOn\bin\CashOnUpdate02232242.exe
c:\program files\CashOn\bin\CashOnUpdate02232243.exe
c:\program files\CashOn\bin\CashOnUpdate02232244.exe
c:\program files\CashOn\bin\CashOnUpdate02232245.exe
c:\program files\CashOn\bin\CashOnUpdate02232246.exe
c:\program files\CashOn\bin\CashOnUpdate02232247.exe
c:\program files\CashOn\bin\CashOnUpdate02232248.exe
c:\program files\CashOn\bin\CashOnUpdate02232249.exe
c:\program files\CashOn\bin\CashOnUpdate02232250.exe
c:\program files\CashOn\bin\CashOnUpdate02232251.exe
c:\program files\CashOn\bin\CashOnUpdate02232252.exe
c:\program files\CashOn\bin\CashOnUpdate02232253.exe
c:\program files\CashOn\bin\CashOnUpdate02232254.exe
c:\program files\CashOn\bin\CashOnUpdate02232255.exe
c:\program files\CashOn\bin\CashOnUpdate02232256.exe
c:\program files\CashOn\bin\CashOnUpdate02232257.exe
c:\program files\CashOn\bin\CashOnUpdate02232258.exe
c:\program files\CashOn\bin\CashOnUpdate02232259.exe
c:\program files\CashOn\bin\CashOnUpdate02232300.exe
c:\program files\CashOn\bin\CashOnUpdate02232301.exe
c:\program files\CashOn\bin\CashOnUpdate02232302.exe
c:\program files\CashOn\bin\CashOnUpdate02232303.exe
c:\program files\CashOn\bin\CashOnUpdate02232304.exe
c:\program files\CashOn\bin\CashOnUpdate02232305.exe
c:\program files\CashOn\bin\CashOnUpdate02232306.exe
c:\program files\CashOn\bin\CashOnUpdate02232307.exe
c:\program files\CashOn\bin\CashOnUpdate02232308.exe
c:\program files\CashOn\bin\CashOnUpdate02232309.exe
c:\program files\CashOn\bin\CashOnUpdate02232310.exe
c:\program files\CashOn\bin\CashOnUpdate02232311.exe
c:\program files\CashOn\bin\CashOnUpdate02232312.exe
c:\program files\CashOn\bin\CashOnUpdate02232313.exe
c:\program files\CashOn\bin\CashOnUpdate02232314.exe
c:\program files\CashOn\bin\CashOnUpdate02232315.exe
c:\program files\CashOn\bin\CashOnUpdate02232316.exe
c:\program files\CashOn\bin\CashOnUpdate02232317.exe
c:\program files\CashOn\bin\CashOnUpdate02232318.exe
c:\program files\CashOn\bin\CashOnUpdate02232319.exe
c:\program files\CashOn\bin\CashOnUpdate02232320.exe
c:\program files\CashOn\bin\CashOnUpdate02232321.exe
c:\program files\CashOn\bin\CashOnUpdate02232322.exe
c:\program files\CashOn\bin\CashOnUpdate02232323.exe
c:\program files\CashOn\bin\CashOnUpdate02232324.exe
c:\program files\CashOn\bin\CashOnUpdate02232325.exe
c:\program files\CashOn\bin\CashOnUpdate02232326.exe
c:\program files\CashOn\bin\CashOnUpdate02232327.exe
c:\program files\CashOn\bin\CashOnUpdate02232328.exe
c:\program files\CashOn\bin\CashOnUpdate02232329.exe
c:\program files\CashOn\bin\CashOnUpdate02232330.exe
c:\program files\CashOn\bin\CashOnUpdate02232331.exe
c:\program files\CashOn\bin\CashOnUpdate02232332.exe
c:\program files\CashOn\bin\CashOnUpdate02232333.exe
c:\program files\CashOn\bin\CashOnUpdate02232334.exe
c:\program files\CashOn\bin\CashOnUpdate02232335.exe
c:\program files\CashOn\bin\CashOnUpdate02232336.exe
c:\program files\CashOn\bin\CashOnUpdate02232337.exe
c:\program files\CashOn\bin\CashOnUpdate02232338.exe
c:\program files\CashOn\bin\CashOnUpdate02232339.exe
c:\program files\CashOn\bin\CashOnUpdate02232340.exe
c:\program files\CashOn\bin\CashOnUpdate02232341.exe
c:\program files\CashOn\bin\CashOnUpdate02232342.exe
c:\program files\CashOn\bin\CashOnUpdate02232343.exe
c:\program files\CashOn\bin\CashOnUpdate02232344.exe
c:\program files\CashOn\bin\CashOnUpdate02232345.exe
c:\program files\CashOn\bin\CashOnUpdate02232346.exe
c:\program files\CashOn\bin\CashOnUpdate02232347.exe
c:\program files\CashOn\bin\CashOnUpdate02232348.exe
c:\program files\CashOn\bin\CashOnUpdate02232349.exe
c:\program files\CashOn\bin\CashOnUpdate02232350.exe
c:\program files\CashOn\bin\CashOnUpdate02232351.exe
c:\program files\CashOn\bin\CashOnUpdate02232352.exe
c:\program files\CashOn\bin\CashOnUpdate02232353.exe
c:\program files\CashOn\bin\CashOnUpdate02232354.exe
c:\program files\CashOn\bin\CashOnUpdate02232355.exe
c:\program files\CashOn\bin\CashOnUpdate02232356.exe
c:\program files\CashOn\bin\CashOnUpdate02232357.exe
c:\program files\CashOn\bin\CashOnUpdate02232358.exe
c:\program files\CashOn\bin\CashOnUpdate02232359.exe
c:\program files\CashOn\bin\CashOnUpdate02240000.exe
c:\program files\CashOn\bin\CashOnUpdate02240001.exe
c:\program files\CashOn\bin\CashOnUpdate02240002.exe
c:\program files\CashOn\bin\CashOnUpdate02240003.exe
c:\program files\CashOn\bin\CashOnUpdate02240004.exe
c:\program files\CashOn\bin\CashOnUpdate02240005.exe
c:\program files\CashOn\bin\CashOnUpdate02240006.exe
c:\program files\CashOn\bin\CashOnUpdate02240007.exe
c:\program files\CashOn\bin\CashOnUpdate02240008.exe
c:\program files\CashOn\bin\CashOnUpdate02240009.exe
c:\program files\CashOn\bin\CashOnUpdate02240010.exe
c:\program files\CashOn\bin\CashOnUpdate02240011.exe
c:\program files\CashOn\bin\CashOnUpdate02240012.exe
c:\program files\CashOn\bin\CashOnUpdate02240013.exe
c:\program files\CashOn\bin\CashOnUpdate02240014.exe
c:\program files\CashOn\bin\CashOnUpdate02240015.exe
c:\program files\CashOn\bin\CashOnUpdate02240016.exe
c:\program files\CashOn\bin\CashOnUpdate02240017.exe
c:\program files\CashOn\bin\CashOnUpdate02240018.exe
c:\program files\CashOn\bin\CashOnUpdate02240019.exe
c:\program files\CashOn\bin\CashOnUpdate02240020.exe
c:\program files\CashOn\bin\CashOnUpdate02240021.exe
c:\program files\CashOn\bin\CashOnUpdate02240022.exe
c:\program files\CashOn\bin\CashOnUpdate02240023.exe
c:\program files\CashOn\bin\CashOnUpdate02240024.exe
c:\program files\CashOn\bin\CashOnUpdate02240025.exe
c:\program files\CashOn\bin\CashOnUpdate02240026.exe
c:\program files\CashOn\bin\CashOnUpdate02240027.exe
c:\program files\CashOn\bin\CashOnUpdate02240028.exe
c:\program files\CashOn\bin\CashOnUpdate02240029.exe
c:\program files\CashOn\bin\CashOnUpdate02240030.exe
c:\program files\CashOn\bin\CashOnUpdate02240031.exe
c:\program files\CashOn\bin\CashOnUpdate02240032.exe
c:\program files\CashOn\bin\CashOnUpdate02240033.exe
c:\program files\CashOn\bin\CashOnUpdate02240034.exe
c:\program files\CashOn\bin\CashOnUpdate02240035.exe
c:\program files\CashOn\bin\CashOnUpdate02240036.exe
c:\program files\CashOn\bin\CashOnUpdate02240037.exe
c:\program files\CashOn\bin\CashOnUpdate02240038.exe
c:\program files\CashOn\bin\CashOnUpdate02240039.exe
c:\program files\CashOn\bin\CashOnUpdate02240040.exe
c:\program files\CashOn\bin\CashOnUpdate02240041.exe
c:\program files\CashOn\bin\CashOnUpdate02240042.exe
c:\program files\CashOn\bin\CashOnUpdate02240043.exe
c:\program files\CashOn\bin\CashOnUpdate02240044.exe
c:\program files\CashOn\bin\CashOnUpdate02240045.exe
c:\program files\CashOn\bin\CashOnUpdate02240046.exe
c:\program files\CashOn\bin\CashOnUpdate02240047.exe
c:\program files\CashOn\bin\CashOnUpdate02240048.exe
c:\program files\CashOn\bin\CashOnUpdate02240049.exe
c:\program files\CashOn\bin\CashOnUpdate02240050.exe
c:\program files\CashOn\bin\CashOnUpdate02240051.exe
c:\program files\CashOn\bin\CashOnUpdate02240052.exe
c:\program files\CashOn\bin\CashOnUpdate02240053.exe
c:\program files\CashOn\bin\CashOnUpdate02240054.exe
c:\program files\CashOn\bin\CashOnUpdate02240055.exe
c:\program files\CashOn\bin\CashOnUpdate02240056.exe
c:\program files\CashOn\bin\CashOnUpdate02240057.exe
c:\program files\CashOn\bin\CashOnUpdate02240058.exe
c:\program files\CashOn\bin\CashOnUpdate02240059.exe
c:\program files\CashOn\bin\CashOnUpdate02240100.exe
c:\program files\CashOn\bin\CashOnUpdate02240101.exe
c:\program files\CashOn\bin\CashOnUpdate02240102.exe
c:\program files\CashOn\bin\CashOnUpdate02240103.exe
c:\program files\CashOn\bin\CashOnUpdate02240104.exe
c:\program files\CashOn\bin\CashOnUpdate02240105.exe
c:\program files\CashOn\bin\CashOnUpdate02240106.exe
c:\program files\CashOn\bin\CashOnUpdate02240107.exe
c:\program files\CashOn\bin\CashOnUpdate02240108.exe
c:\program files\CashOn\bin\CashOnUpdate02240109.exe
c:\program files\CashOn\bin\CashOnUpdate02240110.exe
c:\program files\CashOn\bin\CashOnUpdate02240111.exe
c:\program files\CashOn\bin\CashOnUpdate02240112.exe
c:\program files\CashOn\bin\CashOnUpdate02240113.exe
c:\program files\CashOn\bin\CashOnUpdate02240114.exe
c:\program files\CashOn\bin\CashOnUpdate02240115.exe
c:\program files\CashOn\bin\CashOnUpdate02240116.exe
c:\program files\CashOn\bin\CashOnUpdate02240117.exe
c:\program files\CashOn\bin\CashOnUpdate02240118.exe
c:\program files\CashOn\bin\CashOnUpdate02240119.exe
c:\program files\CashOn\bin\CashOnUpdate02240120.exe
c:\program files\CashOn\bin\CashOnUpdate02240121.exe
c:\program files\CashOn\bin\CashOnUpdate02240122.exe
c:\program files\CashOn\bin\CashOnUpdate02240123.exe
c:\program files\CashOn\bin\CashOnUpdate02240124.exe
c:\program files\CashOn\bin\CashOnUpdate02240125.exe
c:\program files\CashOn\bin\CashOnUpdate02240126.exe
c:\program files\CashOn\bin\CashOnUpdate02240127.exe
c:\program files\CashOn\bin\CashOnUpdate02240128.exe
c:\program files\CashOn\bin\CashOnUpdate02240129.exe
c:\program files\CashOn\bin\CashOnUpdate02240130.exe
c:\program files\CashOn\bin\CashOnUpdate02240131.exe
c:\program files\CashOn\bin\CashOnUpdate02240132.exe
c:\program files\CashOn\bin\CashOnUpdate02240133.exe
c:\program files\CashOn\bin\CashOnUpdate02240134.exe
c:\program files\CashOn\bin\CashOnUpdate02240135.exe
c:\program files\CashOn\bin\CashOnUpdate02240136.exe
c:\program files\CashOn\bin\CashOnUpdate02240137.exe
c:\program files\CashOn\bin\CashOnUpdate02240138.exe
c:\program files\CashOn\bin\CashOnUpdate02240139.exe
c:\program files\CashOn\bin\CashOnUpdate02240140.exe
c:\program files\CashOn\bin\CashOnUpdate02240141.exe
c:\program files\CashOn\bin\CashOnUpdate02240142.exe
c:\program files\CashOn\bin\CashOnUpdate02240143.exe
c:\program files\CashOn\bin\CashOnUpdate02240144.exe
c:\program files\CashOn\bin\CashOnUpdate02240145.exe
c:\program files\CashOn\bin\CashOnUpdate02240146.exe
c:\program files\CashOn\bin\CashOnUpdate02240147.exe
c:\program files\CashOn\bin\CashOnUpdate02240148.exe
c:\program files\CashOn\bin\CashOnUpdate02240149.exe
c:\program files\CashOn\bin\CashOnUpdate02240150.exe
c:\program files\CashOn\bin\CashOnUpdate02240151.exe
c:\program files\CashOn\bin\CashOnUpdate02240152.exe
c:\program files\CashOn\bin\CashOnUpdate02240153.exe
c:\program files\CashOn\bin\CashOnUpdate02240154.exe
c:\program files\CashOn\bin\CashOnUpdate02240155.exe
c:\program files\CashOn\bin\CashOnUpdate02240156.exe
c:\program files\CashOn\bin\CashOnUpdate02240157.exe
c:\program files\CashOn\bin\CashOnUpdate02240158.exe
c:\program files\CashOn\bin\CashOnUpdate02240159.exe
c:\program files\CashOn\bin\CashOnUpdate02240200.exe
c:\program files\CashOn\bin\CashOnUpdate02240201.exe
c:\program files\CashOn\bin\CashOnUpdate02240202.exe
c:\program files\CashOn\bin\CashOnUpdate02240203.exe
c:\program files\CashOn\bin\CashOnUpdate02240204.exe
c:\program files\CashOn\bin\CashOnUpdate02240205.exe
c:\program files\CashOn\bin\CashOnUpdate02240206.exe
c:\program files\CashOn\bin\CashOnUpdate02240207.exe
c:\program files\CashOn\bin\CashOnUpdate02240208.exe
c:\program files\CashOn\bin\CashOnUpdate02240209.exe
c:\program files\CashOn\bin\CashOnUpdate02240210.exe
c:\program files\CashOn\bin\CashOnUpdate02240211.exe
c:\program files\CashOn\bin\CashOnUpdate02240212.exe
c:\program files\CashOn\bin\CashOnUpdate02240213.exe
c:\program files\CashOn\bin\CashOnUpdate02240214.exe
c:\program files\CashOn\bin\CashOnUpdate02240215.exe
c:\program files\CashOn\bin\CashOnUpdate02240216.exe
c:\program files\CashOn\bin\CashOnUpdate02240217.exe
c:\program files\CashOn\bin\CashOnUpdate02240218.exe
c:\program files\CashOn\bin\CashOnUpdate02240219.exe
c:\program files\CashOn\bin\CashOnUpdate02240220.exe
c:\program files\CashOn\bin\CashOnUpdate02240221.exe
c:\program files\CashOn\bin\CashOnUpdate02240222.exe
c:\program files\CashOn\bin\CashOnUpdate02240223.exe
c:\program files\CashOn\bin\CashOnUpdate02240224.exe
c:\program files\CashOn\bin\CashOnUpdate02240225.exe
c:\program files\CashOn\bin\CashOnUpdate02240226.exe
c:\program files\CashOn\bin\CashOnUpdate02240227.exe
c:\program files\CashOn\bin\CashOnUpdate02240228.exe
c:\program files\CashOn\bin\CashOnUpdate02240229.exe
c:\program files\CashOn\bin\CashOnUpdate02240230.exe
c:\program files\CashOn\bin\CashOnUpdate02240231.exe
c:\program files\CashOn\bin\CashOnUpdate02240232.exe
c:\program files\CashOn\bin\CashOnUpdate02240233.exe
c:\program files\CashOn\bin\CashOnUpdate02240234.exe
c:\program files\CashOn\bin\CashOnUpdate02240235.exe
c:\program files\CashOn\bin\CashOnUpdate02240236.exe
c:\program files\CashOn\bin\CashOnUpdate02240237.exe
c:\program files\CashOn\bin\CashOnUpdate02240238.exe
c:\program files\CashOn\bin\CashOnUpdate02240239.exe
c:\program files\CashOn\bin\CashOnUpdate02240240.exe
c:\program files\CashOn\bin\CashOnUpdate02240241.exe
c:\program files\CashOn\bin\CashOnUpdate02240242.exe
c:\program files\CashOn\bin\CashOnUpdate02240243.exe
c:\program files\CashOn\bin\CashOnUpdate02240244.exe
c:\program files\CashOn\bin\CashOnUpdate02240245.exe
c:\program files\CashOn\bin\CashOnUpdate02240246.exe
c:\program files\CashOn\bin\CashOnUpdate02240247.exe
c:\program files\CashOn\bin\CashOnUpdate02240248.exe
c:\program files\CashOn\bin\CashOnUpdate02240249.exe
c:\program files\CashOn\bin\CashOnUpdate02240250.exe
c:\program files\CashOn\bin\CashOnUpdate02240251.exe
c:\program files\CashOn\bin\CashOnUpdate02240252.exe
c:\program files\CashOn\bin\CashOnUpdate02240253.exe
c:\program files\CashOn\bin\CashOnUpdate02240254.exe
c:\program files\CashOn\bin\CashOnUpdate02240255.exe
c:\program files\CashOn\bin\CashOnUpdate02240256.exe
c:\program files\CashOn\bin\CashOnUpdate02240257.exe
c:\program files\CashOn\bin\CashOnUpdate02240258.exe
c:\program files\CashOn\bin\CashOnUpdate02240259.exe
c:\program files\CashOn\bin\CashOnUpdate02240300.exe
c:\program files\CashOn\bin\CashOnUpdate02240301.exe
c:\program files\CashOn\bin\CashOnUpdate02240302.exe
c:\program files\CashOn\bin\CashOnUpdate02240303.exe
c:\program files\CashOn\bin\CashOnUpdate02240304.exe
c:\program files\CashOn\bin\CashOnUpdate02240305.exe
c:\program files\CashOn\bin\CashOnUpdate02240306.exe
c:\program files\CashOn\bin\CashOnUpdate02240307.exe
c:\program files\CashOn\bin\CashOnUpdate02240308.exe
c:\program files\CashOn\bin\CashOnUpdate02240309.exe
c:\program files\CashOn\bin\CashOnUpdate02240310.exe
c:\program files\CashOn\bin\CashOnUpdate02240311.exe
c:\program files\CashOn\bin\CashOnUpdate02240312.exe
c:\program files\CashOn\bin\CashOnUpdate02240313.exe
c:\program files\CashOn\bin\CashOnUpdate02240314.exe
c:\program files\CashOn\bin\CashOnUpdate02240315.exe
c:\program files\CashOn\bin\CashOnUpdate02240316.exe
c:\program files\CashOn\bin\CashOnUpdate02240317.exe
c:\program files\CashOn\bin\CashOnUpdate02240318.exe
c:\program files\CashOn\bin\CashOnUpdate02240319.exe
c:\program files\CashOn\bin\CashOnUpdate02240320.exe
c:\program files\CashOn\bin\CashOnUpdate02240321.exe
c:\program files\CashOn\bin\CashOnUpdate02240322.exe
c:\program files\CashOn\bin\CashOnUpdate02240323.exe
c:\program files\CashOn\bin\CashOnUpdate02240324.exe
c:\program files\CashOn\bin\CashOnUpdate02240325.exe
c:\program files\CashOn\bin\CashOnUpdate02240326.exe
c:\program files\CashOn\bin\CashOnUpdate02240327.exe
c:\program files\CashOn\bin\CashOnUpdate02240328.exe
c:\program files\CashOn\bin\CashOnUpdate02240329.exe
c:\program files\CashOn\bin\CashOnUpdate02240330.exe
c:\program files\CashOn\bin\CashOnUpdate02240331.exe
c:\program files\CashOn\bin\CashOnUpdate02240332.exe
c:\program files\CashOn\bin\CashOnUpdate02240333.exe
c:\program files\CashOn\bin\CashOnUpdate02240334.exe
c:\program files\CashOn\bin\CashOnUpdate02240335.exe
c:\program files\CashOn\bin\CashOnUpdate02240336.exe
c:\program files\CashOn\bin\CashOnUpdate02240337.exe
c:\program files\CashOn\bin\CashOnUpdate02240338.exe
c:\program files\CashOn\bin\CashOnUpdate02240339.exe
c:\program files\CashOn\bin\CashOnUpdate02240340.exe
c:\program files\CashOn\bin\CashOnUpdate02240341.exe
c:\program files\CashOn\bin\CashOnUpdate02240342.exe
c:\program files\CashOn\bin\CashOnUpdate02240343.exe
c:\program files\CashOn\bin\CashOnUpdate02240344.exe
c:\program files\CashOn\bin\CashOnUpdate02240345.exe
c:\program files\CashOn\bin\CashOnUpdate02240346.exe
c:\program files\CashOn\bin\CashOnUpdate02240347.exe
c:\program files\CashOn\bin\CashOnUpdate02240348.exe
c:\program files\CashOn\bin\CashOnUpdate02240349.exe
c:\program files\CashOn\bin\CashOnUpdate02240350.exe
c:\program files\CashOn\bin\CashOnUpdate02240351.exe
c:\program files\CashOn\bin\CashOnUpdate02240352.exe
c:\program files\CashOn\bin\CashOnUpdate02240353.exe
c:\program files\CashOn\bin\CashOnUpdate02240354.exe
c:\program files\CashOn\bin\CashOnUpdate02240355.exe
c:\program files\CashOn\bin\CashOnUpdate02240356.exe
c:\program files\CashOn\bin\CashOnUpdate02240357.exe
c:\program files\CashOn\bin\CashOnUpdate02240358.exe
c:\program files\CashOn\bin\CashOnUpdate02240359.exe
c:\program files\CashOn\bin\CashOnUpdate02240400.exe
c:\program files\CashOn\bin\CashOnUpdate02240401.exe
c:\program files\CashOn\bin\CashOnUpdate02240402.exe
c:\program files\CashOn\bin\CashOnUpdate02240403.exe
c:\program files\CashOn\bin\CashOnUpdate02240404.exe
c:\program files\CashOn\bin\CashOnUpdate02240405.exe
c:\program files\CashOn\bin\CashOnUpdate02240406.exe
c:\program files\CashOn\bin\CashOnUpdate02240407.exe
c:\program files\CashOn\bin\CashOnUpdate02240408.exe
c:\program files\CashOn\bin\CashOnUpdate02240409.exe
c:\program files\CashOn\bin\CashOnUpdate02240410.exe
c:\program files\CashOn\bin\CashOnUpdate02240411.exe
c:\program files\CashOn\bin\CashOnUpdate02240412.exe
c:\program files\CashOn\bin\CashOnUpdate02240413.exe
c:\program files\CashOn\bin\CashOnUpdate02240414.exe
c:\program files\CashOn\bin\CashOnUpdate02240415.exe
c:\program files\CashOn\bin\CashOnUpdate02240416.exe
c:\program files\CashOn\bin\CashOnUpdate02240417.exe
c:\program files\CashOn\bin\CashOnUpdate02240418.exe
c:\program files\CashOn\bin\CashOnUpdate02240419.exe
c:\program files\CashOn\bin\CashOnUpdate02240420.exe
c:\program files\CashOn\bin\CashOnUpdate02240421.exe
c:\program files\CashOn\bin\CashOnUpdate02240422.exe
c:\program files\CashOn\bin\CashOnUpdate02240423.exe
c:\program files\CashOn\bin\CashOnUpdate02240424.exe
c:\program files\CashOn\bin\CashOnUpdate02240425.exe
c:\program files\CashOn\bin\CashOnUpdate02240426.exe
c:\program files\CashOn\bin\CashOnUpdate02240427.exe
c:\program files\CashOn\bin\CashOnUpdate02240428.exe
c:\program files\CashOn\bin\CashOnUpdate02240429.exe
c:\program files\CashOn\bin\CashOnUpdate02240430.exe
c:\program files\CashOn\bin\CashOnUpdate02240431.exe
c:\program files\CashOn\bin\CashOnUpdate02240432.exe
c:\program files\CashOn\bin\CashOnUpdate02240433.exe
c:\program files\CashOn\bin\CashOnUpdate02240434.exe
c:\program files\CashOn\bin\CashOnUpdate02240435.exe
c:\program files\CashOn\bin\CashOnUpdate02240436.exe
c:\program files\CashOn\bin\CashOnUpdate02240437.exe
c:\program files\CashOn\bin\CashOnUpdate02240438.exe
c:\program files\CashOn\bin\CashOnUpdate02240439.exe
c:\program files\CashOn\bin\CashOnUpdate02240440.exe
c:\program files\CashOn\bin\CashOnUpdate02240441.exe
c:\program files\CashOn\bin\CashOnUpdate02240442.exe
c:\program files\CashOn\bin\CashOnUpdate02240443.exe
c:\program files\CashOn\bin\CashOnUpdate02240444.exe
c:\program files\CashOn\bin\CashOnUpdate02240445.exe
c:\program files\CashOn\bin\CashOnUpdate02240446.exe
c:\program files\CashOn\bin\CashOnUpdate02240447.exe
c:\program files\CashOn\bin\CashOnUpdate02240448.exe
c:\program files\CashOn\bin\CashOnUpdate02240449.exe
c:\program files\CashOn\bin\CashOnUpdate02240450.exe
c:\program files\CashOn\bin\CashOnUpdate02240451.exe
c:\program files\CashOn\bin\CashOnUpdate02240452.exe
c:\program files\CashOn\bin\CashOnUpdate02240453.exe
c:\program files\CashOn\bin\CashOnUpdate02240454.exe
c:\program files\CashOn\bin\CashOnUpdate02240455.exe
c:\program files\CashOn\bin\CashOnUpdate02240456.exe
c:\program files\CashOn\bin\CashOnUpdate02240457.exe
c:\program files\CashOn\bin\CashOnUpdate02240458.exe
c:\program files\CashOn\bin\CashOnUpdate02240459.exe
c:\program files\CashOn\bin\CashOnUpdate02240500.exe
c:\program files\CashOn\bin\CashOnUpdate02240501.exe
c:\program files\CashOn\bin\CashOnUpdate02240502.exe
c:\program files\CashOn\bin\CashOnUpdate02240503.exe
c:\program files\CashOn\bin\CashOnUpdate02240504.exe
c:\program files\CashOn\bin\CashOnUpdate02240505.exe
c:\program files\CashOn\bin\CashOnUpdate02240506.exe
c:\program files\CashOn\bin\CashOnUpdate02240507.exe
c:\program files\CashOn\bin\CashOnUpdate02240508.exe
c:\program files\CashOn\bin\CashOnUpdate02240509.exe
c:\program files\CashOn\bin\CashOnUpdate02240510.exe
c:\program files\CashOn\bin\CashOnUpdate02240511.exe
c:\program files\CashOn\bin\CashOnUpdate02240512.exe
c:\program files\CashOn\bin\CashOnUpdate02240513.exe
c:\program files\CashOn\bin\CashOnUpdate02240514.exe
c:\program files\CashOn\bin\CashOnUpdate02240515.exe
c:\program files\CashOn\bin\CashOnUpdate02240516.exe
c:\program files\CashOn\bin\CashOnUpdate02240517.exe
c:\program files\CashOn\bin\CashOnUpdate02240518.exe
c:\program files\CashOn\bin\CashOnUpdate02240519.exe
c:\program files\CashOn\bin\CashOnUpdate02240520.exe
c:\program files\CashOn\bin\CashOnUpdate02240521.exe
c:\program files\CashOn\bin\CashOnUpdate02240522.exe
c:\program files\CashOn\bin\CashOnUpdate02240523.exe
c:\program files\CashOn\bin\CashOnUpdate02240524.exe
c:\program files\CashOn\bin\CashOnUpdate02240525.exe
c:\program files\CashOn\bin\CashOnUpdate02240526.exe
c:\program files\CashOn\bin\CashOnUpdate02240527.exe
c:\program files\CashOn\bin\CashOnUpdate02240528.exe
c:\program files\CashOn\bin\CashOnUpdate02240529.exe
c:\program files\CashOn\bin\CashOnUpdate02240530.exe
c:\program files\CashOn\bin\CashOnUpdate02240531.exe
c:\program files\CashOn\bin\CashOnUpdate02240532.exe
c:\program files\CashOn\bin\CashOnUpdate02240533.exe
c:\program files\CashOn\bin\CashOnUpdate02240534.exe
c:\program files\CashOn\bin\CashOnUpdate02240535.exe
c:\program files\CashOn\bin\CashOnUpdate02240536.exe
c:\program files\CashOn\bin\CashOnUpdate02240537.exe
c:\program files\CashOn\bin\CashOnUpdate02240538.exe
c:\program files\CashOn\bin\CashOnUpdate02240539.exe
c:\program files\CashOn\bin\CashOnUpdate02240540.exe
c:\program files\CashOn\bin\CashOnUpdate02240541.exe
c:\program files\CashOn\bin\CashOnUpdate02240542.exe
c:\program files\CashOn\bin\CashOnUpdate02240543.exe
c:\program files\CashOn\bin\CashOnUpdate02240544.exe
c:\program files\CashOn\bin\CashOnUpdate02240545.exe
c:\program files\CashOn\bin\CashOnUpdate02240546.exe
c:\program files\CashOn\bin\CashOnUpdate02240547.exe
c:\program files\CashOn\bin\CashOnUpdate02240548.exe
c:\program files\CashOn\bin\CashOnUpdate02240549.exe
c:\program files\CashOn\bin\CashOnUpdate02240550.exe
c:\program files\CashOn\bin\CashOnUpdate02240551.exe
c:\program files\CashOn\bin\CashOnUpdate02240552.exe
c:\program files\CashOn\bin\CashOnUpdate02240553.exe
c:\program files\CashOn\bin\CashOnUpdate02240554.exe
c:\program files\CashOn\bin\CashOnUpdate02240555.exe
c:\program files\CashOn\bin\CashOnUpdate02240556.exe
c:\program files\CashOn\bin\CashOnUpdate02240557.exe
c:\program files\CashOn\bin\CashOnUpdate02240558.exe
c:\program files\CashOn\bin\CashOnUpdate02240559.exe
c:\program files\CashOn\bin\CashOnUpdate02240600.exe
c:\program files\CashOn\bin\CashOnUpdate02240601.exe
c:\program files\CashOn\bin\CashOnUpdate02240602.exe
c:\program files\CashOn\bin\CashOnUpdate02240603.exe
c:\program files\CashOn\bin\CashOnUpdate02240604.exe
c:\program files\Gamevance
c:\program files\Gamevance\ars.cfg
c:\program files\Gamevance\gamevance32.exe
c:\program files\Gamevance\gamevancelib32.dll
c:\program files\Gamevance\gvun.exe
c:\program files\Gamevance\icon.ico
c:\program files\pointgo
c:\program files\pointgo\cfg.dat
c:\program files\pointgo\favorite.lst
c:\program files\pointgo\pgo.exe
c:\program files\pointgo\pointgo.dll
c:\program files\pointgo\uninstall.exe
c:\program files\rnic\SPBho.dll
c:\program files\WebSearchBar
c:\program files\WildTangent
c:\program files\WildTangent\Apps\GameChannel\Games\81A1E9DA-7293-4DF5-A7E8-EF5E156CDD24\def.dat
c:\program files\WildTangent\Apps\GameChannel\Games\C0A0AA4D-C79B-48CA-8843-2B02B626C9E6\def.dat
c:\program files\WildTangent\Apps\GameChannel\Games\C0A0AA4D-C79B-48CA-8843-2B02B626C9E6\options.dat
c:\program files\WildTangent\Apps\GameChannel\Games\D1A6F3FD-7B40-443F-8767-BADB25A0D222\data.dat
c:\program files\WildTangent\Apps\GameChannel\Games\D1A6F3FD-7B40-443F-8767-BADB25A0D222\def.dat
c:\program files\WildTangent\LicenseStores\WT\wt.sto
c:\windows\system32\5rqkCemn.exe
c:\windows\Tasks\At100.job
c:\windows\Tasks\At101.job
c:\windows\Tasks\At102.job
c:\windows\Tasks\At103.job
c:\windows\Tasks\At104.job
c:\windows\Tasks\At105.job
c:\windows\Tasks\At106.job
c:\windows\Tasks\At107.job
c:\windows\Tasks\At108.job
c:\windows\Tasks\At109.job
c:\windows\Tasks\At110.job
c:\windows\Tasks\At111.job
c:\windows\Tasks\At112.job
c:\windows\Tasks\At113.job
c:\windows\Tasks\At114.job
c:\windows\Tasks\At115.job
c:\windows\Tasks\At116.job
c:\windows\Tasks\At117.job
c:\windows\Tasks\At118.job
c:\windows\Tasks\At119.job
c:\windows\Tasks\At120.job
c:\windows\Tasks\At121.job
c:\windows\Tasks\At122.job
c:\windows\Tasks\At123.job
c:\windows\Tasks\At124.job
c:\windows\Tasks\At125.job
c:\windows\Tasks\At126.job
c:\windows\Tasks\At127.job
c:\windows\Tasks\At128.job
c:\windows\Tasks\At129.job
c:\windows\Tasks\At130.job
c:\windows\Tasks\At131.job
c:\windows\Tasks\At132.job
c:\windows\Tasks\At133.job
c:\windows\Tasks\At134.job
c:\windows\Tasks\At135.job
c:\windows\Tasks\At136.job
c:\windows\Tasks\At137.job
c:\windows\Tasks\At138.job
c:\windows\Tasks\At139.job
c:\windows\Tasks\At140.job
c:\windows\Tasks\At141.job
c:\windows\Tasks\At142.job
c:\windows\Tasks\At143.job
c:\windows\Tasks\At144.job
c:\windows\Tasks\At145.job
c:\windows\Tasks\At146.job
c:\windows\Tasks\At147.job
c:\windows\Tasks\At148.job
c:\windows\Tasks\At149.job
c:\windows\Tasks\At150.job
c:\windows\Tasks\At151.job
c:\windows\Tasks\At152.job
c:\windows\Tasks\At153.job
c:\windows\Tasks\At154.job
c:\windows\Tasks\At155.job
c:\windows\Tasks\At156.job
c:\windows\Tasks\At157.job
c:\windows\Tasks\At158.job
c:\windows\Tasks\At159.job
c:\windows\Tasks\At160.job
c:\windows\Tasks\At161.job
c:\windows\Tasks\At162.job
c:\windows\Tasks\At163.job
c:\windows\Tasks\At164.job
c:\windows\Tasks\At165.job
c:\windows\Tasks\At166.job
c:\windows\Tasks\At167.job
c:\windows\Tasks\At168.job
c:\windows\Tasks\At169.job
c:\windows\Tasks\At170.job
c:\windows\Tasks\At171.job
c:\windows\Tasks\At172.job
c:\windows\Tasks\At173.job
c:\windows\Tasks\At174.job
c:\windows\Tasks\At175.job
c:\windows\Tasks\At176.job
c:\windows\Tasks\At177.job
c:\windows\Tasks\At178.job
c:\windows\Tasks\At179.job
c:\windows\Tasks\At180.job
c:\windows\Tasks\At181.job
c:\windows\Tasks\At182.job
c:\windows\Tasks\At183.job
c:\windows\Tasks\At184.job
c:\windows\Tasks\At185.job
c:\windows\Tasks\At186.job
c:\windows\Tasks\At187.job
c:\windows\Tasks\At188.job
c:\windows\Tasks\At189.job
c:\windows\Tasks\At190.job
c:\windows\Tasks\At191.job
c:\windows\Tasks\At192.job
c:\windows\Tasks\At193.job
c:\windows\Tasks\At194.job
c:\windows\Tasks\At195.job
c:\windows\Tasks\At196.job
c:\windows\Tasks\At197.job
c:\windows\Tasks\At198.job
c:\windows\Tasks\At199.job
c:\windows\Tasks\At200.job
c:\windows\Tasks\At201.job
c:\windows\Tasks\At202.job
c:\windows\Tasks\At203.job
c:\windows\Tasks\At204.job
c:\windows\Tasks\At205.job
c:\windows\Tasks\At206.job
c:\windows\Tasks\At207.job
c:\windows\Tasks\At208.job
c:\windows\Tasks\At209.job
c:\windows\Tasks\At210.job
c:\windows\Tasks\At211.job
c:\windows\Tasks\At212.job
c:\windows\Tasks\At213.job
c:\windows\Tasks\At214.job
c:\windows\Tasks\At215.job
c:\windows\Tasks\At216.job
c:\windows\Tasks\At25.job
c:\windows\Tasks\At26.job
c:\windows\Tasks\At27.job
c:\windows\Tasks\At28.job
c:\windows\Tasks\At29.job
c:\windows\Tasks\At30.job
c:\windows\Tasks\At31.job
c:\windows\Tasks\At32.job
c:\windows\Tasks\At33.job
c:\windows\Tasks\At34.job
c:\windows\Tasks\At35.job
c:\windows\Tasks\At36.job
c:\windows\Tasks\At37.job
c:\windows\Tasks\At38.job
c:\windows\Tasks\At39.job
c:\windows\Tasks\At40.job
c:\windows\Tasks\At41.job
c:\windows\Tasks\At42.job
c:\windows\Tasks\At43.job
c:\windows\Tasks\At44.job
c:\windows\Tasks\At45.job
c:\windows\Tasks\At46.job
c:\windows\Tasks\At47.job
c:\windows\Tasks\At48.job
c:\windows\Tasks\At49.job
c:\windows\Tasks\At50.job
c:\windows\Tasks\At51.job
c:\windows\Tasks\At52.job
c:\windows\Tasks\At53.job
c:\windows\Tasks\At54.job
c:\windows\Tasks\At55.job
c:\windows\Tasks\At56.job
c:\windows\Tasks\At57.job
c:\windows\Tasks\At58.job
c:\windows\Tasks\At59.job
c:\windows\Tasks\At60.job
c:\windows\Tasks\At61.job
c:\windows\Tasks\At62.job
c:\windows\Tasks\At63.job
c:\windows\Tasks\At64.job
c:\windows\Tasks\At65.job
c:\windows\Tasks\At66.job
c:\windows\Tasks\At67.job
c:\windows\Tasks\At68.job
c:\windows\Tasks\At69.job
c:\windows\Tasks\At70.job
c:\windows\Tasks\At71.job
c:\windows\Tasks\At72.job
c:\windows\Tasks\At73.job
c:\windows\Tasks\At74.job
c:\windows\Tasks\At75.job
c:\windows\Tasks\At76.job
c:\windows\Tasks\At77.job
c:\windows\Tasks\At78.job
c:\windows\Tasks\At79.job
c:\windows\Tasks\At80.job
c:\windows\Tasks\At81.job
c:\windows\Tasks\At82.job
c:\windows\Tasks\At83.job
c:\windows\Tasks\At84.job
c:\windows\Tasks\At85.job
c:\windows\Tasks\At86.job
c:\windows\Tasks\At87.job
c:\windows\Tasks\At88.job
c:\windows\Tasks\At89.job
c:\windows\Tasks\At90.job
c:\windows\Tasks\At91.job
c:\windows\Tasks\At92.job
c:\windows\Tasks\At93.job
c:\windows\Tasks\At94.job
c:\windows\Tasks\At95.job
c:\windows\Tasks\At96.job
c:\windows\Tasks\At97.job
c:\windows\Tasks\At98.job
c:\windows\Tasks\At99.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_DUMP_WMIMMC
——-\Service_dump_wmimmc


((((((((((((((((((((((((( Files Created from 2009-01-25 to 2009-02-25 )))))))))))))))))))))))))))))))
.

2009-02-24 19:43 . 2009-02-24 19:45 d——– C:\Rooter$
2009-02-23 20:42 . 2009-01-18 14:35 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-02-23 19:05 . 2009-01-18 14:30 64,160 –a—— c:\windows\system32\drivers\Lbd.sys
2009-02-23 19:03 . 2009-02-23 19:03 d——– c:\program files\Lavasoft
2009-02-23 19:03 . 2009-02-23 19:05 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-23 19:03 . 2009-02-23 19:03 d–h-c— c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-23 18:25 . 2009-02-23 18:25 d——– C:\HijackThis

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-25 02:53 ——— d—–w c:\program files\rnic
2009-02-25 02:18 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-02-25 01:13 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-02-24 03:49 ——— d—–w c:\program files\MUSICMATCH
2009-02-24 03:44 ——— d—–w c:\program files\ESTsoft
2009-02-24 03:44 ——— d—–w c:\documents and settings\Thomas Bryant\Application Data\ESTsoft
2009-02-24 03:05 ——— d—–w c:\program files\LimeWire
2009-02-24 03:04 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-24 03:04 ——— d—–w c:\documents and settings\All Users\Application Data\Napster
2009-02-24 03:03 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-22 22:49 ——— d—–w c:\program files\Dl_cats
2009-02-21 17:06 ——— d—–w c:\documents and settings\NetworkService\Application Data\Yahoo!
2009-02-12 02:20 ——— d—–w c:\program files\Google
2009-01-16 23:06 ——— d—–w c:\documents and settings\All Users\Application Data\Electronic Arts
2009-01-15 22:57 ——— d—–w c:\documents and settings\Kum Bryant\Application Data\LimeWire
2009-01-12 22:40 ——— d—–w c:\documents and settings\Kum Bryant\Application Data\Elluminate
2008-02-06 00:31 131,584 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-02-24_18.18.21.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-25 02:56:29 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_7b8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2006-04-02 389120]
"AIM"="c:\progra~1\AIM\aim.exe" [2006-08-01 67112]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-09 68856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2008-06-10 785520]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-05 29744]
"DLCJCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll" [2005-08-14 73728]
"dlcjmon.exe"="c:\program files\Dell Photo AIO Printer 964\dlcjmon.exe" [2005-08-11 430080]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 964\memcard.exe" [2005-08-09 286720]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-27 185896]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-18 506712]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\stsystra.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-06-09 24576]
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Nexon\\Common\\NGLC_Nexon.exe"=
"c:\\Program Files\\Nexon\\Common\\NMService.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Nexon\\NGM\\NGM.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Nexon\\Common\\NMService.exe"=
"c:\\WINDOWS\\system32\\skcbgm.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre1.6.0_01\\bin\\javaw.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\KartRider\\NMService.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Games\\Halo Custom Edition\\haloce.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-23 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 921936]
S2 gupdate1c98c63cdc65d30;Google Update Service (gupdate1c98c63cdc65d30);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-11 133104]
S3 GoogleDesktopManager-093007-112848;Google Desktop Manager 5.5.709.30344;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-06-09 29744]
S3 scskusbf;USB SCSK Filter Driver Service;c:\windows\system32\drivers\scskusbf.sys [2007-01-07 18316]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
Contents of the 'Scheduled Tasks' folder

2009-02-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 14:34]

2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-02-25 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-11 09:13]

2009-02-25 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-11 09:14]

2009-02-25 c:\windows\Tasks\SDMsgUpdate (TE).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2008-08-11 07:29]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Gamevance - c:\program files\Gamevance\gamevance32.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Google; Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Search; - http://edits.mywebsearch.com/toolbaredits/…?p=ZKxdm021YYUS
IE: &Translate; English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm
DPF: {044123B5-35DF-4C4E-BAED-26B8ED964342} - hxxp://fx.hauri.net/HProduct/livesuite/shinhancard/CLIENT/LiveSuite/web/HLiveRobotWeb.cab
DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} - hxxp://s.nx.com/activex/public_new/nxpm.cab
DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} - hxxp://www.auctiva.com/Aurigma/ImageUploader55.cab
DPF: {5DAEF053-DEF0-4752-A963-CCE9B49B0B79} - hxxp://blog.naver.com/common/item/nbgm.cab
DPF: {6FE760D3-7851-4879-8838-62D9881D7177} - hxxp://www.letskt.com/imas/IniMasPlugin.cab
DPF: {7E9FDB80-5316-11D4-B02C-00C04F0CD404} - hxxp://www.samsungcard.co.kr/XecureDemo/XecureObject/xw_install.cab
DPF: {8BCAB742-72F8-4119-A4B4-8F639A6E27B3} - hxxp://photolog.blog.naver.com/NIU.CAB
DPF: {92D0D610-A6FA-48D8-94CB-BD47FDF68655} - hxxp://app.tubemusic.com/naver/naverx.cab
DPF: {9CDD57AC-CA86-464C-B920-3228A388CC78} - hxxp://file.naver.com/down/NaverFile.cab
DPF: {A9DD5FE2-5567-4983-971F-C792375025A6} - hxxp://software.musicnow.com/musicnow/phoenix/5.0.0.23/MusicNow.cab
DPF: {BD6BB450-7C69-43B8-96F3-689CAE57AB51} - hxxp://netv.sbs.co.kr/object/player/SBSWebPlayer.cab
DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} - hxxp://flash.hangame.com/common/HanSetup1009.cab
DPF: {D26A941D-7E89-4098-B583-43291FC14218} - hxxp://image.pullbbang.com/images/Pull0Control.ocx
DPF: {D7602755-1F82-4EA4-B8F8-F0FA7E8A430D} - hxxp://egis.onoffkorea.com/activex/EgisBVMActiveX.cab
DPF: {E75386B4-C629-11DB-8338-444553544200} - hxxp://cyimg7.cyworld.nate.com/cymusic/package/cyinstal.cab
DPF: {F1F07506-6CB4-44AC-8615-66D1234EFD05} - hxxp://www.shinhancard.com/initech/plugin/down/INIS50.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-24 19:58:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCJCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Gamevance = c:\program files\Gamevance\gamevance32.exe?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-578257276-644222742-322493702-1005\Software\SecuROM\License information*]
"datasecu"=hex:fc,4a,27,7d,0e,fe,e6,ef,9f,a9,db,89,dd,24,e0,a3,ad,2b,e2,63,11,
93,0f,fc,1a,e8,ff,b6,eb,f5,01,86,15,23,38,c1,2f,01,11,f2,97,9b,ba,0c,67,58,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\windows\system32\npkcmsvc.exe
c:\windows\ehome\RMSvc.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\ehome\McrdSvc.exe
c:\windows\system32\fxssvc.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\dlcjcoms.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-02-24 20:02:34 - machine was rebooted [Kum Bryant]
ComboFix-quarantined-files.txt 2009-02-25 03:02:31
ComboFix2.txt 2009-02-25 01:19:12

Pre-Run: 176,188,321,792 bytes free
Post-Run: 176,126,406,656 bytes free

1017 — E O F — 2009-02-24 01:22:05

MALWARE TEXT

Malwarebytes' Anti-Malware 1.34
Database version: 1749
Windows 5.1.2600 Service Pack 2

2/24/2009 8:13:18 PM
mbam-log-2009-02-24 (20-13-18).txt

Scan type: Quick Scan
Objects scanned: 81854
Time elapsed: 2 minute(s), 43 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 22
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\gamevance.linker.1 (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\xml.xml.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1e5b2693-d348-4ca7-8364-4f5e51bf9c6d} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{54a3f8b7-228e-4ed8-895b-de832b2c3959} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bfc08cff-c737-4433-bd5a-0ee7efcfee54} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gamevance (Adware.Gamevance) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\The Weather Channel (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Weather Services (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search;\ (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls\wxfw.dll (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\upfilemans.exe (Spyware.Banker) -> Quarantined and deleted successfully.
C:\WINDOWS\inupdaters.exe (Spyware.Banker) -> Quarantined and deleted successfully.

HJT LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:14:21 PM, on 2/24/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\npkcmsvc.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\PROGRA~1\SMARTD~1\Messages\SDNotify.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dlcjcoms.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: &Google; Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate; English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {044123B5-35DF-4C4E-BAED-26B8ED964342} (HLiveRobotWeb Control) - http://fx.hauri.net/HProduct/livesuite/shi…iveRobotWeb.cab
O16 - DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} (Nexon Package Manager Control) - http://s.nx.com/activex/public_new/nxpm.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} (Auctiva Image Uploader Control) - http://www.auctiva.com/Aurigma/ImageUploader55.cab
O16 - DPF: {39FC0CF9-86F3-4502-B773-D16706EDEC83} (SCSK Control) - http://www.shinhancard.com/common/scsk4.cab
O16 - DPF: {5DAEF053-DEF0-4752-A963-CCE9B49B0B79} (Gogs Class) - http://blog.naver.com/common/item/nbgm.cab
O16 - DPF: {6FE760D3-7851-4879-8838-62D9881D7177} (IniMasHandler Class) - http://www.letskt.com/imas/IniMasPlugin.cab
O16 - DPF: {7E9FDB80-5316-11D4-B02C-00C04F0CD404} (XecureWeb 4.0 Client Control) - http://www.samsungcard.co.kr/XecureDemo/Xe…/xw_install.cab
O16 - DPF: {8BCAB742-72F8-4119-A4B4-8F639A6E27B3} (CNaverImageUploadCtl Object) - http://photolog.blog.naver.com/NIU.CAB
O16 - DPF: {92D0D610-A6FA-48D8-94CB-BD47FDF68655} (Launcher Class) - http://app.tubemusic.com/naver/naverx.cab
O16 - DPF: {9CDD57AC-CA86-464C-B920-3228A388CC78} (NaverFileControl Control) - http://file.naver.com/down/NaverFile.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A9DD5FE2-5567-4983-971F-C792375025A6} (PhoenixBody Class) - http://software.musicnow.com/musicnow/phoe…23/MusicNow.cab
O16 - DPF: {BD6BB450-7C69-43B8-96F3-689CAE57AB51} (SBSWebPlayer Class) - http://netv.sbs.co.kr/object/player/SBSWebPlayer.cab
O16 - DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} (HanSetupCtrl1009 Class) - http://flash.hangame.com/common/HanSetup1009.cab
O16 - DPF: {D26A941D-7E89-4098-B583-43291FC14218} (Pull0PlayerX Control) - http://image.pullbbang.com/images/Pull0Control.ocx
O16 - DPF: {D7602755-1F82-4EA4-B8F8-F0FA7E8A430D} (EgisBVMActiveX Control) - http://egis.onoffkorea.com/activex/EgisBVMActiveX.cab
O16 - DPF: {E75386B4-C629-11DB-8338-444553544200} (PcubeSet Class) - http://cyimg7.cyworld.nate.com/cymusic/package/cyinstal.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.auctiva.com/hostedimages/active…oad/XUpload.ocx
O16 - DPF: {F1F07506-6CB4-44AC-8615-66D1234EFD05} (WebCtl Class) - http://www.shinhancard.com/initech/plugin/down/INIS50.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Desktop Manager 5.5.709.30344 (GoogleDesktopManager-093007-112848) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c98c63cdc65d30) (gupdate1c98c63cdc65d30) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcmsvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O24 - Desktop Component 0: (no name) - http://www.bungie.net/images/themes/Defaul…nBackground.gif

–
End of file - 15178 bytes


These are all the logs requested. The computer seems to be running much smoother and faster. Please let me know if I need to do anything further.

Thank you so much for all the help so far!

Beth Ann
bethk,

Good! Little more to do.

Your Java is out of date and you have other old versions still on your computer, those old versions are now a security vulnerability:

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer - Version 6 update 12


Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply please provide:
  • Javara report
  • Kaspersky report
  • New HijackThis log taken after everything else completed
Hi Tom,

Here are the reports - unfortunately, when I went out to the Kapersky site it would not do the update to the database. I kept getting an error, so could not run this. |
Any suggestions??

Report follows after line.

————————————

The JavaRa removal process was started on Wed Feb 25 17:33:43 2009

Found and removed: C:\Program Files\Java\j2re1.4.2_03

Found and removed: C:\Program Files\Java\jre1.5.0_06

Found and removed: C:\Program Files\Java\jre1.6.0_01

Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142030}

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4

Found and removed: Software\JavaSoft\Java2D\1.5.0_06

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510006

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510006

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510006

Found and removed: SOFTWARE\Classes\JavaPlugin.150_06

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_06

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_06

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510006

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510006

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150060}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\JavaPlugin.160_01

Found and removed: SOFTWARE\Classes\JavaPlugin.160_03

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_01

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_03

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_01

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_03

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160010}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160030}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142030}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410203

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410203

Found and removed: SOFTWARE\Classes\JavaPlugin.142_03

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_03

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_06

Found and removed: Software\Classes\JavaPlugin.142_03

Found and removed: Software\Classes\JavaPlugin.160_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_03

Found and removed: Software\JavaSoft\Java2D\1.6.0_01

Found and removed: Software\JavaSoft\Java2D\1.6.0_03

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_01

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_03

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_06\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_01\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_01\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_01.b06\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_03.b05\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core1.zip

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core2.zip

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core3.zip

————————————

Finished reporting.



HJT REPORT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:32:04 PM, on 2/25/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\npkcmsvc.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dlcjcoms.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {39FC0CF9-86F3-4502-B773-D16706EDEC83} (SCSK Control) - http://www.shinhancard.com/common/scsk4.cab
O16 - DPF: {7E9FDB80-5316-11D4-B02C-00C04F0CD404} (XecureWeb 4.0 Client Control) - http://www.samsungcard.co.kr/XecureDemo/Xe…/xw_install.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A9DD5FE2-5567-4983-971F-C792375025A6} (PhoenixBody Class) - http://software.musicnow.com/musicnow/phoe…23/MusicNow.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.auctiva.com/hostedimages/active…oad/XUpload.ocx
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Desktop Manager 5.5.709.30344 (GoogleDesktopManager-093007-112848) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c98c63cdc65d30) (gupdate1c98c63cdc65d30) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcmsvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O24 - Desktop Component 0: (no name) - http://www.bungie.net/images/themes/Defaul…nBackground.gif

–
End of file - 13188 bytes


Let me know what I need to do next ….

Beth Ann
bethk,

Let's try a different online scan.

I need you to run the following scan: Eset Online Scanner

  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Hi again, Here is the log from ESET # version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=3890 (20090226) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.066 (20070917) # EOSSerial=d11bda2cc45e034e8b6f5141a86ad45c # end=finished # remove_checked=false # unwanted_checked=false # utc_time=2009-02-26 02:45:52 # local_time=2009-02-25 07:45:52 (-0700, US Mountain Standard Time) # country="United States" # osver=5.1.2600 NT Service Pack 2 # scanned=634058 # found=15 # scan_time=2553 C:\Program Files\dalgonaTVPlayer\dalgonaTVPlayer.exe probably a variant of Win32/TrojanDownloader.Delf trojan 9A14318D9109D982D1362FA504BC4C06 C:\Program Files\rnic\SPExe.exe probably a variant of Win32/Spy.Banker trojan 239C35C6DB8EE9BF938F8D6571286A26 C:\Program Files\rnic\Uninstall.exe probably unknown NewHeur_PE virus 00000000000000000000000000000000 C:\Qoobox\Quarantine\C\WINDOWS\system32\5rqkCemn.exe.vir Win32/TrojanClicker.Agent.NEB trojan B45325D3BC6EA191BBB1DE76FEA9306D C:\WINDOWS\3457\backup2_26.zip probably a variant of Win32/TrojanDownloader.Seimon.D trojan 336C98FF35C113290211837E0607495B C:\WINDOWS\3457\backup2_26.zip »ZIP »backup2_26.exe probably a variant of Win32/TrojanDownloader.Seimon.D trojan 00000000000000000000000000000000 C:\WINDOWS\8857\Agent_01.zip probably a variant of Win32/TrojanDownloader.Seimon.D trojan A996AA6DB4AC5B6F6969F1FDD0FEAE67 C:\WINDOWS\8857\Agent_01.zip »ZIP »Agent_01.exe probably a variant of Win32/TrojanDownloader.Seimon.D trojan 00000000000000000000000000000000 C:\WINDOWS\8857\Agent_05.zip probably a variant of Win32/TrojanDownloader.Seimon.D trojan 1AFE04F41A33BC0E769957E5197BBBA5 C:\WINDOWS\8857\Agent_05.zip »ZIP »Agent_05.exe probably a variant of Win32/TrojanDownloader.Seimon.D trojan 00000000000000000000000000000000 C:\WINDOWS\8857\backup1_26.zip probably a variant of Win32/TrojanDownloader.Seimon.D trojan 8F79EDA24043CEC0D918137C43ED10A2 C:\WINDOWS\8857\backup1_26.zip »ZIP »backup1_26.exe probably a variant of Win32/TrojanDownloader.Seimon.D trojan 00000000000000000000000000000000 C:\WINDOWS\system32\ecashsave.dll probably a variant of Win32/BHO trojan AA1C3DCC8292BC3B674FBC70E35E5FD4 C:\WINDOWS\system32\ninza.exe probably a variant of Win32/TrojanDownloader.Agent trojan 2E1ABF1BACE348E9B0EABEF5B523B9B9 C:\WINDOWS\system32\rnic.EXE probably unknown NewHeur_PE virus 00000000000000000000000000000000 Awaiting your instructions …..
bethk,

We're getting close.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Program Files\dalgonaTVPlayer\dalgonaTVPlayer.exe
    C:\WINDOWS\system32\ecashsave.dll
    C:\WINDOWS\system32\ninza.exe 
    C:\WINDOWS\system32\rnic.EXE 
    
    Folder::
    C:\WINDOWS\8857
    C:\WINDOWS\3457
    C:\Program Files\rnic
    
    Registry::
    
    Driver::
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then please give me another HijackThis log.
Hi Tom,

Here I am again - this is the COMBOFIX log … will get HJT log on in a few minutes….

Thanks so much …. it seems to be a neverending story!

ComboFix 09-02-24.01 - Kum Bryant 2009-02-25 20:52:09.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.406 [GMT -7:00]
Running from: E:\ComboFix.exe
Command switches used :: c:\documents and settings\Kum Bryant\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
c:\program files\dalgonaTVPlayer\dalgonaTVPlayer.exe
c:\windows\system32\ecashsave.dll
c:\windows\system32\ninza.exe
c:\windows\system32\rnic.EXE
.

((((((((((((((((((((((((((((((((((((((( Other Deletions

)))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\dalgonaTVPlayer\dalgonaTVPlayer.exe
c:\program files\rnic
c:\program files\rnic\SPData.dll
c:\program files\rnic\SPdll.dll
c:\program files\rnic\SPExe.exe
c:\program files\rnic\SPOData.dll
c:\program files\rnic\SPSbar.dll
c:\program files\rnic\SPSql.dll
c:\program files\rnic\Uninstall.exe
c:\windows\3457
c:\windows\3457\backup2_26.zip
c:\windows\8857
c:\windows\8857\Agent_01.zip
c:\windows\8857\Agent_05.zip
c:\windows\8857\backup1_26.zip
c:\windows\system32\ecashsave.dll
c:\windows\system32\rnic.EXE

.
((((((((((((((((((((((((( Files Created from 2009-01-26 to 2009-02-26

)))))))))))))))))))))))))))))))
.

2009-02-25 20:28 . 2009-02-25 20:28 d——– c:\program files\Symantec
2009-02-25 20:28 . 2009-02-25 20:28 110,952 –a——

c:\windows\system32\drivers\SYMEVENT.SYS
2009-02-25 20:28 . 2009-02-25 20:28 48,768 –a—— c:\windows\system32\S32EVNT1.DLL
2009-02-25 20:28 . 2009-02-25 20:28 8,014 –a——

c:\windows\system32\drivers\SYMEVENT.CAT
2009-02-25 20:28 . 2009-02-25 20:28 805 –a——

c:\windows\system32\drivers\SYMEVENT.INF
2009-02-25 20:27 . 2009-02-25 20:49 d——– c:\program files\Symantec

AntiVirus
2009-02-25 18:59 . 2009-02-25 19:45 d——– c:\program

files\EsetOnlineScanner
2009-02-25 17:54 . 2009-02-25 17:53 410,984 –a—— c:\windows\system32\deploytk.dll
2009-02-25 17:46 . 2009-02-25 17:46 d——– c:\program files\Belkin
2009-02-25 17:46 . 2005-08-02 23:00 232,192 –a——

c:\windows\system32\drivers\rt73.sys
2009-02-25 17:46 . 2003-10-13 15:30 94,208 –a—— c:\windows\system32\GTW32N50.dll
2009-02-25 17:46 . 2004-04-30 15:12 40,960 –a—— c:\windows\system32\B11gUSB.dll
2009-02-25 17:46 . 2003-09-25 23:28 31,930 –a—— c:\windows\system32\GTNDIS3.VXD
2009-02-25 17:46 . 2009-02-25 17:46 20,747 –a——

c:\windows\system32\drivers\AegisP.sys
2009-02-25 17:46 . 2003-09-25 22:15 15,872 –a—— c:\windows\system32\GTNDIS5.sys
2009-02-24 20:14 . 2009-02-24 20:14 d——– c:\program files\Trend Micro
2009-02-24 20:09 . 2009-02-24 20:09 d——– c:\documents and settings\Kum

Bryant\Application Data\Malwarebytes
2009-02-24 20:09 . 2009-02-24 20:09 d——– c:\documents and settings\All

Users\Application Data\Malwarebytes
2009-02-24 19:43 . 2009-02-24 19:45 d——– C:\Rooter$
2009-02-23 20:42 . 2009-01-18 14:35 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-02-23 19:05 . 2009-01-18 14:30 64,160 –a——

c:\windows\system32\drivers\Lbd.sys
2009-02-23 19:03 . 2009-02-23 19:03 d——– c:\program files\Lavasoft
2009-02-23 19:03 . 2009-02-23 19:05 d——– c:\documents and settings\All

Users\Application Data\Lavasoft
2009-02-23 19:03 . 2009-02-23 19:03 d–h-c— c:\documents and settings\All

Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-23 18:25 . 2009-02-23 18:25 d——– C:\HijackThis

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report

))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-26 03:52 ——— d—–w c:\program files\dalgonaTVPlayer
2009-02-26 03:28 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-02-26 03:27 ——— d—–w c:\documents and settings\All Users\Application

Data\Symantec
2009-02-26 03:19 ——— d—–w c:\documents and settings\All Users\Application

Data\Google Updater
2009-02-26 01:26 ——— d—–w c:\program files\Java
2009-02-25 03:54 5,018 –sha-w c:\windows\system32\KGyGaAvL.sys
2009-02-24 03:49 ——— d—–w c:\program files\MUSICMATCH
2009-02-24 03:44 ——— d—–w c:\program files\ESTsoft
2009-02-24 03:44 ——— d—–w c:\documents and settings\Thomas

Bryant\Application Data\ESTsoft
2009-02-24 03:05 ——— d—–w c:\program files\LimeWire
2009-02-24 03:04 ——— d–h–w c:\program files\InstallShield Installation

Information
2009-02-24 03:04 ——— d—–w c:\documents and settings\All Users\Application

Data\Napster
2009-02-24 03:03 ——— d—a-w c:\documents and settings\All Users\Application

Data\TEMP
2009-02-22 22:49 ——— d—–w c:\program files\Dl_cats
2009-02-21 17:06 ——— d—–w c:\documents and

settings\NetworkService\Application Data\Yahoo!
2009-02-12 02:20 ——— d—–w c:\program files\Google
2009-01-17 04:35 3,594,752 —-a-w c:\windows\system32\dllcache\mshtml.dll
2009-01-16 23:06 ——— d—–w c:\documents and settings\All Users\Application

Data\Electronic Arts
2009-01-15 22:57 ——— d—–w c:\documents and settings\Kum Bryant\Application

Data\LimeWire
2009-01-12 22:40 ——— d—–w c:\documents and settings\Kum Bryant\Application

Data\Elluminate
2008-12-19 09:10 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 —-a-w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
2008-12-11 11:57 333,184 ——w c:\windows\system32\dllcache\srv.sys
2008-02-06 00:31 131,584 —-a-w c:\program files\mozilla

firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-02-24_18.18.21.45

)))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-26 03:28:54 25,214 —-a-r

c:\windows\Installer\{50E125D1-88E5-48CE-80AE-98EC9698E639}\ARPPRODUCTICON.exe
+ 2009-02-26 03:28:54 40,960 —-a-r

c:\windows\Installer\{50E125D1-88E5-48CE-80AE-98EC9698E639}\DTIcon.ECFEE69D_DA66_4F00_ABE5_54E931

059C01.exe
+ 2009-02-26 03:28:54 40,960 —-a-r

c:\windows\Installer\{50E125D1-88E5-48CE-80AE-98EC9698E639}\NewShortcut1.ECFEE69D_DA66_4F00_ABE5_

54E931059C01.exe
- 2005-09-09 00:20:04 89,088 —-a-w c:\windows\system32\atl71.dll
+ 2006-11-01 03:24:10 89,088 —-a-w c:\windows\system32\atl71.dll
+ 2007-03-15 02:50:54 34,552 —-a-w c:\windows\system32\cba.dll
+ 2007-03-29 01:51:20 12,944 —-a-w c:\windows\system32\drivers\symdns.sys
+ 2007-03-29 01:51:26 97,936 —-a-w c:\windows\system32\drivers\symfw.sys
+ 2007-03-29 01:51:36 31,888 —-a-w c:\windows\system32\drivers\symids.sys
+ 2007-03-29 01:51:32 28,304 —-a-w c:\windows\system32\drivers\symndis.sys
+ 2007-03-29 01:51:42 24,208 —-a-w c:\windows\system32\drivers\symredrv.sys
+ 2007-03-29 01:51:48 189,584 —-a-w c:\windows\system32\drivers\symtdi.sys
- 2007-09-25 05:30:28 135,168 —-a-w c:\windows\system32\java.exe
+ 2009-02-26 00:53:59 144,792 —-a-w c:\windows\system32\java.exe
- 2007-09-25 05:30:30 135,168 —-a-w c:\windows\system32\javaw.exe
+ 2009-02-26 00:53:59 144,792 —-a-w c:\windows\system32\javaw.exe
- 2007-09-25 06:31:42 139,264 —-a-w c:\windows\system32\javaws.exe
+ 2009-02-26 00:53:59 148,888 —-a-w c:\windows\system32\javaws.exe
+ 2007-07-27 21:49:02 196,683 —-a-w c:\windows\system32\lnod32apiA.dll
+ 2007-07-27 21:49:02 225,355 —-a-w c:\windows\system32\lnod32apiW.dll
+ 2005-12-06 02:25:22 139,264 —-a-w c:\windows\system32\lnod32umc.dll
+ 2005-12-05 19:37:10 106,496 —-a-w c:\windows\system32\lnod32upd.dll
+ 2007-03-15 02:50:56 83,648 —-a-w c:\windows\system32\loc32vc0.dll
- 2004-09-01 16:56:46 1,060,864 —-a-w c:\windows\system32\mfc71.dll
+ 2006-11-01 03:50:02 1,056,768 —-a-w c:\windows\system32\mfc71.dll
+ 2006-11-01 03:54:26 40,960 —-a-w c:\windows\system32\MFC71CHS.DLL
+ 2006-11-01 03:54:26 45,056 —-a-w c:\windows\system32\MFC71CHT.DLL
+ 2006-11-01 03:54:24 65,536 —-a-w c:\windows\system32\MFC71DEU.DLL
+ 2006-11-01 03:54:26 57,344 —-a-w c:\windows\system32\MFC71ENU.DLL
+ 2006-11-01 03:54:26 61,440 —-a-w c:\windows\system32\MFC71ESP.DLL
+ 2006-11-01 03:54:24 61,440 —-a-w c:\windows\system32\MFC71FRA.DLL
+ 2006-11-01 03:54:26 61,440 —-a-w c:\windows\system32\MFC71ITA.DLL
+ 2006-11-01 03:54:26 49,152 —-a-w c:\windows\system32\MFC71JPN.DLL
+ 2006-11-01 03:54:26 49,152 —-a-w c:\windows\system32\MFC71KOR.DLL
- 2003-03-19 02:12:12 1,047,552 —-a-w c:\windows\system32\mfc71u.dll
+ 2006-11-01 04:05:20 1,049,600 —-a-w c:\windows\system32\mfc71u.dll
+ 2007-03-15 02:50:56 46,848 —-a-w c:\windows\system32\msgsys.dll
+ 2007-06-06 20:26:24 43,712 —-a-w c:\windows\system32\NavLogon.dll
+ 2007-03-15 02:50:58 91,896 —-a-w c:\windows\system32\nts.dll
+ 2008-02-11 16:39:26 253,952 —-a-w c:\windows\system32\OnlineScannerDLLA.dll
+ 2008-02-11 16:39:18 237,568 —-a-w c:\windows\system32\OnlineScannerDLLW.dll
+ 2008-02-08 20:53:46 110,592 —-a-w c:\windows\system32\OnlineScannerLang.dll
+ 2008-02-05 15:48:04 77,824 —-a-w c:\windows\system32\OnlineScannerUninstaller.exe
+ 2007-03-15 02:51:00 83,704 —-a-w c:\windows\system32\pds.dll
+ 2007-03-29 01:51:54 538,256 —-a-w c:\windows\system32\SymNeti.dll
+ 2007-03-29 01:51:52 161,424 —-a-w c:\windows\system32\SymRedir.dll
+ 2009-02-26 03:47:33 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_4a0.dat
+ 2009-02-26 03:47:32 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_84.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points

))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2006-04-02

389120]
"AIM"="c:\progra~1\AIM\aim.exe" [2006-08-01 67112]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-09

68856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07

111856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2008-06-10 785520]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07

111856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10

81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe"

[2008-02-05 29744]
"DLCJCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll" [2005-08-14 73728]
"dlcjmon.exe"="c:\program files\Dell Photo AIO Printer 964\dlcjmon.exe" [2005-08-11 430080]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 964\memcard.exe" [2005-08-09 286720]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-25 148888]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07

111856]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-27 185896]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-18 506712]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-29 52840]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-06-06 125632]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-06-09 24576]
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\Li

st]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Nexon\\Common\\NGLC_Nexon.exe"=
"c:\\Program Files\\Nexon\\Common\\NMService.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Nexon\\NGM\\NGM.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Nexon\\Common\\NMService.exe"=
"c:\\WINDOWS\\system32\\skcbgm.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\KartRider\\NMService.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Games\\Halo Custom Edition\\haloce.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-23 64160]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec

Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-25 101936]
S2 gupdate1c98c63cdc65d30;Google Update Service (gupdate1c98c63cdc65d30);c:\program

files\Google\Update\GoogleUpdate.exe [2009-02-11 133104]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program

files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 921936]
S3 GoogleDesktopManager-093007-112848;Google Desktop Manager 5.5.709.30344;c:\program

files\Google\Google Desktop Search\GoogleDesktop.exe [2006-06-09 29744]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2007-06-06 116928]
S3 scskusbf;USB SCSK Filter Driver Service;c:\windows\system32\drivers\scskusbf.sys [2007-01-07

18316]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
Contents of the 'Scheduled Tasks' folder

2009-02-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 14:34]

2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-02-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-11 09:13]

2009-02-26 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-11 09:14]

2009-02-26 c:\windows\Tasks\SDMsgUpdate (TE).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2008-08-11 07:29]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL =

hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Search
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
DPF: {7E9FDB80-5316-11D4-B02C-00C04F0CD404} -

hxxp://www.samsungcard.co.kr/XecureDemo/XecureObject/xw_install.cab
DPF: {A9DD5FE2-5567-4983-971F-C792375025A6} -

hxxp://software.musicnow.com/musicnow/phoenix/5.0.0.23/MusicNow.cab
FF - ProfilePath - c:\documents and settings\Kum Bryant\Application

Data\Mozilla\Firefox\Profiles\8rm77mk0.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com/?o=20011&l=dis
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1487.6512\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-25 20:57:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCJCATS = rundll32

c:\windows\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll,_RunDLLEntry@16??????????????????????????

?????????????????????????????????????????????????????????????????????????????????????????????????

????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-578257276-644222742-322493702-1005\Software\SecuROM\License information*]
"datasecu"=hex:fc,4a,27,7d,0e,fe,e6,ef,9f,a9,db,89,dd,24,e0,a3,ad,2b,e2,63,11,
93,0f,fc,1a,e8,ff,b6,eb,f5,01,86,15,23,38,c1,2f,01,11,f2,97,9b,ba,0c,67,58,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
.
Completion time: 2009-02-25 20:59:32
ComboFix-quarantined-files.txt 2009-02-26 03:59:04
ComboFix2.txt 2009-02-25 03:02:35
ComboFix3.txt 2009-02-25 01:19:12

Pre-Run: 175,413,415,936 bytes free
Post-Run: 175,409,836,032 bytes free

302 — E O F — 2009-02-24 01:22:05
Hello again -

Here is the latest HJT log ….

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:04:16 PM, on 2/25/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SMARTD~1\Messages\SDNotify.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\npkcmsvc.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\dlcjcoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] c:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {39FC0CF9-86F3-4502-B773-D16706EDEC83} (SCSK Control) - http://www.shinhancard.com/common/scsk4.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {7E9FDB80-5316-11D4-B02C-00C04F0CD404} (XecureWeb 4.0 Client Control) - http://www.samsungcard.co.kr/XecureDemo/Xe…/xw_install.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A9DD5FE2-5567-4983-971F-C792375025A6} (PhoenixBody Class) - http://software.musicnow.com/musicnow/phoe…23/MusicNow.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.auctiva.com/hostedimages/active…oad/XUpload.ocx
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - c:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Desktop Manager 5.5.709.30344 (GoogleDesktopManager-093007-112848) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c98c63cdc65d30) (gupdate1c98c63cdc65d30) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcmsvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - c:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - c:\Program Files\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: (no name) - http://www.bungie.net/images/themes/Defaul…nBackground.gif

–
End of file - 14622 bytes

I will await the usual … *SMILE*

Beth Ann
bethk,

Well. Every story must come to an end. :(

Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.

The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI