This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer unusually slow. Log showed trojans. Please he

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.
Yesterday I was trying to make my computer work better. I downloaded some protective and scanning programs. Some of those programs were (reading from my desktop):
spywareguard
mwav
quickscan
sarsfx
antrootkit
pandascan,

and maybe something else.

Main reason was that my AVG AV started giving me alerts that I have trojans. Some of them were repeated. It looked like they were appearing when I was doing any scans (e.g. MBAM scan), but it could be misleading as that was almost all that I was doing yesterday and today…

I was answering "Heal" and those files/trojans (?) were sent to the vault.

The trojans were mainly in the directory C:\WINDOWS\system32\drivers\ with these files:

securentm.sys
ati64si.sys
systemntmi.sys
port135sik.sys
i386si.sys
netsik.sys
ksi32sk.sys
fip32cup.sys
ws_32sik.sys
acpi32.sys
nicsk32.sys

Some of them are also associated with BN…tmp files.

I disabled AVG now and made HJT scan. Here is the log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:32:43 PM, on 24/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\PROGRA~1\MOZILL~2\THUNDE~1.EXE
C:\Program Files\AVG\AVG8\avgui.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by130fd.bay130.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: FinePrint Dispatcher v5 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O23 - Service: FinePrint Dispatcher v6 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
O23 - Service: Google Desktop Manager 5.7.805.16405 (GoogleDesktopManager-051608-133132) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c8e254e49c1a68) (gupdate1c8e254e49c1a68) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe

–
End of file - 10226 bytes

Thanks in advance for more help. Best regards.

pumex
Hi,

Yes, it appears a rootkit/backdoor trojan has arrived on board

These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been compromised.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps

This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.




Please do the following:

Download Rooter.exe to your desktop

  • Doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows).
  • Post that in your next reply.

NEXT

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
The trojans started to appear yesterday about 7:30 PM. Today they were showing up in similar fashion - once an hour or so. But I didn't have an alert since about 7 PM today. In fact, I downloaded free AVG Antiroot kit and it didn't show any rootkit after the scan that I finished about 30 minutes ago.

To answer your questions:

- I would much prefer to fix it and not to reformat my HD. I don't want to lose my stuff…
- In last few hours I used other computer that has no viruses to change my passwords and security questions at few banking/other sites that I use.
- I was not using any of those sites since about 2 PM yesterday, i.e. I didn't use them when that trojan issue started and not at all since then

Now, I downloaded rooter.exe and combofix.

When I started rooter, I got strange error message:

"Windows-No Disk
Exception Processing Message c0000013 Parameters 75b6bf7c 4 75b6bf7c 75b6bf7c"

So I didn't do that part.

Regarding combofix, I did the scan; here is the log:

ComboFix 09-04-25.03 - HP_Administrator 24/04/2009 21:18.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1398 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
.

((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-4-25 )))))))))))))))))))))))))))))))
.

2009-04-25 02:49 . 2007-01-18 12:00 3968 —-a-w c:\windows\system32\drivers\AvgArCln.sys
2009-04-24 20:07 . 2009-04-24 20:13 ——– d—–w c:\program files\SpywareBlaster
2009-04-24 19:00 . 2009-04-24 20:15 ——– d—–w c:\program files\Registry Genius
2009-04-24 08:04 . 2008-06-19 23:24 28544 —-a-w c:\windows\system32\drivers\pavboot.sys
2009-04-24 08:04 . 2009-04-24 08:04 ——– d—–w c:\program files\Panda Security
2009-04-24 05:03 . 2009-04-24 05:03 ——– d—–w c:\program files\Sophos
2009-04-24 04:39 . 2009-04-24 04:39 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\QuickScan
2009-04-24 04:16 . 2009-04-06 22:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-24 04:16 . 2009-04-06 22:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-24 04:16 . 2009-04-24 04:17 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-24 03:08 . 2009-04-24 03:08 ——– d—a-w c:\windows\system32\runouce.exe
2009-04-24 03:06 . 2009-04-24 03:08 54 —-a-w c:\windows\Lic.xxx
2009-04-24 03:06 . 2009-04-24 03:06 28672 —-a-w c:\windows\system32\eEmpty.exe
2009-04-24 03:06 . 2005-09-23 06:22 522 —-a-w c:\windows\system32\Microsoft.VC80.CRT.manifest
2009-04-24 03:06 . 2008-04-14 00:12 135680 —-a-w c:\windows\system32\T.COM
2009-04-24 03:06 . 2008-04-14 00:12 146432 —-a-w c:\windows\R.COM
2009-04-24 03:06 . 2009-04-24 03:06 ——– d—–w c:\program files\Common Files\MicroWorld
2009-04-24 03:06 . 2009-04-24 03:06 ——– d—–w c:\documents and settings\All Users\Application Data\MicroWorld
2009-04-23 23:55 . 2009-04-23 23:55 ——– d—–w c:\documents and settings\LocalService\Application Data\SACore
2009-04-23 23:55 . 2009-04-23 23:55 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\SACore
2009-04-23 23:54 . 2009-04-23 23:54 ——– d—–w c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-04-23 23:54 . 2009-04-23 23:54 ——– d—–w c:\program files\Common Files\McAfee
2009-04-23 23:53 . 2009-04-24 03:42 ——– d—–w c:\program files\McAfee
2009-04-23 23:53 . 2009-04-23 23:54 ——– d—–w c:\documents and settings\All Users\Application Data\McAfee
2009-04-23 22:59 . 2009-04-23 23:54 ——– d—–w c:\program files\SpywareGuard
2009-04-22 22:04 . 2009-04-22 22:04 ——– d—–w c:\documents and settings\HP_Administrator\DoctorWeb
2009-04-21 19:18 . 2009-04-21 19:18 54156 —ha-w c:\windows\QTFont.qfn
2009-04-21 19:18 . 2009-04-21 19:18 1409 —-a-w c:\windows\QTFont.for
2009-04-20 21:07 . 2009-03-06 14:22 284160 ——w c:\windows\system32\dllcache\pdh.dll
2009-04-20 21:07 . 2009-02-09 12:10 401408 ——w c:\windows\system32\dllcache\rpcss.dll
2009-04-20 21:07 . 2009-02-06 11:11 110592 ——w c:\windows\system32\dllcache\services.exe
2009-04-20 21:07 . 2009-02-09 12:10 729088 ——w c:\windows\system32\dllcache\lsasrv.dll
2009-04-20 21:07 . 2009-02-09 12:10 617472 ——w c:\windows\system32\dllcache\advapi32.dll
2009-04-20 21:07 . 2009-02-09 12:10 473600 ——w c:\windows\system32\dllcache\fastprox.dll
2009-04-20 21:07 . 2009-02-09 12:10 453120 ——w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-20 21:07 . 2009-02-06 10:10 227840 ——w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-20 21:07 . 2009-02-09 12:10 714752 ——w c:\windows\system32\dllcache\ntdll.dll
2009-04-20 20:58 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-20 20:58 . 2009-03-27 06:58 1203922 ——w c:\windows\system32\dllcache\sysmain.sdb
2009-04-20 20:58 . 2008-04-21 12:08 215552 ——w c:\windows\system32\dllcache\wordpad.exe
2009-04-20 19:24 . 2009-04-20 19:24 ——– d—–w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-04-19 01:08 . 2009-04-19 01:36 ——– d—–w c:\documents and settings\HP_Administrator\Local Settings\Application Data\FullTiltPoker
2009-04-19 01:07 . 2009-04-19 01:36 ——– d—–w c:\program files\Full Tilt Poker
2009-04-18 06:18 . 2009-04-18 06:23 ——– d—–w c:\program files\EsetOnlineScanner
2009-04-16 18:01 . 2009-04-25 04:13 ——– d—–w C:\Rooter$
2009-04-16 01:53 . 2009-04-16 01:54 ——– d—–w c:\program files\ERUNT
2009-04-05 08:09 . 2009-04-05 08:09 ——– d—–w c:\documents and settings\HP_Administrator\Local Settings\Application Data\{38962301-708A-4293-A228-0564C1121181}
2009-04-03 21:14 . 2009-04-03 21:14 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\1.0.0.0
2009-04-03 21:14 . 2009-04-03 21:14 ——– d—–w c:\program files\Wincorp Consulting Company
2009-04-03 00:03 . 2009-04-03 00:04 ——– d—–w c:\program files\MetaTrader 4 Client Terminal
2009-03-27 00:27 . 2009-03-27 00:27 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\AVG8

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-25 02:53 . 2006-04-06 22:54 ——– d—–w c:\program files\Mozilla Thunderbird
2009-04-24 13:35 . 2006-04-07 02:51 ——– d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-24 04:02 . 2006-02-13 18:21 229224 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-24 03:52 . 2008-12-07 06:50 ——– d—–w c:\program files\Evrsoft First Page 2006
2009-04-23 22:51 . 2006-04-26 17:06 ——– d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-22 21:44 . 2008-12-08 02:14 ——– d—–w c:\program files\Trend Micro
2009-04-21 10:02 . 2008-12-02 04:35 ——– d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-20 19:30 . 2009-04-16 18:04 4478 —-a-w C:\Rooter.txt
2009-04-19 01:07 . 2006-02-13 18:05 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-16 02:33 . 2007-01-20 01:24 ——– d—–w c:\program files\SUPERAntiSpyware
2009-04-16 02:33 . 2007-01-20 01:24 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
2009-04-16 02:32 . 2008-11-30 02:34 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-04-08 17:34 . 2008-06-06 03:08 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-08 13:05 . 2006-07-14 21:05 ——– d—–w c:\program files\Opera
2009-04-02 23:04 . 2008-02-19 01:26 ——– d—–w c:\program files\iTunes
2009-04-02 23:03 . 2006-08-15 21:50 ——– d—–w c:\program files\MetaTrader 4
2009-04-02 22:57 . 2009-03-22 00:49 ——– d—–w c:\program files\FXCM Trader 4
2009-03-31 19:31 . 2006-02-13 18:45 ——– d—–w c:\program files\Google
2009-03-31 14:12 . 2006-06-13 00:25 ——– d—–w c:\documents and settings\All Users\Application Data\Skype
2009-03-31 14:12 . 2006-06-13 00:25 ——– d—–r c:\program files\Skype
2009-03-30 15:41 . 2008-06-06 03:08 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-03-27 01:02 . 2006-04-03 23:07 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\AdobeUM
2009-03-27 00:52 . 2008-06-06 03:08 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-03-27 00:52 . 2008-06-06 03:08 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-03-22 02:27 . 2009-03-22 02:26 ——– d—–w c:\program files\CBE
2009-03-21 14:06 . 2009-03-21 14:06 989696 ——w c:\windows\system32\dllcache\kernel32.dll
2009-03-16 05:04 . 2006-07-31 01:00 ——– d—–w c:\program files\CandleWorks
2009-03-07 18:11 . 2009-03-07 18:11 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\iLike
2009-03-06 14:22 . 2004-08-09 21:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-09 21:00 826368 —-a-w c:\windows\system32\wininet.dll
2009-03-03 00:18 . 2004-08-09 21:00 826368 —-a-w c:\windows\system32\dllcache\wininet.dll
2009-03-01 06:38 . 2009-03-01 06:38 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
2009-03-01 06:38 . 2009-03-01 06:38 ——– d—–w c:\program files\TweetDeck
2009-03-01 06:38 . 2009-03-01 06:38 ——– d—–w c:\program files\Common Files\Adobe AIR
2009-02-28 04:54 . 2004-08-09 21:00 636072 —-a-w c:\windows\system32\dllcache\iexplore.exe
2009-02-24 03:45 . 2009-02-24 03:17 20 —h–w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-02-24 03:17 . 2003-03-19 03:05 106496 —-a-w c:\windows\system32\ATL71.DLL
2009-02-20 10:20 . 2007-05-09 02:43 13824 ——w c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 10:20 . 2004-08-09 21:00 70656 —-a-w c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 05:14 . 2004-08-09 21:00 161792 —-a-w c:\windows\system32\dllcache\ieakui.dll
2009-02-09 12:10 . 2004-08-09 21:00 729088 ——w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-10 04:00 714752 ——w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-09 21:00 617472 ——w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-09 21:00 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2008-10-15 09:33 1846784 ——w c:\windows\system32\dllcache\win32k.sys
2009-02-09 11:13 . 2004-08-09 21:00 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-08 02:02 . 2008-10-15 09:33 2066048 ——w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-06 11:11 . 2004-08-09 21:00 110592 ——w c:\windows\system32\services.exe
2009-02-06 11:08 . 2008-10-15 09:33 2189056 ——w c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-06 11:06 . 2008-10-15 09:33 2145280 ——w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-06 11:06 . 2004-08-10 04:00 2145280 ——w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-09 21:00 35328 ——w c:\windows\system32\sc.exe
2009-02-06 10:39 . 2004-08-09 21:00 35328 ——w c:\windows\system32\dllcache\sc.exe
2009-02-06 10:32 . 2008-10-15 09:33 2023936 ——w c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-06 10:32 . 2004-08-10 04:00 2023936 ——w c:\windows\system32\ntkrnlpa.exe
2009-02-06 06:40 . 2009-02-06 06:40 196 —ha-w C:\aaw7boot.cmd
2009-02-03 19:59 . 2009-02-03 19:59 56832 ——w c:\windows\system32\dllcache\secur32.dll
2009-02-03 19:59 . 2004-08-09 21:00 56832 —-a-w c:\windows\system32\secur32.dll
2008-10-17 01:36 . 2008-10-17 01:36 365040 —-a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2008-09-28 22:15 . 2008-09-28 22:15 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-02-06 03:15 . 2006-04-07 23:21 198512 —-a-w c:\documents and settings\karolinka\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-11-15 03:13 . 2006-07-15 06:32 14 —-a-w c:\documents and settings\HP_Administrator\getfile.dat
2006-10-11 01:05 . 2006-10-11 01:05 368 —-a-w c:\documents and settings\HP_Administrator\DesktopLightningUpgrader.bat
2006-09-22 04:16 . 2006-09-22 01:15 14 —-a-w c:\documents and settings\karolinka\getfile.dat
2006-04-15 17:32 . 2006-04-07 23:21 132 —-a-w c:\documents and settings\karolinka\Local Settings\Application Data\fusioncache.dat
2006-04-06 20:05 . 2006-04-06 20:05 0 —-a-w c:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
2006-03-30 23:49 . 2006-03-30 22:45 139 —-a-w c:\documents and settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
2006-02-13 18:37 . 2006-03-30 22:45 51976 —-a-w c:\documents and settings\HP_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-02-13 17:49 . 2006-02-13 17:49 136 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2006-05-04 22:2006-05-04 22:53 53:17 . c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-10-24 20:2008-10-24 20:20 14:52 . c:\program files\opera\program\plugins\dapop.dll
2008-06-05 00:2008-06-05 00:55 55:16 . c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-09-23 04:12 . 2008-09-23 04:12 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092220080923\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-02 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-27 1932568]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-06-05 29744]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-24 185872]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-7-28 368640]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 18:05 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-27 00:52 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates From HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk
backup=c:\windows\pss\Updates From HP.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^HP_Administrator^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"Pml Driver HPZ12"=0 (0x0)
"NVSvc"=2 (0x2)
"nmservice"=2 (0x2)
"nmraapache"=3 (0x3)
"MDM"=2 (0x2)
"LightScribeService"=2 (0x2)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"IAANTMON"=2 (0x2)
"gusvc"=2 (0x2)
"FinePrint Dispatcher v5"=2 (0x2)
"ELService"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"aawservice"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\userinit.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgtray.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service

R2 gupdate1c8e254e49c1a68;Google Update Service (gupdate1c8e254e49c1a68);c:\program files\Google\Update\GoogleUpdate.exe [2008-09-02 133104]
R2 netsik;netsik; [x]
R2 port135sik;port135sik; [x]
R2 securentm;securentm; [x]
R3 GoogleDesktopManager-051608-133132;Google Desktop Manager 5.7.805.16405;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-06-05 29744]
R3 MEMSWEEP2;MEMSWEEP2; [x]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-19 28544]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-03-27 325640]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-03-30 108552]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-01-15 8944]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-01-15 55024]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-03-27 908056]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-27 298264]
S2 FinePrint Dispatcher v5;FinePrint Dispatcher v5;c:\windows\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe [2008-04-09 520192]
S2 FinePrint Dispatcher v6;FinePrint Dispatcher v6;c:\windows\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe [2008-10-28 602112]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-02-11 210216]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]


— Other Services/Drivers In Memory —

*NewlyCreated* - AVGARCLN
*NewlyCreated* - AVG_ANTI-ROOTKIT

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dfe55943-04f2-11dc-bedf-0015f2d56872}]
\Shell\AutoRun\command - K:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder

2009-04-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 21:57]

2009-04-25 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2006-12-24 05:50]

2009-04-25 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-07-12 18:59]

2009-02-26 c:\windows\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job
- c:\program files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe [2005-10-17 10:04]

2009-04-15 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-02-24 02:15]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.speedbit.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_CA&c;=Q106&bd;=pavilion&pf;=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mStart Page = hxxp://www.msn.com
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_CA&c;=Q106&bd;=pavilion&pf;=desktop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Customize Menu
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
IE: Fill Forms
IE: RoboForm Toolbar
IE: Save Forms
Trusted Zone: trymedia.com
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2103525&SearchSource;=3&q;=
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\extensions\{32be036a-4d7a-44e7-827d-4cb5b3da428f}\components\FFAlert.dll
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll

—- FIREFOX POLICIES —-
FF - user.js: general.useragent.extra.zencast - Creative ZENcast v1.02.10.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-24 21:20
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\16.tmp"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(788)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(2208)
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-04-25 21:22
ComboFix-quarantined-files.txt 2009-04-25 04:22
ComboFix2.txt 2009-04-25 02:14

Pre-Run: 118,209,110,016 bytes free
Post-Run: 118,192,947,200 bytes free

344 — E O F — 2009-04-21 10:09

I hope we can solve the problem. Thanks again.

pumex
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

KillAll::

File::
c:\windows\system32\runouce.exe
c:\windows\Lic.xxx
c:\windows\system32\eEmpty.exe
c:\windows\system32\T.COM
c:\windows\R.COM

Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dfe55943-04f2-11dc-bedf-0015f2d56872}]

Driver::
netsik
port135sik
securentm
MEMSWEEP2

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

* Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
* ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
* When finished, it shall produce a log for you.
* Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

NOTE: CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



NEXT:


Please download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a number of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

  • Post the contents of GMER.txt in your next reply.
Here are the logs.
Re GMER I had strange message that Windows was unable to save, there was his error message - Windows-Delay Write Failed. But I clicked on SAVE , gave the name and it was saved to the Desktop.
BUT, my mouse wasn't reacting - the cursor was not moving! So I turned the computer off by pushing the button. It restarted and the file was on the Desktop. I hope it's fine:

Logs:

ComboFix:
ComboFix 09-04-25.05 - HP_Administrator 24/04/2009 23:00.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1172 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
* Created a new restore point

FILE ::
c:\windows\Lic.xxx
c:\windows\R.COM
c:\windows\system32\eEmpty.exe
c:\windows\system32\runouce.exe
c:\windows\system32\T.COM
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Lic.xxx
c:\windows\R.COM
c:\windows\system32\eEmpty.exe
c:\windows\system32\T.COM

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_MEMSWEEP2
——-\Legacy_SECURENTM
——-\Service_netsik
——-\Service_port135sik
——-\Service_securentm


((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-4-25 )))))))))))))))))))))))))))))))
.

2009-04-25 05:06 . 2009-04-25 05:29 ——– d—–w c:\program files\a-squared Free
2009-04-25 05:02 . 2009-04-25 05:04 44711936 —-a-w c:\windows\system32\PGV
2009-04-25 02:49 . 2007-01-18 12:00 3968 —-a-w c:\windows\system32\drivers\AvgArCln.sys
2009-04-24 20:07 . 2009-04-24 20:13 ——– d—–w c:\program files\SpywareBlaster
2009-04-24 19:00 . 2009-04-24 20:15 ——– d—–w c:\program files\Registry Genius
2009-04-24 08:04 . 2008-06-19 23:24 28544 —-a-w c:\windows\system32\drivers\pavboot.sys
2009-04-24 08:04 . 2009-04-24 08:04 ——– d—–w c:\program files\Panda Security
2009-04-24 05:03 . 2009-04-24 05:03 ——– d—–w c:\program files\Sophos
2009-04-24 04:39 . 2009-04-24 04:39 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\QuickScan
2009-04-24 04:16 . 2009-04-06 22:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-24 04:16 . 2009-04-06 22:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-24 04:16 . 2009-04-24 04:17 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-24 03:08 . 2009-04-24 03:08 ——– d—a-w c:\windows\system32\runouce.exe
2009-04-24 03:06 . 2005-09-23 06:22 522 —-a-w c:\windows\system32\Microsoft.VC80.CRT.manifest
2009-04-24 03:06 . 2009-04-24 03:06 ——– d—–w c:\program files\Common Files\MicroWorld
2009-04-24 03:06 . 2009-04-24 03:06 ——– d—–w c:\documents and settings\All Users\Application Data\MicroWorld
2009-04-23 23:55 . 2009-04-23 23:55 ——– d—–w c:\documents and settings\LocalService\Application Data\SACore
2009-04-23 23:55 . 2009-04-23 23:55 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\SACore
2009-04-23 23:54 . 2009-04-23 23:54 ——– d—–w c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-04-23 23:54 . 2009-04-23 23:54 ——– d—–w c:\program files\Common Files\McAfee
2009-04-23 23:53 . 2009-04-24 03:42 ——– d—–w c:\program files\McAfee
2009-04-23 23:53 . 2009-04-23 23:54 ——– d—–w c:\documents and settings\All Users\Application Data\McAfee
2009-04-23 22:59 . 2009-04-23 23:54 ——– d—–w c:\program files\SpywareGuard
2009-04-22 22:04 . 2009-04-22 22:04 ——– d—–w c:\documents and settings\HP_Administrator\DoctorWeb
2009-04-21 19:18 . 2009-04-21 19:18 54156 —ha-w c:\windows\QTFont.qfn
2009-04-21 19:18 . 2009-04-21 19:18 1409 —-a-w c:\windows\QTFont.for
2009-04-20 21:07 . 2009-03-06 14:22 284160 ——w c:\windows\system32\dllcache\pdh.dll
2009-04-20 21:07 . 2009-02-09 12:10 401408 ——w c:\windows\system32\dllcache\rpcss.dll
2009-04-20 21:07 . 2009-02-06 11:11 110592 ——w c:\windows\system32\dllcache\services.exe
2009-04-20 21:07 . 2009-02-09 12:10 729088 ——w c:\windows\system32\dllcache\lsasrv.dll
2009-04-20 21:07 . 2009-02-09 12:10 617472 ——w c:\windows\system32\dllcache\advapi32.dll
2009-04-20 21:07 . 2009-02-09 12:10 473600 ——w c:\windows\system32\dllcache\fastprox.dll
2009-04-20 21:07 . 2009-02-09 12:10 453120 ——w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-20 21:07 . 2009-02-06 10:10 227840 ——w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-20 21:07 . 2009-02-09 12:10 714752 ——w c:\windows\system32\dllcache\ntdll.dll
2009-04-20 20:58 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-20 20:58 . 2009-03-27 06:58 1203922 ——w c:\windows\system32\dllcache\sysmain.sdb
2009-04-20 20:58 . 2008-04-21 12:08 215552 ——w c:\windows\system32\dllcache\wordpad.exe
2009-04-20 19:24 . 2009-04-20 19:24 ——– d—–w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-04-19 01:08 . 2009-04-19 01:36 ——– d—–w c:\documents and settings\HP_Administrator\Local Settings\Application Data\FullTiltPoker
2009-04-19 01:07 . 2009-04-19 01:36 ——– d—–w c:\program files\Full Tilt Poker
2009-04-18 06:18 . 2009-04-18 06:23 ——– d—–w c:\program files\EsetOnlineScanner
2009-04-16 18:01 . 2009-04-25 04:13 ——– d—–w C:\Rooter$
2009-04-16 01:53 . 2009-04-16 01:54 ——– d—–w c:\program files\ERUNT
2009-04-05 08:09 . 2009-04-05 08:09 ——– d—–w c:\documents and settings\HP_Administrator\Local Settings\Application Data\{38962301-708A-4293-A228-0564C1121181}
2009-04-03 21:14 . 2009-04-03 21:14 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\1.0.0.0
2009-04-03 21:14 . 2009-04-03 21:14 ——– d—–w c:\program files\Wincorp Consulting Company
2009-04-03 00:03 . 2009-04-03 00:04 ——– d—–w c:\program files\MetaTrader 4 Client Terminal
2009-03-27 00:27 . 2009-03-27 00:27 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\AVG8

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-25 05:07 . 2006-04-06 22:54 ——– d—–w c:\program files\Mozilla Thunderbird
2009-04-24 13:35 . 2006-04-07 02:51 ——– d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-24 04:02 . 2006-02-13 18:21 229224 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-24 03:52 . 2008-12-07 06:50 ——– d—–w c:\program files\Evrsoft First Page 2006
2009-04-23 22:51 . 2006-04-26 17:06 ——– d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-22 21:44 . 2008-12-08 02:14 ——– d—–w c:\program files\Trend Micro
2009-04-21 10:02 . 2008-12-02 04:35 ——– d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-20 19:30 . 2009-04-16 18:04 4478 —-a-w C:\Rooter.txt
2009-04-19 01:07 . 2006-02-13 18:05 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-16 02:33 . 2007-01-20 01:24 ——– d—–w c:\program files\SUPERAntiSpyware
2009-04-16 02:33 . 2007-01-20 01:24 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
2009-04-16 02:32 . 2008-11-30 02:34 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-04-08 17:34 . 2008-06-06 03:08 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-08 13:05 . 2006-07-14 21:05 ——– d—–w c:\program files\Opera
2009-04-02 23:04 . 2008-02-19 01:26 ——– d—–w c:\program files\iTunes
2009-04-02 23:03 . 2006-08-15 21:50 ——– d—–w c:\program files\MetaTrader 4
2009-04-02 22:57 . 2009-03-22 00:49 ——– d—–w c:\program files\FXCM Trader 4
2009-03-31 19:31 . 2006-02-13 18:45 ——– d—–w c:\program files\Google
2009-03-31 14:12 . 2006-06-13 00:25 ——– d—–w c:\documents and settings\All Users\Application Data\Skype
2009-03-31 14:12 . 2006-06-13 00:25 ——– d—–r c:\program files\Skype
2009-03-30 15:41 . 2008-06-06 03:08 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-03-27 01:02 . 2006-04-03 23:07 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\AdobeUM
2009-03-27 00:52 . 2008-06-06 03:08 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-03-27 00:52 . 2008-06-06 03:08 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-03-22 02:27 . 2009-03-22 02:26 ——– d—–w c:\program files\CBE
2009-03-21 14:06 . 2009-03-21 14:06 989696 ——w c:\windows\system32\dllcache\kernel32.dll
2009-03-16 05:04 . 2006-07-31 01:00 ——– d—–w c:\program files\CandleWorks
2009-03-07 18:11 . 2009-03-07 18:11 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\iLike
2009-03-06 14:22 . 2004-08-09 21:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-09 21:00 826368 —-a-w c:\windows\system32\wininet.dll
2009-03-03 00:18 . 2004-08-09 21:00 826368 —-a-w c:\windows\system32\dllcache\wininet.dll
2009-03-01 06:38 . 2009-03-01 06:38 ——– d—–w c:\documents and settings\HP_Administrator\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
2009-03-01 06:38 . 2009-03-01 06:38 ——– d—–w c:\program files\TweetDeck
2009-03-01 06:38 . 2009-03-01 06:38 ——– d—–w c:\program files\Common Files\Adobe AIR
2009-02-28 04:54 . 2004-08-09 21:00 636072 —-a-w c:\windows\system32\dllcache\iexplore.exe
2009-02-24 03:45 . 2009-02-24 03:17 20 —h–w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-02-24 03:17 . 2003-03-19 03:05 106496 —-a-w c:\windows\system32\ATL71.DLL
2009-02-20 10:20 . 2007-05-09 02:43 13824 ——w c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 10:20 . 2004-08-09 21:00 70656 —-a-w c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 05:14 . 2004-08-09 21:00 161792 —-a-w c:\windows\system32\dllcache\ieakui.dll
2009-02-09 12:10 . 2004-08-09 21:00 729088 ——w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-10 04:00 714752 ——w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-09 21:00 617472 ——w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-09 21:00 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2008-10-15 09:33 1846784 ——w c:\windows\system32\dllcache\win32k.sys
2009-02-09 11:13 . 2004-08-09 21:00 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-08 02:02 . 2008-10-15 09:33 2066048 ——w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-06 11:11 . 2004-08-09 21:00 110592 ——w c:\windows\system32\services.exe
2009-02-06 11:08 . 2008-10-15 09:33 2189056 ——w c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-06 11:06 . 2008-10-15 09:33 2145280 ——w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-06 11:06 . 2004-08-10 04:00 2145280 ——w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-09 21:00 35328 ——w c:\windows\system32\sc.exe
2009-02-06 10:39 . 2004-08-09 21:00 35328 ——w c:\windows\system32\dllcache\sc.exe
2009-02-06 10:32 . 2008-10-15 09:33 2023936 ——w c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-06 10:32 . 2004-08-10 04:00 2023936 ——w c:\windows\system32\ntkrnlpa.exe
2009-02-06 06:40 . 2009-02-06 06:40 196 —ha-w C:\aaw7boot.cmd
2009-02-03 19:59 . 2009-02-03 19:59 56832 ——w c:\windows\system32\dllcache\secur32.dll
2009-02-03 19:59 . 2004-08-09 21:00 56832 —-a-w c:\windows\system32\secur32.dll
2008-10-17 01:36 . 2008-10-17 01:36 365040 —-a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2008-09-28 22:15 . 2008-09-28 22:15 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-02-06 03:15 . 2006-04-07 23:21 198512 —-a-w c:\documents and settings\karolinka\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-11-15 03:13 . 2006-07-15 06:32 14 —-a-w c:\documents and settings\HP_Administrator\getfile.dat
2006-10-11 01:05 . 2006-10-11 01:05 368 —-a-w c:\documents and settings\HP_Administrator\DesktopLightningUpgrader.bat
2006-09-22 04:16 . 2006-09-22 01:15 14 —-a-w c:\documents and settings\karolinka\getfile.dat
2006-04-15 17:32 . 2006-04-07 23:21 132 —-a-w c:\documents and settings\karolinka\Local Settings\Application Data\fusioncache.dat
2006-04-06 20:05 . 2006-04-06 20:05 0 —-a-w c:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
2006-03-30 23:49 . 2006-03-30 22:45 139 —-a-w c:\documents and settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
2006-02-13 18:37 . 2006-03-30 22:45 51976 —-a-w c:\documents and settings\HP_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-02-13 17:49 . 2006-02-13 17:49 136 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2006-05-04 22:2006-05-04 22:53 53:17 . c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-10-24 20:2008-10-24 20:20 14:52 . c:\program files\opera\program\plugins\dapop.dll
2008-06-05 00:2008-06-05 00:55 55:16 . c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-09-23 04:12 . 2008-09-23 04:12 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092220080923\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-04-25_04.20.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-25 06:04 . 2009-04-25 06:04 16384 c:\windows\temp\Perflib_Perfdata_5ac.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-02 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-27 1932568]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-06-05 29744]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-24 185872]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-7-28 368640]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 18:05 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-27 00:52 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates From HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk
backup=c:\windows\pss\Updates From HP.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^HP_Administrator^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"Pml Driver HPZ12"=0 (0x0)
"NVSvc"=2 (0x2)
"nmservice"=2 (0x2)
"nmraapache"=3 (0x3)
"MDM"=2 (0x2)
"LightScribeService"=2 (0x2)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"IAANTMON"=2 (0x2)
"gusvc"=2 (0x2)
"FinePrint Dispatcher v5"=2 (0x2)
"ELService"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"aawservice"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\userinit.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgtray.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service

R2 gupdate1c8e254e49c1a68;Google Update Service (gupdate1c8e254e49c1a68);c:\program files\Google\Update\GoogleUpdate.exe [2008-09-02 133104]
R3 GoogleDesktopManager-051608-133132;Google Desktop Manager 5.7.805.16405;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-06-05 29744]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-19 28544]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-03-27 325640]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-03-30 108552]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-01-15 8944]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-01-15 55024]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-03-27 908056]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-27 298264]
S2 FinePrint Dispatcher v5;FinePrint Dispatcher v5;c:\windows\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe [2008-04-09 520192]
S2 FinePrint Dispatcher v6;FinePrint Dispatcher v6;c:\windows\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe [2008-10-28 602112]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-02-11 210216]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]

.
Contents of the 'Scheduled Tasks' folder

2009-04-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 21:57]

2009-04-25 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2006-12-24 05:50]

2009-04-25 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-07-12 18:59]

2009-02-26 c:\windows\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job
- c:\program files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe [2005-10-17 10:04]

2009-04-15 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-02-24 02:15]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.speedbit.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_CA&c;=Q106&bd;=pavilion&pf;=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mStart Page = hxxp://www.msn.com
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_CA&c;=Q106&bd;=pavilion&pf;=desktop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Customize Menu
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
IE: Fill Forms
IE: RoboForm Toolbar
IE: Save Forms
Trusted Zone: trymedia.com
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2103525&SearchSource;=3&q;=
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\extensions\{32be036a-4d7a-44e7-827d-4cb5b3da428f}\components\FFAlert.dll
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\gxf7v8cj.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll

—- FIREFOX POLICIES —-
FF - user.js: general.useragent.extra.zencast - Creative ZENcast v1.02.10.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-24 23:04
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(816)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(560)
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\a-squared Free\a2service.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dllhost.exe
c:\program files\SpywareGuard\sgbhp.exe
.
**************************************************************************
.
Completion time: 2009-04-25 23:09 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-25 06:09
ComboFix2.txt 2009-04-25 04:22
ComboFix3.txt 2009-04-25 02:14

Pre-Run: 117,973,254,144 bytes free
Post-Run: 117,907,742,720 bytes free

375 — E O F — 2009-04-21 10:09
==
GMER.txt:
GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2009-04-25 10:20:06
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB69DBF20]

Code \??\C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\catchme.sys pIofCallDriver

—- Kernel code sections - GMER 1.0.15 —-

? Combo-Fix.sys The system cannot find the file specified. !
? C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\catchme.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[3120] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 050522C5 C:\Program Files\Google\Google Desktop Search\GoogleServices.DLL (Google Desktop/Google)
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[3120] USER32.dll!MessageBoxA 7E4507EA 5 Bytes JMP 0505226F C:\Program Files\Google\Google Desktop Search\GoogleServices.DLL (Google Desktop/Google)
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[3120] USER32.dll!MessageBoxW 7E466534 5 Bytes JMP 0505229A C:\Program Files\Google\Google Desktop Search\GoogleServices.DLL (Google Desktop/Google)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 ELkbd.sys (Intel Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 ELkbd.sys (Intel Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Files - GMER 1.0.15 —-

File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\free-giveaway-content-nov07-845\Hybrid Cars\graphics\psd\Hybrid Cars-700.psd 2010322 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\free-giveaway-content-nov07-845\Hybrid Cars\graphics\psd\Hybrid Cars.psd 2029527 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\free-giveaway-content-nov07-845\Hybrid Cars\graphics\psd\Hybrid Cars1-700.psd 1014209 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\free-giveaway-content-nov07-845\Hybrid Cars\graphics\psd\Hybrid Cars1.psd 1029627 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\free-giveaway-content-nov07-845\Hybrid Cars\graphics\psd\Thumbs.db 7168 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\license.txt 1039 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\Product 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\Product\Blog&PingMasterCourse2006.pdf; 2355527 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\Product\readme.txt 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\Product_SourceCode 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\Product_SourceCode\Blog&PingMasterCourse2006.doc; 1851904 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\Product_SourceCode\cover.psd 628300 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\Product_SourceCode\header.jpg 42166 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\Product_SourceCode\header.psd 879861 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\Product_SourceCode\license-enduser.txt 180 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\Product_SourceCode\license-masterrights.txt 801 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\Product_SourceCode\license-privatelabel.txt 976 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\Product_SourceCode\license-resellrights.txt 620 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\readme.txt 3288 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\blogandping-order1.jpg 25639 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\blogandping-order2.jpg 6965 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\blogping-flat4.jpg 15501 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\blogping-header.jpg 47489 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\checkmark.gif 383 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\e-book_large.jpg 78208 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\e-book_medium.jpg 49004 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\e-book_small.jpg 16542 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\flat_large.jpg 88393 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\flat_medium.jpg 62504 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\flat_small.jpg 10793 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\header.jpg 90221 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\pdf.jpg 4362 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\Thumbs.db 110592 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\images\word.jpg 4047 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\index.html 30066 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\license.txt 180 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\readme.txt 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness\thankyou.html 2941 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\blogandping-order1.jpg 25639 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\blogandping-order2.jpg 6965 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\blogping-flat4.jpg 15501 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\blogping-header.jpg 47489 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\checkmark.gif 383 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\e-book_large.jpg 78208 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\e-book_medium.jpg 49004 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\e-book_small.jpg 16542 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\flat_large.jpg 88393 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\flat_medium.jpg 62504 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\flat_small.jpg 10793 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\header.jpg 90221 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\pdf.jpg 4362 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\Thumbs.db 110592 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\images\word.jpg 4047 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\index-resellrights.html 20725 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\index.html 30066 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\license.txt 620 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\readme.txt 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\thankyou-resellrights.html 2941 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\BlognPingMasterCourse\Blog&PingMasterCourse2006;\ReadyToGoWebBusiness_withRights\thankyou.html 2941 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\license.txt 1037 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\Product 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\Product\AdsenseEmpire.pdf 3699778 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\Product\readme.txt 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\Product_SourceCode 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\Product_SourceCode\AdsenseEmpire.doc 5721088 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\Product_SourceCode\cover.psd 419441 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\Product_SourceCode\header.jpg 25235 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\Product_SourceCode\header.psd 476582 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\Product_SourceCode\license-enduser.txt 180 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\Product_SourceCode\license-masterrights.txt 801 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\Product_SourceCode\license-privatelabel.txt 976 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\Product_SourceCode\license-resellrights.txt 620 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\readme.txt 3286 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\Thumbs.db 105984 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\button.jpg 7320 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\checkmark.gif 383 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\e-book_large.jpg 27943 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\e-book_medium.jpg 18203 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\e-book_small.jpg 5875 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\flat_large.jpg 33374 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\flat_medium.jpg 22560 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\flat_small.jpg 4040 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\header.jpg 34629 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\pdf.jpg 4138 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-back1.jpg 5175 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-back2.jpg 6718 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-ebookcover-big.jpg 25435 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-ebookcover-medium.jpg 16099 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-ebookcover-small.jpg 10373 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-ebookcover-tiny.jpg 6621 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-flat1.jpg 51035 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-flat2.jpg 33484 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-flat3.jpg 21567 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-flat4.jpg 13750 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-footer.jpg 25657 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-header.jpg 36686 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-order1.jpg 21407 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\vae-order2.jpg 7320 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\wae.jpg 67519 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\images\word.jpg 3816 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\index.html 19352 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\license.txt 180 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\readme.txt 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness\thankyou.html 2819 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\Thumbs.db 105984 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\button.jpg 7320 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\checkmark.gif 383 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\e-book_large.jpg 27943 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\e-book_medium.jpg 18203 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\e-book_small.jpg 5875 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\flat_large.jpg 33374 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\flat_medium.jpg 22560 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\flat_small.jpg 4040 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\header.jpg 34629 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\pdf.jpg 4138 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-back1.jpg 5175 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-back2.jpg 6718 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-ebookcover-big.jpg 25435 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-ebookcover-medium.jpg 16099 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-ebookcover-small.jpg 10373 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-ebookcover-tiny.jpg 6621 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-flat1.jpg 51035 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-flat2.jpg 33484 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-flat3.jpg 21567 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-flat4.jpg 13750 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-footer.jpg 25657 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-header.jpg 36686 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-order1.jpg 21407 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\vae-order2.jpg 7320 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\wae.jpg 67519 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\images\word.jpg 3816 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\index-resellrights.html 20692 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\index.html 19352 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\license.txt 620 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\readme.txt 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\thankyou-resellrights.html 2819 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\GoogleAdSenseCashCow\GoogleAdSenseCashCow2006\ReadyToGoWebBusiness_withRights\thankyou.html 2819 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\license.txt 997 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\autorun.inf 41 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Images 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Images\Thumbs.db 13824 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Images\~B_73.bmp 921654 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\menu.cmmcd 24609 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Video 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Video\bizop99.avi 35012324 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Video\businesstv.avi 29529512 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Video\contentcontent03.avi 17422194 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Video\editingcompress.avi 2673586 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Video\Finish.avi 418296 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Video\Introduction.avi 1679490 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Video\live.avi 54747474 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Video\personal.avi 25249162 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Video\shoot.avi 12394668 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Video\strat02a.avi 7288618 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\3bdf02ce-657c-4970-9062-8dca9b8d1c01\Video\Thumbs.db 41984 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\Common 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\Common\Programs 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\Common\Programs\CamPlay.exe 434176 bytes executable
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Media\StartMenu.txt 54 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\readme.html 10627 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product\Your_Own_TV_Station.exe 339968 bytes executable
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product_SourceCode 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product_SourceCode\cover.psd 690766 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product_SourceCode\license-enduser.txt 180 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product_SourceCode\license-masterrights.txt 801 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product_SourceCode\license-privatelabel.txt 976 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\Product_SourceCode\license-resellrights.txt 620 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\readme.txt 3277 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\1.jpg 34088 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\1a.jpg 127759 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\2.jpg 21693 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\2a.jpg 79698 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\3.jpg 11325 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\3a.jpg 41124 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\4.jpg 3594 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\4a.jpg 12421 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\back.jpg 2371 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\banner.swf 16879 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\bannerinfo.htm 1794 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\bottomband.jpg 20693 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\button.jpg 17582 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\b_01.png 344 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\b_02.png 143 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\b_04.png 454 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\b_07.png 131 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\b_10.png 151 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\b_13.png 469 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\b_15.png 168 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\b_17.png 548 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\checkmark.gif 383 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\flat.jpg 33485 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\header.jpg 33753 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\notused 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\notused\1.jpg 61725 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\notused\2.jpg 38929 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\notused\3.jpg 20811 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\notused\4.jpg 6562 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\notused\flat.jpg 55354 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\notused\Thumbs.db 8192 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\spacer.gif 43 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\images\Thumbs.db 59392 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\index.html 26530 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\license.txt 180 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\readme.txt 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness\thankyou.html 8551 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\1.jpg 34088 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\1a.jpg 127759 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\2.jpg 21693 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\2a.jpg 79698 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\3.jpg 11325 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\3a.jpg 41124 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\4.jpg 3594 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\4a.jpg 12421 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\back.jpg 2371 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\banner.swf 16879 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\bannerinfo.htm 1794 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\bottomband.jpg 20693 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\button.jpg 17582 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\b_01.png 344 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\b_02.png 143 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\b_04.png 454 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\b_07.png 131 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\b_10.png 151 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\b_13.png 469 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\b_15.png 168 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\b_17.png 548 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\checkmark.gif 383 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\flat.jpg 33485 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\header.jpg 33753 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\notused 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\notused\1.jpg 61725 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\notused\2.jpg 38929 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\notused\3.jpg 20811 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\notused\4.jpg 6562 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\notused\flat.jpg 55354 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\notused\Thumbs.db 8192 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\spacer.gif 43 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\images\Thumbs.db 59392 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\index-resellrights.html 26294 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\index.html 26530 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\license.txt 620 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\readme.txt 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\thankyou-resellrights.html 8755 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\Wu\YourOwnTVStation\YourOwnTVStation\ReadyToGoWebBusiness_withRights\thankyou.html 8551 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\YourFreeGifts\1000Visitors.pdf 164207 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\YourFreeGifts\download_vpm_zip.zip 250549 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\YourFreeGifts\odp_report_cb.pdf 479856 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\YourFreeGifts\tmp_report_cb.pdf 305328 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\YourFreeGifts\WriteThatReport.pdf 170806 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\UltimateSoftwareLibrary1-and-2\UltimateSoftwareLibrary1-and-2\UltimateSoftwareLibrary-V1 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\increase\site\index.html 8047 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\increase\site\step-three.html 1813 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\increase\site\step-two.html 2303 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\InfoproductChecklist\InfoproductChecklist.doc 102912 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\InfoproductChecklist\openmefirst-infochecklist.pdf 97106 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\DOC 7 New Products Every Day - Innovate & Create.doc 301568 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\JPEG Cover.jpg 88417 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\PDF 7 New Products Every Day - Innovate & Create.pdf 265427 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\Site - Innovate And Create 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\Site - Innovate And Create\blank.html 2953 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\Site - Innovate And Create\box3.jpg 49575 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\Site - Innovate And Create\contact.html 5595 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\Site - Innovate And Create\css 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\Site - Innovate And Create\css\MrCSS.css 419 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\Site - Innovate And Create\finbot.jpg 35141 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\Site - Innovate And Create\fintop.jpg 44258 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\Site - Innovate And Create\index.html 23269 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\Site - Innovate And Create\order.html 2948 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\Site - Innovate And Create\Thumbs.db 31744 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\innovatecreate\4. Innovate And Create\Thumbs.db 13824 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\Dave.jpg 3870 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\background.jpg 1836 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\background.jpg.old 4846 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\button_paypal.gif 3147 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\CBNiche_background.jpg 4846 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\CBNiche_footer.jpg 9946 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\CBNiche_header.jpg 62459 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\check.gif 415 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\clickhere.jpg 9650 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\clicktopurchase.gif 6518 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\demo.jpg 5289 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\EBox.jpg 27719 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\eBox_CBNiche.jpg 14769 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\footer.jpg 9946 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\guarantee.gif 5395 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\header.jpg 21796 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\icon_guarantee.gif 5395 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\jeffery_small.gif 3281 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\mslogo.gif 4909 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\paypal.gif 4388 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\rshields4.jpg 2949 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\rtick_small.gif 297 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\sambiz.JPG 43530 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\template1.jpg 4613 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\template2.jpg 5027 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\template3.jpg 4795 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\Thumbs.db 112640 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\TT_Dave.jpg 3870 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\TT_Jeffery.gif 3281 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\images\TT_Shields.jpg 2949 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\index.html 98454 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\readme.txt 182 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\resellerwebsites\thankyou.html 7085 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SBI\Aff-Masters.zip 1230928 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SBI\mynas-masters.zip 1736981 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SBI\MYPS!Masters.pdf 444061 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SBI\NetwritingMasters.pdf 429762 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SBI\ServiceSellersMastersCourse.zip 1004528 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SBI\wahm-masters.zip 1398548 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SBI\webmasterbusiness.zip 190053 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\FirstFrame.png 88056 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images\cd.png 18465 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images\index_01.gif 13973 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images\index_02.gif 22386 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images\index_03.gif 1768 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images\index_04.gif 9281 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images\order04.png 42153 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images\screen300.jpg 30430 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images\Skin_01.gif 12132 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images\Skin_02.gif 8778 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images\Skin_03.gif 29225 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images\Skin_04.gif 3395 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images\Skin_05.gif 3051 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\images\Thumbs.db 28160 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\index.html 9567 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\intro.mp4 4414477 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\intro_controller.swf 404383 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\ProductionInfo.xml 13591 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\swfobject.js 9759 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\titles 0 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\titles\download-black.png 14659 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\titles\download-white.png 12537 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\titles\ebook-black.png 13479 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\titles\ebook-white.png 11754 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\titles\instant-black.png 17645 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\titles\instant-white.png 15202 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\titles\report-black.png 13116 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\titles\report-white.png 11642 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\titles\report.png 21562 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\titles\shadow.png 1148 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\titles\submit-black.png 1912 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\SubmitMySiteSoftwareV1.5\SubmitMySiteSoftwareV1.5\Squeeze Page\titles\submit-red.png 1062 bytes
File C:\Documents and Settings\HP_Administrator\Desktop\Goodies\products\products 0 bytes

—- EOF - GMER 1.0.15 —-



==
HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:29:19 AM, on 25/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\PROGRA~1\MOZILL~2\THUNDE~1.EXE
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Google; Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by130fd.bay130.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: FinePrint Dispatcher v5 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O23 - Service: FinePrint Dispatcher v6 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
O23 - Service: Google Desktop Manager 5.7.805.16405 (GoogleDesktopManager-051608-133132) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c8e254e49c1a68) (gupdate1c8e254e49c1a68) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe

–
End of file - 10486 bytes
==
Note:
HJT done with AVG disabled.
No trojan discovered by AVG since 7 pm yesterday. - Could that be result of my changing passwords at critical sites by that time?!
Yes, since 7 PM no trojan was found in the scans or at least there was no alert - you may see something in attached logs.

I also have 2 questions:
1/ I plan to get rid of AVG Antivirus and install avast. Is it good idea?
2/ What to do with the content of AVG AV vault - there are trojans there, I imagine. Should I EMPTY it?

Thanks in advance for all your help. Best regards!

pumex
Hi,

When you uninstall AVG the quarantine file will go with it.

Avast is an extremely good Antivirus.

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



>>>NEXT<<<


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply I need

  • MBAM Log
  • Kaspersky report
  • FreshHJT Log
Here are the logs. Kasp took some time…

Malwarebytes' Anti-Malware 1.36
Database version: 2040
Windows 5.1.2600 Service Pack 3

25/04/2009 11:28:25 AM
mbam-log-2009-04-25 (11-28-25).txt

Scan type: Quick Scan
Objects scanned: 93155
Time elapsed: 4 minute(s), 41 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
==
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Saturday, April 25, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Saturday, April 25, 2009 20:06:28
Records in database: 2078441
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan statistics:
Files scanned: 245068
Threat name: 4
Infected objects: 4
Suspicious objects: 4
Duration of the scan: 04:35:52


File name / Threat name / Threats count
C:\Documents and Settings\HP_Administrator\Application Data\Thunderbird\Profiles\a5jytdt8.default\Mail\Local Folders\Inbox Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Documents and Settings\HP_Administrator\Application Data\Thunderbird\Profiles\a5jytdt8.default\Mail\Local Folders\Inbox Infected: Trojan-Clicker.HTML.Agent.ag 1
C:\Documents and Settings\HP_Administrator\Application Data\Thunderbird\Profiles\a5jytdt8.default\Mail\Local Folders\Inbox.sbd\20062008 Deals Suspicious: Trojan-Spy.HTML.Fraud.gen 3
C:\Documents and Settings\HP_Administrator\Desktop\Goodies\FREERemoteControlPC.rar Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 2
C:\Documents and Settings\HP_Administrator\Desktop\Goodies\FREERemoteControlPC.rar Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 1

The selected area was scanned.
==
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:07:03 PM, on 25/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\a-squared Free\a2service.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\HP_Administrator\Local Settings\temp\jkos-HP_Administrator\binaries\ScanningProcess.exe
C:\Documents and Settings\HP_Administrator\Local Settings\temp\jkos-HP_Administrator\binaries\ScanningProcess.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\MOZILL~2\THUNDE~1.EXE
C:\Program Files\AVG\AVG8\avgui.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by130fd.bay130.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: FinePrint Dispatcher v5 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O23 - Service: FinePrint Dispatcher v6 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
O23 - Service: Google Desktop Manager 5.7.805.16405 (GoogleDesktopManager-051608-133132) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c8e254e49c1a68) (gupdate1c8e254e49c1a68) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe

–
End of file - 10725 bytes
===
Thanks!
good news.

the logs are clean, still those infected emails that we discussed earlier.

we need to clean up the tools again



Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]



go back over the thread and follow the rest of the closing recommendations.

You may wish to consider a third party firewall

I also recommend using a third party firewall to protect your computer from hackers.
We don't recommend the firewall that comes built in to Windows.
It doesn't block everything that may try to get in, and the entire firewall is written to the registry.
As various kinds of malware hack the Registry in order to disable the Windows firewall, it's far preferable to install one of the excellent third party solutions.
Three excellent free firewalls are:

Comodo
Sunbelt Kerio
Sygate
NOTE: DO NOT install more than one firewall.

Note: If you choose Comodo - Please be careful with the installation of the Comodo program, it comes bundled with an adware toolbar which you need to de-select when you are going through the installation process. It's not a malicious program, but it may be a privacy risk and I don't think you want it on your system.

If you are switching out your AV, make sure you completely uninstall AVG.

Just follow the recommendations I had posted earlier, you shouldn't need anything more.

Best wishes
CB :wavey:
Thank you very much for everything! I hope the trojans are gone; at least I'm not getting those nasty alerts about them! Plus I protected myself by changing the passwords. It's funny that as soon as I did that those trojan alerts stopped!!! Was it coincidence? Or they gave up on me after I did those changes??? Anyway, I'm changing soon the AV to avast and also the firewall, but have to do some research. Thanks a lot again! Best regards. pumex
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI