mrs.hunt-taylor
Topic Starter
Problem in a nutshell:
Attempting to clean up my daughter's computer (desktop) as it was running VERY slow and Firefox was dying every time we started it, in doing so found a Zwangi.exe file. Did an internet search and found it is a backdoor trojan.
Concerns:
Computer is still running slower than usual. My concern is that the program is hiding somewhere else still infecting my computer(s) somehow. I am concerned that my laptop and other computers I have connected to via logmein may have been infected as well (I am also experiencing some issues with those PCs). I use a wireless network as well as logmein at home and am not sure if this type of trojan has the ability to be transferred over the network and infect other PCs. Do you know if this is the case? Desktop in question is running a Windows 2000 system and I was not able to download the SysRestorePoint which is what WhattheTech has suggested. Is there something else I can run to create a system restore? I have backed up my PC and have run ERUNT. Are there any other steps I need to take? Any other precautions (besides getting away from Windows
) that I can take to protect my PC? My daughter is constantly on Facebook, myspace and downloading games and music. Please advise, thank you.
What I've done thus far:
Prior to coming to the site I ran IObit Security 360 and deleted the .exe file from the Add/Remove program files. I have uninstalled Firefox and reinstalled, and so far Firefox seems to be running fine.
Below are the log files you have requested that I post if I start a new Topic regarding infections. I have also attached the logs from the IObit scan. I thank you in advance for your assistance!
================================================================================
===================================================
Malwarebytes' Anti-Malware 1.43
Database version: 3460
Windows 5.0.2195 Service Pack 4
Internet Explorer 6.0.2800.1106
12/30/2009 8:35:38 PM
mbam-log-2009-12-30 (20-35-38).txt
Scan type: Quick Scan
Objects scanned: 164045
Time elapsed: 26 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINNT/Downloaded Program Files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINNT\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\RelevantKnowledge (Spyware.MarketScore) -> Quarantined and deleted successfully.
Files Infected:
C:\Documents and Settings\aisha.FRONTDESK\Local Settings\Temp\~nsu.tmp\Au_.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\WINNT\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
C:\Program Files\RelevantKnowledge\rlls.dll (Spyware.MarketScore) -> Quarantined and deleted successfully.
================================================================================
===================================================
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2009-12-30 20:21:01
Windows 5.0.2195 Service Pack 4
Running: gmer.exe; Driver: C:\DOCUME~1\AISHA~1.FRO\LOCALS~1\Temp\kxlyrpob.sys
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Fastfat \Fat SSFS0BB9.SYS (Spy Sweeper FileSystem Filter Driver/Webroot Software Inc (www.webroot.com))
AttachedDevice \FileSystem\Fastfat \Fat avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device \Driver\Tcpip \Device\Ip 81620D20
Device \Driver\Tcpip \Device\Tcp 81620D20
Device \Driver\Tcpip \Device\Udp 81620D20
Device \Driver\Tcpip \Device\RawIp 81620D20
—- EOF - GMER 1.0.15 —-
================================================================================
==================================================
DDS (Ver_09-06-26.01) - FAT32x86
Run by [removed] at 20:23:29.47 on Wed 12/30/2009
Internet Explorer: 6.0.2800.1106 BrowserJavaVersion: 1.6.0_05
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.254.33 [GMT -5:00]
============== Running Processes ===============
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\WINNT\system32\lxctcoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINNT\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\IObit\IObit Security 360\IS360tray.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\aisha.FRONTDESK\Local Settings\Temporary Internet Files\Content.IE5\0LY507UT\dds[1].scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearch Page =
uSearch Bar =
mDefault_Page_URL = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride =
mSearchAssistant =
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
BHO: PCCBHO.CPCCBHO: {22fc6ce8-7d47-479f-b74a-bfbb04adb9af} - c:\program files\winferno\pc confidential\PCCBHO.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn3\YTSingleInstance.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {D0523BB4-21E7-11DD-9AB7-415B56D89593} - No File
EB: &Yahoo;! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\progra~1\yahoo!\common\yhexbmesus.dll
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\Browseui.dll
uRun: [ctfmon.exe] ctfmon.exe
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
uRun: [blinkxgate] c:\program files\blinkx\blinkx.exe -gate30
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [AROReminder] c:\program files\advanced registry optimizer\aro.exe -rem
mRun: [Synchronization Manager] mobsync.exe /logon
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [IObit Security 360] "c:\program files\iobit\iobit security 360\IS360tray.exe" /autostart
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
StartupFolder: c:\docume~1\aisha~1.fro\startm~1\programs\startup\memturbo.lnk - c:\program files\memturbo 4\MemTurbo.exe
StartupFolder: c:\docume~1\aisha~1.fro\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\aisha~1.fro\startm~1\programs\startup\memturbo.lnk - c:\program files\memturbo 4\MemTurbo.exe
StartupFolder: c:\docume~1\aisha~1.fro\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: &Yahoo;! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
IE: Yahoo! &Dictionary; - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\yahoo!\Common/ycsms.htm
IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - c:\program files\winferno\pc confidential\PCConfidential.exe
IE: {925DAB62-F9AC-4221-806A-057BFB1014AA} - c:\program files\winferno\pc confidential\PCConfidential.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} - hxxps://install.charter.com/diskless/bin/ssctlsma.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxps://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} - hxxp://www.freerealms.com/gamedata/FreeRealmsInstaller.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188250047702
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188250030868
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
Notify: WRNotifier - WRLogonNTF.dll
============= SERVICES / DRIVERS ===============
R0 Cdr4vsd;Cdr4vsd;c:\winnt\system32\drivers\Cdr4vsd.sys [2004-3-3 60560]
R1 Avg7Core;AVG7 Kernel;c:\winnt\system32\drivers\avg7core.sys [2007-10-24 821856]
R1 Avg7RsNT;AVG7 Resident Driver NT;c:\winnt\system32\drivers\avg7rsnt.sys [2007-10-24 26944]
R1 Avg7RsW;AVG7 Wrap Driver;c:\winnt\system32\drivers\avg7rsw.sys [2007-10-24 4224]
R1 AvgClean;AVG7 Clean Driver;c:\winnt\system32\drivers\avgclean.sys [2007-10-24 10760]
R1 cdudf;cdudf;c:\winnt\system32\drivers\Cdudf.sys [2001-1-11 363927]
R1 GhPciScan;GhostPciScanner;c:\program files\symantec\norton ghost 2003\GhPciScan.sys [2003-12-17 5632]
R2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avg7\avgamsvr.exe [2007-10-25 418816]
R2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avg7\avgupsvc.exe [2007-10-24 49664]
R2 IS360service;IS360service;c:\program files\iobit\iobit security 360\is360srv.exe [2009-12-30 312592]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2007-6-7 12992]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\winnt\system32\drivers\LMIRfsDriver.sys [2007-6-7 46112]
R2 NProtectService;Norton Unerase Protection;c:\program files\norton systemworks\norton utilities\NPROTECT.EXE [2004-1-9 135168]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\spy sweeper\SpySweeper.exe [2005-8-11 3567928]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\winnt\system32\drivers\mbamswissarmy.sys [2009-12-30 38224]
R3 usbhub20;USB 2.0 Root Hub Support;c:\winnt\system32\drivers\usbhub20.sys [2003-8-6 49776]
S3 BrUsbMdm;Brother MFC USB FaxModem driver;c:\winnt\system32\drivers\BrUsbMdm.sys [2007-8-27 10946]
S3 BrUsbScn;Brother MFC USB Scanner driver;c:\winnt\system32\drivers\BrUsbScn.sys [2007-8-27 10946]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
=============== Created Last 30 ================
2009-12-30 20:02 –d—– c:\docume~1\aisha~1.fro\applic~1\Malwarebytes
2009-12-30 20:02 38,224 a——- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-12-30 20:02 –d—– c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2009-12-30 20:02 18,520 a——- c:\winnt\system32\drivers\mbam.sys
2009-12-30 20:02 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-12-30 16:27 –d—– c:\docume~1\alluse~1.win\applic~1\IObit
2009-12-30 16:27 –d—– c:\program files\IObit
2009-12-30 16:23 –d—– c:\docume~1\aisha~1.fro\applic~1\Sammsoft
2009-12-30 16:22 –d—– c:\program files\MemTurbo 4
2009-12-30 16:22 –d—– c:\program files\Advanced Registry Optimizer
2009-12-30 15:43 125 a——- C:\ioSpecial.ini
2009-12-26 22:50 16,384 a——- c:\winnt\system32\Perflib_Perfdata_18d4.dat
2009-12-19 18:58 16,384 a——- c:\winnt\system32\Perflib_Perfdata_4c0.dat
2009-12-11 16:26 –d—– C:\FOUND.007
2009-12-11 15:49 16,384 a——- c:\winnt\system32\Perflib_Perfdata_5a8.dat
==================== Find3M ====================
2009-11-20 02:05 288,528 a——- c:\winnt\apppatch\aclayers.dll
2009-11-15 19:33 16,384 a——- c:\winnt\system32\Perflib_Perfdata_b40.dat
2009-11-12 18:21 16,384 a——- c:\winnt\system32\Perflib_Perfdata_9b0.dat
2009-11-12 17:35 16,384 a——- c:\winnt\system32\Perflib_Perfdata_490.dat
2009-11-11 12:33 16,384 a——- c:\winnt\system32\Perflib_Perfdata_448.dat
2009-11-10 15:39 16,384 a——- c:\winnt\system32\Perflib_Perfdata_430.dat
2009-11-08 16:29 16,384 a——- c:\winnt\system32\Perflib_Perfdata_444.dat
2009-11-07 13:44 16,384 a——- c:\winnt\system32\Perflib_Perfdata_f14.dat
2009-11-05 16:32 16,384 a——- c:\winnt\system32\Perflib_Perfdata_43c.dat
2009-10-27 13:01 132,096 a——- c:\winnt\system32\dllcache\MSRATING.DLL
2009-10-27 13:00 143,360 a——- c:\winnt\system32\dllcache\CDFVIEW.DLL
2009-10-27 13:00 1,018,368 a——- c:\winnt\system32\dllcache\BROWSEUI.DLL
2009-10-27 13:00 1,352,192 a——- c:\winnt\system32\dllcache\SHDOCVW.DLL
2009-10-27 12:54 576,512 a——- c:\winnt\system32\WININET.DLL
2009-10-27 12:54 576,512 a——- c:\winnt\system32\dllcache\WININET.DLL
2009-10-27 12:54 12,288 a——- c:\winnt\system32\dllcache\JSPROXY.DLL
2009-10-27 12:54 471,040 a——- c:\winnt\system32\dllcache\URLMON.DLL
2009-10-27 12:53 69,632 a——- c:\winnt\system32\dllcache\INSENG.DLL
2009-10-27 12:53 236,032 a——- c:\winnt\system32\dllcache\IEPEERS.DLL
2009-10-27 12:53 34,816 a——- c:\winnt\system32\dllcache\PNGFILT.DLL
2009-10-27 12:53 2,708,992 a——- c:\winnt\system32\dllcache\MSHTML.DLL
2009-10-27 12:53 351,744 a——- c:\winnt\system32\dllcache\DXTMSFT.DLL
2009-10-27 12:53 192,512 a——- c:\winnt\system32\dllcache\DXTRANS.DLL
2009-10-27 12:53 498,176 a——- c:\winnt\system32\dllcache\MSTIME.DLL
2009-10-16 15:13 1,227,264 a——- c:\winnt\system32\quartz.dll
2009-10-16 15:13 1,227,264 a——- c:\winnt\system32\dllcache\quartz.dll
2009-10-16 14:30 16,384 a——- c:\winnt\system32\Perflib_Perfdata_434.dat
2009-10-15 15:16 16,384 a——- c:\winnt\system32\Perflib_Perfdata_c18.dat
2009-10-13 06:17 64,784 a——- c:\winnt\system32\mswsock.dll
2009-10-13 06:17 64,784 a——- c:\winnt\system32\dllcache\mswsock.dll
2009-10-09 14:22 2,873 a——- c:\winnt\EReg515.dat
2009-10-09 01:21 101,136 a——- c:\winnt\system32\rastls.dll
2009-10-09 01:21 101,136 a——- c:\winnt\system32\dllcache\rastls.dll
2009-10-09 01:21 61,200 a——- c:\winnt\system32\RASCHAP.DLL
2009-10-09 01:21 61,200 a——- c:\winnt\system32\dllcache\RASCHAP.DLL
2009-10-08 08:54 417,552 a——- c:\winnt\system32\oakley.dll
2009-10-08 08:54 417,552 a——- c:\winnt\system32\dllcache\oakley.dll
2009-10-04 15:37 40,280 a——- c:\docume~1\aisha~1.fro\applic~1\GDIPFONTCACHEV1.DAT
2009-10-04 14:59 16,384 a——- c:\winnt\system32\Perflib_Perfdata_484.dat
2009-08-29 10:57 16,384 ——– c:\program files\Blinkx
2006-09-21 12:16 73,728 a—h— c:\docume~1\aisha~1.fro\applic~1\rbqt500.DLL
2006-06-21 15:44 6,999,984 a——- c:\program files\DJVUCNTL_601_EN.EXE
2006-06-13 19:49 2,995,368 a——- c:\program files\SVGView.exe
2003-06-02 18:54 21,952 —-h— c:\program files\folder.htt
2003-06-02 18:54 271 —-h— c:\program files\desktop.ini
1999-12-07 12:00 32,528 a——- c:\winnt\inf\wbfirdma.sys
2004-01-09 15:00 32 a–sh— c:\winnt\{7006CC4E-29FD-4045-BEFE-5AE67660ED1F}.dat
2004-01-09 15:00 32 a–sh— c:\winnt\{69F1C6D7-D17F-4CD6-8636-1853656EA8D0}.dat
2004-01-09 15:00 32 a–sh— c:\winnt\{801D94B7-5E85-4AC1-B4D6-806A0293B428}.dat
2004-01-09 15:01 32 a–sh— c:\winnt\{DC9A122F-A3E5-4FE4-8BC4-E22E2519D44D}.dat
2004-01-09 15:02 32 a–sh— c:\winnt\{5D62E720-07B8-4137-A4CE-CD65649D7FDC}.dat
2004-01-09 15:02 32 a–sh— c:\winnt\{7E5FD05F-B00A-4752-B5EB-A93CA45EE957}.dat
2004-01-09 15:00 32 a–sh— c:\winnt\system32\{C05826A4-6915-4291-B50D-A8D3A7099C81}.dat
2004-01-09 15:00 32 a–sh— c:\winnt\system32\{7BA0E987-1305-4718-B0B0-6DD000D3F522}.dat
2004-01-09 15:00 32 a–sh— c:\winnt\system32\{D79A0C06-1372-4BE3-9120-04BD3C1FA2F1}.dat
2004-01-09 15:01 32 a–sh— c:\winnt\system32\{EF4078DE-B8A7-42F0-A69D-CCE26366F2AF}.dat
2004-01-09 15:02 32 a–sh— c:\winnt\system32\{ABDBA2B6-7FEC-4F85-AD35-7A53F2E1489A}.dat
2004-01-09 15:02 32 a–sh— c:\winnt\system32\{2E94CC6A-B0E5-425A-A8BD-58F9C9F89231}.dat
============= FINISH: 20:26:06.98 ===============
================================================================================
===================================================
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows 2000 Professional
Boot Device: \Device\Harddisk0\Partition1
Install Date:
System Uptime: 12/30/2009 2:22:59 PM (6 hours ago)
Motherboard: Asus | | CUW-AM/MEW-AM
Processor: Intel Pentium III processor | Slot A | 1002/mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (FAT32) - 57 GiB total, 34.38 GiB free.
D: is CDROM ()
E: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.9
Adobe Shockwave Player
Advanced Registry Optimizer
AVG 7.5
Compatibility Pack for the 2007 Office system
Easy CD Creator 5 Platinum
eFax Messenger 3.5
ERUNT 1.1j
FaxRedist
HijackThis 1.99.1
Hotfix for MDAC 2.53 (KB911562)
Hotfix for MDAC 2.53 (KB927779)
Hotfix for Microsoft .NET Framework 2.0 Service Pack 1 (KB953300)
Hotfix for Microsoft .NET Framework 2.0 Service Pack 1 (KB971110)
hp LaserJet 1150 / 1300
IObit Security 360
iTunes
Java™ 6 Update 3
Java™ 6 Update 5
Lexmark 5400 Series
Lexmark Toolbar
LiveReg (Symantec Corporation)
LiveUpdate 2.6 (Symantec Corporation)
LogMeIn
Malwarebytes' Anti-Malware
MemTurbo 4
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 1.1 Security Update (KB971108)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Office XP Professional with FrontPage
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Norton CleanSweep
Norton Ghost
Norton Speed Disk 7.0 for Windows NT
Norton SystemWorks 2003
Norton Utilities 2003 for Windows
Norton WMI Update
OmniPage Pro 12.0
PC Confidential 2008
PC VGA Camer@ Plus
QuickTime
ScanSoft RealSpeak
Security Update for CAPICOM (KB931906)
Security Update for DirectX 8 (KB951698)
Security Update for DirectX 9 (KB951698)
Security Update for DirectX 9.0 (KB971633)
Security Update for DirectX 9.0 (KB976138)
Security Update for DirectX 9.0b (KB961373)
Security Update for Windows 2000 (KB923689)
Security Update for Windows 2000 (KB941569)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB975025)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 6.4 (KB954600)
Security Update for Windows Media Player 6.4 (KB974112)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows Media Player 9 (KB973540)
Spy Sweeper
Startup Manager 1.5
SVWin
Time, Money and Fractions
Update Rollup 1 for Windows 2000 SP4
WebEx
WebFldrs
Windows 2000 Hotfix - KB842773
Windows 2000 Hotfix - KB867282
Windows 2000 Hotfix - KB883939
Windows 2000 Hotfix - KB890046
Windows 2000 Hotfix - KB893756
Windows 2000 Hotfix - KB894320
Windows 2000 Hotfix - KB896358
Windows 2000 Hotfix - KB896422
Windows 2000 Hotfix - KB896423
Windows 2000 Hotfix - KB896424
Windows 2000 Hotfix - KB896688
Windows 2000 Hotfix - KB896727
Windows 2000 Hotfix - KB897715
Windows 2000 Hotfix - KB899587
Windows 2000 Hotfix - KB899588
Windows 2000 Hotfix - KB899589
Windows 2000 Hotfix - KB900725
Windows 2000 Hotfix - KB901017
Windows 2000 Hotfix - KB901214
Windows 2000 Hotfix - KB902400
Windows 2000 Hotfix - KB904706
Windows 2000 Hotfix - KB905414
Windows 2000 Hotfix - KB905495
Windows 2000 Hotfix - KB905749
Windows 2000 Hotfix - KB905915
Windows 2000 Hotfix - KB908519
Windows 2000 Hotfix - KB908523
Windows 2000 Hotfix - KB908531
Windows 2000 Hotfix - KB911280
Windows 2000 Hotfix - KB911567
Windows 2000 Hotfix - KB912812
Windows 2000 Hotfix - KB912919
Windows 2000 Hotfix - KB913580
Windows 2000 Hotfix - KB914388
Windows 2000 Hotfix - KB914389
Windows 2000 Hotfix - KB916281
Windows 2000 Hotfix - KB917008
Windows 2000 Hotfix - KB917159
Windows 2000 Hotfix - KB917422
Windows 2000 Hotfix - KB917537
Windows 2000 Hotfix - KB917736
Windows 2000 Hotfix - KB917953
Windows 2000 Hotfix - KB918118
Windows 2000 Hotfix - KB918899
Windows 2000 Hotfix - KB920213
Windows 2000 Hotfix - KB920670
Windows 2000 Hotfix - KB920683
Windows 2000 Hotfix - KB920685
Windows 2000 Hotfix - KB920958
Windows 2000 Hotfix - KB921398
Windows 2000 Hotfix - KB921503
Windows 2000 Hotfix - KB921883
Windows 2000 Hotfix - KB922582
Windows 2000 Hotfix - KB922616
Windows 2000 Hotfix - KB922760
Windows 2000 Hotfix - KB923191
Windows 2000 Hotfix - KB923414
Windows 2000 Hotfix - KB923561
Windows 2000 Hotfix - KB923694
Windows 2000 Hotfix - KB923810
Windows 2000 Hotfix - KB923980
Windows 2000 Hotfix - KB924191
Windows 2000 Hotfix - KB924270
Windows 2000 Hotfix - KB924667
Windows 2000 Hotfix - KB925454
Windows 2000 Hotfix - KB925486
Windows 2000 Hotfix - KB925902
Windows 2000 Hotfix - KB926122
Windows 2000 Hotfix - KB926436
Windows 2000 Hotfix - KB927891
Windows 2000 Hotfix - KB928090
Windows 2000 Hotfix - KB928843
Windows 2000 Hotfix - KB929969
Windows 2000 Hotfix - KB930178
Windows 2000 Hotfix - KB931768
Windows 2000 Hotfix - KB931784
Windows 2000 Hotfix - KB932168
Windows 2000 Hotfix - KB933566
Windows 2000 Hotfix - KB933729
Windows 2000 Hotfix - KB935839
Windows 2000 Hotfix - KB935840
Windows 2000 Hotfix - KB936021
Windows 2000 Hotfix - KB937143
Windows 2000 Hotfix - KB937894
Windows 2000 Hotfix - KB938127
Windows 2000 Hotfix - KB938464
Windows 2000 Hotfix - KB938827
Windows 2000 Hotfix - KB938829
Windows 2000 Hotfix - KB939653
Windows 2000 Hotfix - KB941202
Windows 2000 Hotfix - KB941568
Windows 2000 Hotfix - KB941644
Windows 2000 Hotfix - KB941693
Windows 2000 Hotfix - KB942615
Windows 2000 Hotfix - KB943055
Windows 2000 Hotfix - KB943485
Windows 2000 Hotfix - KB944338
Windows 2000 Hotfix - KB944533
Windows 2000 Hotfix - KB945553
Windows 2000 Hotfix - KB947864
Windows 2000 Hotfix - KB948590
Windows 2000 Hotfix - KB948881
Windows 2000 Hotfix - KB950749
Windows 2000 Hotfix - KB950759
Windows 2000 Hotfix - KB950760
Windows 2000 Hotfix - KB950974
Windows 2000 Hotfix - KB951066
Windows 2000 Hotfix - KB951698
Windows 2000 Hotfix - KB951748
Windows 2000 Hotfix - KB951748-V2
Windows 2000 Hotfix - KB952004
Windows 2000 Hotfix - KB952954
Windows 2000 Hotfix - KB954211
Windows 2000 Hotfix - KB955069
Windows 2000 Hotfix - KB955759
Windows 2000 Hotfix - KB956391
Windows 2000 Hotfix - KB956802
Windows 2000 Hotfix - KB956844
Windows 2000 Hotfix - KB957097
Windows 2000 Hotfix - KB958215
Windows 2000 Hotfix - KB958470
Windows 2000 Hotfix - KB958644
Windows 2000 Hotfix - KB958687
Windows 2000 Hotfix - KB958690
Windows 2000 Hotfix - KB958869
Windows 2000 Hotfix - KB959426
Windows 2000 Hotfix - KB960225
Windows 2000 Hotfix - KB960714
Windows 2000 Hotfix - KB960715
Windows 2000 Hotfix - KB960803
Windows 2000 Hotfix - KB960859
Windows 2000 Hotfix - KB961371
Windows 2000 Hotfix - KB961371-V2
Windows 2000 Hotfix - KB961501
Windows 2000 Hotfix - KB963027
Windows 2000 Hotfix - KB967715
Windows 2000 Hotfix - KB968537
Windows 2000 Hotfix - KB969059
Windows 2000 Hotfix - KB969897
Windows 2000 Hotfix - KB969898
Windows 2000 Hotfix - KB969947
Windows 2000 Hotfix - KB970238
Windows 2000 Hotfix - KB971486
Windows 2000 Hotfix - KB971557
Windows 2000 Hotfix - KB971961
Windows 2000 Hotfix - KB972260
Windows 2000 Hotfix - KB973346
Windows 2000 Hotfix - KB973354
Windows 2000 Hotfix - KB973507
Windows 2000 Hotfix - KB973525
Windows 2000 Hotfix - KB973869
Windows 2000 Hotfix - KB973904
Windows 2000 Hotfix - KB974318
Windows 2000 Hotfix - KB974392
Windows 2000 Hotfix - KB974455
Windows 2000 Hotfix - KB974571
Windows 2000 Hotfix - KB976325
Windows 2000 Hotfix - KB976749
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Media Player 9 Hotfix [See KB885492 for more information]
Windows Media Player Hotfix [See Q828026 for more information]
Windows Media Player system update (9 Series)
Winferno Registry Power Cleaner
WinZip
Yahoo! extras
Yahoo! Internet Mail
Yahoo! Software Update
Yahoo! Toolbar
==== End Of File ===========================
================================================================================
==================================================
IObit logs…
Logfile of IObit HijackScan v1.0.0.0
Scan saved at 17:39:53, on 2009-12-30
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\WINNT\system32\lxctcoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINNT\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\IObit\IObit Security 360\is360.exe
C:\Program Files\IObit\IObit Security 360\IS360tray.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\IObit\IObit Security 360\a_hijackscan.exe
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Unknown - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [ctfmon.exe] ctfmon.exe
O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [blinkxgate] C:\Program Files\Blinkx\blinkx.exe -gate30
O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [IObit Security 360] "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
O9 - Extra button: PC Confidential - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe
O9 - Extra button: PC Confidential - {925DAB62-F9AC-4221-806A-057BFB1014AA} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe
O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE}SPRT.SmartAccessCtl.1 - https://install.charter.com/diskless/bin/ssctlsma.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}SWCtl.SWCtl.10.1.1 - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB}YInstHelper.YInstStarter.1 - https://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1}soex.SonyOnlineInstallerXctl.1 - http://www.freerealms.com/gamedata/FreeRealmsInstaller.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}SoftwareDistribution.WebControl.1 - http://www.update.microsoft.com/microsoftu…b?1188250047702
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}SoftwareDistribution.MicrosoftUpdateWebControl.1 - http://www.update.microsoft.com/microsoftu…b?1188250030868
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}Java Plug-in 1.6.0_05 - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A}MySpace.Uploader.5.1 - http://lads.myspace.com/upload/MySpaceUploader2.cab
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}Java Plug-in 1.6.0_03 - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}Java Plug-in 1.6.0_05 - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}Java Plug-in 1.6.0_05 - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}PopCapLoader.PopCapLoaderCtrl2.1 - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: GhostStartService (GhostStartService) - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn (LogMeIn) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: lxct_device (lxct_device) - - C:\WINNT\system32\lxctcoms.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 (Pml Driver HPZ12) - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Speed Disk service (Speed Disk service) - Symantec Corporation - C:\Program Files\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
O23 - Service: IS360service (IS360service) - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe
================================================================================
===================================================
IObit Security 360
OS:Windows 2000
Version:1.3.0.10
Define Version:1302
Time Elapsed:00:09:29
Objects Scanned:47076
Threats Found:52
|Name|Type|Description|ID|
Spyware.Marketscore, Folder, C:\Program Files\RelevantKnowledge, 3-328
Spyware.Marketscore, File, C:\Program Files\RelevantKnowledge\rlvknlg.exe, 3-328
Spyware.Marketscore, File, C:\Program Files\RelevantKnowledge\rloci.bin, 3-328
Spyware.Marketscore, File, C:\Program Files\RelevantKnowledge\rlls.dll, 3-328
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1853
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1848
Tracking Cookies, Cookies, Cookie:[removed]/smt2/, 7-1522
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1853
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1699
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2184
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1545
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1535
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1655
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1873
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1813
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1567
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1698
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1698
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1776
Tracking Cookies, Cookies, Cookie:[removed]/, 7-14
Tracking Cookies, Cookies, Cookie:[removed]/, 7-7
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1813
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2225
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1656
Tracking Cookies, Cookies, Cookie:[removed]/, 7-19
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1853
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1573
Tracking Cookies, Cookies, Cookie:[removed]/, 7-9
Tracking Cookies, Cookies, Cookie:[removed]/, 7-55
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1559
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1886
Tracking Cookies, Cookies, Cookie:[removed]/, 7-9
Tracking Cookies, Cookies, Cookie:[removed]/pagead/imgclick/8mtTql4IO-NgzNk_g31S/newsletter_20090901, 7-1856
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1892
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1853
Tracking Cookies, Cookies, Cookie:[removed]/, 7-12
Tracking Cookies, Cookies, Cookie:[removed]/, 7-9
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2180
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2170
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1691
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2222
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1746
Tracking Cookies, Cookies, Cookie:[removed]/pagead/, 7-1856
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2184
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2073
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2048
Tracking Cookies, Cookies, Cookie:[removed]/pagead/, 7-1856
Tracking Cookies, Cookies, Cookie:[removed]/, 7-45
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1823
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1574
Adware.PopCap, Registry Key, HKEY_CLASSES_ROOT\PopCapLoader.PopCapLoaderCtrl2, 4-19290
Adware.PopCap, Registry Key, HKEY_CLASSES_ROOT\PopCapLoader.PopCapLoaderCtrl2.1, 4-19290
================================================================================
===================================================
IObit Security 360
OS:Windows 2000
Version:1.3.0.10
Define Version:1302
Time Elapsed:00:45:11
Objects Scanned:60854
Threats Found:19
|Name|Type|Description|ID|
Spyware.Marketscore, Folder, C:\Program Files\RelevantKnowledge, 3-328
Spyware.Marketscore, File, C:\Program Files\RelevantKnowledge\rlls.dll, 3-328
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1908
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2231
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2027
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1646
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2171
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2178
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2171
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1853
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1718
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1853
Tracking Cookies, Cookies, Cookie:[removed]/adlytics, 7-1656
Tracking Cookies, Cookies, Cookie:[removed]/, 7-9
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2052
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1664
Adware.MyWeb, File, C:\My Documents\Downloads\IWONSetup2.3.50.49.ZLfox000.exe, 8-55
Injector.UD, File, C:\backup\LAUR_BAK\Program Files\Adaptec\Shared\Web-Checkup\uninst.exe, 11-2214
Injector.UD, File, C:\backup\KATR_BAK\Program Files\Adaptec\Shared\Web-Checkup\uninst.exe, 11-2214
Attempting to clean up my daughter's computer (desktop) as it was running VERY slow and Firefox was dying every time we started it, in doing so found a Zwangi.exe file. Did an internet search and found it is a backdoor trojan.
Concerns:
Computer is still running slower than usual. My concern is that the program is hiding somewhere else still infecting my computer(s) somehow. I am concerned that my laptop and other computers I have connected to via logmein may have been infected as well (I am also experiencing some issues with those PCs). I use a wireless network as well as logmein at home and am not sure if this type of trojan has the ability to be transferred over the network and infect other PCs. Do you know if this is the case? Desktop in question is running a Windows 2000 system and I was not able to download the SysRestorePoint which is what WhattheTech has suggested. Is there something else I can run to create a system restore? I have backed up my PC and have run ERUNT. Are there any other steps I need to take? Any other precautions (besides getting away from Windows
What I've done thus far:
Prior to coming to the site I ran IObit Security 360 and deleted the .exe file from the Add/Remove program files. I have uninstalled Firefox and reinstalled, and so far Firefox seems to be running fine.
Below are the log files you have requested that I post if I start a new Topic regarding infections. I have also attached the logs from the IObit scan. I thank you in advance for your assistance!
================================================================================
===================================================
Malwarebytes' Anti-Malware 1.43
Database version: 3460
Windows 5.0.2195 Service Pack 4
Internet Explorer 6.0.2800.1106
12/30/2009 8:35:38 PM
mbam-log-2009-12-30 (20-35-38).txt
Scan type: Quick Scan
Objects scanned: 164045
Time elapsed: 26 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINNT/Downloaded Program Files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINNT\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\RelevantKnowledge (Spyware.MarketScore) -> Quarantined and deleted successfully.
Files Infected:
C:\Documents and Settings\aisha.FRONTDESK\Local Settings\Temp\~nsu.tmp\Au_.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\WINNT\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
C:\Program Files\RelevantKnowledge\rlls.dll (Spyware.MarketScore) -> Quarantined and deleted successfully.
================================================================================
===================================================
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2009-12-30 20:21:01
Windows 5.0.2195 Service Pack 4
Running: gmer.exe; Driver: C:\DOCUME~1\AISHA~1.FRO\LOCALS~1\Temp\kxlyrpob.sys
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Fastfat \Fat SSFS0BB9.SYS (Spy Sweeper FileSystem Filter Driver/Webroot Software Inc (www.webroot.com))
AttachedDevice \FileSystem\Fastfat \Fat avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device \Driver\Tcpip \Device\Ip 81620D20
Device \Driver\Tcpip \Device\Tcp 81620D20
Device \Driver\Tcpip \Device\Udp 81620D20
Device \Driver\Tcpip \Device\RawIp 81620D20
—- EOF - GMER 1.0.15 —-
================================================================================
==================================================
DDS (Ver_09-06-26.01) - FAT32x86
Run by [removed] at 20:23:29.47 on Wed 12/30/2009
Internet Explorer: 6.0.2800.1106 BrowserJavaVersion: 1.6.0_05
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.254.33 [GMT -5:00]
============== Running Processes ===============
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\WINNT\system32\lxctcoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINNT\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\IObit\IObit Security 360\IS360tray.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\aisha.FRONTDESK\Local Settings\Temporary Internet Files\Content.IE5\0LY507UT\dds[1].scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearch Page =
uSearch Bar =
mDefault_Page_URL = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride =
mSearchAssistant =
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
BHO: PCCBHO.CPCCBHO: {22fc6ce8-7d47-479f-b74a-bfbb04adb9af} - c:\program files\winferno\pc confidential\PCCBHO.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn3\YTSingleInstance.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {D0523BB4-21E7-11DD-9AB7-415B56D89593} - No File
EB: &Yahoo;! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\progra~1\yahoo!\common\yhexbmesus.dll
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\Browseui.dll
uRun: [ctfmon.exe] ctfmon.exe
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
uRun: [blinkxgate] c:\program files\blinkx\blinkx.exe -gate30
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [AROReminder] c:\program files\advanced registry optimizer\aro.exe -rem
mRun: [Synchronization Manager] mobsync.exe /logon
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [IObit Security 360] "c:\program files\iobit\iobit security 360\IS360tray.exe" /autostart
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
StartupFolder: c:\docume~1\aisha~1.fro\startm~1\programs\startup\memturbo.lnk - c:\program files\memturbo 4\MemTurbo.exe
StartupFolder: c:\docume~1\aisha~1.fro\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\aisha~1.fro\startm~1\programs\startup\memturbo.lnk - c:\program files\memturbo 4\MemTurbo.exe
StartupFolder: c:\docume~1\aisha~1.fro\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: &Yahoo;! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
IE: Yahoo! &Dictionary; - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\yahoo!\Common/ycsms.htm
IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - c:\program files\winferno\pc confidential\PCConfidential.exe
IE: {925DAB62-F9AC-4221-806A-057BFB1014AA} - c:\program files\winferno\pc confidential\PCConfidential.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} - hxxps://install.charter.com/diskless/bin/ssctlsma.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxps://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} - hxxp://www.freerealms.com/gamedata/FreeRealmsInstaller.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188250047702
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188250030868
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
Notify: WRNotifier - WRLogonNTF.dll
============= SERVICES / DRIVERS ===============
R0 Cdr4vsd;Cdr4vsd;c:\winnt\system32\drivers\Cdr4vsd.sys [2004-3-3 60560]
R1 Avg7Core;AVG7 Kernel;c:\winnt\system32\drivers\avg7core.sys [2007-10-24 821856]
R1 Avg7RsNT;AVG7 Resident Driver NT;c:\winnt\system32\drivers\avg7rsnt.sys [2007-10-24 26944]
R1 Avg7RsW;AVG7 Wrap Driver;c:\winnt\system32\drivers\avg7rsw.sys [2007-10-24 4224]
R1 AvgClean;AVG7 Clean Driver;c:\winnt\system32\drivers\avgclean.sys [2007-10-24 10760]
R1 cdudf;cdudf;c:\winnt\system32\drivers\Cdudf.sys [2001-1-11 363927]
R1 GhPciScan;GhostPciScanner;c:\program files\symantec\norton ghost 2003\GhPciScan.sys [2003-12-17 5632]
R2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avg7\avgamsvr.exe [2007-10-25 418816]
R2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avg7\avgupsvc.exe [2007-10-24 49664]
R2 IS360service;IS360service;c:\program files\iobit\iobit security 360\is360srv.exe [2009-12-30 312592]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2007-6-7 12992]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\winnt\system32\drivers\LMIRfsDriver.sys [2007-6-7 46112]
R2 NProtectService;Norton Unerase Protection;c:\program files\norton systemworks\norton utilities\NPROTECT.EXE [2004-1-9 135168]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\spy sweeper\SpySweeper.exe [2005-8-11 3567928]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\winnt\system32\drivers\mbamswissarmy.sys [2009-12-30 38224]
R3 usbhub20;USB 2.0 Root Hub Support;c:\winnt\system32\drivers\usbhub20.sys [2003-8-6 49776]
S3 BrUsbMdm;Brother MFC USB FaxModem driver;c:\winnt\system32\drivers\BrUsbMdm.sys [2007-8-27 10946]
S3 BrUsbScn;Brother MFC USB Scanner driver;c:\winnt\system32\drivers\BrUsbScn.sys [2007-8-27 10946]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
=============== Created Last 30 ================
2009-12-30 20:02 –d—– c:\docume~1\aisha~1.fro\applic~1\Malwarebytes
2009-12-30 20:02 38,224 a——- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-12-30 20:02 –d—– c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2009-12-30 20:02 18,520 a——- c:\winnt\system32\drivers\mbam.sys
2009-12-30 20:02 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-12-30 16:27 –d—– c:\docume~1\alluse~1.win\applic~1\IObit
2009-12-30 16:27 –d—– c:\program files\IObit
2009-12-30 16:23 –d—– c:\docume~1\aisha~1.fro\applic~1\Sammsoft
2009-12-30 16:22 –d—– c:\program files\MemTurbo 4
2009-12-30 16:22 –d—– c:\program files\Advanced Registry Optimizer
2009-12-30 15:43 125 a——- C:\ioSpecial.ini
2009-12-26 22:50 16,384 a——- c:\winnt\system32\Perflib_Perfdata_18d4.dat
2009-12-19 18:58 16,384 a——- c:\winnt\system32\Perflib_Perfdata_4c0.dat
2009-12-11 16:26 –d—– C:\FOUND.007
2009-12-11 15:49 16,384 a——- c:\winnt\system32\Perflib_Perfdata_5a8.dat
==================== Find3M ====================
2009-11-20 02:05 288,528 a——- c:\winnt\apppatch\aclayers.dll
2009-11-15 19:33 16,384 a——- c:\winnt\system32\Perflib_Perfdata_b40.dat
2009-11-12 18:21 16,384 a——- c:\winnt\system32\Perflib_Perfdata_9b0.dat
2009-11-12 17:35 16,384 a——- c:\winnt\system32\Perflib_Perfdata_490.dat
2009-11-11 12:33 16,384 a——- c:\winnt\system32\Perflib_Perfdata_448.dat
2009-11-10 15:39 16,384 a——- c:\winnt\system32\Perflib_Perfdata_430.dat
2009-11-08 16:29 16,384 a——- c:\winnt\system32\Perflib_Perfdata_444.dat
2009-11-07 13:44 16,384 a——- c:\winnt\system32\Perflib_Perfdata_f14.dat
2009-11-05 16:32 16,384 a——- c:\winnt\system32\Perflib_Perfdata_43c.dat
2009-10-27 13:01 132,096 a——- c:\winnt\system32\dllcache\MSRATING.DLL
2009-10-27 13:00 143,360 a——- c:\winnt\system32\dllcache\CDFVIEW.DLL
2009-10-27 13:00 1,018,368 a——- c:\winnt\system32\dllcache\BROWSEUI.DLL
2009-10-27 13:00 1,352,192 a——- c:\winnt\system32\dllcache\SHDOCVW.DLL
2009-10-27 12:54 576,512 a——- c:\winnt\system32\WININET.DLL
2009-10-27 12:54 576,512 a——- c:\winnt\system32\dllcache\WININET.DLL
2009-10-27 12:54 12,288 a——- c:\winnt\system32\dllcache\JSPROXY.DLL
2009-10-27 12:54 471,040 a——- c:\winnt\system32\dllcache\URLMON.DLL
2009-10-27 12:53 69,632 a——- c:\winnt\system32\dllcache\INSENG.DLL
2009-10-27 12:53 236,032 a——- c:\winnt\system32\dllcache\IEPEERS.DLL
2009-10-27 12:53 34,816 a——- c:\winnt\system32\dllcache\PNGFILT.DLL
2009-10-27 12:53 2,708,992 a——- c:\winnt\system32\dllcache\MSHTML.DLL
2009-10-27 12:53 351,744 a——- c:\winnt\system32\dllcache\DXTMSFT.DLL
2009-10-27 12:53 192,512 a——- c:\winnt\system32\dllcache\DXTRANS.DLL
2009-10-27 12:53 498,176 a——- c:\winnt\system32\dllcache\MSTIME.DLL
2009-10-16 15:13 1,227,264 a——- c:\winnt\system32\quartz.dll
2009-10-16 15:13 1,227,264 a——- c:\winnt\system32\dllcache\quartz.dll
2009-10-16 14:30 16,384 a——- c:\winnt\system32\Perflib_Perfdata_434.dat
2009-10-15 15:16 16,384 a——- c:\winnt\system32\Perflib_Perfdata_c18.dat
2009-10-13 06:17 64,784 a——- c:\winnt\system32\mswsock.dll
2009-10-13 06:17 64,784 a——- c:\winnt\system32\dllcache\mswsock.dll
2009-10-09 14:22 2,873 a——- c:\winnt\EReg515.dat
2009-10-09 01:21 101,136 a——- c:\winnt\system32\rastls.dll
2009-10-09 01:21 101,136 a——- c:\winnt\system32\dllcache\rastls.dll
2009-10-09 01:21 61,200 a——- c:\winnt\system32\RASCHAP.DLL
2009-10-09 01:21 61,200 a——- c:\winnt\system32\dllcache\RASCHAP.DLL
2009-10-08 08:54 417,552 a——- c:\winnt\system32\oakley.dll
2009-10-08 08:54 417,552 a——- c:\winnt\system32\dllcache\oakley.dll
2009-10-04 15:37 40,280 a——- c:\docume~1\aisha~1.fro\applic~1\GDIPFONTCACHEV1.DAT
2009-10-04 14:59 16,384 a——- c:\winnt\system32\Perflib_Perfdata_484.dat
2009-08-29 10:57 16,384 ——– c:\program files\Blinkx
2006-09-21 12:16 73,728 a—h— c:\docume~1\aisha~1.fro\applic~1\rbqt500.DLL
2006-06-21 15:44 6,999,984 a——- c:\program files\DJVUCNTL_601_EN.EXE
2006-06-13 19:49 2,995,368 a——- c:\program files\SVGView.exe
2003-06-02 18:54 21,952 —-h— c:\program files\folder.htt
2003-06-02 18:54 271 —-h— c:\program files\desktop.ini
1999-12-07 12:00 32,528 a——- c:\winnt\inf\wbfirdma.sys
2004-01-09 15:00 32 a–sh— c:\winnt\{7006CC4E-29FD-4045-BEFE-5AE67660ED1F}.dat
2004-01-09 15:00 32 a–sh— c:\winnt\{69F1C6D7-D17F-4CD6-8636-1853656EA8D0}.dat
2004-01-09 15:00 32 a–sh— c:\winnt\{801D94B7-5E85-4AC1-B4D6-806A0293B428}.dat
2004-01-09 15:01 32 a–sh— c:\winnt\{DC9A122F-A3E5-4FE4-8BC4-E22E2519D44D}.dat
2004-01-09 15:02 32 a–sh— c:\winnt\{5D62E720-07B8-4137-A4CE-CD65649D7FDC}.dat
2004-01-09 15:02 32 a–sh— c:\winnt\{7E5FD05F-B00A-4752-B5EB-A93CA45EE957}.dat
2004-01-09 15:00 32 a–sh— c:\winnt\system32\{C05826A4-6915-4291-B50D-A8D3A7099C81}.dat
2004-01-09 15:00 32 a–sh— c:\winnt\system32\{7BA0E987-1305-4718-B0B0-6DD000D3F522}.dat
2004-01-09 15:00 32 a–sh— c:\winnt\system32\{D79A0C06-1372-4BE3-9120-04BD3C1FA2F1}.dat
2004-01-09 15:01 32 a–sh— c:\winnt\system32\{EF4078DE-B8A7-42F0-A69D-CCE26366F2AF}.dat
2004-01-09 15:02 32 a–sh— c:\winnt\system32\{ABDBA2B6-7FEC-4F85-AD35-7A53F2E1489A}.dat
2004-01-09 15:02 32 a–sh— c:\winnt\system32\{2E94CC6A-B0E5-425A-A8BD-58F9C9F89231}.dat
============= FINISH: 20:26:06.98 ===============
================================================================================
===================================================
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows 2000 Professional
Boot Device: \Device\Harddisk0\Partition1
Install Date:
System Uptime: 12/30/2009 2:22:59 PM (6 hours ago)
Motherboard: Asus | | CUW-AM/MEW-AM
Processor: Intel Pentium III processor | Slot A | 1002/mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (FAT32) - 57 GiB total, 34.38 GiB free.
D: is CDROM ()
E: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.9
Adobe Shockwave Player
Advanced Registry Optimizer
AVG 7.5
Compatibility Pack for the 2007 Office system
Easy CD Creator 5 Platinum
eFax Messenger 3.5
ERUNT 1.1j
FaxRedist
HijackThis 1.99.1
Hotfix for MDAC 2.53 (KB911562)
Hotfix for MDAC 2.53 (KB927779)
Hotfix for Microsoft .NET Framework 2.0 Service Pack 1 (KB953300)
Hotfix for Microsoft .NET Framework 2.0 Service Pack 1 (KB971110)
hp LaserJet 1150 / 1300
IObit Security 360
iTunes
Java™ 6 Update 3
Java™ 6 Update 5
Lexmark 5400 Series
Lexmark Toolbar
LiveReg (Symantec Corporation)
LiveUpdate 2.6 (Symantec Corporation)
LogMeIn
Malwarebytes' Anti-Malware
MemTurbo 4
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 1.1 Security Update (KB971108)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Office XP Professional with FrontPage
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Norton CleanSweep
Norton Ghost
Norton Speed Disk 7.0 for Windows NT
Norton SystemWorks 2003
Norton Utilities 2003 for Windows
Norton WMI Update
OmniPage Pro 12.0
PC Confidential 2008
PC VGA Camer@ Plus
QuickTime
ScanSoft RealSpeak
Security Update for CAPICOM (KB931906)
Security Update for DirectX 8 (KB951698)
Security Update for DirectX 9 (KB951698)
Security Update for DirectX 9.0 (KB971633)
Security Update for DirectX 9.0 (KB976138)
Security Update for DirectX 9.0b (KB961373)
Security Update for Windows 2000 (KB923689)
Security Update for Windows 2000 (KB941569)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB975025)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 6.4 (KB954600)
Security Update for Windows Media Player 6.4 (KB974112)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows Media Player 9 (KB973540)
Spy Sweeper
Startup Manager 1.5
SVWin
Time, Money and Fractions
Update Rollup 1 for Windows 2000 SP4
WebEx
WebFldrs
Windows 2000 Hotfix - KB842773
Windows 2000 Hotfix - KB867282
Windows 2000 Hotfix - KB883939
Windows 2000 Hotfix - KB890046
Windows 2000 Hotfix - KB893756
Windows 2000 Hotfix - KB894320
Windows 2000 Hotfix - KB896358
Windows 2000 Hotfix - KB896422
Windows 2000 Hotfix - KB896423
Windows 2000 Hotfix - KB896424
Windows 2000 Hotfix - KB896688
Windows 2000 Hotfix - KB896727
Windows 2000 Hotfix - KB897715
Windows 2000 Hotfix - KB899587
Windows 2000 Hotfix - KB899588
Windows 2000 Hotfix - KB899589
Windows 2000 Hotfix - KB900725
Windows 2000 Hotfix - KB901017
Windows 2000 Hotfix - KB901214
Windows 2000 Hotfix - KB902400
Windows 2000 Hotfix - KB904706
Windows 2000 Hotfix - KB905414
Windows 2000 Hotfix - KB905495
Windows 2000 Hotfix - KB905749
Windows 2000 Hotfix - KB905915
Windows 2000 Hotfix - KB908519
Windows 2000 Hotfix - KB908523
Windows 2000 Hotfix - KB908531
Windows 2000 Hotfix - KB911280
Windows 2000 Hotfix - KB911567
Windows 2000 Hotfix - KB912812
Windows 2000 Hotfix - KB912919
Windows 2000 Hotfix - KB913580
Windows 2000 Hotfix - KB914388
Windows 2000 Hotfix - KB914389
Windows 2000 Hotfix - KB916281
Windows 2000 Hotfix - KB917008
Windows 2000 Hotfix - KB917159
Windows 2000 Hotfix - KB917422
Windows 2000 Hotfix - KB917537
Windows 2000 Hotfix - KB917736
Windows 2000 Hotfix - KB917953
Windows 2000 Hotfix - KB918118
Windows 2000 Hotfix - KB918899
Windows 2000 Hotfix - KB920213
Windows 2000 Hotfix - KB920670
Windows 2000 Hotfix - KB920683
Windows 2000 Hotfix - KB920685
Windows 2000 Hotfix - KB920958
Windows 2000 Hotfix - KB921398
Windows 2000 Hotfix - KB921503
Windows 2000 Hotfix - KB921883
Windows 2000 Hotfix - KB922582
Windows 2000 Hotfix - KB922616
Windows 2000 Hotfix - KB922760
Windows 2000 Hotfix - KB923191
Windows 2000 Hotfix - KB923414
Windows 2000 Hotfix - KB923561
Windows 2000 Hotfix - KB923694
Windows 2000 Hotfix - KB923810
Windows 2000 Hotfix - KB923980
Windows 2000 Hotfix - KB924191
Windows 2000 Hotfix - KB924270
Windows 2000 Hotfix - KB924667
Windows 2000 Hotfix - KB925454
Windows 2000 Hotfix - KB925486
Windows 2000 Hotfix - KB925902
Windows 2000 Hotfix - KB926122
Windows 2000 Hotfix - KB926436
Windows 2000 Hotfix - KB927891
Windows 2000 Hotfix - KB928090
Windows 2000 Hotfix - KB928843
Windows 2000 Hotfix - KB929969
Windows 2000 Hotfix - KB930178
Windows 2000 Hotfix - KB931768
Windows 2000 Hotfix - KB931784
Windows 2000 Hotfix - KB932168
Windows 2000 Hotfix - KB933566
Windows 2000 Hotfix - KB933729
Windows 2000 Hotfix - KB935839
Windows 2000 Hotfix - KB935840
Windows 2000 Hotfix - KB936021
Windows 2000 Hotfix - KB937143
Windows 2000 Hotfix - KB937894
Windows 2000 Hotfix - KB938127
Windows 2000 Hotfix - KB938464
Windows 2000 Hotfix - KB938827
Windows 2000 Hotfix - KB938829
Windows 2000 Hotfix - KB939653
Windows 2000 Hotfix - KB941202
Windows 2000 Hotfix - KB941568
Windows 2000 Hotfix - KB941644
Windows 2000 Hotfix - KB941693
Windows 2000 Hotfix - KB942615
Windows 2000 Hotfix - KB943055
Windows 2000 Hotfix - KB943485
Windows 2000 Hotfix - KB944338
Windows 2000 Hotfix - KB944533
Windows 2000 Hotfix - KB945553
Windows 2000 Hotfix - KB947864
Windows 2000 Hotfix - KB948590
Windows 2000 Hotfix - KB948881
Windows 2000 Hotfix - KB950749
Windows 2000 Hotfix - KB950759
Windows 2000 Hotfix - KB950760
Windows 2000 Hotfix - KB950974
Windows 2000 Hotfix - KB951066
Windows 2000 Hotfix - KB951698
Windows 2000 Hotfix - KB951748
Windows 2000 Hotfix - KB951748-V2
Windows 2000 Hotfix - KB952004
Windows 2000 Hotfix - KB952954
Windows 2000 Hotfix - KB954211
Windows 2000 Hotfix - KB955069
Windows 2000 Hotfix - KB955759
Windows 2000 Hotfix - KB956391
Windows 2000 Hotfix - KB956802
Windows 2000 Hotfix - KB956844
Windows 2000 Hotfix - KB957097
Windows 2000 Hotfix - KB958215
Windows 2000 Hotfix - KB958470
Windows 2000 Hotfix - KB958644
Windows 2000 Hotfix - KB958687
Windows 2000 Hotfix - KB958690
Windows 2000 Hotfix - KB958869
Windows 2000 Hotfix - KB959426
Windows 2000 Hotfix - KB960225
Windows 2000 Hotfix - KB960714
Windows 2000 Hotfix - KB960715
Windows 2000 Hotfix - KB960803
Windows 2000 Hotfix - KB960859
Windows 2000 Hotfix - KB961371
Windows 2000 Hotfix - KB961371-V2
Windows 2000 Hotfix - KB961501
Windows 2000 Hotfix - KB963027
Windows 2000 Hotfix - KB967715
Windows 2000 Hotfix - KB968537
Windows 2000 Hotfix - KB969059
Windows 2000 Hotfix - KB969897
Windows 2000 Hotfix - KB969898
Windows 2000 Hotfix - KB969947
Windows 2000 Hotfix - KB970238
Windows 2000 Hotfix - KB971486
Windows 2000 Hotfix - KB971557
Windows 2000 Hotfix - KB971961
Windows 2000 Hotfix - KB972260
Windows 2000 Hotfix - KB973346
Windows 2000 Hotfix - KB973354
Windows 2000 Hotfix - KB973507
Windows 2000 Hotfix - KB973525
Windows 2000 Hotfix - KB973869
Windows 2000 Hotfix - KB973904
Windows 2000 Hotfix - KB974318
Windows 2000 Hotfix - KB974392
Windows 2000 Hotfix - KB974455
Windows 2000 Hotfix - KB974571
Windows 2000 Hotfix - KB976325
Windows 2000 Hotfix - KB976749
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Media Player 9 Hotfix [See KB885492 for more information]
Windows Media Player Hotfix [See Q828026 for more information]
Windows Media Player system update (9 Series)
Winferno Registry Power Cleaner
WinZip
Yahoo! extras
Yahoo! Internet Mail
Yahoo! Software Update
Yahoo! Toolbar
==== End Of File ===========================
================================================================================
==================================================
IObit logs…
Logfile of IObit HijackScan v1.0.0.0
Scan saved at 17:39:53, on 2009-12-30
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\WINNT\system32\lxctcoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINNT\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\IObit\IObit Security 360\is360.exe
C:\Program Files\IObit\IObit Security 360\IS360tray.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\IObit\IObit Security 360\a_hijackscan.exe
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Unknown - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [ctfmon.exe] ctfmon.exe
O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [blinkxgate] C:\Program Files\Blinkx\blinkx.exe -gate30
O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU|\Software\Microsoft\Windows\CurrentVersion\Run\: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM|\Software\Microsoft\Windows\CurrentVersion\Run\: [IObit Security 360] "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
O9 - Extra button: PC Confidential - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe
O9 - Extra button: PC Confidential - {925DAB62-F9AC-4221-806A-057BFB1014AA} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe
O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE}SPRT.SmartAccessCtl.1 - https://install.charter.com/diskless/bin/ssctlsma.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}SWCtl.SWCtl.10.1.1 - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB}YInstHelper.YInstStarter.1 - https://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1}soex.SonyOnlineInstallerXctl.1 - http://www.freerealms.com/gamedata/FreeRealmsInstaller.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}SoftwareDistribution.WebControl.1 - http://www.update.microsoft.com/microsoftu…b?1188250047702
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}SoftwareDistribution.MicrosoftUpdateWebControl.1 - http://www.update.microsoft.com/microsoftu…b?1188250030868
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}Java Plug-in 1.6.0_05 - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A}MySpace.Uploader.5.1 - http://lads.myspace.com/upload/MySpaceUploader2.cab
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}Java Plug-in 1.6.0_03 - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}Java Plug-in 1.6.0_05 - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}Java Plug-in 1.6.0_05 - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}PopCapLoader.PopCapLoaderCtrl2.1 - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: GhostStartService (GhostStartService) - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn (LogMeIn) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: lxct_device (lxct_device) - - C:\WINNT\system32\lxctcoms.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 (Pml Driver HPZ12) - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Speed Disk service (Speed Disk service) - Symantec Corporation - C:\Program Files\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
O23 - Service: IS360service (IS360service) - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe
================================================================================
===================================================
IObit Security 360
OS:Windows 2000
Version:1.3.0.10
Define Version:1302
Time Elapsed:00:09:29
Objects Scanned:47076
Threats Found:52
|Name|Type|Description|ID|
Spyware.Marketscore, Folder, C:\Program Files\RelevantKnowledge, 3-328
Spyware.Marketscore, File, C:\Program Files\RelevantKnowledge\rlvknlg.exe, 3-328
Spyware.Marketscore, File, C:\Program Files\RelevantKnowledge\rloci.bin, 3-328
Spyware.Marketscore, File, C:\Program Files\RelevantKnowledge\rlls.dll, 3-328
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1853
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1848
Tracking Cookies, Cookies, Cookie:[removed]/smt2/, 7-1522
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1853
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1699
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2184
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1545
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1535
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1655
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1873
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1813
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1567
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1698
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1698
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1776
Tracking Cookies, Cookies, Cookie:[removed]/, 7-14
Tracking Cookies, Cookies, Cookie:[removed]/, 7-7
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1813
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2225
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1656
Tracking Cookies, Cookies, Cookie:[removed]/, 7-19
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1853
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1573
Tracking Cookies, Cookies, Cookie:[removed]/, 7-9
Tracking Cookies, Cookies, Cookie:[removed]/, 7-55
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1559
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1886
Tracking Cookies, Cookies, Cookie:[removed]/, 7-9
Tracking Cookies, Cookies, Cookie:[removed]/pagead/imgclick/8mtTql4IO-NgzNk_g31S/newsletter_20090901, 7-1856
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1892
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1853
Tracking Cookies, Cookies, Cookie:[removed]/, 7-12
Tracking Cookies, Cookies, Cookie:[removed]/, 7-9
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2180
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2170
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1691
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2222
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1746
Tracking Cookies, Cookies, Cookie:[removed]/pagead/, 7-1856
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2184
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2073
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2048
Tracking Cookies, Cookies, Cookie:[removed]/pagead/, 7-1856
Tracking Cookies, Cookies, Cookie:[removed]/, 7-45
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1823
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1574
Adware.PopCap, Registry Key, HKEY_CLASSES_ROOT\PopCapLoader.PopCapLoaderCtrl2, 4-19290
Adware.PopCap, Registry Key, HKEY_CLASSES_ROOT\PopCapLoader.PopCapLoaderCtrl2.1, 4-19290
================================================================================
===================================================
IObit Security 360
OS:Windows 2000
Version:1.3.0.10
Define Version:1302
Time Elapsed:00:45:11
Objects Scanned:60854
Threats Found:19
|Name|Type|Description|ID|
Spyware.Marketscore, Folder, C:\Program Files\RelevantKnowledge, 3-328
Spyware.Marketscore, File, C:\Program Files\RelevantKnowledge\rlls.dll, 3-328
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1908
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2231
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2027
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1646
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2171
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2178
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2171
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1853
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1718
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1853
Tracking Cookies, Cookies, Cookie:[removed]/adlytics, 7-1656
Tracking Cookies, Cookies, Cookie:[removed]/, 7-9
Tracking Cookies, Cookies, Cookie:[removed]/, 7-2052
Tracking Cookies, Cookies, Cookie:[removed]/, 7-1664
Adware.MyWeb, File, C:\My Documents\Downloads\IWONSetup2.3.50.49.ZLfox000.exe, 8-55
Injector.UD, File, C:\backup\LAUR_BAK\Program Files\Adaptec\Shared\Web-Checkup\uninst.exe, 11-2214
Injector.UD, File, C:\backup\KATR_BAK\Program Files\Adaptec\Shared\Web-Checkup\uninst.exe, 11-2214