This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Command Service Problem

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please assist, upon running spybot I have Command Service that I cant get rid of. I continually now get pop ups, my home page changes automaticaly. Any assistance would be greatly appreciated. Log as follows


Logfile of HijackThis v1.99.1
Scan saved at 6:36:55 PM, on 22/06/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\dryqbmqzls.exe
C:\WINDOWS\pop06ap2.exe
C:\dfndra.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\a2F5\command.exe
C:\DOCUME~1\ADMINI~1\MYDOCU~1\ICROSO~1.NET\attrib.exe
C:\WINDOWS\system32\PPATCH~1\NPDB~1.EXE
C:\PROGRA~1\COMMON~1\fizi\fizim.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\windows\system32\spool\printers\FireDaemon.exe
C:\windows\system32\spool\printers\FireDaemon.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearch.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\spool\PRINTERS\dll32.exe
c:\windows\system32\spool\printers\events.exe
C:\PROGRA~1\COMMON~1\fizi\fizia.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Windows NT\whypertrm.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearchIndexer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearchFilter.exe
C:\Documents and Settings\Administrator\My Documents\My Pictures\Athletics\hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\vhfcg.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,gdmgqvi.exe
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\System32\pmnnomn.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - (no file)
O3 - Toolbar: ninemsn Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-au\msntb.dll
O3 - Toolbar: ToolBar888 - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\Program Files\ToolBar888\MyToolBar.dll
O3 - Toolbar: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Bin\AudioRack.exe /MixerStartup
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Recylinder Check] dryqbmqzls.exe
O4 - HKLM\..\Run: [pop06ap] C:\WINDOWS\pop06ap2.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrd.exe
O4 - HKLM\..\Run: [defender] C:\\dfndra.exe
O4 - HKLM\..\Run: [newname] C:\\nwnm.exe
O4 - HKLM\..\RunServices: [Windows Recylinder Check] dryqbmqzls.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Prcn] "C:\DOCUME~1\ADMINI~1\MYDOCU~1\ICROSO~1.NET\attrib.exe" -vt ndrv
O4 - HKCU\..\Run: [Mawtt] C:\WINDOWS\system32\PPATCH~1\NPDB~1.EXE
O4 - HKCU\..\Run: [fizi] C:\PROGRA~1\COMMON~1\fizi\fizim.exe
O4 - Startup: Event Reminder.lnk = C:\pmw\PMREMIND.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearch.exe
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &ninemsn Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-au\msntb.dll/search.htm
O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-au\msntabres.dll/229?ce103b183eab4e149fabe3e5765b86d
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-au\msntabres.dll/230?ce103b183eab4e149fabe3e5765b86d
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: NVDESK32.DLL C:\WINDOWS\System32\dvdplay.dll C:\WINDOWS\System32\regsvr32.dll
O20 - Winlogon Notify: pmnnomn - C:\WINDOWS\SYSTEM32\pmnnomn.dll
O20 - Winlogon Notify: ShellCompatibility - C:\WINDOWS\system32\hrpm0571e.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\a2F5\command.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: FireDaemon Service: dll32 (dll32) - Sublime Solutions Pty Ltd - C:\windows\system32\spool\printers\FireDaemon.exe
O23 - Service: FireDaemon Service: events (events) - Sublime Solutions Pty Ltd - C:\windows\system32\spool\printers\FireDaemon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hello ginkara, and welcome to TomCoyote forums. I'm dak, and I'll be helping you to fix your computer. I'm sorry for the delay in replying to your log. If you still require assistance, please make a new HijackThis log and post it as a reply to this thread. Please could you also go to the 'open misc tools' section of HijackThis, click 'open uninstall manager', and then click 'save list'. post the contents of 'uninstall_log.txt' up with your new HijackThis log, please.
Hi Dak,

Thanks so much for your time, its really appreciated, new Hijak This Log

Logfile of HijackThis v1.99.1
Scan saved at 5:39:46 PM, on 3/07/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\pop06ap2.exe
C:\dfndrb_3.exe
C:\WINDOWS\System32\ctfmon.exe
C:\DOCUME~1\ADMINI~1\MYDOCU~1\ICROSO~1.NET\attrib.exe
C:\WINDOWS\system32\PPATCH~1\NPDB~1.EXE
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearch.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearchIndexer.exe
C:\WINDOWS\a2F5\command.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\windows\system32\spool\printers\FireDaemon.exe
C:\windows\system32\spool\printers\FireDaemon.exe
C:\WINDOWS\system32\spool\PRINTERS\dll32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
c:\windows\system32\spool\printers\events.exe
C:\Program Files\Network Monitor\netmon.exe
C:\Program Files\Windows\wWinUpdate.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Administrator\My Documents\My Pictures\Athletics\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\vhfcg.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,gdmgqvi.exe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - (no file)
O3 - Toolbar: ninemsn Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-au\msntb.dll
O3 - Toolbar: (no name) - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - (no file)
O3 - Toolbar: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Bin\AudioRack.exe /MixerStartup
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Recylinder Check] dryqbmqzls.exe
O4 - HKLM\..\Run: [pop06ap] C:\WINDOWS\pop06ap2.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdb_3.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrb_3.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmb_3.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\RunServices: [Windows Recylinder Check] dryqbmqzls.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Prcn] "C:\DOCUME~1\ADMINI~1\MYDOCU~1\ICROSO~1.NET\attrib.exe" -vt ndrv
O4 - HKCU\..\Run: [Mawtt] C:\WINDOWS\system32\PPATCH~1\NPDB~1.EXE
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: Event Reminder.lnk = C:\pmw\PMREMIND.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: jjih.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearch.exe
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &ninemsn Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-au\msntb.dll/search.htm
O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-au\msntabres.dll/229?ce103b183eab4e149fabe3e5765b86d
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-au\msntabres.dll/230?ce103b183eab4e149fabe3e5765b86d
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: repairs303169590.dll,dvdplay.dll
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\f6l0lg3m16.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\a2F5\command.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: FireDaemon Service: dll32 (dll32) - Sublime Solutions Pty Ltd - C:\windows\system32\spool\printers\FireDaemon.exe
O23 - Service: FireDaemon Service: events (events) - Sublime Solutions Pty Ltd - C:\windows\system32\spool\printers\FireDaemon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

The uninstall Log
Adobe Acrobat 5.0
Adobe Download Manager 2.0 (Remove Only)
Adobe Reader 7.0
Ahead Nero Burning ROM
ArcSoft PhotoImpression
ATI Display Driver
Avance AC'97 Drivers and Applications
Canon CanoScan Toolbox 4.5
Command
Cowabanga by OIN
Digital Camera
Drug Lord 2
DVDXCopy Xpress 2.5.0
Enable S3 for USB Device
HijackThis 1.99.1
HP Memories Disc
HP Software Update
iMesh 6
iPod for Windows 2005-09-23
iTunes
Java 2 Runtime Environment, SE v1.4.2
Kazaa 3.0
LiveReg (Symantec Corporation)
LiveUpdate 2.6 (Symantec Corporation)
Macromedia Flash Player 8
Macromedia Shockwave Player
Microsoft Age of Empires
Microsoft DirectX Transform optional components
Microsoft Office FrontPage 2003
Microsoft Office Professional Edition 2003
Microsoft XML Parser and SDK
MP3 Player Utilities
MSN Messenger 7.5
Multimedia Combo Set Driver
Need2Find Bar
Network Monitor
ninemsn Search Toolbar
Norton AntiVirus 2003 Professional Edition
Norton WMI Update
NVIDIA Display Driver
NVIDIA nForce Drivers
NVIDIA Windows 2000/XP Display Drivers
PCI Audio Applications
Photosmart 140,240,7200,7600,7700,7900 Series
PowerDVD
PrintMaster Gold 4.00
QuickTime
Realtek AC'97 Audio
RollerCoaster Tycoon® 3
Shareaza version 2.1.0.0
Snowball Wars by OIN
Sony Ericsson File Manager
Sony Ericsson Image Editor
Sony Ericsson MMS Home Studio
Sony Ericsson Mobile Networking Wizard
Sony Ericsson Sound Editor
Sony Ericsson Sync Station
Sound Blaster Live!
Spybot - Search & Destroy 1.4
Surf SideKick
ToolBar888
Trainz
Turbo Lister
Ulead DVD MovieFactory 2.5 SE
Ulead Photo Express 3.0 SE
Ulead VideoStudio 7 SE DVD
WinAce Archiver
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB823559
Windows XP Hotfix - KB828741
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB842773
Windows XP Hotfix (SP1) [See Q329048 for more information]
Windows XP Hotfix (SP1) [See Q329390 for more information]
Windows XP Hotfix (SP1) [See Q329441 for more information]
Windows XP Hotfix (SP1) [See Q329834 for more information]
Windows XP Hotfix (SP1) Q329170
Windows XP Hotfix (SP1) Q810577
Windows XP Hotfix (SP1) Q810833
Windows XP Hotfix (SP1) Q817606
Windows XP Hotfix (SP2) [See Q329115 for more information]
www.find.fm Toolbar
Zoo Tycoon: Complete Collection
Phew! that's quite alot of nasty malware.

Lets shift look2me first:

Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so! This Fix must NOT be run in safe mode for it to work.

if you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application.."…then please use option 5 or the web page link in the l2mfix folder to solve this error condition. do not run the fix portion without fixing this first.

Could you also do the following please:

Go to http://virusscan.jotti.org/ and upload the following files, one at a time, for analysis.

After uploading, click the 'submit' button, wait for the results to come through, and then copy/paste each result (all of it from file: to VBA32 please) into a notepad document for inclusion in your next reply.

the files to upload are:

dryqbmqzls.exe

C:\WINDOWS\system32\spool\PRINTERS\dll32.exe

c:\windows\system32\spool\printers\events.exe

C:\dfndrb_3.exe
(this has probably changed name by now… it's going to be something like 'dfndr*.exe', 'kybrd*.exe', or 'nwnm*.exe', where * is a few random charectors)

Could you also tell me wether you recognise the Multimedia Combo Set as something that you have installed (looks like its for wireless mouse/keyboard), and wether you have intentionally installed a program called 'firedaemon'.

So, in your next reply, if i could have the jotti scans, the L2mfix scan, and the answres to the last two questions please :)
Dak, Scans as requested, When using Jotti you mentioned that it may have changed its name, I have found dfndrb_3.exe, I also found the other names you mentioned like 'dfndr*.exe', 'kybrd*.exe', or 'nwnm*.exe', infact most of these had 3 or 4 with a different number proceeding it. If you want me to scan all let me know I cant locate dryqbmqzls.exe to scan, I used search & cant locate. The two questions you had, the Multimedia Combo Set is my wireless mouse & keyboard & I havent intentionally installed a program called 'firedaemon' Thanks Again No errors when running option 1 in Lm2fix L2MFIX find log 051206 These are the registry keys present ********************************************************************************** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent] "DLLName"="Ati2evxx.dll" "Asynchronous"=dword:00000000 "Impersonate"=dword:00000001 "Lock"="AtiLockEvent" "Logoff"="AtiLogoffEvent" "Logon"="AtiLogonEvent" "Disconnect"="AtiDisConnectEvent" "Reconnect"="AtiReConnectEvent" "Safe"=dword:00000000 "Shutdown"="AtiShutdownEvent" "StartScreenSaver"="AtiStartScreenSaverEvent" "StartShell"="AtiStartShellEvent" "Startup"="AtiStartupEvent" "StopScreenSaver"="AtiStopScreenSaverEvent" "Unlock"="AtiUnLockEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellCompatibility] "Asynchronous"=dword:00000000 "DllName"="C:\\WINDOWS\\system32\\e020lafm1d2a.dll" "Impersonate"=dword:00000000 "Logon"="WinLogon" "Logoff"="WinLogoff" "Shutdown"="WinShutdown" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 ********************************************************************************** useragent: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{18AD86D6-058C-4E11-9A88-EDFAF6116055}"="" ********************************************************************************** Shell Extension key: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] "{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet" "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management" "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page" "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page" "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing" "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension" "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension" "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension" "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension" "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page" "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page" "{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler" "{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension" "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects" "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management" "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management" "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression" "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension" "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI" "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu" "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase" "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext" "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts" "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile" "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page" "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing" "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension" "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension" "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension" "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections" "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections" "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras" "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras" "{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras" "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras" "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras" "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension" "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension" "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host" "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link" "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler" "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension" "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks" "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu" "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search" "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run…" "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet" "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail" "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts" "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools" "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler" "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler" "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler" "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler" "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler" "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor" "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar" "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status" "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder" "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2" "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy" "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand" "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band" "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band" "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search" "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search" "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility" "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address" "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox" "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete" "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor" "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List" "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List" "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible" "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar" "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser" "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List" "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List" "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container" "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu" "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp" "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar" "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite" "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist" "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings" "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band" "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service" "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer" "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture" "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut" "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service" "{FF393560-C2A7-11CF-BFF4-444553540000}"="History" "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook" "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen" "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook" "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC" "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC" "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet" "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space" "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band" "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder" "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck" "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr" "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder" "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler" "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent" "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent" "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent" "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent" "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent" "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler" "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager" "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator" "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher" "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs" "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory" "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor" "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)" "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor" "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler" "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard" "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web" "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object" "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard" "{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts" "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler" "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target" "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File" "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut" "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object" "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu" "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties" "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview" "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext" "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control" "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control" "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control" "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control" "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control" "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI" "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object" "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find" "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find" "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI" "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs" "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook" "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target" "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties" "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu" "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options" "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder" "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler" "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell" "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%" "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler" "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer" "{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People…" "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler" "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler" "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler" "{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer" "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu" "{A5110426-177D-4e08-AB3F-785F10B4439C}"="My Phones" "{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b5 (beta test) Context Menu Shell Extension" "{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b5 (beta test) DragDrop Shell Extension" "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b5 (beta test) Context Menu Shell Extension" "{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b5 (beta test) Property Sheet Shell Extension" "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices" "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu" "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders" "{00020D75-0000-0000-C000-000000000046}"="Microsoft Office Outlook Desktop Icon Handler" "{0006F045-0000-0000-C000-000000000046}"="Microsoft Office Outlook Custom Icon Handler" "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler" "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes" "{13E7F612-F261-4391-BEA2-39DF4F3FA311}"="Windows Desktop Search" "{97090E2F-3062-4459-855B-014F0D3CDBB1}"="MSN Deskbar" "{B5802301-E6C6-44A1-ADDE-60B790560B0A}"="" "{7E99C732-F644-4421-BEC7-F86823E61425}"="" "{CC940205-6939-449D-A5CA-82CA3B961FC7}"="" "{1B0601CA-C4EA-4678-8777-48839584299F}"="" "{7792EB31-F77F-4AFA-90F2-B666012D9FA9}"="" "{E961CBA7-1C90-46C2-853A-1219EDD17C9D}"="" "{740A6973-7C10-4AAD-A9B3-D30ABDF2F55C}"="" "{CF4043D4-D8F8-42E1-ADB0-D450AC39FE7F}"="" "{CBA93638-4ED6-4BA1-B0F7-C18967BD4A2A}"="" "{302A7840-49E9-4196-8E72-21138EE2C03E}"="" "{170303AD-3CD4-44F2-BA23-31803DC3C45A}"="" "{360838BE-D929-404E-84AC-3F1D42D77CFC}"="" "{FF4A544A-294D-4641-B362-B0C1D54402D2}"="" "{7BE1AA6A-F0DC-46F8-A552-04DB698B1C5B}"="" "{4D8AA325-F044-43C8-8F56-0EBA201988E1}"="" "{56C7EB90-90FF-4E16-BA17-DF8B61524E28}"="" "{A5A958DE-5B42-4673-9D13-D2B522C90A85}"="" "{192BEB9C-CDAA-4873-AD81-03A17AE2C4D3}"="" "{D4F1AA13-9CAA-4F56-BA3A-7D032B239913}"="" "{CC6DE179-8510-48C3-A8DA-C99D38C8B645}"="" "{7165CE3E-547C-4814-8458-4CFECF818237}"="" "{86629FF8-CCCA-4C0D-8A92-9A379EDF31B6}"="" "{961AEC1D-B9B2-4B1E-BA71-65404F0A4907}"="" "{8AE95517-BB4E-4881-8885-6A2250F54ED2}"="" "{E700A8B2-72FA-4C6D-9129-A4EEB59ECBC5}"="" "{C709AE8A-B412-4C7F-A7FE-5A6A20EA1A2D}"="" "{CB0C100B-23DF-4F26-BAA7-38E45222574A}"="" "{818D0681-2565-4377-ADCC-A711D710362F}"="" "{70285259-280F-41C6-804A-0B833CCCD5C0}"="" "{D516454F-2B48-4351-82CD-1C53E8974D76}"="" "{698E56EA-E028-40F2-8D59-AB265E74C5D6}"="" "{3E0B4258-6B37-435F-85F6-25A74B31E709}"="" "{11CA054F-CD01-4EBB-984F-2AD5B3ABC26B}"="" "{BC3407C1-C896-4346-9631-700548857874}"="" "{9128EBDC-B07B-4032-AA1E-A5A92B83FB74}"="" "{AF0F3C99-368B-4CD9-A100-08D5BAB0364B}"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D426CFD0-87FC-4906-98D9-A23F5D515D61}] @="MSN Desktop Search Outlook Express ISearchFolder Class" ********************************************************************************** HKEY ROOT CLASSIDS: Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{B5802301-E6C6-44A1-ADDE-60B790560B0A}] @="" "IDEx"="ADDR" [HKEY_CLASSES_ROOT\CLSID\{B5802301-E6C6-44A1-ADDE-60B790560B0A}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{B5802301-E6C6-44A1-ADDE-60B790560B0A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{B5802301-E6C6-44A1-ADDE-60B790560B0A}\InprocServer32] @="C:\\WINDOWS\\system32\\wLvemsp.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{7E99C732-F644-4421-BEC7-F86823E61425}] @="" [HKEY_CLASSES_ROOT\CLSID\{7E99C732-F644-4421-BEC7-F86823E61425}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{7E99C732-F644-4421-BEC7-F86823E61425}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{7E99C732-F644-4421-BEC7-F86823E61425}\InprocServer32] @="C:\\WINDOWS\\system32\\nawmsdrm.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{CC940205-6939-449D-A5CA-82CA3B961FC7}] @="" [HKEY_CLASSES_ROOT\CLSID\{CC940205-6939-449D-A5CA-82CA3B961FC7}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{CC940205-6939-449D-A5CA-82CA3B961FC7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{CC940205-6939-449D-A5CA-82CA3B961FC7}\InprocServer32] @="C:\\WINDOWS\\system32\\oztext32.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{1B0601CA-C4EA-4678-8777-48839584299F}] @="" [HKEY_CLASSES_ROOT\CLSID\{1B0601CA-C4EA-4678-8777-48839584299F}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{1B0601CA-C4EA-4678-8777-48839584299F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{1B0601CA-C4EA-4678-8777-48839584299F}\InprocServer32] @="C:\\WINDOWS\\system32\\MEGAOUT.DLL" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{7792EB31-F77F-4AFA-90F2-B666012D9FA9}] @="" [HKEY_CLASSES_ROOT\CLSID\{7792EB31-F77F-4AFA-90F2-B666012D9FA9}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{7792EB31-F77F-4AFA-90F2-B666012D9FA9}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{7792EB31-F77F-4AFA-90F2-B666012D9FA9}\InprocServer32] @="C:\\WINDOWS\\system32\\lpcmgr10.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{E961CBA7-1C90-46C2-853A-1219EDD17C9D}] @="" [HKEY_CLASSES_ROOT\CLSID\{E961CBA7-1C90-46C2-853A-1219EDD17C9D}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{E961CBA7-1C90-46C2-853A-1219EDD17C9D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{E961CBA7-1C90-46C2-853A-1219EDD17C9D}\InprocServer32] @="C:\\WINDOWS\\system32\\mkxml4.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{740A6973-7C10-4AAD-A9B3-D30ABDF2F55C}] @="" [HKEY_CLASSES_ROOT\CLSID\{740A6973-7C10-4AAD-A9B3-D30ABDF2F55C}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{740A6973-7C10-4AAD-A9B3-D30ABDF2F55C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{740A6973-7C10-4AAD-A9B3-D30ABDF2F55C}\InprocServer32] @="C:\\WINDOWS\\system32\\mvrepl40.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{CF4043D4-D8F8-42E1-ADB0-D450AC39FE7F}] @="" [HKEY_CLASSES_ROOT\CLSID\{CF4043D4-D8F8-42E1-ADB0-D450AC39FE7F}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{CF4043D4-D8F8-42E1-ADB0-D450AC39FE7F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{CF4043D4-D8F8-42E1-ADB0-D450AC39FE7F}\InprocServer32] @="C:\\WINDOWS\\system32\\pkchdprf.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{CBA93638-4ED6-4BA1-B0F7-C18967BD4A2A}] @="" [HKEY_CLASSES_ROOT\CLSID\{CBA93638-4ED6-4BA1-B0F7-C18967BD4A2A}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{CBA93638-4ED6-4BA1-B0F7-C18967BD4A2A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{CBA93638-4ED6-4BA1-B0F7-C18967BD4A2A}\InprocServer32] @="C:\\WINDOWS\\system32\\CTQL1208.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{302A7840-49E9-4196-8E72-21138EE2C03E}] @="" [HKEY_CLASSES_ROOT\CLSID\{302A7840-49E9-4196-8E72-21138EE2C03E}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{302A7840-49E9-4196-8E72-21138EE2C03E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{302A7840-49E9-4196-8E72-21138EE2C03E}\InprocServer32] @="C:\\WINDOWS\\system32\\mgtime.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{170303AD-3CD4-44F2-BA23-31803DC3C45A}] @="" [HKEY_CLASSES_ROOT\CLSID\{170303AD-3CD4-44F2-BA23-31803DC3C45A}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{170303AD-3CD4-44F2-BA23-31803DC3C45A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{170303AD-3CD4-44F2-BA23-31803DC3C45A}\InprocServer32] @="C:\\WINDOWS\\system32\\sllsrv32.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{360838BE-D929-404E-84AC-3F1D42D77CFC}] @="" [HKEY_CLASSES_ROOT\CLSID\{360838BE-D929-404E-84AC-3F1D42D77CFC}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{360838BE-D929-404E-84AC-3F1D42D77CFC}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{360838BE-D929-404E-84AC-3F1D42D77CFC}\InprocServer32] @="C:\\WINDOWS\\system32\\mowebdvd.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{FF4A544A-294D-4641-B362-B0C1D54402D2}] @="" [HKEY_CLASSES_ROOT\CLSID\{FF4A544A-294D-4641-B362-B0C1D54402D2}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{FF4A544A-294D-4641-B362-B0C1D54402D2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{FF4A544A-294D-4641-B362-B0C1D54402D2}\InprocServer32] @="C:\\WINDOWS\\system32\\tkpmon.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{7BE1AA6A-F0DC-46F8-A552-04DB698B1C5B}] @="" [HKEY_CLASSES_ROOT\CLSID\{7BE1AA6A-F0DC-46F8-A552-04DB698B1C5B}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{7BE1AA6A-F0DC-46F8-A552-04DB698B1C5B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{7BE1AA6A-F0DC-46F8-A552-04DB698B1C5B}\InprocServer32] @="C:\\WINDOWS\\system32\\mwgentr.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{4D8AA325-F044-43C8-8F56-0EBA201988E1}] @="" [HKEY_CLASSES_ROOT\CLSID\{4D8AA325-F044-43C8-8F56-0EBA201988E1}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{4D8AA325-F044-43C8-8F56-0EBA201988E1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{4D8AA325-F044-43C8-8F56-0EBA201988E1}\InprocServer32] @="C:\\WINDOWS\\system32\\nqprovau.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{56C7EB90-90FF-4E16-BA17-DF8B61524E28}] @="" [HKEY_CLASSES_ROOT\CLSID\{56C7EB90-90FF-4E16-BA17-DF8B61524E28}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{56C7EB90-90FF-4E16-BA17-DF8B61524E28}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{56C7EB90-90FF-4E16-BA17-DF8B61524E28}\InprocServer32] @="C:\\WINDOWS\\system32\\wzstream.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{A5A958DE-5B42-4673-9D13-D2B522C90A85}] @="" [HKEY_CLASSES_ROOT\CLSID\{A5A958DE-5B42-4673-9D13-D2B522C90A85}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{A5A958DE-5B42-4673-9D13-D2B522C90A85}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{A5A958DE-5B42-4673-9D13-D2B522C90A85}\InprocServer32] @="C:\\WINDOWS\\system32\\mloert2.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{192BEB9C-CDAA-4873-AD81-03A17AE2C4D3}] @="" [HKEY_CLASSES_ROOT\CLSID\{192BEB9C-CDAA-4873-AD81-03A17AE2C4D3}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{192BEB9C-CDAA-4873-AD81-03A17AE2C4D3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{192BEB9C-CDAA-4873-AD81-03A17AE2C4D3}\InprocServer32] @="C:\\WINDOWS\\system32\\MuPMSP.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{D4F1AA13-9CAA-4F56-BA3A-7D032B239913}] @="" [HKEY_CLASSES_ROOT\CLSID\{D4F1AA13-9CAA-4F56-BA3A-7D032B239913}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{D4F1AA13-9CAA-4F56-BA3A-7D032B239913}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{D4F1AA13-9CAA-4F56-BA3A-7D032B239913}\InprocServer32] @="C:\\WINDOWS\\system32\\czmmdlg.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{CC6DE179-8510-48C3-A8DA-C99D38C8B645}] @="" [HKEY_CLASSES_ROOT\CLSID\{CC6DE179-8510-48C3-A8DA-C99D38C8B645}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{CC6DE179-8510-48C3-A8DA-C99D38C8B645}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{CC6DE179-8510-48C3-A8DA-C99D38C8B645}\InprocServer32] @="C:\\WINDOWS\\system32\\tQpiperf.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{7165CE3E-547C-4814-8458-4CFECF818237}] @="" [HKEY_CLASSES_ROOT\CLSID\{7165CE3E-547C-4814-8458-4CFECF818237}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{7165CE3E-547C-4814-8458-4CFECF818237}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{7165CE3E-547C-4814-8458-4CFECF818237}\InprocServer32] @="C:\\WINDOWS\\system32\\ptofmap.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{86629FF8-CCCA-4C0D-8A92-9A379EDF31B6}] @="" [HKEY_CLASSES_ROOT\CLSID\{86629FF8-CCCA-4C0D-8A92-9A379EDF31B6}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{86629FF8-CCCA-4C0D-8A92-9A379EDF31B6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{86629FF8-CCCA-4C0D-8A92-9A379EDF31B6}\InprocServer32] @="C:\\WINDOWS\\system32\\ctyptdll.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{961AEC1D-B9B2-4B1E-BA71-65404F0A4907}] @="" [HKEY_CLASSES_ROOT\CLSID\{961AEC1D-B9B2-4B1E-BA71-65404F0A4907}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{961AEC1D-B9B2-4B1E-BA71-65404F0A4907}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{961AEC1D-B9B2-4B1E-BA71-65404F0A4907}\InprocServer32] @="C:\\WINDOWS\\system32\\wxiprop.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{8AE95517-BB4E-4881-8885-6A2250F54ED2}] @="" [HKEY_CLASSES_ROOT\CLSID\{8AE95517-BB4E-4881-8885-6A2250F54ED2}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{8AE95517-BB4E-4881-8885-6A2250F54ED2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{8AE95517-BB4E-4881-8885-6A2250F54ED2}\InprocServer32] @="C:\\WINDOWS\\system32\\awsldp.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{E700A8B2-72FA-4C6D-9129-A4EEB59ECBC5}] @="" "IDEx"="AD" [HKEY_CLASSES_ROOT\CLSID\{E700A8B2-72FA-4C6D-9129-A4EEB59ECBC5}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{E700A8B2-72FA-4C6D-9129-A4EEB59ECBC5}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{E700A8B2-72FA-4C6D-9129-A4EEB59ECBC5}\InprocServer32] @="C:\\WINDOWS\\system32\\kodit142.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{C709AE8A-B412-4C7F-A7FE-5A6A20EA1A2D}] @="" "IDEx"="AD" [HKEY_CLASSES_ROOT\CLSID\{C709AE8A-B412-4C7F-A7FE-5A6A20EA1A2D}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{C709AE8A-B412-4C7F-A7FE-5A6A20EA1A2D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{C709AE8A-B412-4C7F-A7FE-5A6A20EA1A2D}\InprocServer32] @="C:\\WINDOWS\\system32\\awiiiexx.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{CB0C100B-23DF-4F26-BAA7-38E45222574A}] @="" [HKEY_CLASSES_ROOT\CLSID\{CB0C100B-23DF-4F26-BAA7-38E45222574A}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{CB0C100B-23DF-4F26-BAA7-38E45222574A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{CB0C100B-23DF-4F26-BAA7-38E45222574A}\InprocServer32] @="C:\\WINDOWS\\system32\\mmtime.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{818D0681-2565-4377-ADCC-A711D710362F}] @="" [HKEY_CLASSES_ROOT\CLSID\{818D0681-2565-4377-ADCC-A711D710362F}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{818D0681-2565-4377-ADCC-A711D710362F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{818D0681-2565-4377-ADCC-A711D710362F}\InprocServer32] @="C:\\WINDOWS\\system32\\wxcsapi.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{70285259-280F-41C6-804A-0B833CCCD5C0}] @="" [HKEY_CLASSES_ROOT\CLSID\{70285259-280F-41C6-804A-0B833CCCD5C0}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{70285259-280F-41C6-804A-0B833CCCD5C0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{70285259-280F-41C6-804A-0B833CCCD5C0}\InprocServer32] @="C:\\WINDOWS\\system32\\okepro32.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{D516454F-2B48-4351-82CD-1C53E8974D76}] @="" [HKEY_CLASSES_ROOT\CLSID\{D516454F-2B48-4351-82CD-1C53E8974D76}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{D516454F-2B48-4351-82CD-1C53E8974D76}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{D516454F-2B48-4351-82CD-1C53E8974D76}\InprocServer32] @="C:\\WINDOWS\\system32\\wphtcpip.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{698E56EA-E028-40F2-8D59-AB265E74C5D6}] @="" "IDEx"="AD" [HKEY_CLASSES_ROOT\CLSID\{698E56EA-E028-40F2-8D59-AB265E74C5D6}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{698E56EA-E028-40F2-8D59-AB265E74C5D6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{698E56EA-E028-40F2-8D59-AB265E74C5D6}\InprocServer32] @="C:\\WINDOWS\\system32\\hfetcfg.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{3E0B4258-6B37-435F-85F6-25A74B31E709}] @="" [HKEY_CLASSES_ROOT\CLSID\{3E0B4258-6B37-435F-85F6-25A74B31E709}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{3E0B4258-6B37-435F-85F6-25A74B31E709}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{3E0B4258-6B37-435F-85F6-25A74B31E709}\InprocServer32] @="C:\\WINDOWS\\system32\\ssclient.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{11CA054F-CD01-4EBB-984F-2AD5B3ABC26B}] @="" [HKEY_CLASSES_ROOT\CLSID\{11CA054F-CD01-4EBB-984F-2AD5B3ABC26B}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{11CA054F-CD01-4EBB-984F-2AD5B3ABC26B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{11CA054F-CD01-4EBB-984F-2AD5B3ABC26B}\InprocServer32] @="C:\\WINDOWS\\system32\\rthx32.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{BC3407C1-C896-4346-9631-700548857874}] @="" [HKEY_CLASSES_ROOT\CLSID\{BC3407C1-C896-4346-9631-700548857874}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{BC3407C1-C896-4346-9631-700548857874}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{BC3407C1-C896-4346-9631-700548857874}\InprocServer32] @="C:\\WINDOWS\\system32\\dvnlobby.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{9128EBDC-B07B-4032-AA1E-A5A92B83FB74}] @="" [HKEY_CLASSES_ROOT\CLSID\{9128EBDC-B07B-4032-AA1E-A5A92B83FB74}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{9128EBDC-B07B-4032-AA1E-A5A92B83FB74}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{9128EBDC-B07B-4032-AA1E-A5A92B83FB74}\InprocServer32] @="C:\\WINDOWS\\system32\\kxdblr.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{AF0F3C99-368B-4CD9-A100-08D5BAB0364B}] @="" [HKEY_CLASSES_ROOT\CLSID\{AF0F3C99-368B-4CD9-A100-08D5BAB0364B}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{AF0F3C99-368B-4CD9-A100-08D5BAB0364B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{AF0F3C99-368B-4CD9-A100-08D5BAB0364B}\InprocServer32] @="C:\\WINDOWS\\system32\\nvlanui2.dll" "ThreadingModel"="Apartment" ********************************************************************************** Files Found are not all bad files: C:\WINDOWS\SYSTEM32\ atmtd.dll Mon 26 Jun 2006 7:07:48 A…. 687,592 671.48 K awiiiexx.dll Sun 2 Jul 2006 8:14:02 A…. 234,272 228.78 K awsldp.dll Sat 1 Jul 2006 11:58:40 ..S.R 233,985 228.50 K c6002g~1.dll Tue 27 Jun 2006 15:06:52 ..S.R 237,245 231.68 K ctql1208.dll Wed 21 Jun 2006 18:54:22 ..S.R 234,272 228.78 K ctyptdll.dll Tue 27 Jun 2006 7:09:04 ..S.R 234,108 228.62 K czmmdlg.dll Mon 26 Jun 2006 10:33:34 ..S.R 236,304 230.77 K dmonwv.dll Sat 17 Jun 2006 11:40:24 A…. 32,256 31.50 K dvdplay.dll Sat 17 Jun 2006 10:10:28 A…. 81,920 80.00 K dvnlobby.dll Tue 4 Jul 2006 8:01:36 ..S.R 235,004 229.50 K e020la~1.dll Tue 4 Jul 2006 8:01:40 ..S.R 235,241 229.73 K en68l1~1.dll Sat 1 Jul 2006 20:24:40 ..S.R 233,985 228.50 K f6l00g~1.dll Mon 3 Jul 2006 17:32:00 ..S.R 236,846 231.29 K h0j4la~1.dll Fri 23 Jun 2006 19:57:54 ..S.R 234,115 228.63 K h0n00a~1.dll Thu 22 Jun 2006 18:33:08 ….. 235,021 229.51 K hfetcfg.dll Mon 3 Jul 2006 13:56:26 A…. 234,272 228.78 K i0lola~1.dll Fri 23 Jun 2006 16:49:20 ..S.R 236,101 230.57 K i224lc~1.dll Mon 3 Jul 2006 14:45:28 ..S.R 236,911 231.36 K i660lg~1.dll Tue 20 Jun 2006 7:16:14 ..S.R 235,532 230.01 K i8nmli~1.dll Fri 23 Jun 2006 18:34:22 ..S.R 234,052 228.57 K irr8l5~1.dll Tue 27 Jun 2006 7:09:08 ..S.R 235,357 229.84 K j2n2lc~1.dll Tue 4 Jul 2006 17:56:02 ..S.R 235,414 229.89 K kodit142.dll Sun 2 Jul 2006 8:16:28 ..S.R 236,911 231.36 K kt2ul7~1.dll Tue 4 Jul 2006 17:21:40 ..S.R 236,885 231.33 K kxdblr.dll Tue 4 Jul 2006 16:09:40 ..S.R 236,885 231.33 K lfoxwyt.dll Sat 17 Jun 2006 11:40:26 A…. 51,712 50.50 K lpcmgr10.dll Wed 21 Jun 2006 6:56:54 ..S.R 234,272 228.78 K lvj209~1.dll Mon 3 Jul 2006 17:51:04 ..S.R 235,382 229.86 K m0ju0a~1.dll Thu 22 Jun 2006 21:09:24 ..S.R 234,932 229.43 K megaout.dll Tue 20 Jun 2006 23:11:42 ..S.R 236,793 231.24 K mgtime.dll Thu 22 Jun 2006 20:40:24 ..S.R 234,932 229.43 K mkxml4.dll Wed 21 Jun 2006 11:13:32 ..S.R 235,010 229.50 K mloert2.dll Sun 25 Jun 2006 7:49:06 ..S.R 234,108 228.62 K mmtime.dll Sun 2 Jul 2006 14:56:22 ..S.R 235,004 229.50 K mowebdvd.dll Fri 23 Jun 2006 14:22:16 ..S.R 236,304 230.77 K mupmsp.dll Mon 26 Jun 2006 7:05:40 ..S.R 234,108 228.62 K mvrepl40.dll Wed 21 Jun 2006 13:38:56 ..S.R 234,272 228.78 K mwgentr.dll Sat 24 Jun 2006 12:25:18 ..S.R 236,304 230.77 K nawmsdrm.dll Tue 20 Jun 2006 20:32:30 ..S.R 234,272 228.78 K nnaopsu.dll Thu 22 Jun 2006 20:39:22 A…. 73,216 71.50 K nqprovau.dll Sat 24 Jun 2006 16:34:16 ..S.R 234,108 228.62 K nvlanui2.dll Tue 4 Jul 2006 18:14:40 ..S.R 235,241 229.73 K okepro32.dll Sun 2 Jul 2006 20:54:08 ..S.R 235,004 229.50 K oztext32.dll Tue 20 Jun 2006 22:01:08 ..S.R 234,963 229.45 K p6p60g~1.dll Wed 21 Jun 2006 19:29:22 ..S.R 234,272 228.78 K pkchdprf.dll Wed 21 Jun 2006 14:52:22 ..S.R 235,010 229.50 K pmnnomn.dll Thu 22 Jun 2006 18:04:46 ..SH. 39,437 38.51 K ptofmap.dll Mon 26 Jun 2006 17:54:12 ..S.R 236,304 230.77 K regsvr32.dll Sat 17 Jun 2006 11:54:32 A…. 81,920 80.00 K repair~1.dll Mon 3 Jul 2006 13:56:44 A…. 96,768 94.50 K rthx32.dll Tue 4 Jul 2006 7:06:30 ..S.R 236,885 231.33 K scsvc.dll Sun 2 Jul 2006 8:12:24 ..S.R 236,911 231.36 K sllsrv32.dll Fri 23 Jun 2006 7:07:54 ..S.R 235,021 229.51 K sons.dll Wed 21 Jun 2006 18:30:48 ..S.R 235,010 229.50 K ssclient.dll Mon 3 Jul 2006 18:28:42 ..S.R 235,004 229.50 K tkpmon.dll Fri 23 Jun 2006 15:15:20 ..S.R 236,101 230.57 K tqpiperf.dll Mon 26 Jun 2006 13:32:30 ..S.R 234,108 228.62 K wphtcpip.dll Mon 3 Jul 2006 13:54:28 ..S.R 236,911 231.36 K wwlem.dll Thu 22 Jun 2006 20:39:22 A…. 12,288 12.00 K wxcsapi.dll Sun 2 Jul 2006 16:50:30 ..S.R 236,911 231.36 K wxiprop.dll Sat 1 Jul 2006 3:14:26 ..S.R 235,239 229.72 K wzstream.dll Sat 24 Jun 2006 17:12:02 ..S.R 236,304 230.77 K 62 items found: 62 files (51 H/S), 0 directories. Total of file sizes: 13,630,827 bytes 12.99 M Locate .tmp files: C:\WINDOWS\SYSTEM32\ guard.tmp Tue 4 Jul 2006 18:14:44 A…. 236,928 231.38 K 1 item found: 1 file, 0 directories. Total of file sizes: 236,928 bytes 231.38 K ********************************************************************************** Directory Listing of system files: Volume in drive C has no label. Volume Serial Number is 049D-F5FD Directory of C:\WINDOWS\System32 04/07/2006 06:14 PM 235,241 nvlanui2.dll 04/07/2006 05:56 PM 235,414 j2n2lc5o1f.dll 04/07/2006 05:21 PM 236,885 kt2ul7f91.dll 04/07/2006 04:09 PM 236,885 kxdblr.dll 04/07/2006 08:01 AM 235,241 e020lafm1d2a.dll 04/07/2006 08:01 AM 235,004 dvnlobby.dll 04/07/2006 07:06 AM 236,885 rthx32.dll 03/07/2006 06:28 PM 235,004 ssclient.dll 03/07/2006 05:51 PM 235,382 lvj2091oe.dll 03/07/2006 05:31 PM 236,846 f6l00g3me6.dll 03/07/2006 02:45 PM 236,911 i224lcfq1f2e.dll 03/07/2006 01:54 PM 236,911 wphtcpip.dll 02/07/2006 08:54 PM 235,004 okepro32.dll 02/07/2006 04:50 PM 236,911 wxcsapi.dll 02/07/2006 04:49 PM dllcache 02/07/2006 02:56 PM 235,004 mmtime.dll 02/07/2006 08:16 AM 236,911 kodit142.dll 02/07/2006 08:12 AM 236,911 scsvc.dll 01/07/2006 08:24 PM 233,985 en68l1ju1.dll 01/07/2006 11:58 AM 233,985 awsldp.dll 01/07/2006 03:14 AM 235,239 wxiprop.dll 27/06/2006 03:06 PM 237,245 c6002gdmg60a2.dll 27/06/2006 07:09 AM 235,357 irr8l59u1.dll 27/06/2006 07:09 AM 234,108 ctyptdll.dll 26/06/2006 05:54 PM 236,304 ptofmap.dll 26/06/2006 01:32 PM 234,108 tQpiperf.dll 26/06/2006 10:33 AM 236,304 czmmdlg.dll 26/06/2006 07:05 AM 234,108 MuPMSP.dll 25/06/2006 07:49 AM 234,108 mloert2.dll 24/06/2006 05:12 PM 236,304 wzstream.dll 24/06/2006 04:34 PM 234,108 nqprovau.dll 24/06/2006 12:25 PM 236,304 mwgentr.dll 23/06/2006 07:57 PM 234,115 h0j4la1q1d.dll 23/06/2006 06:34 PM 234,052 i8nmli5118.dll 23/06/2006 04:49 PM 236,101 i0lola331d.dll 23/06/2006 03:15 PM 236,101 tkpmon.dll 23/06/2006 02:22 PM 236,304 mowebdvd.dll 23/06/2006 07:07 AM 235,021 sllsrv32.dll 22/06/2006 09:09 PM 234,932 m0ju0a19ed.dll 22/06/2006 08:40 PM 234,932 mgtime.dll 22/06/2006 06:04 PM 39,437 pmnnomn.dll 21/06/2006 07:29 PM 234,272 p6p60g7se6.dll 21/06/2006 06:54 PM 234,272 CTQL1208.dll 21/06/2006 06:30 PM 235,010 sons.dll 21/06/2006 02:52 PM 235,010 pkchdprf.dll 21/06/2006 01:38 PM 234,272 mvrepl40.dll 21/06/2006 11:13 AM 235,010 mkxml4.dll 21/06/2006 06:56 AM 234,272 lpcmgr10.dll 20/06/2006 11:11 PM 236,793 MEGAOUT.DLL 20/06/2006 10:01 PM 234,963 oztext32.dll 20/06/2006 08:32 PM 234,272 nawmsdrm.dll 20/06/2006 07:16 AM 235,532 i660lgjm16oa.dll 26/05/2005 07:39 PM 32 {07BBBEB7-CAC7-4750-B8E7-2E49AD1CE69C}.dat 25/04/2005 03:13 PM Microsoft 52 File(s) 11,809,622 bytes 2 Dir(s) 39,677,476,864 bytes free File: dll32.exe Status: INFECTED/MALWARE MD5 c8109d1208b57d2a78dd74fbc04549c1 Packers detected: ASPACK, UPX Scanner results AntiVir Found Backdoor-Server/Iroffer.13b9.4 backdoor ArcaVir Found nothing Avast Found Win32:Iroffer-11 AVG Antivirus Found BackDoor.Generic2.XIT BitDefender Found Backdoor.Iroffer.13b9.C ClamAV Found nothing Dr.Web Found BackDoor.Iroffer.1252 F-Prot Antivirus Found Possibly a new variant of W32/Threat-HLLAU-based!Maximus Fortinet Found W32/Iroffer Kaspersky Anti-Virus Found Backdoor.Win32.Iroffer.13b9 NOD32 Found a variant of Win32/Iroffer Norman Virus Control Found nothing UNA Found nothing VirusBuster Found nothing VBA32 Found Backdoor.Win32.Iroffer.13b9 File: events.exe Status: INFECTED/MALWARE MD5 a08787f4ef0f54905b6f45ebb15f56f3 Packers detected: PE_PATCH, MEWBUNDLE, MEW Scanner results AntiVir Found Packer/MEW packer ArcaVir Found nothing Avast Found Win32:Servu-E AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing Dr.Web Found BackDoor.Servu.50011 F-Prot Antivirus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found not-a-virus:Server-FTP.Win32.Serv-U.50011 NOD32 Found nothing Norman Virus Control Found W32/Suspicious_M.gen UNA Found nothing VirusBuster Found nothing VBA32 Found nothing File: dfndrb_3.exe Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) MD5 3a19546a0a0fa6390396c483d94e2cd6 Packers detected: - Scanner results AntiVir Found Trojan/Dldr.VB.afv.3 ArcaVir Found Trojan.Downloader.Vb.Afv Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing Dr.Web Found Adware.DollarRevenue F-Prot Antivirus Found nothing Fortinet Found W32/DollarRevenue.AFV!tr.dldr Kaspersky Anti-Virus Found Trojan-Downloader.Win32.VB.afv NOD32 Found probably a variant of Win32/TrojanClicker.VB.LI (probable variant) Norman Virus Control Found nothing UNA Found nothing VirusBuster Found nothing VBA32 Found Trojan-Downloader.Win32.VB.afv

When using Jotti you mentioned that it may have changed its name, I have found dfndrb_3.exe, I also found the other names you mentioned like 'dfndr*.exe', 'kybrd*.exe', or 'nwnm*.exe', infact most of these had 3 or 4 with a different number proceeding it. If you want me to scan all let me know


Just the one will be ok, cheers.

———-

Please download the suspiciouse files packer.

Unzip the file packer, and copy/paste the following into the window:

C:\WINDOWS\system32\spool\PRINTERS\dll32.exe
c:\windows\system32\spool\printers\events.exe
C:\\kybrdb*.exe
C:\\dfndrb*.exe
C:\\nwnmb*.exe
C:\dryqbmqzls.exe
C:windows\dryqbmqzls.exe
C:\windows\system32\dryqbmqzls.exe


Then press 'next'.

If you could email the cab file that has been made on your desktop to [removed], along with a link to this thread, and the files should get passed on to anti-malware companies (as they look like newish malware).

next, Download AlcanShorty from here.

* Click the download button below and agree to download the fix.
* Download Alcanshorty to your desktop.
* DoubleClick alcanshorty_en.exe and click install
* This will create a new folder on your desktop called alcanshorty_en
* Open that folder and doubleclick Run.bat
* Once the fix starts, your icons and desktop will disappear, this is normal.

Make sure you have a working internet connection. In case your firewall gives an alert, don't block it, because alcanshorty needs to download some additional files to let the tool run properly.

* Wait for the complete script execution box to popup and press OK.
* Press exit to terminate the BFU program.

1. Download combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

When finished, it should produce a log, combofix.txt.

Reboot, make a new HijackThis log, and post it along with combofix.txt as a reply to this thread.

Cheers :)
Dak,

Copy of combofix & hijck This log

I must say pop ups have reduced already :D

Start Time= Wed 05/07/2006 20:17:34.74
Running from: C:\Documents and Settings\[removed]\Desktop

QuickScan did not find any signs of infected files

(((((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log )))))))))))))))))))))))))))))))))))))))))))))))))))))


HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wzcnotif


* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


REGISTRY ENTRIES REMOVED:

[HKEY_CLASSES_ROOT\clsid\{BCAC3B71-AD02-451B-A841-76E09090BA87}]
@=""

[HKEY_CLASSES_ROOT\clsid\{BCAC3B71-AD02-451B-A841-76E09090BA87}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{BCAC3B71-AD02-451B-A841-76E09090BA87}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{BCAC3B71-AD02-451B-A841-76E09090BA87}\InprocServer32]
@="C:\\WINDOWS\\system32\\rqr20.dll"
"ThreadingModel"="Apartment"

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


FILES REMOVED:

C:\WINDOWS\SYSTEM32\awiiiexx.dll
C:\WINDOWS\SYSTEM32\awsldp.dll
C:\WINDOWS\SYSTEM32\c6002gdmg60a2.dll
C:\WINDOWS\SYSTEM32\CTQL1208.dll
C:\WINDOWS\SYSTEM32\ctyptdll.dll
C:\WINDOWS\SYSTEM32\cuwmdm.dll
C:\WINDOWS\SYSTEM32\czmmdlg.dll
C:\WINDOWS\SYSTEM32\dvnlobby.dll
C:\WINDOWS\SYSTEM32\en68l1ju1.dll
C:\WINDOWS\SYSTEM32\f6l00g3me6.dll
C:\WINDOWS\SYSTEM32\h0j4la1q1d.dll
C:\WINDOWS\SYSTEM32\h0n00a5med.dll
C:\WINDOWS\SYSTEM32\hfetcfg.dll
C:\WINDOWS\SYSTEM32\i0lola331d.dll
C:\WINDOWS\SYSTEM32\i224lcfq1f2e.dll
C:\WINDOWS\SYSTEM32\i660lgjm16oa.dll
C:\WINDOWS\SYSTEM32\i8nmli5118.dll
C:\WINDOWS\SYSTEM32\irr8l59u1.dll
C:\WINDOWS\SYSTEM32\j80slid7180.dll
C:\WINDOWS\SYSTEM32\kodit142.dll
C:\WINDOWS\SYSTEM32\kt2ul7f91.dll
C:\WINDOWS\SYSTEM32\kxdblr.dll
C:\WINDOWS\SYSTEM32\lpcmgr10.dll
C:\WINDOWS\SYSTEM32\lvj2091oe.dll
C:\WINDOWS\SYSTEM32\m0ju0a19ed.dll
C:\WINDOWS\SYSTEM32\MEGAOUT.DLL
C:\WINDOWS\SYSTEM32\mgtime.dll
C:\WINDOWS\SYSTEM32\mkxml4.dll
C:\WINDOWS\SYSTEM32\mloert2.dll
C:\WINDOWS\SYSTEM32\mmtime.dll
C:\WINDOWS\SYSTEM32\mowebdvd.dll
C:\WINDOWS\SYSTEM32\MuPMSP.dll
C:\WINDOWS\SYSTEM32\mvrepl40.dll
C:\WINDOWS\SYSTEM32\mwgentr.dll
C:\WINDOWS\SYSTEM32\nawmsdrm.dll
C:\WINDOWS\SYSTEM32\nqprovau.dll
C:\WINDOWS\SYSTEM32\nvlanui2.dll
C:\WINDOWS\SYSTEM32\okepro32.dll
C:\WINDOWS\SYSTEM32\oztext32.dll
C:\WINDOWS\SYSTEM32\p0n8la5u1d.dll
C:\WINDOWS\SYSTEM32\p6p60g7se6.dll
C:\WINDOWS\SYSTEM32\pkchdprf.dll
C:\WINDOWS\SYSTEM32\ptofmap.dll
C:\WINDOWS\SYSTEM32\rqr20.dll
C:\WINDOWS\SYSTEM32\rthx32.dll
C:\WINDOWS\SYSTEM32\scsvc.dll
C:\WINDOWS\SYSTEM32\sllsrv32.dll
C:\WINDOWS\SYSTEM32\sons.dll
C:\WINDOWS\SYSTEM32\ssclient.dll
C:\WINDOWS\SYSTEM32\tkpmon.dll
C:\WINDOWS\SYSTEM32\tQpiperf.dll
C:\WINDOWS\SYSTEM32\wphtcpip.dll
C:\WINDOWS\SYSTEM32\wtserror.dll
C:\WINDOWS\SYSTEM32\wxcsapi.dll
C:\WINDOWS\SYSTEM32\wxiprop.dll
C:\WINDOWS\SYSTEM32\wzstream.dll


Granting sedebugprivilege to Administrators … successful


(((((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log ))))))))))))))))))))))))))))))))))))))))))))))))))))))

20:14:05.39

Qoologic uninstaller found and executed
Registry entries fixed


((((((((((((((((((((((((((((((((((((((((((((((((((( Ssk's Log ))))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\repairs303169590.dll
C:\Documents and Settings\Administrator\Application Data\Sskcwrd.dll
C:\Documents and Settings\Administrator\Application Data\Sskknwrd.dll
C:\Documents and Settings\Administrator\Application Data\Sskuknwrd.dll
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Ssk.log
C:\Program Files\SurfSideKick 3\Ssk.exe
C:\Program Files\SurfSideKick 3\SskBho.dll
C:\Program Files\SurfSideKick 3\SskCore.dll
C:\WINDOWS\system32\bk.exe


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



20:16:56.79
((((((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\Mendoza1.exe
C:\MTE3NDI6ODoxNgnew.exe
C:\warebundle2.exe
C:\warebundlenew.exe
C:\WINDOWS\MTE3NDI6ODoxNg.exe
C:\WINDOWS\warebundle.exe
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\Program Files\snowball wars
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\WINDOWS\a2F5


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-07-03 18:09:38 ( .D… ) "C:\Program Files\AvRack"
2006-07-03 13:55:44 30208 ( A…. ) "C:\SS1001new.exe"
2006-07-01 03:18:24 2 ( A…. ) "C:\WINDOWS\system32\wintsu.exe"
2006-06-30 21:11:54 ( .D… ) "C:\Program Files\FileZilla"
2006-06-30 08:39:26 ( .D… ) "C:\Program Files\Maxis"
2006-06-26 10:35:14 ( .D… ) "C:\Program Files\S?mantec"
2006-06-25 07:50:38 ( .D… ) "C:\Program Files\Common Files\?icrosoft.NET"
2006-06-22 20:39:28 123 ( A…. ) "C:\WINDOWS\iitnp.dll"
2006-06-22 20:39:22 73216 ( A…. ) "C:\WINDOWS\system32\nnaopsu.dll"
2006-06-22 18:04:46 39437 ( ..SH. ) "C:\WINDOWS\system32\pmnnomn.dll"
2006-06-21 15:06:00 751597 ( A…. ) "C:\WINDOWS\Winstall03.exe"
2006-06-21 13:41:46 ( .D… ) "C:\Program Files\FindFM Toolbar"
2006-06-21 11:14:30 310482 ( A…. ) "C:\Cochabamba.exe"
2006-06-20 21:23:10 117 ( A..H. ) "C:\WINDOWS\DWINSTALL329.bat"
2006-06-20 21:14:10 310482 ( A…. ) "C:\WINDOWS\Cochabamba32.exe"
2006-06-20 20:42:46 ( .D… ) "C:\Documents and Settings\Administrator\Application Data\SystemDoctor 2006 Free"
2006-06-19 19:24:40 ( .D… ) "C:\Documents and Settings\Administrator\Application Data\MSN Search Toolbar"
2006-06-19 19:22:56 ( .D… ) "C:\Program Files\MSN Toolbar Suite"
2006-06-19 17:34:04 46110 ( A…. ) "C:\popps2.exe"
2006-06-19 09:19:16 ( .D… ) "C:\Program Files\Common Files\fizi"
2006-06-19 07:49:08 30208 ( A…. ) "C:\SS1001.exe"
2006-06-19 07:48:50 310122 ( A…. ) "C:\Trelew.exe"
2006-06-19 07:46:38 328688 ( A…. ) "C:\WINDOWS\zornnn.exe"
2006-06-19 00:47:34 328688 ( A…. ) "C:\WINDOWS\toolbar9995.exe"
2006-06-19 00:47:04 39920 ( A…. ) "C:\WINDOWS\mc-110-12-0000193.exe"
2006-06-18 16:06:00 46110 ( A…. ) "C:\popps.exe"
2006-06-18 07:59:06 ( .D… ) "C:\Program Files\Windows"
2006-06-17 17:35:18 2048965 ( A…. ) "C:\winsx.exe"
2006-06-17 11:54:32 81920 ( A…. ) "C:\WINDOWS\system32\regsvr32.dll"
2006-06-17 11:53:48 ( .D… ) "C:\Program Files\Common Files\MCROSO~1"
2006-06-17 11:51:34 310482 ( A…. ) "C:\insllre.exe"
2006-06-17 11:40:44 32768 ( A…. ) "C:\WINDOWS\unstall.exe"
2006-06-17 11:40:40 53120 ( A…. ) "C:\WINDOWS\optimize.exe"
2006-06-17 11:40:38 42944 ( A…. ) "C:\WINDOWS\pop06ap2.exe"
2006-06-17 11:40:28 5632 ( A…. ) "C:\WINDOWS\pi1_36.exe"
2006-06-17 11:40:00 102400 ( A…. ) "C:\WINDOWS\mirar.exe"
2006-06-17 11:35:58 ( .D… ) "C:\Program Files\PCRescue4.0"
2006-06-17 10:10:28 81920 ( A…. ) "C:\WINDOWS\system32\dvdplay.dll"
2006-06-17 07:50:00 ( .D… ) "C:\Program Files\Cowabanga"
2006-06-17 07:49:20 46110 ( A…. ) "C:\myspac.exe"
2006-06-08 03:55:52 3753 ( A…. ) "C:\Program Files\html2.htm"
2006-06-08 03:55:52 3626 ( A…. ) "C:\Program Files\html1.htm"
2006-06-04 20:52:44 ( .D… ) "C:\Program Files\Debuggers"
2006-04-28 05:27:48 65536 ( A…. ) "C:\Program Files\Common Files\icrosoft.exe"


((((((((((((((((((((((((((((((((((((((((( Files Created - Last 30days ))))))))))))))))))))))))))))))))))))))))))))))


2006-07-04 18:18 73,728 C:\WINDOWS\system32\pv.exe
2006-07-04 18:18 39,184 C:\WINDOWS\system32\Ntrights.exe
2006-07-04 18:18 175,616 C:\WINDOWS\system32\strings.exe
2006-07-04 18:18 16,384 C:\WINDOWS\system32\restart.exe
2006-07-04 18:18 126,976 C:\WINDOWS\system32\zip.exe
2006-07-04 18:18 11,254 C:\WINDOWS\system32\locate.com
2006-07-03 13:55 30,208 C:\SS1001new.exe
2006-06-22 20:39 73,216 C:\WINDOWS\system32\nnaopsu.dll
2006-06-22 20:39 123 C:\WINDOWS\iitnp.dll
2006-06-22 18:04 39,437 C:\WINDOWS\system32\pmnnomn.dll
2006-06-21 13:41 39,920 C:\WINDOWS\mc-110-12-0000193.exe
2006-06-21 13:41 328,688 C:\WINDOWS\toolbar9995.exe
2006-06-21 13:41 310,482 C:\WINDOWS\Cochabamba32.exe
2006-06-21 13:41 117 C:\WINDOWS\DWINSTALL329.bat
2006-06-21 13:39 751,597 C:\WINDOWS\Winstall03.exe
2006-06-20 20:27 1,060,864 C:\WINDOWS\system32\mfc71.dll
2006-06-20 07:13 310,482 C:\Cochabamba.exe
2006-06-19 17:33 46,110 C:\popps2.exe
2006-06-19 07:48 30,208 C:\SS1001.exe
2006-06-19 07:47 310,122 C:\Trelew.exe
2006-06-19 06:43 328,688 C:\WINDOWS\zornnn.exe
2006-06-18 16:05 46,110 C:\popps.exe
2006-06-17 17:33 2,048,965 C:\winsx.exe
2006-06-17 11:54 81,920 C:\WINDOWS\system32\regsvr32.dll
2006-06-17 11:40 53,120 C:\WINDOWS\optimize.exe
2006-06-17 11:40 5,632 C:\WINDOWS\pi1_36.exe
2006-06-17 11:40 42,944 C:\WINDOWS\pop06ap2.exe
2006-06-17 11:40 32,768 C:\WINDOWS\unstall.exe
2006-06-17 11:39 102,400 C:\WINDOWS\mirar.exe
2006-06-17 10:10 81,920 C:\WINDOWS\system32\dvdplay.dll
2006-06-17 10:10 2 C:\WINDOWS\system32\wintsu.exe
2006-06-17 07:49 310,482 C:\insllre.exe
2006-06-16 16:37 46,110 C:\myspac.exe
2006-06-05 16:45 88,363 C:\WINDOWS\agrsmmsg.exe
2006-06-05 16:45 64,512 C:\WINDOWS\system32\agrsmdel.exe


((((((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb09.exe"
"HPHUPD05"="C:\\Program Files\\Hewlett-Packard\\{45B6180B-DCAB-4093-8EE8-6164457517F0}\\hphupd05.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd.exe\""
"HPHmon05"="C:\\WINDOWS\\System32\\hphmon05.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"ccRegVfy"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe\""
"Advanced Tools Check"="C:\\PROGRA~1\\NORTON~1\\AdvTools\\ADVCHK.EXE"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"C-Media Mixer"="C:\\Program Files\\PCI Audio Applications\\Bin\\AudioRack.exe /MixerStartup"
"WINDVDPatch"="CTHELPER.EXE"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"Jet Detection"="\"C:\\Program Files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe\""
"CTStartup"="C:\\Program Files\\Creative\\Splash Screen\\CTEaxSpl.EXE /run"
"WireLessMouse "="C:\\Program Files\\Multimedia Combo Set\\MouseDrv.exe"
"WireLessKeyboard "="C:\\Program Files\\Multimedia Combo Set\\PS2USBKbdDrv.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Windows Recylinder Check"="dryqbmqzls.exe"
"pop06ap"="C:\\WINDOWS\\pop06ap2.exe"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
"flags"=dword:00000008

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex\000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"Windows Recylinder Check"="dryqbmqzls.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=""
"NoDriveTypeAutoRun"=hex:5f,00,00,00

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"
"Prcn"="\"C:\\DOCUME~1\\ADMINI~1\\MYDOCU~1\\ICROSO~1.NET\\attrib.exe\" -vt ndrv"
"Mawtt"="C:\\WINDOWS\\system32\\PPATCH~1\\NPDB~1.EXE"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"WinUpdate.exe"="C:\\Program Files\\Windows\\WinUpdate.exe"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\HP DArC Task #Hewlett-Packard#7600#MY42A332C9P6.job
C:\WINDOWS\tasks\HP Usg Daily.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
C:\WINDOWS\tasks\Symantec NetDetect.job

Completion time: Wed 05/07/2006 20:18:43.13
ComboFix ver 06.07.04 - This logfile is located at C:\ComboFix.txt

ComboFix.2006-07-05.201734.txt




Logfile of HijackThis v1.99.1
Scan saved at 8:33:36 PM, on 5/07/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\pop06ap2.exe
C:\WINDOWS\System32\ctfmon.exe
C:\DOCUME~1\ADMINI~1\MYDOCU~1\ICROSO~1.NET\attrib.exe
C:\WINDOWS\system32\PPATCH~1\NPDB~1.EXE
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearch.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearchIndexer.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\windows\system32\spool\printers\FireDaemon.exe
C:\windows\system32\spool\printers\FireDaemon.exe
C:\WINDOWS\system32\spool\PRINTERS\dll32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
c:\windows\system32\spool\printers\events.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Administrator\My Documents\My Pictures\Athletics\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo;! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - (no file)
O3 - Toolbar: ninemsn Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-au\msntb.dll
O3 - Toolbar: (no name) - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - (no file)
O3 - Toolbar: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Bin\AudioRack.exe /MixerStartup
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Recylinder Check] dryqbmqzls.exe
O4 - HKLM\..\Run: [pop06ap] C:\WINDOWS\pop06ap2.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunServices: [Windows Recylinder Check] dryqbmqzls.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Prcn] "C:\DOCUME~1\ADMINI~1\MYDOCU~1\ICROSO~1.NET\attrib.exe" -vt ndrv
O4 - HKCU\..\Run: [Mawtt] C:\WINDOWS\system32\PPATCH~1\NPDB~1.EXE
O4 - Startup: Event Reminder.lnk = C:\pmw\PMREMIND.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearch.exe
O8 - Extra context menu item: &MyToolBar; Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &ninemsn; Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-au\msntb.dll/search.htm
O8 - Extra context menu item: &Search; - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-au\msntabres.dll/229?ce103b183eab4e149fabe3e5765b86d
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-au\msntabres.dll/230?ce103b183eab4e149fabe3e5765b86d
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related; Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: FireDaemon Service: dll32 (dll32) - Sublime Solutions Pty Ltd - C:\windows\system32\spool\printers\FireDaemon.exe
O23 - Service: FireDaemon Service: events (events) - Sublime Solutions Pty Ltd - C:\windows\system32\spool\printers\FireDaemon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Cool, that got rid of the real nastys.

Lets nuke what's left :D


1) Download, install, and update stuff

A: Ewido

download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program

1. Once you have downloaded ewido anti-spyware, locate the icon on the desktop
and double-click it to launch the set up program.
2. Once the setup is complete you will need run ewido and update the definition
files.
3. On the main screen select the icon "Update" then select the "
Update now" link.
  • Next select the "Start Update" button, the update will start and a
    progress bar will show the updates being installed.
4. Once the update has completed select the "Scanner" icon at the top of
the screen, then select the "Settings" tab.
5. Once in the Settings screen click on "Recommended actions" and then
select "Quarantine".
6. Under "Reports"
  • Select "Automatically generate report after every scan"
  • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.

B: Ad-Aware SE

Please download, set-up, and update Ad-Aware SE according to these instructions.

C: CWShredder

Download CWShredder from here

2) Automatic scans

1. Reboot your computer into SafeMode. You can do this by restarting
your computer and continually tapping the F8 key until a menu appears.

Use your up arrow key to highlight SafeMode then hit enter.

IMPORTANT: Do not open any other windows or
programs while ewido is scanning, it may interfere with the scanning proccess:
2. Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
3. Select the "Scanner" icon at the top and then the "Scan" tab
then click on "Complete System Scan".
4. ewido will now begin the scanning process, be patient this may take a little
time.
Once the scan is complete do the following:
5. If you have any infections you will prompted, then select "Apply all
actions"
6. Next select the "Reports" icon at the top.
7. Select the "Save report as" button in the lower left hand of the
screen and save it to a text file on your system (make sure to remember where
you saved that file, this is important).
8. Close ewido
9.Scan with CWShredder, using the 'fix' button.
10.reboot your system back into Normal Mode
11. Scan with ad-aware, removing anything that it finds.
12. reboot your computer

3) New logs



Please run combofix again, to generate a new log.

Please also run l2mfix, under option 1 again, to generate a new l2mfix log.

And finally, make a new HijackThis log.

Please post the results of the ewido report scan, the new HijackThis log, the new L2Mfix log, and the new combofix log (phew! :lol:)
Hi Dak,

Here I go,

When running ewido I reached the stage to apply all actions & received the following error

"The file C:\documents and settings\administrator\desktop\requested-files[2006-07-05_19_47].cab/c:\windows\system32\spool\printers\dll32 can not be quarantined because it is embedded in the archive C:\documents and settings\administrator\desktop\requested-files[2006-07-05_19_47].cab

Do you want to quarantine the whole archive ?"

I answered no to this.

When running combofix it came up with two warnings from nortons both were Malicious Script Detected - File C:\sUBs\enter.vbs it recommended to stop the script so I did.

Also upon shutting down I see an end task box with HPCMPMGR.exe


Here are the logs :thumbup:

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 7:17:36 PM 6/07/2006

+ Scan result:



C:\Program Files\Common Files\icrosoft.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\Program Files\Shareaza\wShareaza.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\Program Files\The Movies Unlocker\moviesunlocker.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\Program Files\Kazaa\TopSearch.dll -> Adware.Altnet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\AppID\Altnet Signing Module.EXE -> Adware.Altnet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\AppID\adm.EXE -> Adware.Altnet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Interface\{06CA2DA3-3A44-4FC7-8FD9-246C0F53407C} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_0 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_0\Level_0 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_0\Level_3 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_0\Level_4 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1\Level_0 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1\Level_0\Seqn_4492 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1\Level_0\Seqn_4496 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1\Level_0\Seqn_4543 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1\Level_4 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_2 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_2\Level_0 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_2\Level_3 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_2\Level_4 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_3 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_3\Level_0 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_3\Level_3 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_3\Level_4 -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Services -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Services\Queue -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\Kazaa\Promotions\Cydoor\Adwr_329\Services\Status -> Adware.Cydoor : Cleaned with backup (quarantined).
C:\Program Files\Common Files\ldlrendb\abnnpcpp\dplntcte.exe -> Adware.Gator : Cleaned with backup (quarantined).
C:\Program Files\Common Files\ldlrendb\larnbppdtp\lrlltdnrf.exe -> Adware.Gator : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264223.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264241.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264244.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264247.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264670.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264672.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264676.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264944.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264968.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00265052.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00265390.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00265906.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266819.EXE -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266865.EXE -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266866.EXE -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266868.EXE -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\pop06ap2.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\WINDOWS\unstall.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\bintheredunthat\000wn.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\Program Files\Cowabanga\Cowabanga.exe -> Adware.MediaTicket : Cleaned with backup (quarantined).
C:\WINDOWS\mirar.exe -> Adware.NetNucleus : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\WebP2PInstaller.dll -> Adware.PeerNet : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dvdplay.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\regsvr32.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ΑрpPatch\nоpdb.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
HKU\S-1-5-21-1844237615-725345543-725956986-500\Software\RX Toolbar -> Adware.RXToolbar : Cleaned with backup (quarantined).
C:\Program Files\FindFM Toolbar\toolbar.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\WINDOWS\toolbar9995.exe/toolbar.dll -> Adware.Softomate : Error during cleaning.
C:\WINDOWS\zornnn.exe/toolbar.dll -> Adware.Softomate : Error during cleaning.
C:\WINDOWS\system32\dxtpdx(2).dll -> Backdoor.Haxdoor.jc : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\requested-files[2006-07-05_19_47].cab/C:\WINDOWS\system32\spool\PRINTERS\dll32.exe -> Backdoor.Iroffer.13b9 : Error during cleaning.
C:\WINDOWS\system32\spool\PRINTERS\dll32.exe -> Backdoor.Iroffer.13b9 : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\requested-files[2006-07-05_19_47].cab/C:\\kybrdb_3.exe -> Backdoor.VB.ary : Error during cleaning.
C:\RECYCLER\NPROTECT\00266809.exe -> Backdoor.VB.ary : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266811.exe -> Downloader.Adload.ce : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266812.exe -> Downloader.Adload.ce : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266806.exe -> Downloader.Adload.cf : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266782.EXE -> Downloader.Adload.ck : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266783.EXE -> Downloader.Adload.ck : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266784.EXE -> Downloader.Adload.ck : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266787.EXE -> Downloader.Adload.ck : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266788.EXE -> Downloader.Adload.ck : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266789.EXE -> Downloader.Adload.ck : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266792.EXE -> Downloader.Adload.ck : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266793.EXE -> Downloader.Adload.ck : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266794.EXE -> Downloader.Adload.ck : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\requested-files[2006-07-05_19_47].cab/C:\\nwnmb_3.exe -> Downloader.Adload.cm : Error during cleaning.
C:\RECYCLER\NPROTECT\00266804.exe -> Downloader.Adload.cm : Cleaned with backup (quarantined).
C:\WINDOWS\optimize.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\WINDOWS\system32\actskn45.ocx -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Common Files\MCROSO~1\smss.exe -> Downloader.PurityScan.co : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\My Documents\Μicrosoft.NET\attrib.exe -> Downloader.PurityScan.cs : Cleaned with backup (quarantined).
C:\WINDOWS\system32\nnaopsu.dll -> Downloader.Qoologic.ax : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060524.033\0000NAV~.TMP -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266864.EXE -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266867.EXE -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\WINDOWS\pi1_36.exe -> Downloader.Small.cqy : Cleaned with backup (quarantined).
C:\VSL.dl_ -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00263627.exe -> Downloader.Small.cwq : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266798.EXE -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266799.EXE -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\requested-files[2006-07-05_19_47].cab/C:\\dfndrb_2.exe -> Downloader.VB.afv : Error during cleaning.
C:\Documents and Settings\Administrator\Desktop\requested-files[2006-07-05_19_47].cab/C:\\dfndrb_3.exe -> Downloader.VB.afv : Error during cleaning.
C:\RECYCLER\NPROTECT\00266814.exe -> Downloader.VB.afv : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266815.exe -> Downloader.VB.afv : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266810.exe -> Downloader.VB.agi : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266805.exe -> Downloader.VB.agp : Cleaned with backup (quarantined).
C:\WINDOWS\amm06.ocx -> Downloader.VB.bo : Cleaned with backup (quarantined).
C:\SS1001.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\SS1001new.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266801.exe -> Hijacker.VB.fb : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\requested-files[2006-07-05_19_47].cab/C:\\kybrdb_2.exe -> Hijacker.VB.fc : Error during cleaning.
C:\Documents and Settings\Administrator\Desktop\requested-files[2006-07-05_19_47].cab/C:\\nwnmb_2.exe -> Hijacker.VB.fc : Error during cleaning.
C:\RECYCLER\NPROTECT\00266802.exe -> Hijacker.VB.fc : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266803.exe -> Hijacker.VB.fc : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266807.exe -> Hijacker.VB.fc : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266808.exe -> Hijacker.VB.fc : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266813.exe -> Hijacker.VB.nh : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266816.exe -> Hijacker.VB.nh : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\USDR6_0001_D09M0706NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266829.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@tcompany.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Cookies\system@casinotropez[1].txt -> TrackingCookie.Casinotropez : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> TrackingCookie.Casinotropez : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> TrackingCookie.Casinotropez : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@com[1].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Cookies\system@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264341.TXT -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00265158.TXT -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266383.TXT -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Epilot : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Cookies\system@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264474.TXT -> TrackingCookie.Goclick : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00265006.TXT -> TrackingCookie.Goclick : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266381.TXT -> TrackingCookie.Goclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@kmpads[1].txt -> TrackingCookie.Kmpads : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@overture[1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Realtracker : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264342.TXT -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264343.TXT -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00264344.TXT -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266384.TXT -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266385.TXT -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@revenue[2].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
C:\myspac.exe -> Trojan.VB.abv : Cleaned with backup (quarantined).
C:\popps.exe -> Trojan.VB.abv : Cleaned with backup (quarantined).
C:\popps2.exe -> Trojan.VB.abv : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00266826.exe -> Trojan.Zapchast.bl : Cleaned with backup (quarantined).


::Report end


Logfile of HijackThis v1.99.1
Scan saved at 7:49:51 PM, on 6/07/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Documents and Settings\Administrator\Desktop\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearch.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearchIndexer.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\windows\system32\spool\printers\FireDaemon.exe
c:\windows\system32\spool\printers\events.exe
C:\Documents and Settings\Administrator\Desktop\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearchFilter.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Documents and Settings\Administrator\My Documents\My Pictures\Athletics\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
F2 - REG:system.ini: UserInit=userinit.exe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo;! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ninemsn Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-au\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Bin\AudioRack.exe /MixerStartup
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Recylinder Check] dryqbmqzls.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!ewido] "C:\Documents and Settings\Administrator\Desktop\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\RunServices: [Windows Recylinder Check] dryqbmqzls.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Event Reminder.lnk = C:\pmw\PMREMIND.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearch.exe
O8 - Extra context menu item: &MyToolBar; Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &ninemsn; Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-au\msntb.dll/search.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-au\msntabres.dll/229?ce103b183eab4e149fabe3e5765b86d
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-au\msntabres.dll/230?ce103b183eab4e149fabe3e5765b86d
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: FireDaemon Service: dll32 (dll32) - Sublime Solutions Pty Ltd - C:\windows\system32\spool\printers\FireDaemon.exe
O23 - Service: FireDaemon Service: events (events) - Sublime Solutions Pty Ltd - C:\windows\system32\spool\printers\FireDaemon.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\Administrator\Desktop\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


L2MFIX find log 051206
These are the registry keys present
**********************************************************************************
Winlogon/notify:
**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run…"
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address;"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People;…"
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{A5110426-177D-4e08-AB3F-785F10B4439C}"="My Phones"
"{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b5 (beta test) Context Menu Shell Extension"
"{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b5 (beta test) DragDrop Shell Extension"
"{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b5 (beta test) Context Menu Shell Extension"
"{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b5 (beta test) Property Sheet Shell Extension"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{00020D75-0000-0000-C000-000000000046}"="Microsoft Office Outlook Desktop Icon Handler"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Office Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
"{13E7F612-F261-4391-BEA2-39DF4F3FA311}"="Windows Desktop Search"
"{97090E2F-3062-4459-855B-014F0D3CDBB1}"="MSN Deskbar"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D426CFD0-87FC-4906-98D9-A23F5D515D61}]
@="MSN Desktop Search Outlook Express ISearchFolder Class"

**********************************************************************************
HKEY ROOT CLASSIDS:
**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
pmnnomn.dll Thu 22 Jun 2006 18:04:46 ..SH. 39,437 38.51 K

1 item found: 1 file (1 H/S), 0 directories.
Total of file sizes: 39,437 bytes 38.51 K
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is 049D-F5FD

Directory of C:\WINDOWS\System32

05/07/2006 08:22 PM dllcache
22/06/2006 06:04 PM 39,437 pmnnomn.dll
26/05/2005 07:39 PM 32 {07BBBEB7-CAC7-4750-B8E7-2E49AD1CE69C}.dat
25/04/2005 03:13 PM Microsoft
2 File(s) 39,469 bytes
2 Dir(s) 39,751,139,328 bytes free


Start Time= Wed 05/07/2006 20:17:34.74
Running from: C:\Documents and Settings\[removed]\Desktop

QuickScan did not find any signs of infected files

(((((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log )))))))))))))))))))))))))))))))))))))))))))))))))))))


HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wzcnotif


* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


REGISTRY ENTRIES REMOVED:

[HKEY_CLASSES_ROOT\clsid\{BCAC3B71-AD02-451B-A841-76E09090BA87}]
@=""

[HKEY_CLASSES_ROOT\clsid\{BCAC3B71-AD02-451B-A841-76E09090BA87}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{BCAC3B71-AD02-451B-A841-76E09090BA87}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{BCAC3B71-AD02-451B-A841-76E09090BA87}\InprocServer32]
@="C:\\WINDOWS\\system32\\rqr20.dll"
"ThreadingModel"="Apartment"

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


FILES REMOVED:

C:\WINDOWS\SYSTEM32\awiiiexx.dll
C:\WINDOWS\SYSTEM32\awsldp.dll
C:\WINDOWS\SYSTEM32\c6002gdmg60a2.dll
C:\WINDOWS\SYSTEM32\CTQL1208.dll
C:\WINDOWS\SYSTEM32\ctyptdll.dll
C:\WINDOWS\SYSTEM32\cuwmdm.dll
C:\WINDOWS\SYSTEM32\czmmdlg.dll
C:\WINDOWS\SYSTEM32\dvnlobby.dll
C:\WINDOWS\SYSTEM32\en68l1ju1.dll
C:\WINDOWS\SYSTEM32\f6l00g3me6.dll
C:\WINDOWS\SYSTEM32\h0j4la1q1d.dll
C:\WINDOWS\SYSTEM32\h0n00a5med.dll
C:\WINDOWS\SYSTEM32\hfetcfg.dll
C:\WINDOWS\SYSTEM32\i0lola331d.dll
C:\WINDOWS\SYSTEM32\i224lcfq1f2e.dll
C:\WINDOWS\SYSTEM32\i660lgjm16oa.dll
C:\WINDOWS\SYSTEM32\i8nmli5118.dll
C:\WINDOWS\SYSTEM32\irr8l59u1.dll
C:\WINDOWS\SYSTEM32\j80slid7180.dll
C:\WINDOWS\SYSTEM32\kodit142.dll
C:\WINDOWS\SYSTEM32\kt2ul7f91.dll
C:\WINDOWS\SYSTEM32\kxdblr.dll
C:\WINDOWS\SYSTEM32\lpcmgr10.dll
C:\WINDOWS\SYSTEM32\lvj2091oe.dll
C:\WINDOWS\SYSTEM32\m0ju0a19ed.dll
C:\WINDOWS\SYSTEM32\MEGAOUT.DLL
C:\WINDOWS\SYSTEM32\mgtime.dll
C:\WINDOWS\SYSTEM32\mkxml4.dll
C:\WINDOWS\SYSTEM32\mloert2.dll
C:\WINDOWS\SYSTEM32\mmtime.dll
C:\WINDOWS\SYSTEM32\mowebdvd.dll
C:\WINDOWS\SYSTEM32\MuPMSP.dll
C:\WINDOWS\SYSTEM32\mvrepl40.dll
C:\WINDOWS\SYSTEM32\mwgentr.dll
C:\WINDOWS\SYSTEM32\nawmsdrm.dll
C:\WINDOWS\SYSTEM32\nqprovau.dll
C:\WINDOWS\SYSTEM32\nvlanui2.dll
C:\WINDOWS\SYSTEM32\okepro32.dll
C:\WINDOWS\SYSTEM32\oztext32.dll
C:\WINDOWS\SYSTEM32\p0n8la5u1d.dll
C:\WINDOWS\SYSTEM32\p6p60g7se6.dll
C:\WINDOWS\SYSTEM32\pkchdprf.dll
C:\WINDOWS\SYSTEM32\ptofmap.dll
C:\WINDOWS\SYSTEM32\rqr20.dll
C:\WINDOWS\SYSTEM32\rthx32.dll
C:\WINDOWS\SYSTEM32\scsvc.dll
C:\WINDOWS\SYSTEM32\sllsrv32.dll
C:\WINDOWS\SYSTEM32\sons.dll
C:\WINDOWS\SYSTEM32\ssclient.dll
C:\WINDOWS\SYSTEM32\tkpmon.dll
C:\WINDOWS\SYSTEM32\tQpiperf.dll
C:\WINDOWS\SYSTEM32\wphtcpip.dll
C:\WINDOWS\SYSTEM32\wtserror.dll
C:\WINDOWS\SYSTEM32\wxcsapi.dll
C:\WINDOWS\SYSTEM32\wxiprop.dll
C:\WINDOWS\SYSTEM32\wzstream.dll


Granting sedebugprivilege to Administrators … successful


(((((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log ))))))))))))))))))))))))))))))))))))))))))))))))))))))

20:14:05.39

Qoologic uninstaller found and executed
Registry entries fixed


((((((((((((((((((((((((((((((((((((((((((((((((((( Ssk's Log ))))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\repairs303169590.dll
C:\Documents and Settings\Administrator\Application Data\Sskcwrd.dll
C:\Documents and Settings\Administrator\Application Data\Sskknwrd.dll
C:�
Ok, we're winning :). Hopefully, this'll be the last big step.

When running ewido I reached the stage to apply all actions & received the following error

"The file C:\documents and settings\administrator\desktop\requested-files[2006-07-05_19_47].cab/c:\windows\system32\spool\printers\dll32 can not be quarantined because it is embedded in the archive C:\documents and settings\administrator\desktop\requested-files[2006-07-05_19_47].cab

Do you want to quarantine the whole archive ?"

I answered no to this.


That's ok. it was detecting some malware in the cab file that you created earlyer to submit some files, so no worries.

When running combofix it came up with two warnings from nortons both were Malicious Script Detected - File C:\sUBs\enter.vbs it recommended to stop the script so I did.


If that happens again with a tool that you know to be ok, (like combofix), please allow it to run.

Also upon shutting down I see an end task box with HPCMPMGR.exe


Hmm… hopefully that was a one-off, but if it keeps happening, tell me.

On with the fix…

1) Show hidden files

Go to start>control panel>folder options>view (tab)
*choose to "show hidden files and folders,"
*uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
*Close the window with ok
*All hidden files will now be visible

2) Submitt files for research

There are some maliciouse files there that have avoided detection by ewido and norton, so i'd like you to submit them so that they can be sent to anti-virus/anti-spyware files for research.

Delete the old 'requested-flies' cab file from your desktop

Open the suspicious file submitter that you downloaded earlyer.

copy/paste the following into the window.

C:\Program Files\html2.htm
C:\Program Files\html1.htm
C:\WINDOWS\system32\wintsu.exe
C:\Program Files\Maxis\*.*
C:\WINDOWS\iitnp.dll
C:\WINDOWS\system32\pmnnomn.dll
C:\WINDOWS\Winstall03.exe
C:\Program Files\FindFM Toolbar\*.*
C:\Cochabamba.exe
C:\WINDOWS\DWINSTALL329.bat
C:\WINDOWS\Cochabamba32.exe
C:\Documents and Settings\Administrator\Application Data\SystemDoctor 2006 Free\*.*
C:\Trelew.exe
C:\WINDOWS\mc-110-12-0000193.exe
C:\winsx.exe
C:\Program Files\Common Files\MCROSO~1\*.*
C:\insllre.exe
C:\Program Files\Cowabanga\*.*
C:\WINDOWS\system32\mfc71.dll


And click 'continue'.

Email the newly created 'requested-files' to [removed]. please include a link to this thread in your email.

Please delete the requested-files cab archive after submitting it.

3) empty recycle bin

Please empty your recycle bin by double-clicking it, and clicking 'empty recycle bin'.

4) VundoFix

Please download VundoFix.exe to your desktop.

* Double-click VundoFix.exe to run it.
* Put a check next to Run VundoFix as a task.
* You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
* When VundoFix re-opens, click the Scan for Vundo button.
* Once it's done scanning, click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will shutdown your computer, click OK.
* Turn your computer back on.


5) HijackThis

Run HijackThis, and click 'do a system scan'.

select the following entries:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

F2 - REG:system.ini: UserInit=userinit.exe

O4 - HKLM\..\Run: [Windows Recylinder Check] dryqbmqzls.exe

O4 - HKLM\..\RunServices: [Windows Recylinder Check] dryqbmqzls.exe

O8 - Extra context menu item: &MyToolBar; Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -


And, unless you know that the following entry is ok, select this aswell:

O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab

Then, with all other windows closed (including this one), click 'fix selected'.

6) Reboot into safe mode

Restart your computer.

As it is booting up, continually poke the F8 button.

Use the arrow keys to select 'safe mode', and hit enter.

7) Delete files and folders

Please delete any of the following files/folders that still exist, making a note of any that you can't delete.



Folders

C:\Documents and
Settings\Administrator\Application
Data\SystemDoctor 2006 Free

C:\Program Files\Common Files\MCROSO~1 <– this will be a folder that starts with the letters 'mcroso', most likely 'mcrosoft'. Make sure you dont delete any files named 'microsoft'

C:\Program Files\Cowabanga

C:\Program Files\FindFM Toolbar

C:\Program Files\Maxis


Files

C:\Cochabamba.exe

C:\combofix.txt

C:\insllre.exe

C:\Trelew.exe

C:\winsx.exe

C:\WINDOWS\Cochabamba32.exe

C:\WINDOWS\DWINSTALL329.bat

C:\WINDOWS\iitnp.dll

C:\WINDOWS\mc-110-12-0000193.exe

C:\WINDOWS\toolbar9995.exe

C:\WINDOWS\Winstall03.exe

C:\WINDOWS\zornnn.exe

C:\WINDOWS\system32\pmnnomn.dll

C:\WINDOWS\system32\wintsu.exe

8) Ewido (again)

Reboot into normal mode, and scan your computer with Ewido, same as you did last time.

9 online anti-virus

Please do an online scan with Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
10) Combofix (again)

Please re-run combofix, the same way as you did before.

11) New logs

please reboot, and post the following logs:


C:\vundofix.txt

The kaspersky report

C:\combofix.txt

and a new HijackThis log.

Don't forget to mention any files that you couldn't delete

Cheers :)
Hi Dak, :D It happened again upon shutting down I see an end task box with HPCMPMGR.exe if I push end task it goes & pc shuts down When going to delete the files & folders, there were three that I couldn't locate, they were: C:\Trelew.exe C:\WINDOWS\mc-110-12-0000193.exe C:\WINDOWS\system32\pmnnomn.dll There was also one that wouldn't delete C:\WINDOWS\system32\wintsu.exe Here are the logs VundoFix V5.0.0 Running as SYSTEM from c:\windows\system32\VundoFix.exe Checking Java version… Scan started at 6:21:05 PM 7/07/2006 Listing files found while scanning…. C:\windows\system32\pmnnomn.dll Attempting to delete C:\windows\system32\pmnnomn.dll C:\windows\system32\pmnnomn.dll Has been deleted! Performing Repairs to the registry. Done! ——————————————————————————- KASPERSKY ON-LINE SCANNER REPORT Friday, July 07, 2006 11:13:34 PM Operating System: Microsoft Windows XP Professional, (Build 2600) Kaspersky On-line Scanner version: 5.0.78.0 Kaspersky Anti-Virus database last update: 7/07/2006 Kaspersky Anti-Virus database records: 205600 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ Scan Statistics: Total number of scanned objects: 75056 Number of viruses found: 67 Number of infected objects: 626 Number of suspicious objects: 2 Duration of the scan process: 01:16:06 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Wed, 5 Jul 2006 20:02:06 +1000]/UNNAMED/requested-files[2006-07-05_19_47].cab/C:/WINDOWS/system32/spool/PRINTERS/dll32.exe Infected: Backdoor.Win32.Iroffer.13b9 skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Wed, 5 Jul 2006 20:02:06 +1000]/UNNAMED/requested-files[2006-07-05_19_47].cab/c:/windows/system32/spool/printers/events.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.50011 skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Wed, 5 Jul 2006 20:02:06 +1000]/UNNAMED/requested-files[2006-07-05_19_47].cab/C://kybrdb_2.exe Infected: Trojan-Clicker.Win32.VB.fc skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Wed, 5 Jul 2006 20:02:06 +1000]/UNNAMED/requested-files[2006-07-05_19_47].cab/C://kybrdb_3.exe Infected: Backdoor.Win32.VB.ary skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Wed, 5 Jul 2006 20:02:06 +1000]/UNNAMED/requested-files[2006-07-05_19_47].cab/C://dfndrb_2.exe Infected: Trojan-Downloader.Win32.VB.afv skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Wed, 5 Jul 2006 20:02:06 +1000]/UNNAMED/requested-files[2006-07-05_19_47].cab/C://dfndrb_3.exe Infected: Trojan-Downloader.Win32.VB.afv skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Wed, 5 Jul 2006 20:02:06 +1000]/UNNAMED/requested-files[2006-07-05_19_47].cab/C://nwnmb_2.exe Infected: Trojan-Clicker.Win32.VB.fc skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Wed, 5 Jul 2006 20:02:06 +1000]/UNNAMED/requested-files[2006-07-05_19_47].cab/C://nwnmb_3.exe Infected: Trojan-Downloader.Win32.Adload.cm skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Wed, 5 Jul 2006 20:02:06 +1000]/UNNAMED/requested-files[2006-07-05_19_47].cab Infected: Trojan-Downloader.Win32.Adload.cm skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Wed, 5 Jul 2006 20:02:06 +1000]/UNNAMED Infected: Trojan-Downloader.Win32.Adload.cm skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/WINDOWS/Winstall03.exe/data.rar/toolbar9995.exe/toolbar.dll Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/WINDOWS/Winstall03.exe/data.rar/toolbar9995.exe Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/WINDOWS/Winstall03.exe/data.rar/Cochabamba32.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/WINDOWS/Winstall03.exe/data.rar/Cochabamba32.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/WINDOWS/Winstall03.exe/data.rar/drsmartload904a.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/WINDOWS/Winstall03.exe/data.rar Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/WINDOWS/Winstall03.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/Cochabamba.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/Cochabamba.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/winsx.exe/data.rar/dll32.exe Infected: Backdoor.Win32.Iroffer.13b9 skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/winsx.exe/data.rar/events.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.50011 skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/winsx.exe/data.rar Infected: not-a-virus:Server-FTP.Win32.Serv-U.50011 skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/winsx.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.50011 skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/insllre.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab/C:/insllre.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED/requested-files[2006-07-07_17_44].cab Infected: Trojan-Dropper.Win32.VB.nn skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx/[From "Kay" <[removed]>][Date Fri, 7 Jul 2006 17:45:53 +1000]/UNNAMED Infected: Trojan-Dropper.Win32.VB.nn skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{E581FD35-7F4D-45E0-B1ED-42F67D5B1865}\Microsoft\Outlook Express\Sent Items.dbx Mail MS Outlook 5: infected - 27 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Altnet2.zip/asmend.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Altnet2.zip ZIP: suspicious - 1 skipped C:\Program Files\Need2Find\bar\1.bin\N2PLUGIN.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.l skipped C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL Infected: not-a-virus:AdWare.Win32.MySearch.e skipped C:\Program Files\Need2Find\bar\1.bin\NPND2FN.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.o skipped C:\Program Files\Norton AntiVirus\Quarantine\119E5B78.exe Infected: Trojan-Downloader.MSIL.Agent.a skipped C:\Program Files\Norton AntiVirus\Quarantine\255865D0.exe Infected: Trojan-Spy.Win32.VB.eh skipped C:\Program Files\Norton AntiVirus\Quarantine\37A30BEA/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y skipped C:\Program Files\Norton AntiVirus\Quarantine\37A30BEA ZIP: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\37A30BEA CryptFF: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\37CD47EC.exe Infected: Virus.Win32.Parite.b skipped C:\Program Files\Norton AntiVirus\Quarantine\70000D0D.exe Infected: Trojan-Spy.Win32.VB.eh skipped C:\Program Files\Norton AntiVirus\Quarantine\73212741.htm Infected: Exploit.JS.ActiveXComponent skipped C:\RECYCLER\NPROTECT\00266863.exe/data0004 Infected: Trojan-Downloader.MSIL.Agent.a skipped C:\RECYCLER\NPROTECT\00266863.exe/data0010 Infected: Trojan.Win32.Zapchast.bl skipped C:\RECYCLER\NPROTECT\00266863.exe/data0011/data0006 Infected: Trojan-Dropper.Win32.VB.mz skipped C:\RECYCLER\NPROTECT\00266863.exe/data0011 Infected: Trojan-Dropper.Win32.VB.mz skipped C:\RECYCLER\NPROTECT\00266863.exe NSIS: infected - 4 skipped C:\RECYCLER\NPROTECT\00267806.exe/data0004 Infected: Trojan-Downloader.Win32.Small.ctp skipped C:\RECYCLER\NPROTECT\00267806.exe/data0005 Infected: Trojan-Downloader.Win32.Small.ajc skipped C:\RECYCLER\NPROTECT\00267806.exe NSIS: infected - 2 skipped C:\RECYCLER\NPROTECT\00267807.exe/data0006 Infected: Trojan-Dropper.Win32.VB.mz skipped C:\RECYCLER\NPROTECT\00267807.exe NSIS: infected - 1 skipped C:\RECYCLER\NPROTECT\00267811.htm Infected: Trojan-Clicker.Win32.Small.jf skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc10.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc10.exe NSIS: infected - 1 skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc14.exe/data.rar/toolbar9995.exe/toolbar.dll Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc14.exe/data.rar/toolbar9995.exe Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc14.exe/data.rar/Cochabamba32.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc14.exe/data.rar/Cochabamba32.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc14.exe/data.rar/drsmartload904a.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc14.exe/data.rar Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc14.exe RarSFX: infected - 6 skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc6.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc6.exe NSIS: infected - 1 skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc8.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc8.exe NSIS: infected - 1 skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc9.exe/data.rar/dll32.exe Infected: Backdoor.Win32.Iroffer.13b9 skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc9.exe/data.rar/events.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.50011 skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc9.exe/data.rar Infected: not-a-virus:Server-FTP.Win32.Serv-U.50011 skipped C:\RECYCLER\S-1-5-21-1844237615-725345543-725956986-500\Dc9.exe RarSFX: infected - 3 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP310\A0104225.exe Infected: Trojan.Win32.VB.abv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP310\A0104243.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP310\A0104243.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP310\A0104244.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP310\A0104250.exe Infected: Trojan-Downloader.Win32.Qoologic.at skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP310\A0104259.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP310\A0104259.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP310\A0104260.exe Infected: not-a-virus:AdWare.Win32.MediaMotor.q skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP310\A0104261.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP310\A0104264.ocx Infected: not-a-virus:AdWare.Win32.MediaMotor.m skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP310\A0104270.exe Infected: Trojan-Downloader.Win32.Dyfuca.ey skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP310\A0104280.exe Infected: not-a-virus:AdWare.Win32.MediaMotor.q skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP310\A0104281.ocx Infected: not-a-virus:AdWare.Win32.MediaMotor.m skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP311\A0104375.exe/toolbar.dll Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP311\A0104375.exe ZIP: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0105426.exe Infected: Trojan-Downloader.Win32.Adload.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106455.exe Infected: not-a-virus:AdWare.Win32.AdURL.c skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106469.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106494.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106495.exe Infected: Trojan-Downloader.Win32.PurityScan.cl skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106507.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106512.exe Infected: Trojan-Clicker.Win32.VB.fb skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106523.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106524.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106525.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106526.EXE Infected: not-a-virus:AdWare.Win32.PurityScan.em skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106527.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106528.exe Infected: Trojan-Downloader.Win32.PurityScan.cq skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106529.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106530.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106531.EXE Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106533.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106535.exe Infected: Trojan-Downloader.Win32.PurityScan.co skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106536.exe Infected: Trojan-Downloader.Win32.Adload.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106539.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106641.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106673.exe Infected: Backdoor.Win32.Iroffer.13b9 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106674.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.50011 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106703.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106703.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106703.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106703.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106703.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106716.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106716.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106717.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106721.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106721.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106721.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106721.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106721.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106729.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106746.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106772.exe/data.rar/toolbar9995.exe/toolbar.dll Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106772.exe/data.rar/toolbar9995.exe Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106772.exe/data.rar/Cochabamba32.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106772.exe/data.rar/Cochabamba32.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106772.exe/data.rar/drsmartload904a.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106772.exe/data.rar Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106772.exe RarSFX: infected - 6 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106773.exe/toolbar.dll Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106773.exe ZIP: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106774.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106774.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106775.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106778.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106783.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106792.exe/data.rar/toolbar9995.exe/toolbar.dll Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106792.exe/data.rar/toolbar9995.exe Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106792.exe/data.rar/Cochabamba32.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106792.exe/data.rar/Cochabamba32.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106792.exe/data.rar/drsmartload904a.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106792.exe/data.rar Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106792.exe RarSFX: infected - 6 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106793.exe/toolbar.dll Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106793.exe ZIP: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106794.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106794.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106795.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106798.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106829.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106845.exe/TRICKLER_PIC_WYVERN_WYVERN.EXE Infected: not-a-virus:AdWare.Win32.Gator.1023 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106845.exe ZIP: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106846.exe/data0002 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106846.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106847.exe/data0002 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP312\A0106847.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106887.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106898.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106902.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106905.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106906.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106906.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106907.exe/toolbar.dll Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106907.exe ZIP: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106908.exe/data.rar/toolbar9995.exe/toolbar.dll Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106908.exe/data.rar/toolbar9995.exe Infected: not-a-virus:AdWare.Win32.Softomate.e skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106908.exe/data.rar/Cochabamba32.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106908.exe/data.rar/Cochabamba32.exe Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106908.exe/data.rar/drsmartload904a.exe Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106908.exe/data.rar Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106908.exe RarSFX: infected - 6 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106909.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106921.exe/data0002 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106921.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106923.exe/data0006 Infected: Trojan-Dropper.Win32.VB.nn skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106923.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106924.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106930.exe/data0002 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106930.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0106934.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107033.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107033.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107033.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107033.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107033.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107039.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107041.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107041.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107041.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107041.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107041.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107043.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107043.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107043.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107043.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107043.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107045.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107045.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107045.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107045.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0107045.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0108051.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0108051.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0108051.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0108051.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0108051.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0108052.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0108053.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0108059.exe Infected: Trojan-Clicker.Win32.Small.jf skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0108060.EXE Infected: Trojan-Downloader.Win32.Small.ajc skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0109152.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0109168.exe Infected: Trojan-Downloader.Win32.VB.afl skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0110163.exe/data.rar/drsmartload408a.exe Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0110163.exe/data.rar Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0110163.exe RarSFX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0110165.exe Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0110168.exe Infected: Trojan-Downloader.Win32.VB.afl skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0110223.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0111226.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0111258.exe Infected: Trojan-Clicker.Win32.VB.fb skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0111301.exe Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0111304.exe Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0111308.exe Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0111312.exe Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0111318.exe Infected: Trojan-Downloader.Win32.VB.afl skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0111343.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0111377.exe/data0002 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP313\A0111377.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111384.EXE Infected: Trojan-Clicker.Win32.VB.fb skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111407.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111408.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111420.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111421.sys Infected: Backdoor.Win32.Haxdoor.jc skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111422.sys Infected: Backdoor.Win32.Haxdoor.jc skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111423.dll Infected: Backdoor.Win32.Haxdoor.jc skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111424.exe Infected: Backdoor.Win32.Haxdoor.jc skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111431.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111433.exe/data0002 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111433.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111435.exe Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111436.exe/data.rar/drsmartload408a.exe Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111436.exe/data.rar Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111436.exe RarSFX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111437.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111439.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111441.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111443.exe Infected: Trojan-Downloader.Win32.Adload.ce skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111447.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111463.EXE Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111465.EXE Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111467.EXE Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111469.EXE Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111471.EXE Infected: Trojan-Downloader.Win32.Adload.bo skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111473.EXE Infected: Trojan-Downloader.Win32.Adload.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111528.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111528.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111528.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111528.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111528.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111535.EXE Infected: Trojan-Clicker.Win32.VB.fb skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111603.EXE Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111605.EXE Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111607.EXE Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111609.EXE Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111611.EXE Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111613.EXE Infected: Trojan-Downloader.Win32.VB.afl skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111615.DLL Infected: not-a-virus:AdWare.Win32.Softomate.q skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111622.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111624.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111624.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111624.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111624.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111624.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111625.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111626.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111630.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111631.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0111699.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0112702.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0112721.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0112738.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0112776.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP314\A0113779.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0113844.exe Infected: Trojan-Downloader.Win32.VB.afl skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114838.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114884.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114886.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114889.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114889.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114889.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114889.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114889.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114893.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114893.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114893.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114893.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114893.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114894.exe Infected: Trojan-Downloader.Win32.Small.daz skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114898.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114898.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114898.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114898.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114898.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114899.EXE Infected: Backdoor.Win32.Rbot.gen skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114900.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114907.EXE Infected: Trojan-Clicker.Win32.VB.fb skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114963.EXE Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114965.EXE Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114967.EXE Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114969.EXE Infected: Trojan-Downloader.Win32.Adload.ch skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114971.EXE Infected: Trojan-Downloader.Win32.VB.afl skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114973.DLL Infected: not-a-virus:AdWare.Win32.Softomate.q skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114980.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114981.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114983.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114983.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114983.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114983.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114983.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114984.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114986.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114986.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114986.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114986.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114986.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114988.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114988.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114988.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114988.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114988.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114990.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114990.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114990.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114990.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0114990.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0115107.EXE/data0004/data0006 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0115107.EXE/data0004 Infected: not-a-virus:AdWare.Win32.Agent.y skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0115107.EXE NSIS: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0115107.EXE UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0115107.EXE PE_Patch.UPX: infected - 2 skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP315\A0115108.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP
And the other logs :D


Start Time= Fri 07/07/2006 23:17:48.62
Running from: C:\Documents and Settings\[removed]\Desktop

QuickScan did not find any signs of infected files

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-07-06 20:07:52 90112 ( ….R ) "C:\WINDOWS\bwUnin-6.1.2.93-7288971L.exe"
2006-07-06 20:05:30 ( .D… ) "C:\Program Files\Common Files\KODAK"
2006-07-06 20:05:02 ( .D… ) "C:\Program Files\KODAK"
2006-07-06 18:11:16 ( .D… ) "C:\Documents and Settings\Administrator\Application Data\Lavasoft"
2006-07-06 18:10:28 ( .D… ) "C:\Program Files\Lavasoft"
2006-07-03 18:09:38 ( .D… ) "C:\Program Files\AvRack"
2006-07-01 03:18:24 2 ( A…. ) "C:\WINDOWS\system32\wintsu.exe"
2006-06-30 21:11:54 ( .D… ) "C:\Program Files\FileZilla"
2006-06-26 10:35:14 ( .D… ) "C:\Program Files\S?mantec"
2006-06-25 07:50:38 ( .D… ) "C:\Program Files\Common Files\?icrosoft.NET"
2006-06-19 19:24:40 ( .D… ) "C:\Documents and Settings\Administrator\Application Data\MSN Search Toolbar"
2006-06-19 19:22:56 ( .D… ) "C:\Program Files\MSN Toolbar Suite"
2006-06-19 09:19:16 ( .D… ) "C:\Program Files\Common Files\fizi"
2006-06-18 07:59:06 ( .D… ) "C:\Program Files\Windows"
2006-06-17 11:35:58 ( .D… ) "C:\Program Files\PCRescue4.0"
2006-06-04 20:52:44 ( .D… ) "C:\Program Files\Debuggers"


((((((((((((((((((((((((((((((((((((((((( Files Created - Last 30days ))))))))))))))))))))))))))))))))))))))))))))))


2006-07-06 20:18 80,896 C:\WINDOWS\system32\dc210usd.dll
2006-07-06 20:18 25,600 C:\WINDOWS\system32\dc210_32.dll
2006-07-06 20:07 90,112 C:\WINDOWS\bwUnin-6.1.2.93-7288971L.exe
2006-07-06 20:07 86,016 C:\WINDOWS\system32\PrintAPI.dll
2006-07-06 20:07 73,839 C:\WINDOWS\system32\KodakOneTouch.dll
2006-07-06 20:07 37,376 C:\WINDOWS\system32\kpsys32.dll
2006-07-06 20:07 197,632 C:\WINDOWS\system32\kpcp32.dll
2006-07-06 20:07 19,456 C:\WINDOWS\system32\kcm2sp.dll
2006-07-06 20:07 133,120 C:\WINDOWS\system32\sprof32.dll
2006-07-04 18:18 73,728 C:\WINDOWS\system32\pv.exe
2006-07-04 18:18 39,184 C:\WINDOWS\system32\Ntrights.exe
2006-07-04 18:18 175,616 C:\WINDOWS\system32\strings.exe
2006-07-04 18:18 16,384 C:\WINDOWS\system32\restart.exe
2006-07-04 18:18 126,976 C:\WINDOWS\system32\zip.exe
2006-07-04 18:18 11,254 C:\WINDOWS\system32\locate.com
2006-06-20 20:27 1,060,864 C:\WINDOWS\system32\mfc71.dll
2006-06-17 10:10 2 C:\WINDOWS\system32\wintsu.exe
2006-06-05 16:45 88,363 C:\WINDOWS\agrsmmsg.exe
2006-06-05 16:45 64,512 C:\WINDOWS\system32\agrsmdel.exe


((((((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb09.exe"
"HPHUPD05"="C:\\Program Files\\Hewlett-Packard\\{45B6180B-DCAB-4093-8EE8-6164457517F0}\\hphupd05.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd.exe\""
"HPHmon05"="C:\\WINDOWS\\System32\\hphmon05.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"ccRegVfy"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe\""
"Advanced Tools Check"="C:\\PROGRA~1\\NORTON~1\\AdvTools\\ADVCHK.EXE"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"C-Media Mixer"="C:\\Program Files\\PCI Audio Applications\\Bin\\AudioRack.exe /MixerStartup"
"WINDVDPatch"="CTHELPER.EXE"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"Jet Detection"="\"C:\\Program Files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe\""
"CTStartup"="C:\\Program Files\\Creative\\Splash Screen\\CTEaxSpl.EXE /run"
"WireLessMouse "="C:\\Program Files\\Multimedia Combo Set\\MouseDrv.exe"
"WireLessKeyboard "="C:\\Program Files\\Multimedia Combo Set\\PS2USBKbdDrv.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"!ewido"="\"C:\\Documents and Settings\\Administrator\\Desktop\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"UserFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,75,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=""
"NoDriveTypeAutoRun"=hex:5f,00,00,00

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\HP DArC Task #Hewlett-Packard#7600#MY42A332C9P6.job
C:\WINDOWS\tasks\HP Usg Daily.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
C:\WINDOWS\tasks\Symantec NetDetect.job

Completion time: Fri 07/07/2006 23:18:10.88
ComboFix ver 06.07.04 - This logfile is located at C:\ComboFix.txt

ComboFix.2006-07-07.231748.txt



Logfile of HijackThis v1.99.1
Scan saved at 11:33:28 PM, on 7/07/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Documents and Settings\Administrator\Desktop\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Kodak\KODAK Picture Transfer Software\pts.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearch.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\windows\system32\spool\printers\FireDaemon.exe
C:\Documents and Settings\Administrator\Desktop\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
c:\windows\system32\spool\printers\events.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearchIndexer.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\Administrator\My Documents\My Pictures\Athletics\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo;! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ninemsn Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-au\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Bin\AudioRack.exe /MixerStartup
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Documents and Settings\Administrator\Desktop\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Event Reminder.lnk = C:\pmw\PMREMIND.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: KODAK Picture Transfer Software.lnk = ?
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-au\bin\WindowsSearch.exe
O8 - Extra context menu item: &ninemsn; Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-au\msntb.dll/search.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-au\msntabres.dll/229?ce103b183eab4e149fabe3e5765b86d
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-au\msntabres.dll/230?ce103b183eab4e149fabe3e5765b86d
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: FireDaemon Service: dll32 (dll32) - Sublime Solutions Pty Ltd - C:\windows\system32\spool\printers\FireDaemon.exe
O23 - Service: FireDaemon Service: events (events) - Sublime Solutions Pty Ltd - C:\windows\system32\spool\printers\FireDaemon.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\Administrator\Desktop\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hi Dak :) When computer was booting up I had two errors, the first was Fire Daemon encounted an error at startup the 2nd was "your system has just recovered from a serious error" (this appeared 3 times) the missing log ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 10:56:23 AM 8/07/2006 + Scan result: C:\Documents and Settings\Administrator\Cookies\administrator@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : No action taken. ::Report end

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI