This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help the laptop keeps restarting when I try to get on the internet

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 1:49:12 PM, on 6/27/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\csrss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\windows\System32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\windows\System32\wuauclt.exe
C:\windows\Explorer.EXE
C:\Program Files\EzButton\CplBTQ00.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\windows\System32\hphmon03.exe
C:\Program Files\QuickTime\qttask.exe
C:\s2jen33.exe
C:\msek3k.exe
C:\revres.exe
C:\dfndrb_2.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\windows\System32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\GetRight\getright.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Documents and Settings\Ryan\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {A14822C5-ADDB-4F5B-AF69-C5127D3B2511} - \
O3 - Toolbar: Foxie - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\Program Files\Foxie Suite\foxiecoreu.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CplBTQ00] C:\Program Files\EzButton\CplBTQ00.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AutoLoaderwsrG1aYWXQXP] "C:\WINDOWS\System32\imgwt.exe"
O4 - HKLM\..\Run: [wF8g3ml] imgwt.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\windows\System32\hphmon03.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WINDO23] C:\s2jen33.exe
O4 - HKLM\..\Run: [WINDO39] C:\msek3k.exe
O4 - HKLM\..\Run: [Anti-Virus Update Scheduler V1.39.12R] C:\revres.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdb_2.exe
O4 - HKLM\..\Run: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKLM\..\Run: [ÿ_zskJBC_DOMK] C:\windows\System32\_zskwrkni04UATFITX\KMOD_CBJ.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrb_2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [newname] C:\\nwnmb_2.exe
O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKLM\..\RunServices: [ÿ_zskJBC_DOMK] C:\windows\System32\_zskwrkni04UATFITX\KMOD_CBJ.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\System32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [GoogleAdBGone] C:\Program Files\GoogleAdBGone\GoogleAdBGone.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O9 - Extra button: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra 'Tools' menuitem: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra 'Tools' menuitem: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra 'Tools' menuitem: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra 'Tools' menuitem: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2871FC9B-5E34-4AAE-9E9C-EBD1652D5C92} (Rhapsody Player Engine) - http://forms.real.com/real/player/download…ne_Inst_Win.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1138189251421
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: bw+0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: offline-8876480 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: mmxeroxk - mmxeroxk.dll (file missing)
O20 - Winlogon Notify: se500mdm - se500mdm.dll (file missing)
O21 - SSODL: ocOatwA - {982EEA5E-3284-40F4-5564-FD1C95AD7801} - C:\windows\System32\owt.dll (file missing)
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - (no file)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\windows\dcmhelp.exe (file missing)
O23 - Service: dllmgr64 - Unknown owner - C:\windows\dllmgr64.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\windows\lsass.exe (file missing)
O23 - Service: Microsoft Networks DN (msndn) - Unknown owner - C:\windows\msndn.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\windows\System32\HPHipm09.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Windows NT Session Manager (SMSS) - Unknown owner - C:\windows\smss.exe (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: sysmgr64 - Unknown owner - C:\windows\sysmgr64.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Windows Service Manager (WSCM) - Unknown owner - C:\windows\System32\service.exe (file missing)
Click Start > Run > and type in:

services.msc

Click OK.

In the services window find Windows Service Manager (WSCM)
Right click and choose "Properties". On the "General" tab under "Service
Status" click the "Stop" button to stop the service. Beside "Startup Type"
in the dropdown menu select "Disabled". Click Apply then OK. Exit the
Services utility.

Please repeat the above for these as well:
In the services window find:
sysmgr64
Windows NT Session Manager (SMSS)
Microsoft Networks DN (msndn)
dllmgr64.exe




Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {A14822C5-ADDB-4F5B-AF69-C5127D3B2511} - \

O4 - HKLM\..\Run: [AutoLoaderwsrG1aYWXQXP] "C:\WINDOWS\System32\imgwt.exe"
O4 - HKLM\..\Run: [wF8g3ml] imgwt.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WINDO23] C:\s2jen33.exe
O4 - HKLM\..\Run: [WINDO39] C:\msek3k.exe
O4 - HKLM\..\Run: [Anti-Virus Update Scheduler V1.39.12R] C:\revres.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdb_2.exe
O4 - HKLM\..\Run: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKLM\..\Run: [ÿ_zskJBC_DOMK] C:\windows\System32\_zskwrkni04UATFITX\KMOD_CBJ.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrb_2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [newname] C:\\nwnmb_2.exe
O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKLM\..\RunServices: [ÿ_zskJBC_DOMK] C:\windows\System32\_zskwrkni04UATFITX\KMOD_CBJ.exe
O4 - HKCU\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe

O16 - DPF: {2871FC9B-5E34-4AAE-9E9C-EBD1652D5C92} (Rhapsody Player Engine) - http://forms.real.com/real/player/download…ne_Inst_Win.cab

O20 - Winlogon Notify: mmxeroxk - mmxeroxk.dll (file missing)
O20 - Winlogon Notify: se500mdm - se500mdm.dll (file missing)

O21 - SSODL: ocOatwA - {982EEA5E-3284-40F4-5564-FD1C95AD7801} - C:\windows\System32\owt.dll (file missing)
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - (no file)

O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\windows\dcmhelp.exe (file missing)
O23 - Service: dllmgr64 - Unknown owner - C:\windows\dllmgr64.exe (file missing)
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\windows\lsass.exe (file missing)
O23 - Service: Microsoft Networks DN (msndn) - Unknown owner - C:\windows\msndn.exe (file missing)
O23 - Service: Windows NT Session Manager (SMSS) - Unknown owner - C:\windows\smss.exe (file missing)
O23 - Service: sysmgr64 - Unknown owner - C:\windows\sysmgr64.exe (file missing)
O23 - Service: Windows Service Manager (WSCM) - Unknown owner - C:\windows\System32\service.exe (file missing)


Close ALL windows and browsers except HijackThis and click "Fix checked"


Delete these files if listed from this location only:
C:\windows\System32\service.exe
C:\windows\sysmgr64.exe
C:\windows\msndn.exe
C:\windows\lsass.exe
C:\windows\dcmhelp.exe
C:\windows\dllmgr64.exe
C:\WINDOWS\System32\imgwt.exe
C:\s2jen33.exe
C:\msek3k.exe
C:\revres.exe
C:\kybrdb_2.exe
C:\dfndrb_2.exe
C:\nwnmb_2.exe




Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
I haven't experienced a restart yet but its kind of slow now. I coulden't find some of the stuff you told me to delete.



Logfile of HijackThis v1.99.1
Scan saved at 6:13:49 PM, on 7/3/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\csrss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\windows\System32\WgaTray.exe
C:\windows\Explorer.EXE
C:\Program Files\EzButton\CplBTQ00.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\windows\System32\hphmon03.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\windows\System32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\GoGoData.com\GOGODA~1\ADBUST~1.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Foxie Suite\Firewall.exe
C:\Documents and Settings\Ryan\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Foxie - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\Program Files\Foxie Suite\foxiecoreu.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CplBTQ00] C:\Program Files\EzButton\CplBTQ00.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\windows\System32\hphmon03.exe
O4 - HKLM\..\Run: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\System32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [GoogleAdBGone] C:\Program Files\GoogleAdBGone\GoogleAdBGone.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [GoGoTray.exe] C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O9 - Extra button: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra 'Tools' menuitem: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra 'Tools' menuitem: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra 'Tools' menuitem: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra button: (no name) - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra 'Tools' menuitem: GoGoData AdBuster - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra 'Tools' menuitem: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1138189251421
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: bw+0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: offline-8876480 - {1D918654-960A-4D4F-8E7A-4973890B7534} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - AppInit_DLLs: interceptor.dll
O20 - Winlogon Notify: WgaLogon - C:\windows\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\windows\dcmhelp.exe (file missing)
O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - Unknown owner - C:\Program Files\ProcessGuard\dcsuserprot.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\windows\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\windows\System32\HPHipm09.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Use ADD/Remove Programs and remove:
Logitech\Desktop Messenger


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com

O4 - HKLM\..\Run: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe

O4 - HKLM\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe

O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe

O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe

O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe

O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe

O4 - HKCU\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe


Close ALL windows and browsers except HijackThis and click "Fix checked"


Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Sorry for the late reply, something came up. The laptop has not been on since the last scan if that is of any help.


Logfile of HijackThis v1.99.1
Scan saved at 8:42:42 PM, on 7/14/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\csrss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\windows\System32\WgaTray.exe
C:\Program Files\EzButton\CplBTQ00.EXE
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\windows\System32\hphmon03.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\windows\System32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe
C:\PROGRA~1\GoGoData.com\GOGODA~1\ADBUST~1.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\GetRight\getright.exe
C:\WINDOWS\system32\RAMASST.exe
C:\windows\explorer.exe
C:\Documents and Settings\Ryan\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Foxie - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\Program Files\Foxie Suite\foxiecoreu.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CplBTQ00] C:\Program Files\EzButton\CplBTQ00.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\windows\System32\hphmon03.exe
O4 - HKLM\..\Run: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\System32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [GoogleAdBGone] C:\Program Files\GoogleAdBGone\GoogleAdBGone.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [GoGoTray.exe] C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O9 - Extra button: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra 'Tools' menuitem: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra 'Tools' menuitem: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra 'Tools' menuitem: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra button: (no name) - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra 'Tools' menuitem: GoGoData AdBuster - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra 'Tools' menuitem: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1138189251421
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: interceptor.dll
O20 - Winlogon Notify: WgaLogon - C:\windows\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\windows\dcmhelp.exe (file missing)
O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - Unknown owner - C:\Program Files\ProcessGuard\dcsuserprot.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\windows\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\windows\System32\HPHipm09.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)



Next:

Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

If you are taken to the internet page, just close the page.

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Exit Spy Sweeper.

Empty Recycle Bin

Reboot and "copy/paste" a new HJT log as well as the Results from Spy Sweeper file into this thread.
Also please describe how your computer behaves at the moment.
Logfile of HijackThis v1.99.1
Scan saved at 10:47:11 AM, on 7/17/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\csrss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\windows\System32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\windows\System32\WgaTray.exe
C:\Program Files\EzButton\CplBTQ00.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\windows\System32\ctfmon.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe
C:\PROGRA~1\GoGoData.com\GOGODA~1\ADBUST~1.EXE
C:\Program Files\GetRight\getright.exe
C:\Program Files\GetRight\getright.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\windows\explorer.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\Ryan\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Foxie - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\Program Files\Foxie Suite\foxiecoreu.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\windows\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [CplBTQ00] "C:\Program Files\EzButton\CplBTQ00.EXE"
O4 - HKLM\..\Run: [CeEKEY] "C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe"
O4 - HKLM\..\Run: [LtMoh] "C:\Program Files\ltmoh\Ltmoh.exe"
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CeEPOWER] "C:\Program Files\TOSHIBA\Power Management\CePMTray.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TPNF] "C:\Program Files\TOSHIBA\TouchPad\TPTray.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pinger] "c:\toshiba\ivp\ism\pinger.exe" /run
O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\System32\ctfmon.exe
O4 - HKCU\..\Run: [GoogleAdBGone] C:\Program Files\GoogleAdBGone\GoogleAdBGone.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [GoGoTray.exe] "C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O9 - Extra button: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra 'Tools' menuitem: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra 'Tools' menuitem: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra 'Tools' menuitem: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra button: (no name) - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra 'Tools' menuitem: GoGoData AdBuster - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra 'Tools' menuitem: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1138189251421
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: interceptor.dll
O20 - Winlogon Notify: WgaLogon - C:\windows\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\windows\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\windows\dcmhelp.exe (file missing)
O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - Unknown owner - C:\Program Files\ProcessGuard\dcsuserprot.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\windows\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\windows\System32\HPHipm09.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe



8:22 PM: Removal process completed. Elapsed time 00:04:09
8:22 PM: A reboot was required but declined.
8:21 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\Temp\SST22F.tmp". Reason: The system cannot find the file specified
8:21 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
8:21 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\Temp\SST22F.tmp". Reason: The system cannot find the file specified
8:21 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
8:21 PM: Quarantining All Traces: gator ewallet
8:21 PM: Quarantining All Traces: dealhelper
8:21 PM: Quarantining All Traces: taskmgn
8:21 PM: Quarantining All Traces: browseraid
8:21 PM: Quarantining All Traces: command
8:21 PM: Quarantining All Traces: bookedspace
8:21 PM: Quarantining All Traces: dollarrevenue
8:21 PM: Quarantining All Traces: hellz little spy
8:21 PM: Quarantining All Traces: surfsidekick
8:21 PM: Quarantining All Traces: sp2ms
8:21 PM: Quarantining All Traces: coolwebsearch (cws)
8:21 PM: Quarantining All Traces: adwaresheriff fakealert
8:21 PM: c:\windows\system32\pe386.sys is in use. It will be removed on reboot.
8:21 PM: c:\windows\temp\pe386.sys is in use. It will be removed on reboot.
8:21 PM: potentially rootkit-masked files is in use. It will be removed on reboot.
8:20 PM: Quarantining All Traces: potentially rootkit-masked files
8:20 PM: Quarantining All Traces: 180search assistant/zango
8:20 PM: Quarantining All Traces: icannnews
8:20 PM: Quarantining All Traces: look2me
8:20 PM: Quarantining All Traces: trojan-backdoor-haxdoor
8:19 PM: Quarantining All Traces: zenosearchassistant
8:19 PM: Quarantining All Traces: elitebar
8:19 PM: Quarantining All Traces: trojan-downloader-conhook
8:19 PM: Quarantining All Traces: trojan-backdoor-goldun
8:18 PM: Removal process initiated
8:15 PM: Traces Found: 107
8:15 PM: Full Sweep has completed. Elapsed time 01:24:49
8:15 PM: File Sweep Complete, Elapsed Time: 01:21:41
8:15 PM: C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\z_start.lnk (ID = 300281)
8:15 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\a0364235.lnk (ID = 300281)
8:15 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\a0364304.lnk (ID = 300281)
8:15 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\a0364295.lnk (ID = 300281)
8:15 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\a0362234.lnk (ID = 300281)
8:15 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\a0363235.lnk (ID = 300281)
8:14 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP344\A0365376.lnk (ID = 300281)
7:36 PM: c:\windows\system32\pe386.sys (ID = 0)
7:36 PM: c:\windows\system32\spoolsv.exe (ID = 0)
7:36 PM: c:\windows\temp\pe386.sys (ID = 0)
7:36 PM: HKLM\Software\Microsoft\Windows\CurrentVersion\Run || HPHmon03 (ID = 0)
7:36 PM: c:\windows\system32\hphmon03.exe (ID = 0)
7:36 PM: c:\documents and settings\ryan\local settings\temp\hph3 (ID = 0)
7:36 PM: c:\documents and settings\ryan\local settings\temp\hph2 (ID = 0)
7:36 PM: Found System Monitor: potentially rootkit-masked files
7:35 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP299\a0334876.vbs (ID = 185675)
7:35 PM: C:\WINDOWS\system32\sqjodxdk.xml (ID = 57645)
7:35 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\a0328294.cfg (ID = 91140)
7:35 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\a0329368.cfg (ID = 91140)
7:34 PM: C:\WINDOWS\system32\msnav32.ax (ID = 220229)
7:34 PM: C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\z_start.lnk (ID = 235994)
7:32 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364309.dll (ID = 159)
7:32 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364324.dll (ID = 120432)
7:32 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364310.dll (ID = 159)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364311.dll (ID = 159)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364312.dll (ID = 159)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364325.dll (ID = 120432)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364313.dll (ID = 159)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364314.dll (ID = 159)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364315.dll (ID = 159)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364326.dll (ID = 120432)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364316.dll (ID = 159)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364317.dll (ID = 159)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364327.dll (ID = 120432)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364318.dll (ID = 159)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364319.dll (ID = 159)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364330.exe (ID = 141431)
7:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364335.exe (ID = 142436)
7:24 PM: C:\WINDOWS\system32\sqjodxu.xml (ID = 57649)
7:24 PM: C:\WINDOWS\system32\sqjodxu1.xml (ID = 57650)
7:24 PM: C:\WINDOWS\system32\sqjodxu2.xml (ID = 57651)
7:24 PM: C:\dfndrc_2.exe (ID = 319990)
7:24 PM: C:\dfndrb_3.exe (ID = 320702)
7:24 PM: C:\WINDOWS\bs7beta.exe (ID = 142436)
7:24 PM: Found Adware: bookedspace
7:24 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP335\a0357170.exe (ID = 319514)
7:24 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP302\a0347963.exe (ID = 319001)
7:24 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP302\a0347962.exe (ID = 319002)
7:24 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP302\a0347964.exe (ID = 319515)
7:24 PM: Found Adware: dollarrevenue
7:24 PM: C:\INSTALL\zigid003.exe (ID = 300281)
7:23 PM: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\hellzlittlespy.zip (ID = 62102)
7:23 PM: Found Trojan Horse: hellz little spy
7:23 PM: c:\windows\system32\dwdsregt.exe (ID = 235995)
7:23 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\a0329369.exe (ID = 293)
7:23 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\a0328292.exe (ID = 293)
7:23 PM: C:\WINDOWS\system32\ppdsregl.exe (ID = 293)
7:23 PM: C:\Program Files\Yahoo!\YPSR\Quarantine\ppqf1.tmp (ID = 293)
7:23 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\a0364238.exe (ID = 293)
7:23 PM: C:\WINDOWS\system32\uder32.dll (ID = 120432)
7:23 PM: C:\WINDOWS\system32\eas.dll (ID = 120432)
7:23 PM: C:\WINDOWS\system32\dfdramp.dll (ID = 120432)
7:23 PM: C:\WINDOWS\system32\dqwsock.dll (ID = 120432)
7:23 PM: C:\WINDOWS\system32\kqdsl.dll (ID = 120432)
7:23 PM: C:\WINDOWS\system32\uyib.dll (ID = 120432)
7:23 PM: C:\WINDOWS\stubinstaller6282.exe (ID = 141431)
7:23 PM: Found Adware: 180search assistant/zango
7:23 PM: C:\WINDOWS\system32\dmnmpntw.dll (ID = 159)
7:23 PM: C:\WINDOWS\system32\dnn8015ue.dll (ID = 159)
7:23 PM: C:\WINDOWS\system32\gp24l3fq1.dll (ID = 159)
7:22 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364320.dll (ID = 159)
7:22 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364321.dll (ID = 159)
7:22 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364322.dll (ID = 159)
7:22 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364328.dll (ID = 120432)
7:20 PM: C:\WINDOWS\system32\j4n20e5oeh.dll (ID = 159)
7:19 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364329.dll (ID = 120432)
7:19 PM: Found Adware: icannnews
7:19 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364323.dll (ID = 159)
7:18 PM: C:\WINDOWS\system32\k0no0a53ed.dll (ID = 159)
7:18 PM: C:\WINDOWS\system32\m8po0i73e8.dll (ID = 159)
7:17 PM: C:\WINDOWS\system32\nqwdev.dll (ID = 159)
7:16 PM: C:\WINDOWS\system32\skprv.dll (ID = 159)
7:16 PM: C:\WINDOWS\system32\wzavusd.dll (ID = 159)
7:10 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\a0364237.exe (ID = 320715)
7:10 PM: C:\kybrdb_3.exe (ID = 320716)
7:10 PM: C:\WINDOWS\system32\sqjodxu3.xml (ID = 57652)
7:10 PM: Found Adware: dealhelper
7:06 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364332.exe (ID = 320716)
7:06 PM: C:\WINDOWS\system32\oke32.dll (ID = 159)
7:04 PM: C:\WINDOWS\system32\mhoeacct.dll (ID = 159)
7:01 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\a0329370.exe (ID = 187078)
7:01 PM: Found Adware: surfsidekick
7:01 PM: C:\WINDOWS\system32\mkjava.dll (ID = 159)
7:01 PM: C:\WINDOWS\system32\gpnql3551.dll (ID = 159)
7:01 PM: C:\WINDOWS\system32\agledit.dll (ID = 159)
7:01 PM: C:\WINDOWS\system32\gator.exe (ID = 61383)
7:01 PM: Found Adware: gator ewallet
7:01 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\a0328280.vbs (ID = 231442)
7:00 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364333.exe (ID = 320702)
6:58 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364306.exe (ID = 293)
6:56 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364307.exe (ID = 300281)
6:56 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364334.exe (ID = 319990)
6:56 PM: Found Trojan Horse: sp2ms
6:56 PM: C:\WINDOWS\system32\dfdiagn.dll (ID = 159)
6:56 PM: Found Adware: look2me
6:56 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP302\a0344748.sys (ID = 367)
6:56 PM: Found Trojan Horse: trojan-backdoor-haxdoor
6:56 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP302\a0344747.sys (ID = 299859)
6:55 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364308.exe (ID = 293)
6:55 PM: Found Adware: zenosearchassistant
6:53 PM: Starting File Sweep
6:53 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
6:53 PM: Starting Cookie Sweep
6:53 PM: Registry Sweep Complete, Elapsed Time:00:00:31
6:53 PM: HKU\S-1-5-18\software\microsoft\dmsdos\ (ID = 143627)
6:53 PM: Found Adware: taskmgn
6:53 PM: HKU\WRSS_Profile_S-1-5-21-1417521138-3830423373-2457987554-1005\software\lq\ (ID = 125741)
6:53 PM: Found Adware: elitebar
6:53 PM: HKU\WRSS_Profile_S-1-5-21-1417521138-3830423373-2457987554-1005\software\a70f6a1d-0195-42a2-934c-d8ac0f7c08eb\ (ID = 105078)
6:53 PM: Found Adware: browseraid
6:53 PM: HKU\S-1-5-21-1417521138-3830423373-2457987554-1006\software\microsoft\internet explorer\sites\ (ID = 109822)
6:53 PM: Found Adware: coolwebsearch (cws)
6:53 PM: HKLM\software\microsoft\windows\currentversion\explorer\shellexecutehooks\ || {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (ID = 1374139)
6:53 PM: Found Trojan Horse: trojan-downloader-conhook
6:53 PM: HKLM\system\currentcontrolset\services\se500mdmd\ (ID = 1364102)
6:53 PM: HKLM\system\currentcontrolset\services\wscm\ || imagepath (ID = 1348193)
6:53 PM: Found Adware: adwaresheriff fakealert
6:53 PM: HKLM\system\currentcontrolset\services\directprt\ (ID = 1178762)
6:53 PM: Found Trojan Horse: trojan-backdoor-goldun
6:53 PM: HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\ (ID = 1016072)
6:53 PM: HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\0000\ (ID = 1016064)
6:53 PM: Found Adware: command
6:53 PM: Starting Registry Sweep
6:53 PM: Memory Sweep Complete, Elapsed Time: 00:02:12
6:51 PM: Starting Memory Sweep
6:50 PM: Sweep initiated using definitions version 719
6:50 PM: Spy Sweeper 5.0.5.1286 started
6:50 PM: | Start of Session, Sunday, July 16, 2006 |
********
6:50 PM: | End of Session, Sunday, July 16, 2006 |
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
6:47 PM: Shield States
6:47 PM: Spyware Definitions: 719
6:47 PM: Spy Sweeper 5.0.5.1286 started
4:55 PM: c:\windows\system32\spoolsv.exe (ID = 0)
4:55 PM: HKLM\Software\Microsoft\Windows\CurrentVersion\Run || HPHmon03 (ID = 0)
4:55 PM: c:\windows\system32\hphmon03.exe (ID = 0)
4:55 PM: c:\documents and settings\ryan\local settings\temp\hph3 (ID = 0)
4:55 PM: c:\documents and settings\ryan\local settings\temp\hph2 (ID = 0)
4:55 PM: Found System Monitor: potentially rootkit-masked files
4:55 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP299\a0334876.vbs (ID = 185675)
4:55 PM: C:\WINDOWS\system32\sqjodxdk.xml (ID = 57645)
4:55 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\a0328294.cfg (ID = 91140)
4:55 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\a0329368.cfg (ID = 91140)
4:54 PM: C:\WINDOWS\system32\msnav32.ax (ID = 220229)
4:54 PM: C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\z_start.lnk (ID = 235994)
4:53 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364309.dll (ID = 159)
4:53 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364324.dll (ID = 120432)
4:53 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364310.dll (ID = 159)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364311.dll (ID = 159)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364312.dll (ID = 159)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364325.dll (ID = 120432)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364313.dll (ID = 159)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364314.dll (ID = 159)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364315.dll (ID = 159)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364326.dll (ID = 120432)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364316.dll (ID = 159)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364317.dll (ID = 159)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364327.dll (ID = 120432)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364318.dll (ID = 159)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364319.dll (ID = 159)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364330.exe (ID = 141431)
4:52 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364335.exe (ID = 142436)
4:45 PM: C:\WINDOWS\system32\sqjodxu.xml (ID = 57649)
4:45 PM: C:\WINDOWS\system32\sqjodxu1.xml (ID = 57650)
4:45 PM: C:\WINDOWS\system32\sqjodxu2.xml (ID = 57651)
4:45 PM: C:\dfndrc_2.exe (ID = 319990)
4:45 PM: C:\dfndrb_3.exe (ID = 320702)
4:45 PM: C:\WINDOWS\bs7beta.exe (ID = 142436)
4:45 PM: Found Adware: bookedspace
4:45 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP335\a0357170.exe (ID = 319514)
4:45 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP302\a0347963.exe (ID = 319001)
4:45 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP302\a0347962.exe (ID = 319002)
4:45 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP302\a0347964.exe (ID = 319515)
4:45 PM: Found Adware: dollarrevenue
4:45 PM: C:\INSTALL\zigid003.exe (ID = 300281)
4:45 PM: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\hellzlittlespy.zip (ID = 62102)
4:45 PM: Found Trojan Horse: hellz little spy
4:45 PM: c:\windows\system32\dwdsregt.exe (ID = 235995)
4:45 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\a0329369.exe (ID = 293)
4:45 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\a0328292.exe (ID = 293)
4:45 PM: C:\WINDOWS\system32\ppdsregl.exe (ID = 293)
4:45 PM: C:\Program Files\Yahoo!\YPSR\Quarantine\ppqf1.tmp (ID = 293)
4:45 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\a0364238.exe (ID = 293)
4:45 PM: C:\WINDOWS\system32\uder32.dll (ID = 120432)
4:45 PM: C:\WINDOWS\system32\eas.dll (ID = 120432)
4:45 PM: C:\WINDOWS\system32\dfdramp.dll (ID = 120432)
4:45 PM: C:\WINDOWS\system32\dqwsock.dll (ID = 120432)
4:45 PM: C:\WINDOWS\system32\kqdsl.dll (ID = 120432)
4:45 PM: C:\WINDOWS\system32\uyib.dll (ID = 120432)
4:45 PM: C:\WINDOWS\stubinstaller6282.exe (ID = 141431)
4:45 PM: Found Adware: 180search assistant/zango
4:44 PM: C:\WINDOWS\system32\dmnmpntw.dll (ID = 159)
4:44 PM: C:\WINDOWS\system32\dnn8015ue.dll (ID = 159)
4:44 PM: C:\WINDOWS\system32\gp24l3fq1.dll (ID = 159)
4:43 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364320.dll (ID = 159)
4:43 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364321.dll (ID = 159)
4:43 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364322.dll (ID = 159)
4:43 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364328.dll (ID = 120432)
4:41 PM: C:\WINDOWS\system32\j4n20e5oeh.dll (ID = 159)
4:40 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364329.dll (ID = 120432)
4:40 PM: Found Adware: icannnews
4:40 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364323.dll (ID = 159)
4:38 PM: C:\WINDOWS\system32\k0no0a53ed.dll (ID = 159)
4:38 PM: C:\WINDOWS\system32\m8po0i73e8.dll (ID = 159)
4:38 PM: C:\WINDOWS\system32\nqwdev.dll (ID = 159)
4:37 PM: C:\WINDOWS\system32\skprv.dll (ID = 159)
4:37 PM: C:\WINDOWS\system32\wzavusd.dll (ID = 159)
4:31 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\a0364237.exe (ID = 320715)
4:31 PM: C:\kybrdb_3.exe (ID = 320716)
4:31 PM: C:\WINDOWS\system32\sqjodxu3.xml (ID = 57652)
4:31 PM: Found Adware: dealhelper
4:27 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364332.exe (ID = 320716)
4:27 PM: C:\WINDOWS\system32\oke32.dll (ID = 159)
4:25 PM: C:\WINDOWS\system32\mhoeacct.dll (ID = 159)
4:22 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\a0329370.exe (ID = 187078)
4:22 PM: Found Adware: surfsidekick
4:22 PM: C:\WINDOWS\system32\mkjava.dll (ID = 159)
4:22 PM: C:\WINDOWS\system32\gpnql3551.dll (ID = 159)
4:22 PM: C:\WINDOWS\system32\agledit.dll (ID = 159)
4:22 PM: C:\WINDOWS\system32\gator.exe (ID = 61383)
4:22 PM: Found Adware: gator ewallet
4:22 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\a0328280.vbs (ID = 231442)
4:20 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364333.exe (ID = 320702)
4:19 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364306.exe (ID = 293)
4:17 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364307.exe (ID = 300281)
4:17 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364334.exe (ID = 319990)
4:17 PM: Found Trojan Horse: sp2ms
4:17 PM: C:\WINDOWS\system32\dfdiagn.dll (ID = 159)
4:17 PM: Found Adware: look2me
4:16 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP302\a0344748.sys (ID = 367)
4:16 PM: Found Trojan Horse: trojan-backdoor-haxdoor
4:16 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP302\a0344747.sys (ID = 299859)
4:16 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364308.exe (ID = 293)
4:16 PM: Found Adware: zenosearchassistant
4:14 PM: Starting File Sweep
4:14 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
4:14 PM: Starting Cookie Sweep
4:14 PM: Registry Sweep Complete, Elapsed Time:00:00:31
4:14 PM: HKU\S-1-5-18\software\microsoft\dmsdos\ (ID = 143627)
4:14 PM: Found Adware: taskmgn
4:14 PM: HKU\WRSS_Profile_S-1-5-21-1417521138-3830423373-2457987554-1005\software\lq\ (ID = 125741)
4:14 PM: Found Adware: elitebar
4:14 PM: HKU\WRSS_Profile_S-1-5-21-1417521138-3830423373-2457987554-1005\software\a70f6a1d-0195-42a2-934c-d8ac0f7c08eb\ (ID = 105078)
4:14 PM: Found Adware: browseraid
4:14 PM: HKU\S-1-5-21-1417521138-3830423373-2457987554-1006\software\microsoft\internet explorer\sites\ (ID = 109822)
4:14 PM: Found Adware: coolwebsearch (cws)
4:14 PM: HKLM\software\microsoft\windows\currentversion\explorer\shellexecutehooks\ || {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (ID = 1374139)
4:14 PM: Found Trojan Horse: trojan-downloader-conhook
4:14 PM: HKLM\system\currentcontrolset\services\se500mdmd\ (ID = 1364102)
4:14 PM: HKLM\system\currentcontrolset\services\wscm\ || imagepath (ID = 1348193)
4:14 PM: Found Adware: adwaresheriff fakealert
4:14 PM: HKLM\system\currentcontrolset\services\directprt\ (ID = 1178762)
4:14 PM: Found Trojan Horse: trojan-backdoor-goldun
4:14 PM: HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\ (ID = 1016072)
4:14 PM: HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\0000\ (ID = 1016064)
4:14 PM: Found Adware: command
4:13 PM: Starting Registry Sweep
4:13 PM: Memory Sweep Complete, Elapsed Time: 00:02:15
4:11 PM: Starting Memory Sweep
4:11 PM: Sweep initiated using definitions version 719
4:11 PM: Spy Sweeper 5.0.5.1286 started
4:11 PM: | Start of Session, Sunday, July 16, 2006 |
********
4:11 PM: | End of Session, Sunday, July 16, 2006 |
4:10 PM: Restore from quarantine completed. Elapsed time 00:00:39
4:10 PM: Processing: gator ewallet
4:10 PM: Processing: taskmgn
4:10 PM: Processing: command
4:10 PM: Processing: command
4:10 PM: Processing: command
4:10 PM: Processing: dealhelper
4:10 PM: Processing: dealhelper
4:10 PM: Processing: dealhelper
4:10 PM: Processing: dealhelper
4:10 PM: Processing: dealhelper
4:10 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\Temp\SST22E.tmp". Reason: The system cannot find the file specified
4:10 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
4:10 PM: Processing: browseraid
4:10 PM: Processing: adwaresheriff fakealert
4:10 PM: Processing: surfsidekick
4:10 PM: Processing: sp2ms
4:10 PM: Processing: sp2ms
4:10 PM: Processing: sp2ms
4:10 PM: Processing: sp2ms
4:10 PM: Processing: bookedspace
4:10 PM: Processing: hellz little spy
4:10 PM: Processing: coolwebsearch (cws)
4:10 PM: Processing: dollarrevenue
4:10 PM: Processing: dollarrevenue
4:10 PM: Processing: dollarrevenue
4:10 PM: Processing: dollarrevenue
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: zenosearchassistant
4:10 PM: Processing: icannnews
4:10 PM: Processing: icannnews
4:10 PM: Processing: icannnews
4:10 PM: Processing: icannnews
4:10 PM: Processing: icannnews
4:10 PM: Processing: icannnews
4:10 PM: Processing: trojan-backdoor-haxdoor
4:10 PM: Processing: trojan-downloader-conhook
4:10 PM: Processing: 180search assistant/zango
4:10 PM: Processing: potentially rootkit-masked files
4:10 PM: Processing: potentially rootkit-masked files
4:10 PM: Processing: potentially rootkit-masked files
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Processing: look2me
4:10 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\Temp\SST15E.tmp". Reason: The system cannot find the file specified
4:10 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
4:10 PM: Processing: elitebar
4:10 PM: Processing: trojan-backdoor-goldun
4:10 PM: Processing: trojan-backdoor-goldun
4:10 PM: Processing: trojan-backdoor-goldun
4:10 PM: Restore from quarantine initiated
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
3:28 PM: Shield States
3:28 PM: Spyware Definitions: 719
3:27 PM: Spy Sweeper 5.0.5.1286 started
8:01 AM: Access to Hosts file allowed for C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGW.EXE
Operation: File Access
Target:
Source: C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGW.EXE
8:00 AM: Tamper Detection
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
10:54 PM: Shield States
10:53 PM: Spyware Definitions: 719
10:53 PM: Spy Sweeper 5.0.5.1286 started
9:19 PM: | End of Session, Saturday, July 15, 2006 |
9:17 PM: Your definitions are up to date.
9:16 PM: Your definitions are up to date.
9:16 PM: Your definitions are up to date.
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
9:14 PM: Shield States
9:14 PM: Spyware Definitions: 719
9:14 PM: Spy Sweeper 5.0.5.1286 started
9:10 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:10 PM: Warning: System Error. Code: 1722.
9:10 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:10 PM: Warning: System Error. Code: 1722.
9:10 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:10 PM: Warning: System Error. Code: 1722.
9:10 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:10 PM: Warning: System Error. Code: 1722.
9:10 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:10 PM: Warning: System Error. Code: 1722.
9:10 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:10 PM: Warning: System Error. Code: 1722.
9:10 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:10 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Your spyware definitions have been updated.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Automated check for program update in progress.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
9:09 PM: Warning: Unable to query service start type: The RPC server is unavailable
The RPC server is unavailable
9:09 PM: Warning: System Error. Code: 1722.
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
9:06 PM: Shield States
9:06 PM: Spyware Definitions: 691
9:05 PM: Spy Sweeper 5.0.5.1286 started
9:05 PM: Spy Sweeper 5.0.5.1286 started
9:05 PM: | Start of Session, Saturday, July 15, 2006 |
********
9:20 PM: | End of Session, Saturday, July 15, 2006 |
9:20 PM: None
9:20 PM: Traces Found: 0
9:20 PM: Sweep Canceled
9:19 PM: Sweep initiated using definitions version 719
9:19 PM: Spy Sweeper 5.0.5.1286 started
9:19 PM: | Start of Session, Saturday, July 15, 2006 |
********
10:47 PM: Removal process completed. Elapsed time 00:02:21
10:47 PM: Preparing to restart your computer. Please wait…
10:47 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\Temp\SST205.tmp". Reason: The system cannot find the file specified
10:47 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
10:46 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\Temp\SST205.tmp". Reason: The system cannot find the file specified
10:46 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
10:46 PM: Quarantining All Traces: gator ewallet
10:46 PM: Quarantining All Traces: dealhelper
10:46 PM: Quarantining All Traces: taskmgn
10:46 PM: Quarantining All Traces: browseraid
10:46 PM: Quarantining All Traces: command
10:46 PM: Quarantining All Traces: surfsidekick
10:46 PM: Quarantining All Traces: bookedspace
10:46 PM: Quarantining All Traces: sp2ms
10:46 PM: Quarantining All Traces: dollarrevenue
10:46 PM: Quarantining All Traces: hellz little spy
10:46 PM: Quarantining All Traces: coolwebsearch (cws)
10:46 PM: Quarantining All Traces: adwaresheriff fakealert
10:46 PM: c:\windows\temp\pe386.sys is in use. It will be removed on reboot.
10:46 PM: c:\windows\system32\pe386.sys is in use. It will be removed on reboot.
10:46 PM: potentially rootkit-masked files is in use. It will be removed on reboot.
10:46 PM: Quarantining All Traces: potentially rootkit-masked files
10:46 PM: Quarantining All Traces: 180search assistant/zango
10:45 PM: Quarantining All Traces: icannnews
10:45 PM: Quarantining All Traces: look2me
10:45 PM: Quarantining All Traces: trojan-backdoor-haxdoor
10:45 PM: c:\documents and settings\ryan\start menu\programs\startup\z_start.lnk is in use. It will be removed on reboot.
10:45 PM: zenosearchassistant is in use. It will be removed on reboot.
10:45 PM: Quarantining All Traces: zenosearchassistant
10:45 PM: Quarantining All Traces: elitebar
10:45 PM: Quarantining All Traces: trojan-downloader-conhook
10:45 PM: Quarantining All Traces: trojan-backdoor-goldun
10:45 PM: Removal process initiated
10:41 PM: Traces Found: 73
10:41 PM: Full Sweep has completed. Elapsed time 01:21:15
10:41 PM: File Sweep Complete, Elapsed Time: 01:18:17
10:41 PM: C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\Z_Start.lnk (ID = 300281)
10:41 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364295.lnk (ID = 300281)
10:41 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364304.lnk (ID = 300281)
10:40 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0363235.lnk (ID = 300281)
10:40 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0362234.lnk (ID = 300281)
10:40 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP336\A0364235.lnk (ID = 300281)
10:13 PM: Warning: Stream read error
10:05 PM: c:\windows\temp\pe386.sys (ID = 0)
10:05 PM: c:\windows\system32\spoolsv.exe (ID = 0)
10:05 PM: c:\windows\system32\pe386.sys (ID = 0)
10:05 PM: Found System Monitor: potentially rootkit-masked files
10:04 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP299\A0334876.vbs (ID = 185675)
10:04 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\A0328294.cfg (ID = 91140)
10:04 PM: C:\System Volume Information\_restore{b8194ee4-e65e-4af3-b138-80272dcc4b9f}\RP298\A0329368.cfg (ID = 91140)
10:04 PM: C:\WINDOWS\system32\Sqjodxdk.xml (ID = 57645)
10:03 PM: C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\Z_Start.lnk (ID = 235994)
10:03 PM: C:\WINDOWS\system32\msnav32.ax (ID = 220229)
10:02 PM: C:\WINDOWS\system32\wzavusd.dll (ID = 159)
10:02 PM: C:\WINDOWS\system32\uyib.dll (ID = 120432)
10:02 PM: C:\WINDOWS\system32\Sqjodxu2.xml (ID = 57651)
10:02 PM: C:\WINDOWS\system32\Sqjodxu1.xml (ID = 57650)
10:02 PM: C:\WINDOWS\system32\Sqjodxu.xml (ID = 57649)
10:02 PM: C:\WINDOWS\system32\skprv.dll (ID = 159)
10:02 PM: C:\WINDOWS\system32\Sqjodxu3.xml (ID = 57652)
10:02 PM: Found Adware: dealhelper
10:02 PM: C:\WINDOWS\system32\nqwdev.dll (ID = 159)
10:02 PM: C:\WINDOWS\system32\m8po0i73e8.dll (ID = 159)
10:02 PM: C:\WINDOWS\system32\kqdsl.dll (ID = 120432)
10:02 PM: C:\WINDOWS\system32\k0no0a53ed.dll (ID = 159)
10:02 PM: C:\WINDOWS\system32\j4n20e5oeh.dll (ID = 159)
10:01 PM: C:\WINDOWS\system32\gp24l3fq1.dll (ID = 159)
10:01 PM: C:\WINDOWS\system32\dqwsock.dll (ID = 120432)
10:01 PM: C:\WINDOWS\system32\dnn8015ue.dll (ID = 159)
10:01 PM: C:\WINDOWS\system32\dmnmpntw.dll (ID = 159)
10:01 PM: C:\WINDOWS\system32\dFd
* Download Combofix to your desktop.
Doubleclick combo.exe
Follow the prompts.
Don't click on the window while the fix is running, because that will cause your system to hang.

When finished, it should produce a log, combofix.txt.
Post this log in your next reply together with a new hijackthislog.
Start Time= Mon 07/17/2006 15:51:40.96
Running from: C:\Documents and Settings\[removed]\Desktop

QuickScan did not find any signs of infected files

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-07-16 20:29:10 ( .D… ) "C:\Program Files\Common Files"
2006-07-15 21:00:20 ( .D… ) "C:\Program Files\Webroot"
2006-07-15 21:00:20 ( .D… ) "C:\Documents and Settings\Ryan\Application Data\Webroot"
2006-07-14 22:16:32 ( .D… ) "C:\Documents and Settings\Ryan\Application Data\Talkback"
2006-07-14 22:14:22 107132 ( A…. ) "C:\WINDOWS\UninstallFirefox.exe"
2006-07-07 16:54:10 252928 ( A…. ) "C:\WINDOWS\WRUninstall.dll"
2006-07-07 16:53:54 208896 ( A…. ) "C:\WINDOWS\system32\WRLogonNtf.dll"
2006-07-07 16:53:52 8704 ( A…. ) "C:\WINDOWS\system32\ssiefr.EXE"
2006-07-07 16:53:50 20992 ( A…. ) "C:\WINDOWS\system32\wrlzma.dll"
2006-06-28 23:00:14 16517680 ( A…. ) "C:\sp25s609vidx.exe"
2006-06-28 22:10:22 ( .D… ) "C:\Program Files\ProcessGuard"
2006-06-28 21:54:46 ( .D… ) "C:\Program Files\GoGoData.com"
2006-06-28 21:50:56 ( .D… ) "C:\Program Files\SpyCatcher 2006"
2006-06-26 09:36:08 ( .D… ) "C:\Program Files\CleanUp!"
2006-06-25 19:56:06 ( .D… ) "C:\Documents and Settings\Ryan\Application Data\AVG7"
2006-06-25 19:55:16 ( .D… ) "C:\Program Files\Grisoft"
2006-06-24 17:08:24 ( .D… ) "C:\Program Files\SpywareBlaster"
2006-06-23 07:29:38 ( .D… ) "C:\Program Files\Common Files\wqzk"
2006-06-23 07:29:30 8464 ( A…. ) "C:\WINDOWS\system32\sporder.dll"
2006-06-23 07:28:54 266240 ( A…. ) "C:\NNSCAA638.EXE"
2006-06-23 07:28:20 159867 ( A…. ) "C:\WINDOWS\system32\nwinqqez.exe"
2006-06-22 23:25:22 ( .D… ) "C:\Program Files\Silkroad"
2006-06-19 16:20:42 702768 ( ….. ) "C:\WINDOWS\system32\WgaLogon.dll"
2006-06-16 22:03:18 35040 ( A…. ) "C:\ssfvbnr.exe"
2006-06-16 22:00:50 12960 ( A…. ) "C:\qynbdil.exe"
2006-06-16 21:58:20 23360 ( A…. ) "C:\gvtrf.exe"
2006-06-15 23:06:48 185600 ( A…. ) "C:\visfx500.exe"
2006-06-15 22:45:46 38413 ( ..SH. ) "C:\WINDOWS\system32\rqrsspp.dll"
2006-06-15 00:00:16 33292 ( A…. ) "C:\WINDOWS\system32\eraseme_73048.exe"
2006-06-12 18:22:50 32942 ( A…. ) "C:\wincd3.exe"
2006-06-12 17:42:04 38413 ( ..SH. ) "C:\WINDOWS\system32\pmnmlii.dll"
2006-06-11 14:58:46 38413 ( ..SH. ) "C:\WINDOWS\system32\opnklkl.dll"
2006-06-10 20:29:18 38413 ( ..SH. ) "C:\WINDOWS\system32\nnnmlji.dll"
2006-06-10 19:18:38 38413 ( ..SH. ) "C:\WINDOWS\system32\fccbbcd.dll"
2006-06-10 18:08:18 38413 ( ..SH. ) "C:\WINDOWS\system32\yayabcd.dll"
2006-06-10 17:58:12 0 ( A…. ) "C:\WINDOWS\system32\fdhbe_58546.exe"
2006-06-10 00:55:26 38413 ( ..SH. ) "C:\WINDOWS\system32\iifddee.dll"
2006-06-10 00:14:14 38413 ( ..SH. ) "C:\WINDOWS\system32\ssqonmj.dll"
2006-06-09 19:45:30 8192 ( A…. ) "C:\WINDOWS\system32\iedriver.exexplore.exe"
2006-06-09 19:45:30 8192 ( A…. ) "C:\WINDOWS\system32\ddm_d.exe"
2006-06-09 19:45:30 8192 ( A…. ) "C:\WINDOWS\msxmlfilt.dll"
2006-06-09 19:45:28 8192 ( A…. ) "C:\WINDOWS\system32\johnwb.dll"
2006-06-09 19:45:28 8192 ( A…. ) "C:\WINDOWS\fsg_4203.exe"
2006-06-06 15:39:10 9640 ( ..SH. ) "C:\WINDOWS\system32\rqrsqnm.dll"
2006-06-05 06:36:16 17340 ( A…. ) "C:\WINDOWS\system32\fdhbe_76748.exe"
2006-06-05 06:21:44 38413 ( ..SH. ) "C:\WINDOWS\system32\nnnklif.dll"
2006-06-04 20:48:18 0 ( A…. ) "C:\WINDOWS\system32\eraseme_73757.exe"
2006-06-04 17:39:22 38413 ( ..SH. ) "C:\WINDOWS\system32\qomllmm.dll"
2006-06-04 16:46:56 38413 ( ..SH. ) "C:\WINDOWS\system32\cbxyxur.dll"
2006-06-03 19:38:56 38413 ( ..SH. ) "C:\WINDOWS\system32\fccyywu.dll"
2006-06-03 19:31:54 38413 ( ..SH. ) "C:\WINDOWS\system32\awtssqp.dll"
2006-06-03 19:19:02 38413 ( ..SH. ) "C:\WINDOWS\system32\tuvtstt.dll"
2006-06-03 16:29:54 16940 ( ..SH. ) "C:\WINDOWS\system32\vtutust.dll"
2006-06-03 16:16:04 9641 ( ..SH. ) "C:\WINDOWS\system32\ljjkhhg.dll"
2006-06-03 15:53:34 9640 ( ..SH. ) "C:\WINDOWS\system32\gebbcbb.dll"
2006-06-03 15:44:44 21321 ( ..SH. ) "C:\WINDOWS\system32\nnnnoop.dll"
2006-06-03 14:33:50 47117 ( A…. ) "C:\WINDOWS\isd.exe"
2006-06-03 10:38:04 120832 ( A…. ) "C:\ejke.exe"
2006-05-31 07:24:16 230168 ( A…. ) "C:\WINDOWS\system32\xactengine2_2.dll"
2006-05-31 07:22:42 63768 ( A…. ) "C:\WINDOWS\system32\dxdllreg.exe"
2006-05-30 21:53:50 120832 ( A…. ) "C:\eijefe.exe"
2006-05-30 05:24:58 61952 ( A…. ) "C:\ptamgum.exe"
2006-05-24 22:22:38 20480 ( A…. ) "C:\WINDOWS\system32\fdhbe_38375.exe"
2006-05-24 19:47:20 57856 ( A…. ) "C:\s2842p03.exe"
2006-05-23 09:13:08 20480 ( A…. ) "C:\ejeoi.exe"
2006-05-22 06:09:22 0 ( A…. ) "C:\WINDOWS\system32\fdhbe_82335.exe"
2006-05-21 21:13:46 0 ( A…. ) "C:\WINDOWS\system32\fdhbe_74425.exe"
2006-05-19 21:35:10 0 ( A…. ) "C:\WINDOWS\system32\fdhbe_72474.exe"
2006-05-19 06:54:28 ( .D… ) "C:\Program Files\ImTOO"
2006-05-19 05:15:34 140288 ( A…. ) "C:\WINDOWS\system32\dnsapi.dll"
2006-05-19 05:15:34 83456 ( A…. ) "C:\WINDOWS\system32\iphlpapi.dll"
2006-05-19 05:15:34 70656 ( A…. ) "C:\WINDOWS\system32\ws2_32.dll"
2006-05-19 05:15:34 54272 ( A…. ) "C:\WINDOWS\system32\ipv6mon.dll"
2006-05-19 05:15:34 31232 ( A…. ) "C:\WINDOWS\system32\inetmib1.dll"
2006-05-19 05:15:34 13312 ( A…. ) "C:\WINDOWS\system32\wship6.dll"
2006-05-19 05:15:32 103936 ( A…. ) "C:\WINDOWS\system32\dhcpcsvc.dll"
2006-05-19 05:15:32 95232 ( A…. ) "C:\WINDOWS\system32\6to4svc.dll"
2006-05-19 01:51:02 159232 ( A…. ) "C:\WINDOWS\system32\xpob2res.dll"
2006-05-19 01:46:02 48640 ( A…. ) "C:\WINDOWS\system32\ipv6.exe"
2006-05-19 01:44:56 83456 ( A…. ) "C:\WINDOWS\system32\netsh.exe"
2006-05-14 02:13:42 364544 ( A…. ) "C:\WINDOWS\system32\ipsmsnap.dll"
2006-05-14 02:13:42 334848 ( A…. ) "C:\WINDOWS\system32\ipsecsnp.dll"
2006-05-14 02:13:42 257536 ( A…. ) "C:\WINDOWS\system32\oakley.dll"
2006-05-14 02:13:42 159744 ( A…. ) "C:\WINDOWS\system32\ipsecsvc.dll"
2006-05-14 02:13:42 98304 ( A…. ) "C:\WINDOWS\system32\polstore.dll"
2006-05-14 02:13:42 29184 ( A…. ) "C:\WINDOWS\system32\winipsec.dll"
2006-05-12 22:19:38 57344 ( A…. ) "C:\ejnn3.exe"
2006-05-07 14:43:36 0 ( A…. ) "C:\WINDOWS\system32\fdhbe_51541.exe"
2006-04-27 22:12:32 0 ( A…. ) "C:\WINDOWS\system32\fdhbe_13080.exe"
2006-04-24 20:47:46 108544 ( ..SHR ) "C:\WINDOWS\msinit.exe"
2005-07-05 09:23:34 233472 ( A…. ) "C:\Program Files\Uninstall Need2Find Bar.dll"


(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days )))))))))))))))))))))))))))))))))))))))))))


2006-07-15 21:00 8,704 C:\windows\system32\ssiefr.EXE
2006-07-15 21:00 684,032 C:\windows\libeay32.dll
2006-07-15 21:00 252,928 C:\windows\WRUninstall.dll
2006-07-15 21:00 208,896 C:\windows\system32\WRLogonNtf.dll
2006-07-15 21:00 20,992 C:\windows\system32\wrlzma.dll
2006-07-15 21:00 155,648 C:\windows\ssleay32.dll
2006-07-14 22:14 107,132 C:\windows\UninstallFirefox.exe
2006-07-03 15:10 535,875,584 C:\hiberfil.sys
2006-06-28 22:58 16,517,680 C:\sp25s609vidx.exe
2006-06-28 21:50 307,200 C:\windows\system32\InterceptHelper.dll
2006-06-28 21:50 180,224 C:\windows\system32\archlib.dll
2006-06-28 21:50 176,128 C:\windows\system32\Interceptor.dll
2006-06-26 14:05 180,224 C:\windows\system32\NVUNINST.EXE
2006-06-25 18:23 62,672 C:\windows\system32\xinput1_1.dll
2006-06-25 18:23 230,168 C:\windows\system32\xactengine2_2.dll
2006-06-25 18:23 229,584 C:\windows\system32\xactengine2_1.dll
2006-06-25 18:22 61,136 C:\windows\system32\xinput9_1_0.dll
2006-06-25 18:22 230,096 C:\windows\system32\xactengine2_0.dll
2006-06-25 18:22 2,388,176 C:\windows\system32\d3dx9_30.dll
2006-06-25 18:22 2,337,488 C:\windows\system32\d3dx9_25.dll
2006-06-25 18:22 2,332,368 C:\windows\system32\d3dx9_29.dll
2006-06-25 18:22 2,323,664 C:\windows\system32\d3dx9_28.dll
2006-06-25 18:22 2,319,568 C:\windows\system32\d3dx9_27.dll
2006-06-25 18:22 2,297,552 C:\windows\system32\d3dx9_26.dll
2006-06-25 18:22 14,032 C:\windows\system32\x3daudio1_0.dll
2006-06-25 18:21 2,222,800 C:\windows\system32\d3dx9_24.dll
2006-06-25 18:07 974,848 C:\windows\system32\dxdiag.exe
2006-06-25 18:07 797,184 C:\windows\system32\d3dim700.dll
2006-06-25 18:07 68,096 C:\windows\system32\dsdmoprp.dll
2006-06-25 18:07 63,768 C:\windows\system32\dxdllreg.exe
2006-06-25 18:07 57,856 C:\windows\system32\dpwsockx.dll
2006-06-25 18:07 53,248 C:\windows\system32\devenum.dll
2006-06-25 18:07 524,800 C:\windows\system32\qedit.dll
2006-06-25 18:07 47,104 C:\windows\system32\wstdecod.dll
2006-06-25 18:07 382,976 C:\windows\system32\qdvd.dll
2006-06-25 18:07 377,856 C:\windows\system32\dpnet.dll
2006-06-25 18:07 363,520 C:\windows\system32\dsound.dll
2006-06-25 18:07 354,816 C:\windows\system32\psisdecd.dll
2006-06-25 18:07 32,768 C:\windows\system32\dpnhpast.dll
2006-06-25 18:07 276,480 C:\windows\system32\qdv.dll
2006-06-25 18:07 265,728 C:\windows\system32\ddraw.dll
2006-06-25 18:07 230,400 C:\windows\system32\dplayx.dll
2006-06-25 18:07 22,016 C:\windows\system32\dpmodemx.dll
2006-06-25 18:07 203,264 C:\windows\system32\dpvoice.dll
2006-06-25 18:07 194,560 C:\windows\system32\mswebdvd.dll
2006-06-25 18:07 181,248 C:\windows\system32\dmime.dll
2006-06-25 18:07 177,152 C:\windows\system32\qcap.dll
2006-06-25 18:07 16,896 C:\windows\system32\msyuv.dll
2006-06-25 18:07 104,448 C:\windows\system32\dmusic.dll
2006-06-25 18:07 1,769,472 C:\windows\system32\dxdiagn.dll
2006-06-25 18:07 1,689,600 C:\windows\system32\d3d9.dll
2006-06-25 18:07 1,230,336 C:\windows\system32\msvidctl.dll
2006-06-25 18:07 1,189,888 C:\windows\system32\dx8vb.dll
2006-06-25 18:07 1,179,648 C:\windows\system32\d3d8.dll
2006-06-24 17:08 118,784 C:\windows\system32\MSSTDFMT.DLL
2006-06-23 07:29 8,464 C:\windows\system32\sporder.dll
2006-06-23 07:28 266,240 C:\NNSCAA638.EXE
2006-06-23 07:28 159,867 C:\windows\system32\nwinqqez.exe
2006-06-19 16:20 702,768 C:\windows\system32\WgaLogon.dll
2006-06-16 22:02 35,040 C:\ssfvbnr.exe
2006-06-16 21:58 12,960 C:\qynbdil.exe
2006-06-16 21:57 23,360 C:\gvtrf.exe
2006-06-16 05:40 47,117 C:\windows\isd.exe
2006-06-15 22:53 185,600 C:\visfx500.exe
2006-06-15 22:45 38,413 C:\windows\system32\rqrsspp.dll
2006-06-14 23:56 33,292 C:\windows\system32\eraseme_73048.exe
2006-06-12 18:20 32,942 C:\wincd3.exe
2006-06-12 17:42 38,413 C:\windows\system32\pmnmlii.dll
2006-06-11 14:58 38,413 C:\windows\system32\opnklkl.dll
2006-06-10 20:29 38,413 C:\windows\system32\nnnmlji.dll
2006-06-10 19:18 38,413 C:\windows\system32\fccbbcd.dll
2006-06-10 18:08 38,413 C:\windows\system32\yayabcd.dll
2006-06-10 17:58 0 C:\windows\system32\fdhbe_58546.exe
2006-06-10 00:55 38,413 C:\windows\system32\iifddee.dll
2006-06-10 00:14 38,413 C:\windows\system32\ssqonmj.dll
2006-06-08 16:33 0 C:\windows\system32\mswinf32.exe
2006-06-06 15:39 9,640 C:\windows\system32\rqrsqnm.dll
2006-06-05 06:33 17,340 C:\windows\system32\fdhbe_76748.exe
2006-06-05 06:21 38,413 C:\windows\system32\nnnklif.dll
2006-06-04 20:48 0 C:\windows\system32\eraseme_73757.exe
2006-06-04 17:39 38,413 C:\windows\system32\qomllmm.dll
2006-06-04 16:46 38,413 C:\windows\system32\cbxyxur.dll
2006-06-03 19:38 38,413 C:\windows\system32\fccyywu.dll
2006-06-03 19:31 38,413 C:\windows\system32\awtssqp.dll
2006-06-03 19:19 38,413 C:\windows\system32\tuvtstt.dll
2006-06-03 16:29 16,940 C:\windows\system32\vtutust.dll
2006-06-03 16:16 9,641 C:\windows\system32\ljjkhhg.dll
2006-06-03 15:53 9,640 C:\windows\system32\gebbcbb.dll
2006-06-03 15:44 21,321 C:\windows\system32\nnnnoop.dll
2006-06-02 16:22 120,832 C:\ejke.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="\"RUNDLL32.EXE\" C:\\windows\\System32\\NvCpl.dll,NvStartup"
"nwiz"="\"nwiz.exe\" /install"
"CplBTQ00"="\"C:\\Program Files\\EzButton\\CplBTQ00.EXE\""
"CeEKEY"="\"C:\\Program Files\\TOSHIBA\\E-KEY\\CeEKey.exe\""
@=""
"LtMoh"="\"C:\\Program Files\\ltmoh\\Ltmoh.exe\""
"CpRmtKey"="\"C:\\Program Files\\Toshiba Controls\\CpRmtKey.EXE\""
"CeEPOWER"="\"C:\\Program Files\\TOSHIBA\\Power Management\\CePMTray.exe\""
"ezShieldProtector for Px"="C:\\WINDOWS\\System32\\ezSP_Px.exe"
"TPNF"="\"C:\\Program Files\\TOSHIBA\\TouchPad\\TPTray.exe\""
"ccRegVfy"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe\""
"Pinger"="\"c:\\toshiba\\ivp\\ism\\pinger.exe\" /run"
"RealTray"="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" SYSTEMBOOTHIDEPLAYER"
"Symantec NetDriver Monitor"="\"C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe\" /Consumer"
"MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"LVCOMSX"="C:\\WINDOWS\\System32\\LVCOMSX.EXE"
"LogitechVideoRepair"="\"C:\\Program Files\\Logitech\\Video\\ISStart.exe\" "
"LogitechVideoTray"="\"C:\\Program Files\\Logitech\\Video\\LogiTray.exe\""
"HPDJ Taskbar Utility"="C:\\windows\\System32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"ÿ_zskFSD_RQARX"="C:\\windows\\System32\\_zskwrkni04]\\SM_G\\XRAQR_DSF.exe"
"ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_"="c:\\windows\\system32\\_zskwrkni04tmv_i`msei`qzfi].exe"
"SpyCatcher Reminder"="\"C:\\Program Files\\SpyCatcher 2006\\SpyCatcher.exe\" reminder"
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe\" /startintray"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\windows\\System32\\ctfmon.exe"
"GoogleAdBGone"="C:\\Program Files\\GoogleAdBGone\\GoogleAdBGone.exe"
"MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\" /WinStart"
"Yahoo! Pager"="\"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\ypager.exe\" -quiet"
"LogitechSoftwareUpdate"="\"C:\\Program Files\\Logitech\\Video\\ManifestEngine.exe\" boot"
"ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_"="c:\\windows\\system32\\_zskwrkni04tmv_i`msei`qzfi].exe"
"GoGoTray.exe"="\"C:\\Program Files\\GoGoData.com\\GoGoData Toolbar\\GoGoTray.exe\""
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"ÿ_zskFSD_RQARX"="C:\\windows\\System32\\_zskwrkni04]\\SM_G\\XRAQR_DSF.exe"
"ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_"="c:\\windows\\system32\\_zskwrkni04tmv_i`msei`qzfi].exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,04,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,b9,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
"ef9de30d.exe"="C:\\Documents and Settings\\LocalService\\Local Settings\\Application Data\\ef9de30d.exe"
"ÿ_zskFSD_RQARX"="C:\\windows\\System32\\_zskwrkni04]\\SM_G\\XRAQR_DSF.exe"
"ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_"="c:\\windows\\system32\\_zskwrkni04tmv_i`msei`qzfi].exe"
"ÿ_zskJBC_DOMK"="C:\\windows\\System32\\_zskwrkni04UATFITX\\KMOD_CBJ.exe"
"shell"="\"C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\ibm00013.exe\""
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
"ef9de30d.exe"="C:\\Documents and Settings\\LocalService\\Local Settings\\Application Data\\ef9de30d.exe"
"ÿ_zskFSD_RQARX"="C:\\windows\\System32\\_zskwrkni04]\\SM_G\\XRAQR_DSF.exe"
"ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_"="c:\\windows\\system32\\_zskwrkni04tmv_i`msei`qzfi].exe"
"ÿ_zskJBC_DOMK"="C:\\windows\\System32\\_zskwrkni04UATFITX\\KMOD_CBJ.exe"
"shell"="\"C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\ibm00013.exe\""
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService


Contents of the 'Scheduled Tasks' folder
C:\windows\tasks\Norton AntiVirus - Scan my computer.job
C:\windows\tasks\Symantec NetDetect.job

Completion time: 2006-07-17 15:54:46.90
ComboFix ver 06.07.15 - This logfile is located at C:\ComboFix.txt



Logfile of HijackThis v1.99.1
Scan saved at 15:55:36, on 2006-07-17
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\csrss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\windows\System32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\windows\System32\WgaTray.exe
C:\Program Files\EzButton\CplBTQ00.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\windows\System32\ctfmon.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe
C:\PROGRA~1\GoGoData.com\GOGODA~1\ADBUST~1.EXE
C:\Program Files\GetRight\getright.exe
C:\Program Files\GetRight\getright.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\windows\explorer.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\windows\system32\NOTEPAD.EXE
C:\Documents and Settings\Ryan\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Foxie - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\Program Files\Foxie Suite\foxiecoreu.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\windows\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [CplBTQ00] "C:\Program Files\EzButton\CplBTQ00.EXE"
O4 - HKLM\..\Run: [CeEKEY] "C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe"
O4 - HKLM\..\Run: [LtMoh] "C:\Program Files\ltmoh\Ltmoh.exe"
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CeEPOWER] "C:\Program Files\TOSHIBA\Power Management\CePMTray.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TPNF] "C:\Program Files\TOSHIBA\TouchPad\TPTray.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pinger] "c:\toshiba\ivp\ism\pinger.exe" /run
O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\System32\ctfmon.exe
O4 - HKCU\..\Run: [GoogleAdBGone] C:\Program Files\GoogleAdBGone\GoogleAdBGone.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [GoGoTray.exe] "C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O9 - Extra button: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra 'Tools' menuitem: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra 'Tools' menuitem: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra 'Tools' menuitem: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra button: (no name) - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra 'Tools' menuitem: GoGoData AdBuster - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra 'Tools' menuitem: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1138189251421
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: interceptor.dll
O20 - Winlogon Notify: WgaLogon - C:\windows\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\windows\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\windows\dcmhelp.exe (file missing)
O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - Unknown owner - C:\Program Files\ProcessGuard\dcsuserprot.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\windows\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\windows\System32\HPHipm09.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Before we do any registry fixes, lets try this:

* Download AlcanShorty from here.
Click the download button below and agree to download the fix.
Download Alcanshorty to your desktop.
DoubleClick alcanshorty_en.exe and click install
This will create a new folder on your desktop called alcanshorty_en
Open that folder and doubleclick Run.bat
Once the fix starts, your icons and desktop will disappear, this is normal.
Make sure you have a working internet connection. In case your firewall gives an alert, don't block it,
because alcanshorty needs to download some additional files to let the tool run properly.
Wait for the complete script execution box to popup and press OK.
Press exit to terminate the BFU program.


Open the Combofix folder and doubleclick combo.exe
Follow the prompts.
Don't click on the window while the fix is running, because that will cause your system to hang.
When finished, it should produce a log, combofix.txt. Post this log in your next reply together with a new hijackthislog.
Start Time= 2006-07-17 19:38:58.57
Running from: C:\Documents and Settings\[removed]\Desktop

QuickScan did not find any signs of infected files

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-07-17 18:36:16 ( .D… ) "C:\Program Files\Common Files"
2006-07-15 21:00:20 ( .D… ) "C:\Program Files\Webroot"
2006-07-15 21:00:20 ( .D… ) "C:\Documents and Settings\Ryan\Application Data\Webroot"
2006-07-14 22:16:32 ( .D… ) "C:\Documents and Settings\Ryan\Application Data\Talkback"
2006-07-14 22:14:22 107132 ( A…. ) "C:\WINDOWS\UninstallFirefox.exe"
2006-07-07 16:54:10 252928 ( A…. ) "C:\WINDOWS\WRUninstall.dll"
2006-07-07 16:53:54 208896 ( A…. ) "C:\WINDOWS\system32\WRLogonNtf.dll"
2006-07-07 16:53:52 8704 ( A…. ) "C:\WINDOWS\system32\ssiefr.EXE"
2006-07-07 16:53:50 20992 ( A…. ) "C:\WINDOWS\system32\wrlzma.dll"
2006-06-28 23:00:14 16517680 ( A…. ) "C:\sp25s609vidx.exe"
2006-06-28 22:10:22 ( .D… ) "C:\Program Files\ProcessGuard"
2006-06-28 21:54:46 ( .D… ) "C:\Program Files\GoGoData.com"
2006-06-28 21:50:56 ( .D… ) "C:\Program Files\SpyCatcher 2006"
2006-06-26 09:36:08 ( .D… ) "C:\Program Files\CleanUp!"
2006-06-25 19:56:06 ( .D… ) "C:\Documents and Settings\Ryan\Application Data\AVG7"
2006-06-25 19:55:16 ( .D… ) "C:\Program Files\Grisoft"
2006-06-24 17:08:24 ( .D… ) "C:\Program Files\SpywareBlaster"
2006-06-23 07:29:38 ( .D… ) "C:\Program Files\Common Files\wqzk"
2006-06-23 07:29:30 8464 ( A…. ) "C:\WINDOWS\system32\sporder.dll"
2006-06-23 07:28:54 266240 ( A…. ) "C:\NNSCAA638.EXE"
2006-06-22 23:25:22 ( .D… ) "C:\Program Files\Silkroad"
2006-06-19 16:20:42 702768 ( ….. ) "C:\WINDOWS\system32\WgaLogon.dll"
2006-06-16 22:03:18 35040 ( A…. ) "C:\ssfvbnr.exe"
2006-06-16 22:00:50 12960 ( A…. ) "C:\qynbdil.exe"
2006-06-16 21:58:20 23360 ( A…. ) "C:\gvtrf.exe"
2006-06-15 23:06:48 185600 ( A…. ) "C:\visfx500.exe"
2006-06-15 22:45:46 38413 ( ..SH. ) "C:\WINDOWS\system32\rqrsspp.dll"
2006-06-15 00:00:16 33292 ( A…. ) "C:\WINDOWS\system32\eraseme_73048.exe"
2006-06-12 18:22:50 32942 ( A…. ) "C:\wincd3.exe"
2006-06-12 17:42:04 38413 ( ..SH. ) "C:\WINDOWS\system32\pmnmlii.dll"
2006-06-11 14:58:46 38413 ( ..SH. ) "C:\WINDOWS\system32\opnklkl.dll"
2006-06-10 20:29:18 38413 ( ..SH. ) "C:\WINDOWS\system32\nnnmlji.dll"
2006-06-10 19:18:38 38413 ( ..SH. ) "C:\WINDOWS\system32\fccbbcd.dll"
2006-06-10 18:08:18 38413 ( ..SH. ) "C:\WINDOWS\system32\yayabcd.dll"
2006-06-10 17:58:12 0 ( A…. ) "C:\WINDOWS\system32\fdhbe_58546.exe"
2006-06-10 00:55:26 38413 ( ..SH. ) "C:\WINDOWS\system32\iifddee.dll"
2006-06-10 00:14:14 38413 ( ..SH. ) "C:\WINDOWS\system32\ssqonmj.dll"
2006-06-09 19:45:30 8192 ( A…. ) "C:\WINDOWS\system32\iedriver.exexplore.exe"
2006-06-09 19:45:30 8192 ( A…. ) "C:\WINDOWS\system32\ddm_d.exe"
2006-06-09 19:45:30 8192 ( A…. ) "C:\WINDOWS\msxmlfilt.dll"
2006-06-09 19:45:28 8192 ( A…. ) "C:\WINDOWS\system32\johnwb.dll"
2006-06-09 19:45:28 8192 ( A…. ) "C:\WINDOWS\fsg_4203.exe"
2006-06-06 15:39:10 9640 ( ..SH. ) "C:\WINDOWS\system32\rqrsqnm.dll"
2006-06-05 06:36:16 17340 ( A…. ) "C:\WINDOWS\system32\fdhbe_76748.exe"
2006-06-05 06:21:44 38413 ( ..SH. ) "C:\WINDOWS\system32\nnnklif.dll"
2006-06-04 20:48:18 0 ( A…. ) "C:\WINDOWS\system32\eraseme_73757.exe"
2006-06-04 17:39:22 38413 ( ..SH. ) "C:\WINDOWS\system32\qomllmm.dll"
2006-06-04 16:46:56 38413 ( ..SH. ) "C:\WINDOWS\system32\cbxyxur.dll"
2006-06-03 19:38:56 38413 ( ..SH. ) "C:\WINDOWS\system32\fccyywu.dll"
2006-06-03 19:31:54 38413 ( ..SH. ) "C:\WINDOWS\system32\awtssqp.dll"
2006-06-03 19:19:02 38413 ( ..SH. ) "C:\WINDOWS\system32\tuvtstt.dll"
2006-06-03 16:29:54 16940 ( ..SH. ) "C:\WINDOWS\system32\vtutust.dll"
2006-06-03 16:16:04 9641 ( ..SH. ) "C:\WINDOWS\system32\ljjkhhg.dll"
2006-06-03 15:53:34 9640 ( ..SH. ) "C:\WINDOWS\system32\gebbcbb.dll"
2006-06-03 15:44:44 21321 ( ..SH. ) "C:\WINDOWS\system32\nnnnoop.dll"
2006-06-03 14:33:50 47117 ( A…. ) "C:\WINDOWS\isd.exe"
2006-06-03 10:38:04 120832 ( A…. ) "C:\ejke.exe"
2006-05-31 07:24:16 230168 ( A…. ) "C:\WINDOWS\system32\xactengine2_2.dll"
2006-05-31 07:22:42 63768 ( A…. ) "C:\WINDOWS\system32\dxdllreg.exe"
2006-05-30 21:53:50 120832 ( A…. ) "C:\eijefe.exe"
2006-05-30 05:24:58 61952 ( A…. ) "C:\ptamgum.exe"
2006-05-24 22:22:38 20480 ( A…. ) "C:\WINDOWS\system32\fdhbe_38375.exe"
2006-05-24 19:47:20 57856 ( A…. ) "C:\s2842p03.exe"
2006-05-22 06:09:22 0 ( A…. ) "C:\WINDOWS\system32\fdhbe_82335.exe"
2006-05-21 21:13:46 0 ( A…. ) "C:\WINDOWS\system32\fdhbe_74425.exe"
2006-05-19 21:35:10 0 ( A…. ) "C:\WINDOWS\system32\fdhbe_72474.exe"
2006-05-19 06:54:28 ( .D… ) "C:\Program Files\ImTOO"
2006-05-19 05:15:34 140288 ( A…. ) "C:\WINDOWS\system32\dnsapi.dll"
2006-05-19 05:15:34 83456 ( A…. ) "C:\WINDOWS\system32\iphlpapi.dll"
2006-05-19 05:15:34 70656 ( A…. ) "C:\WINDOWS\system32\ws2_32.dll"
2006-05-19 05:15:34 54272 ( A…. ) "C:\WINDOWS\system32\ipv6mon.dll"
2006-05-19 05:15:34 31232 ( A…. ) "C:\WINDOWS\system32\inetmib1.dll"
2006-05-19 05:15:34 13312 ( A…. ) "C:\WINDOWS\system32\wship6.dll"
2006-05-19 05:15:32 103936 ( A…. ) "C:\WINDOWS\system32\dhcpcsvc.dll"
2006-05-19 05:15:32 95232 ( A…. ) "C:\WINDOWS\system32\6to4svc.dll"
2006-05-19 01:51:02 159232 ( A…. ) "C:\WINDOWS\system32\xpob2res.dll"
2006-05-19 01:46:02 48640 ( A…. ) "C:\WINDOWS\system32\ipv6.exe"
2006-05-19 01:44:56 83456 ( A…. ) "C:\WINDOWS\system32\netsh.exe"
2006-05-14 02:13:42 364544 ( A…. ) "C:\WINDOWS\system32\ipsmsnap.dll"
2006-05-14 02:13:42 334848 ( A…. ) "C:\WINDOWS\system32\ipsecsnp.dll"
2006-05-14 02:13:42 257536 ( A…. ) "C:\WINDOWS\system32\oakley.dll"
2006-05-14 02:13:42 159744 ( A…. ) "C:\WINDOWS\system32\ipsecsvc.dll"
2006-05-14 02:13:42 98304 ( A…. ) "C:\WINDOWS\system32\polstore.dll"
2006-05-14 02:13:42 29184 ( A…. ) "C:\WINDOWS\system32\winipsec.dll"
2006-05-12 22:19:38 57344 ( A…. ) "C:\ejnn3.exe"
2006-05-07 14:43:36 0 ( A…. ) "C:\WINDOWS\system32\fdhbe_51541.exe"
2006-04-27 22:12:32 0 ( A…. ) "C:\WINDOWS\system32\fdhbe_13080.exe"
2006-04-24 20:47:46 108544 ( ..SHR ) "C:\WINDOWS\msinit.exe"
2005-07-05 09:23:34 233472 ( A…. ) "C:\Program Files\Uninstall Need2Find Bar.dll"


(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days )))))))))))))))))))))))))))))))))))))))))))


2006-07-15 21:00 8,704 C:\windows\system32\ssiefr.EXE
2006-07-15 21:00 684,032 C:\windows\libeay32.dll
2006-07-15 21:00 252,928 C:\windows\WRUninstall.dll
2006-07-15 21:00 208,896 C:\windows\system32\WRLogonNtf.dll
2006-07-15 21:00 20,992 C:\windows\system32\wrlzma.dll
2006-07-15 21:00 155,648 C:\windows\ssleay32.dll
2006-07-14 22:14 107,132 C:\windows\UninstallFirefox.exe
2006-07-03 15:10 535,875,584 C:\hiberfil.sys
2006-06-28 22:58 16,517,680 C:\sp25s609vidx.exe
2006-06-28 21:50 307,200 C:\windows\system32\InterceptHelper.dll
2006-06-28 21:50 180,224 C:\windows\system32\archlib.dll
2006-06-28 21:50 176,128 C:\windows\system32\Interceptor.dll
2006-06-26 14:05 180,224 C:\windows\system32\NVUNINST.EXE
2006-06-25 18:23 62,672 C:\windows\system32\xinput1_1.dll
2006-06-25 18:23 230,168 C:\windows\system32\xactengine2_2.dll
2006-06-25 18:23 229,584 C:\windows\system32\xactengine2_1.dll
2006-06-25 18:22 61,136 C:\windows\system32\xinput9_1_0.dll
2006-06-25 18:22 230,096 C:\windows\system32\xactengine2_0.dll
2006-06-25 18:22 2,388,176 C:\windows\system32\d3dx9_30.dll
2006-06-25 18:22 2,337,488 C:\windows\system32\d3dx9_25.dll
2006-06-25 18:22 2,332,368 C:\windows\system32\d3dx9_29.dll
2006-06-25 18:22 2,323,664 C:\windows\system32\d3dx9_28.dll
2006-06-25 18:22 2,319,568 C:\windows\system32\d3dx9_27.dll
2006-06-25 18:22 2,297,552 C:\windows\system32\d3dx9_26.dll
2006-06-25 18:22 14,032 C:\windows\system32\x3daudio1_0.dll
2006-06-25 18:21 2,222,800 C:\windows\system32\d3dx9_24.dll
2006-06-25 18:07 974,848 C:\windows\system32\dxdiag.exe
2006-06-25 18:07 797,184 C:\windows\system32\d3dim700.dll
2006-06-25 18:07 68,096 C:\windows\system32\dsdmoprp.dll
2006-06-25 18:07 63,768 C:\windows\system32\dxdllreg.exe
2006-06-25 18:07 57,856 C:\windows\system32\dpwsockx.dll
2006-06-25 18:07 53,248 C:\windows\system32\devenum.dll
2006-06-25 18:07 524,800 C:\windows\system32\qedit.dll
2006-06-25 18:07 47,104 C:\windows\system32\wstdecod.dll
2006-06-25 18:07 382,976 C:\windows\system32\qdvd.dll
2006-06-25 18:07 377,856 C:\windows\system32\dpnet.dll
2006-06-25 18:07 363,520 C:\windows\system32\dsound.dll
2006-06-25 18:07 354,816 C:\windows\system32\psisdecd.dll
2006-06-25 18:07 32,768 C:\windows\system32\dpnhpast.dll
2006-06-25 18:07 276,480 C:\windows\system32\qdv.dll
2006-06-25 18:07 265,728 C:\windows\system32\ddraw.dll
2006-06-25 18:07 230,400 C:\windows\system32\dplayx.dll
2006-06-25 18:07 22,016 C:\windows\system32\dpmodemx.dll
2006-06-25 18:07 203,264 C:\windows\system32\dpvoice.dll
2006-06-25 18:07 194,560 C:\windows\system32\mswebdvd.dll
2006-06-25 18:07 181,248 C:\windows\system32\dmime.dll
2006-06-25 18:07 177,152 C:\windows\system32\qcap.dll
2006-06-25 18:07 16,896 C:\windows\system32\msyuv.dll
2006-06-25 18:07 104,448 C:\windows\system32\dmusic.dll
2006-06-25 18:07 1,769,472 C:\windows\system32\dxdiagn.dll
2006-06-25 18:07 1,689,600 C:\windows\system32\d3d9.dll
2006-06-25 18:07 1,230,336 C:\windows\system32\msvidctl.dll
2006-06-25 18:07 1,189,888 C:\windows\system32\dx8vb.dll
2006-06-25 18:07 1,179,648 C:\windows\system32\d3d8.dll
2006-06-24 17:08 118,784 C:\windows\system32\MSSTDFMT.DLL
2006-06-23 07:29 8,464 C:\windows\system32\sporder.dll
2006-06-23 07:28 266,240 C:\NNSCAA638.EXE
2006-06-19 16:20 702,768 C:\windows\system32\WgaLogon.dll
2006-06-16 22:02 35,040 C:\ssfvbnr.exe
2006-06-16 21:58 12,960 C:\qynbdil.exe
2006-06-16 21:57 23,360 C:\gvtrf.exe
2006-06-16 05:40 47,117 C:\windows\isd.exe
2006-06-15 22:53 185,600 C:\visfx500.exe
2006-06-15 22:45 38,413 C:\windows\system32\rqrsspp.dll
2006-06-14 23:56 33,292 C:\windows\system32\eraseme_73048.exe
2006-06-12 18:20 32,942 C:\wincd3.exe
2006-06-12 17:42 38,413 C:\windows\system32\pmnmlii.dll
2006-06-11 14:58 38,413 C:\windows\system32\opnklkl.dll
2006-06-10 20:29 38,413 C:\windows\system32\nnnmlji.dll
2006-06-10 19:18 38,413 C:\windows\system32\fccbbcd.dll
2006-06-10 18:08 38,413 C:\windows\system32\yayabcd.dll
2006-06-10 17:58 0 C:\windows\system32\fdhbe_58546.exe
2006-06-10 00:55 38,413 C:\windows\system32\iifddee.dll
2006-06-10 00:14 38,413 C:\windows\system32\ssqonmj.dll
2006-06-08 16:33 0 C:\windows\system32\mswinf32.exe
2006-06-06 15:39 9,640 C:\windows\system32\rqrsqnm.dll
2006-06-05 06:33 17,340 C:\windows\system32\fdhbe_76748.exe
2006-06-05 06:21 38,413 C:\windows\system32\nnnklif.dll
2006-06-04 20:48 0 C:\windows\system32\eraseme_73757.exe
2006-06-04 17:39 38,413 C:\windows\system32\qomllmm.dll
2006-06-04 16:46 38,413 C:\windows\system32\cbxyxur.dll
2006-06-03 19:38 38,413 C:\windows\system32\fccyywu.dll
2006-06-03 19:31 38,413 C:\windows\system32\awtssqp.dll
2006-06-03 19:19 38,413 C:\windows\system32\tuvtstt.dll
2006-06-03 16:29 16,940 C:\windows\system32\vtutust.dll
2006-06-03 16:16 9,641 C:\windows\system32\ljjkhhg.dll
2006-06-03 15:53 9,640 C:\windows\system32\gebbcbb.dll
2006-06-03 15:44 21,321 C:\windows\system32\nnnnoop.dll
2006-06-02 16:22 120,832 C:\ejke.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="\"RUNDLL32.EXE\" C:\\windows\\System32\\NvCpl.dll,NvStartup"
"nwiz"="\"nwiz.exe\" /install"
"CplBTQ00"="\"C:\\Program Files\\EzButton\\CplBTQ00.EXE\""
"CeEKEY"="\"C:\\Program Files\\TOSHIBA\\E-KEY\\CeEKey.exe\""
@=""
"LtMoh"="\"C:\\Program Files\\ltmoh\\Ltmoh.exe\""
"CpRmtKey"="\"C:\\Program Files\\Toshiba Controls\\CpRmtKey.EXE\""
"CeEPOWER"="\"C:\\Program Files\\TOSHIBA\\Power Management\\CePMTray.exe\""
"ezShieldProtector for Px"="C:\\WINDOWS\\System32\\ezSP_Px.exe"
"TPNF"="\"C:\\Program Files\\TOSHIBA\\TouchPad\\TPTray.exe\""
"ccRegVfy"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe\""
"Pinger"="\"c:\\toshiba\\ivp\\ism\\pinger.exe\" /run"
"RealTray"="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" SYSTEMBOOTHIDEPLAYER"
"Symantec NetDriver Monitor"="\"C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe\" /Consumer"
"MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"LVCOMSX"="C:\\WINDOWS\\System32\\LVCOMSX.EXE"
"LogitechVideoRepair"="\"C:\\Program Files\\Logitech\\Video\\ISStart.exe\" "
"LogitechVideoTray"="\"C:\\Program Files\\Logitech\\Video\\LogiTray.exe\""
"HPDJ Taskbar Utility"="C:\\windows\\System32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"ÿ_zskFSD_RQARX"="C:\\windows\\System32\\_zskwrkni04]\\SM_G\\XRAQR_DSF.exe"
"ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_"="c:\\windows\\system32\\_zskwrkni04tmv_i`msei`qzfi].exe"
"SpyCatcher Reminder"="\"C:\\Program Files\\SpyCatcher 2006\\SpyCatcher.exe\" reminder"
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe\" /startintray"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\windows\\System32\\ctfmon.exe"
"GoogleAdBGone"="C:\\Program Files\\GoogleAdBGone\\GoogleAdBGone.exe"
"MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\" /WinStart"
"Yahoo! Pager"="\"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\ypager.exe\" -quiet"
"LogitechSoftwareUpdate"="\"C:\\Program Files\\Logitech\\Video\\ManifestEngine.exe\" boot"
"ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_"="c:\\windows\\system32\\_zskwrkni04tmv_i`msei`qzfi].exe"
"GoGoTray.exe"="\"C:\\Program Files\\GoGoData.com\\GoGoData Toolbar\\GoGoTray.exe\""
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"ÿ_zskFSD_RQARX"="C:\\windows\\System32\\_zskwrkni04]\\SM_G\\XRAQR_DSF.exe"
"ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_"="c:\\windows\\system32\\_zskwrkni04tmv_i`msei`qzfi].exe"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,04,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,b9,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
"ef9de30d.exe"="C:\\Documents and Settings\\LocalService\\Local Settings\\Application Data\\ef9de30d.exe"
"ÿ_zskFSD_RQARX"="C:\\windows\\System32\\_zskwrkni04]\\SM_G\\XRAQR_DSF.exe"
"ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_"="c:\\windows\\system32\\_zskwrkni04tmv_i`msei`qzfi].exe"
"ÿ_zskJBC_DOMK"="C:\\windows\\System32\\_zskwrkni04UATFITX\\KMOD_CBJ.exe"
"shell"="\"C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\ibm00013.exe\""
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
"ef9de30d.exe"="C:\\Documents and Settings\\LocalService\\Local Settings\\Application Data\\ef9de30d.exe"
"ÿ_zskFSD_RQARX"="C:\\windows\\System32\\_zskwrkni04]\\SM_G\\XRAQR_DSF.exe"
"ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_"="c:\\windows\\system32\\_zskwrkni04tmv_i`msei`qzfi].exe"
"ÿ_zskJBC_DOMK"="C:\\windows\\System32\\_zskwrkni04UATFITX\\KMOD_CBJ.exe"
"shell"="\"C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\ibm00013.exe\""
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService


Contents of the 'Scheduled Tasks' folder
C:\windows\tasks\Norton AntiVirus - Scan my computer.job
C:\windows\tasks\Symantec NetDetect.job

Completion time: 2006-07-17 19:50:47.18
ComboFix ver 06.07.15 - This logfile is located at C:\ComboFix.txt

ComboFix.2006-07-17.193858.txt



Logfile of HijackThis v1.99.1
Scan saved at 21:35:43, on 2006-07-17
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\csrss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\windows\System32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\windows\System32\WgaTray.exe
C:\Program Files\EzButton\CplBTQ00.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\windows\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe
C:\PROGRA~1\GoGoData.com\GOGODA~1\ADBUST~1.EXE
C:\Program Files\GetRight\getright.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Foxie Suite\Firewall.exe
C:\toshiba\ivp\ism\ivpsvmgr.exe
C:\windows\explorer.exe
C:\Documents and Settings\Ryan\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Foxie - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\Program Files\Foxie Suite\foxiecoreu.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\windows\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [CplBTQ00] "C:\Program Files\EzButton\CplBTQ00.EXE"
O4 - HKLM\..\Run: [CeEKEY] "C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe"
O4 - HKLM\..\Run: [LtMoh] "C:\Program Files\ltmoh\Ltmoh.exe"
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CeEPOWER] "C:\Program Files\TOSHIBA\Power Management\CePMTray.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TPNF] "C:\Program Files\TOSHIBA\TouchPad\TPTray.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pinger] "c:\toshiba\ivp\ism\pinger.exe" /run
O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\System32\ctfmon.exe
O4 - HKCU\..\Run: [GoogleAdBGone] C:\Program Files\GoogleAdBGone\GoogleAdBGone.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [GoGoTray.exe] "C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O9 - Extra button: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra 'Tools' menuitem: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra 'Tools' menuitem: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra 'Tools' menuitem: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra button: (no name) - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra 'Tools' menuitem: GoGoData AdBuster - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra 'Tools' menuitem: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1138189251421
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: interceptor.dll
O20 - Winlogon Notify: WgaLogon - C:\windows\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\windows\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\windows\dcmhelp.exe (file missing)
O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - Unknown owner - C:\Program Files\ProcessGuard\dcsuserprot.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\windows\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\windows\System32\HPHipm09.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
If you know what any of these programs are like: C:\WINDOWS\system32\fdhbe_38375.exe remove them from this list to be deleted.

Download & launch KillBox v2.0.0.175.exe (it's important that you get version v2.0.0.175)


Select the following option - delete on Reboot
Use your mouse to select all the filenames listed below & then right-click & select Copy

C:\NNSCAA638.EXE
C:\ssfvbnr.exe
C:\qynbdil.exe
C:\gvtrf.exe
C:\visfx500.exe
C:\WINDOWS\system32\rqrsspp.dll
C:\WINDOWS\system32\eraseme_73048.exe
C:\wincd3.exe
C:\WINDOWS\system32\pmnmlii.dll
C:\WINDOWS\system32\opnklkl.dll
C:\WINDOWS\system32\fccbbcd.dll
C:\WINDOWS\system32\yayabcd.dll
C:\WINDOWS\system32\fdhbe_58546.exe
C:\WINDOWS\system32\iifddee.dll
C:\WINDOWS\system32\ssqonmj.dll
C:\WINDOWS\system32\iedriver.exexplore.exe
C:\WINDOWS\system32\ddm_d.exe
C:\WINDOWS\msxmlfilt.dll
C:\WINDOWS\system32\johnwb.dll
C:\WINDOWS\fsg_4203.exe
C:\WINDOWS\system32\rqrsqnm.dll
C:\WINDOWS\system32\fdhbe_76748.exe
C:\WINDOWS\system32\nnnklif.dll
C:\WINDOWS\system32\eraseme_73757.exe
C:\WINDOWS\system32\qomllmm.dll
C:\WINDOWS\system32\cbxyxur.dll
C:\WINDOWS\system32\fccyywu.dll
C:\WINDOWS\system32\awtssqp.dll
C:\WINDOWS\system32\tuvtstt.dll
C:\WINDOWS\system32\vtutust.dll
C:\WINDOWS\system32\ljjkhhg.dll
C:\WINDOWS\system32\gebbcbb.dll
C:\WINDOWS\system32\nnnnoop.dll
C:\ejke.exe
C:\eijefe.exe
C:\ptamgum.exe
C:\WINDOWS\system32\fdhbe_38375.exe
C:\WINDOWS\system32\fdhbe_82335.exe
C:\WINDOWS\system32\fdhbe_74425.exe
C:\WINDOWS\system32\fdhbe_72474.exe
C:\WINDOWS\msinit.exe
C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe


* Go to the File menu, and choose Paste from Clipboard
* Click the RED X button.
* Click Yes at the Delete on Reboot prompt.
* Click Yes at the 'Pending Operations prompt'.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, download and run missingfilesetup.exe Then try Killbox again.


"copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
The laptop has stopped restarting and I am able to stay connected to the internet. The computer has also gotten faster.


Logfile of HijackThis v1.99.1
Scan saved at 18:11:37, on 2006-07-23
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\csrss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\windows\System32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\windows\System32\WgaTray.exe
C:\windows\Explorer.EXE
C:\Program Files\EzButton\CplBTQ00.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\windows\System32\ctfmon.exe
C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\GoGoData.com\GOGODA~1\ADBUST~1.EXE
C:\Program Files\GetRight\getright.exe
C:\Program Files\GetRight\getright.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\toshiba\ivp\ism\ivpsvmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Foxie Suite\Firewall.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ryan\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Foxie - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\Program Files\Foxie Suite\foxiecoreu.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\windows\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [CplBTQ00] "C:\Program Files\EzButton\CplBTQ00.EXE"
O4 - HKLM\..\Run: [CeEKEY] "C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe"
O4 - HKLM\..\Run: [LtMoh] "C:\Program Files\ltmoh\Ltmoh.exe"
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CeEPOWER] "C:\Program Files\TOSHIBA\Power Management\CePMTray.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TPNF] "C:\Program Files\TOSHIBA\TouchPad\TPTray.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pinger] "c:\toshiba\ivp\ism\pinger.exe" /run
O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\System32\ctfmon.exe
O4 - HKCU\..\Run: [GoogleAdBGone] C:\Program Files\GoogleAdBGone\GoogleAdBGone.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [GoGoTray.exe] "C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O9 - Extra button: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra 'Tools' menuitem: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra 'Tools' menuitem: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra 'Tools' menuitem: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra button: (no name) - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra 'Tools' menuitem: GoGoData AdBuster - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra 'Tools' menuitem: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1138189251421
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: interceptor.dll
O20 - Winlogon Notify: WgaLogon - C:\windows\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\windows\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\windows\dcmhelp.exe (file missing)
O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - Unknown owner - C:\Program Files\ProcessGuard\dcsuserprot.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\windows\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\windows\System32\HPHipm09.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI