This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer dead - Vundo behavior but no Vundo detected. Please help!

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help, I can't start my computer!

Explorer.exe eats 99% of processor on boot, startup does not complete. This happens in safe mode, too. I've run every malware/virus checker around (ewido, spybot, mcaffee). McAffee found Vundo and cleaned it. The system continues to behave in the same way, but now no Vundo can be found. I've run the latest VundoFix.exe, and Symantec's FixVundo, and both come up blank. HijackThis log looks very clean. Yet the only way I can do anything is to shut down the explorer.exe process.

Can anyone please help me with the next step???

Thanks a lot in advance!

–

Logfile of HijackThis v1.99.1
Scan saved at 3:06:56 PM, on 7/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.computers.us.fujitsu.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATSwpNav] "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LoadFUJ02E3] C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Startup: YPOPs.lnk = C:\Program Files\YPOPs\ypops.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.computers.us.fujitsu.com/
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
Do me a favour. Rename Hiackthis.exe to something like hjtviewer.exe and then scan and post a new log. There is a new vundo infection that actually hides in hijackthis if it sees the hijackthis executionable file.
Thanks for the reply. Here's a renamed executable:

Logfile of HijackThis v1.99.1
Scan saved at 5:53:05 PM, on 7/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\HijacThi\hjchecker.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.computers.us.fujitsu.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATSwpNav] "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LoadFUJ02E3] C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [FJUPDNV_Chitose] C:\Program Files\Fujitsu\fjdvrupd\fjdvrupd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Startup: YPOPs.lnk = C:\Program Files\YPOPs\ypops.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.computers.us.fujitsu.com/
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols3/fscax.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
Please do an online scan with Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post as well as a bew hijackthis log please.
Kaspersky didn't find or clean anything. It found mirc and vnc, both of which I'd installed a long time ago. Everything else registers clean, with this and all other on and offline scanners I've tried. Here's the kaspersky log: ——————————————————————————- KASPERSKY ON-LINE SCANNER REPORT Monday, July 17, 2006 9:13:35 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky On-line Scanner version: 5.0.78.0 Kaspersky Anti-Virus database last update: 18/07/2006 Kaspersky Anti-Virus database records: 208020 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 101135 Number of viruses found: 3 Number of infected objects: 6 Number of suspicious objects: 0 Duration of the scan process: 01:22:00 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\Ben\My Documents\_Downloaded\mirc612.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.612 skipped C:\Documents and Settings\Ben\My Documents\_Downloaded\mirc612.exe mIRC: infected - 1 skipped C:\Documents and Settings\Ben\My Documents\_Downloaded\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped C:\Documents and Settings\Ben\My Documents\_Downloaded\mirc616.exe mIRC: infected - 1 skipped C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped Scan process completed.
  • Download FindIt NT-2K-XP.
  • Unzip the contents of FindIt NT-2K-XP.zip to a convenient location.
  • Navigate to the FindIt NT-2K-XP directory.
  • Double-click on FindNarrator.bat and wait for it to run. It will take several minuites. (at least 10)
  • It should open a Notepad window with the FindNarrator log.
  • Post the contents of FindNarrator.txt into your next post.
Hi, thanks for bearing with me so far. The whole story started when I ill-advisedly ran an executable that Avast! AV pronounced as clean. As soon as I ran it, Avast detected a virus, but by then it was too late. This was some kind of downloader, and it filled my whole system up with all kinds of malware. I cleaned it using all the AV and spyware software at my disposal. Then, I ran SmitfraudFix to fix one piece of malware, and the current behavior began (explorer.exe at 99%, startup never finishes, have to kill explorer process to do anything else). After that, I installed McAffee, which found a few more trojans, one of them being Vundo. It cleaned most of them up, and I cleaned a couple manually. Since then, nothing is detected by any scanning software, but the problematic behavior persists. There are no other errors, popups, etc, but XP just won't finish starting up, so I'll have to format unless we figure it out. Here are all the logs you asked for. Unfortunately, I can't find the logs from when all the virii were cleaned. FindNarrator doesn't seem to find anything interesting. I've also run WinPFind, with no interesting results, rootkitrevealer (nothing), and other stuff. Could something in the process when I removed all that malware have caused my system to go haywire? Is it at all possible that there's no malware anymore, only some remnant that screws up explorer.exe? Thanks for your help! —————- FindNarrator NT-2K-XP —————- Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. ***** Operating System ***** Microsoft Windows XP Professional 5.1 Service Pack 2 (Build 2600) ********* Date/Time ******** Tuesday, July 18, 2006 (7/18/2006) 1:33 PM, Pacific Daylight Time *********** Path *********** FindNarrator.bat is running from: C:\Documents and Settings\[removed]\Desktop\FindIt NT-2K-XP\FindIt NT-2K-XP —————- Strings.exe Qoologic Results —————- —————- Strings.exe Aspack Results —————- C:\WINDOWS\system32\d3dx9_25.dll: D3DXUVAtlasPack C:\WINDOWS\system32\d3dx9_26.dll: D3DXUVAtlasPack C:\WINDOWS\system32\d3dx9_27.dll: D3DXUVAtlasPack C:\WINDOWS\system32\d3dx9_28.dll: D3DXUVAtlasPack C:\WINDOWS\system32\MRT.exe: (ASPack) C:\WINDOWS\system32\MRT.exe: (AsPack2k) C:\WINDOWS\system32\MRT.exe: ASPack2000 C:\WINDOWS\system32\MRT.exe: (Aspack %s) C:\WINDOWS\system32\MRT.exe: ASPack 1.61 C:\WINDOWS\system32\MRT.exe: ASPack 1.084 C:\WINDOWS\system32\MRT.exe: ASPack 1.083 C:\WINDOWS\system32\MRT.exe: ASPack 1.08.02b C:\WINDOWS\system32\MRT.exe: ASPack 1.07b C:\WINDOWS\system32\MRT.exe: ASPack 1.05b C:\WINDOWS\system32\MRT.exe: ASPack 1.02 C:\WINDOWS\system32\MRT.exe: ASPACK C:\WINDOWS\system32\MRT.exe: aspACK C:\WINDOWS\system32\MRT.exe: aspACK C:\WINDOWS\system32\MRT.exe: aspACK C:\WINDOWS\system32\MRT.exe: aspACK C:\WINDOWS\system32\MRT.exe: aspACK C:\WINDOWS\system32\MRT.exe: aspACK C:\WINDOWS\system32\MRT.exe: aspACK C:\WINDOWS\system32\MRT.exe: aspACK C:\WINDOWS\system32\ntdll.dll: .aspack —————- Active Setup Installed Components —————- ! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{05466845-FF44-4671-92C1-A5FD0F9EEE1C} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{10072CEC-8CC1-11D1-986E-00A0C955B42F} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{233C1507-6A77-46A4-9443-F871F945D258} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{283807B5-2C60-11D0-A31D-00AA00B92C03} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2A202491-F00D-11cf-87CC-0020AFEECF20} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{36f8ec70-c29a-11d1-b5c7-0000f8051515} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3bf42070-b3b1-11d1-b5c5-0000f8051515} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3F62EDE2-6D4F-427B-079A-70FD3182ED20} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{411EDCF7-755D-414E-A74B-3DCD6583F589} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4278c270-a269-11d1-b5bf-0000f8051515} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4b218e3e-bc98-4770-93d3-2731b9329278} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f216970-c90c-11d1-b5c7-0000f8051515} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5A8D6EE0-3E18-11D0-821E-444553540000} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8b15971b-5355-4c82-8c07-7e181ea07608} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8EFA4753-7169-4CC3-A28B-0A1643B8A39B} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{94de52c8-2d59-4f1b-883e-79663d2d9a8c} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CC2A9BA0-3BDD-11D0-821E-444553540000} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{D27CDB6E-AE6D-11cf-96B8-444553540000} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{F97D1BFD-D512-1EEE-C200-F06FED10DD83} —————- Context Menu Handlers —————- REGEDIT4 [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers] [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido anti-spyware] @="{8934FCEF-F5B8-468f-951F-78A921CD3920}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files] @="{750fdf0e-2a26-11d1-a3ea-080036587f03}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With] @="{09799AFB-AD67-11d1-ABCD-00C04FC30936}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu] @="{A470F8CF-A1E8-4f65-8335-227475AA5C46}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\VirusScan] @="{cda2863e-2497-4c49-9b89-06840e070a87}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinRAR] @="{B41DB860-8EE4-11D2-9906-E49FADC173CA}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}] @="Start Menu Pin" —————- Run Key —————- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATSwpNav"="\"C:\\Program Files\\Fingerprint Sensor\\ATSwpNav\" -run" "IndicatorUtility"="C:\\Program Files\\Fujitsu\\Fujitsu Hotkey Utility\\IndicatorUty.exe" "LoadFUJ02E3"="C:\\Program Files\\Fujitsu\\FUJ02E3\\FUJ02E3.exe" "LoadFujitsuQuickTouch"="C:\\Program Files\\Fujitsu\\Application Panel\\QuickTouch.exe" "LoadBtnHnd"="C:\\Program Files\\Fujitsu\\BtnHnd\\BtnHnd.exe" "BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent" "igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe" "ShStatEXE"="\"C:\\Program Files\\Network Associates\\VirusScan\\SHSTAT.EXE\" /STANDALONE" "McAfeeUpdaterUI"="\"C:\\Program Files\\Network Associates\\Common Framework\\UpdaterUI.exe\" /StartedFromRunKey" "Network Associates Error Reporting Service"="\"C:\\Program Files\\Common Files\\Network Associates\\TalkBack\\TBMon.exe\"" "FJUPDNV_Chitose"="C:\\Program Files\\Fujitsu\\fjdvrupd\\fjdvrupd.exe" "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_07\\bin\\jusched.exe" "RTHDCPL"="RTHDCPL.EXE" "itype"="\"C:\\Program Files\\Microsoft IntelliType Pro\\itype.exe\"" "igfxpers"="C:\\WINDOWS\\system32\\igfxpers.exe" "igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe" "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe" "Alcmtr"="ALCMTR.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" —————- FindNarrator NT-2K-XP —————- 
Download MicroWorld virus scan here >>> Micro World http://www.mwti.net/antivirus/free_utilities.asp

To run the virus scan make sure you click the following

memory, registry, startup folders, system folders, services, drive (all drives will be added) then click on scan clean. When the scan is complete hilight all the files in the LOWER box. Then ctrl + c and paste them into the thread ctrl + v.

I warn you the scan will take a long time to run and will not fix anything just identifies bad files.
It says it found zlob, but I don't see evidence of its activity, and the symptoms are not like zlob at all. Otherwise, I don't see anything that could be causing this…. Object "powerstrip Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "zlob Trojan-Downloader" found in File System! Action Taken: No Action Taken. Object "abetterinternet.aurora Adware" found in File System! Action Taken: No Action Taken. Object "speer Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "abetterinternet.aurora Adware" found in File System! Action Taken: No Action Taken. Object "abetterinternet.aurora Adware" found in File System! Action Taken: No Action Taken. Object "abetterinternet.aurora Adware" found in File System! Action Taken: No Action Taken. Object "speer Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "speer Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "speer Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "powerstrip Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smitfraud Browser Hijacker" found in File System! Action Taken: No Action Taken. Object "powerstrip Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smitfraud Browser Hijacker" found in File System! Action Taken: No Action Taken. Object "zlob Trojan-Downloader" found in File System! Action Taken: No Action Taken. Object "abetterinternet.aurora Adware" found in File System! Action Taken: No Action Taken. Object "speer Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "abetterinternet.aurora Adware" found in File System! Action Taken: No Action Taken. Object "abetterinternet.aurora Adware" found in File System! Action Taken: No Action Taken. Object "abetterinternet.aurora Adware" found in File System! Action Taken: No Action Taken. Object "speer Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "speer Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "speer Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "xrenoder Spyware/Adware" found in File System! Action Taken: No Action Taken. Entry "HKCR\Adobe.Illustrator.dwg" refers to invalid object "{C0ED15F0-61BB-11d3-B6CA-00C04F6A0D06}". Action Taken: No Action Taken. Entry "HKCR\Adobe.Illustrator.dxf" refers to invalid object "{C0ED15F0-61BB-11d3-B6CA-00C04F6A0D06}". Action Taken: No Action Taken. Entry "HKCR\Adobe.Illustrator.pict" refers to invalid object "{C0ED15F0-61BB-11d3-B6CA-00C04F6A0D06}". Action Taken: No Action Taken. Entry "HKCR\ComPlusMetaData.MsCorHost" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken. Entry "HKCR\ComPlusMetaData.MsCorHost.2" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken. Entry "HKCR\DSP.DSP" refers to invalid object "{9C123EA9-AEC9-4f75-BBC0-7565FA1398966}". Action Taken: No Action Taken. Entry "HKCR\igfxsrvc.CUIService" refers to invalid object "{0F195FA1-CCF0-11D2-8B20-00A0C93CB1F4}". Action Taken: No Action Taken. Entry "HKCR\ITIR.NumberNormalizer.3" refers to invalid object "{3F2D0A36-5CBF-137B-223A-51A2DEE47F3E}". Action Taken: No Action Taken. Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\PhotoshopElements.Application" refers to invalid object "{5BDDE329-543B-411b-A14C-5EB01519338B}". Action Taken: No Action Taken. Entry "HKCR\PhotoshopElements.Application.4" refers to invalid object "{a1093992-8beb-4307-943b-3ff7023ad1e2}". Action Taken: No Action Taken. Entry "HKCR\PhotoshopElements.Image" refers to invalid object "{A34E12B1-8241-44b9-AE21-928CFD72817A}". Action Taken: No Action Taken. Entry "HKCR\PhotoshopElements.Image.4" refers to invalid object "{A34E12B1-8241-44b9-AE21-928CFD72817A}". Action Taken: No Action Taken. Entry "HKCR\SymWriter.pdb" refers to invalid object "{520DC67A-752E-11D3-8D56-00C04F680B2B}". Action Taken: No Action Taken. Entry "HKCR\WMP.CatalogServer.1" refers to invalid object "{16E2D4F7-2935-4A66-DB4B-B57CB0CB1216}". Action Taken: No Action Taken. Entry "HKCR\WMSServer.Server" refers to invalid object "{845FB959-4279-11D2-BF23-00805FBE84A6}". Action Taken: No Action Taken. Entry "HKCR\WMSServer.Server.9" refers to invalid object "{845FB959-4279-11D2-BF23-00805FBE84A6}". Action Taken: No Action Taken. Entry "HKCR\YAZZLEACTIVEX.YazzleActiveXCtrl.1" refers to invalid object "{74CD40EA-EF77-4BAD-808A-B5982DA73F20}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\YazzleActiveX.ocx". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\pxwma.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\CoverDesigner\covered-deu.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\CoverDesigner\covered-jpn.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Deu.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Jpn.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\InterVideo\Common\Bin\IVIPromotion.exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\YazzleActiveX.ocx". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\DIMM.DLL". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe" refers to invalid object "C:\WINDOWS\system32\cmmgr32.exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\HijackThis.exe" refers to invalid object "C:\HijacThi\hijackthis.exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\yourapp.Exe" refers to invalid object "C:\Program Files\Oni\yourapp.Exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Fujitsu Driver Update\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\GlobalSCAPE\CuteFTP Home\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\GlobalSCAPE\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Adobe\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\iTunes\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Ben\Start Menu\Programs\palmOne\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Salling Clicker\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\PowerQuest PartitionMagic 8.0\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\PowerQuest PartitionMagic 8.0\PartitionMagic 8.0 Tools\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\PowerQuest PartitionMagic 8.0\PartitionMagic 8.0 Documentation\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Powertoys for Windows XP\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Windows Media\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Windows Media\Utilities\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Keyboard\". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".001". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".adr". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".bak". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".cbr". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".crd". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".in". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".met". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".p2p". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".r54". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".tab". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".tmp". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".xpi". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "ffdshow". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Google Desktop". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "InterActual Player". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "LiveReg". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Mozilla Firefox (1.5)". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Mozilla Firefox (1.5.0.2)". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Mozilla Firefox (1.5.0.3)". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "New.net". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "QuickTime". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "SizeExplorer Pro 3.3_is1". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{1526D87C-A955-4FAB-BF18-697BA457E352}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{2B257128-0B59-4A88-AFDF-BE12E5F5B9A0}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{2B257128-0B59-4A88-AFDF-BE12E5F5B9A1}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{607EC8AE-B5AD-4240-A267-E8BA50AA16A4}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{81CFF79E-04E6-41BC-B4FA-D2FF4DE58A15}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{8997F2E8-9CA1-44FF-9DAD-D3E5EB4B41F7}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{B6912B4B-C8E9-4B83-A16F-7D753FE3590E}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{B6F867E8-F092-4C5E-7D72-AC7057DBEF45}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{B901999B-27BF-46D1-8F53-5497FC957F29}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{C6F1E87D-F3E1-4874-97EC-F87DAB6D6878}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{E9F81423-211E-46B6-9AE0-38568BC5CF6F}". Action Taken: No Action Taken. File C:\Documents and Settings\Ben\My Documents\_Downloaded\mirc612.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.612. No Action Taken. File C:\Documents and Settings\Ben\My Documents\_Downloaded\mirc616.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken. File C:\Program Files\mIRC\mirc.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken. File C:\Program Files\RealVNC\VNC4\wm_hooks.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.4. No Action Taken.
Download Blacklight Beta from here:
http://www.f-secure.com/blacklight/try.shtml
Hit I accept. It will take you to download page.
Download blbeta.exe and save it to the Desktop.
Once saved… double click blbeta.exe to install the program.
Click accept agreement and Click scan
This app too may fire off a warning from antivirus. Let the driver load.
Wait for it to finish.
If it displays any items…don't do anything with them yet. Just hit exit (close)
It will drop a log on Desktop that starts with fsbl….big number
Please post contents of log.
Nada. – 07/19/06 14:42:14 [Info]: BlackLight Engine 1.0.42 initialized 07/19/06 14:42:14 [Info]: OS: 5.1 build 2600 (Service Pack 2) 07/19/06 14:42:14 [Note]: 7019 4 07/19/06 14:42:14 [Note]: 7005 0 07/19/06 14:42:17 [Note]: 7006 0 07/19/06 14:42:17 [Note]: 7011 2728 07/19/06 14:42:17 [Note]: 7026 0 07/19/06 14:42:18 [Note]: 7026 0 07/19/06 14:42:23 [Note]: FSRAW library version 1.7.1019 07/19/06 14:48:45 [Error]: 6019 0 07/19/06 14:48:55 [Note]: 7007 0
Lets use windows sfc (system file checker) You'd need your XP CD to make this work. Click Start> Run> type sfc /scannow (Note that there is a space between sfc and /scannow) This will repair any bad windows files Then reboot and a new log please.
No change. Not a windows file, I guess. New log:

Logfile of HijackThis v1.99.1
Scan saved at 8:40:30 PM, on 7/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\HijacThi\hjchecker.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.computers.us.fujitsu.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATSwpNav] "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LoadFUJ02E3] C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [FJUPDNV_Chitose] C:\Program Files\Fujitsu\fjdvrupd\fjdvrupd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Startup: YPOPs.lnk = C:\Program Files\YPOPs\ypops.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.computers.us.fujitsu.com/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols3/fscax.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
Please do not delete anything unless instructed to.


Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

[external image: Posted Image]

______________________________

Next:
Download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
    ______________________________

    Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter

    [external image: Posted Image]

    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. It will create a file named: c:\rapport.txt

    We suggest you stop at this point and post a HijackThis log along with the contents of the c:\rapport.txt


    IMPORTANT: Do NOT run any other options until you are asked to do so!

    Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
Sorry, still nothing. Smitfraudfix found nothing wrong, and Ewido only found tracking cookies. Argh! What could it possibly be?!?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI