This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need help fast

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I completed everything. I was unable to find or delete the following folders and files:


C:\Program Files\Bargain Buddy
C:\Program Files\IMESH
C:\Program Files\NewDotNet
C:\Program Files\Common Files\CMEII
C:\Program Files\Common Files\GMT

C:\WINDOWS\desktop.html
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GStartup.lnk
C:\Program Files\Messenger\mebe.html
C:\Program Files\Carbon Copy Support\podowimy.html

I was also unable to uninstall these programs:

1.)IMESH
2.)Bargain Buddy
3.)NewdotNet or New.Net I did run the uninstaller, so I am assuming that it is gone.


My computer is still slow, but I did get my background fixed so that I can change it. For some reason, starting up and restarting my computer takes forever. Openning programs also takes some time.

Blacklight Report
*****************************************************************************
09/19/06 23:12:11 [Info]: BlackLight Engine 1.0.46 initialized
09/19/06 23:12:11 [Info]: OS: 5.1 build 2600 (Service Pack 1)
09/19/06 23:12:11 [Note]: 7019 4
09/19/06 23:12:11 [Note]: 7005 0
09/19/06 23:12:15 [Note]: 7006 0
09/19/06 23:12:15 [Note]: 7022 0
09/19/06 23:12:15 [Note]: 7011 1484
09/19/06 23:12:16 [Note]: 7026 0
09/19/06 23:12:16 [Note]: 7026 0
09/19/06 23:12:16 [Note]: FSRAW library version 1.7.1019
09/20/06 21:36:38 [Note]: 7007 0
*********************************************************************************

Fresh HJT Log
*********************************************************************************
Logfile of HijackThis v1.99.1
Scan saved at 10:01:57 PM, on 9/20/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\Program Files\Cyberhawk\CHService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Ewido Anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Cyberhawk\CHTray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Palm\Hotsync.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\SYSTEM32\calc.exe
C:\Documents and Settings\Nathan Harsh\Desktop\HTJ\HJT.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.180nutrition.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Program Files\Netscape\Users\nharsh23\prefs.js)
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Cyberhawk] C:\Program Files\Cyberhawk\CHTray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [tbon] C:\Program Files\TBONBin\tbon.exe /r
O4 - HKCU\..\Run: [Malware Sweeper] C:\Program Files\MalwareSweeper.com\MalwareSweeper\MalSwep.exe /STARTUP
O4 - Global Startup: PowerReg Scheduler.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\Hotsync.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: (no name) - {06FE5D04-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/home (file missing)
O9 - Extra 'Tools' menuitem: AV Home - {06FE5D04-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/home (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: APEX Weight Center 2.0.2.818 - https://application.bodybugg.com/files/stat…x_2_0_2_818.cab
O16 - DPF: APEX Weight Center 2.0.4.822 - https://application.bodybugg.com/files/stat…x_2_0_4_822.cab
O16 - DPF: APEX Weight Center 2.2.0.884 - http://beta.bodybugg.com/files/static/inst…x_2_2_0_884.cab
O16 - DPF: APEX Weight Center 2.2.0.902 - http://beta.bodybugg.com/files/static/inst…x_2_2_0_902.cab
O16 - DPF: Dialpad Java Applet - http://www.dialpad.com/applet/src/vscp.cab
O16 - DPF: Dialpad US Java Applet - http://www.dialpad.com/applet/src/vscp.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: Cyberhawk - Novatix Corporation - C:\Program Files\Cyberhawk\CHService.exe
O23 - Service: DvpApi (dvpapi) - Unknown owner - C:\Program Files\Common Files\Command Software\dvpapi.exe (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\Ewido Anti-spyware 4.0\guard.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
************************************************************************************************

Let me know if there are any other steps that I can take to fix my computer. Thanks.
Please download WinPFind2.
  • Extract the files to a folder(eg: C:\WinPFind2).
  • Double click WinPFind2.exe to start the program.
  • Click the Select All button in the File Options box of the Configuration tab(this is the tab the program opens up to by default).
  • Click the Run all Scans button.
  • When its finished scanning you will see Scans Complete! at the bottom left of the program.
  • Click the Simple Report button at the bottom right of the window.
  • Notepad will open with the results of the scan and the log will be saved to the folder that you extracted the program to(C:\WinPFind2\WinPFind2.txt)
  • Post the log in your next reply please.
Below is my WinPFinder2 Log:

Logfile created on: 09/23/2006 15:35
WinPFind2 by OldTimer - Version 1.0.10 Folder = C:\WindPFind2\WinPFind2\
Microsoft Windows XP Service Pack 1 (Version = 5.1.2600)
Internet Explorer (Version = 6.0.2800.1106)


< Processes (Non-Microsoft Only) >
c:\program files\network associates\virusscan\avconsol.exe - ( )
c:\progra~1\grisoft\avgfre~1\avgamsvr.exe - (GRISOFT, s.r.o. )
c:\progra~1\grisoft\avgfre~1\avgcc.exe - (GRISOFT, s.r.o. )
c:\progra~1\grisoft\avgfre~1\avgemc.exe - (GRISOFT, s.r.o. )
c:\progra~1\grisoft\avgfre~1\avgupsvc.exe - (GRISOFT, s.r.o. )
c:\progra~1\grisoft\avgfre~1\avgw.exe - (GRISOFT, s.r.o. )
c:\program files\network associates\virusscan\avsynmgr.exe - ( )
c:\program files\cyberhawk\chservice.exe - (Novatix Corporation )
c:\program files\cyberhawk\chtray.exe - (Novatix Corporation )
c:\windows\system32\devldr32.exe - (Creative Technology Ltd. )
c:\program files\common files\dataviz\dvzincmsgr.exe - (DataViz, Inc. )
c:\program files\logitech\video\fxsvr2.exe - (Logitech Inc. )
c:\palm\hotsync.exe - (PalmSource, Inc )
c:\program files\logitech\video\logitray.exe - (Logitech Inc. )
c:\windows\system32\lvcomsx.exe - (Logitech Inc. )
c:\program files\common files\real\update_ob\realsched.exe - (RealNetworks, Inc. )
c:\program files\tgtsoft\stylexp\stylexpservice.exe - ( )
c:\program files\network associates\virusscan\vsstat.exe - ( )
c:\windpfind2\winpfind2\winpfind2.exe - (OldTimer Tools )

< Registry Entries >

[>> Internet Explorer Settings <<]
HKCU->Internet Explorer\\SearchURL - http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKLM->Main\\Start Page - about:blank
HKLM->Main\\Search Bar -
HKLM->Main\\Search Page - http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKLM->Main\\Default_Page_URL - http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
HKLM->Main\\Default_Search_URL - http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKLM->Main\\Local Page - %SystemRoot%\system32\blank.htm
HKCU->Main\\Start Page - http://www.180nutrition.com/
HKCU->Main\\Search Page - http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKCU->Main\\Local Page - C:\WINDOWS\System32\blank.htm
HKLM->Search\\CustomizeSearch - http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM->Search\\SearchAssistant - http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKCU->Search\\CustomizeSearch - http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKCU->Search\\SearchAssistant - http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKCU->URLSearchHooks\\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Microsoft Url Search Hook = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation )
HKCU->Internet Settings\\ProxyEnable - 0

[>> BHO's <<]

[>> Internet Explorer Bars, Toolbars and Extensions <<]

[HKLM-> Internet Explorer Bars]
{4D5C8C25-D075-11d0-B416-00C04FB90376} - &Tip of the Day = C:\WINDOWS\SYSTEM32\SHDOCVW.DLL (Microsoft Corporation )
{FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - Real.com = C:\WINDOWS\System32\Shdocvw.dll (Microsoft Corporation )

[HKCU-> Internet Explorer Bars]
{32683183-48a0-441b-a342-7c2a440a9478} - Media Band = C:\WINDOWS\SYSTEM32\BROWSEUI.DLL (Microsoft Corporation )
{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1} - File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
{EFA24E61-B078-11D0-89E4-00C04FC9E26E} - Favorites Band = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation )
{EFA24E62-B078-11D0-89E4-00C04FC9E26E} - History Band = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation )

[HKCU-> Internet Explorer ToolBars]
ShellBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Address = %SystemRoot%\System32\browseui.dll (Microsoft Corporation )
ShellBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383} - &Links = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Data missing or invalid = Reg Data missing or invalid (File not found))
WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Address = %SystemRoot%\System32\browseui.dll (Microsoft Corporation )
WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383} - &Links = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Data missing or invalid = Reg Data missing or invalid (File not found))
WebBrowser\\{9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - Reg Data missing or invalid = Reg Data missing or invalid (File not found))
WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Data missing or invalid = Reg Data missing or invalid (File not found))
WebBrowser\\{F5735C15-1FB2-41FE-BA12-242757E69DDE} - ZeroBar = C:\Program Files\NetZero\Toolbar.dll (File not found))

[HKCU-> Internet Explorer CmdMapping]
{06FE5D02-8F11-11d2-804F-00105A133818} - 8195 - Reg Data missing or invalid
{06FE5D03-8F11-11d2-804F-00105A133818} - 8196 - Reg Data missing or invalid
{06FE5D04-8F11-11d2-804F-00105A133818} - 8197 - AV Home
{06FE5D05-8F11-11d2-804F-00105A133818} - 8194 - Reg Data missing or invalid
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - 8199 - Sun Java Console
{2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - 8200 - Reg Data missing or invalid
{BF69DF00-2734-477F-8257-27CD04F88779} - 8201 - Reg Data missing or invalid
{c95fe080-8f5d-11d2-a20b-00aa003c157a} - 8192 - Reg Data missing or invalid
{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - 8198 - Reg Data missing or invalid
{FB5F1910-F110-11d2-BB9E-00C04F795683} - 8193 - Messenger
NextId - 8202

[HKLM-> Internet Explorer Extensions]
{06FE5D04-8F11-11d2-804F-00105A133818} - MenuText: AV Home = Reg Data missing or invalid (File not found))
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - MenuText: Sun Java Console = C:\WINDOWS\System32\msjava.dll (Microsoft Corporation )
{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - ButtonText: Real.com = Reg Data missing or invalid (File not found))
{FB5F1910-F110-11d2-BB9E-00C04F795683} - ButtonText: Messenger = C:\Program Files\Messenger\MSMSGS.EXE (Microsoft Corporation )

[HKCU-> Internet Explorer Menu Extensions]
Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228 (File not found))
Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227 (File not found))

[>> Approved Shell Extensions (Non-Microsoft only) <<]

[HKLM-> Approved Shell Extensions]
{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3} - My Logitech Pictures = C:\Program Files\Logitech\Video\Namespc2.dll (Logitech Inc. )
{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} - AVG7 Shell Extension = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. )
{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} - AVG7 Find Extension = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. )
{AE308E75-07C2-41D7-AA97-2F23E13E5877} - = C:\WINDOWS\system32\micbase.dll (File not found))
{C56C4E21-706D-11d0-AFC5-444553540002} - My Digital Camera = C:\Program Files\PhotoDeluxe\FotoNation Explorer\camview.dll (FotoNation Inc. )
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - Shell Extensions for RealOne Player = C:\Program Files\Real\RealPlayer\rpshell.dll (RealNetworks, Inc. )

[HKCU-> Approved Shell Extensions]
{0006F045-0000-0000-C000-000000000046} - Microsoft Outlook Custom Icon Handler = c:\PROGRA~1\MICROS~4\OFFICE\OLKFSTUB.DLL (Microsoft Corporation )

[>> ContextMenuHandlers (Non-Microsoft only) <<]

[HKLM-> ContextMenuHandlers]
* - AVG7 Shell Extension - {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. )
* - ewido anti-spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Ewido Anti-spyware 4.0\context.dll (Anti-Malware Development a.s. )
* - WinZip - {E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. )
Directory - ewido anti-spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Ewido Anti-spyware 4.0\context.dll (Anti-Malware Development a.s. )
Directory - WinZip - {E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. )
Folder - AVG7 Shell Extension - {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. )
Folder - WinZip - {E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc. )

[>> ColumnHandlers (Non-Microsoft only) <<]

[HKLM-> ColumnHandlers]

[>> File Associations Keys <<]
HKLM->SOFTWARE\Classes\.bat\\'' - batfile
HKLM->SOFTWARE\Classes\batfile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.cmd\\'' - cmdfile
HKLM->SOFTWARE\Classes\cmdfile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.com\\'' - comfile
HKLM->SOFTWARE\Classes\comfile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.exe\\'' - exefile
HKLM->SOFTWARE\Classes\exefile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.hta\\'' - htafile
HKLM->SOFTWARE\Classes\htafile\shell\open\command\\'' - C:\WINDOWS\System32\mshta.exe "%1" %*
HKLM->SOFTWARE\Classes\.js\\'' - JSFile
HKLM->SOFTWARE\Classes\jsfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.jse\\'' - JSEFile
HKLM->SOFTWARE\Classes\jsefile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.scr\\'' - scrfile
HKLM->SOFTWARE\Classes\scrfile\shell\open\command\\'' - "%1" /S
HKLM->SOFTWARE\Classes\.vbe\\'' - VBEFile
HKLM->SOFTWARE\Classes\vbefile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.vbs\\'' - VBSFile
HKLM->SOFTWARE\Classes\vbsfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.wsf\\'' - WSFFile
HKLM->SOFTWARE\Classes\wsffile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.wsh\\'' - WSHFile
HKLM->SOFTWARE\Classes\wshfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.txt\\'' - txtfile
HKLM->SOFTWARE\Classes\txtfile\shell\open\command\\'' - %SystemRoot%\system32\NOTEPAD.EXE %1

[>> Registry Run Keys <<]
HKLM->Run\\AVG7_CC - C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP (GRISOFT, s.r.o. )
HKLM->Run\\Cyberhawk - C:\Program Files\Cyberhawk\CHTray.exe (Novatix Corporation )
HKLM->Run\\DXM6Patch_981116 - C:\WINDOWS\p_981116.exe /Q:A (Microsoft Corporation )
HKLM->Run\\LogitechVideoRepair - C:\Program Files\Logitech\Video\ISStart.exe (Logitech Inc. )
HKLM->Run\\LogitechVideoTray - C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc. )
HKLM->Run\\LVCOMSX - C:\WINDOWS\System32\LVCOMSX.EXE (Logitech Inc. )
HKLM->Run\\PRISMSVR.EXE - "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY (File not found))
HKLM->Run\\TkBellExe - "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc. )
HKLM->Run\OptionalComponents\IMAIL - Installed = 1
HKLM->Run\OptionalComponents\MAPI - Installed = 1
HKLM->Run\OptionalComponents\MSFS - Installed = 1
HKCU->Run\\Malware Sweeper - C:\Program Files\MalwareSweeper.com\MalwareSweeper\MalSwep.exe /STARTUP (MalwareSweeper.com )
HKCU->Run\\STYLEXP - C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide ( )
HKCU->Run\\tbon - C:\Program Files\TBONBin\tbon.exe /r (File not found))

[>> Miscellaneous Startup Keys <<]

[AppInit DLLs]
AppInit_DLL - (File not found))

[Image File Execution Options]
Your Image File Name Here without a path - Debugger = ntsd -d

[Shell Service Object Delay Load]
CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll (Microsoft Corporation )
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll (Microsoft Corporation )

[Shell Execute Hooks]
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} - CShellExecuteHookImpl Object = C:\Program Files\Ewido Anti-spyware 4.0\shellexecutehook.dll (Anti-Malware Development a.s. )
{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - Reg Data missing or invalid = Reg Data missing or invalid (File not found))
{AEB6717E-7E19-11d0-97EE-00C04FD91972} - URL Exec Hook = shell32.dll (Microsoft Corporation )

[Shared Task Scheduler]

[SafeBoot Option]

[HKLM Command Processor AutoRun]
HKLM->Command Processor\\AutoRun -

[HKCU Command Processor AutoRun]

[Security Providers]
SecurityProviders\\SecurityProviders - msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll

[BootExecute]
Session Manager\\BootExecute - autocheck autochk *;

[PendingFileRenameOperations]

[FileRenameOperations]

[ExcludeFromKnownDlls]
Session Manager\\ExcludeFromKnownDlls -

[>> Disabled MSConfig Items <<]
StartUpFolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 8.0 Tray Icon.lnk - America Online 8.0 Tray Icon = C:\PROGRA~1\AMERIC~1.0\aoltray.exe -check (File not found))
StartUpFolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Encoder Agent.lnk - Encoder Agent = C:\PROGRA~1\WINDOW~3\Encoder\Wmencagt.exe (Microsoft Corporation )
StartUpFolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk - HotSync Manager = C:\Palm\Hotsync.exe (PalmSource, Inc )
StartUpFolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk - Microsoft Office = C:\PROGRA~1\MICROS~4\Office\Osa9.exe -b -l (Microsoft Corporation )
StartUpFolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PowerReg Scheduler.exe - PowerReg Scheduler = C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PowerReg Scheduler.exe ( )
StartUpFolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk - WinZip Quick Pick = C:\PROGRA~1\WinZip\WZQKPICK.EXE (WinZip Computing, Inc. )
StartUpReg\Avast32 - ASTART32 = C:\PROGRA~1\ALWILS~1\AVAST32\ASTART32.EXE /keepserver (File not found))
StartUpReg\MSMSGS - msmsgs = "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation )
StartUpReg\RealTray - RealPlay = C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER (RealNetworks, Inc. )
StartUpReg\STYLEXP - StyleXP = C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide ( )
StartUpReg\SystemTray - SysTray = SysTray.Exe (Microsoft Corporation )

[>> User Agent Post Platform <<]
{7A9DB823-7310-E2FE-AB01-BB270EC983F5} - Reg Data missing or invalid = Reg Data missing or invalid (File not found))

[>> Winlogon <<]
HMLM->UserInit - C:\WINDOWS\system32\userinit.exe, (Microsoft Corporation )
HKLM->Shell - explorer.exe (Microsoft Corporation )
HKLM->System - (File not found))
HKLM->VMApplet - rundll32 shell32,Control_RunDLL "sysdm.cpl"

[>> DNS Name Servers <<]
{09D61B6E-B486-4862-B92D-D8248B2E778E} - (Motorola SURFboard SB5120 USB Cable Modem)
{0D7E5E62-F1A7-465A-AEFB-7F8B6CEE72EB} - ()
{15C08599-C528-4144-A068-FCE6DF1906F3} - (Linksys Wireless-G Portable USB Adapter)
{1D4ECF60-0DAA-449B-BB24-C0E6E57FE989} - (Motorola SURFboard SB5120 USB Cable Modem)
{7C5811A6-350E-4742-97E2-7264544C0957} - (Linksys Wireless-G Portable USB Adapter)
{AD5BDDA1-891A-486D-869F-9736A0A461B5} - (SMC EZ Card 10/100 PCI (SMC1211TX))
{BAA9335A-BD68-4741-AD68-3213F6880D03} - (1394 Net Adapter)
{EBBB9101-4910-4DBE-AB36-1DFB038486E7} - (Linksys Wireless-G Portable USB Adapter)

[>> All Winsock2 Catalogs <<]
NameSpace_Catalog5\Catalog_Entries\000000000001 - %SystemRoot%\System32\nwprovau.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000002 - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000004 - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000021 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000022 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000023 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000024 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000027 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000028 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000029 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000030 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000031 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000032 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000033 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000034 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000035 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000036 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )

[>> Protocol Handlers (Non-Microsoft only) <<]
ipp - (File not found))
msdaipp - (File not found))
vnd.ms.radio - C:\WINDOWS\System32\msdxm.ocx ( )

[>> Protocol Filters (Non-Microsoft only) <<]

< Services (Non-Microsoft Only) >
AVG7 Alert Manager Server (Avg7Alrt) - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (GRISOFT, s.r.o. ) [Automatic - Running - Win32, running in it's own process]
AVG7 Update Service (Avg7UpdSvc) - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (GRISOFT, s.r.o. ) [Automatic - Running - Win32, running in it's own process]
AVG E-mail Scanner (AVGEMS) - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe (GRISOFT, s.r.o. ) [Automatic - Running - Win32, running in it's own process]
AVSync Manager (AvSynMgr) - "C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe" ( ) [Automatic - Running - Win32, running in it's own process]
Cyberhawk (Cyberhawk) - C:\Program Files\Cyberhawk\CHService.exe service (Novatix Corporation ) [Automatic - Running - Win32, running in it's own process]
StyleXPService (StyleXPService) - "C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe" ( ) [Automatic - Running - Win32, running in it's own process]

< Files >

%SystemDrive%

%ProgramFilesDir%

%WinDir%
C:\WINDOWS\IAMNET~1.EXE - UPX! (CallWave, Inc. [Ver = 2.04.1 | Size = 294960 bytes | Date = 07/31/2001 15:22 | Attr = ])
C:\WINDOWS\DUMPa8c2.tmp - FSG! ( [Ver = | Size = 201326592 bytes | Date = 12/01/2005 22:13 | Attr = ])

%System%
C:\WINDOWS\SYSTEM32\dfrg.msc - PEC2 ( [Ver = | Size = 41397 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\ntbackup.exe - WSUD (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 1135616 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\nusrmgr.cpl - WSUD (Microsoft Corporation [Ver = 6.00.2600.0000 (xpclient.010817-1148) | Size = 256000 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\wbdbase.deu - winsync ( [Ver = | Size = 1309184 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\adrotate.dll - UPX! ( [Ver = 1, 0, 3, 2 | Size = 59904 bytes | Date = 07/31/2006 12:50 | Attr = ])
C:\WINDOWS\SYSTEM32\mfc70u.pdb - PEC2 ( [Ver = | Size = 9538560 bytes | Date = 01/05/2002 06:36 | Attr = ])
C:\WINDOWS\SYSTEM32\mfc70ud.pdb - PEC2 ( [Ver = | Size = 7597056 bytes | Date = 01/05/2002 05:56 | Attr = ])
C:\WINDOWS\SYSTEM32\atl70.pdb - PEC2 ( [Ver = | Size = 2011136 bytes | Date = 01/05/2002 04:18 | Attr = ])
C:\WINDOWS\SYSTEM32\mfc70d.pdb - PEC2 ( [Ver = | Size = 7564288 bytes | Date = 01/05/2002 05:54 | Attr = ])
C:\WINDOWS\SYSTEM32\mfc70.pdb - PEC2 ( [Ver = | Size = 9546752 bytes | Date = 01/05/2002 06:48 | Attr = ])
C:\WINDOWS\SYSTEM32\rasdlg.dll - Umonitor (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 631808 bytes | Date = 08/29/2002 03:41 | Attr = ])

%System%\Drivers folder and sub-folders
C:\WINDOWS\SYSTEM32\drivers\avg7core.sys - UPX! (GRISOFT, s.r.o. [Ver = 7,1,0,402 | Size = 777472 bytes | Date = 08/16/2006 22:17 | Attr = ])
C:\WINDOWS\SYSTEM32\drivers\avg7core.sys - FSG! (GRISOFT, s.r.o. [Ver = 7,1,0,402 | Size = 777472 bytes | Date = 08/16/2006 22:17 | Attr = ])
C:\WINDOWS\SYSTEM32\drivers\avg7core.sys - PEC2 (GRISOFT, s.r.o. [Ver = 7,1,0,402 | Size = 777472 bytes | Date = 08/16/2006 22:17 | Attr = ])
C:\WINDOWS\SYSTEM32\drivers\avg7core.sys - aspack (GRISOFT, s.r.o. [Ver = 7,1,0,402 | Size = 777472 bytes | Date = 08/16/2006 22:17 | Attr = ])

%windir% + sub-dirs for System or Hidden files less than 60 days old
C:\WINDOWS\bootstat.dat - ( [Ver = | Size = 2048 bytes | Date = 09/18/2006 23:27 | Attr = S])
C:\WINDOWS\SYSTEM32\config\system.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/22/2006 21:17 | Attr = H ])
C:\WINDOWS\SYSTEM32\config\software.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/23/2006 09:21 | Attr = H ])
C:\WINDOWS\SYSTEM32\config\default.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/23/2006 08:28 | Attr = H ])
C:\WINDOWS\SYSTEM32\config\SAM.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/18/2006 23:27 | Attr = H ])
C:\WINDOWS\SYSTEM32\config\SECURITY.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/23/2006 00:10 | Attr = H ])
C:\WINDOWS\SYSTEM32\GroupPolicy\Adm\admfiles.ini - ( [Ver = | Size = 69 bytes | Date = 08/06/2006 14:15 | Attr = H ])
C:\WINDOWS\CSC\00000001 - ( [Ver = | Size = 64 bytes | Date = 08/06/2006 13:52 | Attr = S])
C:\WINDOWS\CSC\csc1.tmp - ( [Ver = | Size = 64 bytes | Date = 08/04/2006 20:13 | Attr = S])
C:\WINDOWS\CSC\00000002 - ( [Ver = | Size = 64 bytes | Date = 08/06/2006 12:42 | Attr = S])
C:\WINDOWS\All Users\DRM\drmstore.hds - ( [Ver = | Size = 102400 bytes | Date = 07/30/2006 20:06 | Attr = HS])
C:\WINDOWS\All Users\DRM\migration.log - ( [Ver = | Size = 2046 bytes | Date = 07/30/2006 20:06 | Attr = HS])
C:\WINDOWS\Tasks\SA.DAT - ( [Ver = | Size = 6 bytes | Date = 09/18/2006 23:27 | Attr = H ])
CPL files -
C:\WINDOWS\SYSTEM32\desk.cpl - (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 129024 bytes | Date = 08/29/2002 03:41 | Attr = ])
C:\WINDOWS\SYSTEM32\CSACPL.CPL - (Conexant [Ver = 2.1.2.164.013.013 | Size = 286720 bytes | Date = 03/10/2000 20:04 | Attr = ])
C:\WINDOWS\SYSTEM32\cch.cpl - ( [Ver = | Size = 110592 bytes | Date = 10/14/1999 17:27 | Attr = ])
C:\WINDOWS\SYSTEM32\intl.cpl - (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 121856 bytes | Date = 08/29/2002 03:41 | Attr = ])
C:\WINDOWS\SYSTEM32\appwiz.cpl - (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 578560 bytes | Date = 08/29/2002 03:41 | Attr = ])
C:\WINDOWS\SYSTEM32\hdwwiz.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 150016 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\inetcpl.cpl - (Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 292352 bytes | Date = 08/29/2002 03:41 | Attr = ])
C:\WINDOWS\SYSTEM32\joy.cpl - (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 65536 bytes | Date = 08/29/2002 03:41 | Attr = ])
C:\WINDOWS\SYSTEM32\main.cpl - (Microsoft Corporation [Ver = 5.1.2403.1 | Size = 187904 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\mmsys.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 559616 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\wuaucpl.cpl - (Microsoft Corporation [Ver = 5.8.0.2469 built by: lab01_n(wmbla) | Size = 174360 bytes | Date = 05/26/2005 04:16 | Attr = ])
C:\WINDOWS\SYSTEM32\ncpa.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 35840 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\nusrmgr.cpl - (Microsoft Corporation [Ver = 6.00.2600.0000 (xpclient.010817-1148) | Size = 256000 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\nwc.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 36864 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\odbccp32.cpl - (Microsoft Corporation [Ver = 3.520.7713.0 | Size = 36864 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\powercfg.cpl - (Microsoft Corporation [Ver = 6.00.2600.0000 (xpclient.010817-1148) | Size = 109056 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\telephon.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 28160 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\timedate.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 90112 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\CamCpl.cpl - (Logitech Inc. [Ver = 8.4.7.1034 | Size = 282624 bytes | Date = 06/08/2005 15:13 | Attr = ])
C:\WINDOWS\SYSTEM32\access.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 66048 bytes | Date = 08/23/2001 06:00 | Attr = ])
C:\WINDOWS\SYSTEM32\jpicpl32.cpl - (Sun Microsystems [Ver = 1, 4, 1, 01 | Size = 229482 bytes | Date = 09/30/2002 08:56 | Attr = ])
C:\WINDOWS\SYSTEM32\QuickTime.cpl - (Apple Computer, Inc. [Ver = 5.0.1 | Size = 287232 bytes | Date = 04/11/2001 12:22 | Attr = ])
C:\WINDOWS\SYSTEM32\prefscpl.cpl - (RealNetworks, Inc. [Ver = 6.0.9.573 | Size = 24576 bytes | Date = 07/24/2003 02:22 | Attr = ])
C:\WINDOWS\SYSTEM32\Avsmcpa.cpl - ( [Ver = | Size = 98304 bytes | Date = 04/30/2001 04:51 | Attr = ])
C:\WINDOWS\SYSTEM32\sysdm.cpl - (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 268288 bytes | Date = 08/29/2002 03:41 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\nwc.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 36864 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\joy.cpl - (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 208896 bytes | Date = 08/29/2002 03:41 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 150016 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\odbccp32.cpl - (Microsoft Corporation [Ver = 3.520.7713.0 | Size = 36864 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\access.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 66048 bytes | Date = 08/23/2001 06:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 35840 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\nusrmgr.cpl - (Microsoft Corporation [Ver = 6.00.2600.0000 (xpclient.010817-1148) | Size = 256000 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\powercfg.cpl - (Microsoft Corporation [Ver = 6.00.2600.0000 (xpclient.010817-1148) | Size = 109056 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\main.cpl - (Microsoft Corporation [Ver = 5.1.2403.1 | Size = 187904 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\mmsys.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 559616 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 28160 bytes | Date = 08/23/2001 12:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\timedate.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 90112 bytes | Date = 08/23/2001 12:00 | Attr = ])

Auto-Start Folders

HKLM->Explorer\Shell Folders\\Common Startup = C:\Documents and Settings\All Users\Start Menu\Programs\Startup
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DataViz Inc Messenger.lnk - C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe (DataViz, Inc. [Ver = 6,0,1,723 | Size = 28672 bytes | Date = 03/25/2006 22:52 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini - ( [Ver = | Size = 84 bytes | Date = 11/07/2002 17:49 | Attr = HS])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk - C:\Palm\Hotsync.exe (PalmSource, Inc [Ver = 6.0.1 | Size = 471040 bytes | Date = 06/09/2004 14:16 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PowerReg Scheduler.exe - ( [Ver = 1, 0, 0, 1 | Size = 251392 bytes | Date = 06/07/2004 22:59 | Attr = ])

HKLM->Explorer\User Shell Folders\\Common Startup = %ALLUSERSPROFILE%\Start Menu\Programs\Startup

HKLM->Explorer\Shell Folders\\Startup = C:\Documents and Settings\Nathan Harsh\Start Menu\Programs\Startup
C:\Documents and Settings\Nathan Harsh\Start Menu\Programs\Startup\desktop.ini - ( [Ver = | Size = 84 bytes | Date = 11/07/2002 17:49 | Attr = HS])

HKCU->Explorer\User Shell Folders\\Startup = %USERPROFILE%\Start Menu\Programs\Startup

Miscellaneous Auto-Start Files
System.ini->[Boot]\\Shell - explorer.exe
Wininit.ini: Line 1 - [rename]
Wininit.ini: Line 2 - NUL=C:\WINDOWS\DELETE.EXE
Wininit.ini: Line 3 - NUL=
Wininit.ini: Line 4 - NUL=
Wininit.ini: Line 5 - NUL=
Wininit.ini: Line 7 - NUL=
DosStart.bat: Line 1 - C:\PROGRA~1\CREATIVE\SBLIVE\DOSDRV\SBEINIT.COM
DosStart.bat: Line 2 - @echo off
DosStart.bat: Line 3 - LH C:\WINDOWS\COMMAND\MSCDEX.EXE /D:IDECD001 /M:12
Config.nt: Line 1 - REM Windows MS-DOS Startup File
Config.nt: Line 2 - REM
Config.nt: Line 3 - REM CONFIG.SYS vs CONFIG.NT
Config.nt: Line 4 - REM CONFIG.SYS is not used to initialize the MS-DOS environment.
Config.nt: Line 5 - REM CONFIG.NT is used to initialize the MS-DOS environment unless a
Config.nt: Line 6 - REM different startup file is specified in an application's PIF.
Config.nt: Line 7 - REM
Config.nt: Line 8 - REM ECHOCONFIG
Config.nt: Line 9 - REM By default, no information is displayed when the MS-DOS environment
Config.nt: Line 10 - REM is initialized. To display CONFIG.NT/AUTOEXEC.NT information, add
Config.nt: Line 11 - REM the command echoconfig to CONFIG.NT or other startup file.
Config.nt: Line 12 - REM
Config.nt: Line 13 - REM NTCMDPROMPT
Config.nt: Line 14 - REM When you return to the command prompt from a TSR or while running an
Config.nt: Line 15 - REM MS-DOS-based application, Windows runs COMMAND.COM. This allows the
Config.nt: Line 16 - REM TSR to remain active. To run CMD.EXE, the Windows command prompt,
Config.nt: Line 17 - REM rather than COMMAND.COM, add the command ntcmdprompt to CONFIG.NT or
Config.nt: Line 18 - REM other startup file.
Config.nt: Line 19 - REM
Config.nt: Line 20 - REM DOSONLY
Config.nt: Line 21 - REM By default, you can start any type of application when running
Config.nt: Line 22 - REM COMMAND.COM. If you start an application other than an MS-DOS-based
Config.nt: Line 23 - REM application, any running TSR may be disrupted. To ensure that only
Config.nt: Line 24 - REM MS-DOS-based applications can be started, add the command dosonly to
Config.nt: Line 25 - REM CONFIG.NT or other startup file.
Config.nt: Line 26 - REM
Config.nt: Line 27 - REM EMM
Config.nt: Line 28 - REM You can use EMM command line to configure EMM(Expanded Memory Manager).
Config.nt: Line 29 - REM The syntax is:
Config.nt: Line 30 - REM
Config.nt: Line 31 - REM EMM = [A=AltRegSets] [RAM]
Config.nt: Line 32 - REM
Config.nt: Line 33 - REM AltRegSets
Config.nt: Line 34 - REM specifies the total Alternative Mapping Register Sets you
Config.nt: Line 35 - REM want the system to support. 1 <= AltRegSets <= 255. The
Config.nt: Line 36 - REM default value is 8.
Config.nt: Line 37 - REM BaseSegment
Config.nt: Line 38 - REM specifies the starting segment address in the Dos conventional
Config.nt: Line 39 - REM memory you want the system to allocate for EMM page frames.
Config.nt: Line 40 - REM The value must be given in Hexdecimal.
Config.nt: Line 41 - REM 0x1000 <= BaseSegment <= 0x4000. The value is rounded down to
Config.nt: Line 42 - REM 16KB boundary. The default value is 0x4000
Config.nt: Line 43 - REM RAM
Config.nt: Line 44 - REM specifies that the system should only allocate 64Kb address
Config.nt: Line 45 - REM space from the Upper Memory Block(UMB) area for EMM page frames
Config.nt: Line 46 - REM and leave the rests(if available) to be used by DOS to support
Config.nt: Line 47 - REM loadhigh and devicehigh commands. The system, by default, would
Config.nt: Line 48 - REM allocate all possible and available UMB for page frames.
Config.nt: Line 49 - REM
Config.nt: Line 50 - REM The EMM size is determined by pif file(either the one associated
Config.nt: Line 51 - REM with your application or _default.pif). If the size from PIF file
Config.nt: Line 52 - REM is zero, EMM will be disabled and the EMM line will be ignored.
Config.nt: Line 53 - REM
Config.nt: Line 54 - dos=high, umb
Config.nt: Line 55 - device=%SystemRoot%\system32\himem.sys
Config.nt: Line 56 - files=40
Config.nt: Line 58 - REM
Config.nt: Line 59 - REM *************************************************
Config.nt: Line 60 - REM ** Lines below this have been migrated from the
Config.nt: Line 61 - REM ** original Windows 98 settings.
Config.nt: Line 62 - REM *************************************************
Config.nt: Line 63 - REM
Config.nt: Line 65 - DEVICE=C:\WINDOWS\SYSTEM32\HIMEM.SYS
Config.nt: Line 66 - REM DEVICE=C:\WINDOWS\EMM386.EXE
Config.nt: Line 67 - REM DOS=HIGH,UMB,AUTO
Config.nt: Line 68 - REM FILESHIGH=80
Config.nt: Line 69 - REM BUFFERSHIGH=40,4
Config.nt: Line 70 - SHELL=C:\WINDOWS\SYSTEM32\COMMAND.COM /P /E:2048
Config.nt: Line 71 - REM DEVICEHIGH=C:\WINDOWS\SYSTEM\CPQIDECD.SYS /D:IDECD001
AutoExec.nt: Line 1 - @echo off
AutoExec.nt: Line 3 - REM AUTOEXEC.BAT is not used to initialize the MS-DOS environment.
AutoExec.nt: Line 4 - REM AUTOEXEC.NT is used to initialize the MS-DOS environment unless a
AutoExec.nt: Line 5 - REM different startup file is specified in an application's PIF.
AutoExec.nt: Line 7 - REM Install CD ROM extensions
AutoExec.nt: Line 8 - lh %SystemRoot%\system32\mscdexnt.exe
AutoExec.nt: Line 10 - REM Install network redirector (load before dosx.exe)
AutoExec.nt: Line 11 - lh %SystemRoot%\system32\redir
AutoExec.nt: Line 13 - REM Install DPMI support
AutoExec.nt: Line 14 - lh %SystemRoot%\system32\dosx
AutoExec.nt: Line 16 - REM The following line enables Sound Blaster 2.0 support on NTVDM.
AutoExec.nt: Line 17 - REM The command for setting the BLASTER environment is as follows:
AutoExec.nt: Line 18 - REM SET BLASTER=A220 I5 D1 P330
AutoExec.nt: Line 19 - REM where:
AutoExec.nt: Line 20 - REM A specifies the sound blaster's base I/O port
AutoExec.nt: Line 21 - REM I specifies the interrupt request line
AutoExec.nt: Line 22 - REM D specifies the 8-bit DMA channel
AutoExec.nt: Line 23 - REM P specifies the MPU-401 base I/O port
AutoExec.nt: Line 24 - REM T specifies the type of sound blaster card
AutoExec.nt: Line 25 - REM 1 - Sound Blaster 1.5
AutoExec.nt: Line 26 - REM 2 - Sound Blaster Pro I
AutoExec.nt: Line 27 - REM 3 - Sound Blaster 2.0
AutoExec.nt: Line 28 - REM 4 - Sound Blaster Pro II
AutoExec.nt: Line 29 - REM 6 - SOund Blaster 16/AWE 32/32/64
AutoExec.nt: Line 30 - REM
AutoExec.nt: Line 31 - REM The default value is A220 I5 D1 T3 and P330. If any of the switches is
AutoExec.nt: Line 32 - REM left unspecified, the default value will be used. (NOTE, since all the
AutoExec.nt: Line 33 - REM ports are virtualized, the information provided here does not have to
AutoExec.nt: Line 34 - REM match the real hardware setting.) NTVDM supports Sound Blaster 2.0 only.
AutoExec.nt: Line 35 - REM The T switch must be set to 3, if specified.
AutoExec.nt: Line 36 - SET BLASTER=A220 I5 D1 P330 T3
AutoExec.nt: Line 38 - REM To disable the sound blaster 2.0 support on NTVDM, specify an invalid
AutoExec.nt: Line 39 - REM SB base I/O port address. For example:
AutoExec.nt: Line 40 - REM SET BLASTER=A0
AutoExec.nt: Line 41 - REM Install network redirector
AutoExec.nt: Line 43 - lh %SystemRoot%\system32\nw16
AutoExec.nt: Line 45 - lh %SystemRoot%\system32\vwipxspx
AutoExec.nt: Line 48 - REM
AutoExec.nt: Line 49 - REM *************************************************
AutoExec.nt: Line 50 - REM ** Lines below this have been migrated from the
AutoExec.nt: Line 51 - REM ** original Windows 98 settings.
AutoExec.nt: Line 52 - REM *************************************************
AutoExec.nt: Line 53 - REM
AutoExec.nt: Line 55 - @ECHO OFF
AutoExec.nt: Line 56 - SET BLASTER=A220 I7 D3 H7 P330 T6
AutoExec.nt: Line 57 - SET CTSYN=C:\WINDOWS
AutoExec.nt: Line 58 - REM C:\PROGRA~1\CREATIVE\SBLIVE\DOSDRV\SBEINIT.COM
AutoExec.nt: Line 60 - PATH=C:\WINDOWS\system32
AutoExec.bat: Line 1 - @ECHO OFF
AutoExec.bat: Line 2 - SET BLASTER=A220 I7 D3 H7 P330 T6
AutoExec.bat: Line 3 - SET CTSYN=C:\WINDOWS
AutoExec.bat: Line 4 - C:\PROGRA~1\CREATIVE\SBLIVE\DOSDRV\SBEINIT.COM

Miscellaneous Folders

AllUsers ApplicationData Folder
C:\Documents and Settings\All Users\Application Data\desktop.ini - ( [Ver = | Size = 62 bytes | Date = 11/07/2002 17:36 | Attr = HS])

CurrentUser ApplicationData Folder
C:\Documents and Settings\Nathan Harsh\Application Data\desktop.ini - ( [Ver = | Size = 62 bytes | Date = 11/07/2002 17:36 | Attr = HS])
C:\Documents and Settings\Nathan Harsh\Application Data\dw.log - ( [Ver = | Size = 226 bytes | Date = 05/06/2002 12:39 | Attr = ])
C:\Documents and Settings\Nathan Harsh\Application Data\kc.tmp - ( [Ver = | Size = 5 bytes | Date = 04/27/2006 09:02 | Attr = ])
C:\Documents and Settings\Nathan Harsh\Application Data\internaldb41.dat - ( [Ver = | Size = 0 bytes | Date = 08/04/2006 20:35 | Attr = ])

Program Files Folder
C:\Program Files\folder.htt - ( [Ver = | Size = 11079 bytes | Date = 07/22/1999 00:25 | Attr = ])
C:\Program Files\desktop.ini - ( [Ver = | Size = 266 bytes | Date = 07/22/1999 00:25 | Attr = HS])
C:\Program Files\uninst.log - ( [Ver = | Size = 359584 bytes | Date = 05/13/2004 20:12 | Attr = ])
C:\Program Files\Porsche.exe - ( [Ver = | Size = 249119 bytes | Date = 03/13/2000 14:52 | Attr = ])
C:\Program Files\mrbupd.dll - (Marimba, Inc. [Ver = 4, 0, 0, 0 | Size = 102400 bytes | Date = 03/07/2000 21:32 | Attr = ])
C:\Program Files\install.txt - ( [Ver = | Size = 1226 bytes | Date = 01/26/2000 11:08 | Attr = ])
C:\Program Files\gimme.dll - ( [Ver = | Size = 4599863 bytes | Date = 03/07/2000 21:31 | Attr = ])
C:\Program Files\fe.txt - ( [Ver = | Size = 13805 bytes | Date = 03/07/2000 21:31 | Attr = ])
C:\Program Files\NFS5.ico - ( [Ver = | Size = 2238 bytes | Date = 02/15/2000 17:14 | Attr = ])
C:\Program Files\dplayerx.dll - ( [Ver = | Size = 173568 bytes | Date = 03/13/2000 14:52 | Attr = ])
C:\Program Files\PORSCHE.ICD - ( [Ver = | Size = 2129965 bytes | Date = 03/13/2000 14:52 | Attr = ])
C:\Program Files\secdrv.sys - ( [Ver = | Size = 10848 bytes | Date = 03/13/2000 14:52 | Attr = ])
C:\Program Files\drvmgt.dll - ( [Ver = | Size = 31744 bytes | Date = 03/13/2000 14:52 | Attr = ])
C:\Program Files\clcd32.dll - ( [Ver = | Size = 27648 bytes | Date = 03/13/2000 14:52 | Attr = ])
C:\Program Files\clcd16.dll - ( [Ver = | Size = 6784 bytes | Date = 03/13/2000 14:52 | Attr = ])
C:\Program Files\clokspl.exe - ( [Ver = | Size = 177152 bytes | Date = 03/13/2000 14:52 | Attr = ])
C:\Program Files\00000409.016 - ( [Ver = | Size = 107318 bytes | Date = 03/13/2000 14:52 | Attr = ])
C:\Program Files\00000409.256 - ( [Ver = | Size = 215478 bytes | Date = 03/13/2000 14:52 | Attr = ])
C:\Program Files\00000001.TMP - ( [Ver = | Size = 20 bytes | Date = 03/13/2000 14:52 | Attr = ])
C:\Program Files\readme.txt - ( [Ver = | Size = 8079 bytes | Date = 03/08/2000 04:38 | Attr = ])
C:\Program Files\Need For Speed - Porsche Unleashed.lnk - ( [Ver = | Size = 1278 bytes | Date = 05/13/2004 20:11 | Attr = ])
C:\Program Files\Uninstall Need For Speed - Porsche Unleashed.lnk - ( [Ver = | Size = 471 bytes | Date = 05/13/2004 20:11 | Attr = ])
C:\Program Files\fe_out.txt - ( [Ver = | Size = 19740 bytes | Date = 06/04/2006 09:40 | Attr = ])

Common Files Folder

DPF files
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - CKAVWebScan Object - CodeBase = http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
{193C772A-87BE-4B19-A7BB-445B226FE9A1} - ewidoOnlineScan Control - CodeBase = http://download.ewido.net/ewidoOnlineScan.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} - Java Plug-in 1.4.1_01 - CodeBase = http://java.sun.com/products/plugin/1.4/ji…indows-i586.cab
{9F1C11AA-197B-4942-BA54-47A8489BB47F} - - CodeBase = http://v4.windowsupdate.microsoft.com/CAB/…7855.8089351852
{A4639D2F-774E-11D3-A490-00C04F6843FB} - - CodeBase = http://download.microsoft.com/download/viz…N-US/msorun.cab
{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} - Java Plug-in 1.4.1_01 - CodeBase = http://java.sun.com/products/plugin/autodl…indows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} - - CodeBase = http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
APEX Weight Center 2.0.2.818 - - CodeBase = https://application.bodybugg.com/files/stat…x_2_0_2_818.cab
APEX Weight Center 2.0.4.822 - - CodeBase = https://application.bodybugg.com/files/stat…x_2_0_4_822.cab
APEX Weight Center 2.2.0.884 - - CodeBase = http://beta.bodybugg.com/files/static/inst…x_2_2_0_884.cab
APEX Weight Center 2.2.0.902 - - CodeBase = http://beta.bodybugg.com/files/static/inst…x_2_2_0_902.cab
Dialpad Java Applet - - CodeBase = http://www.dialpad.com/applet/src/vscp.cab
Dialpad US Java Applet - - CodeBase = http://www.dialpad.com/applet/src/vscp.cab
DirectAnimation Java Classes - - CodeBase = file://c:\windows\SYSTEM\dajava.cab
Internet Explorer Classes for Java - - CodeBase = file://c:\windows\SYSTEM\iejava.cab
Microsoft XML Parser for Java - - CodeBase = file://C:\WINDOWS\Java\classes\xmldso.cab

Hosts file = 105 bytes. Reading all entries. C:\WINDOWS\System32\drivers\etc\Hosts
127.0.0.1 localhost -
127.0.0.1 localhost -
127.0.0.1 localhost -
127.0.0.1 localhost -
127.0.0.1 localhost -

< End of report >
Please go here: virusscan.jotti.org and scan the file below.

click browse and navigate to this file: C:\WINDOWS\DUMPa8c2.tmp

then click submit.

Open Windows Explorer by hitting your windows key + E at the same time.
*If you do not have a windows key, double click My computer > click the folders icon

Then navigate to these files and delete them:

C:\WINDOWS\System32\adrotate.dll

Empty your recycle bin then reboot

after that, please post a new hijackthis log, the results of the jotti scan and a description on how your pc is running.
Here are the results of my latest HJT scan and my online Jotti scan. As far as the way my computer is running, I really haven't noticed a difference since the last set of instructions. Thanks.

***************************************************************************************
Logfile of HijackThis v1.99.1
Scan saved at 7:01:53 AM, on 9/27/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\Program Files\Cyberhawk\CHService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Cyberhawk\CHTray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Palm\Hotsync.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\Nathan Harsh\Desktop\HTJ\HJT.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.180nutrition.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Program Files\Netscape\Users\nharsh23\prefs.js)
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Cyberhawk] C:\Program Files\Cyberhawk\CHTray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [tbon] C:\Program Files\TBONBin\tbon.exe /r
O4 - HKCU\..\Run: [Malware Sweeper] C:\Program Files\MalwareSweeper.com\MalwareSweeper\MalSwep.exe /STARTUP
O4 - Global Startup: PowerReg Scheduler.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\Hotsync.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: (no name) - {06FE5D04-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/home (file missing)
O9 - Extra 'Tools' menuitem: AV Home - {06FE5D04-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/home (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: APEX Weight Center 2.0.2.818 - https://application.bodybugg.com/files/stat…x_2_0_2_818.cab
O16 - DPF: APEX Weight Center 2.0.4.822 - https://application.bodybugg.com/files/stat…x_2_0_4_822.cab
O16 - DPF: APEX Weight Center 2.2.0.884 - http://beta.bodybugg.com/files/static/inst…x_2_2_0_884.cab
O16 - DPF: APEX Weight Center 2.2.0.902 - http://beta.bodybugg.com/files/static/inst…x_2_2_0_902.cab
O16 - DPF: Dialpad Java Applet - http://www.dialpad.com/applet/src/vscp.cab
O16 - DPF: Dialpad US Java Applet - http://www.dialpad.com/applet/src/vscp.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: Cyberhawk - Novatix Corporation - C:\Program Files\Cyberhawk\CHService.exe
O23 - Service: DvpApi (dvpapi) - Unknown owner - C:\Program Files\Common Files\Command Software\dvpapi.exe (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\Ewido Anti-spyware 4.0\guard.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

**************************************************************************************

Online Jotti Scan Rusults- for some reason the file I scanned isn't the one listed below?? I am going to try to run the scan again to see what happens.

**************************************************************************************
Last file scanned at least one scanner reported something about: twk303ra.exe, detected by:

Scanner Malware name
AntiVir X
ArcaVir X
Avast X
AVG Antivirus Downloader.Zlob.CP
BitDefender Generic.Zlob.D9D958E8
ClamAV X
Dr.Web Trojan.Popuper
F-Prot Antivirus X
Fortinet W32/Zlob.ACW!tr.dldr
Kaspersky Anti-Virus Trojan-Downloader.Win32.Zlob.acw
NOD32 Win32/TrojanDownloader.Zlob.YZ
Norman Virus Control X
UNA X
VirusBuster X
VBA32 Trojan-Downloader.Win32.Zlob.acw

Online Jotti Scan Rusults- for some reason the file I scanned isn't the one listed below?? I am going to try to run the scan again to see what happens.


Does that mean when you scanned this: C:\WINDOWS\DUMPa8c2.tmp it gave out that result?

Also, is this file: twk303ra.exe found in your computer?
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI