This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Severe Problems Here <---------

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have scanned my PC numerous times with Norton 2005. It is upto date and identifies a virus in two DLL files xxyxwuv.dll and winlft32.dll howver it will not clean or delete them. I have tried deleting myslef and in safe mode bu I can't figure it out here is my Hijack this log PLease help My pc is so slow and the pop-ups are around 40 a day while my system is idle.

Logfile of HijackThis v1.99.1
Scan saved at 7:17:43 PM, on 8/28/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\issearch.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Norton AntiVirus\NAVW32.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Albert\Desktop\hj\HijackThis.exe

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\wytdf.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,itbgqtx.exe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\System32\WinNB58.dll
O4 - HKLM\..\Run: [Motorola Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [VOBID] C:\Program Files\Pinnacle\InstantCDDVD\InstantDrive\InstantDrive.exe /remount
O4 - HKLM\..\Run: [IW ControlCenter] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - HKCU\..\Run: [Zbgs] C:\PROGRA~1\SSEMBL~1\JVAW~1.EXE
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Bmap] "C:\WINDOWS\System32\APPATC~1\chkntfs.exe" -vt yazr
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} (Mirar_Dummy_ATS1 Class) - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\rundll.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

:(
Thank you for your help I followed the link and installed Service Pack 1 only. This is my new HJT Log. I must aslo note that most of the pop-ups have stopped but I am still infected and I think isnotify.exe is part of the problem along with, userinit.exe, itbgqtx.exe, wytdf.exe. The reason I say this is because they keep trying to modify my registry and Ad-aware will not let them. Anyway you know more about this than I, thank you so much for your help!! Logfile of HijackThis v1.99.1 Scan saved at 9:44:51 PM, on 9/6/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\savedump.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe C:\WINDOWS\System32\RunDll32.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe C:\Documents and Settings\Albert\Desktop\hj\HijackThis.exe O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\System32\WinNB58.dll (file missing) O4 - HKLM\..\Run: [Motorola Wireless Manager UI] C:\WINDOWS\system32\WLTRAY O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [VOBID] C:\Program Files\Pinnacle\InstantCDDVD\InstantDrive\InstantDrive.exe /remount O4 - HKLM\..\Run: [IW ControlCenter] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe" O4 - HKCU\..\Run: [Bmap] "C:\WINDOWS\System32\APPATC~1\chkntfs.exe" -vt yazr O4 - HKCU\..\Run: [Zbgs] C:\PROGRA~1\SSEMBL~1\JVAW~1.EXE O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O20 - AppInit_DLLs: C:\WINDOWS\System32\rundll.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Open the HijackThis Folder. Find the file HijackThis.exe, Right Click on the file and Select Rename. Rename Hijackthis.exe to spyware.exe.

I see you have Ewido 4.0 already. Run a scan with it following these instructions:
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the
    results of the ewido report scan along with a new HijackThis log.
I followed all of the step here are the logs first one is ewido. ALso I have noticed at this point that the registry modification seems to have stopped, however, norton is still saying that there is a downloader in xxyxwuv.dll and it is unable to clean the file. This info was not from A Norton Scan but My Live Scan. ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 10:06:46 PM 9/7/2006 + Scan result: C:\WINDOWS\system32\xxyxwuv.dll -> Adware.Virtumonde : Cleaned. C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ywoam.exe -> Downloader.Qoologic.bj : Cleaned. C:\WINDOWS\system32\hpdyfo.exe -> Downloader.Qoologic.bj : Cleaned. C:\WINDOWS\system32\itbgqtx.exe -> Downloader.Qoologic.bj : Cleaned. C:\WINDOWS\system32\nwcywwj.dll -> Downloader.Qoologic.bj : Cleaned. C:\WINDOWS\system32\wytdf.exe -> Downloader.Qoologic.bj : Cleaned. :mozilla.17:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\xa9wvogg.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. C:\WINDOWS\system32\winlft32.dll -> Trojan.Mezzia : Cleaned. ::Report end Logfile of HijackThis v1.99.1 Scan saved at 10:24:10 PM, on 9/7/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe C:\WINDOWS\System32\RunDll32.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Albert\Desktop\hj\HijackThis.exe O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\System32\WinNB58.dll (file missing) O4 - HKLM\..\Run: [Motorola Wireless Manager UI] C:\WINDOWS\system32\WLTRAY O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [VOBID] C:\Program Files\Pinnacle\InstantCDDVD\InstantDrive\InstantDrive.exe /remount O4 - HKLM\..\Run: [IW ControlCenter] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe" O4 - HKCU\..\Run: [Bmap] "C:\WINDOWS\System32\APPATC~1\chkntfs.exe" -vt yazr O4 - HKCU\..\Run: [Zbgs] C:\PROGRA~1\SSEMBL~1\JVAW~1.EXE O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O20 - AppInit_DLLs: C:\WINDOWS\System32\rundll.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
You need To disable SpySweeper and Ad-Watch, it can stop our fix.
SpySweeper

To disable SpySweeper Shields

  • Open SpySweeper.
  • Click Shield Settings on the right
    (or Shields on the left, depending what screen you're on).
  • Click Internet Explorer and uncheck all items.
  • Click Windows System and uncheck all items.
  • Click Hosts File and uncheck all items.
  • Click Startup Programs and uncheck all items.
  • Close SpySweeper.After all of the fixes are complete it is very important that you enable Real-time Protection again.




Ad-Watch

Please disable Ad-Watch, as it may hinder the removal of some HijackThis entries. You can re-enable it after your computer is clean.

To disable Ad-Watch:

1. Right click on the Ad-Watch icon in the system tray and select "Restore Ad-Watch".
2. At the bottom of the screen there will be two checkable items called "Active" and "Automatic".Active: Switches Monitoring On or Off without closing
Automatic: Switches Automatic Blocking On or Off
3. Uncheck (red X) both items.



Please do not delete anything unless instructed to.




Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\System32\WinNB58.dll (file missing)
O4 - HKCU\..\Run: [Bmap] "C:\WINDOWS\System32\APPATC~1\chkntfs.exe" -vt yazr
O4 - HKCU\..\Run: [Zbgs] C:\PROGRA~1\SSEMBL~1\JVAW~1.EXE
O20 - AppInit_DLLs: C:\WINDOWS\System32\rundll.dll


Close ALL windows and browsers except HijackThis and click "Fix checked"






Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Okay thank you again for your help. I have followed your intructions exactly except for disabling spy sweeper, I do not have spy sweeper however My norton antivirus sweeps for stuff constantly so I disabled it. Anyway eveything went great except when I tried to remove line 020 - Appinit it said there was an error and then it removed it anyway. When I restarted my pc Ad-aware noticed some registry atempts I blocked them. Norton is still saying that I have a virus in xxyxwuv.dll and it says that it is a "downloader" Everything else seems to be okay except for that line is back O20 - AppInit_DLLs: C:\WINDOWS\System32\rundll.dll Here is my new log Logfile of HijackThis v1.99.1 Scan saved at 5:34:55 AM, on 9/8/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe C:\WINDOWS\System32\RunDll32.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe C:\Documents and Settings\Albert\Desktop\hj\HijackThis.exe O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [Motorola Wireless Manager UI] C:\WINDOWS\system32\WLTRAY O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [VOBID] C:\Program Files\Pinnacle\InstantCDDVD\InstantDrive\InstantDrive.exe /remount O4 - HKLM\..\Run: [IW ControlCenter] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe" O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O20 - AppInit_DLLs: C:\WINDOWS\System32\rundll.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
You need To disable TeaTimer, it can stop our fix.

1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts

The best way is to do both, Right click the system tray icon and shut down. This will reset TT's registry snapshot. Then, open spybot in advanced mode and turn it off. When cleaning is done, open Spybot in advanced mode to turn back on.




Ad-Watch

Please disable Ad-Watch, as it may hinder the removal of some HijackThis entries. You can re-enable it after your computer is clean.

To disable Ad-Watch:

1. Right click on the Ad-Watch icon in the system tray and select "Restore Ad-Watch".
2. At the bottom of the screen there will be two checkable items called "Active" and "Automatic".Active: Switches Monitoring On or Off without closing
Automatic: Switches Automatic Blocking On or Off
3. Uncheck (red X) both items.



1. Copy and paste this bold box text into a text editor such as Notepad.


REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""



2. Save this text as ResetAppInit.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop. Include the word REGEDIT4

3. Double-click on ResetAppInit.reg. When it asks you to merge the information to the registry click Yes.

4.Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Norton still days that there is an infection in xxyxwuv.dll Also Spybot S&D, Bit Torrent haven't been installed on my PC for awhile and I don't understand why they are showing up on this log. I followed your instruction precisely, but Norton says I still am infected. I know this is frustrating for you and I just want you to know that I really do appreciate all of the time you have spent helping me. Logfile of HijackThis v1.99.1 Scan saved at 12:29:06 AM, on 9/10/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe C:\WINDOWS\System32\RunDll32.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe C:\Documents and Settings\Albert\Desktop\hj\HijackThis.exe O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [Motorola Wireless Manager UI] C:\WINDOWS\system32\WLTRAY O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [VOBID] C:\Program Files\Pinnacle\InstantCDDVD\InstantDrive\InstantDrive.exe /remount O4 - HKLM\..\Run: [IW ControlCenter] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe" O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

Open the HijackThis Folder. Find the file HijackThis.exe, Right Click on the file and Select Rename. Rename Hijackthis.exe to Spyware.exe.


Open C:\Documents and Settings\Albert\Desktop\hj\HijackThis.exe <–Rename HijackThis.exe to Spyware.exe.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.

Post a new HijackThis Log.
Followed instrctions exactly here is my new log. Logfile of HijackThis v1.99.1 Scan saved at 12:19:47 PM, on 9/10/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe C:\WINDOWS\System32\RunDll32.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Albert\Desktop\hj\Spyware.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {1A96BF57-CC29-4055-A962-E2B1EBCA0EE1} - (no file) O2 - BHO: (no name) - {1D10D845-EB53-4283-A691-A72D12118BE7} - (no file) O2 - BHO: (no name) - {435328EB-8EF8-49C5-A047-3BB4048099F1} - (no file) O2 - BHO: (no name) - {4E70A7A0-22A2-4843-B53B-5022E1F061C0} - (no file) O2 - BHO: (no name) - {5A3E97DD-2A08-48BC-8F43-C0DEABC90266} - C:\WINDOWS\System32\xxyxwuv.dll O2 - BHO: (no name) - {6854B941-45D8-4E5B-BA7E-24414851E7B8} - C:\WINDOWS\System32\gebyw.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\System32\WinNB58.dll (file missing) O2 - BHO: (no name) - {A0015195-470D-4CA6-BF2F-9A61B61F7E06} - (no file) O2 - BHO: (no name) - {AAD16DAE-56D4-4DEE-9BEB-8869858C60DB} - (no file) O2 - BHO: (no name) - {BC9BAF99-2492-422D-8699-FB7406C34621} - (no file) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {D704A92A-68A9-4DFF-B605-2A95B57E221B} - (no file) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [Motorola Wireless Manager UI] C:\WINDOWS\system32\WLTRAY O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [VOBID] C:\Program Files\Pinnacle\InstantCDDVD\InstantDrive\InstantDrive.exe /remount O4 - HKLM\..\Run: [IW ControlCenter] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe" O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O20 - Winlogon Notify: gebyw - C:\WINDOWS\System32\gebyw.dll O20 - Winlogon Notify: winlft32 - winlft32.dll (file missing) O20 - Winlogon Notify: xxyxwuv - C:\WINDOWS\SYSTEM32\xxyxwuv.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
* Download Combofix to your desktop.
Doubleclick combo.exe
Follow the prompts.
Don't click on the window while the fix is running, because that will cause your system to hang.

When finished, it should produce a log, combofix.txt.
Post this log in your next reply together with a new hijackthislog.
OKay here are my new logs. Albert - 06-09-10 12:41:25.32 ComboFix 06.09.07 - Running from: C:\Documents and Settings\[removed]\Desktop Microsoft Windows XP [Version 5.1.2600] ((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log ))))))))))))))))))))))))))))))))))))))))))))))))))) * * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * * 06-08-10 21:15 28672 sethc.exe.qoo 06-09-06 21:49 265 fkjfw.dll.qoo 06-08-16 14:57 53 vbceeo.dat.qoo DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Program Files\Inetget2 C:\WINDOWS\system32\components C:\Program Files\Common Files\{481EAAFC-0703-1033-0221-030327030001} ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Folders Quarantined: C:\QooBox\Purity\Documents and Settings\Albert\Application Data\CROSOF~1 C:\QooBox\Purity\Documents and Settings\Albert\Application Data\SKS~1 C:\QooBox\Purity\Documents and Settings\Albert\Application Data\SKS~1\??sks C:\QooBox\Purity\Documents and Settings\Albert\Application Data\SKS~1\??sks\!update-4115.0000 C:\QooBox\Purity\WINDOWS\CURITY~1 C:\QooBox\Purity\WINDOWS\system32\ECURIT~1 ((((((((((((((((((((((((((((((( Files Created from 2006-08-10 to 2006-09-10 )))))))))))))))))))))))))))))))))) 2006-09-06 21:19 9,216 –a—— C:\WINDOWS\system32\wuauserv.dll 2006-09-06 21:19 86,528 –a—— C:\WINDOWS\system32\wlnotify.dll 2006-09-06 21:19 86,016 –a—— C:\WINDOWS\system32\xactsrv.dll 2006-09-06 21:19 77,824 –a—— C:\WINDOWS\system32\wmpstub.exe 2006-09-06 21:19 77,824 –a—— C:\WINDOWS\system32\wmpshell.dll 2006-09-06 21:19 61,952 –a—— C:\WINDOWS\system32\webclnt.dll 2006-09-06 21:19 60,416 –a—— C:\WINDOWS\system32\wextract.exe 2006-09-06 21:19 56,832 –a—— C:\WINDOWS\system32\wzcdlg.dll 2006-09-06 21:19 51,200 –a—— C:\WINDOWS\system32\wmerrenu.dll 2006-09-06 21:19 48,640 –a—— C:\WINDOWS\system32\vdmredir.dll 2006-09-06 21:19 48,128 –a—— C:\WINDOWS\system32\winsta.dll 2006-09-06 21:19 479,261 –a—— C:\WINDOWS\system32\vbscript.dll 2006-09-06 21:19 47,616 –a—— C:\WINDOWS\system32\utilman.exe 2006-09-06 21:19 446,464 –a—— C:\WINDOWS\system32\wmvdmoe.dll 2006-09-06 21:19 442,398 –a—— C:\WINDOWS\system32\wmadmoe.dll 2006-09-06 21:19 409,088 –a—— C:\WINDOWS\system32\vssapi.dll 2006-09-06 21:19 38,912 –a—— C:\WINDOWS\system32\wsnmp32.dll 2006-09-06 21:19 339,456 –a—— C:\WINDOWS\system32\usp10.dll 2006-09-06 21:19 316,416 –a—— C:\WINDOWS\system32\zipfldr.dll 2006-09-06 21:19 316,416 –a—— C:\WINDOWS\system32\wiaservc.dll 2006-09-06 21:19 311,327 –a—— C:\WINDOWS\system32\wmv8dmod.dll 2006-09-06 21:19 296,448 –a—— C:\WINDOWS\system32\wmstream.dll 2006-09-06 21:19 294,912 –a—— C:\WINDOWS\system32\wmvdmod.dll 2006-09-06 21:19 274,432 –a—— C:\WINDOWS\system32\wmasf.dll 2006-09-06 21:19 266,752 –a—— C:\WINDOWS\winhlp32.exe 2006-09-06 21:19 264,704 –a—— C:\WINDOWS\system32\wzcsvc.dll 2006-09-06 21:19 258,048 –a—— C:\WINDOWS\system32\webcheck.dll 2006-09-06 21:19 253,952 –a—— C:\WINDOWS\system32\wmpcd.dll 2006-09-06 21:19 253,952 –a—— C:\WINDOWS\system32\wmnetmgr.dll 2006-09-06 21:19 247,808 –a—— C:\WINDOWS\system32\wow32.dll 2006-09-06 21:19 23,552 –a—— C:\WINDOWS\system32\wzcsapi.dll 2006-09-06 21:19 203,264 –a—— C:\WINDOWS\system32\uxtheme.dll 2006-09-06 21:19 184,320 –a—— C:\WINDOWS\system32\wmadmod.dll 2006-09-06 21:19 172,664 –a—— C:\WINDOWS\system32\xenroll.dll 2006-09-06 21:19 171,520 –a—— C:\WINDOWS\system32\winmm.dll 2006-09-06 21:19 17,408 –a—— C:\WINDOWS\system32\wtsapi32.dll 2006-09-06 21:19 168,448 –a—— C:\WINDOWS\system32\wldap32.dll 2006-09-06 21:19 165,376 –a—— C:\WINDOWS\system32\w32time.dll 2006-09-06 21:19 16,384 –a—— C:\WINDOWS\system32\watchdog.sys 2006-09-06 21:19 13,312 –a—— C:\WINDOWS\system32\wship6.dll 2006-09-06 21:19 124,928 –a—— C:\WINDOWS\system32\webvw.dll 2006-09-06 21:19 119,808 –a—— C:\WINDOWS\system32\wiadss.dll 2006-09-06 21:19 118,784 –a—— C:\WINDOWS\system32\wmsdmoe.dll 2006-09-06 21:19 110,592 –a—— C:\WINDOWS\system32\wmsdmod.dll 2006-09-06 21:19 1,998,848 –a—— C:\WINDOWS\system32\wmploc.dll 2006-09-06 21:19 1,404,928 –a—— C:\WINDOWS\system32\wmpui.dll 2006-09-06 21:19 1,298,432 –a—— C:\WINDOWS\system32\wmpcore.dll 2006-09-06 21:19 1,220,608 –a—— C:\WINDOWS\system32\wmvcore.dll 2006-09-06 21:18 91,136 –a—— C:\WINDOWS\system32\rastls.dll 2006-09-06 21:18 88,064 –a—— C:\WINDOWS\system32\tscfgwmi.dll 2006-09-06 21:18 87,304 –a—— C:\WINDOWS\system32\rdpdd.dll 2006-09-06 21:18 82,944 –a—— C:\WINDOWS\system32\smlogsvc.exe 2006-09-06 21:18 82,944 –a—— C:\WINDOWS\system32\psbase.dll 2006-09-06 21:18 81,920 –a—— C:\WINDOWS\system32\trkwks.dll 2006-09-06 21:18 8,192 –a—— C:\WINDOWS\system32\scrnsave.scr 2006-09-06 21:18 75,912 –a—— C:\WINDOWS\system32\rdpwsx.dll 2006-09-06 21:18 74,240 –a—— C:\WINDOWS\system32\rtcshare.exe 2006-09-06 21:18 71,168 –a—— C:\WINDOWS\system32\telnet.exe 2006-09-06 21:18 71,168 –a—— C:\WINDOWS\system32\storprop.dll 2006-09-06 21:18 71,168 –a—— C:\WINDOWS\system32\sdbinst.exe 2006-09-06 21:18 674,816 –a—— C:\WINDOWS\system32\sxs.dll 2006-09-06 21:18 667,648 –a—— C:\WINDOWS\system32\ss3dfo.scr 2006-09-06 21:18 66,560 –a—— C:\WINDOWS\system32\spoolss.dll 2006-09-06 21:18 66,048 –a—— C:\WINDOWS\system32\sigverif.exe 2006-09-06 21:18 638,976 –a—— C:\WINDOWS\system32\sstext3d.scr 2006-09-06 21:18 63,488 –a—— C:\WINDOWS\system32\srclient.dll 2006-09-06 21:18 62,976 –a—— C:\WINDOWS\system32\shgina.dll 2006-09-06 21:18 61,952 –a—— C:\WINDOWS\system32\sti.dll 2006-09-06 21:18 60,416 –a—— C:\WINDOWS\system32\shimeng.dll 2006-09-06 21:18 6,144 –a—— C:\WINDOWS\system32\sensapi.dll 2006-09-06 21:18 57,856 –a—— C:\WINDOWS\system32\raschap.dll 2006-09-06 21:18 569,344 –a—— C:\WINDOWS\system32\sspipes.scr 2006-09-06 21:18 56,320 –a—— C:\WINDOWS\system32\remotepg.dll 2006-09-06 21:18 548,864 –a—— C:\WINDOWS\system32\rtcdll.dll 2006-09-06 21:18 534,016 –a—— C:\WINDOWS\system32\spider.exe 2006-09-06 21:18 530,432 –a—— C:\WINDOWS\system32\rpcrt4.dll 2006-09-06 21:18 52,224 –a—— C:\WINDOWS\system32\secur32.dll 2006-09-06 21:18 511,488 –a—— C:\WINDOWS\system32\qedit.dll 2006-09-06 21:18 48,128 –a—— C:\WINDOWS\system32\reg.exe 2006-09-06 21:18 44,032 –a—— C:\WINDOWS\system32\regapi.dll 2006-09-06 21:18 44,032 –a—— C:\WINDOWS\system32\rdpclip.exe 2006-09-06 21:18 43,008 –a—— C:\WINDOWS\system32\ssdpsrv.dll 2006-09-06 21:18 423,424 –a—— C:\WINDOWS\system32\riched20.dll 2006-09-06 21:18 420,864 –a—— C:\WINDOWS\system32\shimgvw.dll 2006-09-06 21:18 40,960 –a—— C:\WINDOWS\system32\tscupgrd.exe 2006-09-06 21:18 385,024 –a—— C:\WINDOWS\system32\sqlsrv32.dll 2006-09-06 21:18 384,000 –a—— C:\WINDOWS\system32\themeui.dll 2006-09-06 21:18 364,544 –a—— C:\WINDOWS\system32\ssflwbox.scr 2006-09-06 21:18 36,352 –a—— C:\WINDOWS\system32\sens.dll 2006-09-06 21:18 357,376 –a—— C:\WINDOWS\system32\qdvd.dll 2006-09-06 21:18 34,304 –a—— C:\WINDOWS\system32\rcimlby.exe 2006-09-06 21:18 334,848 –a—— C:\WINDOWS\system32\smlogcfg.dll 2006-09-06 21:18 33,280 –a—— C:\WINDOWS\system32\shmgrate.exe 2006-09-06 21:18 32,256 –a—— C:\WINDOWS\system32\umandlg.dll 2006-09-06 21:18 31,744 –a—— C:\WINDOWS\system32\pid.dll 2006-09-06 21:18 3,338 –a—— C:\WINDOWS\system32\redir.exe 2006-09-06 21:18 297,984 –a—— C:\WINDOWS\system32\scesrv.dll 2006-09-06 21:18 27,136 –a—— C:\WINDOWS\system32\ssdpapi.dll 2006-09-06 21:18 260,608 –a—— C:\WINDOWS\system32\rpcss.dll 2006-09-06 21:18 251,904 –a—— C:\WINDOWS\system32\strmdll.dll 2006-09-06 21:18 24,064 –a—— C:\WINDOWS\system32\skeys.exe 2006-09-06 21:18 233,984 –a—— C:\WINDOWS\system32\tapisrv.dll 2006-09-06 21:18 231,424 –a—— C:\WINDOWS\system32\upnpui.dll 2006-09-06 21:18 226,304 –a—— C:\WINDOWS\system32\srrstr.dll 2006-09-06 21:18 22,528 –a—— C:\WINDOWS\system32\slayerxp.dll 2006-09-06 21:18 22,528 –a—— C:\WINDOWS\system32\shfolder.dll 2006-09-06 21:18 22,016 –a—— C:\WINDOWS\system32\udhisapi.dll 2006-09-06 21:18 200,192 –a—— C:\WINDOWS\system32\termsrv.dll 2006-09-06 21:18 20,992 –a—— C:\WINDOWS\system32\setup.exe 2006-09-06 21:18 193,536 –a—— C:\WINDOWS\system32\rasppp.dll 2006-09-06 21:18 19,456 –a—— C:\WINDOWS\system32\ssmarque.scr 2006-09-06 21:18 184,832 –a—— C:\WINDOWS\system32\qcap.dll 2006-09-06 21:18 18,944 –a—— C:\WINDOWS\system32\ssbezier.scr 2006-09-06 21:18 174,592 –a—— C:\WINDOWS\system32\scecli.dll 2006-09-06 21:18 171,008 –a—— C:\WINDOWS\system32\sccsccp.dll 2006-09-06 21:18 17,408 –a—— C:\WINDOWS\system32\ssmyst.scr 2006-09-06 21:18 17,408 –a—— C:\WINDOWS\system32\psapi.dll 2006-09-06 21:18 169,984 –a—— C:\WINDOWS\system32\sccbase.dll 2006-09-06 21:18 165,376 –a—— C:\WINDOWS\system32\tapi32.dll 2006-09-06 21:18 164,864 –a—— C:\WINDOWS\system32\upnphost.dll 2006-09-06 21:18 16,896 –a—— C:\WINDOWS\system32\snmpapi.dll 2006-09-06 21:18 16,384 –a—— C:\WINDOWS\system32\ups.exe 2006-09-06 21:18 16,384 –a—— C:\WINDOWS\system32\ping.exe 2006-09-06 21:18 159,232 –a—— C:\WINDOWS\system32\schedsvc.dll 2006-09-06 21:18 158,720 –a—— C:\WINDOWS\system32\srsvc.dll 2006-09-06 21:18 14,848 –a—— C:\WINDOWS\system32\rdpsnd.dll 2006-09-06 21:18 135,680 –a—— C:\WINDOWS\system32\rdchost.dll 2006-09-06 21:18 134,144 –a—— C:\WINDOWS\regedit.exe 2006-09-06 21:18 133,632 –a—— C:\WINDOWS\system32\rsaenh.dll 2006-09-06 21:18 133,120 –a—— C:\WINDOWS\system32\sfc_os.dll 2006-09-06 21:18 130,560 –a—— C:\WINDOWS\system32\sti_ci.dll 2006-09-06 21:18 13,824 –a—— C:\WINDOWS\system32\rassapi.dll 2006-09-06 21:18 13,312 –a—— C:\WINDOWS\system32\ssstars.scr 2006-09-06 21:18 128,512 –a—— C:\WINDOWS\system32\taskmgr.exe 2006-09-06 21:18 120,320 –a—— C:\WINDOWS\system32\upnp.dll 2006-09-06 21:18 12,800 –a—— C:\WINDOWS\system32\runonce.exe 2006-09-06 21:18 12,288 –a—— C:\WINDOWS\system32\rdsaddin.exe 2006-09-06 21:18 117,760 –a—— C:\WINDOWS\system32\stobject.dll 2006-09-06 21:18 116,224 –a—— C:\WINDOWS\system32\shsvcs.dll 2006-09-06 21:18 11,776 –a—— C:\WINDOWS\system32\sigtab.dll 2006-09-06 21:18 107,008 –a—— C:\WINDOWS\system32\umpnpmgr.dll 2006-09-06 21:18 106,496 –a—— C:\WINDOWS\system32\url.dll 2006-09-06 21:18 10,752 –a—— C:\WINDOWS\system32\tracert.exe 2006-09-06 21:18 1,349,120 –a—— C:\WINDOWS\system32\query.dll 2006-09-06 21:18 1,157,632 –a—— C:\WINDOWS\system32\sfcfiles.dll 2006-09-06 21:18 1,142,784 –a—— C:\WINDOWS\system32\quartz.dll 2006-09-06 21:17 98,304 –a—— C:\WINDOWS\system32\oleprn.dll 2006-09-06 21:17 95,744 –a—— C:\WINDOWS\system32\nlhtml.dll 2006-09-06 21:17 94,208 –a—— C:\WINDOWS\system32\odbccp32.dll 2006-09-06 21:17 686,080 –a—— C:\WINDOWS\system32\opengl32.dll 2006-09-06 21:17 61,440 –a—— C:\WINDOWS\system32\odbccu32.dll 2006-09-06 21:17 61,440 –a—— C:\WINDOWS\system32\odbccr32.dll 2006-09-06 21:17 58,880 –a—— C:\WINDOWS\system32\pautoenr.dll 2006-09-06 21:17 53,248 –a—— C:\WINDOWS\system32\packager.exe 2006-09-06 21:17 53,248 –a—— C:\WINDOWS\system32\odbcconf.exe 2006-09-06 21:17 49,152 –a—— C:\WINDOWS\system32\npptools.dll 2006-09-06 21:17 392,704 –a—— C:\WINDOWS\system32\ntmssvc.dll 2006-09-06 21:17 38,400 –a—— C:\WINDOWS\system32\ntmsapi.dll 2006-09-06 21:17 38,400 –a—— C:\WINDOWS\system32\ntlanman.dll 2006-09-06 21:17 33,808 –a—— C:\WINDOWS\system32\ntio.sys 2006-09-06 21:17 328,704 –a—— C:\WINDOWS\system32\oakley.dll 2006-09-06 21:17 32,768 –a—— C:\WINDOWS\system32\odbcad32.exe 2006-09-06 21:17 254,976 –a—— C:\WINDOWS\system32\pdh.dll 2006-09-06 21:17 24,576 –a—— C:\WINDOWS\system32\odbcbcp.dll 2006-09-06 21:17 24,576 –a—— C:\WINDOWS\system32\nmmkcert.dll 2006-09-06 21:17 238,080 –a—— C:\WINDOWS\system32\newdev.dll 2006-09-06 21:17 212,480 –a—— C:\WINDOWS\system32\osk.exe 2006-09-06 21:17 200,704 –a—— C:\WINDOWS\system32\odbc32.dll 2006-09-06 21:17 165,888 –a—— C:\WINDOWS\system32\ntmsdba.dll 2006-09-06 21:17 16,384 –a—— C:\WINDOWS\system32\odbc32gt.dll 2006-09-06 21:17 147,456 –a—— C:\WINDOWS\system32\odbctrac.dll 2006-09-06 21:17 137,216 –a—— C:\WINDOWS\system32\ntshrui.dll 2006-09-06 21:17 122,880 –a—— C:\WINDOWS\system32\odbcconf.dll 2006-09-06 21:17 12,288 –a—— C:\WINDOWS\system32\odbcp32r.dll 2006-09-06 21:17 112,128 –a—— C:\WINDOWS\system32\ntmarta.dll 2006-09-06 21:17 109,568 –a—— C:\WINDOWS\system32\offfilt.dll 2006-09-06 21:17 1,677,312 –a—— C:\WINDOWS\system32\wmvcore2.dll 2006-09-06 21:17 1,169,920 –a—— C:\WINDOWS\system32\ole32.dll 2006-09-06 21:16 921,475 –a—— C:\WINDOWS\system32\ati3d2ag.dll 2006-09-06 21:16 9,728 –a—— C:\WINDOWS\system32\mstinit.exe 2006-09-06 21:16 857,600 –a—— C:\WINDOWS\system32\netplwiz.dll 2006-09-06 21:16 844,675 –a—— C:\WINDOWS\system32\ati3d1ag.dll 2006-09-06 21:16 81,408 –a—— C:\WINDOWS\system32\msoert2.dll 2006-09-06 21:16 699,392 –a—— C:\WINDOWS\system32\msxml2.dll 2006-09-06 21:16 598,016 –a—— C:\WINDOWS\system32\mstscax.dll 2006-09-06 21:16 584,192 –a—— C:\WINDOWS\system32\netcfgx.dll 2006-09-06 21:16 552,991 –a—— C:\WINDOWS\system32\msrepl40.dll 2006-09-06 21:16 421,919 –a—— C:\WINDOWS\system32\msrd2x40.dll 2006-09-06 21:16 42,496 –a—— C:\WINDOWS\system32\ncobjapi.dll 2006-09-06 21:16 401,462 –a—— C:\WINDOWS\system32\msvcp60.dll 2006-09-06 21:16 399,360 –a—— C:\WINDOWS\system32\netlogon.dll 2006-09-06 21:16 39,424 –a—— C:\WINDOWS\system32\net.exe 2006-09-06 21:16 388,608 –a—— C:\WINDOWS\system32\mstsc.exe 2006-09-06 21:16 377,984 –a—— C:\WINDOWS\system32\ati2dvaa.dll 2006-09-06 21:16 348,191 –a—— C:\WINDOWS\system32\mspbde40.dll 2006-09-06 21:16 344,095 –a—— C:\WINDOWS\system32\msxbde40.dll 2006-09-06 21:16 339,968 –a—— C:\WINDOWS\system32\mspaint.exe 2006-09-06 21:16 326,656 –a—— C:\WINDOWS\system32\netsetup.exe 2006-09-06 21:16 323,072 –a—— C:\WINDOWS\system32\msvcrt.dll 2006-09-06 21:16 319,760 –a—— C:\WINDOWS\system32\msnsspc.dll 2006-09-06 21:16 253,983 –a—— C:\WINDOWS\system32\mstext40.dll 2006-09-06 21:16 250,368 –a—— C:\WINDOWS\system32\mstask.dll 2006-09-06 21:16 245,760 –a—— C:\WINDOWS\system32\msscp.dll 2006-09-06 21:16 241,725 –a—— C:\WINDOWS\system32\msuni11.dll 2006-09-06 21:16 228,864 –a—— C:\WINDOWS\system32\msoeacct.dll 2006-09-06 21:16 202,496 –a—— C:\WINDOWS\system32\ati2dvag.dll 2006-09-06 21:16 192,512 –a—— C:\WINDOWS\system32\mswebdvd.dll 2006-09-06 21:16 182,784 –a—— C:\WINDOWS\system32\msutb.dll 2006-09-06 21:16 18,944 –a—— C:\WINDOWS\system32\faxpatch.exe 2006-09-06 21:16 175,104 –a—— C:\WINDOWS\system32\mspmsp.dll 2006-09-06 21:16 16,384 –a—— C:\WINDOWS\system32\nddenb32.dll 2006-09-06 21:16 154,112 –a—— C:\WINDOWS\system32\netman.dll 2006-09-06 21:16 131,072 –a—— C:\WINDOWS\system32\msorcl32.dll 2006-09-06 21:16 115,200 –a—— C:\WINDOWS\system32\net1.exe 2006-09-06 21:16 113,664 –a—— C:\WINDOWS\system32\msvfw32.dll 2006-09-06 21:16 105,984 –a—— C:\WINDOWS\system32\netdde.exe 2006-09-06 21:16 10,240 –a—— C:\WINDOWS\system32\msrle32.dll 2006-09-06 21:16 1,622,528 –a—— C:\WINDOWS\system32\netshell.dll 2006-09-06 21:16 1,220,608 –a—— C:\WINDOWS\system32\msvidctl.dll 2006-09-06 21:16 1,122,304 –a—— C:\WINDOWS\system32\msxml3.dll 2006-09-06 21:15 68,096 –a—— C:\WINDOWS\system32\mscms.dll 2006-09-06 21:15 67,584 –a—— C:\WINDOWS\system32\msctfp.dll 2006-09-06 21:15 65,536 –a—— C:\WINDOWS\system32\msconf.dll 2006-09-06 21:15 64,512 –a—— C:\WINDOWS\system32\msiexec.exe 2006-09-06 21:15 6,656 –a—— C:\WINDOWS\system32\laprxy.dll 2006-09-06 21:15 57,856 –a—— C:\WINDOWS\system32\licwmi.dll 2006-09-06 21:15 56,320 –a—— C:\WINDOWS\system32\mshtmler.dll 2006-09-06 21:15 512,031 –a—— C:\WINDOWS\system32\msexch40.dll 2006-09-06 21:15 504,320 –a—— C:\WINDOWS\system32\logonui.exe 2006-09-06 21:15 4,608 –a—— C:\WINDOWS\system32\msimg32.dll 2006-09-06 21:15 4,126 –a—— C:\WINDOWS\system32\msdxmlc.dll 2006-09-06 21:15 381,440 –a—— C:\WINDOWS\system32\lmrt.dll 2006-09-06 21:15 368,710 –a—— C:\WINDOWS\system32\msisam11.dll 2006-09-06 21:15 359,936 –a—— C:\WINDOWS\system32\msdtcprx.dll 2006-09-06 21:15 348,195 –a—— C:\WINDOWS\system32\msjetoledb40.dll 2006-09-06 21:15 32,256 –a—— C:\WINDOWS\system32\mnmdd.dll 2006-09-06 21:15 319,519 –a—— C:\WINDOWS\system32\msexcl40.dll 2006-09-06 21:15 305,664 –a—— C:\WINDOWS\system32\msihnd.dll 2006-09-06 21:15 266,752 –a—— C:\WINDOWS\system32\msctf.dll 2006-09-06 21:15 241,695 –a—— C:\WINDOWS\system32\msjtes40.dll 2006-09-06 21:15 24,576 –a—— C:\WINDOWS\system32\logagent.exe 2006-09-06 21:15 233,472 –a—— C:\WINDOWS\system32\mpg4dmod.dll 2006-09-06 21:15 229,888 –a—— C:\WINDOWS\system32\msieftp.dll 2006-09-06 21:15 22,528 –a—— C:\WINDOWS\system32\mslbui.dll 2006-09-06 21:15 219,648 –a—— C:\WINDOWS\system32\logon.scr 2006-09-06 21:15 213,023 –a—— C:\WINDOWS\system32\msltus40.dll 2006-09-06 21:15 210,944 –a—— C:\WINDOWS\system32\moricons.dll 2006-09-06 21:15 2,086,400 –a—— C:\WINDOWS\system32\msi.dll 2006-09-06 21:15 196,096 –a—— C:\WINDOWS\system32\mobsync.dll 2006-09-06 21:15 19,456 –a—— C:\WINDOWS\system32\licmgr10.dll 2006-09-06 21:15 174,592 –a—— C:\WINDOWS\system32\msnetobj.dll 2006-09-06 21:15 163,840 –a—— C:\WINDOWS\system32\mindex.dll 2006-09-06 21:15 143,872 –a—— C:\WINDOWS\system32\msimtf.dll 2006-09-06 21:15 126,976 –a—— C:\WINDOWS\system32\msdart.dll 2006-09-06 21:15 12,288 –a—— C:\WINDOWS\system32\mscpx32r.dll 2006-09-06 21:15 116,736 –a—— C:\WINDOWS\system32\mplay32.exe 2006-09-06 21:15 10,240 –a—— C:\WINDOWS\system32\localui.dll 2006-09-06 21:15 1,503,262 –a—— C:\WINDOWS\system32\msjet40.dll 2006-09-06 21:15 1,128,960 –a—— C:\WINDOWS\system32\mmcndmgr.dll 2006-09-06 21:12 91,648 –a—— C:\WINDOWS\system32\iuctl.dll 2006-09-06 21:12 73,728 –a—— C:\WINDOWS\system32\tlntsess.exe 2006-09-06 21:12 7,168 –a—— C:\WINDOWS\system32\tlntsvrp.dll 2006-09-06 21:12 7,040 –a—— C:\WINDOWS\system32\kd1394.dll 2006-09-06 21:12 67,584 –a—— C:\WINDOWS\system32\tlntsvr.exe 2006-09-06 21:12 60,928 –a—— C:\WINDOWS\system32\ipv6.exe 2006-09-06 21:12 57,856 –a—— C:\WINDOWS\system32\tlntadmn.exe 2006-09-06 21:12 545,792 –a—— C:\WINDOWS\system32\wsecedit.dll 2006-09-06 21:12 51,712 –a—— C:\WINDOWS\system32\ipconfig.exe 2006-09-06 21:12 49,664 –a—— C:\WINDOWS\system32\ixsso.dll 2006-09-06 21:12 435,200 –a—— C:\WINDOWS\system32\ipnathlp.dll 2006-09-06 21:12 42,537 –a—— C:\WINDOWS\system32\keyboard.sys 2006-09-06 21:12 318,464 –a—— C:\WINDOWS\system32\ippromon.dll 2006-09-06 21:12 272,896 –a—— C:\WINDOWS\system32\kerberos.dll 2006-09-06 21:12 27,648 –a—— C:\WINDOWS\system32\pidgen.dll 2006-09-06 21:12 231,936 –a—— C:\WINDOWS\system32\tracerpt.exe 2006-09-06 21:12 155,648 –a—— C:\WINDOWS\system32\ipsecsvc.dll 2006-09-06 21:12 143,872 –a—— C:\WINDOWS\system32\itircl.dll 2006-09-06 21:12 134,144 –a—— C:\WINDOWS\system32\ipv6mon.dll 2006-09-06 21:12 122,368 –a—— C:\WINDOWS\system32\itss.dll 2006-09-06 21:12 115,200 –a—— C:\WINDOWS\system32\dpcdll.dll 2006-09-06 21:11 9,216 –a—— C:\WINDOWS\system32\icaapi.dll 2006-09-06 21:11 89,088 –a—— C:\WINDOWS\system32\mqsec.dll 2006-09-06 21:11 8,832 –a—— C:\WINDOWS\system32\framebuf.dll 2006-09-06 21:11 73,728 –a—— C:\WINDOWS\system32\ils.dll 2006-09-06 21:11 67,584 –a—— C:\WINDOWS\system32\fdeploy.dll 2006-09-06 21:11 613,888 –a—— C:\WINDOWS\system32\mqqm.dll 2006-09-06 21:11 59,392 –a—— C:\WINDOWS\system32\iesetup.dll 2006-09-06 21:11 587,776 –a—— C:\WINDOWS\system32\inetcomm.dll 2006-09-06 21:11 57,344 –a—— C:\WINDOWS\system32\nwwks.dll 2006-09-06 21:11 478,720 –a—— C:\WINDOWS\system32\mqsnap.dll 2006-09-06 21:11 469,504 –a—— C:\WINDOWS\system32\mqutil.dll 2006-09-06 21:11 37,888 –a—— C:\WINDOWS\system32\hhsetup.dll 2006-09-06 21:11 36,922 –a—— C:\WINDOWS\system32\imeshare.dll 2006-09-06 21:11 30,208 –a—— C:\WINDOWS\system32\imgutil.dll 2006-09-06 21:11 294,912 –a—— C:\WINDOWS\system32\iedkcs32.dll 2006-09-06 21:11 28,672 –a—— C:\WINDOWS\system32\ie4uinit.exe 2006-09-06 21:11 277,504 –a—— C:\WINDOWS\system32\appmgr.dll 2006-09-06 21:11 240,640 –a—— C:\WINDOWS\system32\hnetcfg.dll 2006-09-06 21:11 236,032 –a—— C:\WINDOWS\system32\icm32.dll 2006-09-06 21:11 204,288 –a—— C:\WINDOWS\system32\ieaksie.dll 2006-09-06 21:11 183,296 –a—— C:\WINDOWS\system32\gptext.dll 2006-09-06 21:11 164,864 –a—— C:\WINDOWS\system32\mqrt.dll 2006-09-06 21:11 164,352 –a—— C:\WINDOWS\system32\mqtrig.dll 2006-09-06 21:11 156,672 –a—— C:\WINDOWS\system32\appmgmts.dll 2006-09-06 21:11 14,848 –a—— C:\WINDOWS\system32\mqise.dll 2006-09-06 21:11 130,048 –a—— C:\WINDOWS\system32\mqad.dll 2006-09-06 21:11 126,976 –a—— C:\WINDOWS\system32\ieakeng.dll 2006-09-06 21:11 123,904 –a—— C:\WINDOWS\system32\imapi.exe 2006-09-06 21:11 114,176 –a—— C:\WINDOWS\system32\input.dll 2006-09-06 21:11 113,664 –a—— C:\WINDOWS\system32\schtasks.exe 2006-09-06 21:11 113,152 –a—— C:\WINDOWS\system32\idq.dll 2006-09-06 21:11 113,152 –a—— C:\WINDOWS\system32\gpresult.exe 2006-09-06 21:11 103,936 –a—— C:\WINDOWS\system32\rsnotify.exe 2006-09-06 21:11 103,936 –a—— C:\WINDOWS\system32\imm32.dll 2006-09-06 21:11 10,752 –a—— C:\WINDOWS\hh.exe 2006-09-06 21:10 98,816 –a—— C:\WINDOWS\system32\clipbrd.exe 2006-09-06 21:10 94,720 –a—— C:\WINDOWS\system32\dmusic.dll 2006-09-06 21:10 91,648 –a—— C:\WINDOWS\system32\ahui.exe 2006-09-06 21:10 91,136 –a—— C:\WINDOWS\system32\advpack.dll 2006-09-06 21:10 9,216 –a—— C:\WINDOWS\system32\dumprep.exe 2006-09-06 21:10 82,432 –a—— C:\WINDOWS\system32\fldrclnr.dll 2006-09-06 21:10 802,304 –a—— C:\WINDOWS\system32\dxmrtp.dll 2006-09-06 21:10 8,192 –a—— C:\WINDOWS\system32\autolfn.exe 2006-09-06 21:10 786,432 –a—— C:\WINDOWS\system32\dxdiag.exe 2006-09-06 21:10 77,312 –a—— C:\WINDOWS\system32\dmscript.dll 2006-09-06 21:10 76,830 –a—— C:\WINDOWS\system32\drmstor.dll 2006-09-06 21:10 76,288 –a—— C:\WINDOWS\system32\dfrgfat.exe 2006-09-06 21:10 76,288 –a—— C:\WINDOWS\system32\avifil32.dll 2006-09-06 21:10 74,810 –a—— C:\WINDOWS\system32\atl.dll 2006-09-06 21:10 71,680 –a—— C:\WINDOWS\system32\browsewm.dll 2006-09-06 21:10 70,656 –a—— C:\WINDOWS\system32\defrag.exe 2006-09-06 21:10 70,144 –a—— C:\WINDOWS\system32\cryptdlg.dll 2006-09-06 21:10 66,560 –a—— C:\WINDOWS\system32\faultrep.dll 2006-09-06 21:10 64,512 –a—— C:\WINDOWS\system32\ciodm.dll 2006-09-06 21:10 62,976 –a—— C:\WINDOWS\system32\browselc.dll 2006-09-06 21:10 62,464 –a—— C:\WINDOWS\system32\adsmsext.dll 2006-09-06 21:10 61,440 –a—— C:\WINDOWS\system32\dbnetlib.dll 2006-09-06 21:10 602,112 –a—— C:\WINDOWS\system32\drmv2clt.dll 2006-09-06 21:10 6,656 –a—— C:\WINDOWS\system32\batt.dll 2006-09-06 21:10 59,904 –a—— C:\WINDOWS\system32\cabinet.dll 2006-09-06 21:10 59,392 –a—— C:\WINDOWS\system32\6to4svc.dll 2006-09-06 21:10 582,656 –a—— C:\WINDOWS\system32\catsrvut.dll 2006-09-06 21:10 58,368 –a—— C:\WINDOWS\system32\dpvsetup.exe 2006-09-06 21:10 57,344 –a—— C:\WINDOWS\system32\dmcompos.dll 2006-09-06 21:10 56,320 –a—— C:\WINDOWS\system32\dpnhupnp.dll 2006-09-06 21:10 557,568 –a—— C:\WINDOWS\system32\crypt32.dll 2006-09-06 21:10 55,296 –a—— C:\WINDOWS\system32\digest.dll 2006-09-06 21:10 54,272 –a—— C:\WINDOWS\system32\clusapi.dll 2006-09-06 21:10 53,248 –a—— C:\WINDOWS\system32\cryptsvc.dll 2006-09-06 21:10 5,120 –a—— C:\WINDOWS\system32\asferror.dll 2006-09-06 21:10 498,205 –a—— C:\WINDOWS\system32\dxmasf.dll 2006-09-06 21:10 49,664 –a—— C:\WINDOWS\system32\dpwsockx.dll 2006-09-06 21:10 49,152 –a—— C:\WINDOWS\system32\eventlog.dll 2006-09-06 21:10 49,152 –a—— C:\WINDOWS\system32\browser.dll 2006-09-06 21:10 489,984 –a—— C:\WINDOWS\system32\dbghelp.dll 2006-09-06 21:10 471,040 –a—— C:\WINDOWS\system32\cryptui.dll 2006-09-06 21:10 45,568 –a—— C:\WINDOWS\system32\docprop2.dll 2006-09-06 21:10 41,984 –a—— C:\WINDOWS\system32\alg.exe 2006-09-06 21:10 41,472 –a—— C:\WINDOWS\system32\cmdl32.exe 2006-09-06 21:10 380,445 –a—— C:\WINDOWS\system32\expsrv.dll 2006-09-06 21:10 38,912 –a—— C:\WINDOWS\system32\audiosrv.dll 2006-09-06 21:10 35,328 –a—— C:\WINDOWS\system32\dfrgsnap.dll 2006-09-06 21:10 324,608 –a—— C:\WINDOWS\system32\cmdial32.dll 2006-09-06 21:10 32,768 –a—— C:\WINDOWS\system32\cfgbkend.dll 2006-09-06 21:10 31,744 –a—— C:\WINDOWS\system32\dmloader.dll 2006-09-06 21:10 307,712 –a—— C:\WINDOWS\system32\cscui.dll 2006-09-06 21:10 29,696 –a—— C:\WINDOWS\system32\dpnhpast.dll 2006-09-06 21:10 28,672 –a—— C:\WINDOWS\system32\dbnmpntw.dll 2006-09-06 21:10 266,240 –a—— C:\WINDOWS\system32\drmclien.dll 2006-09-06 21:10 263,680 –a—— C:\WINDOWS\system32\duser.dll 2006-09-06 21:10 263,168 –a—— C:\WINDOWS\system32\devmgr.dll 2006-09-06 21:10 26,112 –a—— C:\WINDOWS\system32\dmband.dll 2006-09-06 21:10 253,440 –a—— C:\WINDOWS\system32\ddraw.dll 2006-09-06 21:10 25,600 –a—— C:\WINDOWS\system32\dfsshlex.dll 2006-09-06 21:10 24,576 –a—— C:\WINDOWS\system32\dbmsvinn.dll 2006-09-06 21:10 24,576 –a—— C:\WINDOWS\system32\dbmsrpcn.dll 2006-09-06 21:10 24,576 –a—— C:\WINDOWS\system32\conime.exe 2006-09-06 21:10 239,616 –a—— C:\WINDOWS\system32\adsnt.dll 2006-09-06 21:10 238,592 –a—— C:\WINDOWS\system32\compatui.dll 2006-09-06 21:10 227,840 –a—— C:\WINDOWS\system32\dsquery.dll 2006-09-06 21:10 225,280 –a—— C:\WINDOWS\system32\es.dll 2006-09-06 21:10 22,528 –a—— C:\WINDOWS\system32\at.exe 2006-09-06 21:10 206,336 –a—— C:\WINDOWS\system32\dpvoice.dll 2006-09-06 21:10 20,480 –a—— C:\WINDOWS\system32\dbmsadsn.dll 2006-09-06 21:10 19,456 –a—— C:\WINDOWS\system32\fontview.exe 2006-09-06 21:10 19,456 –a—— C:\WINDOWS\system32\ersvc.dll 2006-09-06 21:10 186,880 –a—— C:\WINDOWS\system32\certcli.dll 2006-09-06 21:10 180,224 –a—— C:\WINDOWS\system32\dwwin.exe 2006-09-06 21:10 179,712 –a—— C:\WINDOWS\system32\cewmdm.dll 2006-09-06 21:10 178,688 –a—— C:\WINDOWS\system32\eudcedit.exe 2006-09-06 21:10 172,544 –a—— C:\WINDOWS\system32\dmime.dll 2006-09-06 21:10 168,960 –a—— C:\WINDOWS\system32\dinput8.dll 2006-09-06 21:10 165,376 –a—— C:\WINDOWS\system32\els.dll 2006-09-06 21:10 162,816 –a—— C:\WINDOWS\system32\adsldp.dll 2006-09-06 21:10 16,384 –a—— C:\WINDOWS\system32\ds32gt.dll 2006-09-06 21:10 158,720 –a—— C:\WINDOWS\system32\credui.dll 2006-09-06 21:10 156,672 –a—— C:\WINDOWS\system32\dpnet.dll 2006-09-06 21:10 151,552 –a—— C:\WINDOWS\system32\dinput.dll 2006-09-06 21:10 14,366 –a—— C:\WINDOWS\system32\asfsipc.dll 2006-09-06 21:10 139,776 –a—— C:\WINDOWS\system32\adsldpc.dll 2006-09-06 21:10 135,680 –a—— C:\WINDOWS\system32\dsprop.dll 2006-09-06 21:10 13,312 –a—— C:\WINDOWS\system32\ctfmon.exe 2006-09-06 21:10 124,928 –a—— C:\WINDOWS\system32\dssenh.dll 2006-09-06 21:10 115,712 –a—— C:\WINDOWS\system32\apphelp.dll 2006-09-06 21:10 113,152 –a—— C:\WINDOWS\system32\dfrgui.dll 2006-09-06 21:10 110,080 –a—— C:\WINDOWS\system32\dmstyle.dll 2006-09-06 21:10 103,424 –a—— C:\WINDOWS\system32\dgnet.dll 2006-09-06 21:10 1,180,672 –a—— C:\WINDOWS\system32\d3d8.dll 2006-09-06 21:10 1,172,992 –a—— C:\WINDOWS\system32\comsvcs.dll 2006-09-06 21:10 1,004,032 –a—— C:\WINDOWS\explorer.exe 2006-08-30 17:35 17,408 –a—— C:\WINDOWS\system32\qmgrprxy.dll 2006-08-27 23:11 922,021 —hs—- C:\WINDOWS\system32\wybeg.ini2 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-09-10 12:41 ——– d——– C:\Program Files\Common Files 2006-09-10 12:31 ——– d——– C:\Program Files\Mozilla Firefox 2006-09-10 00:33 1077481 –ahs—- C:\WINDOWS\system32\wybeg.bak2 2006-09-09 07:35 ——– d——– C:\Program Files\ewido anti-spyware 4.0 2006-09-09 05:41 1077532 –ahs—- C:\WINDOWS\system32\wybeg.bak1 2006-09-06 21:52 ——– d——– C:\Program Files\Common Files\Symantec Shared 2006-09-06 21:29 ——– d——– C:\Program Files\Windows Media Player 2006-09-06 21:29 ——– d——– C:\Program Files\Outlook Express 2006-09-06 21:29 ——– d——– C:\Program Files\NetMeeting 2006-09-06 21:29 ——– d——– C:\Program Files\Movie Maker 2006-09-06 21:29 ——– d——– C:\Program Files\messenger 2006-09-06 21:29 ——– d——– C:\Program Files\Internet Explorer 2006-09-06 21:29 ——– d——– C:\Program Files\Common Files\System 2006-08-30 17:30 ——– d–h—– C:\Program Files\WindowsUpdate 2006-08-28 17:47 ——– d——– C:\Program Files\Software by Design 2006-08-10 21:19 31744 –a—— C:\WINDOWS\system32\rundll32.exe 2006-08-10 21:16 299520 –a—— C:\WINDOWS\uninst.exe 2006-08-10 21:16 25600 –a—— C:\WINDOWS\twunk_32.exe 2006-08-10 21:15 98304 –a—— C:\WINDOWS\system32\verifier.exe 2006-08-10 21:15 9728 –a—— C:\WINDOWS\system32\sfc.exe 2006-08-10 21:15 9216 –a—— C:\WINDOWS\system32\subst.exe 2006-08-10 21:15 8192 –a—— C:\WINDOWS\system32\smbinst.exe 2006-08-10 21:15 77824 –a—— C:\WINDOWS\system32\usrmlnka.exe 2006-08-10 21:15 72192 –a—— C:\WINDOWS\system32\tasklist.exe 2006-08-10 21:15 72192 –a—— C:\WINDOWS\system32\taskkill.exe 2006-08-10 21:15 69632 –a—— C:\WINDOWS\system32\usrshuta.exe 2006-08-10 21:15 69632 –a—— C:\WINDOWS\system32\shrpubw.exe 2006-08-10 21:15 68096 –a—— C:\WINDOWS\system32\systeminfo.exe 2006-08-10 21:15 61440 –a—— C:\WINDOWS\system32\usrprbda.exe 2006-08-10 21:15 56832 –a—— C:\WINDOWS\system32\sol.exe 2006-08-10 21:15 5632 –a—— C:\WINDOWS\system32\write.exe 2006-08-10 21:15 51200 –a—— C:\WINDOWS\system32\syncapp.exe 2006-08-10 21:15 49664 –a—— C:\WINDOWS\system32\w32tm.exe 2006-08-10 21:15 43008 –a—— C:\WINDOWS\system32\ssmypics.scr 2006-08-10 21:15 414720 –a—— C:\WINDOWS\system32\wiaacmgr.exe 2006-08-10 21:15 4096 –a—— C:\WINDOWS\system32\winver.exe 2006-08-10 21:15 4096 –a—— C:\WINDOWS\system32\unlodctr.exe 2006-08-10 21:15 36864 –a—— C:\WINDOWS\system32\syskey.exe 2006-08-10 21:15 36352 –a—— C:\WINDOWS\system32\typeperf.exe 2006-08-10 21:15 33792 –a—— C:\WINDOWS\system32\vssadmin.exe 2006-08-10 21:15 32256 –a—— C:\WINDOWS\system32\wupdmgr.exe 2006-08-10 21:15 31744 –a—— C:\WINDOWS\system32\tracert6.exe 2006-08-10 21:15 31232 –a—— C:\WINDOWS\system32\wpabaln.exe 2006-08-10 21:15 3072 –a—— C:\WINDOWS\system32\systray.exe 2006-08-10 21:15 28160 –a—— C:\WINDOWS\system32\xcopy.exe 2006-08-10 21:15 275456 –a—— C:\WINDOWS\system32\vssvc.exe 2006-08-10 21:15 23552 –a—— C:\WINDOWS\system32\sort.exe 2006-08-10 21:15 20480 –a—— C:\WINDOWS\system32\stimon.exe 2006-08-10 21:15 19456 –a—— C:\WINDOWS\system32\tcpsvcs.exe 2006-08-10 21:15 17920 –a—— C:\WINDOWS\system32\shutdown.exe 2006-08-10 21:15 16896 –a—— C:\WINDOWS\system32\tsshutdn.exe 2006-08-10 21:15 16896 –a—— C:\WINDOWS\system32\tftp.exe 2006-08-10 21:15 16896 –a—— C:\WINDOWS\system32\secedit.exe 2006-08-10 21:15 16384 –a—— C:\WINDOWS\system32\tskill.exe 2006-08-10 21:15 15360 –a—— C:\WINDOWS\taskman.exe 2006-08-10 21:15 15360 –a—— C:\WINDOWS\system32\taskman.exe 2006-08-10 21:15 14848 –a—— C:\WINDOWS\system32\tsdiscon.exe 2006-08-10 21:15 14848 –a—— C:\WINDOWS\system32\tscon.exe 2006-08-10 21:15 14848 –a—— C:\WINDOWS\system32\shadow.exe 2006-08-10 21:15 138752 –a—— C:\WINDOWS\system32\sndvol32.exe 2006-08-10 21:15 13824 –a—— C:\WINDOWS\system32\wscntfy.exe 2006-08-10 21:15 124416 –a—— C:\WINDOWS\system32\sndrec32.exe 2006-08-10 21:15 12288 –a—— C:\WINDOWS\system32\tcmsetup.exe 2006-08-10 21:15 119808 –a—— C:\WINDOWS\system32\winmine.exe 2006-08-10 21:15 11776 –a—— C:\WINDOWS\system32\winmsd.exe 2006-08-10 21:15 11776 –a—— C:\WINDOWS\system32\spnpinst.exe 2006-08-10 21:15 103936 –a—— C:\WINDOWS\system32\sysocmgr.exe 2006-08-10 21:14 97792 –a—— C:\WINDOWS\system32\mqtgsvc.exe 2006-08-10 21:14 9728 –a—— C:\WINDOWS\system32\reset.exe 2006-08-10 21:14 9728 –a—— C:\WINDOWS\system32\label.exe 2006-08-10 21:14 93184 –a—— C:\WINDOWS\system32\scardsvr.exe 2006-08-10 21:14 9216 –a—— C:\WINDOWS\system32\print.exe 2006-08-10 21:14 82944 –a—— C:\WINDOWS\system32\netsh.exe 2006-08-10 21:14 8192 –a—— C:\WINDOWS\system32\mountvol.exe 2006-08-10 21:14 8192 –a—— C:\WINDOWS\system32\lpr.exe 2006-08-10 21:14 79360 –a—— C:\WINDOWS\system32\makecab.exe 2006-08-10 21:14 71680 –a—— C:\WINDOWS\system32\nslookup.exe 2006-08-10 21:14 7168 –a—— C:\WINDOWS\system32\recover.exe 2006-08-10 21:14 68096 –a—— C:\WINDOWS\system32\locator.exe 2006-08-10 21:14 67584 –a—— C:\WINDOWS\system32\magnify.exe 2006-08-10 21:14 6656 –a—— C:\WINDOWS\system32\msswchx.exe 2006-08-10 21:14 62976 –a—— C:\WINDOWS\system32\rsopprov.exe 2006-08-10 21:14 61440 –a—— C:\WINDOWS\system32\openfiles.exe 2006-08-10 21:14 6144 –a—— C:\WINDOWS\system32\msdtc.exe 2006-08-10 21:14 6144 –a—— C:\WINDOWS\system32\lpq.exe 2006-08-10 21:14 55296 –a—— C:\WINDOWS\system32\logman.exe 2006-08-10 21:14 51712 –a—— C:\WINDOWS\system32\migpwd.exe 2006-08-10 21:14 51200 –a—— C:\WINDOWS\system32\narrator.exe 2006-08-10 21:14 5120 –a—— C:\WINDOWS\system32\lodctr.exe 2006-08-10 21:14 49152 –a—— C:\WINDOWS\system32\rsm.exe 2006-08-10 21:14 49152 –a—— C:\WINDOWS\system32\powercfg.exe 2006-08-10 21:14 4608 –a—— C:\WINDOWS\system32\regwiz.exe 2006-08-10 21:14 4608 –a—— C:\WINDOWS\system32\mqsvc.exe 2006-08-10 21:14 45056 –a—— C:\WINDOWS\system32\proquota.exe 2006-08-10 21:14 44032 –a—— C:\WINDOWS\system32\ipsec6.exe 2006-08-10 21:14 4096 –a—— C:\WINDOWS\system32\nddeapir.exe 2006-08-10 21:14 40448 –a—— C:\WINDOWS\system32\osuninst.exe 2006-08-10 21:14 39936 –a—— C:\WINDOWS\system32\MAPISRVR.EXE 2006-08-10 21:14 3584 –a—— C:\WINDOWS\system32\regedt32.exe 2006-08-10 21:14 34816 –a—— C:\WINDOWS\system32\msiregmv.exe 2006-08-10 21:14 33792 –a—— C:\WINDOWS\system32\regini.exe 2006-08-10 21:14 33280 –a—— C:\WINDOWS\system32\ping6.exe 2006-08-10 21:14 32768 –a—— C:\WINDOWS\system32\relog.exe 2006-08-10 21:14 32768 –a—— C:\WINDOWS\system32\mnmsrvc.exe 2006-08-10 21:14 31744 –a—— C:\WINDOWS\system32\ntsd.exe 2006-08-10 21:14 31232 –a—— C:\WINDOWS\system32\sc.exe 2006-08-10 21:14 30720 –a—— C:\WINDOWS\system32\netstat.exe 2006-08-10 21:14 29696 –a—— C:\WINDOWS\system32\lights.exe 2006-08-10 21:14 25600 –a—— C:\WINDOWS\system32\routemon.exe 2006-08-10 21:14 25088 –a—— C:\WINDOWS\system32\lnkstub.exe 2006-08-10 21:14 24576 –a—— C:\WINDOWS\system32\rsmsink.exe 2006-08-10 21:14 23040 –a—— C:\WINDOWS\system32\proxycfg.exe 2006-08-10 21:14 22016 –a—— C:\WINDOWS\system32\qwinsta.exe 2006-08-10 21:14 22016 –a—— C:\WINDOWS\system32\ipxroute.exe 2006-08-10 21:14 21504 –a—— C:\WINDOWS\system32\pathping.exe 2006-08-10 21:14 20992 –a—— C:\WINDOWS\system32\msg.exe 2006-08-10 21:14 205824 –a—— C:\WINDOWS\system32\progman.exe 2006-08-10 21:14 20480 –a—— C:\WINDOWS\system32\nbtstat.exe 2006-08-10 21:14 19968 –a—— C:\WINDOWS\system32\route.exe 2006-08-10 21:14 19968 –a—— C:\WINDOWS\system32\rcp.exe 2006-08-10 21:14 18432 –a—— C:\WINDOWS\system32\qprocess.exe 2006-08-10 21:14 17408 –a—— C:\WINDOWS\system32\mqbkup.exe 2006-08-10 21:14 16896 –a—— C:\WINDOWS\system32\qappsrv.exe 2006-08-10 21:14 16384 –a—— C:\WINDOWS\system32\runas.exe 2006-08-10 21:14 15872 –a—— C:\WINDOWS\system32\rwinsta.exe 2006-08-10 21:14 15360 –a—— C:\WINDOWS\system32\pentnt.exe 2006-08-10 21:14 15360 –a—— C:\WINDOWS\system32\logoff.exe 2006-08-10 21:14 135680 –a—— C:\WINDOWS\system32\mobsync.exe 2006-08-10 21:14 13312 –a—— C:\WINDOWS\system32\rsh.exe 2006-08-10 21:14 132608 –a—— C:\WINDOWS\system32\rsvp.exe 2006-08-10 21:14 12800 –a—— C:\WINDOWS\system32\replace.exe 2006-08-10 21:14 12800 –a—— C:\WINDOWS\system32\mrinfo.exe 2006-08-10 21:14 126464 –a—— C:\WINDOWS\system32\nwscript.exe 2006-08-10 21:14 11776 –a—— C:\WINDOWS\system32\rexec.exe 2006-08-10 21:14 11776 –a—— C:\WINDOWS\system32\rasautou.exe 2006-08-10 21:14 11264 –a—— C:\WINDOWS\system32\rasdial.exe 2006-08-10 21:13 99840 –a—— C:\WINDOWS\system32\iexpress.exe 2006-08-10 21:13 9216 –a—— C:\WINDOWS\system32\finger.exe 2006-08-10 21:13 9216 –a—— C:\WINDOWS\system32\find.exe 2006-08-10 21:13 8704 –a—— C:\WINDOWS\system32\eventvwr.exe 2006-08-10 21:13 77824 –a—— C:\WINDOWS\system32\eventtriggers.exe 2006-08-10 21:13 7680 –a—— C:\WINDOWS\system32\hostname.exe 2006-08-10 21:13 7168 –a—— C:\WINDOWS\system32\forcedos.exe 2006-08-10 21:13 58368 –a—— C:\WINDOWS\system32\driverquery.exe 2006-08-10 21:13 57344 –a—— C:\WINDOWS\system32\gpupdate.exe 2006-08-10 21:13 56320 –a—— C:\WINDOWS\system32\fsutil.exe 2006-08-10 21:13 55296 –a—— C:\WINDOWS\system32\getmac.exe 2006-08-10 21:13 55296 –a—— C:\WINDOWS\system32\freecell.exe 2006-08-10 21:13 55296 –a—— C:\WINDOWS\system32\dvdplay.exe 2006-08-10 21:13 47616 –a—— C:\WINDOWS\system32\eventcreate.exe 2006-08-10 21:13 4608 –a—— C:\WINDOWS\system32\dllhst3g.exe 2006-08-10 21:13 40960 –a—— C:\WINDOWS\system32\extrac32.exe 2006-08-10 21:13 39424 –a—— C:\WINDOWS\system32\esentutl.exe 2006-08-10 21:13 37888 –a—— C:\WINDOWS\system32\grpconv.exe 2006-08-10 21:13 3072 –a—— C:\WINDOWS\system32\fixmapi.exe 2006-08-10 21:13 26112 –a—— C:\WINDOWS\system32\dplaysvr.exe 2006-08-10 21:13 25088 –a—— C:\WINDOWS\system32\findstr.exe 2006-08-10 21:13 22528 –a—— C:\WINDOWS\system32\fltMc.exe 2006-08-10 21:13 204800 –a—— C:\WINDOWS\system32\dmadmin.exe 2006-08-10 21:13 193024 –a—— C:\WINDOWS\system32\fsquirt.exe 2006-08-10 21:13 18944 –a—— C:\WINDOWS\system32\dpnsvr.exe 2006-08-10 21:13 15872 –a—— C:\WINDOWS\system32\expand.exe 2006-08-10 21:13 15872 –a—— C:\WINDOWS\system32\dvdupgrd.exe 2006-08-10 21:13 14848 –a—— C:\WINDOWS\system32\help.exe 2006-08-10 21:13 14848 –a—— C:\WINDOWS\system32\fc.exe 2006-08-10 21:13 14336 –a—— C:\WINDOWS\system32\dmremote.exe 2006-08-10 21:13 10752 –a—— C:\WINDOWS\system32\doskey.exe 2006-08-10 21:10 8192 –a—— C:\WINDOWS\system32\control.exe 2006-08-10 21:10 8192 –a—— C:\WINDOWS\system32\cidaemon.exe 2006-08-10 21:10 80384 –a—— C:\WINDOWS\system32\charmap.exe 2006-08-10 21:10 79360 –a—— C:\WINDOWS\system32\diantz.exe 2006-08-10 21:10 7680 –a—— C:\WINDOWS\system32\ckcnv.exe 2006-08-10 21:10 71680 –a—— C:\WINDOWS\system32\blastcln.exe 2006-08-10 21:10 71680 –a—— C:\WINDOWS\ST5UNST.EXE 2006-08-10 21:10 69632 –a—— C:\WINDOWS\system32\BCMWLD2K.EXE 2006-08-10 21:10 61440 –a—— C:\WINDOWS\system32\cleanmgr.exe 2006-08-10 21:10 54784 –a—— C:\WINDOWS\system32\cmstp.exe 2006-08-10 21:10 5120 –a—— C:\WINDOWS\system32\dcomcnfg.exe 2006-08-10 21:10 5120 –a—— C:\WINDOWS\system32\cisvc.exe 2006-08-10 21:10 5120 –a—— C:\WINDOWS\system32\bootvrfy.exe 2006-08-10 21:10 4608 –a—— C:\WINDOWS\system32\bootok.exe 2006-08-10 21:10 45056 –a—— C:\WINDOWS\system32\cliconfg.exe 2006-08-10 21:10 45056 –a—— C:\WINDOWS\system32\cipher.exe 2006-08-10 21:10 4096 –a—— C:\WINDOWS\system32\actmovie.exe 2006-08-10 21:10 35840 –a—— C:\WINDOWS\system32\cmmon32.exe 2006-08-10 21:10 32768 –a—— C:\WINDOWS\system32\asr_pfu.exe 2006-08-10 21:10 32256 –a—— C:\WINDOWS\system32\asr_ldm.exe 2006-08-10 21:10 30720 –a—— C:\WINDOWS\system32\clipsrv.exe 2006-08-10 21:10 27136 –a—— C:\WINDOWS\system32\ddeshare.exe 2006-08-10 21:10 27136 –a—— C:\WINDOWS\system32\asr_fmt.exe 2006-08-10 21:10 19456 –a—— C:\WINDOWS\system32\arp.exe 2006-08-10 21:10 192512 –a—— C:\WINDOWS\system32\AegisI5.exe 2006-08-10 21:10 184348 –a—— C:\WINDOWS\system32\BCMWLU00.EXE 2006-08-10 21:10 18432 –a—— C:\WINDOWS\system32\cacls.exe 2006-08-10 21:10 17920 –a—— C:\WINDOWS\system32\diskperf.exe 2006-08-10 21:10 17408 –a—— C:\WINDOWS\system32\compact.exe 2006-08-10 21:10 15872 –a—— C:\WINDOWS\system32\comp.exe 2006-08-10 21:10 145920 –a—— C:\WINDOWS\system32\diskpart.exe 2006-08-10 21:10 14336 –a—— C:\WINDOWS\system32\auditusr.exe 2006-08-10 21:10 13824 –a—— C:\WINDOWS\system32\convert.exe 2006-08-10 21:10 136704 –a—— C:\WINDOWS\system32\bootcfg.exe 2006-08-10 21:10 11776 –a—— C:\WINDOWS\system32\chkdsk.exe 2006-08-10 21:10 114688 –a—— C:\WINDOWS\system32\calc.exe 2006-08-10 21:10 11264 –a—— C:\WINDOWS\system32\attrib.exe 2006-08-10 21:10 102400 –a—— C:\WINDOWS\system32\cscript.exe 2006-08-10 21:10 10240 –a—— C:\WINDOWS\system32\atmadm.exe 2006-08-10 21:09 773632 –a—— C:\WINDOWS\MTUn990.exe 2006-08-10 21:09 306688 –a—— C:\WINDOWS\IsUninst.exe 2006-08-10 21:07 41984 –a—— C:\WINDOWS\Ctregrun.exe 2006-08-10 21:07 237568 –a—— C:\WINDOWS\CMIUninstall.exe 2006-08-10 21:07 212992 –a—— C:\WINDOWS\CmiRmRedundDir.exe 2006-08-10 19:48 ——– d——– C:\Program Files\LimeWire 2006-08-10 08:53 49152 –a—— C:\WINDOWS\system32\rsmui.exe 2006-08-10 08:52 61952 –a—— C:\WINDOWS\system32\rdshost.exe 2006-08-10 08:52 14848 –a—— C:\WINDOWS\system32\upnpcont.exe 2006-08-10 08:49 9728 –a—— C:\WINDOWS\system32\regsvr32.exe 2006-08-10 08:49 45568 –a—— C:\WINDOWS\system32\drwtsn32.exe 2006-08-10 08:49 375808 –a—— C:\WINDOWS\system32\cmd.exe 2006-08-10 08:49 346624 –a—— C:\WINDOWS\system32\tourstart.exe 2006-08-10 08:49 126976 –a—— C:\WINDOWS\system32\mshearts.exe 2006-08-10 08:48 22016 –a—— C:\WINDOWS\system32\mpnotify.exe 2006-08-09 21:52 12800 –a—— C:\WINDOWS\system32\spiisupd.exe 2006-08-09 19:24 8192 –a—— C:\WINDOWS\system32\winhlp32.exe 2006-08-09 19:24 774144 –a—— C:\WINDOWS\system32\mmc.exe 2006-08-09 19:24 66048 –a—— C:\WINDOWS\system32\notepad.exe 2006-08-09 19:24 66048 –a—— C:\WINDOWS\notepad.exe 2006-08-09 19:24 54272 –a—— C:\WINDOWS\system32\rasphone.exe 2006-08-09 19:24 29184 –a—— C:\WINDOWS\system32\wpnpinst.exe 2006-08-09 19:24 24064 –a—— C:\WINDOWS\system32\mshta.exe 2006-08-09 19:24 14336 –a—— C:\WINDOWS\system32\perfmon.exe 2006-08-09 19:24 118784 –a—— C:\WINDOWS\system32\wscript.exe 2006-08-09 19:24 1135616 –a—— C:\WINDOWS\system32\ntbackup.exe 2006-08-09 19:23 667680 –a—— C:\WINDOWS\system32\WLTRAY.EXE 2006-08-09 19:23 394240 –a—— C:\WINDOWS\system32\PSDrvCheck.exe 2006-08-09 19:23 179200 –a—— C:\WINDOWS\system32\accwiz.exe 2006-08-09 19:23 155648 –a—— C:\WINDOWS\system32\NeroCheck.exe 2006-08-09 19:19 11264 –a—— C:\WINDOWS\system32\chkntfs.exe 2006-08-08 23:46 ——– d——– C:\Program Files\Lavasoft 2006-08-08 23:46 ——– d——– C:\Documents and Settings\Albert\Application Data\Lavasoft 2006-08-02 02:22 573492 –ahs—- C:\WINDOWS\system32\gebyw.dll 2006-08-01 07:26 2 –a—— C:\WINDOWS\system32\wnsintcc.exe 2006-07-22 05:15 ——– d——– C:\Documents and Settings\Albert\Application Data\Sun 2006-07-22 01:12 ——– d——– C:\Program Files\Norton AntiVirus 2006-07-22 00:21 ——– d——– C:\Program Files\Symantec 2006-07-22 00:19 ——– d——– C:\Program Files\Mexican Motor Mafia 2006-07-21 00:07 ——– d——– C:\Program Files\Visual Music 2006-07-21 00:06 ——– d——– C:\Program Files\NCH Swift Sound 2006-07-21 00:05 ——– d——– C:\Program Files\AV Music Morpher Gold 2006-07-21 00:04 ——– d——– C:\Program Files\AddSynth 2006-07-18 22:16 ——– d——– C:\Program Files\Java 2006-07-18 08:08 ——– d——– C:\Documents and Settings\Albert\Application Data\Mozilla 2006-07-18 08:01 ——– d—s—- C:\Documents and Settings\Albert\Application Data\Microsoft 2006-07-18 07:51 ——– d——– C:\Program Files\Common Files\Java 2006-07-17 22:01 ——– d——– C:\Documents and Settings\Albert\Application Data\Macromedia (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Motorola Wireless Manager UI"="C:\\WINDOWS\\system32\\WLTRAY" "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\"" "Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer" "VOBID"="C:\\Program Files\\Pinnacle\\InstantCDDVD\\InstantDrive\\InstantDrive.exe /remount" "IW ControlCenter"="C:\\Program Files\\Pinnacle\\InstantCDDVD\\InstantWrite\\iwctrl.exe" "PinnacleDriverCheck"="C:\\WINDOWS\\system32\\PSDrvCheck.exe" "Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd" "KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\ 65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00 "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe" "!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "NoChange"="1" "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\"" "AWMON"="\"C:\\Program Files\\Lavasoft\\Ad-Aware SE Plus\\Ad-Watch.exe\"" "BitTorrent"="\"C:\\Program Files\\BitTorrent\\bittorrent.exe\" –force_start_minimized" "SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 "NoLowDiskSpaceChecks"=dword:00000001 "NoInstrumentation"=dword:00000001 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{5A3E97DD-2A08-48BC-8F43-C0DEABC90266}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebyw HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winlft32 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyxwuv Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Albert.job Completion time: Sun 09/10/2006 12:46:46.78 ComboFix.txt Logfile of HijackThis v1.99.1 Scan saved at 12:48:28 PM, on 9/10/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\
Here is my log I don't think it pasted properly from the last post. Logfile of HijackThis v1.99.1 Scan saved at 12:48:28 PM, on 9/10/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\cscript.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe C:\WINDOWS\System32\RunDll32.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Albert\Desktop\hj\Spyware.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {1A96BF57-CC29-4055-A962-E2B1EBCA0EE1} - (no file) O2 - BHO: (no name) - {1D10D845-EB53-4283-A691-A72D12118BE7} - (no file) O2 - BHO: (no name) - {435328EB-8EF8-49C5-A047-3BB4048099F1} - (no file) O2 - BHO: (no name) - {4E70A7A0-22A2-4843-B53B-5022E1F061C0} - (no file) O2 - BHO: (no name) - {5A3E97DD-2A08-48BC-8F43-C0DEABC90266} - C:\WINDOWS\System32\xxyxwuv.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\System32\WinNB58.dll (file missing) O2 - BHO: (no name) - {A0015195-470D-4CA6-BF2F-9A61B61F7E06} - (no file) O2 - BHO: (no name) - {AAD16DAE-56D4-4DEE-9BEB-8869858C60DB} - (no file) O2 - BHO: (no name) - {BC9BAF99-2492-422D-8699-FB7406C34621} - (no file) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {CB03FE0D-1CD3-4683-9EC8-BC5A113178E3} - C:\WINDOWS\System32\gebyw.dll O2 - BHO: (no name) - {D704A92A-68A9-4DFF-B605-2A95B57E221B} - (no file) O4 - HKLM\..\Run: [Motorola Wireless Manager UI] C:\WINDOWS\system32\WLTRAY O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [VOBID] C:\Program Files\Pinnacle\InstantCDDVD\InstantDrive\InstantDrive.exe /remount O4 - HKLM\..\Run: [IW ControlCenter] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe" O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O20 - Winlogon Notify: gebyw - C:\WINDOWS\System32\gebyw.dll O20 - Winlogon Notify: winlft32 - winlft32.dll (file missing) O20 - Winlogon Notify: xxyxwuv - xxyxwuv.dll (file missing) O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
If you don't disable Ad-Watch and Teatimer, this isn't going to work.


Next, launch Notepad (Start>All Programs>Accessories), and copy/paste all the BOLD REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[-HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\gebyw]

[-HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\winlft32]

[-HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\xxyxwuv]


On the desktop, doubleclick fix.reg and allow it to run. Let it merge.





Copy the text in the following quote box into Notepad:

attrib -r -s -h C:\WINDOWS\system32\wybeg.bak2
attrib -r -s -h C:\WINDOWS\system32\wybeg.bak1
attrib -r -s -h C:\WINDOWS\system32\gebyw.dll
del C:\WINDOWS\system32\wybeg.bak2
del C:\WINDOWS\system32\wybeg.bak1
del C:\WINDOWS\system32\gebyw.dll


Save it to your desktop as ff.bat

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: (no name) - {1A96BF57-CC29-4055-A962-E2B1EBCA0EE1} - (no file)
O2 - BHO: (no name) - {1D10D845-EB53-4283-A691-A72D12118BE7} - (no file)
O2 - BHO: (no name) - {435328EB-8EF8-49C5-A047-3BB4048099F1} - (no file)
O2 - BHO: (no name) - {4E70A7A0-22A2-4843-B53B-5022E1F061C0} - (no file)
O2 - BHO: (no name) - {5A3E97DD-2A08-48BC-8F43-C0DEABC90266} - C:\WINDOWS\System32\xxyxwuv.dll (file missing)
O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\System32\WinNB58.dll (file missing)
O2 - BHO: (no name) - {A0015195-470D-4CA6-BF2F-9A61B61F7E06} - (no file)
O2 - BHO: (no name) - {AAD16DAE-56D4-4DEE-9BEB-8869858C60DB} - (no file)
O2 - BHO: (no name) - {BC9BAF99-2492-422D-8699-FB7406C34621} - (no file)
O2 - BHO: (no name) - {CB03FE0D-1CD3-4683-9EC8-BC5A113178E3} - C:\WINDOWS\System32\gebyw.dll
O2 - BHO: (no name) - {D704A92A-68A9-4DFF-B605-2A95B57E221B} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O20 - Winlogon Notify: gebyw - C:\WINDOWS\System32\gebyw.dll
O20 - Winlogon Notify: winlft32 - winlft32.dll (file missing)
O20 - Winlogon Notify: xxyxwuv - xxyxwuv.dll (file missing)


Close ALL windows and browsers except HijackThis and click "Fix checked"

Now click on Config –> Misc Tools –> Open Process Manager

In the list of processes, find explorer.exe

Click to highlight, then click "Kill Process". OK any prompts.

Your desktop will disappear, but that is normal. It will come back when you reboot.

Now, in HijackThis!, click:

Run –> browse

Browse to your desktop and click ff.bat –> open –> OK



Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI