This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Smitfraud.C and Co.

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've "cleaned" my system several times now and ran the Smitfraud fix but it doesn't seem to go away, it's like it recreates itself.

Just after running Spybot I decided to post my HJT log because I know for a fact that it will come back. After Spybot had finished, as usual it said Command Service could not be removed. I've also tried removing this from the registry in safe mode but had no luck. It's Smitfraud toolbar and Command service never seem to go (I've had cmdService for along time and been unable to get rid of it). I think I also have Virtumundo and tried to use the remover for that but it gave an error and crashed.

I'm using Spybot, Adware, Ewido, Win Defender and AVG Free.
Adware usually finds a couple of things but they come back.
This is the same for Ewido.
Win Defender doesn't usually find anything.
AVG has found a couple of viruses and tells me about system files (hosts, kernel32, etc) being changed.

I recently (yesterday) updated IE from 6 to 7 and Java from 1.5.0_06 to 1.5.0_09.

Logfile of HijackThis v1.99.1
Scan saved at 05:26:28, on 09/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Actual Window Manager\ActualWindowManagerCenter.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ShortKeys2\shortkey.exe
C:\Program Files\SnagIt 7\SnagIt32.exe
C:\Program Files\WordWeb\wweb32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\chris\Desktop\misc\jackthishi.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {19E3BEF4-B23B-41CD-B58D-DBA19EE56B38} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {F18F04B0-9CF1-4b93-B004-77A288BEE28B} - (no file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [Actual Window Manager] "C:\Program Files\Actual Window Manager\ActualWindowManagerCenter.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: ShortKeys 2.lnk = C:\Program Files\ShortKeys2\shortkey.exe
O4 - Global Startup: SnagIt 7.lnk = C:\Program Files\SnagIt 7\SnagIt32.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\OFFICE~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149290353810
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149290344607
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames/Check…PA.cab40641.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DEF86AC6-B08A-4ED8-894A-96924ECD8399}: NameServer = 212.139.132.53 212.139.132.52
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: RunOnce - C:\WINDOWS\system32\mv2ol9f31.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winhdn32 - winhdn32.dll (file missing)
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe


Thanks in advance.




Chris
Hello and Welcome to TomCoyote,

Let's run some scans and let me see the results please.
STEP 1.
======
Combofix
  • Download this file - combofix.exe
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Now run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner

Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
Copy and paste that information from Kapersky in your next post.

Download Gmer from here:
http://www.gmer.net/gmer.zip
  • Disconnect from internet and close running programs.
  • There is a small chance this app may crash your computer so save any work you have open.
  • Double click gmer.exe
  • Let the gmer.sys driver load if asked.
  • If it gives you a warning at program start about rootkit activity and asks if you want to run scan…say Ok.
  • If no warning….
  • Click "rootkit" tab and click "scan"
  • Once done click "copy"
  • Open Notepad and hit "ctrl+v" to paste log.
  • Reconnect to internet and post log please.
Please post (reply) with the logs from ComboFix, Kapersky, Gmer, and a new hijackthis log.
I haven't been getting that Windows Defender coming up saying I need to scan all the time which is good. It doesn't feel like I'm as infected as I was now.

ComboFix
chris - 06-11-10 18:34:44.21 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\chris\Desktop"

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

REGISTRY ENTRIES REMOVED:

[HKEY_CLASSES_ROOT\clsid\{4046F057-3FB6-4D81-AC81-83E0061BDC62}]
@=""
"IDEx"="ADDR"

[HKEY_CLASSES_ROOT\clsid\{4046F057-3FB6-4D81-AC81-83E0061BDC62}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{4046F057-3FB6-4D81-AC81-83E0061BDC62}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


Granting sedebugprivilege to Administrators … successful


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\components

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\Program Files\Common Files\SKS~1
C:\QooBox\Purity\Program Files\Common Files\SKS~1\ç?sks


((((((((((((((((((((((((((((((( Files Created from 2006-10-10 to 2006-11-10 ))))))))))))))))))))))))))))))))))


2006-11-10 15:15 8,413 –a—— C:\WINDOWS\system32\drivers\mcstrm.sys
2006-11-08 19:27 0 –a—— C:\WINDOWS\system32\ssqrr.dll.vir
2006-11-08 19:27 0 –a—— C:\WINDOWS\system32\fccaxxw.dll.vir
2006-11-08 17:39 1,940 –a—— C:\WINDOWS\system32\tmp.reg
2006-11-08 17:22 121,856 –a—— C:\WINDOWS\system32\xmllite.dll
2006-11-07 18:02 581,429 –ahs—- C:\WINDOWS\system32\rrqss.ini2
2006-11-07 17:15 110,612 –a—— C:\WINDOWS\system32\mbjdcioj.exe
2006-11-05 20:15 567,972 –ahs—- C:\WINDOWS\system32\rrqss.bak2
2006-11-05 19:53 94,208 –a—— C:\WINDOWS\system32\xhwjde.dll
2006-11-05 19:52 59,392 –a—— C:\WINDOWS\system32\drvzel.dll
2006-11-05 19:52 40,973 –ahs—- C:\WINDOWS\system32\fccaxxw.dll
2006-11-04 20:15 110,612 –a—— C:\WINDOWS\system32\xkhpxdts.exe
2006-11-04 20:14 598,143 –ahs—- C:\WINDOWS\system32\rrqss.bak1
2006-11-04 20:13 692,276 –ahs—- C:\WINDOWS\system32\ssqrr.dll
2006-11-04 19:03 94,208 –a—— C:\WINDOWS\system32\ozrlfcc.dll
2006-11-04 19:03 40,973 –ahs—- C:\WINDOWS\system32\awttqro.dll
2006-11-04 18:27 816,288 –a—— C:\WINDOWS\system32\drivers\avg7core.sys
2006-11-04 18:27 4,224 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-11-04 18:27 3,968 –a—— C:\WINDOWS\system32\drivers\avgclean.sys
2006-11-04 18:27 28,416 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-10-31 22:00 53,248 –a—— C:\WINDOWS\system32\Process.exe
2006-10-31 22:00 40,960 –a—— C:\WINDOWS\system32\swsc.exe
2006-10-31 22:00 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2006-10-31 22:00 135,168 –a—— C:\WINDOWS\system32\swreg.exe
2006-10-27 15:09 6,049,280 –a—— C:\WINDOWS\system32\ieframe.dll
2006-10-27 15:09 50,688 –a—— C:\WINDOWS\system32\msfeedsbs.dll
2006-10-27 15:09 458,752 –a—— C:\WINDOWS\system32\msfeeds.dll
2006-10-27 15:09 180,736 –a—— C:\WINDOWS\system32\ieui.dll
2006-10-27 02:44 13,312 –a—— C:\WINDOWS\system32\ieudinit.exe
2006-10-25 16:22 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2006-10-20 18:05 44,875 –a—— C:\WINDOWS\system32\IPrtCnst.dll
2006-10-20 18:05 13,891 –a—— C:\WINDOWS\system32\drivers\IdeBusDr.sys
2006-10-20 18:05 101,431 –a—— C:\WINDOWS\system32\drivers\IdeChnDr.sys
2006-10-20 17:40 451,072 C:\WINDOWSRadeon Omega Drivers v3.8.291 Uninstall.exe
2006-10-18 02:47 89,360 –a—— C:\WINDOWS\system32\VB5DB.DLL
2006-10-17 13:05 206,336 –a—— C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 12:58 61,952 –a—— C:\WINDOWS\system32\icardie.dll
2006-10-17 12:58 12,288 –a—— C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 12:57 266,752 –a—— C:\WINDOWS\system32\iertutil.dll
2006-10-17 12:27 380,928 –a—— C:\WINDOWS\system32\ieapfltr.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-10 18:35 ——– d——– C:\Program Files\Common Files
2006-11-10 18:26 ——– d——– C:\Program Files\iTunes
2006-11-10 18:26 ——– d——– C:\Program Files\iPod
2006-11-10 18:25 ——– d——– C:\Program Files\QuickTime
2006-11-10 18:22 ——– d——– C:\Program Files\Mozilla Firefox
2006-11-10 18:21 ——– d——– C:\Program Files\ShortKeys2
2006-11-09 17:14 ——– d——– C:\Program Files\Windows Defender
2006-11-08 21:44 ——– d——– C:\Program Files\Internet Explorer
2006-11-08 18:46 ——– d——– C:\Program Files\Java
2006-11-08 18:32 ——– d——– C:\Program Files\VSAdd-in
2006-11-08 16:18 ——– d——– C:\Documents and Settings\chris\Application Data\AVG7
2006-11-08 16:15 ——– d——– C:\Program Files\ewido anti-spyware 4.0
2006-11-07 18:39 ——– d——– C:\Program Files\SpywareBlaster
2006-11-07 18:30 ——– d—s—- C:\Documents and Settings\chris\Application Data\Microsoft
2006-11-06 22:49 ——– d——– C:\Program Files\SnagIt 7
2006-11-04 18:27 ——– d——– C:\Program Files\Grisoft
2006-10-31 23:23 ——– d——– C:\Program Files\Flash Decompiler
2006-10-31 23:23 ——– d——– C:\Documents and Settings\chris\Application Data\Eltima Software
2006-10-31 21:21 ——– d——– C:\Program Files\Diskeeper Corporation
2006-10-30 21:23 ——– d——– C:\Program Files\MSN Messenger
2006-10-28 21:11 ——– d——– C:\Program Files\Radeon Omega Drivers
2006-10-27 15:09 413696 –a—— C:\WINDOWS\system32\vbscript.dll
2006-10-27 15:09 231424 –a—— C:\WINDOWS\system32\webcheck.dll
2006-10-27 15:09 156160 –a—— C:\WINDOWS\system32\msls31.dll
2006-10-27 02:44 71680 –a—— C:\WINDOWS\system32\admparse.dll
2006-10-27 02:44 55296 –a—— C:\WINDOWS\system32\iesetup.dll
2006-10-27 02:44 54784 –a—— C:\WINDOWS\system32\ie4uinit.exe
2006-10-27 02:44 43008 –a—— C:\WINDOWS\system32\iernonce.dll
2006-10-27 02:44 382976 –a—— C:\WINDOWS\system32\iedkcs32.dll
2006-10-27 02:44 229376 –a—— C:\WINDOWS\system32\ieaksie.dll
2006-10-27 02:44 152064 –a—— C:\WINDOWS\system32\ieakeng.dll
2006-10-27 02:44 123904 –a—— C:\WINDOWS\system32\advpack.dll
2006-10-27 02:42 161792 –a—— C:\WINDOWS\system32\ieakui.dll
2006-10-26 14:05 ——– d——– C:\Program Files\Microsoft Works
2006-10-25 17:34 ——– d——– C:\Program Files\Microsoft Office
2006-10-25 17:34 ——– d——– C:\Program Files\Common Files\Microsoft Shared
2006-10-25 17:25 ——– d——– C:\Program Files\Microsoft IntelliPoint
2006-10-25 17:24 ——– d——– C:\Program Files\Microsoft IntelliPoint 5.0
2006-10-21 23:02 ——– d——– C:\Program Files\Microsoft ActiveSync
2006-10-21 23:01 ——– d——– C:\Program Files\Office 2003
2006-10-21 23:00 ——– d——– C:\Program Files\Microsoft.NET
2006-10-21 14:52 ——– d——– C:\Program Files\Apple Software Update
2006-10-20 22:04 ——– d——– C:\Program Files\AutoIt3
2006-10-20 18:05 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-10-20 18:05 ——– d——– C:\Program Files\Intel
2006-10-20 17:41 ——– d——– C:\Program Files\MultiRes
2006-10-20 17:40 451072 –a—— C:\WINDOWS\Radeon Omega Drivers v3.8.291 Uninstall.exe
2006-10-19 17:38 ——– d——– C:\Program Files\Siber Systems
2006-10-19 16:33 ——– d——– C:\Program Files\ProxyChecker
2006-10-19 16:33 ——– d——– C:\Program Files\Last.fm Player
2006-10-19 14:16 ——– d——– C:\Program Files\Microsoft IntelliPoint 4.12
2006-10-18 03:25 126 –a—— C:\Documents and Settings\chris\Application Data\iScrobbler.ini
2006-10-18 03:25 101252 –a—— C:\Documents and Settings\chris\Application Data\.iScrobbler
2006-10-17 13:06 78336 –a—— C:\WINDOWS\system32\ieencode.dll
2006-10-17 13:05 40960 –a—— C:\WINDOWS\system32\licmgr10.dll
2006-10-17 13:05 105984 –a—— C:\WINDOWS\system32\url.dll
2006-10-17 13:04 101376 –a—— C:\WINDOWS\system32\occache.dll
2006-10-17 13:03 17408 –a—— C:\WINDOWS\system32\corpol.dll
2006-10-17 12:57 36352 –a—— C:\WINDOWS\system32\imgutil.dll
2006-10-17 12:56 45568 –a—— C:\WINDOWS\system32\mshta.exe
2006-10-17 12:28 48128 –a—— C:\WINDOWS\system32\mshtmler.dll
2006-10-15 19:41 ——– d——– C:\Program Files\Windows Live Safety Center
2006-10-15 19:23 ——– d——– C:\Program Files\VideoraiPodConverter
2006-10-15 19:23 ——– d——– C:\Program Files\AviSynth 2.5
2006-10-08 20:56 724992 –a—— C:\MatrixSounds.dll
2006-10-07 16:12 ——– d——– C:\Program Files\Microsoft Bootvis
2006-10-07 14:04 ——– d——– C:\Program Files\Photoshop CS2
2006-10-07 13:13 ——– d——– C:\Program Files\Alwil Software
2006-10-07 00:44 ——– d——– C:\Documents and Settings\chris\Application Data\DivX
2006-10-06 13:46 ——– d——– C:\Program Files\ClipMagic
2006-10-06 13:45 ——– d——– C:\Documents and Settings\chris\Application Data\ClipMagic
2006-10-05 15:13 737280 –a—— C:\WINDOWS\iun6002.exe
2006-10-04 19:20 ——– d——– C:\Program Files\TuneSleeve
2006-10-03 20:58 ——– d——– C:\Program Files\DivX
2006-10-03 18:18 ——– d——– C:\Program Files\Messenger Plus! Live
2006-10-02 19:04 806912 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2006-10-02 19:04 806912 –a—— C:\WINDOWS\system32\divx_xx07.dll
2006-10-02 19:04 790528 –a—— C:\WINDOWS\system32\divx_xx11.dll
2006-10-02 19:04 635486 –a—— C:\WINDOWS\system32\DivX.dll
2006-09-27 17:11 ——– d——– C:\Program Files\Boots F2CD
2006-09-23 21:33 1723904 –a—— C:\WINDOWS\system32\drivers\ati2mtag.sys
2006-09-19 15:44 15664 –a—— C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2006-09-19 15:43 109360 –a—— C:\WINDOWS\system32\GEARAspi.dll
2006-09-14 17:17 ——– d——– C:\Program Files\mIRC
2006-09-13 17:34 ——– d——– C:\Program Files\HLSW
2006-09-13 15:08 ——– d——– C:\Program Files\ClamWin
2006-09-13 05:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll
2006-09-11 16:15 ——– d——– C:\Documents and Settings\chris\Application Data\CyberLink
2006-09-11 16:14 ——– d——– C:\Program Files\CyberLink
2006-09-10 22:43 ——– d——– C:\Program Files\Common Files\AOL
2006-09-10 21:14 ——– d——– C:\Program Files\AOL
2006-09-10 17:49 ——– d——– C:\Documents and Settings\chris\Application Data\acccore
2006-09-10 17:48 ——– d——– C:\Program Files\Common Files\Nullsoft
2006-09-10 17:47 ——– d——– C:\Documents and Settings\chris\Application Data\Mozilla
2006-09-10 14:16 ——– d——– C:\Program Files\WordWeb
2006-09-10 11:24 ——– d——– C:\Program Files\TuneXP
2006-09-06 17:43 22752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2006-08-25 15:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll
2006-08-23 02:11 307200 –a—— C:\WINDOWS\system32\atiiiexx.dll
2006-08-23 01:53 260096 –a—— C:\WINDOWS\system32\ati2dvag.dll
2006-08-23 01:47 114688 –a—— C:\WINDOWS\system32\atipdlxx.dll
2006-08-23 01:46 86016 –a—— C:\WINDOWS\system32\ati2evxx.dll
2006-08-23 01:46 77824 –a—— C:\WINDOWS\system32\Oemdspif.dll
2006-08-23 01:46 41984 –a—— C:\WINDOWS\system32\ati2edxx.dll
2006-08-23 01:46 26112 –a—— C:\WINDOWS\system32\Ati2mdxx.exe
2006-08-23 01:45 413696 –a—— C:\WINDOWS\system32\ati2evxx.exe
2006-08-23 01:44 53248 –a—— C:\WINDOWS\system32\ATIDDC.DLL
2006-08-23 01:38 2401984 –a—— C:\WINDOWS\system32\ati3duag.dll
2006-08-23 01:33 303104 –a—— C:\WINDOWS\system32\ATIDEMGR.dll
2006-08-23 01:33 2510752 –a—— C:\WINDOWS\system32\ativvaxx.dll
2006-08-23 01:27 6684672 –a—— C:\WINDOWS\system32\atioglx1.dll
2006-08-23 01:24 5140480 –a—— C:\WINDOWS\system32\atioglxx.dll
2006-08-23 01:21 221184 –a—— C:\WINDOWS\system32\atikvmag.dll
2006-08-23 01:19 17408 –a—— C:\WINDOWS\system32\atitvo32.dll
2006-08-23 01:14 290816 –a—— C:\WINDOWS\system32\ati2cqag.dll
2006-08-21 12:21 16896 –a—— C:\WINDOWS\system32\fltlib.dll
2006-08-21 09:14 23040 –a—— C:\WINDOWS\system32\fltmc.exe
2006-08-16 11:58 100352 –a—— C:\WINDOWS\system32\6to4svc.dll
2006-08-10 23:03 73728 –a—— C:\WINDOWS\system32\dpl100.dll
2006-08-10 23:03 196608 –a—— C:\WINDOWS\system32\dtu100.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Actual Window Manager"="\"C:\\Program Files\\Actual Window Manager\\ActualWindowManagerCenter.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SpeedTouch USB Diagnostics"="\"C:\\Program Files\\Thomson\\SpeedTouch USB\\Dragdiag.exe\" /icon"
"AtiPTA"="atiptaxx.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000004

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
"{F7999166-FDE6-49DA-9AFC-1F6A79E9D1F2}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoSMMyDocs"=dword:00000001
"NoRecentDocsMenu"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^chris^Start Menu^Programs^Startup^Adobe Gamma.lnk]
"path"="C:\\Documents and Settings\\chris\\Start Menu\\Programs\\Startup\\Adobe Gamma.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\defender]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="defender25"
"hkey"="HKLM"
"command"="C:\\\\defender25.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="point32"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Microsoft IntelliPoint\\point32.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\keyboard]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="keyboard25"
"hkey"="HKLM"
"command"="C:\\\\keyboard25.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\newname]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="newname25"
"hkey"="HKLM"
"command"="C:\\\\newname25.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ozrlfcc.dll]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ozrlfcc"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\ozrlfcc.dll,fpbepwb"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RoboTaskBarIcon"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Siber Systems\\AI RoboForm\\RoboTaskBarIcon.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SpyHunter"
"hkey"="HKLM"
"command"="C:\\Program Files\\Enigma Software Group\\SpyHunter\\SpyHunter.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemDoctor 2006 Free]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sd2006"
"hkey"="HKLM"
"command"="C:\\Program Files\\SystemDoctor 2006 Free\\sd2006.exe -scan"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ultimate Cleaner]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="App"
"hkey"="HKLM"
"command"="C:\\Program Files\\Ultimate Cleaner\\App.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VideoraiPodConverter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VideoraiPodConverter"
"hkey"="HKLM"
"command"="C:\\Program Files\\VideoraiPodConverter\\VideoraiPodConverter.exe -t"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAntiVirusPro2006]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WinAV"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\WinAntiVirus Pro 2006\\WinAV.exe\" /min"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zone Labs Client]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="zlclient"
"hkey"="HKLM"
"command"="C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"vsmon"=dword:00000002
"Network Monitor"=dword:00000002
"FWSvc"=dword:00000003
"cmdService"=dword:00000002
"Aol Software"=dword:00000002
"AVGEMS"=dword:00000002
"Apache2"=dword:00000002
"Adobe LM Service"=dword:00000003
"IDriverT"=dword:00000003
"Ati HotKey Poller"=dword:00000002
"Avg7UpdSvc"=dword:00000002
"Avg7Alrt"=dword:00000002
"avast! Web Scanner"=dword:00000003
"avast! Mail Scanner"=dword:00000003
"Spooler"=dword:00000003

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winhdn32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\clearprefetch.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

Completion time: 06-11-10 18:39:16.43
C:\ComboFix.txt … 06-11-10 18:39


Kaspersky
I was a bit busy and this scan went on for two hours so I'm not sure how much this could have affected the scan.

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, November 10, 2006 9:51:41 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 10/11/2006
Kaspersky Anti-Virus database records: 226842
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
G:\

Scan Statistics:
Total number of scanned objects: 65736
Number of viruses found: 0
Number of infected objects: 0 / 0
Number of suspicious objects: 0
Duration of the scan process: 02:12:49

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d953eda3e26304d35e06e3f99844845b_9d4e518d-5622-42b4-a195-861f29ab0d4f Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-11092006-171502.log Object is locked skipped
C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\vnraosd0.default\cert8.db Object is locked skipped
C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\vnraosd0.default\history.dat Object is locked skipped
C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\vnraosd0.default\key3.db Object is locked skipped
C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\vnraosd0.default\parent.lock Object is locked skipped
C:\Documents and Settings\chris\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Logs\Dfsr.log Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_E298_7FA3_987F_753F\dfsr.db Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_E298_7FA3_987F_753F\fsr.log Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_E298_7FA3_987F_753F\tmp.edb Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{C3E6CC4A-C701-4D99-BD9E-F4E45E4A6C74} Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\real\members.stg Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\shadow\members.stg Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Mozilla\Firefox\Profiles\vnraosd0.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Mozilla\Firefox\Profiles\vnraosd0.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Mozilla\Firefox\Profiles\vnraosd0.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Application Data\Mozilla\Firefox\Profiles\vnraosd0.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\chris\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\chris\Local Settings\History\History.IE5\MSHist012006111020061111\index.dat Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Temp\~DF6DCF.tmp Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Temp\~DF6EBB.tmp Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Temp\~DFAF80.tmp Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Temp\~DFAF97.tmp Object is locked skipped
C:\Documents and Settings\chris\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\chris\My Documents\My Music\iTunes\iTunes Library.itl Object is locked skipped
C:\Documents and Settings\chris\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\chris\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{16D942E7-D8D9-47A2-9C2A-98B65E79D5DA}\RP280\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{0B5AF25E-3268-4535-AE6F-4F7C2E9075AE}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edbtmp.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\fccaxxw.dll Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\ssqrr.dll Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
G:\System Volume Information\_restore{16D942E7-D8D9-47A2-9C2A-98B65E79D5DA}\RP280\change.log Object is locked skipped

Scan process completed.


Gmer
GMER 1.0.12.11889 - http://www.gmer.net
Rootkit scan 2006-11-10 22:49:40
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT \??\C:\Program Files\ewido anti-spyware 4.0\guard.sys ZwOpenProcess
SSDT \??\C:\Program Files\ewido anti-spyware 4.0\guard.sys ZwTerminateProcess

—- User code sections - GMER 1.0.12 —-

.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] kernel32.dll!LoadResource 7C809FB5 7 Bytes JMP 27001960 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] kernel32.dll!FindResourceExW 7C80AC88 7 Bytes JMP 270018E0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] kernel32.dll!FindResourceW 7C80BBCE 7 Bytes JMP 27001860 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] kernel32.dll!SizeofResource 7C80BC69 7 Bytes JMP 27001A00 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] kernel32.dll!LockResource 7C80CC97 5 Bytes JMP 27001A90 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] kernel32.dll!CreateEventA 7C8308AD 5 Bytes JMP 27001650 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] kernel32.dll!SetUnhandledExceptionFilter 7C84479D 5 Bytes JMP 004E12D0 C:\Program Files\MSN Messenger\msnmsgr.exe
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] USER32.dll!PeekMessageW 77D4929B 5 Bytes JMP 27003510 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] USER32.dll!CreateWindowExW 77D4FF50 5 Bytes JMP 27003020 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] USER32.dll!SetWindowRgn 77D502DD 7 Bytes JMP 27004840 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] USER32.dll!CreateDialogParamW 77D584EE 5 Bytes JMP 27004BC0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] USER32.dll!SetWindowPlacement 77D5DF46 5 Bytes JMP 27004760 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] USER32.dll!FlashWindow 77D85C5C 5 Bytes JMP 270048E0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] USER32.dll!MessageBoxIndirectW 77D96093 5 Bytes JMP 27004D20 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] USER32.dll!TrackPopupMenuEx 77D9CB1A 5 Bytes JMP 27003CE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] WS2_32.dll!send 71AB428A 5 Bytes JMP 27009360 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 27009150 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] WS2_32.dll!recv 71AB615A 5 Bytes JMP 27008FC0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 270094E0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 270096F0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] SHELL32.dll!Shell_NotifyIconW 7CA21B5A 5 Bytes JMP 27002960 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] ole32.dll!CoInitializeEx 774FEF6B 5 Bytes JMP 27001AF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] ole32.dll!CoRegisterClassObject 77518720 5 Bytes JMP 27001BF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] WININET.dll!InternetCloseHandle 771BE85D 5 Bytes JMP 27008230 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] WININET.dll!HttpOpenRequestA 771C160A 5 Bytes JMP 27007F50 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] WININET.dll!InternetReadFile 771C5BAA 5 Bytes JMP 270080B0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
.text C:\Program Files\MSN Messenger\msnmsgr.exe[1276] WININET.dll!HttpSendRequestA 771C7519 5 Bytes JMP 27008180 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll

—- Files - GMER 1.0.12 —-

ADS C:\Steam\SteamApps\carelessness\counter-strike\hl.exe:SummaryInformation
ADS C:\Steam\SteamApps\carelessness\counter-strike\hl.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

—- EOF - GMER 1.0.12 —-



Hijackthis

Logfile of HijackThis v1.99.1
Scan saved at 10:51:58, on 10/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Actual Window Manager\ActualWindowManagerCenter.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ShortKeys2\shortkey.exe
C:\Program Files\SnagIt 7\SnagIt32.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SnagIt 7\TSCHelp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\chris\Desktop\misc\jackthishi.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {19E3BEF4-B23B-41CD-B58D-DBA19EE56B38} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {F18F04B0-9CF1-4b93-B004-77A288BEE28B} - (no file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Actual Window Manager] "C:\Program Files\Actual Window Manager\ActualWindowManagerCenter.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: ShortKeys 2.lnk = C:\Program Files\ShortKeys2\shortkey.exe
O4 - Global Startup: SnagIt 7.lnk = C:\Program Files\SnagIt 7\SnagIt32.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\OFFICE~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149290353810
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149290344607
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) -
Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
VundoFix

VundoFix V6.2.8

Checking Java version…

Java version is 1.5.0.6

Java version is 1.5.0.9

Scan started at 12:11:21 AM 11/11/2006

Listing files found while scanning….

C:\WINDOWS\system32\ozrlfcc.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\ozrlfcc.dll
C:\WINDOWS\system32\ozrlfcc.dll Has been deleted!

Performing Repairs to the registry.
Done!


HiJackThis

Logfile of HijackThis v1.99.1
Scan saved at 12:36:19, on 11/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Actual Window Manager\ActualWindowManagerCenter.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ShortKeys2\shortkey.exe
C:\Program Files\SnagIt 7\SnagIt32.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\SnagIt 7\TSCHelp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\chris\Desktop\misc\jackthishi.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {19E3BEF4-B23B-41CD-B58D-DBA19EE56B38} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {F18F04B0-9CF1-4b93-B004-77A288BEE28B} - (no file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Actual Window Manager] "C:\Program Files\Actual Window Manager\ActualWindowManagerCenter.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: ShortKeys 2.lnk = C:\Program Files\ShortKeys2\shortkey.exe
O4 - Global Startup: SnagIt 7.lnk = C:\Program Files\SnagIt 7\SnagIt32.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\OFFICE~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149290353810
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149290344607
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames/Check…PA.cab40641.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DEF86AC6-B08A-4ED8-894A-96924ECD8399}: NameServer = 212.139.132.53 212.139.132.52
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winhdn32 - winhdn32.dll (file missing)
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe


As you can see the VundoFix log says Java versions *.06 and *.09. I don't understand though because I'm sure I uninstalled the old version.

I really appreciate you helping me with this Susan.
Awesome service here. :D
Glad thing are improving! :)

About the Java – just go to the Control Panel and Add/Remove programs and remove the Java version 1.5.0.6

Please do the following in order to check the file below.

STEP 1.
======
Please show all files for your system.
You will need to reverse this process when all steps are done.


Submit File to Jotti
Please click on Jotti
Use the "Browse" button and locate the following file on your computer:
C:\WINDOWS\system32\mbjdcioj.exe
Click the "Submit" button.
Please copy and post (reply) with the results

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html

Please also check the properties of those files (right-click and select properties from the popupmenu). Look if you can find some company information, etc.

Please repeat for
C:\WINDOWS\system32\xkhpxdts.exe

and reply with the results for both files.
mbjdcioj.exe

File: mbjdcioj.exe
Status: INFECTED/MALWARE
MD5 c49141b3fdb8f5b7a97814e58100655f
Packers detected: -
Scanner results
AntiVir Found Adware-Spyware/VSAddinDLL.A adware
ArcaVir Found Adware.Agent.At
Avast Found nothing
AVG Antivirus Found Generic.RUQ
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found Adware.SearchColours
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found not-a-virus:AdWare.Win32.Agent.at
NOD32 Found nothing
Norman Virus Control Found W32/Virtumonde.SR
VirusBuster Found Adware.SearchColors.A
VBA32 Found AdWare.Win32.Searchcolor.a


xkhpxdts.exe

File: xkhpxdts.exe
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 c49141b3fdb8f5b7a97814e58100655f
Packers detected: -
Scanner results
AntiVir Found Adware-Spyware/VSAddinDLL.A adware
ArcaVir Found Adware.Agent.At
Avast Found nothing
AVG Antivirus Found Generic.RUQ
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found Adware.SearchColours
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found not-a-virus:AdWare.Win32.Agent.at
NOD32 Found nothing
Norman Virus Control Found W32/Virtumonde.SR
VirusBuster Found Adware.SearchColors.A
VBA32 Found AdWare.Win32.Searchcolor.a


In each of the files' properties I couldn't find any company information or anything.
When there is not company information it is more of an indication that it may be malware.

Do you know anything about C:\WINDOWS\system32\tmp.reg? If not please submit it to Jotti.

STEP 1.
======
Please show all files for your system.
You will need to reverse this process when all steps are done.


Submit File to Jotti
Please click on Jotti
Use the "Browse" button and locate the following file on your computer:

C:\WINDOWS\system32\tmp.reg

Click the "Submit" button.
Please copy and post (reply) with the results

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html

Please also check the properties of those files (right-click and select properties from the popupmenu). Look if you can find some company information, etc.

STEP 2.
======
Delete Files with Killbox

Download Pocket Killbox from http://www.downloads.subratam.org/KillBox.zip and unzip it; save it to your Desktop. DO NOT RUN IT YET.
==========
Double-click on KillBox.exe to launch the program. It is the red circle with a large white X in it
- Highlight the files in bold RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard
C:\WINDOWS\system32\ssqrr.dll.vir
C:\WINDOWS\system32\fccaxxw.dll.vir
C:\WINDOWS\system32\rrqss.ini2
C:\WINDOWS\system32\mbjdcioj.exe
C:\WINDOWS\system32\rrqss.bak2
C:\WINDOWS\system32\xhwjde.dll
C:\WINDOWS\system32\drvzel.dll
C:\WINDOWS\system32\fccaxxw.dll
C:\WINDOWS\system32\xkhpxdts.exe
C:\WINDOWS\system32\rrqss.bak1
C:\WINDOWS\system32\ssqrr.dll
C:\WINDOWS\system32\awttqro.dll


In Killbox click on the File menu and then the Paste from Clipboard item
in the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.)
  • Click the option to Delete on Reboot
  • Click End Explorer Shell while Killing File
  • Click All Files right of the flashing green "Single files"
  • Click Yes when it asks "Files will be Removed on Reboot, Do you want to reboot now?"
(Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X …and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.
Combofix

chris - 06-11-12 14:10:04.74 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\chris\Desktop\misc"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))



~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\Program Files\Common Files\SKS~1
C:\QooBox\Purity\Program Files\Common Files\SKS~1\ç?sks


((((((((((((((((((((((((((((((( Files Created from 2006-10-12 to 2006-11-12 ))))))))))))))))))))))))))))))))))


2006-11-10 22:23 80 –a—— C:\WINDOWS\gmer_uninstall.cmd
2006-11-10 15:15 8,413 –a—— C:\WINDOWS\system32\drivers\mcstrm.sys
2006-11-08 17:39 1,940 –a—— C:\WINDOWS\system32\tmp.reg
2006-11-08 17:22 121,856 –a—— C:\WINDOWS\system32\xmllite.dll
2006-11-05 19:52 40,973 –ahs—- C:\WINDOWS\system32\fccaxxw.dll
2006-11-04 20:13 692,276 –ahs—- C:\WINDOWS\system32\ssqrr.dll
2006-11-04 18:27 816,288 –a—— C:\WINDOWS\system32\drivers\avg7core.sys
2006-11-04 18:27 4,224 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-11-04 18:27 3,968 –a—— C:\WINDOWS\system32\drivers\avgclean.sys
2006-11-04 18:27 28,416 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-10-31 22:00 53,248 –a—— C:\WINDOWS\system32\Process.exe
2006-10-31 22:00 40,960 –a—— C:\WINDOWS\system32\swsc.exe
2006-10-31 22:00 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2006-10-31 22:00 135,168 –a—— C:\WINDOWS\system32\swreg.exe
2006-10-27 15:09 6,049,280 –a—— C:\WINDOWS\system32\ieframe.dll
2006-10-27 15:09 50,688 –a—— C:\WINDOWS\system32\msfeedsbs.dll
2006-10-27 15:09 458,752 –a—— C:\WINDOWS\system32\msfeeds.dll
2006-10-27 15:09 180,736 –a—— C:\WINDOWS\system32\ieui.dll
2006-10-27 02:44 13,312 –a—— C:\WINDOWS\system32\ieudinit.exe
2006-10-25 16:22 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2006-10-20 18:05 44,875 –a—— C:\WINDOWS\system32\IPrtCnst.dll
2006-10-20 18:05 13,891 –a—— C:\WINDOWS\system32\drivers\IdeBusDr.sys
2006-10-20 18:05 101,431 –a—— C:\WINDOWS\system32\drivers\IdeChnDr.sys
2006-10-20 17:40 451,072 C:\WINDOWSRadeon Omega Drivers v3.8.291 Uninstall.exe
2006-10-18 02:47 89,360 –a—— C:\WINDOWS\system32\VB5DB.DLL
2006-10-17 13:05 206,336 –a—— C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 12:58 61,952 –a—— C:\WINDOWS\system32\icardie.dll
2006-10-17 12:58 12,288 –a—— C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 12:57 266,752 –a—— C:\WINDOWS\system32\iertutil.dll
2006-10-17 12:27 380,928 –a—— C:\WINDOWS\system32\ieapfltr.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-12 14:08 ——– d——– C:\Program Files\Mozilla Firefox
2006-11-12 14:03 ——– d——– C:\Program Files\ShortKeys2
2006-11-11 20:08 ——– d——– C:\Program Files\Softwin
2006-11-11 20:08 ——– d——– C:\Program Files\Common Files\Softwin
2006-11-11 20:05 ——– d——– C:\Program Files\Common Files
2006-11-10 18:26 ——– d——– C:\Program Files\iTunes
2006-11-10 18:26 ——– d——– C:\Program Files\iPod
2006-11-10 18:25 ——– d——– C:\Program Files\QuickTime
2006-11-09 17:14 ——– d——– C:\Program Files\Windows Defender
2006-11-08 21:44 ——– d——– C:\Program Files\Internet Explorer
2006-11-08 18:46 ——– d——– C:\Program Files\Java
2006-11-08 18:32 ——– d——– C:\Program Files\VSAdd-in
2006-11-08 16:18 ——– d——– C:\Documents and Settings\chris\Application Data\AVG7
2006-11-08 16:15 ——– d——– C:\Program Files\ewido anti-spyware 4.0
2006-11-07 18:39 ——– d——– C:\Program Files\SpywareBlaster
2006-11-07 18:30 ——– d—s—- C:\Documents and Settings\chris\Application Data\Microsoft
2006-11-06 22:49 ——– d——– C:\Program Files\SnagIt 7
2006-11-04 18:27 ——– d——– C:\Program Files\Grisoft
2006-10-31 23:23 ——– d——– C:\Program Files\Flash Decompiler
2006-10-31 23:23 ——– d——– C:\Documents and Settings\chris\Application Data\Eltima Software
2006-10-31 21:21 ——– d——– C:\Program Files\Diskeeper Corporation
2006-10-30 21:23 ——– d——– C:\Program Files\MSN Messenger
2006-10-28 21:11 ——– d——– C:\Program Files\Radeon Omega Drivers
2006-10-27 15:09 413696 –a—— C:\WINDOWS\system32\vbscript.dll
2006-10-27 15:09 231424 –a—— C:\WINDOWS\system32\webcheck.dll
2006-10-27 15:09 156160 –a—— C:\WINDOWS\system32\msls31.dll
2006-10-27 02:44 71680 –a—— C:\WINDOWS\system32\admparse.dll
2006-10-27 02:44 55296 –a—— C:\WINDOWS\system32\iesetup.dll
2006-10-27 02:44 54784 –a—— C:\WINDOWS\system32\ie4uinit.exe
2006-10-27 02:44 43008 –a—— C:\WINDOWS\system32\iernonce.dll
2006-10-27 02:44 382976 –a—— C:\WINDOWS\system32\iedkcs32.dll
2006-10-27 02:44 229376 –a—— C:\WINDOWS\system32\ieaksie.dll
2006-10-27 02:44 152064 –a—— C:\WINDOWS\system32\ieakeng.dll
2006-10-27 02:44 123904 –a—— C:\WINDOWS\system32\advpack.dll
2006-10-27 02:42 161792 –a—— C:\WINDOWS\system32\ieakui.dll
2006-10-26 14:05 ——– d——– C:\Program Files\Microsoft Works
2006-10-25 17:34 ——– d——– C:\Program Files\Microsoft Office
2006-10-25 17:34 ——– d——– C:\Program Files\Common Files\Microsoft Shared
2006-10-25 17:25 ——– d——– C:\Program Files\Microsoft IntelliPoint
2006-10-25 17:24 ——– d——– C:\Program Files\Microsoft IntelliPoint 5.0
2006-10-21 23:02 ——– d——– C:\Program Files\Microsoft ActiveSync
2006-10-21 23:01 ——– d——– C:\Program Files\Office 2003
2006-10-21 23:00 ——– d——– C:\Program Files\Microsoft.NET
2006-10-21 14:52 ——– d——– C:\Program Files\Apple Software Update
2006-10-20 22:04 ——– d——– C:\Program Files\AutoIt3
2006-10-20 18:05 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-10-20 18:05 ——– d——– C:\Program Files\Intel
2006-10-20 17:41 ——– d——– C:\Program Files\MultiRes
2006-10-20 17:40 451072 –a—— C:\WINDOWS\Radeon Omega Drivers v3.8.291 Uninstall.exe
2006-10-19 17:38 ——– d——– C:\Program Files\Siber Systems
2006-10-19 16:33 ——– d——– C:\Program Files\ProxyChecker
2006-10-19 16:33 ——– d——– C:\Program Files\Last.fm Player
2006-10-19 14:16 ——– d——– C:\Program Files\Microsoft IntelliPoint 4.12
2006-10-18 03:25 126 –a—— C:\Documents and Settings\chris\Application Data\iScrobbler.ini
2006-10-18 03:25 101252 –a—— C:\Documents and Settings\chris\Application Data\.iScrobbler
2006-10-17 13:06 78336 –a—— C:\WINDOWS\system32\ieencode.dll
2006-10-17 13:05 40960 –a—— C:\WINDOWS\system32\licmgr10.dll
2006-10-17 13:05 105984 –a—— C:\WINDOWS\system32\url.dll
2006-10-17 13:04 101376 –a—— C:\WINDOWS\system32\occache.dll
2006-10-17 13:03 17408 –a—— C:\WINDOWS\system32\corpol.dll
2006-10-17 12:57 36352 –a—— C:\WINDOWS\system32\imgutil.dll
2006-10-17 12:56 45568 –a—— C:\WINDOWS\system32\mshta.exe
2006-10-17 12:28 48128 –a—— C:\WINDOWS\system32\mshtmler.dll
2006-10-15 19:41 ——– d——– C:\Program Files\Windows Live Safety Center
2006-10-15 19:23 ——– d——– C:\Program Files\VideoraiPodConverter
2006-10-15 19:23 ——– d——– C:\Program Files\AviSynth 2.5
2006-10-08 20:56 724992 –a—— C:\MatrixSounds.dll
2006-10-07 16:12 ——– d——– C:\Program Files\Microsoft Bootvis
2006-10-07 14:04 ——– d——– C:\Program Files\Photoshop CS2
2006-10-07 13:13 ——– d——– C:\Program Files\Alwil Software
2006-10-07 00:44 ——– d——– C:\Documents and Settings\chris\Application Data\DivX
2006-10-06 13:46 ——– d——– C:\Program Files\ClipMagic
2006-10-06 13:45 ——– d——– C:\Documents and Settings\chris\Application Data\ClipMagic
2006-10-05 15:13 737280 –a—— C:\WINDOWS\iun6002.exe
2006-10-04 19:20 ——– d——– C:\Program Files\TuneSleeve
2006-10-03 20:58 ——– d——– C:\Program Files\DivX
2006-10-03 18:18 ——– d——– C:\Program Files\Messenger Plus! Live
2006-10-02 19:04 806912 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2006-10-02 19:04 806912 –a—— C:\WINDOWS\system32\divx_xx07.dll
2006-10-02 19:04 790528 –a—— C:\WINDOWS\system32\divx_xx11.dll
2006-10-02 19:04 635486 –a—— C:\WINDOWS\system32\DivX.dll
2006-09-27 17:11 ——– d——– C:\Program Files\Boots F2CD
2006-09-23 21:33 1723904 –a—— C:\WINDOWS\system32\drivers\ati2mtag.sys
2006-09-19 15:44 15664 –a—— C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2006-09-19 15:43 109360 –a—— C:\WINDOWS\system32\GEARAspi.dll
2006-09-14 17:17 ——– d——– C:\Program Files\mIRC
2006-09-13 17:34 ——– d——– C:\Program Files\HLSW
2006-09-13 15:08 ——– d——– C:\Program Files\ClamWin
2006-09-13 05:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll
2006-09-06 17:43 22752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2006-08-25 15:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll
2006-08-23 02:11 307200 –a—— C:\WINDOWS\system32\atiiiexx.dll
2006-08-23 01:53 260096 –a—— C:\WINDOWS\system32\ati2dvag.dll
2006-08-23 01:47 114688 –a—— C:\WINDOWS\system32\atipdlxx.dll
2006-08-23 01:46 86016 –a—— C:\WINDOWS\system32\ati2evxx.dll
2006-08-23 01:46 77824 –a—— C:\WINDOWS\system32\Oemdspif.dll
2006-08-23 01:46 41984 –a—— C:\WINDOWS\system32\ati2edxx.dll
2006-08-23 01:46 26112 –a—— C:\WINDOWS\system32\Ati2mdxx.exe
2006-08-23 01:45 413696 –a—— C:\WINDOWS\system32\ati2evxx.exe
2006-08-23 01:44 53248 –a—— C:\WINDOWS\system32\ATIDDC.DLL
2006-08-23 01:38 2401984 –a—— C:\WINDOWS\system32\ati3duag.dll
2006-08-23 01:33 303104 –a—— C:\WINDOWS\system32\ATIDEMGR.dll
2006-08-23 01:33 2510752 –a—— C:\WINDOWS\system32\ativvaxx.dll
2006-08-23 01:27 6684672 –a—— C:\WINDOWS\system32\atioglx1.dll
2006-08-23 01:24 5140480 –a—— C:\WINDOWS\system32\atioglxx.dll
2006-08-23 01:21 221184 –a—— C:\WINDOWS\system32\atikvmag.dll
2006-08-23 01:19 17408 –a—— C:\WINDOWS\system32\atitvo32.dll
2006-08-23 01:14 290816 –a—— C:\WINDOWS\system32\ati2cqag.dll
2006-08-21 12:21 16896 –a—— C:\WINDOWS\system32\fltlib.dll
2006-08-21 09:14 23040 –a—— C:\WINDOWS\system32\fltmc.exe
2006-08-16 11:58 100352 –a—— C:\WINDOWS\system32\6to4svc.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Actual Window Manager"="\"C:\\Program Files\\Actual Window Manager\\ActualWindowManagerCenter.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SpeedTouch USB Diagnostics"="\"C:\\Program Files\\Thomson\\SpeedTouch USB\\Dragdiag.exe\" /icon"
"AtiPTA"="atiptaxx.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"BDNewsAgent"="\"c:\\program files\\softwin\\bitdefender8\\bdnagent.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000004

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
"{F7999166-FDE6-49DA-9AFC-1F6A79E9D1F2}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoSMMyDocs"=dword:00000001
"NoRecentDocsMenu"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^chris^Start Menu^Programs^Startup^Adobe Gamma.lnk]
"path"="C:\\Documents and Settings\\chris\\Start Menu\\Programs\\Startup\\Adobe Gamma.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\defender]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="defender25"
"hkey"="HKLM"
"command"="C:\\\\defender25.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="point32"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Microsoft IntelliPoint\\point32.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\keyboard]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="keyboard25"
"hkey"="HKLM"
"command"="C:\\\\keyboard25.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\newname]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="newname25"
"hkey"="HKLM"
"command"="C:\\\\newname25.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ozrlfcc.dll]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ozrlfcc"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\ozrlfcc.dll,fpbepwb"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RoboTaskBarIcon"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Siber Systems\\AI RoboForm\\RoboTaskBarIcon.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SpyHunter"
"hkey"="HKLM"
"command"="C:\\Program Files\\Enigma Software Group\\SpyHunter\\SpyHunter.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemDoctor 2006 Free]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sd2006"
"hkey"="HKLM"
"command"="C:\\Program Files\\SystemDoctor 2006 Free\\sd2006.exe -scan"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ultimate Cleaner]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="App"
"hkey"="HKLM"
"command"="C:\\Program Files\\Ultimate Cleaner\\App.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VideoraiPodConverter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VideoraiPodConverter"
"hkey"="HKLM"
"command"="C:\\Program Files\\VideoraiPodConverter\\VideoraiPodConverter.exe -t"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAntiVirusPro2006]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WinAV"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\WinAntiVirus Pro 2006\\WinAV.exe\" /min"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zone Labs Client]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="zlclient"
"hkey"="HKLM"
"command"="C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"vsmon"=dword:00000002
"Network Monitor"=dword:00000002
"FWSvc"=dword:00000003
"cmdService"=dword:00000002
"Aol Software"=dword:00000002
"AVGEMS"=dword:00000002
"Apache2"=dword:00000002
"Adobe LM Service"=dword:00000003
"IDriverT"=dword:00000003
"Ati HotKey Poller"=dword:00000002
"Avg7UpdSvc"=dword:00000002
"Avg7Alrt"=dword:00000002
"avast! Web Scanner"=dword:00000003
"avast! Mail Scanner"=dword:00000003
"Spooler"=dword:00000003

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winhdn32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\clearprefetch.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

Completion time: 06-11-12 14:11:18.60
C:\ComboFix.txt … 06-11-12 14:11
C:\ComboFix2.txt … 06-11-10 18:39

Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

STEP 1.
======
Delete Files with Killbox

Download Pocket Killbox from http://www.downloads.subratam.org/KillBox.zip and unzip it; save it to your Desktop. DO NOT RUN IT YET.
==========
Double-click on KillBox.exe to launch the program. It is the red circle with a large white X in it
- Highlight the files in bold RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard
C:\WINDOWS\system32\fccaxxw.dll
C:\WINDOWS\system32\ssqrr.dll


In Killbox click on the File menu and then the Paste from Clipboard item
in the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.)
  • Click the option to Delete on Reboot
  • Click End Explorer Shell while Killing File
  • Click All Files right of the flashing green "Single files"
  • Click Yes when it asks "Files will be Removed on Reboot, Do you want to reboot now?"
(Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X …and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.



STEP 2.
======
Regscan

Please download RegScan.
Within RegScan.zip you will find the file regscan.vbs
You may have to allow this script to run or disable anti-spyware again in order for it to run.
A window will open titled RegFinder.vbs and you will see place to input search terms.
Please enter the search terms:
winhdn32
After the search has completed a window titled Results.txt will open.
Please copy the results and post(reply) back.

Backup the registry:

STEP 3.
======
Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe

Then, go to start–>run

and type this in:
notepad

Paste this into the box:

REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\keyboard]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ozrlfcc.dll]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAntiVirusPro2006]

Then click on the FILE menu and select save as
Save the file as regfix.reg. Save the file to the desktop.
IMPORTANT: make sure to save the file as "all types" and NOT as a text file
**

Now double click on regfix.reg and insert it into the registry.

Please run ComboFix again and reply with:
The results from the registry scan for winhdn32
And the log from ComboFix
and a fresh hijackthis log.
regscan

Windows Registry Editor Version 5.00

; Regscan.vbs Version: 1.2 by rand1038

; 13/11/2006 05:51:05 PM
; Search Term(s) Used: "winhdn32"
; 2 matches were found.
; The search took 57 seconds.


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winhdn32]
"DllName"="winhdn32.dll"


ComboScan

chris - 06-11-13 18:04:36.45 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\chris\Desktop\misc"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))



~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\Program Files\Common Files\SKS~1
C:\QooBox\Purity\Program Files\Common Files\SKS~1\ç?sks


((((((((((((((((((((((((((((((( Files Created from 2006-10-13 to 2006-11-13 ))))))))))))))))))))))))))))))))))


2006-11-10 22:23 80 –a—— C:\WINDOWS\gmer_uninstall.cmd
2006-11-10 15:15 8,413 –a—— C:\WINDOWS\system32\drivers\mcstrm.sys
2006-11-08 17:39 1,940 –a—— C:\WINDOWS\system32\tmp.reg
2006-11-08 17:22 121,856 –a—— C:\WINDOWS\system32\xmllite.dll
2006-11-05 19:52 40,973 –ahs—- C:\WINDOWS\system32\fccaxxw.dll
2006-11-04 20:13 692,276 –ahs—- C:\WINDOWS\system32\ssqrr.dll
2006-11-04 18:27 816,288 –a—— C:\WINDOWS\system32\drivers\avg7core.sys
2006-11-04 18:27 4,224 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-11-04 18:27 3,968 –a—— C:\WINDOWS\system32\drivers\avgclean.sys
2006-11-04 18:27 28,416 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-10-31 22:00 53,248 –a—— C:\WINDOWS\system32\Process.exe
2006-10-31 22:00 40,960 –a—— C:\WINDOWS\system32\swsc.exe
2006-10-31 22:00 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2006-10-31 22:00 135,168 –a—— C:\WINDOWS\system32\swreg.exe
2006-10-27 15:09 6,049,280 –a—— C:\WINDOWS\system32\ieframe.dll
2006-10-27 15:09 50,688 –a—— C:\WINDOWS\system32\msfeedsbs.dll
2006-10-27 15:09 458,752 –a—— C:\WINDOWS\system32\msfeeds.dll
2006-10-27 15:09 180,736 –a—— C:\WINDOWS\system32\ieui.dll
2006-10-27 02:44 13,312 –a—— C:\WINDOWS\system32\ieudinit.exe
2006-10-25 16:22 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2006-10-20 18:05 44,875 –a—— C:\WINDOWS\system32\IPrtCnst.dll
2006-10-20 18:05 13,891 –a—— C:\WINDOWS\system32\drivers\IdeBusDr.sys
2006-10-20 18:05 101,431 –a—— C:\WINDOWS\system32\drivers\IdeChnDr.sys
2006-10-20 17:40 451,072 C:\WINDOWSRadeon Omega Drivers v3.8.291 Uninstall.exe
2006-10-18 02:47 89,360 –a—— C:\WINDOWS\system32\VB5DB.DLL
2006-10-17 13:05 206,336 –a—— C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 12:58 61,952 –a—— C:\WINDOWS\system32\icardie.dll
2006-10-17 12:58 12,288 –a—— C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 12:57 266,752 –a—— C:\WINDOWS\system32\iertutil.dll
2006-10-17 12:27 380,928 –a—— C:\WINDOWS\system32\ieapfltr.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-13 17:55 ——– d——– C:\Program Files\ERUNT
2006-11-13 17:46 ——– d——– C:\Program Files\Mozilla Firefox
2006-11-13 17:44 ——– d——– C:\Program Files\ShortKeys2
2006-11-11 20:08 ——– d——– C:\Program Files\Softwin
2006-11-11 20:08 ——– d——– C:\Program Files\Common Files\Softwin
2006-11-11 20:05 ——– d——– C:\Program Files\Common Files
2006-11-10 18:26 ——– d——– C:\Program Files\iTunes
2006-11-10 18:26 ——– d——– C:\Program Files\iPod
2006-11-10 18:25 ——– d——– C:\Program Files\QuickTime
2006-11-09 17:14 ——– d——– C:\Program Files\Windows Defender
2006-11-08 21:44 ——– d——– C:\Program Files\Internet Explorer
2006-11-08 18:46 ——– d——– C:\Program Files\Java
2006-11-08 18:32 ——– d——– C:\Program Files\VSAdd-in
2006-11-08 16:18 ——– d——– C:\Documents and Settings\chris\Application Data\AVG7
2006-11-08 16:15 ——– d——– C:\Program Files\ewido anti-spyware 4.0
2006-11-07 18:39 ——– d——– C:\Program Files\SpywareBlaster
2006-11-07 18:30 ——– d—s—- C:\Documents and Settings\chris\Application Data\Microsoft
2006-11-06 22:49 ——– d——– C:\Program Files\SnagIt 7
2006-11-04 18:27 ——– d——– C:\Program Files\Grisoft
2006-10-31 23:23 ——– d——– C:\Program Files\Flash Decompiler
2006-10-31 23:23 ——– d——– C:\Documents and Settings\chris\Application Data\Eltima Software
2006-10-31 21:21 ——– d——– C:\Program Files\Diskeeper Corporation
2006-10-30 21:23 ——– d——– C:\Program Files\MSN Messenger
2006-10-28 21:11 ——– d——– C:\Program Files\Radeon Omega Drivers
2006-10-27 15:09 413696 –a—— C:\WINDOWS\system32\vbscript.dll
2006-10-27 15:09 231424 –a—— C:\WINDOWS\system32\webcheck.dll
2006-10-27 15:09 156160 –a—— C:\WINDOWS\system32\msls31.dll
2006-10-27 02:44 71680 –a—— C:\WINDOWS\system32\admparse.dll
2006-10-27 02:44 55296 –a—— C:\WINDOWS\system32\iesetup.dll
2006-10-27 02:44 54784 –a—— C:\WINDOWS\system32\ie4uinit.exe
2006-10-27 02:44 43008 –a—— C:\WINDOWS\system32\iernonce.dll
2006-10-27 02:44 382976 –a—— C:\WINDOWS\system32\iedkcs32.dll
2006-10-27 02:44 229376 –a—— C:\WINDOWS\system32\ieaksie.dll
2006-10-27 02:44 152064 –a—— C:\WINDOWS\system32\ieakeng.dll
2006-10-27 02:44 123904 –a—— C:\WINDOWS\system32\advpack.dll
2006-10-27 02:42 161792 –a—— C:\WINDOWS\system32\ieakui.dll
2006-10-26 14:05 ——– d——– C:\Program Files\Microsoft Works
2006-10-25 17:34 ——– d——– C:\Program Files\Microsoft Office
2006-10-25 17:34 ——– d——– C:\Program Files\Common Files\Microsoft Shared
2006-10-25 17:25 ——– d——– C:\Program Files\Microsoft IntelliPoint
2006-10-25 17:24 ——– d——– C:\Program Files\Microsoft IntelliPoint 5.0
2006-10-21 23:02 ——– d——– C:\Program Files\Microsoft ActiveSync
2006-10-21 23:01 ——– d——– C:\Program Files\Office 2003
2006-10-21 23:00 ——– d——– C:\Program Files\Microsoft.NET
2006-10-21 14:52 ——– d——– C:\Program Files\Apple Software Update
2006-10-20 22:04 ——– d——– C:\Program Files\AutoIt3
2006-10-20 18:05 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-10-20 18:05 ——– d——– C:\Program Files\Intel
2006-10-20 17:41 ——– d——– C:\Program Files\MultiRes
2006-10-20 17:40 451072 –a—— C:\WINDOWS\Radeon Omega Drivers v3.8.291 Uninstall.exe
2006-10-19 17:38 ——– d——– C:\Program Files\Siber Systems
2006-10-19 16:33 ——– d——– C:\Program Files\ProxyChecker
2006-10-19 16:33 ——– d——– C:\Program Files\Last.fm Player
2006-10-19 14:16 ——– d——– C:\Program Files\Microsoft IntelliPoint 4.12
2006-10-18 03:25 126 –a—— C:\Documents and Settings\chris\Application Data\iScrobbler.ini
2006-10-18 03:25 101252 –a—— C:\Documents and Settings\chris\Application Data\.iScrobbler
2006-10-17 13:06 78336 –a—— C:\WINDOWS\system32\ieencode.dll
2006-10-17 13:05 40960 –a—— C:\WINDOWS\system32\licmgr10.dll
2006-10-17 13:05 105984 –a—— C:\WINDOWS\system32\url.dll
2006-10-17 13:04 101376 –a—— C:\WINDOWS\system32\occache.dll
2006-10-17 13:03 17408 –a—— C:\WINDOWS\system32\corpol.dll
2006-10-17 12:57 36352 –a—— C:\WINDOWS\system32\imgutil.dll
2006-10-17 12:56 45568 –a—— C:\WINDOWS\system32\mshta.exe
2006-10-17 12:28 48128 –a—— C:\WINDOWS\system32\mshtmler.dll
2006-10-15 19:41 ——– d——– C:\Program Files\Windows Live Safety Center
2006-10-15 19:23 ——– d——– C:\Program Files\VideoraiPodConverter
2006-10-15 19:23 ——– d——– C:\Program Files\AviSynth 2.5
2006-10-08 20:56 724992 –a—— C:\MatrixSounds.dll
2006-10-07 16:12 ——– d——– C:\Program Files\Microsoft Bootvis
2006-10-07 14:04 ——– d——– C:\Program Files\Photoshop CS2
2006-10-07 13:13 ——– d——– C:\Program Files\Alwil Software
2006-10-07 00:44 ——– d——– C:\Documents and Settings\chris\Application Data\DivX
2006-10-06 13:46 ——– d——– C:\Program Files\ClipMagic
2006-10-06 13:45 ——– d——– C:\Documents and Settings\chris\Application Data\ClipMagic
2006-10-05 15:13 737280 –a—— C:\WINDOWS\iun6002.exe
2006-10-04 19:20 ——– d——– C:\Program Files\TuneSleeve
2006-10-03 20:58 ——– d——– C:\Program Files\DivX
2006-10-03 18:18 ——– d——– C:\Program Files\Messenger Plus! Live
2006-10-02 19:04 806912 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2006-10-02 19:04 806912 –a—— C:\WINDOWS\system32\divx_xx07.dll
2006-10-02 19:04 790528 –a—— C:\WINDOWS\system32\divx_xx11.dll
2006-10-02 19:04 635486 –a—— C:\WINDOWS\system32\DivX.dll
2006-09-27 17:11 ——– d——– C:\Program Files\Boots F2CD
2006-09-23 21:33 1723904 –a—— C:\WINDOWS\system32\drivers\ati2mtag.sys
2006-09-19 15:44 15664 –a—— C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2006-09-19 15:43 109360 –a—— C:\WINDOWS\system32\GEARAspi.dll
2006-09-14 17:17 ——– d——– C:\Program Files\mIRC
2006-09-13 17:34 ——– d——– C:\Program Files\HLSW
2006-09-13 15:08 ——– d——– C:\Program Files\ClamWin
2006-09-13 05:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll
2006-09-06 17:43 22752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2006-08-25 15:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll
2006-08-23 02:11 307200 –a—— C:\WINDOWS\system32\atiiiexx.dll
2006-08-23 01:53 260096 –a—— C:\WINDOWS\system32\ati2dvag.dll
2006-08-23 01:47 114688 –a—— C:\WINDOWS\system32\atipdlxx.dll
2006-08-23 01:46 86016 –a—— C:\WINDOWS\system32\ati2evxx.dll
2006-08-23 01:46 77824 –a—— C:\WINDOWS\system32\Oemdspif.dll
2006-08-23 01:46 41984 –a—— C:\WINDOWS\system32\ati2edxx.dll
2006-08-23 01:46 26112 –a—— C:\WINDOWS\system32\Ati2mdxx.exe
2006-08-23 01:45 413696 –a—— C:\WINDOWS\system32\ati2evxx.exe
2006-08-23 01:44 53248 –a—— C:\WINDOWS\system32\ATIDDC.DLL
2006-08-23 01:38 2401984 –a—— C:\WINDOWS\system32\ati3duag.dll
2006-08-23 01:33 303104 –a—— C:\WINDOWS\system32\ATIDEMGR.dll
2006-08-23 01:33 2510752 –a—— C:\WINDOWS\system32\ativvaxx.dll
2006-08-23 01:27 6684672 –a—— C:\WINDOWS\system32\atioglx1.dll
2006-08-23 01:24 5140480 –a—— C:\WINDOWS\system32\atioglxx.dll
2006-08-23 01:21 221184 –a—— C:\WINDOWS\system32\atikvmag.dll
2006-08-23 01:19 17408 –a—— C:\WINDOWS\system32\atitvo32.dll
2006-08-23 01:14 290816 –a—— C:\WINDOWS\system32\ati2cqag.dll
2006-08-21 12:21 16896 –a—— C:\WINDOWS\system32\fltlib.dll
2006-08-21 09:14 23040 –a—— C:\WINDOWS\system32\fltmc.exe
2006-08-16 11:58 100352 –a—— C:\WINDOWS\system32\6to4svc.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Actual Window Manager"="\"C:\\Program Files\\Actual Window Manager\\ActualWindowManagerCenter.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SpeedTouch USB Diagnostics"="\"C:\\Program Files\\Thomson\\SpeedTouch USB\\Dragdiag.exe\" /icon"
"AtiPTA"="atiptaxx.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"BDNewsAgent"="\"c:\\program files\\softwin\\bitdefender8\\bdnagent.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000004

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
"{F7999166-FDE6-49DA-9AFC-1F6A79E9D1F2}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoSMMyDocs"=dword:00000001
"NoRecentDocsMenu"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^chris^Start Menu^Programs^Startup^Adobe Gamma.lnk]
"path"="C:\\Documents and Settings\\chris\\Start Menu\\Programs\\Startup\\Adobe Gamma.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\defender]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="defender25"
"hkey"="HKLM"
"command"="C:\\\\defender25.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="point32"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Microsoft IntelliPoint\\point32.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\newname]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="newname25"
"hkey"="HKLM"
"command"="C:\\\\newname25.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RoboTaskBarIcon"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Siber Systems\\AI RoboForm\\RoboTaskBarIcon.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemDoctor 2006 Free]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sd2006"
"hkey"="HKLM"
"command"="C:\\Program Files\\SystemDoctor 2006 Free\\sd2006.exe -scan"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ultimate Cleaner]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="App"
"hkey"="HKLM"
"command"="C:\\Program Files\\Ultimate Cleaner\\App.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VideoraiPodConverter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VideoraiPodConverter"
"hkey"="HKLM"
"command"="C:\\Program Files\\VideoraiPodConverter\\VideoraiPodConverter.exe -t"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zone Labs Client]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="zlclient"
"hkey"="HKLM"
"command"="C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"vsmon"=dword:00000002
"Network Monitor"=dword:00000002
"FWSvc"=dword:00000003
"cmdService"=dword:00000002
"Aol Software"=dword:00000002
"AVGEMS"=dword:00000002
"Apache2"=dword:00000002
"Adobe LM Service"=dword:00000003
"IDriverT"=dword:00000003
"Ati HotKey Poller"=dword:00000002
"Avg7UpdSvc"=dword:00000002
"Avg7Alrt"=dword:00000002
"avast! Web Scanner"=dword:00000003
"avast! Mail Scanner"=dword:00000003
"Spooler"=dword:00000003

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winhdn32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\clearprefetch.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

Completion time: 06-11-13 18:05:52.53
C:\ComboFix.txt … 06-11-13 18:05
C:\ComboFix2.txt … 06-11-12 14:11
C:\ComboFix3.txt … 06-11-10 18:39


HijackThis

Logfile of HijackThis v1.99.1
Scan saved at 06:22:34, on 13/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\program files\softwin\bitdefender8\bdnagent.exe
C:\Program Files\Actual Window Manager\ActualWindowManagerCenter.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ShortKeys2\shortkey.exe
C:\Program Files\SnagIt 7\SnagIt32.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\SnagIt 7\TSCHelp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\chris\Desktop\misc\jackthishi.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {19E3BEF4-B23B-41CD-B58D-DBA19EE56B38} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {F18F04B0-9CF1-4b93-B004-77A288BEE28B} - (no file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "c:\program files\softwin\bitdefender8\bdnagent.exe"
O4 - HKCU\..\Run: [Actual Window Manager] "C:\Program Files\Actual Window Manager\ActualWindowManagerCenter.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: ShortKeys 2.lnk = C:\Program Files\ShortKeys2\shortkey.exe
O4 - Global Startup: SnagIt 7.lnk = C:\Program Files\SnagIt 7\SnagIt32.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\OFFICE~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149290353810
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149290344607
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames/Check…PA.cab40641.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DEF86AC6-B08A-4ED8-894A-96924ECD8399}: NameServer = 212.139.132.53 212.139.132.52
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winhdn32 - winhdn32.dll (file missing)
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)


(btw I think your link is broke for erunt. I managed to get it though and backup registry).
I followed all the steps :)
Thanks, I will study it and get back with instructions. There are a couple of items that are being stubborn so we may need to use a different tool.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI