This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

still getting popups after recent SP2 install

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

it's making me crazy……any help will be GREATLY appreciated. thanks!

Logfile of HijackThis v1.99.1
Scan saved at 1:10:38 PM, on 12/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\??crosoft.NET\r?ndll32.exe
C:\PROGRA~1\DOBE~1\services.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {1521A0D6-6F42-17B7-4496-36918BD38BB7} - C:\WINDOWS\System32\avrj.dll (file missing)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
R3 - URLSearchHook: (no name) - {B77FB00A-7FCC-5C35-9EDB-2250D7F625BD} - C:\WINDOWS\system32\xefwt.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1521A0D6-6F42-17B7-4496-36918BD38BB7} - C:\WINDOWS\System32\avrj.dll (file missing)
O2 - BHO: (no name) - {1ee03ad2-9421-48b8-a605-1abe23513ec0} - C:\WINDOWS\system32\c_8dsw.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {78B604B6-9872-B1DE-7D20-CDCE1FECE8E5} - C:\WINDOWS\System32\waad.dll (file missing)
O2 - BHO: (no name) - {F56B3F1A-FDDB-8779-DEDF-A228907263E9} - C:\WINDOWS\System32\vztgt.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Txhrndl] C:\WINDOWS\system32\??crosoft.NET\r?ndll32.exe
O4 - HKCU\..\Run: [Notn] "C:\PROGRA~1\DOBE~1\services.exe" -vt yazr
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/2549e5097f66ec…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164905465328
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164905459765
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: c_8dsw - C:\WINDOWS\SYSTEM32\c_8dsw.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: winzdn32 - winzdn32.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Welcome to the forum :wavey:

Download combofix.exe from the link below:

Combofix.exe

Save it to your desktop.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run combofix.

When finished, it will produce a log for you.

Post that log in your next reply, along with a new HijackThis! log.

There will be a few things left we'll need to remove manually, so don't become a stranger to the forum after posting the requested logs.

:)

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Owner - 06-12-12 11:04:02.96 Service Pack 2
ComboFix 06.11.27W - Running from: "C:\Documents and Settings\Owner\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Common Files\system32.dll
C:\temp.zip
C:\x.txt
C:\z.txt
C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\setup.exe.tmp
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\tracert.com
C:\Program Files\Common Files\download
C:\Program Files\Common Files\inetget2
C:\Program Files\DNS
C:\Program Files\msconfigs
C:\Program Files\outlook
C:\Program Files\windows
C:\Program Files\winupdates
C:\Program Files\Common Files\{1C8E4DC8-0822-1033-0219-040522050001}
C:\Program Files\Common Files\{1C8E4DC8-0823-1033-0219-040522050001}
C:\Program Files\Common Files\{3C8E4DC8-0823-1033-0219-040522050001}

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\Documents and Settings\Owner\Application Data\CROSOF~1
C:\QooBox\Purity\Documents and Settings\Owner\Application Data\STEM32~1
C:\QooBox\Purity\Documents and Settings\Owner\Application Data\STEM~1
C:\QooBox\Purity\Documents and Settings\Owner\My Documents\ASEMBL~1
C:\QooBox\Purity\Documents and Settings\Owner\My Documents\ICROSO~1
C:\QooBox\Purity\Documents and Settings\Owner\My Documents\RACLE~1
C:\QooBox\Purity\Documents and Settings\Owner\My Documents\SEMBLY~1
C:\QooBox\Purity\Documents and Settings\Owner\My Documents\WNSXS~1
C:\QooBox\Purity\Documents and Settings\Owner\My Documents\SEMBLY~1\l?gonui.exe
C:\QooBox\Purity\Program Files\DOBE~1
C:\QooBox\Purity\Program Files\YSTEM3~1
C:\QooBox\Purity\Program Files\Common Files\ASEMBL~1
C:\QooBox\Purity\Program Files\Common Files\FNTS~1
C:\QooBox\Purity\Program Files\DOBE~1\DOBE~1
C:\QooBox\Purity\Program Files\DOBE~1\services.exe
C:\QooBox\Purity\WINDOWS\MCROSO~1.NET
C:\QooBox\Purity\WINDOWS\SSEMBL~1
C:\QooBox\Purity\WINDOWS\system32\CROSOF~1.NET
C:\QooBox\Purity\WINDOWS\system32\MCROSO~1.NET
C:\QooBox\Purity\WINDOWS\system32\PPATCH~1
C:\QooBox\Purity\WINDOWS\system32\RACLE~1
C:\QooBox\Purity\WINDOWS\system32\SEMBLY~1
C:\QooBox\Purity\WINDOWS\system32\CROSOF~1.NET\r?ndll32.exe


((((((((((((((((((((((((((((((( Files Created from 2006-11-12 to 2006-12-12 ))))))))))))))))))))))))))))))))))


2006-12-11 16:05 d——– C:\Program Files\BearShare applications
2006-12-11 16:05 d——– C:\Documents and Settings\Owner\Application Data\BearShare
2006-12-11 14:19 56,320 –a—— C:\WINDOWS\system32\xthnd.dll
2006-12-02 13:19 d——– C:\Program Files\MSXML 4.0
2006-12-02 13:18 d——– C:\3041ec73649ec00ea3
2006-12-01 16:03 d——– C:\Program Files\SpywareGuard
2006-12-01 15:48 dr-h—– C:\$VAULT$.AVG
2006-12-01 15:46 816,672 –a—— C:\WINDOWS\system32\drivers\avg7core.sys
2006-12-01 15:46 4,960 –a—— C:\WINDOWS\system32\drivers\avgtdi.sys
2006-12-01 15:46 4,224 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-12-01 15:46 3,968 –a—— C:\WINDOWS\system32\drivers\avgclean.sys
2006-12-01 15:46 28,416 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-12-01 15:46 18,240 –a—— C:\WINDOWS\system32\drivers\avgmfx86.sys
2006-12-01 15:46 d——– C:\Documents and Settings\Owner\Application Data\AVG7
2006-12-01 15:45 d——– C:\Program Files\Grisoft
2006-12-01 15:45 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2006-12-01 15:45 d——– C:\Documents and Settings\All Users\Application Data\avg7
2006-12-01 15:37 d——– C:\WINDOWS\Prefetch
2006-12-01 14:10 95,424 ——— C:\WINDOWS\system32\drivers\slnthal.sys
2006-12-01 14:10 9,216 ——— C:\WINDOWS\system32\proxycfg.exe
2006-12-01 14:10 88,064 ——— C:\WINDOWS\system32\p2pnetsh.dll
2006-12-01 14:10 870,784 ——— C:\WINDOWS\system32\ati3d1ag.dll
2006-12-01 14:10 86,016 ——— C:\WINDOWS\system32\p2pgasvc.dll
2006-12-01 14:10 86,016 ——— C:\WINDOWS\system32\mdmxsdk.dll
2006-12-01 14:10 81,920 ——— C:\WINDOWS\system32\ieencode.dll
2006-12-01 14:10 81,408 ——— C:\WINDOWS\system32\wscsvc.dll
2006-12-01 14:10 8,192 ——— C:\WINDOWS\system32\smbinst.exe
2006-12-01 14:10 78,464 ——— C:\WINDOWS\system32\drivers\usbvideo.sys
2006-12-01 14:10 75,776 ——— C:\WINDOWS\system32\strmfilt.dll
2006-12-01 14:10 73,832 ——— C:\WINDOWS\system32\slcoinst.dll
2006-12-01 14:10 73,796 ——— C:\WINDOWS\system32\slserv.exe
2006-12-01 14:10 73,216 ——— C:\WINDOWS\system32\drivers\atintuxx.sys
2006-12-01 14:10 71,680 ——— C:\WINDOWS\system32\blastcln.exe
2006-12-01 14:10 701,440 ——— C:\WINDOWS\system32\drivers\ati2mtag.sys
2006-12-01 14:10 7,680 ——— C:\WINDOWS\system32\kbdsmsno.dll
2006-12-01 14:10 7,680 ——— C:\WINDOWS\system32\kbdsmsfi.dll
2006-12-01 14:10 7,168 ——— C:\WINDOWS\system32\kbdukx.dll
2006-12-01 14:10 7,168 ——— C:\WINDOWS\system32\kbdno1.dll
2006-12-01 14:10 7,168 ——— C:\WINDOWS\system32\kbdfi1.dll
2006-12-01 14:10 685,056 ——— C:\WINDOWS\system32\drivers\hsfcxts2.sys
2006-12-01 14:10 67,584 ——— C:\WINDOWS\system32\drivers\sdbus.sys
2006-12-01 14:10 63,663 ——— C:\WINDOWS\system32\drivers\ati1rvxx.sys
2006-12-01 14:10 63,488 ——— C:\WINDOWS\system32\drivers\atinxsxx.sys
2006-12-01 14:10 60,416 ——— C:\WINDOWS\system32\fwcfg.dll
2006-12-01 14:10 6,656 ——— C:\WINDOWS\system32\kbdinmal.dll
2006-12-01 14:10 6,656 ——— C:\WINDOWS\system32\kbdinben.dll
2006-12-01 14:10 6,144 ——— C:\WINDOWS\system32\kbdmlt48.dll
2006-12-01 14:10 6,144 ——— C:\WINDOWS\system32\kbdmlt47.dll
2006-12-01 14:10 6,144 ——— C:\WINDOWS\system32\kbdinbe1.dll
2006-12-01 14:10 6,016 ——— C:\WINDOWS\system32\drivers\smbali.sys
2006-12-01 14:10 59,648 ——— C:\WINDOWS\system32\drivers\rfcomm.sys
2006-12-01 14:10 59,392 ——— C:\WINDOWS\system32\logman.exe
2006-12-01 14:10 57,856 ——— C:\WINDOWS\system32\drivers\atinbtxx.sys
2006-12-01 14:10 56,623 ——— C:\WINDOWS\system32\drivers\ati1btxx.sys
2006-12-01 14:10 526,848 ——— C:\WINDOWS\system32\p2psvc.dll
2006-12-01 14:10 52,224 ——— C:\WINDOWS\system32\drivers\atinraxx.sys
2006-12-01 14:10 516,768 ——— C:\WINDOWS\system32\ativvaxx.dll
2006-12-01 14:10 50,688 ——— C:\WINDOWS\system32\btpanui.dll
2006-12-01 14:10 50,176 ——— C:\WINDOWS\system32\xmlprovi.dll
2006-12-01 14:10 5,632 ——— C:\WINDOWS\system32\kbdmaori.dll
2006-12-01 14:10 49,152 ——— C:\WINDOWS\system32\powercfg.exe
2006-12-01 14:10 48,640 ——— C:\WINDOWS\system32\pnrpnsp.dll
2006-12-01 14:10 46,464 ——— C:\WINDOWS\system32\drivers\gagp30kx.sys
2006-12-01 14:10 452,736 ——— C:\WINDOWS\system32\drivers\mtxparhm.sys
2006-12-01 14:10 44,928 ——— C:\WINDOWS\system32\drivers\agpcpq.sys
2006-12-01 14:10 44,672 ——— C:\WINDOWS\system32\drivers\uagp35.sys
2006-12-01 14:10 44,032 ——— C:\WINDOWS\system32\twext.dll
2006-12-01 14:10 43,008 ——— C:\WINDOWS\system32\drivers\amdagp.sys
2006-12-01 14:10 42,752 ——— C:\WINDOWS\system32\drivers\alim1541.sys
2006-12-01 14:10 42,368 ——— C:\WINDOWS\system32\drivers\agp440.sys
2006-12-01 14:10 42,240 ——— C:\WINDOWS\system32\drivers\viaagp.sys
2006-12-01 14:10 41,088 ——— C:\WINDOWS\system32\drivers\sisagp.sys
2006-12-01 14:10 404,990 ——— C:\WINDOWS\system32\drivers\slntamr.sys
2006-12-01 14:10 4,255 ——— C:\WINDOWS\system32\drivers\adv01nt5.dll
2006-12-01 14:10 397,056 ——— C:\WINDOWS\system32\s3gnb.dll
2006-12-01 14:10 38,016 ——— C:\WINDOWS\system32\drivers\bthmodem.sys
2006-12-01 14:10 377,984 ——— C:\WINDOWS\system32\ati2dvaa.dll
2006-12-01 14:10 36,463 ——— C:\WINDOWS\system32\drivers\ati1tuxx.sys
2006-12-01 14:10 36,096 ——— C:\WINDOWS\system32\drivers\intelppm.sys
2006-12-01 14:10 35,456 ——— C:\WINDOWS\system32\drivers\bthprint.sys
2006-12-01 14:10 34,735 ——— C:\WINDOWS\system32\drivers\ati1xsxx.sys
2006-12-01 14:10 327,040 ——— C:\WINDOWS\system32\drivers\ati2mtaa.sys
2006-12-01 14:10 32,866 ——— C:\WINDOWS\system32\slrundll.exe
2006-12-01 14:10 32,866 ——— C:\WINDOWS\slrundll.exe
2006-12-01 14:10 32,768 ——— C:\WINDOWS\system32\ativtmxx.dll
2006-12-01 14:10 32,285 ——— C:\WINDOWS\system32\hsfcisp2.dll
2006-12-01 14:10 312,320 ——— C:\WINDOWS\system32\p2pgraph.dll
2006-12-01 14:10 31,744 ——— C:\WINDOWS\system32\drivers\atinxbxx.sys
2006-12-01 14:10 30,671 ——— C:\WINDOWS\system32\drivers\ati1raxx.sys
2006-12-01 14:10 30,208 ——— C:\WINDOWS\system32\bthserv.dll
2006-12-01 14:10 30,080 ——— C:\WINDOWS\system32\drivers\rndismpx.sys
2006-12-01 14:10 3,967 ——— C:\WINDOWS\system32\drivers\adv02nt5.dll
2006-12-01 14:10 3,901 ——— C:\WINDOWS\system32\drivers\siint5.dll
2006-12-01 14:10 3,775 ——— C:\WINDOWS\system32\drivers\adv11nt5.dll
2006-12-01 14:10 3,711 ——— C:\WINDOWS\system32\drivers\adv09nt5.dll
2006-12-01 14:10 3,647 ——— C:\WINDOWS\system32\drivers\adv07nt5.dll
2006-12-01 14:10 3,615 ——— C:\WINDOWS\system32\drivers\adv05nt5.dll
2006-12-01 14:10 3,135 ——— C:\WINDOWS\system32\drivers\adv08nt5.dll
2006-12-01 14:10 29,455 ——— C:\WINDOWS\system32\drivers\ati1xbxx.sys
2006-12-01 14:10 29,184 ——— C:\WINDOWS\system32\sdhcinst.dll
2006-12-01 14:10 29,056 ——— C:\WINDOWS\system32\drivers\ip6fw.sys
2006-12-01 14:10 286,792 ——— C:\WINDOWS\system32\slextspk.dll
2006-12-01 14:10 28,672 ——— C:\WINDOWS\system32\drivers\atinsnxx.sys
2006-12-01 14:10 274,304 ——— C:\WINDOWS\system32\drivers\bthport.sys
2006-12-01 14:10 262,784 ——— C:\WINDOWS\system32\drivers\http.sys
2006-12-01 14:10 26,367 ——— C:\WINDOWS\system32\drivers\ati1snxx.sys
2006-12-01 14:10 25,600 ——— C:\WINDOWS\system32\drivers\hidbth.sys
2006-12-01 14:10 25,471 ——— C:\WINDOWS\system32\drivers\watv10nt.sys
2006-12-01 14:10 25,471 ——— C:\WINDOWS\system32\drivers\atv04nt5.dll
2006-12-01 14:10 24,576 ——— C:\WINDOWS\system32\httpapi.dll
2006-12-01 14:10 23,040 –a—— C:\WINDOWS\system32\fltmc.exe
2006-12-01 14:10 229,376 ——— C:\WINDOWS\system32\ati2cqag.dll
2006-12-01 14:10 220,032 ——— C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2006-12-01 14:10 22,271 ——— C:\WINDOWS\system32\drivers\watv06nt.sys
2006-12-01 14:10 21,343 ——— C:\WINDOWS\system32\drivers\ati1ttxx.sys
2006-12-01 14:10 21,183 ——— C:\WINDOWS\system32\drivers\atv01nt5.dll
2006-12-01 14:10 201,728 ——— C:\WINDOWS\system32\ati2dvag.dll
2006-12-01 14:10 20,992 ——— C:\WINDOWS\system32\bthci.dll
2006-12-01 14:10 193,024 ——— C:\WINDOWS\system32\fsquirt.exe
2006-12-01 14:10 188,508 ——— C:\WINDOWS\system32\slgen.dll
2006-12-01 14:10 180,360 ——— C:\WINDOWS\system32\drivers\ntmtlfax.sys
2006-12-01 14:10 18,944 ——— C:\WINDOWS\system32\drivers\bthusb.sys
2006-12-01 14:10 17,408 ——— C:\WINDOWS\system32\winshfhc.dll
2006-12-01 14:10 17,279 ——— C:\WINDOWS\system32\drivers\atv10nt5.dll
2006-12-01 14:10 17,024 ——— C:\WINDOWS\system32\drivers\bthenum.sys
2006-12-01 14:10 166,912 ——— C:\WINDOWS\system32\drivers\s3gnbm.sys
2006-12-01 14:10 16,896 –a—— C:\WINDOWS\system32\fltlib.dll
2006-12-01 14:10 15,872 ——— C:\WINDOWS\system32\w3ssl.dll
2006-12-01 14:10 15,488 ——— C:\WINDOWS\system32\drivers\mssmbios.sys
2006-12-01 14:10 15,423 ——— C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2006-12-01 14:10 15,104 ——— C:\WINDOWS\system32\drivers\hidir.sys
2006-12-01 14:10 14,336 ——— C:\WINDOWS\system32\drivers\atinpdxx.sys
2006-12-01 14:10 14,336 ——— C:\WINDOWS\system32\auditusr.exe
2006-12-01 14:10 14,143 ——— C:\WINDOWS\system32\drivers\atv06nt5.dll
2006-12-01 14:10 13,824 ——— C:\WINDOWS\system32\wscntfy.exe
2006-12-01 14:10 13,824 ——— C:\WINDOWS\system32\drivers\atinttxx.sys
2006-12-01 14:10 13,824 ——— C:\WINDOWS\system32\drivers\atinmdxx.sys
2006-12-01 14:10 13,824 ——— C:\WINDOWS\system32\cmsetacl.dll
2006-12-01 14:10 13,776 ——— C:\WINDOWS\system32\drivers\recagent.sys
2006-12-01 14:10 13,568 ——— C:\WINDOWS\system32\drivers\wacompen.sys
2006-12-01 14:10 13,240 ——— C:\WINDOWS\system32\drivers\slwdmsup.sys
2006-12-01 14:10 129,536 ——— C:\WINDOWS\system32\xmlprov.dll
2006-12-01 14:10 129,535 ——— C:\WINDOWS\system32\drivers\slnt7554.sys
2006-12-01 14:10 128,896 ——— C:\WINDOWS\system32\drivers\fltmgr.sys
2006-12-01 14:10 126,686 ——— C:\WINDOWS\system32\drivers\mtlmnt5.sys
2006-12-01 14:10 12,672 ——— C:\WINDOWS\system32\drivers\usb8023x.sys
2006-12-01 14:10 12,672 ——— C:\WINDOWS\system32\drivers\mutohpen.sys
2006-12-01 14:10 12,047 ——— C:\WINDOWS\system32\drivers\ati1pdxx.sys
2006-12-01 14:10 118,784 ——— C:\WINDOWS\system32\msdadiag.dll
2006-12-01 14:10 116,224 ——— C:\WINDOWS\system32\p2p.dll
2006-12-01 14:10 11,935 ——— C:\WINDOWS\system32\drivers\wadv11nt.sys
2006-12-01 14:10 11,871 ——— C:\WINDOWS\system32\drivers\wadv09nt.sys
2006-12-01 14:10 11,868 ——— C:\WINDOWS\system32\drivers\mdmxsdk.sys
2006-12-01 14:10 11,807 ——— C:\WINDOWS\system32\drivers\wadv07nt.sys
2006-12-01 14:10 11,615 ——— C:\WINDOWS\system32\drivers\ati1mdxx.sys
2006-12-01 14:10 11,359 ——— C:\WINDOWS\system32\drivers\atv02nt5.dll
2006-12-01 14:10 11,325 ——— C:\WINDOWS\system32\drivers\vchnt5.dll
2006-12-01 14:10 11,295 ——— C:\WINDOWS\system32\drivers\wadv08nt.sys
2006-12-01 14:10 11,136 ——— C:\WINDOWS\system32\drivers\sffdisk.sys
2006-12-01 14:10 108,032 ——— C:\WINDOWS\system32\wshbth.dll
2006-12-01 14:10 104,960 ——— C:\WINDOWS\system32\drivers\atinrvxx.sys
2006-12-01 14:10 100,992 ——— C:\WINDOWS\system32\drivers\bthpan.sys
2006-12-01 14:10 10,240 ——— C:\WINDOWS\system32\drivers\sffp_sd.sys
2006-12-01 14:10 1,888,992 ——— C:\WINDOWS\system32\ati3duag.dll
2006-12-01 14:10 1,737,856 ——— C:\WINDOWS\system32\mtxparhd.dll
2006-12-01 14:10 1,309,184 ——— C:\WINDOWS\system32\drivers\mtlstrm.sys
2006-12-01 14:10 1,041,536 ——— C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2006-12-01 14:10 d——– C:\WINDOWS\provisioning
2006-12-01 14:10 d——– C:\WINDOWS\peernet
2006-12-01 14:07 d——– C:\WINDOWS\ServicePackFiles
2006-12-01 14:00 d——– C:\WINDOWS\EHome
2006-11-30 14:15 d——– C:\Program Files\SlimBrowser
2006-11-30 14:15 d——– C:\Documents and Settings\Owner\Application Data\SlimBrowser
2006-11-30 12:35 614,912 –a—— C:\WINDOWS\system32\h323msp.dll
2006-11-30 12:35 39,936 –a—— C:\WINDOWS\system32\mf3216.dll
2006-11-30 12:35 331,264 –a—— C:\WINDOWS\system32\ipnathlp.dll
2006-11-30 12:34 60,288 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2006-11-30 12:34 145,792 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2006-11-30 12:17 1,082,368 –a—— C:\WINDOWS\system32\esent.dll
2006-11-30 11:58 d——– C:\WINDOWS\system32\PreInstall
2006-11-30 11:57 d——– C:\WINDOWS\system32\bits
2006-11-30 11:56 8,192 ——— C:\WINDOWS\system32\bitsprx2.dll
2006-11-30 11:56 7,168 ——— C:\WINDOWS\system32\bitsprx3.dll
2006-11-30 11:56 351,232 –a—— C:\WINDOWS\system32\winhttp.dll
2006-11-30 11:56 18,944 –a—— C:\WINDOWS\system32\qmgrprxy.dll
2006-11-30 11:53 127,208 –a—— C:\WINDOWS\system32\mucltui.dll
2006-11-30 11:52 465,176 –a—— C:\WINDOWS\system32\wuapi.dll
2006-11-30 11:52 41,240 –a—— C:\WINDOWS\system32\wups.dll
2006-11-30 11:52 194,328 –a—— C:\WINDOWS\system32\wuaueng1.dll
2006-11-30 11:52 18,200 –a—— C:\WINDOWS\system32\wups2.dll
2006-11-30 11:52 172,312 –a—— C:\WINDOWS\system32\wuauclt1.exe
2006-11-30 11:52 127,256 –a—— C:\WINDOWS\system32\wucltui.dll
2006-11-30 09:50 d——– C:\Documents and Settings\Owner\Application Data\URSoft
2006-11-30 09:49 d——– C:\Program Files\Your Uninstaller 2006
2006-11-29 11:02 d——– C:\Program Files\Spybot - Search & Destroy
2006-11-29 10:19 d——– C:\Program Files\kmp
2006-11-29 10:09 d——– C:\Documents and Settings\Owner\Application Data\vlc
2006-11-29 10:07 d——– C:\Program Files\VideoLAN
2006-11-26 12:00 d——– C:\Program Files\OIN Search
2006-11-22 19:16 d——– C:\temp
2006-11-20 11:50 d——– C:\Documents and Settings\Owner\Application Data\àdobe
2006-11-19 23:25 d——– C:\Program Files\çasks
2006-11-14 20:26 d——– C:\Documents and Settings\Owner\Application Data\DriveCleaner 2006 Free
2006-11-14 20:16 d——– C:\Program Files\DriveCleaner 2006 Free


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-12-12 11:08 ——– d——– C:\Program Files\Common Files
2006-12-11 16:35 ——– d——– C:\Program Files\BearShare
2006-12-11 14:20 2 –a—— C:\WINDOWS\system32\wnscpsv.exe
2006-12-03 09:33 ——– d——– C:\Program Files\Windows Media Player
2006-12-03 09:33 ——– d——– C:\Program Files\Common Files\zfmr
2006-12-02 13:19 ——– d——– C:\Program Files\Messenger
2006-12-02 13:18 ——– d——– C:\Program Files\Outlook Express
2006-12-02 13:18 ——– d——– C:\Program Files\Internet Explorer
2006-12-02 13:18 ——– d——– C:\Program Files\Common Files\System
2006-12-01 17:29 ——– d—s—- C:\Documents and Settings\Owner\Application Data\Microsoft
2006-12-01 14:10 ——– d——– C:\Program Files\Movie Maker
2006-12-01 14:07 ——– d——– C:\Program Files\Windows NT
2006-12-01 14:07 ——– d——– C:\Program Files\NetMeeting
2006-11-30 12:53 ——– d——– C:\Program Files\Common Files\Microsoft Shared
2006-11-30 11:48 ——– d——– C:\Program Files\Symantec
2006-11-30 11:48 ——– d——– C:\Program Files\Common Files\Symantec Shared
2006-11-30 11:46 ——– d——– C:\Program Files\Norton AntiVirus
2006-11-30 10:46 ——– d——– C:\Program Files\Save
2006-11-30 10:44 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-11-30 10:42 ——– d——– C:\Program Files\PH Train & Assess IT
2006-11-30 10:14 ——– d——– C:\Program Files\Easy Internet signup
2006-11-30 10:13 ——– d——– C:\Program Files\BroadJump
2006-11-30 10:10 ——– d——– C:\Program Files\Creative
2006-11-30 10:01 ——– d——– C:\Program Files\interMute
2006-11-30 10:01 ——– d——– C:\Documents and Settings\Owner\Application Data\interMute
2006-11-29 11:22 ——– d——– C:\Program Files\whInstall
2006-11-29 11:22 ——– d——– C:\Program Files\Toolbar
2006-11-29 11:21 ——– d——– C:\Program Files\BulletProofSoft.com
2006-11-29 10:54 ——– d——– C:\Documents and Settings\Owner\Application Data\Yahoo!
2006-11-16 22:00 ——– d——– C:\Program Files\Sonic the Hedgehog
2006-11-16 22:00 ——– d——– C:\Program Files\Earth Worm Jim
2006-11-16 22:00 ——– d——– C:\Program Files\Aladdin
2006-11-16 21:59 ——– d——– C:\Program Files\wgens170(2)
2006-11-16 21:59 ——– d——– C:\Program Files\Snes9x
2006-11-04 14:14 1245696 –a—— C:\WINDOWS\system32\msxml4.dll
2006-11-04 05:00 115947 –a—— C:\sstray.exe
2006-10-13 07:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll
2006-10-02 15:20 21840 –a—-t- C:\WINDOWS\system32\SIntfNT.dll
2006-10-02 15:20 17212 –a—-t- C:\WINDOWS\system32\SIntf32.dll
2006-10-02 15:20 12067 –a—-t- C:\WINDOWS\system32\SIntf16.dll
2006-09-13 00:09 1110528 –a—— C:\WINDOWS\system32\msxml3.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Txhrndl"="C:\\WINDOWS\\system32\\??crosoft.NET\\r?ndll32.exe"
"Notn"="\"C:\\PROGRA~1\\DOBE~1\\services.exe\" -vt yazr"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"MSMSGS"="\"C:\\Program Files\\Messenger\\MSMSGS.EXE\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE"
"VTTimer"="VTTimer.exe"
"PS2"="C:\\WINDOWS\\system32\\ps2.exe"
"Sunkist2k"="C:\\Program Files\\Multimedia Card Reader\\shwicon2k.exe"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvMcTray.dll,NvTaskbarInit"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"AlcxMonitor"="ALCXMNTR.EXE"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,02,01,00,00,5b,00,00,00,2c,00,00,00,14,00,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{81559C35-8464-49F7-BB0E-07A383BEF910}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Gamma Loader.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma Loader"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Compaq Connections.lnk"
"backup"="C:\\WINDOWS\\pss\\Compaq Connections.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\COMPAQ~1\\1940576\\Program\\BACKWE~1.EXE -startup"
"item"="Compaq Connections"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\HP Digital Imaging Monitor.lnk"
"backup"="C:\\WINDOWS\\pss\\HP Digital Imaging Monitor.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\HP\\DIGITA~1\\bin\\hpqtra08.exe "
"item"="HP Digital Imaging Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Quicken Scheduled Updates.lnk"
"backup"="C:\\WINDOWS\\pss\\Quicken Scheduled Updates.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Quicken\\bagent.exe "
"item"="Quicken Scheduled Updates"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Windows Desktop Search.lnk"
"backup"="C:\\WINDOWS\\pss\\Windows Desktop Search.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\Program Files\\MSN Toolbar Suite\\DS\\02.01.0000.2217\\en-us\\bin\\WindowsSearch.exe /startup"
"item"="Windows Desktop Search"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\WinZip Quick Pick.lnk"
"backup"="C:\\WINDOWS\\pss\\WinZip Quick Pick.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\WinZip\\WZQKPICK.EXE "
"item"="WinZip Quick Pick"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Civilization Registration.lnk]
"path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\Civilization Registration.lnk"
"backup"="C:\\WINDOWS\\pss\\Civilization Registration.lnkStartup"
"location"="Startup"
"command"="E:\\ATR1.EXE /remind /language=ENU /PRNM=\"Civilization\"/PRMP=\"CV3C\"/SKUN=\"PCXX\"/GTYP=\"STRY\""
"item"="Civilization Registration"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk]
"path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\spamsubtract.lnk"
"backup"="C:\\WINDOWS\\pss\\spamsubtract.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\INTERM~1\\SPAMSU~1\\SpamSub.exe -q"
"item"="spamsubtract"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ALCXMNTR"
"hkey"="HKLM"
"command"="ALCXMNTR.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BearShare"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\BearShare\\BearShare.exe\" /pause"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CFD"
"hkey"="HKLM"
"command"="C:\\Program Files\\BroadJump\\Client Foundation\\CFD.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hpztsb08"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb08.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hphmon05"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\hphmon05.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hphupd05"
"hkey"="HKLM"
"command"="c:\\Program Files\\HP\\{45B6180B-DCAB-4093-8EE8-6164457517F0}\\hphupd05.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hpsysdrv"
"hkey"="HKLM"
"command"="c:\\windows\\system\\hpsysdrv.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IpWins]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ipwins"
"hkey"="HKLM"
"command"="C:\\Program Files\\ipwins\\ipwins.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="KBD"
"hkey"="HKLM"
"command"="C:\\HP\\KBD\\KBD.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTMSG]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="LTMSG"
"hkey"="HKLM"
"command"="LTMSG.exe 7"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsgCenterExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RealOneMessageCenter"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\RealOneMessageCenter.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Notn]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="services"
"hkey"="HKCU"
"command"="\"C:\\PROGRA~1\\DOBE~1\\services.exe\" -vt yazr"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvCpl"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\outlook]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="outlook"
"hkey"="HKLM"
"command"="C:\\Program Files\\outlook\\outlook.exe /auto"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecordNow!]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sgtray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Save"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Save\\Save.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="YahooMessenger"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"inimapping"="0"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\c_8dsw
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winzdn32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job
C:\WINDOWS\tasks\WebReg 20051214014134.job

Completion time: 06-12-12 11:10:05.82
C:\ComboFix.txt … 06-12-12 11:10

——————————————————————-


Logfile of HijackThis v1.99.1
Scan saved at 11:13:32 AM, on 12/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {1521A0D6-6F42-17B7-4496-36918BD38BB7} - C:\WINDOWS\System32\avrj.dll (file missing)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
R3 - URLSearchHook: (no name) - {B77FB00A-7FCC-5C35-9EDB-2250D7F625BD} - C:\WINDOWS\system32\xefwt.dll (file missing)
R3 - URLSearchHook: (no name) - {D05379EF-E92B-C084-7E35-ECECACE115BB} - C:\WINDOWS\system32\hbxrwiiz.dll (file missing)
R3 - URLSearchHook: (no name) - {98E18B49-1ED4-627D-875F-1A73153A00EF} - C:\WINDOWS\system32\jzxk.dll (file missing)
R3 - URLSearchHook: (no name) - {C8E6DE46-1E83-647A-835F-1A73153A03EA} - C:\WINDOWS\system32\avv.dll (file missing)
R3 - URLSearchHook: (no name) - {FCD855BE-9375-B1D8-2C20-9D5B272964E7} - C:\WINDOWS\system32\xthnd.dll
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1521A0D6-6F42-17B7-4496-36918BD38BB7} - C:\WINDOWS\System32\avrj.dll (file missing)
O2 - BHO: (no name) - {1ee03ad2-9421-48b8-a605-1abe23513ec0} - C:\WINDOWS\system32\c_8dsw.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {78B604B6-9872-B1DE-7D20-CDCE1FECE8E5} - C:\WINDOWS\System32\waad.dll (file missing)
O2 - BHO: (no name) - {98E18B49-1ED4-627D-875F-1A73153A00EF} - C:\WINDOWS\system32\jzxk.dll (file missing)
O2 - BHO: (no name) - {F56B3F1A-FDDB-8779-DEDF-A228907263E9} - C:\WINDOWS\System32\vztgt.dll (file missing)
O2 - BHO: (no name) - {FCD855BE-9375-B1D8-2C20-9D5B272964E7} - C:\WINDOWS\system32\xthnd.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Txhrndl] C:\WINDOWS\system32\??crosoft.NET\r?ndll32.exe
O4 - HKCU\..\Run: [Notn] "C:\PROGRA~1\DOBE~1\services.exe" -vt yazr
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/2549e5097f66ec…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164905465328
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164905459765
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: c_8dsw - C:\WINDOWS\SYSTEM32\c_8dsw.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: winzdn32 - winzdn32.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Download VundoFix.exe to your desktop from here:

VundoFix.exe

DON'T RUN IT YET.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R3 - URLSearchHook: (no name) - {1521A0D6-6F42-17B7-4496-36918BD38BB7} - C:\WINDOWS\System32\avrj.dll (file missing)

R3 - URLSearchHook: (no name) - {B77FB00A-7FCC-5C35-9EDB-2250D7F625BD} - C:\WINDOWS\system32\xefwt.dll (file missing)

R3 - URLSearchHook: (no name) - {D05379EF-E92B-C084-7E35-ECECACE115BB} - C:\WINDOWS\system32\hbxrwiiz.dll (file missing)

R3 - URLSearchHook: (no name) - {98E18B49-1ED4-627D-875F-1A73153A00EF} - C:\WINDOWS\system32\jzxk.dll (file missing)

R3 - URLSearchHook: (no name) - {C8E6DE46-1E83-647A-835F-1A73153A03EA} - C:\WINDOWS\system32\avv.dll (file missing)

R3 - URLSearchHook: (no name) - {FCD855BE-9375-B1D8-2C20-9D5B272964E7} - C:\WINDOWS\system32\xthnd.dll

O2 - BHO: (no name) - {1521A0D6-6F42-17B7-4496-36918BD38BB7} - C:\WINDOWS\System32\avrj.dll (file missing)

O2 - BHO: (no name) - {1ee03ad2-9421-48b8-a605-1abe23513ec0} - C:\WINDOWS\system32\c_8dsw.dll

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

O2 - BHO: (no name) - {78B604B6-9872-B1DE-7D20-CDCE1FECE8E5} - C:\WINDOWS\System32\waad.dll (file missing)

O2 - BHO: (no name) - {98E18B49-1ED4-627D-875F-1A73153A00EF} - C:\WINDOWS\system32\jzxk.dll (file missing)

O2 - BHO: (no name) - {F56B3F1A-FDDB-8779-DEDF-A228907263E9} - C:\WINDOWS\System32\vztgt.dll (file missing)

O2 - BHO: (no name) - {FCD855BE-9375-B1D8-2C20-9D5B272964E7} - C:\WINDOWS\system32\xthnd.dll

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

O4 - HKCU\..\Run: [Txhrndl] C:\WINDOWS\system32\??crosoft.NET\r?ndll32.exe

O4 - HKCU\..\Run: [Notn] "C:\PROGRA~1\DOBE~1\services.exe" -vt yazr

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/2549e5097f66ec…ip/RdxIE601.cab

O20 - Winlogon Notify: c_8dsw - C:\WINDOWS\SYSTEM32\c_8dsw.dll

O20 - Winlogon Notify: winzdn32 - winzdn32.dll (file missing)

Then click "Fix checked" and close Hijack This!.

1. Double-click VundoFix.exe to run it.
2. Click the Scan for Vundo button.
3. Once it's done scanning, click the Remove Vundo button.
4. If it doesn't find anything, in the main program window, choose "Add more files?".
Type the next line into the box EXACTLY AS SHOWN:

C:\WINDOWS\SYSTEM32\c_8dsw.dll

Click Close Window, then Remove Vundo.

5. You will receive a prompt asking if you want to remove the files, click YES.
6. Once you click yes, your desktop will go blank as it starts removing Vundo.
7. When completed, it will prompt that it will shutdown your computer, click OK.
8. Turn your computer back on.

Post a new HijackThis! log, along with the contents of this file:

C:\vundofix.txt


into this thread.
:)
Logfile of HijackThis v1.99.1
Scan saved at 2:34:21 PM, on 12/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\ps2.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1ee03ad2-9421-48b8-a605-1abe23513ec0} - C:\WINDOWS\system32\c_8dsw.dll (file missing)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: XBTP01621 - {9EBBE90B-282E-4c39-8A7E-120749169F0F} - C:\PROGRA~1\BEA878~1\MediaBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O3 - Toolbar: BearShare MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\BearShare MediaBar\MediaBar.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164905465328
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164905459765
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

——————————————————————————-


VundoFix V6.2.13

Checking Java version…

Java version is 1.4.2.3

Java version is 1.5.0.3

Java version is 1.5.0.8

Scan started at 2:17:03 PM 12/13/2006

Listing files found while scanning….

No infected files were found.


Beginning removal…

Beginning removal…

Attempting to delete C:\WINDOWS\SYSTEM32\c_8dsw.dll
C:\WINDOWS\SYSTEM32\c_8dsw.dll Has been deleted!

Performing Repairs to the registry.
Done!
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: (no name) - {1ee03ad2-9421-48b8-a605-1abe23513ec0} - C:\WINDOWS\system32\c_8dsw.dll (file missing)

Then click "Fix checked" and close Hijack This!.

Reboot and "copy/paste" a new HijackThis! log file into this thread.

Also, please do this:

Run HijackThis!

Click the "Open the Misc Tools" section Button.

Click the "Open Uninstall Manager" Button.

Click the "Save list…" Button.

Save it to your desktop. Copy and paste the contents into your next reply.

I'm looking to see if you can "uninstall" the "Bearshare Mediabar".

If not, we'll have to remove it another way.

Is the PC performing better for you now?
:unsure:

Please read:
Securing Your PC After An Attack
Logfile of HijackThis v1.99.1
Scan saved at 5:33:33 PM, on 12/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: XBTP01621 - {9EBBE90B-282E-4c39-8A7E-120749169F0F} - C:\PROGRA~1\BEA878~1\MediaBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O3 - Toolbar: BearShare MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\BearShare MediaBar\MediaBar.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164905465328
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164905459765
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

——————————————————————–


Adobe Flash Player 9 ActiveX
Adobe Photoshop Album Starter Edition
Adobe Reader 6.0
Ahead Nero Burning ROM
Ahead NeroVision Express
ArcSoft PhotoImpression
AVG 7.5
BearShare
BearShare MediaBar
Compaq Instant Support
Compaq Organize
Creative WebCam Center
Creative WebCam Instant Driver (1.00.08.0416)
Creative WebCam Instant User's Guide (English)
DreamStation DXi2
DVC301
Game Elements PC Recoil Pad
GameSpy Arcade
GTAIII
HijackThis 1.99.1
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
hp deskjet 5100
HP Deskjet Preloaded Printer Drivers
HP Image Zone 3.5
HP Photo & Imaging 3.5 - HP Devices
HP PSC & OfficeJet 3.0
HP Software Update
InterVideo WinDVD Creator 2
InterVideo WinDVD Player
Java 2 Runtime Environment, SE v1.4.2_03
KBD
LiveUpdate 1.90 (Symantec Corporation)
Memories Disc Creator 2.0
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Works 7.0
MSN Messenger 7.5
MSXML 4.0 SP2 (KB927978)
Multimedia Card Reader
NVIDIA Drivers
PC-Doctor for Windows
Photosmart 140,240,7200,7600,7700,7900 Series
PS2
Python 2.2 combined Win32 extensions
Python 2.2.1
Quicken 2004
Rhapsody Player Engine
S3 S3Display
S3 S3Gamma2
S3 S3Info2
S3 S3Overlay
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB925486)
SlimBrowser (remove only)
Spybot - Search & Destroy 1.4
SpywareGuard v2.2
The Sims Makin' Magic
Ultimate Spider-Man ™
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
VIA Rhine-Family Fast Ethernet Adapter
VIA/S3G Display Driver
VideoLAN VLC media player 0.8.5
Viewpoint Media Player (Remove Only)
Virtual Sound Canvas DXi
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
X-Men™ Legends 2
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Toolbar
Your Uninstaller! 2006 Version 5
Zone Deluxe Games

——————————————————–

Micah, the PC is performing SOOOO much better now thanks to you. Thanks for the BearShare help too btw, I'm in the process of trying to teach my son about BitTorrent—–BearShare is all he knows unfortunately.
Go to:

Start –> Control Panel –> Add/Remove Programs

Remove BearShare MediaBar.

Reboot and post a new HijackThis! log.

Be very, very, careful with "Peer to peer" file sharing….

Many times you get more than you bargained for.
;)
Logfile of HijackThis v1.99.1
Scan saved at 4:23:07 PM, on 12/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Documents and Settings\Owner\Desktop\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn6\yt.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164905465328
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164905459765
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll

O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll

Then click "Fix checked" and close Hijack This!.

Reboot.

That should do it.

Thank you for choosing TomCoyote for your malware removal solutions.

M68 :)

Securing Your PC After An Attack

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI