This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

slow =google redirect

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 9:16:15 PM, on 12/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\hj\HijackThis.exe

O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{731213EC-EE40-47C5-AE19-2E05AD96B232}: NameServer = 85.255.113.132,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\..\{8598F7E3-4720-468C-BE48-FDC973561652}: NameServer = 85.255.113.132,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\..\{A227BE2F-3DD2-49C9-9DCA-691BB39F3739}: NameServer = 85.255.113.132,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\..\{B0DEA1E6-89C6-4252-B606-C91FD6743626}: NameServer = 85.255.113.132,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC986685-8A3C-4BCE-876C-C65ABAEF6689}: NameServer = 85.255.113.132,85.255.112.133
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.132 85.255.112.133
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.132 85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.132 85.255.112.133
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe


———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 12:04:05 AM 12/6/2006

+ Scan result:



[200] VM_00D70000 -> Downloader.Zlob.aty : Cleaned with backup (quarantined).
[224] VM_00C20000 -> Downloader.Zlob.aty : Cleaned with backup (quarantined).
[892] VM_00B40000 -> Downloader.Zlob.aty : Cleaned with backup (quarantined).
C:\Documents and Settings\Jodi Ferrell\Cookies\jodi ferrell@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Jodi Ferrell\Cookies\jodi [removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Jodi Ferrell\Cookies\jodi ferrell@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.


::Report end
Hello Fatman and Welcome to TomCoyote,

You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

At the end of the fix, you may need to restart your computer again.


Disable Microsoft Windows Defender:
We need to disable your Microsoft Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.
  • Open Microsoft Windows Defender. Click Start, Programs, Windows Defender
  • Click on Tools, General Settings.
  • Under Real-time protection options, unselect the Turn on real-time protection check box
  • Click Save
After all of the fixes are complete it is very important that you enable Real-time Protection again.

Updating Java
  • Download the latest version of Java Runtime Environment (JRE) 5.0 Update 10.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-1_5_0_10-windowsi586-p.exe to install the newest version.
Scan with HijackThis. Place a check against each of the following:
O17 - HKLM\System\CCS\Services\Tcpip\..\{731213EC-EE40-47C5-AE19-2E05AD96B232}: NameServer = 85.255.113.132,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\..\{8598F7E3-4720-468C-BE48-FDC973561652}: NameServer = 85.255.113.132,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\..\{A227BE2F-3DD2-49C9-9DCA-691BB39F3739}: NameServer = 85.255.113.132,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\..\{B0DEA1E6-89C6-4252-B606-C91FD6743626}: NameServer = 85.255.113.132,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC986685-8A3C-4BCE-876C-C65ABAEF6689}: NameServer = 85.255.113.132,85.255.112.133
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.132 85.255.112.133
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.132 85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.132 85.255.112.133

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Finally, please post a fresh HijackThis log, along with the contents of the logfile C:\fixwareout\report.txt
Thanks for the reply. I couldn't download the Java update. My downloader would freeze about half way through while saving the file jre-1_5_0_10-windowsi586-p.exe. I didn't delete other instances of Java because this download failed.

Logfile of HijackThis v1.99.1
Scan saved at 8:37:04 PM, on 12/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\hj\scannme.exe

O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe



Fixwareout
Last edited 12/06/2006
Post this report in the forums please

Reg Entries that were deleted
…

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
…

PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

»»»»» Searching by size/names…

»»»»»
Search five digit cs, dm kd and jb files.
This WILL/CAN also list Legit Files, Submit them at Virustotal

Other suspects.
Directory of C:\WINDOWS\system32

»»»»» Misc files.

»»»»» Checking for older varients covered by the Rem3 tool.

Thanks,
Fatman
======
Combofix
  • Download this file - combofix.exe
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Please post the ComboFix log and a new hijackthis log.
Combo Fix ran. Note: I still have downloader.zlob.aty. Latest avg scan report attached also. Thanks, Fatman Jodi - 06-12-08 6:31:25.87 Service Pack 2 ComboFix 06.11.27W - Running from: "C:\Documents and Settings\Jodi.DFTH9G41\Desktop" ((((((((((((((((((((((((((((((( Files Created from 2006-11-08 to 2006-12-08 )))))))))))))))))))))))))))))))))) 2006-12-07 20:48 d——– C:\Documents and Settings\Jodi.DFTH9G41\.SunDownloadManager 2006-12-07 19:15 d——– C:\fixwareout 2006-12-06 23:20 d——– C:\VundoFix Backups 2006-12-06 22:55 d——– C:\WINDOWS\SYSTEM32\ActiveScan 2006-12-05 22:38 3,968 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys 2006-12-05 22:38 d——– C:\Program Files\Grisoft 2006-12-04 23:11 d——– C:\hj 2006-12-03 21:47 d——– C:\Program Files\Windows Defender 2006-11-18 06:37 d——– C:\Program Files\MSXML 4.0 2006-11-18 06:36 d——– C:\7bcac2365455bd935491e982 2006-11-17 21:55 684,032 –a—— C:\WINDOWS\SYSTEM32\libeay32.dll 2006-11-17 21:55 155,648 –a—— C:\WINDOWS\SYSTEM32\ssleay32.dll 2006-11-15 23:10 d——– C:\Documents and Settings\Jodi.DFTH9G41\Application Data\Mozilla 2006-11-15 23:09 d——– C:\Program Files\Mozilla Firefox 2006-11-13 22:24 d——– C:\WINDOWS\WBEM 2006-11-13 22:24 d——– C:\WINDOWS\SYSTEM32\en-US 2006-11-13 22:22 d–h-c— C:\WINDOWS\ie7 2006-11-13 22:21 121,856 ——— C:\WINDOWS\SYSTEM32\xmllite.dll 2006-11-13 22:21 d——– C:\WINDOWS\network diagnostic (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-12-07 22:45 ——– d——– C:\Program Files\SwiftView 2006-12-07 22:38 ——– d——– C:\Program Files\Common Files 2006-12-07 22:36 ——– d——– C:\Program Files\Java 2006-12-07 22:33 ——– d——– C:\Program Files\PacificPoker 2006-12-03 21:47 ——– d——– C:\Program Files\Common Files\Microsoft Shared 2006-11-26 21:04 33280 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avgntdd.sys 2006-11-13 22:26 ——– d——– C:\Program Files\Internet Explorer 2006-11-04 14:14 1245696 –a—— C:\WINDOWS\SYSTEM32\msxml4.dll 2006-10-27 15:09 6049280 ——— C:\WINDOWS\SYSTEM32\ieframe.dll 2006-10-27 15:09 50688 ——— C:\WINDOWS\SYSTEM32\msfeedsbs.dll 2006-10-27 15:09 458752 ——— C:\WINDOWS\SYSTEM32\msfeeds.dll 2006-10-27 15:09 413696 –a—— C:\WINDOWS\SYSTEM32\vbscript.dll 2006-10-27 15:09 231424 –a—— C:\WINDOWS\SYSTEM32\webcheck.dll 2006-10-27 15:09 180736 ——— C:\WINDOWS\SYSTEM32\ieui.dll 2006-10-27 15:09 156160 –a—— C:\WINDOWS\SYSTEM32\msls31.dll 2006-10-27 02:44 71680 –a—— C:\WINDOWS\SYSTEM32\admparse.dll 2006-10-27 02:44 55296 –a—— C:\WINDOWS\SYSTEM32\iesetup.dll 2006-10-27 02:44 54784 –a—— C:\WINDOWS\SYSTEM32\ie4uinit.exe 2006-10-27 02:44 43008 –a—— C:\WINDOWS\SYSTEM32\iernonce.dll 2006-10-27 02:44 382976 –a—— C:\WINDOWS\SYSTEM32\iedkcs32.dll 2006-10-27 02:44 229376 –a—— C:\WINDOWS\SYSTEM32\ieaksie.dll 2006-10-27 02:44 152064 –a—— C:\WINDOWS\SYSTEM32\ieakeng.dll 2006-10-27 02:44 13312 –a—— C:\WINDOWS\SYSTEM32\ieudinit.exe 2006-10-27 02:44 123904 –a—— C:\WINDOWS\SYSTEM32\advpack.dll 2006-10-27 02:42 161792 –a—— C:\WINDOWS\SYSTEM32\ieakui.dll 2006-10-22 12:26 ——– d——– C:\Program Files\AntiVir PersonalEdition Classic 2006-10-17 13:06 78336 –a—— C:\WINDOWS\SYSTEM32\ieencode.dll 2006-10-17 13:05 40960 –a—— C:\WINDOWS\SYSTEM32\licmgr10.dll 2006-10-17 13:05 206336 ——— C:\WINDOWS\SYSTEM32\WinFXDocObj.exe 2006-10-17 13:05 105984 –a—— C:\WINDOWS\SYSTEM32\url.dll 2006-10-17 13:04 101376 –a—— C:\WINDOWS\SYSTEM32\occache.dll 2006-10-17 13:03 17408 –a—— C:\WINDOWS\SYSTEM32\corpol.dll 2006-10-17 12:58 61952 ——— C:\WINDOWS\SYSTEM32\icardie.dll 2006-10-17 12:58 12288 ——— C:\WINDOWS\SYSTEM32\msfeedssync.exe 2006-10-17 12:57 36352 –a—— C:\WINDOWS\SYSTEM32\imgutil.dll 2006-10-17 12:57 266752 ——— C:\WINDOWS\SYSTEM32\iertutil.dll 2006-10-17 12:56 45568 –a—— C:\WINDOWS\SYSTEM32\mshta.exe 2006-10-17 12:28 48128 –a—— C:\WINDOWS\SYSTEM32\mshtmler.dll 2006-10-17 12:27 380928 ——— C:\WINDOWS\SYSTEM32\ieapfltr.dll 2006-10-13 04:35 65536 –a—— C:\WINDOWS\SYSTEM32\nwwks.dll 2006-10-13 04:35 64000 –a—— C:\WINDOWS\SYSTEM32\nwapi32.dll 2006-10-13 04:35 142336 –a—— C:\WINDOWS\SYSTEM32\nwprovau.dll 2006-10-13 02:23 163584 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\nwrdr.sys 2006-09-12 21:01 1084416 –a—— C:\WINDOWS\SYSTEM32\msxml3.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "Sonic RecordNow!"="" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "ATIModeChange"="Ati2mdxx.exe" "SynTPLpr"="\"C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe\"" "SynTPEnh"="\"C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe\"" "ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\"" "DVDSentry"="C:\\WINDOWS\\System32\\DSentry.exe" "avgnt"="\"C:\\Program Files\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min" "Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide" "!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,e8,00,00,00,00,00,00,00,18,04,00,00,da,03,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 "RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\ 00,00,01,00,00,00 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\MP Scheduled Scan.job Completion time: 06-12-08 6:32:11.77 C:\ComboFix.txt … 06-12-08 06:32 C:\ComboFix2.txt … 06-12-07 22:25 C:\ComboFix3.txt … 06-12-06 23:16 ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 10:17:09 PM 12/7/2006 + Scan result: C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP400\A0071769.exe -> Downloader.Zlob.aty : Cleaned. C:\Documents and Settings\Jodi.DFTH9G41\Cookies\jodi@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Jodi.DFTH9G41\Cookies\jodi@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Jodi.DFTH9G41\Cookies\jodi@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned. ::Report end
Please do the following:

STEP 1.
======
Look2Me

You have the latest version of VX2. Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

You may receive pop-up asking if you will allow script to run when you perform the following instructions. Please allow the script to run.

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy and save the contents of that log so you can paste it into your next reply.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

If you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application.."…then please use option 5 or the web page link in the l2mfix folder to solve this error condition. do not run the fix portion without fixing this first.


STEP 2.
======
GMER
Please create a new subfolder in the Program Files folder called GMER. If you have an older version of GMER installed, you must delete it.
  • Download GMER and extract it to the C:\program files\GMER folder.
  • Please rename the GMER file
    Note: You can rename gmer.exe to anything you like as long as you keep the .exe ending.
    Run the Gmer.exerenamed program by double-clicking the executable file (gmer.exe) in Windows Explorer.
    You may be prompted to scan immediately if GMER detects rootkit activity.
  • If you are prompted to scan your system click "yes" to begin the scan.
  • If you are not prompted, Click the "Rootkit" tab, then click "Scan".
At the end of the scan, click "Copy" to copy the scan results to the clipboard. Then paste the results in a notepad file and also paste them back in a reply here.

Please post (reply) with the results from the l2mfix report, the GMER scan, and a fresh hijackthis log.
Scans requested are attached. Wish I knew what they meant.
Thanks,
Fatman

LOOK2ME
L2MFIX find log 032106
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
"Logon"="WLEventLogon"
"Logoff"="WLEventLogoff"
"Startup"="WLEventStartup"
"Shutdown"="WLEventShutdown"
"StartScreenSaver"="WLEventStartScreenSaver"
"StopScreenSaver"="WLEventStopScreenSaver"
"Lock"="WLEventLock"
"Unlock"="WLEventUnlock"
"StartShell"="WLEventStartShell"
"PostShell"="WLEventPostShell"
"Disconnect"="WLEventDisconnect"
"Reconnect"="WLEventReconnect"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000000
"SafeMode"=dword:00000001
"MaxWait"=dword:ffffffff
"DllName"=hex(2):57,00,67,00,61,00,4c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Event"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings]
"Data"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,\
00,00,6b,61,c3,b0,33,92,6e,4f,ab,5e,63,18,e8,bf,ca,d5,04,00,00,00,04,00,00,\
00,53,00,00,00,03,66,00,00,a8,00,00,00,10,00,00,00,32,27,93,70,3f,68,55,83,\
33,82,4a,4c,78,7b,64,dd,00,00,00,00,04,80,00,00,a0,00,00,00,10,00,00,00,da,\
0a,fc,0b,61,99,fd,dc,d9,f9,fa,2f,74,aa,ed,42,08,06,00,00,f5,b5,a8,8e,3d,d3,\
bc,3b,ee,f4,78,b1,1c,fc,67,e0,6b,ce,e5,03,6d,47,38,c3,ca,b7,7d,d9,ec,f0,ee,\
8d,94,eb,65,f6,fe,94,26,ab,fb,22,28,f3,fc,dd,11,e7,b4,1d,64,76,12,0e,33,6e,\
12,18,8a,a4,95,0f,93,a5,9d,c2,ff,a9,b3,46,59,6a,c8,b6,7b,ef,5f,94,be,d3,8e,\
af,cd,f9,04,4b,c2,8e,0e,20,c9,95,89,73,e9,3f,ef,5c,e7,8b,29,fd,d9,7c,71,94,\
29,1f,01,ac,76,f9,f3,d6,c9,90,c0,4d,77,f5,77,73,ee,30,58,49,f3,ad,13,3d,b9,\
90,ea,37,2a,b7,fb,60,d0,f5,b2,49,bb,55,08,57,8c,ec,65,aa,44,a4,05,b1,5a,69,\
56,85,4b,b6,8d,7e,df,6c,6e,24,b2,dd,5b,8c,07,33,ec,9a,73,6b,16,04,cc,4f,d2,\
fd,cb,c6,85,dd,82,2c,fc,c3,54,1c,bd,5d,22,97,dd,f7,b9,cf,12,16,ed,00,e2,33,\
fe,e6,57,24,4c,4a,e5,7b,1c,16,3b,41,5f,3b,b1,dc,5c,7f,ad,b3,82,5b,25,d0,60,\
72,a3,c5,f3,e2,71,5d,2e,bb,d4,ef,f3,85,b6,bc,87,46,54,d0,34,83,82,49,5a,43,\
8b,87,9e,0a,28,40,86,86,1b,da,2d,e3,dc,97,3e,23,5a,ce,81,2c,11,9c,78,d8,93,\
c0,b0,24,1c,43,fa,50,ba,b0,2f,a1,72,a5,ac,7b,54,48,70,52,7a,c3,97,71,2d,b3,\
a8,d5,f6,89,db,bd,4b,e3,c0,00,15,e6,24,c0,95,75,3a,a1,48,db,b0,4d,20,d5,5c,\
4b,73,29,e8,5e,2c,70,8b,b8,45,11,ca,3c,a1,be,c4,76,ec,f8,37,09,e5,64,72,af,\
c2,e0,3c,e0,0c,df,a1,f6,02,ac,4f,25,76,a7,bc,61,4f,3e,6d,b9,99,85,7e,b4,55,\
e7,76,16,9c,fb,13,51,03,e1,ae,88,83,fb,45,9d,a3,8d,2d,8e,33,47,34,b0,2a,a4,\
a6,a2,f9,fe,2d,1c,87,21,bf,24,6b,54,93,91,fc,f3,05,03,24,96,fc,5c,7e,b8,49,\
a9,4c,5e,f1,a8,06,66,6b,40,71,29,6f,4c,77,cc,d1,5b,44,4c,f2,8d,3c,42,82,62,\
0c,d0,68,98,38,ea,c3,e2,40,c6,a9,3f,e1,0a,15,3d,a4,10,8d,cf,29,e7,44,4c,20,\
f9,76,47,1b,7d,f0,c0,29,62,20,ad,a6,70,e8,e3,e8,aa,2f,f8,21,02,8f,b4,24,d9,\
a8,37,44,3f,f8,d2,22,c4,4e,a3,bc,05,84,de,cd,42,64,bb,e4,c3,fb,3f,e4,1f,02,\
57,db,37,9c,85,7f,b1,11,c4,23,e4,45,00,5a,eb,fc,85,29,e8,50,23,58,ff,01,0f,\
20,6c,c7,9b,6d,23,75,40,65,fa,8e,17,cb,04,04,77,99,11,6c,71,fb,99,61,56,14,\
09,5d,77,11,d0,3c,00,ab,05,5f,84,4f,13,2f,07,27,0d,b3,74,d0,8f,44,51,33,de,\
54,7e,e1,22,75,bc,88,6a,aa,57,97,9c,21,d2,5d,46,da,d7,78,42,7a,63,36,8c,3b,\
b9,d0,3c,5b,0e,cf,15,86,46,27,87,7e,d8,c7,be,ce,c6,8f,3b,ca,40,8d,98,dd,f4,\
8e,8c,31,1f,28,a7,58,a6,e9,9f,71,08,8c,3e,90,1f,40,2a,14,a5,a5,cd,72,6e,74,\
c6,3f,99,6d,2d,cf,69,3a,ed,6f,e4,0a,e6,d7,a9,f4,8d,c2,5e,d3,c9,e4,b9,15,91,\
4d,40,cc,bb,8c,79,9d,e4,2f,42,d3,8a,5c,7d,07,1a,fe,54,c9,c3,0b,7a,cb,86,72,\
03,2b,07,5e,a0,b5,a2,b2,61,7a,36,97,27,34,df,23,0c,b8,8d,77,eb,24,b3,a5,d8,\
6d,57,9d,d9,65,23,56,7f,12,88,26,29,86,49,e9,1a,c0,26,d4,c5,8b,ed,34,76,80,\
2f,d5,82,df,3d,13,36,63,41,82,a3,f4,1b,15,75,14,82,50,6d,f5,fd,41,5d,9e,9e,\
2c,99,96,ee,e7,1e,a1,58,03,ee,0a,d8,63,f3,d4,f0,64,e7,e2,40,cd,1b,7b,17,f8,\
a7,ca,5c,8e,30,ff,7e,8c,2f,d1,78,18,2c,56,6b,c0,5a,ca,87,f4,07,ae,99,2e,c6,\
db,7a,8a,60,ed,df,37,0d,a0,ff,a7,b1,61,50,88,97,7d,52,43,94,de,d2,c4,0c,f2,\
ba,51,96,44,ff,78,8c,76,57,0e,28,c4,ed,76,ee,f4,28,dd,eb,8f,8f,43,03,f2,b3,\
88,a1,4e,8f,5c,c0,43,52,e7,8e,e4,3f,1b,57,59,3b,01,70,d2,61,6f,35,f8,6a,70,\
bc,fa,ba,73,84,83,dd,e2,a5,05,ec,3a,ee,4e,3d,f2,44,16,d9,79,09,a5,8f,c4,d6,\
d4,e9,d5,b3,0e,12,40,25,82,4a,ed,f0,7d,f2,0e,76,73,e6,5a,c6,7a,52,b3,57,7a,\
fc,9e,6b,09,21,f7,b4,6c,f2,6d,7c,e5,99,59,08,ec,e5,8a,83,a5,a3,21,f6,9c,a6,\
cf,48,4f,f3,99,1b,5b,8a,96,50,5c,b9,a8,0f,9e,6b,d9,9c,35,56,ae,88,09,d2,81,\
0f,cb,e4,ed,e1,0e,9a,af,3a,5c,41,f0,ce,24,91,97,15,98,a5,ce,87,ca,23,0d,ea,\
16,ea,7c,47,3e,8b,db,ff,7d,53,16,ba,0b,b1,ad,eb,2a,1c,0a,7b,e1,da,9e,07,7c,\
86,82,38,f2,25,aa,39,0f,9a,26,e3,af,b1,bc,fb,6d,74,17,03,20,57,98,4f,83,80,\
76,ca,bb,08,67,cb,4a,2a,5c,69,97,d3,3e,6c,30,81,1f,82,3b,6b,89,a9,7d,5a,63,\
03,86,14,81,fe,df,8c,3e,41,a7,6a,72,58,30,37,dd,51,e7,64,67,2e,13,b4,03,19,\
f3,1b,0d,03,ed,8f,5a,5a,2a,11,65,28,0e,03,14,90,8c,5c,de,88,cd,15,c0,8b,55,\
ad,13,6a,4f,98,ed,46,31,9f,ae,2b,d1,bb,ef,52,1f,d4,59,50,c8,4f,49,80,48,80,\
f7,90,b0,e0,c3,bc,7e,41,f2,80,4f,eb,2d,fb,52,3c,8e,b7,ad,8b,43,68,e7,77,7a,\
8b,5c,fe,eb,ed,86,ea,ce,e0,59,2e,c7,1b,8f,03,8b,33,e5,5c,ad,d7,8f,b6,c2,30,\
9d,bb,bd,39,2b,38,79,d0,93,4e,8f,17,29,df,7a,0e,c1,15,d3,4d,3d,61,d7,f5,ab,\
e6,da,26,91,6d,d9,09,35,79,c0,32,32,ce,ab,7e,12,44,36,85,e6,f7,58,87,da,89,\
7b,8e,15,97,f1,ba,da,46,5c,41,ec,28,7c,4c,65,ad,21,63,6f,bc,20,8d,3a,71,13,\
77,b9,ed,04,76,3a,f5,85,3c,92,bd,84,90,58,19,ca,6f,11,f2,42,a8,03,3a,8b,c4,\
e3,76,3c,e7,7f,b0,bc,66,8c,4e,c7,b2,78,76,2d,0e,83,16,b1,c7,9d,10,cd,e5,a1,\
01,0d,0d,7f,ad,e2,e3,5e,a8,0f,cb,6a,33,34,0d,a3,e2,ec,7f,25,27,60,d9,e0,6f,\
30,a9,41,45,e7,bf,c5,99,48,07,a4,cc,9d,1c,9e,08,58,ff,01,76,ad,66,f3,47,41,\
4f,2f,f0,ff,96,f9,87,65,36,60,9d,35,e8,29,e8,d0,51,73,f5,ca,1f,d9,1b,57,eb,\
cf,6c,1e,2d,bd,0f,c8,7c,b2,c9,7f,2f,20,69,1a,64,42,bb,8b,46,0b,79,f8,d5,9e,\
bd,c4,1d,6b,dd,2c,ce,7c,68,97,55,0c,b1,f5,04,7d,ac,58,00,34,91,85,4a,b0,44,\
5c,b7,6f,85,2d,35,5a,e5,d9,b2,4c,da,36,95,ca,e6,cc,32,28,8f,af,fc,27,20,81,\
e7,de,a5,15,ac,f8,e1,57,4e,04,dc,b1,0a,14,00,00,00,8f,15,0d,92,36,9d,45,cf,\
e5,05,df,84,53,03,32,5a,80,0a,12,3a

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier]
"Asynchronous"=dword:00000000
"DllName"="WRLogonNTF.dll"
"Impersonate"=dword:00000001
"Lock"="WRLock"
"StartScreenSaver"="WRStartScreenSaver"
"StartShell"="WRStartShell"
"Startup"="WRStartup"
"StopScreenSaver"="WRStopScreenSaver"
"Unlock"="WRUnlock"
"Shutdown"="WRShutdown"
"Logoff"="WRLogoff"
"Logon"="WRLogon"

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run…"
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="IE Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People…"
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{DEE12703-6333-4D4E-8F34-738C4DCC2E04}"="RecordNow! SendToExt"
"{5CA3D70E-1895-11CF-8E15-001234567890}"="DriveLetterAccess"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
"{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"="Shell Extension for Malware scanning"
"{07C45BB1-4A8C-4642-A1F5-237E7215FF66}"="IE Microsoft BrowserBand"
"{1C1EDB47-CE22-4bbb-B608-77B48F83C823}"="IE Fade Task"
"{205D7A97-F16D-4691-86EF-F3075DCCA57D}"="IE Menu Desk Bar"
"{3028902F-6374-48b2-8DC6-9725E775B926}"="IE AutoComplete"
"{43886CD5-6529-41c4-A707-7B3C92C05E68}"="IE Navigation Bar"
"{44C76ECD-F7FA-411c-9929-1B77BA77F524}"="IE Menu Site"
"{4B78D326-D922-44f9-AF2A-07805C2A3560}"="IE Menu Band"
"{6038EF75-ABFC-4e59-AB6F-12D397F6568D}"="IE Microsoft History AutoComplete List"
"{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}"="IE Tracking Shell Menu"
"{6CF48EF8-44CD-45d2-8832-A16EA016311B}"="IE IShellFolderBand"
"{73CFD649-CD48-4fd8-A272-2070EA56526B}"="IE BandProxy"
"{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}"="IE MRU AutoComplete List"
"{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}"="IE RSS Feeder Folder"
"{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}"="IE Microsoft Shell Folder AutoComplete List"
"{B31C5FAE-961F-415b-BAF0-E697A5178B94}"="IE Microsoft Multiple AutoComplete List Container"
"{BC476F4C-D9D7-4100-8D4E-E043F6DEC409}"="Microsoft Browser Architecture"
"{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}"="IE Shell Rebar BandSite"
"{E6EE9AAC-F76B-4947-8260-A9F136138E11}"="IE Shell Band Site Menu"
"{F2CF5485-4E02-4f68-819C-B92DE9277049}"="&Links"
"{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}"="IE Registry Tree Options Utility"
"{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}"="IE User Assist"
"{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}"="IE Custom MRU AutoCompleted List"
"{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow"

**********************************************************************************
HKEY ROOT CLASSIDS:
**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
admparse.dll Fri Oct 27 2006 2:44:26a A…. 71,680 70.00 K
advpack.dll Fri Oct 27 2006 2:44:06a A…. 123,904 121.00 K
browseui.dll Sat Sep 23 2006 1:12:50p A…. 1,022,976 999.00 K
corpol.dll Tue Oct 17 2006 1:03:56p A…. 17,408 17.00 K
dxtmsft.dll Tue Oct 17 2006 12:58:06p A…. 346,624 338.50 K
dxtrans.dll Tue Oct 17 2006 12:57:50p A…. 214,528 209.50 K
extmgr.dll Fri Oct 27 2006 3:09:58p A…. 131,584 128.50 K
icardie.dll Tue Oct 17 2006 12:58:20p ….. 61,952 60.50 K
ieakeng.dll Fri Oct 27 2006 2:44:36a A…. 152,064 148.50 K
ieaksie.dll Fri Oct 27 2006 2:44:42a A…. 229,376 224.00 K
ieakui.dll Fri Oct 27 2006 2:42:54a A…. 161,792 158.00 K
ieapfltr.dll Tue Oct 17 2006 12:27:56p ….. 380,928 372.00 K
iedkcs32.dll Fri Oct 27 2006 2:44:46a A…. 382,976 374.00 K
ieencode.dll Tue Oct 17 2006 1:06:00p A…. 78,336 76.50 K
ieframe.dll Fri Oct 27 2006 3:09:58p ….. 6,049,280 5.77 M
iepeers.dll Fri Oct 27 2006 3:09:58p A…. 191,488 187.00 K
iernonce.dll Fri Oct 27 2006 2:44:08a A…. 43,008 42.00 K
iertutil.dll Tue Oct 17 2006 12:57:20p ….. 266,752 260.50 K
iesetup.dll Fri Oct 27 2006 2:44:26a A…. 55,296 54.00 K
ieui.dll Fri Oct 27 2006 3:09:58p ….. 180,736 176.50 K
imgutil.dll Tue Oct 17 2006 12:57:58p A…. 36,352 35.50 K
inseng.dll Fri Oct 27 2006 2:44:08a A…. 92,672 90.50 K
jscript.dll Tue Oct 17 2006 1:00:00p A…. 491,520 480.00 K
jsproxy.dll Fri Oct 27 2006 3:09:58p A…. 27,136 26.50 K
legitc~1.dll Mon Oct 30 2006 11:25:08a A…. 1,488,688 1.42 M
licmgr10.dll Tue Oct 17 2006 1:05:10p A…. 40,960 40.00 K
msfeeds.dll Fri Oct 27 2006 3:09:58p ….. 458,752 448.00 K
msfeed~1.dll Fri Oct 27 2006 3:09:58p ….. 50,688 49.50 K
mshtml.dll Fri Oct 27 2006 3:09:58p A…. 3,577,856 3.41 M
mshtmled.dll Fri Oct 27 2006 3:09:58p A…. 475,648 464.50 K
mshtmler.dll Tue Oct 17 2006 12:28:56p A…. 48,128 47.00 K
msls31.dll Fri Oct 27 2006 3:09:58p A…. 156,160 152.50 K
msrating.dll Tue Oct 17 2006 1:05:10p A…. 192,000 187.50 K
mstime.dll Fri Oct 27 2006 3:09:58p A…. 670,720 655.00 K
msxml3.dll Tue Sep 12 2006 9:01:56p A…. 1,084,416 1.03 M
msxml4.dll Sat Nov 4 2006 2:14:00p A…. 1,245,696 1.19 M
nwapi32.dll Fri Oct 13 2006 4:35:12a A…. 64,000 62.50 K
nwprovau.dll Fri Oct 13 2006 4:35:12a A…. 142,336 139.00 K
nwwks.dll Fri Oct 13 2006 4:35:12a A…. 65,536 64.00 K
occache.dll Tue Oct 17 2006 1:04:46p A…. 101,376 99.00 K
pngfilt.dll Tue Oct 17 2006 12:58:08p A…. 44,544 43.50 K
shdocvw.dll Sat Sep 23 2006 1:12:50p A…. 1,497,088 1.43 M
shlwapi.dll Sat Sep 23 2006 1:12:50p A…. 474,112 463.00 K
url.dll Tue Oct 17 2006 1:05:22p A…. 105,984 103.50 K
urlmon.dll Fri Oct 27 2006 3:09:58p A…. 1,162,240 1.11 M
vbscript.dll Fri Oct 27 2006 3:09:58p A…. 413,696 404.00 K
webcheck.dll Fri Oct 27 2006 3:09:58p A…. 231,424 226.00 K
wininet.dll Fri Oct 27 2006 3:09:58p A…. 818,688 799.50 K
xpsp3res.dll Mon Oct 16 2006 2:29:16a A…. 248,320 242.50 K

49 items found: 49 files, 0 directories.
Total of file sizes: 25,669,424 bytes 24.48 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is B0B0-9593

Directory of C:\WINDOWS\System32

11/18/2006 07:09 AM DLLCACHE
03/03/2004 07:01 AM Microsoft
0 File(s) 0 bytes
2 Dir(s) 29,143,154,688 bytes free



ReNamed GMER

GMER 1.0.11.11390 - http://www.gmer.net
Rootkit 2006-12-08 17:23:06
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.11 —-

SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

—- Devices - GMER 1.0.11 —-

Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE EED84C8A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE EED817C8
Device \FileSystem\Fastfat \Fat IRP_MJ_READ EED7D60A
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE EED7DAED
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION EED88958
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION EED8B821
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA EED9438A
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA EED93D49
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS EED8DBBE
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION EED8E331
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION EED9C4F4
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL EED84B37
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL EED80948
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL EED8A46B
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN EED9B79D
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL EED9AC4A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP EED812FD
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP EED9B1DB
Device \FileSystem\Fastfat \Fat FastIoCheckIfPossible EED961F9
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [EFBEF116] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [EFBEF116] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [EFBEF116] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [EFBEF116] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [EFBEF116] tfsnifs.sys
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL [EFBEF253] tfsnifs.sys

—- Files - GMER 1.0.11 —-

ADS …

—- EOF - GMER 1.0.11 —-


renamed Hijackthis

Logfile of HijackThis v1.99.1
Scan saved at 5:25:24 PM, on 12/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\hj\scannme.exe

O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Hi Fatman,

Your logs appear to be clean.

You don't seem to have a firewall program installed. Please do not rely solely on the Windows XP firewall. Unlike the XP firewall which only blocks one-way (incoming), these firewall applications will allow you to give/deny access for applications that want to go online. Select one of these, or another of your choice:Test your Firewall - Please test your firewall and make sure it is working properly.
Test Firewall

Please let me know how your computer seems to be running. Please post (reply) with a hijackthis log.
Thank you, downloader.vlob.aty is Gone. Internet seems a little slow, but that could be the ISP. Do I need a firewall if I'm hooked to a router? I passed the firewall test without installing software. Latest Hijackthis attached:
Thanks,
Fatman



Logfile of HijackThis v1.99.1
Scan saved at 9:25:22 AM, on 12/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hj\scannme.exe

O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Hi Fatman!

Your logs appear to be clean. :) Please be sure to reset and re-enable your restore point.

The old version of Java does not show up in your hijackthis log anymore. If you are having problems with the Java, I would seek support from the Java site. You do not want to use out-of-date Java since security holes may exist.
http://java.sun.com/javase/downloads/index.jsp

STEP 1.
======
System Restore for Windows XP
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
  • Turn off System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.
Reboot.

Turn ON System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • UN-Check *Turn off System Restore*.
  • Click Apply, and then click OK.

STEP 2.
======
DON’T BECOME OVERCONFIDENT WITH ANTIVIRUS APPLICATIONS INSTALLED!!!

http://forum.malwareremoval.com/viewtopic….39eba6ea0b5e8ee

Stay up to date on security patches and be extremely wary of clicking on links and attachments that arrive unbidden in instant messages and e-mail.

"The number one thing the majority of the malicious code we're seeing now does is disable or delete anti-virus and other security software," Dunham said. "In a lot of cases, once the user clicks on that attachment, it's already too late."


Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Use a Firewall - You should try one of those firewalls in addition to the router one. Understanding and Using Firewalls



  • Test your Firewall - Please test your firewall and make sure it is working properly.
    Test Firewall

  • Visit Microsoft's Update Site Frequently - It is important that you visit Windows Updates regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.
    A tutorial on installing & using this product can be found here:
    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.
    A tutorial on installing & using this product can be found here:
    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
    A tutorial on installing & using this product can be found here:
    Using SpywareBlaster to protect your computer from Spyware and Malware

  • More info on how to prevent malware you can also find here (By Tony Klein)
Follow this list and your potential for being infected again will reduce dramatically.

Thank you for allowing me to assist you.

Susan
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI