
Above Recommended Actions Taken.
"Please Post 1.) updated rapport 2.) updated AVG 3.) updated HijackThis! Log"
1.)
SmitFraudFix v2.131
Scan done at 16:33:06.87, Sat 12/23/2006
Run from C:\Documents and Settings\bob\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"cholecyst"="{ee2975b6-e8d5-405e-8448-8fe9590f6cfb}"
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\windows\system32\ot.ico Deleted
C:\windows\system32\stdole3.tlb Deleted
C:\windows\system32\ts.ico Deleted
C:\Program Files\Security Toolbar\ Deleted
C:\Program Files\ZipCodec\ Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
2.)
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 5:40:01 PM 12/23/2006
+ Scan result:
F:\My Shared Folder\_\0day mp3s, full quality albums.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\0day mp3s, quality albums.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\18 Wheels of Steel Convoy Unlocker.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\ACDSee v8.0.39.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\AV Voice Changer Software Diamond v4.0.50.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\AVG v7.0.280.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Adobe Acrobat v8.0 Professional.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Adobe Photoshop CS2 Tryout to Full Activation.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Adobe Photoshop CS2 v9.0.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Advanced Office Password Recovery v3.03 PRO.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Ahead Nero v7.5.9.0A.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\BT Engine v4.7 Build 1126-TE.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Battlefield 2 NOCD.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Battlefield Vietnam NOCD.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Bookworm Adventures Deluxe v1.0-DELiGHT.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Brothers In Arms Earned In Blood UNLOCKER-UNBAiSEDGOATS.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Brothers in Arms Road to Hill 30 FiXED CHEATS.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\C and C Generals Zero Hour GERMAN No-CD Fixed Image.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Call of Duty 2.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Call of Duty United Offensive Minimizer.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Call of Juarez NODVD.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Chili FTP v1.1.0.18.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Civilization 4 UPDATE v1.61 CRACKFiX iNTERNAL-CARBON.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Colin McRae Rally 2005 Crash Fix-IND.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Colin McRae Rally 2005 Crash Fix.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Commandos 3 Destination Berlin ALL ACCESS CHEATDOX.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Devil May Cry 3 Special Edition RELOADED CRACK-IFreon.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Diner Dash Flo On The Go v1.0.0.116-DELiGHT.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Diner Dash Flo On The Go v1.0.0.119 GAME.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Dungeons And Dragons Dragonshard.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Easter Bonus v1.01 Unlocker-TNT.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Easy File Sharing Web Server v3.0.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\ElcomSoft Advanced Archive Password Recovery ARCHPR v3.01.7-POPUP.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\ErrorSafe v1.1.44.0.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\F E A R NODVD CRACK.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Fifa 2005 Unlocker.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\GData AntiVirusKit 2006-YYePG.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Ghost Recon Advanced Warfighter.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Google Earth Pro 3.0beta-VOORHEES.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Grand Theft Auto San Andreas NOCD.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\HP Infotech CodeVisionAVR v1.24.6 Pro.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Half Life 2 OFFLINE ACTIVATION PATCH-oWNAGE.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Half Life 2 OFFLINE ACTIVATION PATCH.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti Virus Personal 5.0.388-TWK.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti Virus Personal 5.0.388.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti Virus Personal 5.0.527.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti-Virus 6.0.1.411 not blacklisted key.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti-Virus v6.0.0.299 FINAL-TWK.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti-Virus v6.0.0.299 FINAL.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti-Virus v6.0.0.300-TWK.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti-Virus v6.0.0.300.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti-Virus v6.0.0.303 RUSSiAN-TWK.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti-Virus v6.0.0.303 RUSSiAN.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti-Virus v6.0.0.303-TWK.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti-Virus v6.0.0.303.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti-Virus v6.0.1.411 RUSSiAN-TWK.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti-Virus v6.0.1.411 RUSSiAN.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti-Virus v6.0.1.411-TWK.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Anti-Virus v6.0.1.411.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Internet Security 2006 v6.0.0.290 RC6 CRK-FFF.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Internet Security 2006 v6.0.0.290 RC6.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Internet Security v6.0.0.300 WIN German-RHI.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Internet Security v6.0.0.300-TWK.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Kaspersky Internet Security v6.0.0.300.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Lingvosoft Flashcards English To Persian Farsi v1.6.14.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Luxor 2 v2.0.6.15 PLUS 10 TRAINER-Unleashed.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\MOTO GP Ultimate Racing Technology Unlocker.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Microsoft Windows Vista FINAL.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Mobile Ringtone Converter v2.3.11-TE.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Mst defrag home edition 1.8.30.58.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\NEED FOR SPEED MOST WANTED CDKEY-2RENTZWH0REZ.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\NEED FOR SPEED MOST WANTED.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\NEED FOR SPEED Most Wanted [MULTI] No-DVD Fixed Image.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Need For Speed Carbon ALL ACCESS CHEAT-ReVOLVeR.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Need For Speed Carbon ALL ACCESS CHEAT.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Need for Speed Carbon CHEAT CODES-Unleashed.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Need for Speed Carbon Collectors Edition PLUS 16 TRAINERDOX.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Need for Speed Underground 2 NOCD.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\NewsLeecher v3.0 Final..Incl CRACK-RESURRECTiON.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Nikon Capture v4.0.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\PPT2DVD v2.5.2.128.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\PaperCut Quota v5.2.570.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Passware Access Password Recovery Key v6.5.918.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\PolderbitS Sound Recorder And Editor v4.0.90.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Prince Of Persia 2 Warrior Within NoDISC-MiNT.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Prince Of Persia 2 Warrior Within NoDISC.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Pro Evolution Soccer 5.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\QUAKE 4 DVD CRACK.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\QUAKE 4 NOCDKEY.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Quake 4 KEYCHECK FiXED-SKULL.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\RegCure v1.0.0.43.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Registry Mechanic v6.00.750.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Sd4hide SafeDisc 4 Hider 1.0-SKULL.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Second Sight Unlocker Complete.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Security Task Manager 1.6c.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Security Task Manager v1.6f.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Skyshape MP3 Resizer v1.0.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\SlySoft AnyDVD v6.0.9.0-CRD.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\SlySoft CloneDVD v2.7.5.1.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Splinter Cell Pandora Tomorrow NOCD.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Spyware Doctor v3.1.0.312.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Spyware Doctor v4.0.0.2618.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Star Wars Battlefront 2.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Star Wars Empire at War Launcher NoCD.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Super Video Cap v4.0.300.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\TOCA RACE DRIVER 3 NODVD CRACK-MORESMELLYTNTANUSFARTS.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\The Elder Scrolls IV Oblivion NoDVD.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\The Godfather The Game NODVD-GHC.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\The Lord of the Rings The Battle for Middle-earth-VENGEANCE.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\The Sims 2.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\TrojanHunter v4.1 Build 903.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Ulead VideoStudio v9.0.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\VMware Workstation v5.0.0.13124-ZWT.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Vampire The Masquerade Bloodlines v1.2 NoCD.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\WinAVI Video Converter v7.7.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\WinRAR v3.51.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Windows Vista FINAL raVen.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\XP Repair Pro v2.4.1.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Xilisoft 3GP Video Converter v2.1.55.1025b.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\XoftSpy v4.21.134-CRD.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\Zuma Deluxe ALL ACCESS CHEAT.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
F:\My Shared Folder\_\n999tn999tn999tn999t.rar/Setup.exe -> Backdoor.IRCBot.qc : Cleaned with backup (quarantined).
::Report end
3.)
Logfile of HijackThis v1.99.1
Scan saved at 5:56:12 PM, on 12/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\System32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Saitek\Software\Profiler.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Saitek\Software\SaiSmart.exe
C:\Program Files\Saitek\Software\SaiMfd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Razer\Copperhead\razerhid.exe
C:\windows\system32\cisvc.exe
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Razer\Copperhead\razerofa.exe
C:\windows\system32\srvany.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\windows\system32\resetservice.exe
C:\windows\System32\svchost.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\windows\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\windows\system32\cidaemon.exe
C:\Documents and Settings\bob\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet
Explorer provided by Insight Broadband
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} -
C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software
Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\Profiler.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA
Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [nettg.exe] C:\WINDOWS\nettg.exe
O4 - HKLM\..\Run: [addnu32.exe] C:\WINDOWS\addnu32.exe
O4 - HKLM\..\Run: [javali.exe] C:\WINDOWS\system32\javali.exe
O4 - HKLM\..\Run: [mfcfz32.exe] C:\WINDOWS\system32\mfcfz32.exe
O4 - HKLM\..\Run: [addwl.exe] C:\WINDOWS\addwl.exe
O4 - HKLM\..\Run: [ienj.exe] C:\WINDOWS\system32\ienj.exe
O4 - HKLM\..\Run: [apino.exe] C:\WINDOWS\system32\apino.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SaiSmart] C:\Program Files\Saitek\Software\SaiSmart.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program
Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [153.tmp.exe] C:\DOCUME~1\bob\LOCALS~1\Temp\153.tmp.exe
O4 - HKLM\..\Run: [153.tmp] C:\DOCUME~1\bob\LOCALS~1\Temp\153.tmp.exe
O4 - HKLM\..\Run: [152.tmp.exe] C:\DOCUME~1\bob\LOCALS~1\Temp\152.tmp.exe
O4 - HKLM\..\Run: [152.tmp] C:\DOCUME~1\bob\LOCALS~1\Temp\152.tmp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI
HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\windows\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program
Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program
Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [BootSkin Startup Jobs]
"C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI
Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program
Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Program
Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Spades -
http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage
Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) -
http://www.mathxl.com/wizmodules/testgen/i…GenXInstall.cab
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) -
http://www.mathxl.com/applets/PearsonInstallAsst.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdat…eb_site.cab?116
6510428061
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…eb_site.cab?116
6510419077
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) -
http://h30155.www3.hp.com/ediags/gs/instal…edsolutions.cab
O16 - DPF: {9E58D78E-C5D3-DCF5-F38E-D1FBF76F5CBA} (MNPerformer Class) -
http://www.charter.net/files/musicnet/down…merSetup-sa.exe
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) -
http://www.linksysfix.com/netcheck/53/install/gtdownls.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate
Support Package) -
http://www.creative.com/su/ocx/15014/CTPID.cab
O16 - DPF: {FC6703A7-5B7E-4f58-BE6D-2693AA3906AE} (HP Content Update) -
http://h30299.www3.hp.com/ediags/hpna/web/…hp.cab?1,0,0,94
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: reset5 - C:\windows\SYSTEM32\reset5.dll
O20 - Winlogon Notify: WgaLogon - C:\windows\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program
Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -
C:\WINDOWS\system32\CTSVCCDA.EXE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation -
C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program
Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Reset 5 - Unknown owner - C:\windows\system32\srvany.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec
AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec
AntiVirus\Rtvscan.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner -
C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

Much Thanks