This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My hijack log

59 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i looked up the service and controller thing and i kept getting information about something called sasser or sasser worm you think i have this??? it doesn't make sense, apparently if i press send or don't send my computer will come up with that thing again about shutting itslef off because of system.exe??
my boyfriend told me he thinks it is because i didn't take the windows/microsoft update for internet explorer, so i went and downloaded it from the microsoft website and now the pop up has not returned!!
Hi I need you to boot into safemode and run rest of fix if you hadn't yet. I need to know. Please do not try to fix anything own your own. We will deal with the popup messages. Can you not boot into safe mode?

Hi

I need you to boot into safemode and run rest of fix if you hadn't yet.
I need to know.
Please do not try to fix anything own your own.
We will deal with the popup messages.
Can you not boot into safe mode?


Yes i am just running the panda scan now i will post everything in a moment
Incident Status Location Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Xodice\NetHood\Desktop\SDFix.exe[SDFix\apps\Process.exe] Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Xodice\NetHood\Desktop\SmitfraudFix\Process.exe Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Xodice\SmitfraudFix\Process.exe Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MSN Messenger\riched20.dll Potentially unwanted tool:Application/Processor Not disinfected C:\SDFix\apps\Process.exe Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\WINDOWS\system32\f3PSSavr.scr Adware:adware/webattaker Not disinfected C:\WINDOWS\uniq
Xodice - 07-01-06 22:13:59.64 Service Pack 2 ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Xodice\NetHood\Desktop\Tom Coyote fixers" ((((((((((((((((((((((((((((((( Files Created from 2006-12-06 to 2007-01-06 )))))))))))))))))))))))))))))))))) 2007-01-06 21:32 d——– C:\WINDOWS\system32\ActiveScan 2007-01-06 21:32 d——– C:\WINDOWS\LastGood 2007-01-06 21:26 dr-h—– C:\Documents and Settings\Xodice\Recent 2007-01-06 21:05 d——– C:\WINDOWS\WBEM 2007-01-06 21:05 d——– C:\WINDOWS\system32\en-US 2007-01-06 21:04 d–h-c— C:\WINDOWS\ie7 2007-01-06 21:03 121,856 ——— C:\WINDOWS\system32\xmllite.dll 2007-01-06 21:03 d——– C:\WINDOWS\network diagnostic 2007-01-06 21:00 d——– C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage 2007-01-06 19:59 d——– C:\SDFix 2007-01-05 18:49 d——– C:\!KillBox 2007-01-05 18:30 d——– C:\VundoFix Backups 2007-01-04 19:41 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-01-03 22:49 d——– C:\Program Files\WON 2007-01-03 22:28 d——– C:\avenger 2007-01-03 22:24 60,416 –a—— C:\WINDOWS\system32\drivers\ev^gnmmn.sys 2007-01-03 22:24 d——– C:\Rustbfix 2007-01-03 19:05 2,506 –a—— C:\WINDOWS\system32\tmp.reg 2007-01-03 19:05 d——– C:\Documents and Settings\Xodice\SmitfraudFix 2007-01-02 12:33 d——– C:\Program Files\CCleaner 2007-01-01 22:30 90,112 –a—— C:\WINDOWS\system32\RegDACL.exe 2007-01-01 22:30 7,483 –a—— C:\clean.bat 2007-01-01 22:30 4,096 –a—— C:\WINDOWS\system32\reboot.exe 2007-01-01 22:30 38,400 –a—— C:\WINDOWS\system32\moveex.exe 2007-01-01 22:29 d——– C:\Program Files\HaxFix 2006-12-27 00:48 dr-h—– C:\$VAULT$.AVG 2006-12-19 23:52 816,672 –a—— C:\WINDOWS\system32\drivers\avg7core.sys 2006-12-19 23:52 4,960 –a—— C:\WINDOWS\system32\drivers\avgtdi.sys 2006-12-19 23:52 4,224 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys 2006-12-19 23:52 3,968 –a—— C:\WINDOWS\system32\drivers\avgclean.sys 2006-12-19 23:52 28,416 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys 2006-12-19 23:52 18,240 –a—— C:\WINDOWS\system32\drivers\avgmfx86.sys 2006-12-19 23:52 d——– C:\Program Files\Grisoft 2006-12-19 23:52 d——– C:\Documents and Settings\Xodice\Application Data\AVG7 2006-12-19 23:52 d——– C:\Documents and Settings\All Users\Application Data\Grisoft 2006-12-19 23:52 d——– C:\Documents and Settings\All Users\Application Data\avg7 2006-12-19 12:41 d——– C:\Documents and Settings\Xodice\Application Data\Real 2006-12-10 00:03 d——– C:\Program Files\Winamp (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-01-06 22:11 ——– d——– C:\Program Files\Mozilla Firefox 2007-01-06 21:51 ——– d——– C:\Program Files\LiveUpdate 2007-01-06 21:50 ——– d——– C:\Program Files\Internet Explorer 2007-01-06 21:14 ——– d——– C:\Program Files\hijack this 2007-01-06 19:54 ——– d——– C:\Documents and Settings\Xodice\Application Data\Azureus 2007-01-04 00:26 ——– d–h—– C:\Program Files\InstallShield Installation Information 2007-01-02 21:43 ——– d——– C:\Program Files\Common Files\Symantec Shared 2006-12-19 23:52 ——– d—s—- C:\Documents and Settings\Xodice\Application Data\Microsoft 2006-12-19 23:25 ——– d-a—— C:\Program Files\Common Files 2006-12-17 23:17 ——– d——– C:\Program Files\Jasc Software Inc 2006-12-14 03:01 ——– d——– C:\Program Files\Outlook Express 2006-12-14 03:01 ——– d——– C:\Program Files\Common Files\System 2006-12-06 22:29 2374472 –a—— C:\WINDOWS\system32\wmvcore.dll 2006-11-07 22:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll 2006-11-07 21:03 6049280 ——— C:\WINDOWS\system32\ieframe.dll 2006-11-07 21:03 50688 ——— C:\WINDOWS\system32\msfeedsbs.dll 2006-11-07 21:03 458752 ——— C:\WINDOWS\system32\msfeeds.dll 2006-11-07 21:03 413696 –a—— C:\WINDOWS\system32\vbscript.dll 2006-11-07 21:03 231424 –a—— C:\WINDOWS\system32\webcheck.dll 2006-11-07 21:03 180736 ——— C:\WINDOWS\system32\ieui.dll 2006-11-07 21:03 156160 –a—— C:\WINDOWS\system32\msls31.dll 2006-11-07 03:27 382976 –a—— C:\WINDOWS\system32\iedkcs32.dll 2006-11-07 03:27 229376 –a—— C:\WINDOWS\system32\ieaksie.dll 2006-11-07 03:26 71680 –a—— C:\WINDOWS\system32\admparse.dll 2006-11-07 03:26 55296 –a—— C:\WINDOWS\system32\iesetup.dll 2006-11-07 03:26 54784 –a—— C:\WINDOWS\system32\ie4uinit.exe 2006-11-07 03:26 43008 –a—— C:\WINDOWS\system32\iernonce.dll 2006-11-07 03:26 152064 –a—— C:\WINDOWS\system32\ieakeng.dll 2006-11-07 03:26 13312 –a—— C:\WINDOWS\system32\ieudinit.exe 2006-11-07 03:26 123904 –a—— C:\WINDOWS\system32\advpack.dll 2006-11-07 03:25 161792 –a—— C:\WINDOWS\system32\ieakui.dll 2006-11-06 12:05 ——– d——– C:\Program Files\MSN Messenger 2006-11-06 12:04 ——– d——– C:\Program Files\Common Files\Microsoft Shared 2006-11-04 14:14 1245696 –a—— C:\WINDOWS\system32\msxml4.dll 2006-10-19 06:56 713216 –a—— C:\WINDOWS\system32\sxs.dll 2006-10-17 12:06 78336 –a—— C:\WINDOWS\system32\ieencode.dll 2006-10-17 12:05 40960 –a—— C:\WINDOWS\system32\licmgr10.dll 2006-10-17 12:05 206336 ——— C:\WINDOWS\system32\WinFXDocObj.exe 2006-10-17 12:05 105984 –a—— C:\WINDOWS\system32\url.dll 2006-10-17 12:04 101376 –a—— C:\WINDOWS\system32\occache.dll 2006-10-17 12:03 17408 –a—— C:\WINDOWS\system32\corpol.dll 2006-10-17 11:58 61952 ——— C:\WINDOWS\system32\icardie.dll 2006-10-17 11:58 12288 ——— C:\WINDOWS\system32\msfeedssync.exe 2006-10-17 11:57 36352 –a—— C:\WINDOWS\system32\imgutil.dll 2006-10-17 11:57 266752 ——— C:\WINDOWS\system32\iertutil.dll 2006-10-17 11:56 45568 –a—— C:\WINDOWS\system32\mshta.exe 2006-10-17 11:28 48128 –a—— C:\WINDOWS\system32\mshtmler.dll 2006-10-17 11:27 380928 ——— C:\WINDOWS\system32\ieapfltr.dll 2006-10-13 05:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "BTCLiveUpdate"="\"C:\\Program Files\\LiveUpdate\\LiveUpdate.exe\" /autostart" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "NVRaidService"="C:\\WINDOWS\\System32\\nvraidservice.exe" "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"" "NVMixerTray"="\"C:\\Program Files\\NVIDIA Corporation\\NvMixer\\NVMixerTray.exe\"" "iRiver Updater"="\\Updater.exe" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe" "nwiz"="nwiz.exe /install" "ANIWZCS2Service"="C:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe" "UserFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,75,00 "NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "DAEMON Tools-1033"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033 -noicon" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000000 [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\ATI CATALYST System Tray.lnk" "backup"="C:\\WINDOWS\\pss\\ATI CATALYST System Tray.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\ATITEC~1\\ATI.ACE\\CLI.exe SystemTray" "item"="ATI CATALYST System Tray" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\HP Digital Imaging Monitor.lnk" "backup"="C:\\WINDOWS\\pss\\HP Digital Imaging Monitor.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\HP\\DIGITA~1\\bin\\hpqtra08.exe " "item"="HP Digital Imaging Monitor" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\InterVideo WinCinema Manager.lnk" "backup"="C:\\WINDOWS\\pss\\InterVideo WinCinema Manager.lnkCommon Startup" "location"="Common Startup" "command"="G:\\PROGRA~1\\INTERV~1\\Common\\Bin\\WINCIN~1.EXE " "item"="InterVideo WinCinema Manager" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinScheduler.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\InterVideo WinScheduler.lnk" "backup"="C:\\WINDOWS\\pss\\InterVideo WinScheduler.lnkCommon Startup" "location"="Common Startup" "command"="G:\\PROGRA~1\\INTERV~1\\MSIPVS\\WINSCH~1.EXE " "item"="InterVideo WinScheduler" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak EasyShare software.lnk" "backup"="C:\\WINDOWS\\pss\\Kodak EasyShare software.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Kodak\\KODAKE~1\\bin\\EASYSH~1.EXE -h" "item"="Kodak EasyShare software" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak software updater.lnk" "backup"="C:\\WINDOWS\\pss\\Kodak software updater.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Kodak\\KODAKS~1\\7288971\\Program\\KODAKS~1.EXE " "item"="Kodak software updater" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Xodice^Start Menu^Programs^Startup^Desperate Housewives Registration.lnk] "path"="C:\\Documents and Settings\\Xodice\\Start Menu\\Programs\\Startup\\Desperate Housewives Registration.lnk" "backup"="C:\\WINDOWS\\pss\\Desperate Housewives Registration.lnkStartup" "location"="Startup" "command"="D:\\PROGRA~1\\BUENAV~1\\DESPER~1\\eReg\\DSN1.exe /remind /language=ENU /PRNM=\"Desperate Housewives\"" "item"="Desperate Housewives Registration" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="" "hkey"="HKCU" "command"="" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\6JceYY45c] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="websk" "hkey"="HKLM" "command"="C:\\WINDOWS\\websk.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASDPLUGIN] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="canada" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\canada.exe -N" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="cli" "hkey"="HKLM" "command"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="atiptaxx" "hkey"="HKLM" "command"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CTDetect" "hkey"="HKCU" "command"="C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe /R" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CU1] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="VCClient" "hkey"="HKCU" "command"="C:\\Program Files\\Common Files\\VCClient\\VCClient.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CU2] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="VCMain" "hkey"="HKCU" "command"="C:\\Program Files\\Common Files\\VCClient\\VCMain.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="daemon" "hkey"="HKLM" "command"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dinst] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dinst" "hkey"="HKLM" "command"="C:\\WINDOWS\\dinst.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dljgmqgA] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dljgmqgA" "hkey"="HKLM" "command"="C:\\WINDOWS\\dljgmqgA.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\etbrun] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="elitehof32" "hkey"="HKLM" "command"="C:\\windows\\system32\\elitehof32.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMOFFICE4DMOUSE] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="moffice" "hkey"="HKLM" "command"="C:\\Program Files\\Labtec\\moffice.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gimmygames] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="gimmygames11" "hkey"="HKLM" "command"="C:\\\\gimmygames11.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HPWuSchd2" "hkey"="HKLM" "command"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ib35jrtp] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ib35jrtp" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\ib35jrtp.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\klop] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="30" "hkey"="HKCU" "command"="C:\\WINDOWS\\30.tmp" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load] "key"="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows" "item"="??¯ ?" "hkey"="HKCU" "command"="??¯ ?" "inimapping"="1" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Access] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="MediaAccK" "hkey"="HKLM" "command"="C:\\Program Files\\Media Access\\MediaAccK.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mhav] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="mhav" "hkey"="HKLM" "command"="C:\\WINDOWS\\mhav.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="msmsgs" "hkey"="HKCU" "command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="MWSBAR" "hkey"="HKLM" "command"="rundll32 C:\\PROGRA~1\\MYWEBS~1\\bar\\2.bin\\MWSBAR.DLL,S" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="mwsoemon" "hkey"="HKLM" "command"="C:\\PROGRA~1\\MYWEBS~1\\bar\\2.bin\\mwsoemon.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="nwiz" "hkey"="HKLM" "command"="nwiz.exe /install" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ongsnah] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="bdkybh" "hkey"="HKLM" "command"="c:\\windows\\system32\\bdkybh.exe r" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="mssysmgr" "hkey"="HKCU" "command"="C:\\PROGRA~1\\Ahead\\NEROPH~2\\data\\Xtras\\mssysmgr.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\POINTER] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="point32" "hkey"="HKLM" "command"="C:\\Program Files\\Microsoft Hardware\\Mouse\\point32.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pop-Up Stopper] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dpps2" "hkey"="HKLM" "command"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\dpps2.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QD FastAndSafe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="point32" "hkey"="HKLM" "command"="C:\\Program Files\\Microsoft Hardware\\Mouse\\point32.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RealPlay" "hkey"="HKLM" "command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PDVDServ" "hkey"="HKLM" "command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\roii] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="roiim" "hkey"="HKCU" "command"="C:\\PROGRA~1\\COMMON~1\\roii\\roiim.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shell] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ibm00001" "hkey"="HKCU" "command"="\"C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\ibm00001.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TeaTimer" "hkey"="HKCU" "command"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="" "hkey"="HKCU" "command"="" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="jusched" "hkey"="HKLM" "command"="C:\\Program Files\\Java\\jre1.5.0_01\\bin\\jusched.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SurfSideKick 3] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Ssk" "hkey"="HKLM" "command"="C:\\Program Files\\SurfSideKick 3\\Ssk.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\svgbwr] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ggkgwm" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\ggkgwm.exe r" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SNDMon" "hkey"="HKLM" "command"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TheMonitor] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SYSC00" "hkey"="HKLM" "command"="C:\\WINDOWS\\SYSC00.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dumprep 0 -u" "hkey"="HKLM" "command"="%systemroot%\\system32\\dumprep 0 -u" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeirdOnTheWeb] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="WeirdOnTheWeb" "hkey"="HKLM" "command"="\"C:\\Program Files\\WeirdOnTheWeb\\WeirdOnTheWeb.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\win32073991086372] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="win32073991086372" "hkey"="HKLM" "command"="C:\\WINDOWS\\win32073991086372.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="winampa" "hkey"="HKLM" "command"="C:\\Program Files\\Winamp\\winampa.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsysban] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="winsysban11" "hkey"="HKLM" "command"="C:\\\\winsysban11.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsysupd] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="winsysupd11" "hkey"="HKLM" "command"="C:\\\\winsysupd11.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xwrrakq] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="izopei" "hkey"="HKLM" "command"="c:\\windows\\system32\\izopei.exe r" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ydcbyf] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ydcbyf" "hkey"="HKLM" "command"="C:\\WINDOWS\\ydcbyf.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yjdtsar] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="zmppnu" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\zmppnu.exe r" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "FreezeScreenSaver"=dword:00000002 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Completion time: 07-01-06 22:14:45.56 C:\ComboFix.txt … 07-01-06 22:14 C:\ComboFix2.txt … 07-01-05 19:06 C:\ComboFix3.txt … 07-01-03 19:00
Logfile of HijackThis v1.99.1
Scan saved at 10:22:55 PM, on 1/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvraidservice.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Updater.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\LiveUpdate\LiveUpdate.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\hijack this\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [BTCLiveUpdate] "C:\Program Files\LiveUpdate\LiveUpdate.exe" /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: D-Link AirPlus.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by23fd.bay23.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1168141373265
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
i could not figure out how to find the

Use Explorer to navigate to and delete the following file (if it is present) just what is in red:

Files:

* C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe <<<< Maybe C:\ProgramFiles\SYMNET << Folder Starting with these letters.



If you can not find SNDMon.exe move to next step.
I don't know what Explorer is but i went into search and typed in SNDMon.exe and nothing popped up and i don't have a SYMNET folder in my program files.
Hello Booberry,

Thanks for posting logs now we are getting some where got rid of some infection much more to go.

i looked up the service and controller thing and i kept getting information about something called sasser or sasser worm you think i have this??? it doesn't make sense, apparently if i press send or don't send my computer will come up with that thing again about shutting itslef off because of system.exe??


If you had sasser worm it should have show up in Panda online scan.
Once we get rid of all this infected files we will see if this error message stops.

I will need you to boot into safe more to carry this out.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
—————————————————————

Start Killbox place a tick next to [x]Delete on reboot Press the ALL Files button <<< Very important to hit the all files button
Copy this whole list into the windows clipboard, all the Bold below.

C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
C:\Program Files\MSN Messenger\riched20.dll
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\ib35jrtp.exe
C:\WINDOWS\dljgmqgA.exe
C:\WINDOWS\websk.exe
c:\windows\system32\bdkybh.exe
C:\WINDOWS\mhav.exe
C:\WINDOWS\system32\ggkgwm.exe
C:\WINDOWS\win32073991086372.exe
c:\windows\system32\izopei.exe
C:\WINDOWS\ydcbyf.exe
C:\WINDOWS\system32\zmppnu.exe
C:\winsysupd11.exe
C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe
C:\WINDOWS\SYSC00.exe
C:\Program Files\Symantec\SNDMon.exe
C:\Program Files\SurfSideKick 3\Ssk.exe
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
C:\Program Files\Common Files\roii\roiim.exe
C:\Program Files\MyWebSearch\bar\2.bin\mwsoemon.exe
C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
C:\Program Files\Media Access\MediaAccK.exe
C:\windows\system32\elitehof32.exe
C:\gimmygames11.exe
C:\WINDOWS\dinst.exe
C:\WINDOWS\system32\canada.exe


Back in Killbox go to > file > paste from clipboard.
Next, click the red highlighted X button and say NO to the prompt to restart the pc.
Now, exit Killbox and restart Your PC. You will have to reboot back into Safemode

—————————————————————


Use Windows Explorer to navigate to and delete the following folders (if it is present) just what is in red:

Folders:

C:\Program Files\WeirdOnTheWeb

This is how you find it:
1. click start > then click My Computer
2. Double click on C; Drive to open
now we are looking for this part of line that I had above
\Program Files\WeirdOnTheWeb
3. look for and double click on Program Files folder to open.
4. Now look for WeirdOnTheWeb when found right on it and choose delete.

Now repeat steps above all these folders and delete them too.
C:\Program Files\Symantec
C:\Program Files\SurfSideKick
C:\Program Files\Common Files\roii
C:\Program Files\MyWebSearch
C:\Program Files\Media Access
C:\WINDOWS\uniq

If you can not find some continue with fix don't stop here. still in safemode go to next step.
_____________________________________________________________


proper regfix to clear that entries: .

1. Please do this:
  • Copy the contents of the Quote Box below to Notepad make sure to just copy what is inside box nothing outside of it. (not Wordpad)
  • On file menu click Save as
  • Name the file as regfix.reg <<<< You must type exactly as shown period and all
  • Change the Save as Type to All Files (NOT as a txt file)
  • and Save it on the desktop
Quote:

REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsysupd]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsysban]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeirdOnTheWeb]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TheMonitor]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SurfSideKick 3]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shell]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\roii]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Access]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gimmygames]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\etbrun]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dinst]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASDPLUGIN]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ib35jrtp]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dljgmqgA]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\6JceYY45c]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mhav]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ongsnah]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\svgbwr]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\win32073991086372]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xwrrakq]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ydcbyf]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yjdtsar]


Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

2. Then double-click on the regfix.reg file icon should look like this [external image: Posted Image], that is on your desktop and when it prompts to merge say yes.

——————————————————————————————————–

Now rerun Ccleaner here still in safe mode.

——————————————————————————

Now reboot into normal mode here

———————————————————

Rerun combofix again here.

———————————————————

This show will show things other done YOU have do use Internt Explorer browser for this not FireFox
Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
  • Scan using the following Anti-Virus database:
  • Extended (If available otherwise Standard)
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
[*]Click OK

[*]Now under select a target to scan select My Computer

[*]The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

[*]Now click on the Save as Text button

[*] Save the file to your desktop.

[*]Copy and paste that information in your next post.

————————————————————–

Please post logs:
combofix log
kaspersky report
New HJT log
i went into safemod and i opened up kill box i copied all the files and i went into killbox and pressed file paste from clipboard and delete after reboot and all files the only things that should up in the lil box was C:\program files\mozilla firefox\plugins\npmywebs.dll C:\program files\msn messenger\richard20.dll C:\windows\system32\f3pssavr.scr Other then that i didn't see any other files i copied show up?? So i came back and didn't go through with it yet, i wanted to know if they would all show up or just thses ones!

i went into safemod and i opened up kill box i copied all the files and i went into killbox and pressed file paste from clipboard and delete after reboot and all files the only things that should up in the lil box was
C:\program files\mozilla firefox\plugins\npmywebs.dll
C:\program files\msn messenger\richard20.dll
C:\windows\system32\f3pssavr.scr
Other then that i didn't see any other files i copied show up??
So i came back and didn't go through with it yet, i wanted to know if they would all show up or just thses ones!


It seems i can only do three at a time maybe??
Start back from here make sure to boot into safe mode.

Use Windows Explorer to navigate to and delete the following folders (if it is present) just what is in red:

Folders:

C:\Program Files\WeirdOnTheWeb

This is how you find it:
1. click start > then click My Computer
2. Double click on C; Drive to open
now we are looking for this part of line that I had above
\Program Files\WeirdOnTheWeb
3. look for and double click on Program Files folder to open.
4. Now look for WeirdOnTheWeb when found right on it and choose delete.

Now repeat steps above all these folders and delete them too.
C:\Program Files\Symantec
C:\Program Files\SurfSideKick
C:\Program Files\Common Files\roii
C:\Program Files\MyWebSearch
C:\Program Files\Media Access
C:\WINDOWS\uniq

If you can not find some continue with fix don't stop here. still in safemode go to next step.
_____________________________________________________________


proper regfix to clear that entries: .

1. Please do this:
  • Copy the contents of the Quote Box below to Notepad make sure to just copy what is inside box nothing outside of it. (not Wordpad)
  • On file menu click Save as
  • Name the file as regfix.reg <<<< You must type exactly as shown period and all
  • Change the Save as Type to All Files (NOT as a txt file)
  • and Save it on the desktop
Quote:

REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsysupd]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsysban]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeirdOnTheWeb]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TheMonitor]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SurfSideKick 3]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shell]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\roii]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Access]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gimmygames]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\etbrun]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dinst]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASDPLUGIN]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ib35jrtp]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dljgmqgA]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\6JceYY45c]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mhav]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ongsnah]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\svgbwr]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\win32073991086372]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xwrrakq]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ydcbyf]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yjdtsar]


Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

2. Then double-click on the regfix.reg file icon should look like this [external image: Posted Image], that is on your desktop and when it prompts to merge say yes.

——————————————————————————————————–

Now rerun Ccleaner here still in safe mode.

——————————————————————————

Now reboot into normal mode here

———————————————————

Rerun combofix again here.

———————————————————

This show will show things other done YOU have do use Internt Explorer browser for this not FireFox
Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
  • Scan using the following Anti-Virus database:
  • Extended (If available otherwise Standard)
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
[*]Click OK

[*]Now under select a target to scan select My Computer

[*]The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

[*]Now click on the Save as Text button

[*] Save the file to your desktop.

[*]Copy and paste that information in your next post.

————————————————————–

Please post logs:
combofix log
kaspersky report
New HJT log
odice - 07-01-08 18:31:42.87 Service Pack 2 ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Xodice\NetHood\Desktop\Tom Coyote fixers" ((((((((((((((((((((((((((((((( Files Created from 2006-12-08 to 2007-01-08 )))))))))))))))))))))))))))))))))) 2007-01-08 18:27 dr-h—– C:\Documents and Settings\Xodice\Recent 2007-01-07 10:25 127,208 –a—— C:\WINDOWS\system32\mucltui.dll 2007-01-06 21:32 d——– C:\WINDOWS\system32\ActiveScan 2007-01-06 21:05 d——– C:\WINDOWS\WBEM 2007-01-06 21:05 d——– C:\WINDOWS\system32\en-US 2007-01-06 21:04 d–h-c— C:\WINDOWS\ie7 2007-01-06 21:03 121,856 ——— C:\WINDOWS\system32\xmllite.dll 2007-01-06 21:03 d——– C:\WINDOWS\network diagnostic 2007-01-06 21:00 d——– C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage 2007-01-06 19:59 d——– C:\SDFix 2007-01-05 18:49 d——– C:\!KillBox 2007-01-05 18:30 d——– C:\VundoFix Backups 2007-01-04 19:41 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-01-03 22:49 d——– C:\Program Files\WON 2007-01-03 22:28 d——– C:\avenger 2007-01-03 22:24 60,416 –a—— C:\WINDOWS\system32\drivers\ev^gnmmn.sys 2007-01-03 22:24 d——– C:\Rustbfix 2007-01-03 19:05 2,506 –a—— C:\WINDOWS\system32\tmp.reg 2007-01-03 19:05 d——– C:\Documents and Settings\Xodice\SmitfraudFix 2007-01-02 12:33 d——– C:\Program Files\CCleaner 2007-01-01 22:30 90,112 –a—— C:\WINDOWS\system32\RegDACL.exe 2007-01-01 22:30 7,483 –a—— C:\clean.bat 2007-01-01 22:30 4,096 –a—— C:\WINDOWS\system32\reboot.exe 2007-01-01 22:30 38,400 –a—— C:\WINDOWS\system32\moveex.exe 2007-01-01 22:29 d——– C:\Program Files\HaxFix 2006-12-27 00:48 dr-h—– C:\$VAULT$.AVG 2006-12-19 23:52 816,672 –a—— C:\WINDOWS\system32\drivers\avg7core.sys 2006-12-19 23:52 4,960 –a—— C:\WINDOWS\system32\drivers\avgtdi.sys 2006-12-19 23:52 4,224 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys 2006-12-19 23:52 3,968 –a—— C:\WINDOWS\system32\drivers\avgclean.sys 2006-12-19 23:52 28,416 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys 2006-12-19 23:52 18,240 –a—— C:\WINDOWS\system32\drivers\avgmfx86.sys 2006-12-19 23:52 d——– C:\Program Files\Grisoft 2006-12-19 23:52 d——– C:\Documents and Settings\Xodice\Application Data\AVG7 2006-12-19 23:52 d——– C:\Documents and Settings\All Users\Application Data\Grisoft 2006-12-19 23:52 d——– C:\Documents and Settings\All Users\Application Data\avg7 2006-12-19 12:41 d——– C:\Documents and Settings\Xodice\Application Data\Real 2006-12-10 00:03 d——– C:\Program Files\Winamp (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-01-08 18:30 ——– d——– C:\Program Files\Mozilla Firefox 2007-01-06 22:22 ——– d——– C:\Program Files\hijack this 2007-01-06 21:51 ——– d——– C:\Program Files\LiveUpdate 2007-01-06 21:50 ——– d——– C:\Program Files\Internet Explorer 2007-01-06 19:54 ——– d——– C:\Documents and Settings\Xodice\Application Data\Azureus 2007-01-04 00:26 ——– d–h—– C:\Program Files\InstallShield Installation Information 2007-01-02 21:43 ——– d——– C:\Program Files\Common Files\Symantec Shared 2006-12-19 23:52 ——– d—s—- C:\Documents and Settings\Xodice\Application Data\Microsoft 2006-12-19 23:25 ——– d-a—— C:\Program Files\Common Files 2006-12-17 23:17 ——– d——– C:\Program Files\Jasc Software Inc 2006-12-14 03:01 ——– d——– C:\Program Files\Outlook Express 2006-12-14 03:01 ——– d——– C:\Program Files\Common Files\System 2006-12-06 22:29 2374472 –a—— C:\WINDOWS\system32\wmvcore.dll 2006-11-07 22:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll 2006-11-07 21:03 6049280 ——— C:\WINDOWS\system32\ieframe.dll 2006-11-07 21:03 50688 ——— C:\WINDOWS\system32\msfeedsbs.dll 2006-11-07 21:03 458752 ——— C:\WINDOWS\system32\msfeeds.dll 2006-11-07 21:03 413696 –a—— C:\WINDOWS\system32\vbscript.dll 2006-11-07 21:03 231424 –a—— C:\WINDOWS\system32\webcheck.dll 2006-11-07 21:03 180736 ——— C:\WINDOWS\system32\ieui.dll 2006-11-07 21:03 156160 –a—— C:\WINDOWS\system32\msls31.dll 2006-11-07 03:27 382976 –a—— C:\WINDOWS\system32\iedkcs32.dll 2006-11-07 03:27 229376 –a—— C:\WINDOWS\system32\ieaksie.dll 2006-11-07 03:26 71680 –a—— C:\WINDOWS\system32\admparse.dll 2006-11-07 03:26 55296 –a—— C:\WINDOWS\system32\iesetup.dll 2006-11-07 03:26 54784 –a—— C:\WINDOWS\system32\ie4uinit.exe 2006-11-07 03:26 43008 –a—— C:\WINDOWS\system32\iernonce.dll 2006-11-07 03:26 152064 –a—— C:\WINDOWS\system32\ieakeng.dll 2006-11-07 03:26 13312 –a—— C:\WINDOWS\system32\ieudinit.exe 2006-11-07 03:26 123904 –a—— C:\WINDOWS\system32\advpack.dll 2006-11-07 03:25 161792 –a—— C:\WINDOWS\system32\ieakui.dll 2006-11-04 14:14 1245696 –a—— C:\WINDOWS\system32\msxml4.dll 2006-10-19 06:56 713216 –a—— C:\WINDOWS\system32\sxs.dll 2006-10-17 12:06 78336 –a—— C:\WINDOWS\system32\ieencode.dll 2006-10-17 12:05 40960 –a—— C:\WINDOWS\system32\licmgr10.dll 2006-10-17 12:05 206336 ——— C:\WINDOWS\system32\WinFXDocObj.exe 2006-10-17 12:05 105984 –a—— C:\WINDOWS\system32\url.dll 2006-10-17 12:04 101376 –a—— C:\WINDOWS\system32\occache.dll 2006-10-17 12:03 17408 –a—— C:\WINDOWS\system32\corpol.dll 2006-10-17 11:58 61952 ——— C:\WINDOWS\system32\icardie.dll 2006-10-17 11:58 12288 ——— C:\WINDOWS\system32\msfeedssync.exe 2006-10-17 11:57 36352 –a—— C:\WINDOWS\system32\imgutil.dll 2006-10-17 11:57 266752 ——— C:\WINDOWS\system32\iertutil.dll 2006-10-17 11:56 45568 –a—— C:\WINDOWS\system32\mshta.exe 2006-10-17 11:28 48128 –a—— C:\WINDOWS\system32\mshtmler.dll 2006-10-17 11:27 380928 ——— C:\WINDOWS\system32\ieapfltr.dll 2006-10-13 05:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "BTCLiveUpdate"="\"C:\\Program Files\\LiveUpdate\\LiveUpdate.exe\" /autostart" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "NVRaidService"="C:\\WINDOWS\\System32\\nvraidservice.exe" "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"" "NVMixerTray"="\"C:\\Program Files\\NVIDIA Corporation\\NvMixer\\NVMixerTray.exe\"" "iRiver Updater"="\\Updater.exe" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe" "nwiz"="nwiz.exe /install" "ANIWZCS2Service"="C:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe" "UserFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,75,00 "NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "DAEMON Tools-1033"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033 -noicon" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000000 [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\ATI CATALYST System Tray.lnk" "backup"="C:\\WINDOWS\\pss\\ATI CATALYST System Tray.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\ATITEC~1\\ATI.ACE\\CLI.exe SystemTray" "item"="ATI CATALYST System Tray" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\HP Digital Imaging Monitor.lnk" "backup"="C:\\WINDOWS\\pss\\HP Digital Imaging Monitor.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\HP\\DIGITA~1\\bin\\hpqtra08.exe " "item"="HP Digital Imaging Monitor" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\InterVideo WinCinema Manager.lnk" "backup"="C:\\WINDOWS\\pss\\InterVideo WinCinema Manager.lnkCommon Startup" "location"="Common Startup" "command"="G:\\PROGRA~1\\INTERV~1\\Common\\Bin\\WINCIN~1.EXE " "item"="InterVideo WinCinema Manager" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinScheduler.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\InterVideo WinScheduler.lnk" "backup"="C:\\WINDOWS\\pss\\InterVideo WinScheduler.lnkCommon Startup" "location"="Common Startup" "command"="G:\\PROGRA~1\\INTERV~1\\MSIPVS\\WINSCH~1.EXE " "item"="InterVideo WinScheduler" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak EasyShare software.lnk" "backup"="C:\\WINDOWS\\pss\\Kodak EasyShare software.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Kodak\\KODAKE~1\\bin\\EASYSH~1.EXE -h" "item"="Kodak EasyShare software" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak software updater.lnk" "backup"="C:\\WINDOWS\\pss\\Kodak software updater.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Kodak\\KODAKS~1\\7288971\\Program\\KODAKS~1.EXE " "item"="Kodak software updater" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Xodice^Start Menu^Programs^Startup^Desperate Housewives Registration.lnk] "path"="C:\\Documents and Settings\\Xodice\\Start Menu\\Programs\\Startup\\Desperate Housewives Registration.lnk" "backup"="C:\\WINDOWS\\pss\\Desperate Housewives Registration.lnkStartup" "location"="Startup" "command"="D:\\PROGRA~1\\BUENAV~1\\DESPER~1\\eReg\\DSN1.exe /remind /language=ENU /PRNM=\"Desperate Housewives\"" "item"="Desperate Housewives Registration" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="" "hkey"="HKCU" "command"="" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="cli" "hkey"="HKLM" "command"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="atiptaxx" "hkey"="HKLM" "command"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CTDetect" "hkey"="HKCU" "command"="C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe /R" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CU1] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="VCClient" "hkey"="HKCU" "command"="C:\\Program Files\\Common Files\\VCClient\\VCClient.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CU2] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="VCMain" "hkey"="HKCU" "command"="C:\\Program Files\\Common Files\\VCClient\\VCMain.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="daemon" "hkey"="HKLM" "command"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMOFFICE4DMOUSE] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="moffice" "hkey"="HKLM" "command"="C:\\Program Files\\Labtec\\moffice.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HPWuSchd2" "hkey"="HKLM" "command"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\klop] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="30" "hkey"="HKCU" "command"="C:\\WINDOWS\\30.tmp" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="msmsgs" "hkey"="HKCU" "command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="nwiz" "hkey"="HKLM" "command"="nwiz.exe /install" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="mssysmgr" "hkey"="HKCU" "command"="C:\\PROGRA~1\\Ahead\\NEROPH~2\\data\\Xtras\\mssysmgr.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\POINTER] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="point32" "hkey"="HKLM" "command"="C:\\Program Files\\Microsoft Hardware\\Mouse\\point32.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pop-Up Stopper] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dpps2" "hkey"="HKLM" "command"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\dpps2.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QD FastAndSafe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="point32" "hkey"="HKLM" "command"="C:\\Program Files\\Microsoft Hardware\\Mouse\\point32.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RealPlay" "hkey"="HKLM" "command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PDVDServ" "hkey"="HKLM" "command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TeaTimer" "hkey"="HKCU" "command"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="" "hkey"="HKCU" "command"="" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="jusched" "hkey"="HKLM" "command"="C:\\Program Files\\Java\\jre1.5.0_01\\bin\\jusched.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dumprep 0 -u" "hkey"="HKLM" "command"="%systemroot%\\system32\\dumprep 0 -u" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="winampa" "hkey"="HKLM" "command"="C:\\Program Files\\Winamp\\winampa.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "FreezeScreenSaver"=dword:00000002 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Completion time: 07-01-08 18:32:29.18 C:\ComboFix.txt … 07-01-08 18:32 C:\ComboFix2.txt … 07-01-06 22:14 C:\ComboFix3.txt … 07-01-05 19:06

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI