This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help with ads.k8l.info . Please help :(

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

System: Running on windows XP version 5.1 with SP2 loaded

The results of hijackThis are shown below:

Logfile of HijackThis v1.99.1
Scan saved at 12:06:40 AM, on 12/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.soccernet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: 0 - {C2941232-6F95-4D41-6387-3B6C9FAF4ADD} - C:\Program Files\ComPlus Applications\lavukasyk.dll
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PID41IER.exe ] C:\WINDOWS\system32\PID41IER.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {3DB7E7DB-3781-4FF8-8147-42419DEA9F26} (Prizmax Control) - https://www.myboeingfleet.com/redars/servic…Plug-in-ext.exe
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Smart Viewer 7) - https://www.eservices-staero.com/Include/activexviewer.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O16 - DPF: {F9043C85-F6F2-101A-A3C9-08002B2F49FB} (Microsoft Common Dialog Control, version 6.0) - http://activex.microsoft.com/controls/vb5/comdlg32.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{61581366-7B0F-49B2-9520-3F2B909AE094}: NameServer = 202.156.1.68,202.156.1.48
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
Hello dude and Welcome to TomCoyote,

Please do the following:

STEP 1.
======
GMER
Please create a new subfolder in the Program Files folder called GMER. If you have an older version of GMER installed, you must delete it.
  • Download GMER and extract it to the C:\program files\GMER folder.
  • Please rename the GMER file
    Note: You can rename gmer.exe to anything you like as long as you keep the .exe ending.
    Run the Gmer.exe renamed program by double-clicking the executable file (gmer.exe) in Windows Explorer.
    You may be prompted to scan immediately if GMER detects rootkit activity.
  • If you are prompted to scan your system click "yes" to begin the scan.
  • If you are not prompted, Click the "Rootkit" tab, then click "Scan".
At the end of the scan, click "Copy" to copy the scan results to the clipboard. Then paste the results in a notepad file and also paste them back in your next reply.


Download this file – combofix.exe
and save it to your desktop. Also save the below command in Notepad as a text file so that you can copy/paste in safe mode.

"%userprofile%\desktop\combofix.exe" /wow

Boot into safe mode by tapping the F8 key just before Windows starts to load.

go to start –> run and copy/paste in the following:

"%userprofile%\desktop\combofix.exe" /wow

When finished, it shall produce a log for you. Save it and post that log in your next reply.

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

In your next post, please include
  • the results from the GMER scan
  • combofix log
  • new hijackthis log
*use separate posts to ensure the logs don't get cut off!
Hi Susan, Thank you so much for your quick response. However I am unable to post a new reply to show you my Gmer scan log. A microsoft internet explorer dialog box pop-up saying that the maximum allowed length is 102400 characters. Current Characters 171894. What should I do in order to post the results to show you?????
Here is the results of my combofix log as requested: "KeLviN" - 07-01-12 23:38:29 Service Pack 2 ComboFix 07-01-10 - Running from: "C:\Documents and Settings\KeLviN\desktop" Command switches used :: /wow ((((((((((((((((((((((((((((((( Files Created from 2006-12-12 to 2007-01-12 )))))))))))))))))))))))))))))))))) 2007-01-12 22:54 d——– C:\Program Files\GMER 2007-01-12 22:53 80 –a—— C:\WINDOWS\gmer_uninstall.cmd 2007-01-11 23:05 d——– C:\WINDOWS\system32\ActiveScan 2007-01-03 23:31 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy 2007-01-03 20:02 d——– C:\Program Files\Yahoo! 2007-01-03 19:09 d——– C:\DOCUME~1\KeLviN\Application Data\System Restore 2006-12-28 00:26 223,128 –a—— C:\WINDOWS\system32\drivers\vaxscsi.sys 2006-12-27 22:08 12,928 –a—— C:\WINDOWS\system32\drivers\filedisk.sys 2006-12-27 21:47 223,128 –a—— C:\WINDOWS\system32\drivers\dtscsi.sys 2006-12-27 21:40 d——– C:\DVDShrink 2006-12-27 21:39 5,600 –a—— C:\WINDOWS\system\WINASPI.DLL 2006-12-27 21:39 45,056 –a—— C:\WINDOWS\system32\WNASPI32.DLL 2006-12-27 21:39 4,672 –a—— C:\WINDOWS\system\WOWPOST.EXE 2006-12-27 21:39 25,244 –a—— C:\WINDOWS\system32\drivers\ASPI32.SYS 2006-12-27 21:21 d——– C:\DOCUME~1\KeLviN\Application Data\SlySoft (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-01-12 23:37 ——– d——– C:\DOCUME~1\KeLviN\Application Data\utorrent 2007-01-03 19:25 ——– d——– C:\DOCUME~1\KeLviN\Application Data\lavasoft 2006-12-27 21:20 40 —hs—- C:\DOCUME~1\KeLviN\Application Data\.zreglib 2006-12-08 00:05 639224 –a—— C:\WINDOWS\system32\drivers\sptd.sys 2006-12-07 14:40 2362184 –a—— C:\WINDOWS\system32\wmvcore.dll 2006-11-08 13:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll 2006-10-19 21:56 713216 –a—— C:\WINDOWS\system32\sxs.dll 2006-10-13 20:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe" "PID41IER.exe "="C:\\WINDOWS\\system32\\PID41IER.exe " [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "PaperPort PTD"="C:\\Program Files\\ScanSoft\\PaperPort\\pptd40nt.exe" "IndexSearch"="C:\\Program Files\\ScanSoft\\PaperPort\\IndexSearch.exe" "SetDefPrt"="C:\\Program Files\\Brother\\Brmfl04a\\BrStDvPt.exe" "ControlCenter2.0"="C:\\Program Files\\Brother\\ControlCenter2\\brctrcen.exe /autorun" "AVG7_CC"="D:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "iTunesHelper"="\"D:\\Program Files\\iTunes\\iTunesHelper.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "PCSuiteTrayApplication"="D:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -startup" "MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk" "backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE " "item"="Adobe Reader Speed Launch" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk" "backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\MICROS~2\\Office\\OSA9.EXE -b -l" "item"="Microsoft Office" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="iTunesHelper" "hkey"="HKLM" "command"="\"D:\\Program Files\\iTunes\\iTunesHelper.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\leci] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="leci" "hkey"="HKLM" "command"="C:\\WINDOWS\\$NtUninstallKB905414$\\leci.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NeroCheck" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\NeroCheck.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rejififa] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="rejififa" "hkey"="HKLM" "command"="C:\\WINDOWS\\$NtUninstallKB910437$\\rejififa.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PDVDServ" "hkey"="HKLM" "command"="\"d:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SOUNDMAN" "hkey"="HKLM" "command"="SOUNDMAN.EXE" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SSBkgdupdate" "hkey"="HKLM" "command"="\"C:\\Program Files\\Common Files\\Scansoft Shared\\SSBkgdUpdate\\SSBkgdupdate.exe\" -Embedding -boot" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="jusched" "hkey"="HKLM" "command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe" "inimapping"="0" [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "AVG7_Run"="D:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "AVG7_Run"="D:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 Usnsvc REG_MULTI_SZ usnsvc\0\0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{355e9941-a890-11da-85ba-806d6172696f}] Shell\AutoRun\command E:\ASUSACPI.exe Completion time: 07-01-12 23:38:47
Susan, here is the new hijackthis log as requested:

Logfile of HijackThis v1.99.1
Scan saved at 11:41:05 PM, on 12/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: 0 - {C2941232-6F95-4D41-6387-3B6C9FAF4ADD} - C:\Program Files\ComPlus Applications\lavukasyk.dll
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PID41IER.exe ] C:\WINDOWS\system32\PID41IER.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {3DB7E7DB-3781-4FF8-8147-42419DEA9F26} (Prizmax Control) - https://www.myboeingfleet.com/redars/servic…Plug-in-ext.exe
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Smart Viewer 7) - https://www.eservices-staero.com/Include/activexviewer.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O16 - DPF: {F9043C85-F6F2-101A-A3C9-08002B2F49FB} (Microsoft Common Dialog Control, version 6.0) - http://activex.microsoft.com/controls/vb5/comdlg32.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{61581366-7B0F-49B2-9520-3F2B909AE094}: NameServer = 202.156.1.68,202.156.1.48
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

A microsoft internet explorer dialog box pop-up saying that the maximum allowed length is 102400 characters. Current Characters 171894.


So GMER ran and gave you huge log and you cannot post it all? Can you split it up and post it in serveral replies?

Also can you tell me anything about this file?

C:\WINDOWS\system32\PID41IER.exe

Please show all files for your system.
You will need to reverse this process when all steps are done.


Submit File to Jotti
Please click on Jotti
Use the "Browse" button and locate the following file on your computer:
C:\WINDOWS\system32\PID41IER.exe
Click the "Submit" button.
Please copy and post (reply) with the results

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html

Please also check the properties of those files (right-click and select properties from the popupmenu). Look if you can find some company information, etc.
Hi susan this is the first part of the GMer log. Second part of the GMER log to follow. Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 89AE2980 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 89AE2980 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 89AE2980 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 89AE2980 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 89AE2980 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 89AE2980 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 89AE2980 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 89AE2980 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 89AE2980 Device \Driver\00000034 \Device\00000044 IRP_MJ_POWER [BA6DFD74] sptd.sys Device \Driver\00000034 \Device\00000044 IRP_MJ_SYSTEM_CONTROL [BA6F92A2] sptd.sys Device \Driver\00000034 \Device\00000044 IRP_MJ_PNP [BA6FA228] sptd.sys Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CREATE 89C09980 Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CLOSE 89C09980 Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 89C09980 Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C09980 Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_POWER 89C09980 Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 89C09980 Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_PNP 89C09980 Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_CREATE 89C546C0 Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_CLOSE 89C546C0 Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 89C546C0 Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C546C0 Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_POWER 89C546C0 Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 89C546C0 Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_PNP 89C546C0 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 89E521D8 Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 89E521D8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 89C47310 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 89C47310 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 89C47310 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 89C47310 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 89C47310 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 89C47310 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C47310 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 89C47310 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 89C47310 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 89C47310 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 89C47310 Device \Driver\nvata \Device\00000065 IRP_MJ_CREATE 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_CREATE_NAMED_PIPE 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_CLOSE 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_READ 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_WRITE 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_QUERY_INFORMATION 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_SET_INFORMATION 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_QUERY_EA 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_SET_EA 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_FLUSH_BUFFERS 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_QUERY_VOLUME_INFORMATION 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_SET_VOLUME_INFORMATION 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_DIRECTORY_CONTROL 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_FILE_SYSTEM_CONTROL 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_DEVICE_CONTROL 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_INTERNAL_DEVICE_CONTROL 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_SHUTDOWN 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_LOCK_CONTROL 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_CLEANUP 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_CREATE_MAILSLOT 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_QUERY_SECURITY 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_SET_SECURITY 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_POWER 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_SYSTEM_CONTROL 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_DEVICE_CHANGE 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_QUERY_QUOTA 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_SET_QUOTA 89E511D8 Device \Driver\nvata \Device\00000065 IRP_MJ_PNP 89E511D8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 89C47310 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 89C47310 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 89C47310 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 89C47310 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 89C47310 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 89C47310 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C47310 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 89C47310 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 89C47310 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 89C47310 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 89C47310 Device \Driver\nvata \Device\00000067 IRP_MJ_CREATE 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_CREATE_NAMED_PIPE 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_CLOSE 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_READ 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_WRITE 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_QUERY_INFORMATION 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_SET_INFORMATION 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_QUERY_EA 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_SET_EA 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_FLUSH_BUFFERS 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_QUERY_VOLUME_INFORMATION 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_SET_VOLUME_INFORMATION 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_DIRECTORY_CONTROL 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_FILE_SYSTEM_CONTROL 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_DEVICE_CONTROL 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_INTERNAL_DEVICE_CONTROL 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_SHUTDOWN 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_LOCK_CONTROL 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_CLEANUP 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_CREATE_MAILSLOT 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_QUERY_SECURITY 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_SET_SECURITY 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_POWER 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_SYSTEM_CONTROL 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_DEVICE_CHANGE 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_QUERY_QUOTA 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_SET_QUOTA 89E511D8 Device \Driver\nvata \Device\00000067 IRP_MJ_PNP 89E511D8 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 890C0980 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 890C0980 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 890C0980 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 890C0980 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 890C0980 Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 890C0980 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 890C0980 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 890C0980 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 890C0980 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 890C0980 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 890C0980 Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 890C0980 Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_CREATE 89C09980 Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_CLOSE 89C09980 Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL 89C09980 Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C09980 Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_POWER 89C09980 Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL 89C09980 Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_PNP 89C09980 Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_CREATE 89C546C0 Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_CLOSE 89C546C0 Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_DEVICE_CONTROL 89C546C0 Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C546C0 Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_POWER 89C546C0 Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_SYSTEM_CONTROL 89C546C0 Device \Driver\usbehci \Device\USBFDO-1 IRP_MJ_PNP 89C546C0 Device \Driver\nvata \Device\NvAta0 IRP_MJ_CREATE 89E511D8 Device \Driver\nvata \Device\NvAta0 IRP_MJ_CREATE_NAMED_PIPE 89E511D8 Device \Driver\nvata \Device\NvAta0 IRP_MJ_CLOSE 89E511D8 Device \Driver\nvata \Device\NvAta0 IRP_MJ_READ 89E511D8 Device \Driver\nvata \Device\NvAta0 IRP_MJ_WRITE 89E511D8 Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_INFORMATION 89E511D8 Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_INFORMATION 89E511D8 Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_EA 89E511D8 Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_EA 89E511D8 Device \Driver\nvata \Device\NvAta0 IRP_MJ_FLUSH_BUFFERS 89E511D8 Device \Driver\nvata \Device\NvAta0 IRP_MJ_QUERY_VOLUME_INFORMATION 89E511D8 Device \Driver\nvata \Device\NvAta0 IRP_MJ_SET_VOLUME_INFORMATION 89E511D8 Device \Driver\nvata \Device\NvAta0 IRP_MJ_DIRECTORY_CONTROL
This is the second part of the GMER log: Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 890A61D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_CREATE 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_CREATE_NAMED_PIPE 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_CLOSE 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_READ 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_WRITE 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_QUERY_INFORMATION 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_SET_INFORMATION 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_QUERY_EA 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_SET_EA 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_FLUSH_BUFFERS 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_QUERY_VOLUME_INFORMATION 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_SET_VOLUME_INFORMATION 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_DIRECTORY_CONTROL 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_FILE_SYSTEM_CONTROL 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_DEVICE_CONTROL 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_INTERNAL_DEVICE_CONTROL 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_SHUTDOWN 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_LOCK_CONTROL 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_CLEANUP 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_CREATE_MAILSLOT 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_QUERY_SECURITY 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_SET_SECURITY 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_POWER 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_SYSTEM_CONTROL 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_DEVICE_CHANGE 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_QUERY_QUOTA 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_SET_QUOTA 89E511D8 Device \Driver\nvata \Device\NvAta2 IRP_MJ_PNP 89E511D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 890A61D8 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 890A61D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 89E521D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 89E521D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 89E521D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 89E521D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 89E521D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 89E521D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 89E521D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 89E521D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 89E521D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 89E521D8 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 89E521D8 Device \Driver\NetBT \Device\NetBT_Tcpip_{61581366-7B0F-49B2-9520-3F2B909AE094} IRP_MJ_CREATE 890C0980 Device \Driver\NetBT \Device\NetBT_Tcpip_{61581366-7B0F-49B2-9520-3F2B909AE094} IRP_MJ_CLOSE 890C0980 Device \Driver\NetBT \Device\NetBT_Tcpip_{61581366-7B0F-49B2-9520-3F2B909AE094} IRP_MJ_DEVICE_CONTROL 890C0980 Device \Driver\NetBT \Device\NetBT_Tcpip_{61581366-7B0F-49B2-9520-3F2B909AE094} IRP_MJ_INTERNAL_DEVICE_CONTROL 890C0980 Device \Driver\NetBT \Device\NetBT_Tcpip_{61581366-7B0F-49B2-9520-3F2B909AE094} IRP_MJ_CLEANUP 890C0980 Device \Driver\NetBT \Device\NetBT_Tcpip_{61581366-7B0F-49B2-9520-3F2B909AE094} IRP_MJ_PNP 890C0980 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_CREATE 89B076F0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_CLOSE 89B076F0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_DEVICE_CONTROL 89B076F0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89B076F0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_POWER 89B076F0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_SYSTEM_CONTROL 89B076F0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 IRP_MJ_PNP 89B076F0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port3Path0Target0Lun0 IRP_MJ_CREATE 89B076F0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port3Path0Target0Lun0 IRP_MJ_CLOSE 89B076F0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port3Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 89B076F0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port3Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89B076F0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port3Path0Target0Lun0 IRP_MJ_POWER 89B076F0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port3Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 89B076F0 Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port3Path0Target0Lun0 IRP_MJ_PNP 89B076F0 Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_READ 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP 89AE2980 Device \FileSystem\Fastfat \Fat IRP_MJ_PNP 89AE2980 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 89B09418 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 89B09418 Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 89B09418 Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 89B09418 Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 89B09418 Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 89B09418 Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 89B09418 Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 89B09418 Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 89B09418 Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 89B09418 Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 89B09418 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 89B09418 Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 89B09418 —- Files - GMER 1.0.12 —- ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\01\10-{8747E020-EF84-530F-BCF2-157D50CDC803}-v1-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\02\202-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v202-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v202-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\11\11-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v11-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\12\239-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v12-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v239-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\12\239-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v12-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v239-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\12\239-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v12-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v239-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\13\13-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v13-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\13\13-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v13-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\13\13-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v13-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\14\14-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v14-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\14\14-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v14-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\14\14-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v14-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\15\15-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v15-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\15\15-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v15-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\15\15-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v15-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\15\215-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v215-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v215-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\16\16-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v16-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v16-Down
Hi Susan, the iwerd thing is I have followed your steps to show all hidden files and folders. However, I couldn't locate the C:\WONDOWS\system32\PID41PER.exe. Instead I use to windows search funtion and found 2 files to be in C:\WINDOWS\Prefetch\PID41IER.EXE-18D9EB8E.pf and C:\WINDOWS\Prefetch\PID41IER.EXE-21FA56DF.pf. I have run the Jotti program and here are the results: File: PID41IER.EXE-18D9EB8E.pf Status: OK MD5 1068f78850b6e692d270bf436d2e9e4e Packers detected: - Scan taken on 14 Jan 2007 16:06:23 (GMT) AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing VirusBuster Found nothing VBA32 Found nothing File: PID41IER.EXE-21FA56DF.pf Status: OK MD5 2862b5845e1c97c075cc4a2887ae0f4d Packers detected: - AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing VirusBuster Found nothing VBA32 Found nothing
as requested this are the description for each files. One thing to note is that the time and date of these files creation happens to be the first attack of spyware for my computer.

PID41IER.EXE-18D9EB8E.pf
Type of file: pf file
Opens with: unkown application
Location: C:\WINDOWS\Prefetch
Size 21.4 KB
Size on disk 24 KB

PID41IER.EXE-21FA56DF.pf
Type of file: pf file
Opens with: unkown application
Location: C:\WINDOWS\Prefetch
Size 21.4 KB
Size on disk 24 KB
Your GMER scan was cut off. I was interested in seeing the end to make sure I did not miss anything.

STEP 1.
======
Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


This scan works with Internet Explorer.
======
Panda Active Scan
Please go to Panda ActiveScan.
Once you are on the Panda site click the Scan your PC button
A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on Local Disks to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log, by using Add Reply.

Let us know if any problems persist.
hi Susan, sorry for that truncated GMER log that I've sent you. The last bit of the GMER log is as such, just for your confirmation: ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\01\10-{8747E020-EF84-530F-BCF2-157D50CDC803}-v1-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\02\202-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v202-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v202-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\11\11-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v11-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\12\239-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v12-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v239-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\12\239-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v12-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v239-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\12\239-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v12-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v239-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\13\13-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v13-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\13\13-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v13-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\13\13-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v13-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\14\14-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v14-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\14\14-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v14-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\14\14-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v14-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\15\15-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v15-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\15\15-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v15-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\15\15-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v15-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\15\215-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v215-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v215-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\16\16-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v16-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\16\16-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v16-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\16\16-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v16-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\16\216-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v216-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v216-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\17\17-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v17-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\17\17-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v17-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\17\17-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v17-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\17\217-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v217-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v217-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\18\18-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v18-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\18\18-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v18-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\18\18-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v18-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\18\218-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v218-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v218-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\19\19-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v19-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\19\19-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v19-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\19\19-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v19-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\19\219-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v219-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v219-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\20\20-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v20-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\20\20-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v20-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\20\20-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v20-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\20\220-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v220-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v220-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\21\21-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v21-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\21\21-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v21-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\21\21-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v21-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\21\221-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v221-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v221-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\22\22-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v22-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\22\22-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v22-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\22\22-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v22-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\22\222-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v222-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v222-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\23\223-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v223-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v223-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\23\223-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v223-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v223-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\23\223-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v223-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v223-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\24\224-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v224-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v224-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\24\224-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v224-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v224-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\24\224-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v224-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v224-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\24\24-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v24-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\24\24-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v24-{2852E44F-8A96-413D-B513-453FDF2ABC82}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\25\225-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v225-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v225-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\26\226-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v226-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v226-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\26\226-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v226-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v226-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\26\226-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v226-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v226-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\27\227-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v227-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v227-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\28\228-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v228-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v228-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\32\232-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v232-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v232-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\33\233-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v233-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v233-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\34\234-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v234-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v234-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\35\235-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v235-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v235-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\36\236-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v236-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v236-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\37\237-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v237-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v237-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\38\238-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v238-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v238-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\90\190-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v190-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v190-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\KeLviN\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{8747E020-EF84-530F-BCF2-157D50CDC803}\91\191-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v191-{41790A55-61FB-49C7-8C9B-BFDE72F8C403}-v191-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS —- EOF - GMER 1.0.12 —-
Hi Susan, Ive download the Activescan and this is the result:


Incident Status Location

Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\KeLviN\Cookies\[removed][1].txt

The later I ran Hijackthis and this is the result:

Logfile of HijackThis v1.99.1
Scan saved at 12:34:54 AM, on 16/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: 0 - {C2941232-6F95-4D41-6387-3B6C9FAF4ADD} - C:\Program Files\ComPlus Applications\lavukasyk.dll
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PID41IER.exe ] C:\WINDOWS\system32\PID41IER.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {3DB7E7DB-3781-4FF8-8147-42419DEA9F26} (Prizmax Control) - https://www.myboeingfleet.com/redars/servic…Plug-in-ext.exe
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Smart Viewer 7) - https://www.eservices-staero.com/Include/activexviewer.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O16 - DPF: {F9043C85-F6F2-101A-A3C9-08002B2F49FB} (Microsoft Common Dialog Control, version 6.0) - http://activex.microsoft.com/controls/vb5/comdlg32.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{61581366-7B0F-49B2-9520-3F2B909AE094}: NameServer = 202.156.1.68,202.156.1.48
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
Can you tell me anything about the lavukasyk.dll file? Do you have any ComPlus Applications?

O2 - BHO: 0 - {C2941232-6F95-4D41-6387-3B6C9FAF4ADD} - C:\Program Files\ComPlus Applications\lavukasyk.dll

STEP 1.
======
Please show all files for your system.
You will need to reverse this process when all steps are done.


Submit File to Jotti
Please click on Jotti
Use the "Browse" button and locate the following file on your computer:
C:\Program Files\ComPlus Applications\lavukasyk.dll
Click the "Submit" button.
Please copy and post (reply) with the results

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html

Please also check the properties of those files (right-click and select properties from the popupmenu). Look if you can find some company information, etc.

STEP 2.
======
Combofix
  • You can skip the download if you still have the ComboFix.
  • Download this file - combofix.exe
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Please let me know about the ComPlus Applications and post(reply) with the results from Jotti, the ComboFix log and a new hijackthis log.
Hi Susan, What is a complus application? What are examples of common complus applications? As is, I don't know anything about lavukasyk.dll file, as well. :( Anyway, will run the following steps you've mentioned in the above reply when i get back from work ;) Will post reply as soon as i get the results. Thank you so much, you've been a great help thus far. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI