This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HELP on Trojan! HJT + Kaspersky + Virustotal log attached

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I've run numerous anti-virus/anti-spyware scans using different applications. Some of them can detect the Trojan, but none can't remove them. Done all the safe mode drills, but no luck. Below is the HJT, Kaspersky log and the VirusTotal scan on "cryptig.dll" (sorry for the long logs).

I shall greatly appreciate any help you can offer to help remove these pests!

HJT
Logfile of HijackThis v1.99.1
Scan saved at 10:35:53 AM, on 2/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Upromise\UpromiseUa.exe
C:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Upromise\Upromise.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Helen Lo\Desktop\Downloads\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn4\YTBSDK.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
c:\progra~1\common~1\instal~1\update~1\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
R3 - URLSearchHook: 9ff1 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\46ccntos.dll (file missing)
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: (no name) - {080f7380-a9d3-4332-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {183cf35a-28ed-465c-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {194dc876-57b3-4d30-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {2ba179a6-3b24-4aeb-8b0d-4e03f37a8dbf} - C:\WINDOWS\system32\4aebcfsb.dll (file missing)
O2 - BHO: (no name) - {2cb9a226-a529-4dce-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {33b8743f-0fb6-461a-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {37769aa7-6e1c-404b-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {3b76bc6d-d481-499f-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {59eb8c0c-9bdd-498e-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {59ebc65e-fdb2-467c-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: NewsWatch Class - {6BD97C5B-7A34-4AE9-8B0D-4E03F37A8DBF} - C:\WINDOWS\system32\4aebcfsb.dll (file missing)
O2 - BHO: (no name) - {8742da56-a326-4f54-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {87aefb91-f3d3-44d3-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9d9fdd44-3beb-4b32-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {c5973ee3-06e6-4f8c-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {d7c0faf2-e11a-4cab-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: 9ff1 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\46ccntos.dll (file missing)
O2 - BHO: (no name) - {e5e99b38-ea7f-477b-8b0d-4e03f37a8dbf} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O3 - Toolbar: 9ff1 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\46ccntos.dll (file missing)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Upromise] C:\Program Files\Upromise\Upromise.exe
O4 - HKCU\..\Run: [Upromise Update] C:\Program Files\Upromise\UpromiseUa.exe
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O9 - Extra 'Tools' menuitem: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptimg.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Kaspersky:
Wednesday, February 07, 2007 10:17:01 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 6/02/2007
Kaspersky Anti-Virus database records: 265512


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\

Scan Statistics
Total number of scanned objects 93065
Number of viruses found 7
Number of infected objects 14 / 0
Number of suspicious objects 0
Duration of the scan process 03:21:43

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.wid Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.wid Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.wid Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wid Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010007.wid Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010008.wid Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.ci Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wsb Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy2.gthr Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf1.tmp Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf2.tmp Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Perflib_Perfdata_3bc.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-01272007-014715.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-02-06_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\533F39D0.TMP Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\B81A79CE.TMP Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\DC9EB453.TMP Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SubEng\submissions.idx Object is locked skipped

C:\Documents and Settings\Helen Lo\Application Data\Mozilla\Firefox\Profiles\nofyi6q8.default\cert8.db Object is locked skipped

C:\Documents and Settings\Helen Lo\Application Data\Mozilla\Firefox\Profiles\nofyi6q8.default\flashgot.log Object is locked skipped

C:\Documents and Settings\Helen Lo\Application Data\Mozilla\Firefox\Profiles\nofyi6q8.default\formhistory.dat Object is locked skipped

C:\Documents and Settings\Helen Lo\Application Data\Mozilla\Firefox\Profiles\nofyi6q8.default\history.dat Object is locked skipped

C:\Documents and Settings\Helen Lo\Application Data\Mozilla\Firefox\Profiles\nofyi6q8.default\key3.db Object is locked skipped

C:\Documents and Settings\Helen Lo\Application Data\Mozilla\Firefox\Profiles\nofyi6q8.default\parent.lock Object is locked skipped

C:\Documents and Settings\Helen Lo\Application Data\Mozilla\Firefox\Profiles\nofyi6q8.default\search.sqlite Object is locked skipped

C:\Documents and Settings\Helen Lo\Application Data\Mozilla\Firefox\Profiles\nofyi6q8.default\urlclassifier2.sqlite Object is locked skipped

C:\Documents and Settings\Helen Lo\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped

C:\Documents and Settings\Helen Lo\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Helen Lo\Desktop\Downloads\AlexaInstaller.exe/data0008 Infected: not-a-virus:AdWare.Win32.AlexaBar.j skipped

C:\Documents and Settings\Helen Lo\Desktop\Downloads\AlexaInstaller.exe/data0009 Infected: not-a-virus:AdWare.Win32.AlexaBar.j skipped

C:\Documents and Settings\Helen Lo\Desktop\Downloads\AlexaInstaller.exe NSIS: infected - 2 skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\pending.dat Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_1234_9971_3499_5895\dfsr.db Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_1234_9971_3499_5895\fsr.log Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_1234_9971_3499_5895\fsrtmp.log Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_1234_9971_3499_5895\tmp.edb Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{E6B41555-69FE-48AA-AAE1-B4126EB6C243} Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\real\members.stg Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\shadow\members.stg Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Mozilla\Firefox\Profiles\nofyi6q8.default\Cache\_CACHE_001_ Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Mozilla\Firefox\Profiles\nofyi6q8.default\Cache\_CACHE_002_ Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Mozilla\Firefox\Profiles\nofyi6q8.default\Cache\_CACHE_003_ Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Application Data\Mozilla\Firefox\Profiles\nofyi6q8.default\Cache\_CACHE_MAP_ Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temp\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temp\hijackthis\backups\backup-20070127-011940-648.dll Infected: not-a-virus:AdWare.Win32.Agent.bk skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temp\hijackthis\backups\backup-20070127-012222-828.dll Infected: not-a-virus:AdWare.Win32.Agent.bk skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temp\Perflib_Perfdata_b78.dat Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temp\Perflib_Perfdata_c44.dat Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temp\scfile.exe Infected: not-a-virus:RiskTool.Win32.DecFile.a skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temp\~DF2589.tmp Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temp\~DFC988.tmp Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temp\~DFCD64.tmp Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temp\~DFEF74.tmp Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temp\~DFEFC1.tmp Object is locked skipped

C:\Documents and Settings\Helen Lo\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Helen Lo\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Helen Lo\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped

C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped

C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped

C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped

C:\Program Files\PC Tools AntiVirus\PCTAVService.txt Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\DEFAULT Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SYSTEM Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\cryptig.dll Infected: Trojan.Win32.Agent.afb skipped

C:\WINDOWS\system32\cryptimg.dll Infected: Trojan.Win32.Agent.afb skipped

C:\WINDOWS\system32\dqojq.dll Infected: Trojan-Downloader.Win32.QQHelper.ko skipped

C:\WINDOWS\system32\drivers\acpidisk.sys Infected: not-a-virus:AdWare.Win32.Cinmus.j skipped

C:\WINDOWS\system32\drivers\ast.sys Infected: not-a-virus:AdWare.Win32.Agent.bk skipped

C:\WINDOWS\system32\drivers\ffpbek.sys Infected: Trojan-Downloader.Win32.Agent.bcc skipped

C:\WINDOWS\system32\drivers\ws2ifsd.sys Infected: Trojan.Win32.Agent.afb skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\vurbk.dll Infected: Trojan-Downloader.Win32.QQHelper.ko skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.



VirusTotal:
Complete scanning result of "cryptig.dll", received in VirusTotal at 02.06.2007, 17:55:37 (CET).

Antivirus Version Update Result
AntiVir 7.3.1.34 02.06.2007 TR/Dldr.Boodo.2
Authentium 4.93.8 02.06.2007 no virus found
Avast 4.7.936.0 02.06.2007 no virus found
AVG 386 02.06.2007 no virus found
BitDefender 7.2 02.05.2007 no virus found
CAT-QuickHeal 9.00 02.06.2007 no virus found
ClamAV devel-20060426 02.06.2007 no virus found
DrWeb 4.33 02.06.2007 no virus found
eSafe 7.0.14.0 02.06.2007 no virus found
eTrust-InoculateIT 30.4.3372 02.06.2007 no virus found
eTrust-Vet 30.4.3372 02.06.2007 no virus found
Ewido 4.0 02.06.2007 no virus found
Fortinet 2.85.0.0 02.06.2007 no virus found
F-Prot 4.2.1.29 02.06.2007 no virus found
Ikarus T3.1.0.31 02.06.2007 no virus found
Kaspersky 4.0.2.24 02.06.2007 Trojan.Win32.Agent.afb
McAfee 4956 02.05.2007 no virus found
Microsoft 1.2101 02.06.2007 no virus found
NOD32v2 2040 02.06.2007 no virus found
Norman 5.80.02 02.06.2007 no virus found
Panda 9.0.0.4 02.06.2007 Suspicious file
Prevx1 V2 02.06.2007 no virus found
Sophos 4.13.0 02.05.2007 no virus found
Sunbelt 2.2.907.0 02.02.2007 no virus found
Symantec 10 02.06.2007 no virus found
TheHacker 6.1.6.052 02.05.2007 no virus found
UNA 1.83 02.06.2007 no virus found
VBA32 3.11.2 02.06.2007 no virus found
VirusBuster 4.3.19:9 02.06.2007 no virus found

Aditional Information
File size: 191488 bytes
MD5: 870675643966dd4820555acf91f54ecd
SHA1: 550d25bd58dcb2b8d151e75afb7686a32499b724
I just ran ComboFix after reading other posts. Here's the log. Please help. Thanks!



"Helen Lo" - 07-02-07 13:51:57 Service Pack 2
ComboFix 07-02-07 - Running from: "C:\Program Files\Mozilla Firefox"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\Helen Lo\Local Settings\Temp\Temporary Internet Files\Content.IE5\1DD26XH3\cnsminex_empty[1].htm
C:\Documents and Settings\Helen Lo\My Documents\Past -HK\Chung Nam Securities\ACB\CNS Minutes 070299.doc
C:\Documents and Settings\Helen Lo\My Documents\Qzone\Past\Chung Nam Securities\ACB\CNS Minutes 070299.doc
C:\WINDOWS\system32\dqojq.dll
C:\WINDOWS\system32\vurbk.dll
C:\WINDOWS\system32\drivers\gajxpyd.sys
C:\WINDOWS\system32\gajxpyd.dll
C:\WINDOWS\system32\drivers\lh_fks.sys
C:\WINDOWS\system32\lh_fks.dll
C:\WINDOWS\system32\drivers\wozupvcu.sys
C:\WINDOWS\system32\lh_fks.dll
C:\WINDOWS\system32\drivers\lh_fks.sys
C:\WINDOWS\system32\nxhp_s.dll
C:\WINDOWS\system32\pcif_j.dll
C:\WINDOWS\system32\advport.dll
C:\WINDOWS\system32\drivers\acpidisk.sys
C:\WINDOWS\system32\dsfhw.dll
C:\WINDOWS\system32\dsssvc.dll
C:\WINDOWS\system32\googleTool.dll
C:\WINDOWS\system32\mprmsgse.axz
C:\WINDOWS\system32\mscpx32r.det
C:\WINDOWS\system32\ncxml.dll
C:\WINDOWS\system32\popfiles.ini
C:\WINDOWS\system32\toolset.ini
C:\WINDOWS\system32\winttrs
C:\WINDOWS\AppPatch\AcJava.sdb
C:\WINDOWS\Debug\bmhrt.log
C:\WINDOWS\Help\bredsk.CNT
C:\WINDOWS\Help\starter\help.htm
C:\WINDOWS\Help\WMSDK.OEM
C:\WINDOWS\inf\1394dbg.inf
C:\WINDOWS\REGEDIT.com
C:\Program Files\OpenSource
C:\WINDOWS\system32\ContentTemp
C:\WINDOWS\system32\drivers\txvvmbl.sys
C:\WINDOWS\system32\txvvmbl.dll
C:\WINDOWS\system32\ym_ezw.dll
C:\WINDOWS\system32\drivers\ym_ezw.sys
C:\WINDOWS\system32\cryptig.dll
C:\WINDOWS\system32\cryptimg.dll
C:\WINDOWS\system32\drivers\ast.sys
C:\WINDOWS\system32\drivers\AST.sys
C:\WINDOWS\system32\drivers\ffpbek.sys
C:\WINDOWS\system32\drivers\fsb.sys
C:\WINDOWS\system32\drivers\MSUSBBUX.sys
C:\WINDOWS\system32\drivers\wspipe.sys
C:\WINDOWS\system32\ntxml.dll
C:\WINDOWS\system32\umtcap.dll


((((((((((((((((((((((((((((((( Files Created from 2007-01-07 to 2007-02-07 ))))))))))))))))))))))))))))))))))


2007-02-07 14:03 d——– C:\WINDOWS\ERDNT
2007-02-07 01:00 31,912 –a—— C:\symlcsv1.exe
2007-02-06 21:19 24,576 –a—— C:\WINDOWS\system32\4cabcfsb.dll
2007-02-06 00:21 d——– C:\Program Files\Enigma Software Group
2007-02-05 23:31 24,576 –a—— C:\WINDOWS\system32\499fcfsb.dll
2007-02-05 16:28 d——– C:\Program Files\GiPo@Utilities
2007-02-05 16:28 d——– C:\Program Files\Common Files\Gibinsoft Shared
2007-02-05 15:47 10,752 –a—— C:\WINDOWS\system32\drivers\ws2ifsd.sys
2007-02-05 15:41 24,576 –a—— C:\WINDOWS\system32\44d3cfsb.dll
2007-02-05 00:52 dr-h—– C:\$VAULT$.AVG
2007-02-04 14:56 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-02-04 14:49 12,292,479 ——— C:\AVG7QT.DAT
2007-02-04 14:41 d——– C:\DOCUME~1\HELENL~1\Application Data\AVG7
2007-02-04 14:37 d——– C:\DOCUME~1\LOCALS~1\Application Data\AVG7
2007-02-04 14:36 816,672 –a—— C:\WINDOWS\system32\drivers\avg7core.sys
2007-02-04 14:36 4,960 –a—— C:\WINDOWS\system32\drivers\avgtdi.sys
2007-02-04 14:36 4,224 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys
2007-02-04 14:36 3,968 –a—— C:\WINDOWS\system32\drivers\avgclean.sys
2007-02-04 14:36 28,416 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys
2007-02-04 14:36 18,240 –a—— C:\WINDOWS\system32\drivers\avgmfx86.sys
2007-02-04 14:35 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Grisoft
2007-02-04 14:35 d——– C:\DOCUME~1\ALLUSE~1\Application Data\avg7
2007-02-04 14:26 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-04 14:25 d——– C:\Program Files\Grisoft
2007-02-03 20:47 d——– C:\DOCUME~1\ADMINI~1.D9Y\Application Data\Simply Super Software
2007-02-03 20:44 1,048,576 –ah—– C:\DOCUME~1\ADMINI~1.D9Y\NTUSER.DAT
2007-02-03 20:44 d–h—– C:\DOCUME~1\ADMINI~1.D9Y\Application Data\Gtek
2007-02-03 20:44 d——– C:\DOCUME~1\ADMINI~1.D9Y\Application Data\Symantec
2007-02-03 20:44 d——– C:\DOCUME~1\ADMINI~1.D9Y\Application Data\Sun
2007-02-03 20:44 d——– C:\DOCUME~1\ADMINI~1.D9Y\Application Data\Jasc Software Inc
2007-02-03 20:44 d——– C:\DOCUME~1\ADMINI~1.D9Y\Application Data\Intel
2007-02-03 08:53 75,264 –a—— C:\WINDOWS\system32\unacev2.dll
2007-02-03 08:53 153,088 –a—— C:\WINDOWS\system32\UNRAR3.dll
2007-02-03 08:53 d——– C:\Program Files\Trojan Remover
2007-02-03 08:53 d——– C:\DOCUME~1\HELENL~1\Application Data\Simply Super Software
2007-02-01 15:45 d——– C:\DOCUME~1\Owner\Application Data\Intel
2007-02-01 15:45 d——– C:\DOCUME~1\NETWOR~1\Application Data\Intel
2007-02-01 15:45 d——– C:\DOCUME~1\LOCALS~1\Application Data\Intel
2007-02-01 15:44 21,425 –a—— C:\WINDOWS\system32\drivers\AegisP.sys
2007-02-01 15:37 557,056 –a—— C:\WINDOWS\system32\Netw2c32.dll
2007-02-01 15:37 2,732,032 –a—— C:\WINDOWS\system32\Netw2r32.dll
2007-02-01 15:35 d——– C:\DOCUME~1\QBDATA~1\Application Data\Intel
2007-02-01 15:35 d——– C:\DOCUME~1\DEFAUL~1\Application Data\Intel
2007-02-01 15:35 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Intel
2007-02-01 15:35 d——– C:\DOCUME~1\ADMINI~1\Application Data\Intel
2007-02-01 15:29 d——– C:\DOCUME~1\HELENL~1\Application Data\Intel
2007-02-01 15:25 d——– C:\Intel
2007-02-01 08:04 66,048 –a—— C:\WINDOWS\ieResetIcons.exe
2007-02-01 01:51 d——– C:\Program Files\Rankbooster
2007-01-31 01:00 d——– C:\DOCUME~1\HELENL~1\Contacts
2007-01-31 00:44 d——– C:\Program Files\Norton Internet Security
2007-01-31 00:41 48,776 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-01-31 00:41 115,000 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-01-30 23:12 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-01-30 19:46 178,408 –a—— C:\WINDOWS\system32\muweb.dll
2007-01-28 10:18 d——– C:\DOCUME~1\ALLUSE~1\Application Data\SUPERAntiSpyware.com
2007-01-27 20:40 d——– C:\DOCUME~1\HELENL~1\Application Data\NewSoft
2007-01-27 14:31 d——– C:\Program Files\SUPERAntiSpyware
2007-01-27 14:31 d——– C:\DOCUME~1\HELENL~1\Application Data\SUPERAntiSpyware.com
2007-01-27 14:20 22,528 –a—— C:\WINDOWS\system32\drivers\AVHook.sys
2007-01-27 14:20 15,872 –a—— C:\WINDOWS\system32\drivers\AVRec.sys
2007-01-27 14:20 15,360 –a—— C:\WINDOWS\system32\drivers\AVFilter.sys
2007-01-27 14:20 d——– C:\Program Files\PC Tools AntiVirus
2007-01-27 14:20 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-01-27 14:20 d——– C:\Program Files\Common Files\PC Tools
2007-01-27 14:20 d——– C:\DOCUME~1\ALLUSE~1\Application Data\PC Tools
2007-01-27 11:19 d——– C:\Program Files\sina
2007-01-27 01:45 d——– C:\Program Files\Windows Defender
2007-01-27 00:49 d——– C:\Program Files\CEZEO software
2007-01-26 12:45 d——– C:\DOCUME~1\LOCALS~1\Application Data\PC Tools
2007-01-26 00:17 51,072 –a—— C:\WINDOWS\system32\drivers\ikhlayer.sys
2007-01-26 00:17 30,592 –a—— C:\WINDOWS\system32\drivers\ikhfile.sys
2007-01-26 00:17 d-a—— C:\DOCUME~1\ALLUSE~1\Application Data\TEMP
2007-01-26 00:16 d——– C:\Program Files\Spyware Doctor
2007-01-26 00:16 d——– C:\DOCUME~1\HELENL~1\Application Data\PC Tools
2007-01-25 22:21 d——– C:\Program Files\Uniblue
2007-01-25 22:01 d——– C:\DOCUME~1\HELENL~1\Application Data\Uniblue
2007-01-24 20:00 0 –a—— C:\WINDOWS\system32\SBRC.dat
2007-01-24 20:00 0 –a—— C:\WINDOWS\system32\SBFC.dat
2007-01-24 01:48 d——– C:\DOCUME~1\LOCALS~1\Application Data\yahoo!
2007-01-23 23:33 28,672 –a—— C:\WINDOWS\mstrandom.exe
2007-01-23 23:32 135,168 –a—— C:\WINDOWS\msvhpsp.exe
2007-01-23 23:12 d——– C:\DOCUME~1\LOCALS~1\Application Data\Google
2007-01-22 12:11 529,792 –a—— C:\autoruns.exe
2007-01-22 12:11 447,872 –a—— C:\autorunsc.exe
2007-01-19 12:53 51,056 –a—— C:\WINDOWS\system32\sirenacm.dll
2007-01-18 19:24 d——– C:\Program Files\Upromise
2007-01-15 20:38 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Adobe
2007-01-12 18:01 276,792 –a—— C:\WINDOWS\system32\drivers\srtspl.sys
2007-01-12 18:01 25,400 –a—— C:\WINDOWS\system32\drivers\srtspx.sys
2007-01-12 18:01 247,608 –a—— C:\WINDOWS\system32\drivers\srtsp.sys
2007-01-11 21:03 d——– C:\WINDOWS\ie7updates
2007-01-08 14:42 d——– C:\DOCUME~1\HELENL~1\WINDOWS
2007-01-08 14:40 11,776 –a—— C:\WINDOWS\system32\pmsbfn32.dll
2007-01-08 14:39 d——– C:\Program Files\Common Files\PDFView
2007-01-08 14:38 d——– C:\WINDOWS\system32\color
2007-01-08 14:38 d——– C:\Program Files\NewSoft
2007-01-08 14:28 d——– C:\WINDOWS\StartHtmico
2007-01-08 14:27 d–h—– C:\WINDOWS\system32\CanonMP Uninstaller Information
2007-01-08 14:26 d–h—– C:\CanonMP
2007-01-08 11:07 2,560 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-01-08 11:07 2,432 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-02-07 13:49 ——– d——– C:\Program Files\mozilla firefox
2007-02-07 08:00 ——– d——– C:\Documents and Settings\Helen Lo\Application Data\avg7
2007-02-07 04:01 ——– d——– C:\Program Files\Common Files\symantec shared
2007-02-06 19:56 ——– d——– C:\Program Files\Common Files\intuit
2007-02-06 00:05 ——– d——– C:\Documents and Settings\Helen Lo\Application Data\skype
2007-02-03 08:53 ——– d——– C:\Documents and Settings\Helen Lo\Application Data\simply super software
2007-02-01 22:54 ——– d——– C:\Program Files\microsoft works
2007-02-01 15:29 ——– d——– C:\Documents and Settings\Helen Lo\Application Data\intel
2007-01-31 16:19 ——– d——– C:\Program Files\registry mechanic
2007-01-31 01:03 ——– d——– C:\Program Files\symantec
2007-01-30 23:36 ——– d——– C:\Program Files\msn messenger
2007-01-30 14:30 ——– d–h—– C:\Program Files\installshield installation information
2007-01-28 10:06 ——– d——– C:\Program Files\musicmatch
2007-01-28 10:03 ——– d——– C:\Program Files\yahoo!
2007-01-27 20:40 ——– d——– C:\Documents and Settings\Helen Lo\Application Data\newsoft
2007-01-27 14:39 ——– d——– C:\Documents and Settings\Helen Lo\Application Data\pc tools
2007-01-27 14:31 ——– d——– C:\Documents and Settings\Helen Lo\Application Data\superantispyware.com
2007-01-26 00:23 ——– d——– C:\Documents and Settings\Helen Lo\Application Data\uniblue
2007-01-25 22:41 ——– d——– C:\Program Files\plaxo
2007-01-25 21:34 ——– d——– C:\Documents and Settings\Helen Lo\Application Data\lavasoft
2007-01-25 09:54 ——– d——– C:\Program Files\quicktime
2007-01-25 09:48 ——– d——– C:\Program Files\apple software update
2007-01-18 16:51 ——– d——– C:\Program Files\google
2007-01-16 16:53 ——– d——– C:\Documents and Settings\Helen Lo\Application Data\canon
2007-01-15 20:31 ——– d——– C:\Documents and Settings\Helen Lo\Application Data\adobeum
2007-01-09 10:29 ——– d——– C:\Program Files\quicken
2007-01-08 15:08 ——– d——– C:\Program Files\canon
2007-01-08 11:07 ——– d——– C:\Program Files\picasa2
2006-12-10 23:05 ——– d——– C:\Program Files\java
2006-12-07 14:40 2362184 –a—— C:\WINDOWS\system32\wmvcore.dll
2006-11-28 17:12 3055 –a—— C:\WINDOWS\mozver.dat
2006-11-08 13:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll
2006-11-07 21:03 6049280 ——— C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50688 ——— C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458752 ——— C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 413696 ——— C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 ——— C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 180736 ——— C:\WINDOWS\system32\ieui.dll
2006-11-07 21:03 156160 ——— C:\WINDOWS\system32\msls31.dll
2006-11-07 14:05 796672 –a—— C:\WINDOWS\gpinstall.exe
2006-11-07 03:27 382976 ——— C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 ——— C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 ——— C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 ——— C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 ——— C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 ——— C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 ——— C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 13312 –a—— C:\WINDOWS\system32\ieudinit.exe
2006-11-07 03:26 123904 ——— C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 ——— C:\WINDOWS\system32\ieakui.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"FreeRAM XP"="\"C:\\Program Files\\YourWare Solutions\\FreeRAM XP Pro\\FreeRAM XP Pro.exe\" -win"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"Upromise"="C:\\Program Files\\Upromise\\Upromise.exe"
"Upromise Update"="C:\\Program Files\\Upromise\\UpromiseUa.exe"
"Spyware Doctor"="C:\\PROGRA~1\\SPYWAR~1\\swdoctor.exe /Q"
"SUPERAntiSpyware"="C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"PCTAVApp"="\"C:\\Program Files\\PC Tools AntiVirus\\PCTAV.exe\" /MONITORSCAN"
"UnlockerAssistant"="\"C:\\Program Files\\Unlocker\\UnlockerAssistant.exe\""
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
"IntelZeroConfig"="\"C:\\Program Files\\Intel\\Wireless\\bin\\ZCfgSvc.exe\""
"IntelWireless"="\"C:\\Program Files\\Intel\\Wireless\\Bin\\ifrmewrk.exe\" /tf Intel PROSet/Wireless"
"TrojanScanner"="C:\\Program Files\\Trojan Remover\\Trjscan.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\AutorunsDisabled]
@="blank"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
"flags"=dword:00000008

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex\000]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CardScan AutoSync"=""
"Internet Download Accelerator"="C:\\Program Files\\Download Accelerator\\ida.exe -autorun"
"Lava-Lava"="\"C:\\Program Files\\Dianji\\Lava-Lava\\Lava-Lava.exe\" /s"
"PcSync"="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\PcSync2.exe /NoDialog"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
@=""
"Apoint"="C:\\Program Files\\Apoint\\Apoint.exe"
"DataLayer"="C:\\Program Files\\Common Files\\PCSuite\\DataLayer\\DataLayer.exe"
"Dell QuickSet"="C:\\Program Files\\Dell\\QuickSet\\quickset.exe"
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"PCSuiteTrayApplication"="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\LaunchApplication.exe -onlytray"
"PDUiP6000DMon"="C:\\Program Files\\Canon\\Memory Card Utility\\PIXMA iP6000D\\PDUiP6000DMon.exe"
"PDUiP6000DTskbr"="C:\\Program Files\\Canon\\Memory Card Utility\\PIXMA iP6000D\\PDUiP6000DTskbr.exe"
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"RegistryMechanic"=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NJStar Chinese Calendar.lnk]
"backup"="C:\\WINDOWS\\pss\\NJStar Chinese Calendar.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\NJSTAR~1\\NJCalend.exe /Automation"
"item"="NJStar Chinese Calendar"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
"backup"="C:\\WINDOWS\\pss\\Windows Desktop Search.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\WI459E~1\\WINDOW~1.EXE /startup"
"item"="Windows Desktop Search"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CdnCtr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="cdnup"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="quickset"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Dell\\QuickSet\\quickset.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DSAgnt"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="googletalk"
"hkey"="HKLM"
"command"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe /autostart"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Pando"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PicasaMediaDetector"
"hkey"="HKLM"
"command"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PlaxoHelper"
"hkey"="HKCU"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YCentral]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="YahooCentral"
"hkey"="HKLM"
"inimapping"="0"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptimg

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\ffpbek
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\fsb
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\msusbbux
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\vcharp
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\ws2ifsd

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0

HKLM\software\Microsoft\Windows NT\CurrentVersion\Svchost *netsvcs*
ClipArt

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Ace Optimizer Maintenance.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Helen Lo.job
C:\WINDOWS\tasks\Uniblue SpyEraser.job


********************************************************************

catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-02-07 14:48:00
Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
Sorry for the dalay. Can't believe both me and my comuter got virus attack. <_<

Here's the SDFix report and latest Hijackthis log:

SDFix: Version 1.69

Run by [removed]
Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:





Restoring Windows Registry Entries
Restoring Default Hosts File


Rebooting…

Normal Mode:
Checking Files:

No Trojan Files Found…




ADS Check:

C:\WINDOWS\system32
No streams found.


Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Pando Networks\\Pando\\pando.exe"="C:\\Program Files\\Pando Networks\\Pando\\pando.exe:*:Disabled:pando"
"C:\\WINDOWS\\temp\\sd155.exe"="C:\\WINDOWS\\temp\\sd155.exe:*:Disabled:sd155.exe"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"


Remaining Files:
—————



Checking For Files with Hidden Attributes :

C:\Documents and Settings\Helen Lo\My Documents\Qzone\Fund Raising\Series A\~$owan.com Share Purchase Agreement.doc
C:\Program Files\Canon\MP Navigator 2.2\uinstrsc.dll
C:\Program Files\Microsoft Works Suite 2005\Setup\MNYINSTA.DLL
C:\Program Files\Microsoft Works Suite 2005\Setup\SETUPLNG.DLL
C:\Program Files\Canon\MP Navigator 2.2\Maint.exe
C:\Program Files\Microsoft Works Suite 2005\Setup\LAUNCHER.EXE
C:\Program Files\Microsoft Works Suite 2005\Setup\RMVSUITE.EXE
C:\Program Files\Microsoft Works Suite 2005\Setup\UNREGWTR.EXE
C:\Program Files\Picasa2\setup.exe
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL1045.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL1440.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL1765.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL2047.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL2157.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL2623.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL2818.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL2902.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL3015.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL3432.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL3828.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL4030.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Marketing\~WRL1974.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Marketing\~WRL2886.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Marketing\~WRL3321.tmp
C:\WINDOWS\system32\config\system.tmp.LOG

Add/Remove Programs List:

7-Zip 4.42
Ad-Aware SE Personal
Adobe Photoshop 6.0
Adobe SVG Viewer
AVG Free Edition
AVG Anti-Spyware 7.5
Canon S520
Canon PIXMA iP6000D
Conexant D110 MDC V.92 Modem
Dell Support 5.0.0 (630)
Canon Utilities Easy-PhotoPrint
Easy-WebPrint
GalleryPlayer Images
Gold Miner (remove only)
Google Pack Screensaver
Google Updater
Google Video Player
HijackThis 1.99.1
Microsoft Internationalized Domain Names Mitigation APIs
Windows Internet Explorer 7
iPod for Windows 2006-01-10
Nokia Connectivity Cable Driver
iPod for Windows 2005-03-23
Nokia PC Suite
Broadcom Management Programs 2
Turbo Lister
AirPort
Jasc Paint Shop Pro Studio.01 , Dell Edition 1.0.1.1 Patch
Kaspersky Online Scanner
Windows Desktop Search 3.0
Keynote Connector
LiveUpdate 3.1 (Symantec Corporation)
CD-LabelPrint
Microsoft .NET Framework 1.1
Microsoft Money 2005
Mozilla Firefox (2.0.0.1)
Canon MP Navigator 2.2
MSN
NJStar Chinese Calendar
Microsoft National Language Support Downlevel APIs
Norton Spyware Scan provided by Yahoo!
PC Tools AntiVirus 3.1
Picasa 2
Microsoft Picture It! Premium 10
Intel® PROSet/Wireless Software
Rankbooster.info 1.0
RealPlayer
Registry Mechanic 5.0
Shockwave
Adobe Flash Player 9 ActiveX
Skype 3.0
Sony Digital Voice Editor 2
Spyware Doctor 4.0
Norton Internet Security (Symantec Corporation)
Trillian
Trojan Remover 6.5.6
TweakNow RegCleaner
Unlocker 1.8.5
Upromise Toolbar (remove only)
Yahoo! Toolbar
Yahoo! Browser Services
Yahoo! Internet Mail
Yahoo! Toolbar
Yahoo! Widget Engine
Yahoo! Install Manager
Chinese (Simplified) Language Support
Chinese (Traditional) Language Support
Zinio Reader
Macromedia Flash Player
Microsoft Encarta Encyclopedia Standard 2005
mSSO
Sonic RecordNow Data
mLogView
Microsoft Plus! Photo Story 2 LE
Qualxserve Service Agreement
Sonic DLA
Internal Network Card Power Management
Sonic MyDVD
Google Talk (remove only)
Google Toolbar for Internet Explorer
mProSafe
Dell Media Experience
Quicken 2006
SymNet
Sonic Update Manager
Canon MP530
J2SE Runtime Environment 5.0 Update 9
Internet Explorer Default Page
Canon PIXMA iP6000D Memory Card Utility
ccCommon
iPod for Windows 2006-01-10
Nokia Connectivity Cable Driver
Skype Plugin Manager
Google Earth
mIWA
Microsoft Picture It! Library 10
NetWaiting
Jasc Paint Shop Photo Album 5
Microsoft Picture It! Premium 10
Yahoo! Widget Engine
iTunes
iPod for Windows 2005-03-23
Norton Internet Security
Norton Confidential Browser Component
QuickTime
Simply Accounting 2005 Basic
Windows Live Messenger
Microsoft Global IME for Office XP (Traditional Chinese)
Dell Driver Reset Tool
Norton Internet Security
Nokia PC Suite
AOLIcon
Windows Genuine Advantage v1.3.0254.0
Broadcom Management Programs 2
PowerDVD 5.5
Microsoft Plus! Digital Media Edition Installer
Java 2 Runtime Environment, SE v1.4.2_03
Dell System Restore
SPBBC 32bit
Jasc Paint Shop Pro Studio, Dell Editon
Modem Helper
Norton AntiVirus
Intel® Graphics Media Accelerator Driver for Mobile
mPfMgr
mHelp
Microsoft Office XP Professional with FrontPage
mPfWiz
mDrWiFi
Presto! PageManager
mZConfig
Turbo Lister
Norton Protection Center
mXML
GiPo@MoveOnBoot 1.9.5
ALPS Touch Pad Driver
Microsoft Digital Image Library 9 - Blocker
Windows Defender
mDriver
Apple Software Update
Windows Defender Signatures
Google Toolbar for Firefox
Norton Spyware Scan
Sonic Audio module
Adobe Reader 7.0.9
Adobe Reader Chinese Traditional Fonts
Dell Picture Studio v3.0
Sonic RecordNow Copy
MSRedist
Canon CanoScan Toolbox 4.1
QuickSet
mToolkit
Microsoft .NET Framework 1.1
Microsoft Works Suite Add-in for Microsoft Word
SUPERAntiSpyware Professional
Bluetooth Stack for Windows by Toshiba
CardScan 7.0.3
Norton Confidential Web Protection Component
Symantec Real Time Storage Protection Component
Canon PhotoRecord
AirPort
Google Toolbar for Internet Explorer
Works Upgrade
Microsoft Global IME for Office XP (Simplified Chinese)
Norton Internet Security
Norton Internet Security
Digital Line Detect
mCore
AgentWebRanking Professional
AppCore
mMHouse
AV
mWlsSafe
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
palmOne

Finished



SDFix: Version 1.69

Run by [removed]
Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:





Restoring Windows Registry Entries
Restoring Default Hosts File


Rebooting…

Normal Mode:
Checking Files:

No Trojan Files Found…




ADS Check:

C:\WINDOWS\system32
No streams found.


Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Pando Networks\\Pando\\pando.exe"="C:\\Program Files\\Pando Networks\\Pando\\pando.exe:*:Disabled:pando"
"C:\\WINDOWS\\temp\\sd155.exe"="C:\\WINDOWS\\temp\\sd155.exe:*:Disabled:sd155.exe"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"


Remaining Files:
—————



Checking For Files with Hidden Attributes :

C:\Documents and Settings\Helen Lo\My Documents\Qzone\Fund Raising\Series A\~$owan.com Share Purchase Agreement.doc
C:\Program Files\Canon\MP Navigator 2.2\uinstrsc.dll
C:\Program Files\Microsoft Works Suite 2005\Setup\MNYINSTA.DLL
C:\Program Files\Microsoft Works Suite 2005\Setup\SETUPLNG.DLL
C:\Program Files\Canon\MP Navigator 2.2\Maint.exe
C:\Program Files\Microsoft Works Suite 2005\Setup\LAUNCHER.EXE
C:\Program Files\Microsoft Works Suite 2005\Setup\RMVSUITE.EXE
C:\Program Files\Microsoft Works Suite 2005\Setup\UNREGWTR.EXE
C:\Program Files\Picasa2\setup.exe
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL1045.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL1440.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL1765.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL2047.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL2157.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL2623.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL2818.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL2902.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL3015.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL3432.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL3828.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Fund Raising\~WRL4030.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Marketing\~WRL1974.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Marketing\~WRL2886.tmp
C:\Documents and Settings\Helen Lo\My Documents\Tianji\Marketing\~WRL3321.tmp
C:\WINDOWS\system32\config\system.tmp.LOG

Add/Remove Programs List:

7-Zip 4.42
Ad-Aware SE Personal
Adobe Photoshop 6.0
Adobe SVG Viewer
AVG Free Edition
AVG Anti-Spyware 7.5
Canon S520
Canon PIXMA iP6000D
Conexant D110 MDC V.92 Modem
Dell Support 5.0.0 (630)
Canon Utilities Easy-PhotoPrint
Easy-WebPrint
GalleryPlayer Images
Gold Miner (remove only)
Google Pack Screensaver
Google Updater
Google Video Player
HijackThis 1.99.1
Microsoft Internationalized Domain Names Mitigation APIs
Windows Internet Explorer 7
iPod for Windows 2006-01-10
Nokia Connectivity Cable Driver
iPod for Windows 2005-03-23
Nokia PC Suite
Broadcom Management Programs 2
Turbo Lister
AirPort
Jasc Paint Shop Pro Studio.01 , Dell Edition 1.0.1.1 Patch
Kaspersky Online Scanner
Windows Desktop Search 3.0
Keynote Connector
LiveUpdate 3.1 (Symantec Corporation)
CD-LabelPrint
Microsoft .NET Framework 1.1
Microsoft Money 2005
Mozilla Firefox (2.0.0.1)
Canon MP Navigator 2.2
MSN
NJStar Chinese Calendar
Microsoft National Language Support Downlevel APIs
Norton Spyware Scan provided by Yahoo!
PC Tools AntiVirus 3.1
Picasa 2
Microsoft Picture It! Premium 10
Intel® PROSet/Wireless Software
Rankbooster.info 1.0
RealPlayer
Registry Mechanic 5.0
Shockwave
Adobe Flash Player 9 ActiveX
Skype 3.0
Sony Digital Voice Editor 2
Spyware Doctor 4.0
Norton Internet Security (Symantec Corporation)
Trillian
Trojan Remover 6.5.6
TweakNow RegCleaner
Unlocker 1.8.5
Upromise Toolbar (remove only)
Yahoo! Toolbar
Yahoo! Browser Services
Yahoo! Internet Mail
Yahoo! Toolbar
Yahoo! Widget Engine
Yahoo! Install Manager
Chinese (Simplified) Language Support
Chinese (Traditional) Language Support
Zinio Reader
Macromedia Flash Player
Microsoft Encarta Encyclopedia Standard 2005
mSSO
Sonic RecordNow Data
mLogView
Microsoft Plus! Photo Story 2 LE
Qualxserve Service Agreement
Sonic DLA
Internal Network Card Power Management
Sonic MyDVD
Google Talk (remove only)
Google Toolbar for Internet Explorer
mProSafe
Dell Media Experience
Quicken 2006
SymNet
Sonic Update Manager
Canon MP530
J2SE Runtime Environment 5.0 Update 9
Internet Explorer Default Page
Canon PIXMA iP6000D Memory Card Utility
ccCommon
iPod for Windows 2006-01-10
Nokia Connectivity Cable Driver
Skype Plugin Manager
Google Earth
mIWA
Microsoft Picture It! Library 10
NetWaiting
Jasc Paint Shop Photo Album 5
Microsoft Picture It! Premium 10
Yahoo! Widget Engine
iTunes
iPod for Windows 2005-03-23
Norton Internet Security
Norton Confidential Browser Component
QuickTime
Simply Accounting 2005 Basic
Windows Live Messenger
Microsoft Global IME for Office XP (Traditional Chinese)
Dell Driver Reset Tool
Norton Internet Security
Nokia PC Suite
AOLIcon
Windows Genuine Advantage v1.3.0254.0
Broadcom Management Programs 2
PowerDVD 5.5
Microsoft Plus! Digital Media Edition Installer
Java 2 Runtime Environment, SE v1.4.2_03
Dell System Restore
SPBBC 32bit
Jasc Paint Shop Pro Studio, Dell Editon
Modem Helper
Norton AntiVirus
Intel® Graphics Media Accelerator Driver for Mobile
mPfMgr
mHelp
Microsoft Office XP Professional with FrontPage
mPfWiz
mDrWiFi
Presto! PageManager
mZConfig
Turbo Lister
Norton Protection Center
mXML
GiPo@MoveOnBoot 1.9.5
ALPS Touch Pad Driver
Microsoft Digital Image Library 9 - Blocker
Windows Defender
mDriver
Apple Software Update
Windows Defender Signatures
Google Toolbar for Firefox
Norton Spyware Scan
Sonic Audio module
Adobe Reader 7.0.9
Adobe Reader Chinese Traditional Fonts
Dell Picture Studio v3.0
Sonic RecordNow Copy
MSRedist
Canon CanoScan Toolbox 4.1
QuickSet
mToolkit
Microsoft .NET Framework 1.1
Microsoft Works Suite Add-in for Microsoft Word
SUPERAntiSpyware Professional
Bluetooth Stack for Windows by Toshiba
CardScan 7.0.3
Norton Confidential Web Protection Component
Symantec Real Time Storage Protection Component
Canon PhotoRecord
AirPort
Google Toolbar for Internet Explorer
Works Upgrade
Microsoft Global IME for Office XP (Simplified Chinese)
Norton Internet Security
Norton Internet Security
Digital Line Detect
mCore
AgentWebRanking Professional
AppCore
mMHouse
AV
mWlsSafe
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
palmOne

Finished

Logfile of HijackThis v1.99.1
Scan saved at 8:54:10 PM, on 3/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Documents and Settings\Helen Lo\Desktop\Downloads\HijackThis.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Upromise\Upromise.exe
C:\Program Files\Upromise\UpromiseUa.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\MSN Messenger\usnsvc.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: (no name) - {080f7380-a9d3-4332-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {183cf35a-28ed-465c-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {194dc876-57b3-4d30-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {2cb9a226-a529-4dce-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {33b8743f-0fb6-461a-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {37769aa7-6e1c-404b-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {3b76bc6d-d481-499f-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {59eb8c0c-9bdd-498e-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {59ebc65e-fdb2-467c-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {8742da56-a326-4f54-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {87aefb91-f3d3-44d3-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9d9fdd44-3beb-4b32-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {c5973ee3-06e6-4f8c-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {d7c0faf2-e11a-4cab-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {e5e99b38-ea7f-477b-8b0d-4e03f37a8dbf} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Upromise] C:\Program Files\Upromise\Upromise.exe
O4 - HKCU\..\Run: [Upromise Update] C:\Program Files\Upromise\UpromiseUa.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &eBay; Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O9 - Extra 'Tools' menuitem: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} (Keynote Connector Launcher 2) - http://webeffective.keynote.com/applicatio…torLauncher.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: F-Secure BlackLight Sensor - F-Secure Corporation - C:\DOCUME~1\HELENL~1\LOCALS~1\Temp\F-Secure\Anti-Virus\fsblsrv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

They look clean, but somehow my IE7 is still running very slowly and it doesn't allow me to install Alexa Toolbar (which got screwed up during the infection). Anything else still wrong?

Thanks much!!!
Close all programs leaving only HijackThis running. Place a check against each of the following,
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: (no name) - {080f7380-a9d3-4332-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {183cf35a-28ed-465c-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {194dc876-57b3-4d30-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {2cb9a226-a529-4dce-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {33b8743f-0fb6-461a-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {37769aa7-6e1c-404b-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {3b76bc6d-d481-499f-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {59eb8c0c-9bdd-498e-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {59ebc65e-fdb2-467c-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {8742da56-a326-4f54-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {87aefb91-f3d3-44d3-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {9d9fdd44-3beb-4b32-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {c5973ee3-06e6-4f8c-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {d7c0faf2-e11a-4cab-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {e5e99b38-ea7f-477b-8b0d-4e03f37a8dbf} - (no file)

Click on Fix Checked when finished and exit HijackThis.



You are running 3 anti-virus programs plese remove two of them.


————————————-
Download and run - ATF Cleaner instructions here.
—————————————
Rescan with HJT and post a new log here.
Also please describe how your computer behaves at the moment.
Logfile of HijackThis v1.99.1
Scan saved at 8:54:10 PM, on 3/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Documents and Settings\Helen Lo\Desktop\Downloads\HijackThis.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Upromise\Upromise.exe
C:\Program Files\Upromise\UpromiseUa.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\MSN Messenger\usnsvc.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: (no name) - {080f7380-a9d3-4332-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {183cf35a-28ed-465c-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {194dc876-57b3-4d30-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {2cb9a226-a529-4dce-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {33b8743f-0fb6-461a-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {37769aa7-6e1c-404b-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {3b76bc6d-d481-499f-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {59eb8c0c-9bdd-498e-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {59ebc65e-fdb2-467c-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {8742da56-a326-4f54-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {87aefb91-f3d3-44d3-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9d9fdd44-3beb-4b32-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {c5973ee3-06e6-4f8c-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {d7c0faf2-e11a-4cab-8b0d-4e03f37a8dbf} - (no file)
O2 - BHO: (no name) - {e5e99b38-ea7f-477b-8b0d-4e03f37a8dbf} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Upromise] C:\Program Files\Upromise\Upromise.exe
O4 - HKCU\..\Run: [Upromise Update] C:\Program Files\Upromise\UpromiseUa.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O9 - Extra 'Tools' menuitem: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} (Keynote Connector Launcher 2) - http://webeffective.keynote.com/applicatio…torLauncher.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: F-Secure BlackLight Sensor - F-Secure Corporation - C:\DOCUME~1\HELENL~1\LOCALS~1\Temp\F-Secure\Anti-Virus\fsblsrv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Computer is still slow. IE takes forever to load.

Which Anti-virus would you suggest keeping then?

Thanks a bunch!
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI