This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack This File

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First adaware and spybot. Yes both of those programs give very few false positives. The error message you recieve . Is it comming from Comodo or windows ? If it is from comodo you can try disabling it for the download. I'm not sure how much help I'll be here but I can look into it a bit. You HJT log is still clean.
ok - I'll install adaware and spybot.

I've disable Comodo before the Zone Alarm installation. However, as soon as I accept the licensing agreement and click install. The Visual Studio Just-in-Time debugger appears with the error message: An unhandled exception Win32 in GLB109.tmp.

I think I'm infected with spyware again. I had to uncheck do not show hidden files and folder to find this file. Here is my HJT log. I'm going to run my spyware programs in safe mode while you're looking at the files.


Logfile of HijackThis v1.99.1
Scan saved at 3:22:03 PM, on 4/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Genie-Soft\GBM7Home\GBMAgent.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\ZipWiz\ZWP32.EXE
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Comodo\Firewall\cpf.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [WinPatrol] "C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe"
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Comodo Firewall] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] "C:\Program Files\Dell\QuickSet\quickset.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [GBMHome7Agent] "C:\Program Files\Genie-Soft\GBM7Home\GBMAgent.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [GBMHome7Agent] "C:\Program Files\Genie-Soft\GBM7Home\GBMAgent.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://supportsoft.adelphia.net/sdccommon/…ad/tgctlins.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1153183810718
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37680.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: Visual Studio 2005 Remote Debugger (msvsmon80) - Unknown owner - C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: OracleJobSchedulerXE - Unknown owner - c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oraclexe\app\oracle\product\10.2.0\server\BIN\omtsreco.exe
O23 - Service: OracleServiceXE - Oracle Corporation - c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE
O23 - Service: OracleXEClrAgent - Unknown owner - C:\oraclexe\app\oracle\product\10.2.0\server\bin\OraClrAgnt.exe
O23 - Service: OracleXETNSListener - Unknown owner - C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe
O23 - Service: OSCM Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Novatel Wireless\Sprint\Sprint PCS Connection Manager\OSCMUtilityService.exe
O23 - Service: Port Reporter (PortReporter) - Unknown owner - C:\Program Files\PortReporter\portreporter.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
O23 - Service: ProgramCheckerPro (sassvc) - Unknown owner - C:\Program Files\Zenturi\ProgramChecker\sassvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
OK lets get a few more scans to be sure.




______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Issues block to clean anything with this program. It is for experts only and it is risky).

________________________________

The following is not the AVG anti virus program you already have. :thumbup:


Please download to your Desktop or to your usual Download Folder.
AVG Anti-Spyware
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit.
  • Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update AVG Anti-spyware.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
______________________________
It will save a log in C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports

Exit AVG.

Reboot normaly.

Post that for me.



________________________________________________
Use internet explorer for this one. We need active x files.
_________________________________
Please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer

The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.

_____________________________

Post those 2 logs and lets be sure your malware free.
My apologies for it taking so long to respond. It took a very long time for me to run AVG Antivirus in safe mode. I've been using CCleaner for awhile now. But I never thought not to run the "Issues" part of the program. Stupid me - I just ran "Issues" and selected fix "all issues" one or two time a week. At least I still have most of my registry backups from the scan and fixes. Here is the Avg Antispyware Log that I ran within Safe Mode. ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 9:40:04 PM 4/12/2007 + Scan result: :mozilla.26:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\focuhqws.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.26:E:\Dell Precision Backups\Partial Backups\Partial Backup.gbp/MF/C/Documents and Settings/Administrator/Application Data/Mozilla/Firefox/Profiles/focuhqws.default/cookies.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.27:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\focuhqws.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.27:E:\Dell Precision Backups\Partial Backups\Partial Backup.gbp/MF/C/Documents and Settings/Administrator/Application Data/Mozilla/Firefox/Profiles/focuhqws.default/cookies.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.28:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\focuhqws.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.28:E:\Dell Precision Backups\Partial Backups\Partial Backup.gbp/MF/C/Documents and Settings/Administrator/Application Data/Mozilla/Firefox/Profiles/focuhqws.default/cookies.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.23:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\focuhqws.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.23:E:\Dell Precision Backups\Partial Backups\Partial Backup.gbp/MF/C/Documents and Settings/Administrator/Application Data/Mozilla/Firefox/Profiles/focuhqws.default/cookies.txt -> TrackingCookie.Atdmt : Error during cleaning. :mozilla.29:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\focuhqws.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.29:E:\Dell Precision Backups\Partial Backups\Partial Backup.gbp/MF/C/Documents and Settings/Administrator/Application Data/Mozilla/Firefox/Profiles/focuhqws.default/cookies.txt -> TrackingCookie.Com : Error during cleaning. :mozilla.6:C:\Documents and Settings\msbennett\Application Data\Mozilla\Firefox\Profiles\ixr6w65w.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.7:C:\Documents and Settings\msbennett\Application Data\Mozilla\Firefox\Profiles\ixr6w65w.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.8:C:\Documents and Settings\msbennett\Application Data\Mozilla\Firefox\Profiles\ixr6w65w.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.9:C:\Documents and Settings\msbennett\Application Data\Mozilla\Firefox\Profiles\ixr6w65w.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.34:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\focuhqws.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.34:E:\Dell Precision Backups\Partial Backups\Partial Backup.gbp/MF/C/Documents and Settings/Administrator/Application Data/Mozilla/Firefox/Profiles/focuhqws.default/cookies.txt -> TrackingCookie.Revsci : Error during cleaning. :mozilla.35:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\focuhqws.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.35:E:\Dell Precision Backups\Partial Backups\Partial Backup.gbp/MF/C/Documents and Settings/Administrator/Application Data/Mozilla/Firefox/Profiles/focuhqws.default/cookies.txt -> TrackingCookie.Revsci : Error during cleaning. :mozilla.14:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\focuhqws.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned. :mozilla.14:E:\Dell Precision Backups\Partial Backups\Partial Backup.gbp/MF/C/Documents and Settings/Administrator/Application Data/Mozilla/Firefox/Profiles/focuhqws.default/cookies.txt -> TrackingCookie.Webtrends : Error during cleaning. C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Webtrends : Cleaned. E:\Dell Precision Backups\Partial Backups\Partial Backup.gbp/MF/C/Documents and Settings/Administrator/Cookies/[removed][1].txt -> TrackingCookie.Webtrends : Cleaned. ::Report end I'll now download and run Kaspersky Online Scanner. I want be able to send you the log files till sometime tomorrow morning.
Bob4 - Here are a couple of problems I've run into. I'm having problems with getting my SiteHound ID. I've given them both my email addresses and have yet to hear from them. Also, I've been trying to run the Kapersky Online Scanner from IE7 since last night. I cannot get it to work. I pull up the website using IE7 and click the online scanner button. I then accept the licensing agreement and wait for the install active x control to appear. I right click in active x area and select install active x control. But then it just takes me back to the licensing agreement form with no accept or decline buttons. I did run my AVG antivirus overnight. It found no viruses. I'm thinking of just downloading the 30 day trial version, but would like your recommendations first. If I'm able to use the online scanner once you reply, should I do it in Safe Mode? I'll await your reply before proceeding further. I still have not been able to install ZoneAlarm Pro so I'm going to call Zone Labs. Oh - And I now have adaware and spybot on my machine. mb
I will check on the site hound issue.
It is possible that they will only contact you if you purchesed the program instead of just using the free version. Let me know if your just using the free version.



Let's check your IE settings and see if we can get an online scan going.
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click on the Security tab
  • Click the Internet icon so it becomes highlighted.
  • Click on Default Level and click Ok
  • Click on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Check that Script ActiveX controls marked safe for scripting is set to Enabled or Prompt
    • Check that Run ActiveX controls and plugins is Enabled
    • Change the Initialise and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • Check that Active Scripting is set to Enabled
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Open a new IE window and try to run the online scan.


Now retry Kasperskys..



If that doeswn't work.


Panda
Run Panda's ActiveScan from here and perform a full system scan.
- Once you are on the Panda site click the "Scan your PC" button
- A new window will open…click the big "Check Now" button
- Enter your Country
- Enter your State/Province
- Enter your Valid Email
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
- Click on "Local Disks" to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
- Post Panda scan results in your next reply.
Bob - I apologize for not returning your reply sooner. I've had to work on other things. I haven't been able to run the Kapersky or Panda online scan yet. The reason is that I've encountered a problem when perform an Adaware Scan. The full system scan locks up when it gets to the following: C:\Windows\Assembly\GAC_32\System.Enterprises\2.0.0.0_b0135 I've ran the scan several times and it always locks up when it gets to this point. I've used my other antispyware programs(SpySweeper, Spybot, Spyware Terminator, and Avg) without any problems. So I thought I'd bring it to your attention before proceeding with your further instructions. Also, when I change the IE7 settings as suggested, I get a warning message saying I'm seriously putting my internet security at risk and recommending changing my settings back to the default settings. Therefore, I'm going to try the Panda scan tonight instead of the Kapersky online scan. I'll send you the results in the morning. In the meantime, do you have any suggestion regarding the Adaware problem? Thanks
Here is the logfile for the Panda Scan. I was able to get the Kapersky online scan to work on my desktop. I'll try it again later today with my laptop and send you the files. Incident Status Location Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Mark Bennett\Cookies\msbennettadmin@2o7[1].txt Adware:Adware/Startpage.ACY Not disinfected C:\Program Files\Support.com\adelphia\scripts\IEconfig.vbs
Bob - I was able to run the Kaspersky online scan and it produced no threats. I'm now going to set my IE setting back to the ones you suggested. Have you had a chance to look at the Adaware problem I'm encountering? Thanks mb
Ok my internet is back!! Down for 12 hrs today.

Do an all files search for this file and remove it.

GLB109.tmp This is a bad file..

Lets get another scan 0r 2 to be sure.


Download and Save Blacklight to your desktop:

  • Doubleclick on blbeta.exe.
  • Click on Scan.
  • Once the Scan is Finished, click on Next.
  • Click on Exit.
    A new document will be produced on the desktop.
    Open this document with Notepad.
  • Copy and Paste its contents your next reply.
_______________________________________

Download WinPFind3U.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.
  • Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
    • In the Files Created Within group click 30 days
    • In the Files Modified Within group select 30 days
    • In the File String Search group select Non-Microsoft
  • Now click the Run Scan button on the toolbar.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.


I have found this thread in Lava supprot forums after looking into someone that has encoutered the same problem as you had with stalling at that folder.
Feel free to read it and try what they suggest.
But as you have so many other good programs if it becomes to problematic Don't worry about keeping the program.

http://www.lavasoftsupport.com/index.php?a…t=4466&st=0


In your next reply I would like to see:
  • A new HJT log
  • The report from winpfind3
  • The report from balck light
  • How have you made out with Zone Alarm and site hound????
Here are the files you requested.

Winpfind3

WinPFind3 logfile created on: 4/18/2007 5:55:14 PM
WinPFind3U by OldTimer - Version 1.0.34 Folder = C:\Documents and Settings\Mark Bennett\Desktop\WinPFind3u\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 7.0.5730.11)

1023.39 Mb Total Physical Memory | 360.96 Mb Available Physical Memory | 35.27% Memory free
2.40 Gb Paging File | 1.83 Gb Available in Paging File | 76.11% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;E:\pagefile.sys 0 0;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.10 Gb Total Space | 65.36 Gb Free Space | 70.21% Space Free
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded

Computer Name: BENO4433
Current User Name: msbennettadmin
Logged in as Administrator.
Current Boot Mode: Normal


[Processes - Non-Microsoft Only]
apntex.exe -> %ProgramFiles%\Apoint\ApntEx.exe -> Alps Electric Co., Ltd. [Ver = 5.5.1.19 | Size = 45056 bytes | Modified Date = 8/19/2004 4:40:08 PM | Attr = ]
apoint.exe -> %ProgramFiles%\Apoint\Apoint.exe -> Alps Electric Co., Ltd. [Ver = 5.5.101.141 | Size = 155648 bytes | Modified Date = 9/13/2004 6:33:20 PM | Attr = ]
avgamsvr.exe -> %ProgramFiles%\Grisoft\AVG7\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.445 | Size = 353792 bytes | Modified Date = 4/18/2007 5:19:34 PM | Attr = ]
avgas.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 50 | Size = 6266880 bytes | Modified Date = 10/7/2006 8:20:00 AM | Attr = ]
avgcc.exe -> %ProgramFiles%\Grisoft\AVG7\avgcc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.438 | Size = 411648 bytes | Modified Date = 4/18/2007 5:19:36 PM | Attr = ]
avgemc.exe -> %ProgramFiles%\Grisoft\AVG7\avgemc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 324096 bytes | Modified Date = 4/18/2007 5:19:36 PM | Attr = ]
avgupsvc.exe -> %ProgramFiles%\Grisoft\AVG7\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 4/18/2007 5:19:40 PM | Attr = ]
dkservice.exe -> %ProgramFiles%\Diskeeper Corporation\Diskeeper\DkService.exe -> Diskeeper Corporation [Ver = 11.0.686.0 | Size = 892928 bytes | Modified Date = 10/4/2006 1:49:02 PM | Attr = ]
dot1xcfg.exe -> %ProgramFiles%\Intel\Wireless\Bin\Dot1XCfg.exe -> Intel Corporation [Ver = 10.5.1.9 | Size = 479232 bytes | Modified Date = 10/18/2006 6:53:24 PM | Attr = ]
evteng.exe -> %ProgramFiles%\Intel\Wireless\Bin\EvtEng.exe -> Intel Corporation [Ver = 10.5.1.21 | Size = 434176 bytes | Modified Date = 10/18/2006 7:05:18 PM | Attr = ]
firefox.exe -> %ProgramFiles%\Mozilla Firefox\firefox.exe -> Mozilla Corporation [Ver = 1.8.1.3: 2007030919 | Size = 7633008 bytes | Modified Date = 3/20/2007 9:17:36 PM | Attr = ]
gbmagent.exe -> %ProgramFiles%\Genie-Soft\GBM7Home\GBMAgent.exe -> Genie-soft [Ver = 2, 0, 14, 24 | Size = 204800 bytes | Modified Date = 2/27/2007 9:09:32 AM | Attr = ]
guard.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Modified Date = 9/28/2006 10:13:20 AM | Attr = ]
ifrmewrk.exe -> %ProgramFiles%\Intel\Wireless\Bin\iFrmewrk.exe -> Intel Corporation [Ver = 10.5.1.18 | Size = 696320 bytes | Modified Date = 10/18/2006 6:58:16 PM | Attr = ]
jusched.exe -> %ProgramFiles%\Java\jre1.6.0_01\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 83608 bytes | Modified Date = 3/14/2007 3:43:44 AM | Attr = ]
nicconfigsvc.exe -> %ProgramFiles%\Dell\QuickSet\NICCONFIGSVC.exe -> Dell Inc. [Ver = 7, 0, 7, 0 | Size = 380928 bytes | Modified Date = 8/3/2006 7:50:46 PM | Attr = ]
regsrvc.exe -> %ProgramFiles%\Intel\Wireless\Bin\RegSrvc.exe -> Intel Corporation [Ver = 10.5.1.5 | Size = 327680 bytes | Modified Date = 10/18/2006 6:49:52 PM | Attr = ]
robotaskbaricon.exe -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe -> Siber Systems [Ver = 6-9-2 | Size = 160832 bytes | Modified Date = 4/14/2007 6:51:46 AM | Attr = ]
s24evmon.exe -> %ProgramFiles%\Intel\Wireless\Bin\S24EvMon.exe -> Intel Corporation [Ver = 10.5.1.3 | Size = 946176 bytes | Modified Date = 10/18/2006 6:56:52 PM | Attr = ]
sp_rsser.exe -> %ProgramFiles%\Spyware Terminator\sp_rsser.exe -> Crawler.com [Ver = 1.8.5.188 | Size = 909824 bytes | Modified Date = 4/7/2007 8:01:38 AM | Attr = ]
spysweeper.exe -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeper.exe -> Webroot Software, Inc. [Ver = 3,3,2,2609 | Size = 3379264 bytes | Modified Date = 3/1/2007 7:55:50 PM | Attr = ]
spysweeperui.exe -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeperUI.exe -> Webroot Software, Inc. [Ver = 5,3,2,2361 | Size = 4865600 bytes | Modified Date = 3/1/2007 7:55:36 PM | Attr = ]
spywareterminatorshield.exe -> %ProgramFiles%\Spyware Terminator\SpywareTerminatorShield.exe -> Crawler.com [Ver = 1.8.5.525 | Size = 2924544 bytes | Modified Date = 4/7/2007 8:01:26 AM | Attr = ]
ssu.exe -> %ProgramFiles%\Webroot\Spy Sweeper\ssu.exe -> [Ver = | Size = 168512 bytes | Modified Date = 3/1/2007 7:55:46 PM | Attr = ]
teatimer.exe -> %ProgramFiles%\Spybot - Search & Destroy\TeaTimer.exe -> Safer Networking Limited [Ver = 1, 4, 0, 2 | Size = 1415824 bytes | Modified Date = 5/31/2005 1:04:00 AM | Attr = ]
thunderbird.exe -> %ProgramFiles%\Mozilla Thunderbird\thunderbird.exe -> Mozilla Corporation [Ver = 1.8.0.10: 2007022120 | Size = 7847022 bytes | Modified Date = 3/3/2007 9:56:52 AM | Attr = ]
vsmon.exe -> %System32%\ZoneLabs\vsmon.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 75568 bytes | Modified Date = 3/9/2007 12:01:58 AM | Attr = ]
winpatrol.exe -> %ProgramFiles%\BillP Studios\WinPatrol\winpatrol.exe -> BillP Studios [Ver = 11, 2, 2007, 0 | Size = 271936 bytes | Modified Date = 3/26/2007 4:16:58 PM | Attr = ]
winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.34.0 | Size = 318976 bytes | Modified Date = 4/10/2007 10:00:18 PM | Attr = ]
zcfgsvc.exe -> %ProgramFiles%\Intel\Wireless\Bin\ZCfgSvc.exe -> Intel Corporation [Ver = 10.5.1.9 | Size = 802816 bytes | Modified Date = 10/18/2006 7:04:28 PM | Attr = ]
zlclient.exe -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 919280 bytes | Modified Date = 3/9/2007 12:02:00 AM | Attr = ]

[Win32 Services - Non-Microsoft Only]
(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Modified Date = 9/28/2006 10:13:20 AM | Attr = ]
(Avg7Alrt) AVG7 Alert Manager Server [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG7\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.445 | Size = 353792 bytes | Modified Date = 4/18/2007 5:19:34 PM | Attr = ]
(Avg7UpdSvc) AVG7 Update Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG7\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 4/18/2007 5:19:40 PM | Attr = ]
(AVGEMS) AVG E-mail Scanner [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG7\avgemc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 324096 bytes | Modified Date = 4/18/2007 5:19:36 PM | Attr = ]
(BAsfIpM) Broadcom ASF IP monitoring service v6.0.4 [Win32_Own | On_Demand | Stopped] -> %System32%\BAsfIpM.exe -> Broadcom Corp. [Ver = 6.0.4 | Size = 77824 bytes | Modified Date = 4/1/2004 8:05:48 PM | Attr = ]
(Diskeeper) Diskeeper [Win32_Own | Auto | Running] -> %ProgramFiles%\Diskeeper Corporation\Diskeeper\DkService.exe -> Diskeeper Corporation [Ver = 11.0.686.0 | Size = 892928 bytes | Modified Date = 10/4/2006 1:49:02 PM | Attr = ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 7:00:00 AM | Attr = ]
(EvtEng) Intel® PROSet/Wireless Event Log [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\EvtEng.exe -> Intel Corporation [Ver = 10.5.1.21 | Size = 434176 bytes | Modified Date = 10/18/2006 7:05:18 PM | Attr = ]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 1:41:10 AM | Attr = ]
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> -> File not found
(NICCONFIGSVC) NICCONFIGSVC [Win32_Own | Auto | Running] -> %ProgramFiles%\Dell\QuickSet\NICCONFIGSVC.exe -> Dell Inc. [Ver = 7, 0, 7, 0 | Size = 380928 bytes | Modified Date = 8/3/2006 7:50:46 PM | Attr = ]
(NVSvc) NVIDIA Display Driver Service [Win32_Own | Disabled | Stopped] -> %System32%\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.10.6771 | Size = 127044 bytes | Modified Date = 12/1/2004 1:05:00 AM | Attr = ]
(OracleJobSchedulerXE) OracleJobSchedulerXE [Win32_Own | On_Demand | Stopped] -> %SystemDrive%\oraclexe\app\oracle\product\10.2.0\server\BIN\extjob.exe -> [Ver = | Size = 102400 bytes | Modified Date = 2/2/2006 1:44:06 AM | Attr = ]
(OracleMTSRecoveryService) OracleMTSRecoveryService [Win32_Own | On_Demand | Stopped] -> %SystemDrive%\oraclexe\app\oracle\product\10.2.0\server\BIN\omtsreco.exe -> Oracle Corporation [Ver = 10.2.0.0.0 | Size = 57616 bytes | Modified Date = 2/2/2006 1:47:28 AM | Attr = ]
(OracleOraHome90Agent) OracleOraHome90Agent [Win32_Own | Disabled | Stopped] -> %SystemDrive%\oracle\ora90\bin\agntsrvc.exe -> Oracle Corporation [Ver = 9.2.0.0.0 | Size = 28944 bytes | Modified Date = 4/26/2002 7:29:26 PM | Attr = ]
(OracleOraHome90ClientCache) OracleOraHome90ClientCache [Win32_Own | Disabled | Stopped] -> %SystemDrive%\oracle\ora90\bin\ONRSD.EXE -> [Ver = | Size = 242328 bytes | Modified Date = 4/26/2002 9:34:38 PM | Attr = ]
(OracleOraHome90HTTPServer) OracleOraHome90HTTPServer [Win32_Own | Disabled | Stopped] -> %SystemDrive%\oracle\ora90\Apache\Apache\Apache.exe -> [Ver = | Size = 4096 bytes | Modified Date = 4/19/2002 12:02:56 AM | Attr = ]
(OracleOraHome90PagingServer) OracleOraHome90PagingServer [Win32_Own | Disabled | Stopped] -> %SystemDrive%\oracle\ora90\bin\pagntsrv.exe -> [Ver = | Size = 49152 bytes | Modified Date = 12/21/2005 8:15:50 PM | Attr = ]
(OracleOraHome90SNMPPeerEncapsulator) OracleOraHome90SNMPPeerEncapsulator [Win32_Own | Disabled | Stopped] -> %SystemDrive%\oracle\ora90\bin\encsvc.exe -> [Ver = | Size = 187392 bytes | Modified Date = 2/13/2002 10:23:20 AM | Attr = ]
(OracleOraHome90SNMPPeerMasterAgent) OracleOraHome90SNMPPeerMasterAgent [Win32_Own | Disabled | Stopped] -> %SystemDrive%\oracle\ora90\bin\agntsvc.exe -> [Ver = | Size = 254464 bytes | Modified Date = 2/13/2002 10:23:18 AM | Attr = ]
(OracleOraHome90TNSListener) OracleOraHome90TNSListener [Win32_Own | Disabled | Stopped] -> %SystemDrive%\oracle\ora90\bin\TNSLSNR.EXE -> [Ver = | Size = 266192 bytes | Modified Date = 4/26/2002 9:34:34 PM | Attr = ]
(OracleServiceORCL) OracleServiceORCL [Win32_Own | Disabled | Stopped] -> %SystemDrive%\oracle\ora90\bin\oracle.exe -> Oracle Corporation [Ver = 9.2.0.1.0 Production | Size = 29475088 bytes | Modified Date = 5/14/2002 11:25:36 AM | Attr = ]
(OracleServiceXE) OracleServiceXE [Win32_Own | On_Demand | Stopped] -> %SystemDrive%\oraclexe\app\oracle\product\10.2.0\server\BIN\oracle.exe -> Oracle Corporation [Ver = 10.2.0.1.0 Production | Size = 59064320 bytes | Modified Date = 2/2/2006 1:43:44 AM | Attr = ]
(OracleXEClrAgent) OracleXEClrAgent [Win32_Own | On_Demand | Stopped] -> %SystemDrive%\oraclexe\app\oracle\product\10.2.0\server\BIN\OraClrAgnt.exe -> [Ver = | Size = 45056 bytes | Modified Date = 2/2/2006 1:51:06 AM | Attr = ]
(OracleXETNSListener) OracleXETNSListener [Win32_Own | On_Demand | Stopped] -> %SystemDrive%\oraclexe\app\oracle\product\10.2.0\server\BIN\TNSLSNR.EXE -> [Ver = | Size = 204800 bytes | Modified Date = 2/2/2006 1:49:14 AM | Attr = ]
(OSCM Utility Service) OSCM Utility Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Novatel Wireless\Sprint\Sprint PCS Connection Manager\OSCMUtilityService.exe -> Sprint Spectrum, L.L.C [Ver = 2, 0, 0, 29 | Size = 155648 bytes | Modified Date = 1/6/2007 9:28:30 AM | Attr = ]
(PortReporter) Port Reporter [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\PortReporter\portreporter.exe -> [Ver = | Size = 90183 bytes | Modified Date = 3/30/2004 4:15:24 PM | Attr = ]
(RegSrvc) Intel® PROSet/Wireless Registry Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\RegSrvc.exe -> Intel Corporation [Ver = 10.5.1.5 | Size = 327680 bytes | Modified Date = 10/18/2006 6:49:52 PM | Attr = ]
(S24EventMonitor) Intel® PROSet/Wireless Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\S24EvMon.exe -> Intel Corporation [Ver = 10.5.1.3 | Size = 946176 bytes | Modified Date = 10/18/2006 6:56:52 PM | Attr = ]
(SandraDataSrv) SiSoftware Database Agent Service [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe -> SiSoftware [Ver = 11.22.2007.4 | Size = 123064 bytes | Modified Date = 2/27/2007 5:19:14 PM | Attr = ]
(SandraTheSrv) SiSoftware Sandra Agent Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe -> SiSoftware [Ver = 11.22.2007.4 | Size = 1204416 bytes | Modified Date = 2/27/2007 5:20:22 PM | Attr = ]
(sassvc) ProgramCheckerPro [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Zenturi\ProgramChecker\sassvc.exe -> [Ver = | Size = 122880 bytes | Modified Date = 2/15/2006 5:17:12 PM | Attr = ]
(sp_rssrv) Spyware Terminator Realtime Shield Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Spyware Terminator\sp_rsser.exe -> Crawler.com [Ver = 1.8.5.188 | Size = 909824 bytes | Modified Date = 4/7/2007 8:01:38 AM | Attr = ]
(StyleXPService) StyleXPService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\TGTSoft\StyleXP\StyleXPService.exe -> [Ver = 0, 20, 0, 3000 | Size = 352256 bytes | Modified Date = 1/23/2006 4:10:00 PM | Attr = ]
(vsmon) TrueVector Internet Monitor [Win32_Own | Auto | Running] -> %System32%\ZoneLabs\vsmon.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 75568 bytes | Modified Date = 3/9/2007 12:01:58 AM | Attr = ]
(WebrootSpySweeperService) Webroot Spy Sweeper Engine [Win32_Own | Auto | Running] -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeper.exe -> Webroot Software, Inc. [Ver = 3,3,2,2609 | Size = 3379264 bytes | Modified Date = 3/1/2007 7:55:50 PM | Attr = ]

[Registry - Non-Microsoft Only]
< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
!AVG Anti-Spyware -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 50 | Size = 6266880 bytes | Modified Date = 10/7/2006 8:20:00 AM | Attr = ]
Apoint -> %ProgramFiles%\Apoint\Apoint.exe -> Alps Electric Co., Ltd. [Ver = 5.5.101.141 | Size = 155648 bytes | Modified Date = 9/13/2004 6:33:20 PM | Attr = ]
AVG7_CC -> %ProgramFiles%\Grisoft\AVG7\avgcc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.438 | Size = 411648 bytes | Modified Date = 4/18/2007 5:19:36 PM | Attr = ]
GBMHome7Agent -> %ProgramFiles%\Genie-Soft\GBM7Home\GBMAgent.exe -> Genie-soft [Ver = 2, 0, 14, 24 | Size = 204800 bytes | Modified Date = 2/27/2007 9:09:32 AM | Attr = ]
IntelWireless -> %ProgramFiles%\Intel\Wireless\Bin\iFrmewrk.exe -> Intel Corporation [Ver = 10.5.1.18 | Size = 696320 bytes | Modified Date = 10/18/2006 6:58:16 PM | Attr = ]
IntelZeroConfig -> %ProgramFiles%\Intel\Wireless\Bin\ZCfgSvc.exe -> Intel Corporation [Ver = 10.5.1.9 | Size = 802816 bytes | Modified Date = 10/18/2006 7:04:28 PM | Attr = ]
NvCplDaemon -> %System32%\nvcpl.dll ["RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> NVIDIA Corporation [Ver = 6.14.10.6771 | Size = 4636672 bytes | Modified Date = 12/1/2004 1:05:00 AM | Attr = ]
nwiz -> %System32%\nwiz.exe -> NVIDIA Corporation [Ver = 6.14.10.6771 | Size = 921600 bytes | Modified Date = 12/1/2004 1:05:00 AM | Attr = ]
SpySweeper -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeperUI.exe -> Webroot Software, Inc. [Ver = 5,3,2,2361 | Size = 4865600 bytes | Modified Date = 3/1/2007 7:55:36 PM | Attr = ]
SpywareTerminator -> %ProgramFiles%\Spyware Terminator\SpywareTerminatorShield.exe -> Crawler.com [Ver = 1.8.5.525 | Size = 2924544 bytes | Modified Date = 4/7/2007 8:01:26 AM | Attr = ]
SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_01\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 83608 bytes | Modified Date = 3/14/2007 3:43:44 AM | Attr = ]
WinPatrol -> %ProgramFiles%\BillP Studios\WinPatrol\winpatrol.exe -> BillP Studios [Ver = 11, 2, 2007, 0 | Size = 271936 bytes | Modified Date = 3/26/2007 4:16:58 PM | Attr = ]
ZoneAlarm Client -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 919280 bytes | Modified Date = 3/9/2007 12:02:00 AM | Attr = ]
< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\
IMAIL -> Installed = 1 ->
MAPI -> Installed = 1 ->
MSFS -> Installed = 1 ->
< Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
GBMHome7Agent -> %ProgramFiles%\Genie-Soft\GBM7Home\GBMAgent.exe -> Genie-soft [Ver = 2, 0, 14, 24 | Size = 204800 bytes | Modified Date = 2/27/2007 9:09:32 AM | Attr = ]
RoboForm -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe -> Siber Systems [Ver = 6-9-2 | Size = 160832 bytes | Modified Date = 4/14/2007 6:51:46 AM | Attr = ]
SpybotSD TeaTimer -> %ProgramFiles%\Spybot - Search & Destroy\TeaTimer.exe -> Safer Networking Limited [Ver = 1, 4, 0, 2 | Size = 1415824 bytes | Modified Date = 5/31/2005 1:04:00 AM | Attr = ]
< ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKLM] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 73728 bytes | Modified Date = 9/28/2006 10:13:28 AM | Attr = ]
< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
WRNotifier -> %System32%\WRLogonNTF.dll -> Webroot Software, Inc. [Ver = 3,3,2,2609 | Size = 233024 bytes | Modified Date = 3/1/2007 7:55:48 PM | Attr = ]
< HOSTS File > (707 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts
< Internet Explorer Settings > ->
HKLM: Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome ->
HKLM: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch ->
HKLM: Local Page -> C:\WINDOWS\system32\blank.htm ->
HKLM: Search Bar -> http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm ->
HKLM: Search Page -> http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch ->
HKLM: Start Page -> http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome ->
HKLM: CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKLM: SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
HKCU: Default_Page_URL -> http://www.dell4me.com/myway ->
HKCU: Local Page -> C:\WINDOWS\system32\blank.htm ->
HKCU: Search Page -> http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch ->
HKCU: Start Page -> http://www.microsoft.com/ ->
HKCU: CustomizeSearch -> http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchcust.htm ->
HKCU: SearchAssistant -> http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm ->
HKCU: ProxyEnable -> 0 ->
< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
msn.com [ - ] -> ->
< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [] -> Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Modified Date = 5/31/2005 1:04:00 AM | Attr = ]
{724d43a9-0d85-11d4-9908-00400523e39a} [HKLM] -> %ProgramFiles%\Siber Systems\AI RoboForm\roboform.dll [Reg Data - Value does not exist] -> Siber Systems [Ver = 6-9-2 | Size = 5571640 bytes | Modified Date = 4/14/2007 6:51:46 AM | Attr = ]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 3/14/2007 3:43:40 AM | Attr = ]
{C86AE9C0-0909-4DDC-B661-C1AFB9F5AE53} [HKLM] -> %ProgramFiles%\FireTrust\SiteHound\SiteHound.dll [CPub Object] -> Firetrust Limited. [Ver = 1.5.0 | Size = 1314816 bytes | Modified Date = 9/1/2006 5:37:22 AM | Attr = ]
< Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
{724d43a0-0d85-11d4-9908-00400523e39a} [HKLM] -> %ProgramFiles%\Siber Systems\AI RoboForm\roboform.dll [&RoboForm] -> Siber Systems [Ver = 6-9-2 | Size = 5571640 bytes | Modified Date = 4/14/2007 6:51:46 AM | Attr = ]
{73F7F495-A325-4C52-BE48-5F97FA511E89} [HKLM] -> %ProgramFiles%\FireTrust\SiteHound\SiteHound.dll [SiteHound] -> Firetrust Limited. [Ver = 1.5.0 | Size = 1314816 bytes | Modified Date = 9/1/2006 5:37:22 AM | Attr = ]
< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
WebBrowser\\{724D43A0-0D85-11D4-9908-00400523E39A} [HKLM] -> %ProgramFiles%\Siber Systems\AI RoboForm\roboform.dll [&RoboForm] -> Siber Systems [Ver = 6-9-2 | Size = 5571640 bytes | Modified Date = 4/14/2007 6:51:46 AM | Attr = ]
< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\npjpi160_01.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 132760 bytes | Modified Date = 3/14/2007 3:43:42 AM | Attr = ]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKCU] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 3/14/2007 3:43:40 AM | Attr = ]
{11316B13-33F0-4C9F-BD55-09994CCFA8EB} [HKLM] -> Reg Data - Key not found [MenuText: Reg Data - Value does not exist] -> File not found
{320AF880-6646-11D3-ABEE-C5DBF3571F46} -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComFillForms.htm [ButtonText: Fill Forms] -> File not found
{320AF880-6646-11D3-ABEE-C5DBF3571F49} -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComSavePass.htm [ButtonText: Save] -> File not found
{724d43aa-0d85-11d4-9908-00400523e39a} -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComShowToolbar.htm [ButtonText: RoboForm] -> File not found
{92780B25-18CC-41C8-B9BE-3C9C571A8263} -> Reg Data - Value does not exist [ButtonText: Research] -> File not found
{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> Reg Data - Key not found [MenuText: @xpsp3res.dll,-20001] -> File not found
< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\
Customize Menu -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.htm -> File not found
E&xport to Microsoft Excel -> -> File not found
Fill Forms -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComFillForms.htm -> File not found
RoboForm Toolbar -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComShowToolbar.htm -> File not found
Save Forms -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComSavePass.htm -> File not found
< Internet Explorer Plugins [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\Extension\
.spop -> %ProgramFiles%\Internet Explorer\PLUGINS\NPDocBox.dll [Reg Data - Value does not exist] -> Intertrust Technologies, Inc. [Ver = 1.0.0.32 | Size = 270336 bytes | Modified Date = 8/1/2001 7:05:42 PM | Attr = ]
< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\
{BFE104B1-B28C-4FFE-B288-F5646B0E8209} -> (Broadcom NetXtreme 57xx Gigabit Controller) ->
{F2D7447C-7DC0-4074-815A-787DD6B5D4CF} -> (Intel® PRO/Wireless 2200BG Network Connection) ->
< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\
belarc -> %ProgramFiles%\Belarc\Advisor\System\BAVoilaX.dll -> Belarc, Inc. [Ver = 7.2 | Size = 33280 bytes | Modified Date = 7/27/2006 7:30:26 PM | Attr = ]
ipp -> Reg Data - Key not found -> File not found
msdaipp -> Reg Data - Key not found -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\
{01111F00-3E00-11D2-8470-0060089874ED} -> Support.com Installer - CodeBase = http://supportsoft.adelphia.net/sdccommon/…ad/tgctlins.cab ->
{01A88BB1-1174-41EC-ACCB-963509EAE56B} -> SysProWmi Class - CodeBase = http://support.dell.com/systemprofiler/SysPro.CAB ->
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} -> Office Genuine Advantage Validation Tool - CodeBase = http://download.microsoft.com/download/e/7…/OGAControl.cab ->
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -> CKAVWebScan Object - CodeBase = http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab ->
{17492023-C23A-453E-A040-C7C580BBF700} -> Windows Genuine Advantage Validation Tool - CodeBase = http://download.microsoft.com/download/3/9…heckControl.cab ->
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -> MUWebControl Class - CodeBase = http://update.microsoft.com/microsoftupdat…b?1153183810718 ->
{7F8C8173-AD80-4807-AA75-5672F22B4582} -> ICSScanner Class - CodeBase = http://download.zonelabs.com/bin/promotion…canner37680.cab ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab ->
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -> ActiveScan Installer Class - CodeBase = http://acs.pandasoftware.com/activescan/as5free/asinst.cab ->
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} -> Shockwave Flash Object - CodeBase = https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab ->
{E856B973-45FD-4559-8F82-EAB539144667} -> Dell PC Checkup Installer Control - CodeBase = http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab ->


[Files/Folders - Created Within 30 days]
ATI -> %SystemDrive%\ATI -> [Folder | Created Date = 4/14/2007 11:46:37 AM | Attr = ]
Computer Information -> %SystemDrive%\Computer Information -> [Folder | Created Date = 4/1/2007 4:09:54 PM | Attr = ]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Created Date = 4/12/2007 4:47:21 PM | Attr = ]
HijackThis -> %SystemDrive%\HijackThis -> [Folder | Created Date = 4/5/2007 4:13:02 PM | Attr = ]
kav -> %SystemDrive%\kav -> [Folder | Created Date = 4/17/2007 3:10:47 PM | Attr = ]
Microsoft Downloads -> %SystemDrive%\Microsoft Downloads -> [Folder | Created Date = 3/31/2007 9:25:26 PM | Attr = ]
Unzipped -> %SystemDrive%\Unzipped -> [Folder | Created Date = 3/23/2007 12:56:56 PM | Attr = ]
ExplorerXP.INI -> %SystemRoot%\ExplorerXP.INI -> [Ver = | Size = 26 bytes | Created Date = 3/23/2007 1:24:34 PM | Attr = ]
Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Created Date = 4/13/2007 1:46:37 PM | Attr = ]
Occache -> %SystemRoot%\Occache -> [Folder | Created Date = 3/31/2007 7:24:56 AM | Attr = ]
WRUninstall.dll -> %SystemRoot%\WRUninstall.dll -> Webroot Software, Inc. [Ver = 5,3,2,2361 | Size = 271936 bytes | Created Date = 4/11/2007 5:02:04 PM | Attr = ]
ActiveScan -> %System32%\ActiveScan -> [Folder | Created Date = 4/16/2007 9:40:45 PM | Attr = ]
asuninst.exe -> %System32%\asuninst.exe -> Panda Software [Ver = 1, 0, 0, 2 | Size = 73728 bytes | Created Date = 4/16/2007 9:41:26 PM | Attr = ]
bih.dll -> %System32%\bih.dll -> Thomas Michel eMail: [removed] Web: http://www.batteryinfo.de.vu or http://home.arcor.de/batteryinfo [Ver = 1, 2, 0, 25 | Size = 200704 bytes | Created Date = 3/26/2007 9:17:02 AM | Attr = ]
Help.ico -> %System32%\Help.ico -> [Ver = | Size = 1406 bytes | Created Date = 4/16/2007 9:40:50 PM | Attr = ]
java.exe -> %System32%\java.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 135168 bytes | Created Date = 4/9/2007 7:02:45 PM | Attr = ]
javacpl.cpl -> %System32%\javacpl.cpl -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 69632 bytes | Created Date = 4/9/2007 7:02:45 PM | Attr = ]
javaw.exe -> %System32%\javaw.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 135168 bytes | Created Date = 4/9/2007 7:02:45 PM | Attr = ]
javaws.exe -> %System32%\javaws.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 139264 bytes | Created Date = 4/9/2007 7:02:45 PM | Attr = ]
Kaspersky Lab -> %System32%\Kaspersky Lab -> [Folder | Created Date = 4/17/2007 8:50:47 AM | Attr = ]
libeay32_0.9.6l.dll -> %System32%\libeay32_0.9.6l.dll -> [Ver = | Size = 796312 bytes | Created Date = 4/13/2007 1:47:26 PM | Attr = ]
Netw2c32.dll -> %System32%\Netw2c32.dll -> Intel Corporation [Ver = 9. 0. 4. 93 | Size = 557056 bytes | Created Date = 4/14/2007 6:52:17 AM | Attr = ]
Netw2r32.dll -> %System32%\Netw2r32.dll -> Intel Corporation [Ver = 9. 0. 4. 93 | Size = 2732032 bytes | Created Date = 4/14/2007 6:52:17 AM | Attr = ]
pavas.ico -> %System32%\pavas.ico -> [Ver = | Size = 30590 bytes | Created Date = 4/16/2007 9:40:49 PM | Attr = ]
pxcpyi64.exe -> %System32%\pxcpyi64.exe -> Sonic Solutions [Ver = 1.00.40a | Size = 116472 bytes | Created Date = 3/26/2007 5:05:49 PM | Attr = ]
qtp-mt334.dll -> %System32%\qtp-mt334.dll -> [Ver = | Size = 4239360 bytes | Created Date = 3/23/2007 1:18:09 PM | Attr = ]
ssiefr.EXE -> %System32%\ssiefr.EXE -> Webroot Software Inc (www.webroot.com) [Ver = 3.3.2.2609 | Size = 10240 bytes | Created Date = 4/11/2007 5:02:09 PM | Attr = ]
Uninstall.ico -> %System32%\Uninstall.ico -> [Ver = | Size = 2550 bytes | Created Date = 4/16/2007 9:40:50 PM | Attr = ]
vsconfig.xml -> %System32%\vsconfig.xml -> [Ver = | Size = 47198 bytes | Created Date = 4/13/2007 1:47:13 PM | Attr = ]
vsdata.dll -> %System32%\vsdata.dll -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 83696 bytes | Created Date = 4/13/2007 1:46:37 PM | Attr = ]
vsdatant.sys -> %System32%\vsdatant.sys -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 394192 bytes | Created Date = 4/13/2007 1:47:13 PM | Attr = ]
vsinit.dll -> %System32%\vsinit.dll -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 157424 bytes | Created Date = 4/13/2007 1:46:37 PM | Attr = ]
vsmonapi.dll -> %System32%\vsmonapi.dll -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 104176 bytes | Created Date = 4/13/2007 1:47:13 PM | Attr = ]
vspubapi.dll -> %System32%\vspubapi.dll -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 276208 bytes | Created Date = 4/13/2007 1:47:13 PM | Attr = ]
vsregexp.dll -> %System32%\vsregexp.dll -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 71408 bytes | Created Date = 4/13/2007 1:47:25 PM | Attr = ]
vsutil.dll -> %System32%\vsutil.dll -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 472816 bytes | Created Date = 4/13/2007 1:46:37 PM | Attr = ]
vswmi.dll -> %System32%\vswmi.dll -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 46832 bytes | Created Date = 4/13/2007 1:47:16 PM | Attr = ]
vsxml.dll -> %System32%\vsxml.dll -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 100080 bytes | Created Date = 4/13/2007 1:47:14 PM | Attr = ]
wnaspi32.dll -> %System32%\wnaspi32.dll -> [Ver = | Size = 8192 bytes | Created Date = 3/23/2007 1:18:09 PM | Attr = ]
WRLogonNtf.dll -> %System32%\WRLogonNtf.dll -> Webroot Software, Inc. [Ver = 3,3,2,2609 | Size = 233024 bytes | Created Date = 4/11/2007 5:03:12 PM | Attr = ]
wrlzma.dll -> %System32%\wrlzma.dll -> [Ver = | Size = 26688 bytes | Created Date = 4/11/2007 5:02:09 PM | Attr = ]
zlcomm.dll -> %System32%\zlcomm.dll -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 83696 bytes | Created Date = 4/13/2007 1:47:22 PM | Attr = ]
zlcommdb.dll -> %System32%\zlcommdb.dll -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 71408 bytes | Created Date = 4/13/2007 1:47:22 PM | Attr = ]
zllictbl.dat -> %System32%\zllictbl.dat -> [Ver = | Size = 4212 bytes | Created Date = 4/13/2007 1:47:34 PM | Attr = H ]
ZoneLabs -> %System32%\ZoneLabs -> [Folder | Created Date = 4/13/2007 1:47:14 PM | Attr = ]
zpeng24.dll -> %System32%\zpeng24.dll -> Python Software Foundation [Ver = 2.4.2 | Size = 1087216 bytes | Created Date = 4/13/2007 1:47:14 PM | Attr = ]
ZPORT4AS.dll -> %System32%\ZPORT4AS.dll -> [Ver = | Size = 11776 bytes | Created Date = 4/16/2007 9:41:26 PM | Attr = ]
avg7core.sys -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.444 | Size = 775680 bytes | Created Date = 4/18/2007 4:19:39 PM | Attr = ]
avg7rsw.sys -> %System32%\drivers\avg7rsw.sys -> GRISOFT, s.r.o. [Ver = 7,0,0,340 | Size = 4224 bytes | Created Date = 4/18/2007 4:19:41 PM | Attr = ]
avg7rsxp.sys -> %System32%\drivers\avg7rsxp.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 27776 bytes | Created Date = 4/18/2007 4:19:42 PM | Attr = ]
AvgAsCln.sys -> %System32%\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 3968 bytes | Created Date = 4/12/2007 5:30:23 PM | Attr = ]
avgclean.sys -> %System32%\drivers\avgclean.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 3968 bytes | Created Date = 4/18/2007 4:19:43 PM | Attr = ]
avgmfx86.sys -> %System32%\drivers\avgmfx86.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.447 | Size = 19840 bytes | Created Date = 4/18/2007 4:19:42 PM | Attr = ]
avgtdi.sys -> %System32%\drivers\avgtdi.sys -> GRISOFT, s.r.o. [Ver = 7,0,0,346 | Size = 4960 bytes | Created Date = 4/18/2007 4:19:42 PM | Attr = ]
famfd.sys -> %System32%\drivers\famfd.sys -> Windows ® 2000 DDK provider [Ver = 5.00.2195.6717 | Size = 62464 bytes | Created Date = 4/6/2007 3:34:31 PM | Attr = ]
SSFS0509.sys -> %System32%\drivers\SSFS0509.sys -> Webroot Software Inc (www.webroot.com) [Ver = 3.3.2.2609 | Size = 20544 bytes | Created Date = 4/11/2007 5:09:42 PM | Attr = ]
sshrmd.sys -> %System32%\drivers\sshrmd.sys -> Webroot Software Inc (www.webroot.com) [Ver = 3.3.2.2609 | Size = 22080 bytes | Created Date = 4/11/2007 5:03:07 PM | Attr = ]
ssidrv.sys -> %System32%\drivers\ssidrv.sys -> Webroot Software Inc (www.webroot.com) [Ver = 3.3.2.2609 | Size = 144960 bytes | Created Date = 4/11/2007 5:03:07 PM | Attr = ]

[Files/Folders - Modified Within 30 days]
ATI -> %SystemDrive%\ATI -> [Folder | Modified Date = 4/14/2007 12:46:38 PM | Attr = ]
Computer Information -> %SystemDrive%\Computer Information -> [Folder | Modified Date = 4/1/2007 5:09:56 PM | Attr = ]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 4/18/2007 5:30:00 PM | Attr = ]
HijackThis -> %SystemDrive%\HijackThis -> [Folder | Modified Date = 4/12/2007 3:22:22 PM | Attr = ]
kav -> %SystemDrive%\kav -> [Folder | Modified Date = 4/17/2007 4:10:48 PM | Attr = ]
Microsoft Downloads -> %SystemDrive%\Microsoft Downloads -> [Folder | Modified Date = 3/31/2007 10:45:54 PM | Attr = ]
My Zip Files -> %SystemDrive%\My Zip Files -> [Folder | Modified Date = 3/26/2007 10:11:04 AM | Attr = ]
NVIDIA -> %SystemDrive%\NVIDIA -> [Folder | Modified Date = 4/14/2007 12:44:34 PM | Attr = ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 4/17/2007 4:37:42 PM | Attr = R ]
s-1-5-21-3316980534-2162892132-898993265-1017.rrr -> %SystemDrive%\s-1-5-21-3316980534-2162892132-898993265-1017.rrr -> [Ver = | Size = 8192 bytes | Modified Date = 3/28/2007 8:56:14 PM | Attr = ]
System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 4/11/2007 8:57:28 PM | Attr = HS]
Unzipped -> %SystemDrive%\Unzipped -> [Folder | Modified Date = 3/26/2007 10:11:28 AM | Attr = ]
WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 4/18/2007 5:18:36 PM | Attr = ]
$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 4/10/2007 8:20:36 PM | Attr = H ]
AppPatch -> %SystemRoot%\AppPatch -> [Folder | Modified Date = 4/17/2007 2:17:26 AM | Attr = ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 4/18/2007 5:30:06 PM | Attr = S]
CSC -> %SystemRoot%\CSC -> [Folder | Modified Date = 4/17/2007 5:56:26 PM | Attr = HS]
Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 4/17/2007 5:58:42 PM | Attr = ]
Downloaded Installations -> %SystemRoot%\Downloaded Installations -> [Folder | Modified Date = 4/16/2007 6:19:56 PM | Attr = ]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 4/17/2007 9:50:50 AM | Attr = S]
ExplorerXP.INI -> %SystemRoot%\ExplorerXP.INI -> [Ver = | Size = 26 bytes | Modified Date = 3/23/2007 2:24:36 PM | Attr = ]
Help -> %SystemRoot%\Help -> [Folder | Modified Date = 4/15/2007 8:52:04 AM | Attr = ]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 4/17/2007 9:50:48 AM | Attr = H ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 4/18/2007 5:28:38 PM | Attr = HS]
Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Modified Date = 4/18/2007 5:48:48 PM | Attr = ]
msagent -> %SystemRoot%\msagent -> [Folder | Modified Date = 4/10/2007 9:41:56 PM | Attr = ]
network diagnostic -> %SystemRoot%\network diagnostic -> [Folder | Modified Date = 4/17/2007 4:03:44 PM | Attr = ]
Occache -> %SystemRoot%\Occache -> [Folder | Modified Date = 3/31/2007 8:24:58 AM | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 4/18/2007 5:20:08 PM | Attr = ]
Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 4/17/2007 3:02:26 AM | Attr = ]
repair -> %SystemRoot%\repair -> [Folder | Modified Date = 3/23/2007 7:02:16 AM | Attr = ]
security -> %SystemRoot%\security -> [Folder | Modified Date = 4/5/2007 4:49:54 PM | Attr = ]
SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Modified Date = 4/17/2007 2:34:04 AM | Attr = ]
system -> %SystemRoot%\system -> [Folder | Modified Date = 4/18/2007 5:18:34 PM | Attr = ]
system32 -> %System32% -> [Folder | Modified Date = 4/18/2007 5:26:46 PM | Attr = ]
Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 3/23/2007 3:52:54 PM | Attr = S]
Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 4/18/2007 5:35:06 PM | Attr = ]
win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 861 bytes | Modified Date = 4/17/2007 5:58:26 PM | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 4/18/2007 5:30:16 PM | Attr = H ]
ActiveScan -> %System32%\ActiveScan -> [Folder | Modified Date = 4/17/2007 2:34:12 AM | Attr = ]
appmgmt -> %System32%\appmgmt -> [Folder | Modified Date = 4/9/2007 7:08:36 PM | Attr = ]
bih.dll -> %System32%\bih.dll -> Thomas Michel eMail: [removed] Web: http://www.batteryinfo.de.vu or http://home.arcor.de/batteryinfo [Ver = 1, 2, 0, 25 | Size = 200704 bytes | Modified Date = 3/26/2007 10:17:04 AM | Attr = ]
CatRoot -> %System32%\CatRoot -> [Folder | Modified Date = 3/31/2007 10:32:18 PM | Attr = ]
CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 4/18/2007 4:52:16 PM | Attr = ]
config -> %System32%\config -> [Folder | Modified Date = 4/17/2007 2:34:44 AM | Attr = ]
dllcache -> %System32%\dllcache -> [Folder | Modified Date = 4/12/2007 5:47:26 PM | Attr = RHS]
drivers -> %System32%\drivers -> [Folder | Modified Date = 4/18/2007 5:30:34 PM | Attr = ]
DRVSTORE -> %System32%\DRVSTORE -> [Folder | Modified Date = 4/14/2007 7:52:18 AM | Attr = ]
FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 134072 bytes | Modified Date = 4/4/2007 6:06:02 PM | Attr = ]
Help.ico -> %System32%\Help.ico -> [Ver = | Size = 1406 bytes | Modified Date = 4/16/2007 10:49:06 PM | Attr = ]
inetsrv -> %System32%\inetsrv -> [Folder | Modified Date = 4/18/2007 5:32:32 PM | Attr = ]
Kaspersky Lab -> %System32%\Kaspersky Lab -> [Folder | Modified Date = 4/17/2007 9:50:48 AM | Attr = ]
LogFiles -> %System32%\LogFiles -> [Folder | Modified Date = 4/17/2007 5:58:42 PM | Attr = ]
NtmsData -> %System32%\NtmsData -> [Folder | Modified Date = 3/23/2007 7:32:20 AM | Attr = ]
nvModes.001 -> %System32%\nvModes.001 -> [Ver = | Size = 71472 bytes | Modified Date = 4/18/2007 5:49:40 PM | Attr = ]
nvModes.dat -> %System32%\nvModes.dat -> [Ver = | Size = 71472 bytes | Modified Date = 4/15/2007 8:28:36 AM | Attr = ]
pavas.ico -> %System32%\pavas.ico -> [Ver = | Size = 30590 bytes | Modified Date = 4/16/2007 10:49:06 PM | Attr = ]
perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 115770 bytes | Modified Date = 4/17/2007 6:42:56 PM | Attr = ]
perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 574236 bytes | Modified Date = 4/17/2007 6:42:56 PM | Attr = ]
PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 703268 bytes | Modified Date = 4/17/2007 6:42:56 PM | Attr = ]
ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Modified Date = 4/14/2007 7:52:22 AM | Attr = ]
Restore -> %System32%\Restore -> [Folder | Modified Date = 4/11/2007 8:57:28 PM | Attr = ]
Uninstall.ico -> %System32%\Uninstall.ico -> [Ver = | Size = 2550 bytes | Modified Date = 4/16/2007 10:49:06 PM | Attr = ]
vsconfig.xml -> %System32%\vsconfig.xml -> [Ver = | Size = 47198 bytes | Modified Date = 4/18/2007 5:31:06 PM | Attr = ]
wbem -> %System32%\wbem -> [Folder | Modified Date = 4/17/2007 2:39:44 AM | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 2206 bytes | Modified Date = 4/18/2007 5:31:02 PM | Attr = ]
zllictbl.dat -> %System32%\zllictbl.dat -> [Ver = | Size = 4212 bytes | Modified Date = 4/18/2007 5:31:06 PM | Attr = H ]
ZoneLabs -> %System32%\ZoneLabs -> [Folder | Modified Date = 4/17/2007 2:40:02 AM | Attr = ]
AegisP.sys -> %System32%\drivers\AegisP.sys -> Meetinghouse Data Communications [Ver = 3.6.0.0 | Size = 21425 bytes | Modified Date = 4/14/2007 8:06:36 AM | Attr = ]
avg7core.sys -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.444 | Size = 775680 bytes | Modified Date = 4/18/2007 5:19:40 PM | Attr = ]
avg7rsw.sys -> %System32%\drivers\avg7rsw.sys -> GRISOFT, s.r.o. [Ver = 7,0,0,340 | Size = 4224 bytes | Modified Date = 4/18/2007 5:19:42 PM | Attr = ]
avg7rsxp.sys -> %System32%\drivers\avg7rsxp.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 27776 bytes | Modified Date = 4/18/2007 5:19:44 PM | Attr = ]
avgclean.sys -> %System32%\drivers\avgclean.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 3968 bytes | Modified Date = 4/18/2007 5:19:44 PM | Attr = ]
avgmfx86.sys -> %System32%\drivers\avgmfx86.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.447 | Size = 19840 bytes | Modified Date = 4/18/2007 5:19:44 PM | Attr = ]
avgtdi.sys -> %System32%\drivers\avgtdi.sys -> GRISOFT, s.r.o. [Ver = 7,0,0,346 | Size = 4960 bytes | Modified Date = 4/18/2007 5:19:44 PM | Attr = ]
sp_rsdrv2.sys -> %System32%\drivers\sp_rsdrv2.sys -> [Ver = | Size = 135936 bytes | Modified Date = 4/7/2007 8:01:40 AM | Attr = ]

[File String Scan - Non-Microsoft Only]
WSUD , -> %SystemDrive%\S50main.mi4 -> [Ver = | Size = 3305472 bytes | Modified Date = 2/17/2006 6:24:40 PM | Attr = ]
PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41397 bytes | Modified Date = 8/4/2004 7:00:00 AM | Attr = ]
UPX! , UPX0 , -> %System32%\dXCtrls.dll -> [Ver = 1, 0, 0, 1 | Size = 124416 bytes | Modified Date = 6/28/2000 2:00:00 AM | Attr = ]
winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 8/4/2004 7:00:00 AM | Attr = ]
Thawte Consulting , -> %System32%\XCEEDZIP.DLL -> Xceed Software Inc [removed] [removed] www.xceedsoft.com [Ver = 5.1.5062.0 | Size = 456536 bytes | Modified Date = 1/12/2005 11:19:46 AM | Attr = ]
WSUD , UPX0 , -> %System32%\dllcache\hwxjpn.dll -> [Ver = | Size = 13463552 bytes | Modified Date = 8/4/2004 7:00:00 AM | Attr = ]
PTech , -> %System32%\dllcache\mtlstrm.sys -> Smart Link [Ver = 3.80.01MC15 | Size = 1309184 bytes | Modified Date = 8/3/2004 11:41:38 PM | Attr = ]
UPX! , FSG! , PEC2 , aspack , -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.444 | Size = 775680 bytes | Modified Date = 4/18/2007 5:19:40 PM | Attr = ]

< End of report >


F-Secure Blacklight

04/18/07 17:39:01 [Info]: BlackLight Engine 1.0.61 initialized
04/18/07 17:39:01 [Info]: OS: 5.1 build 2600 (Service Pack 2)
04/18/07 17:39:01 [Note]: 7019 4
04/18/07 17:39:01 [Note]: 7005 0
04/18/07 17:41:45 [Note]: 7006 0
04/18/07 17:41:48 [Note]: 7011 796
04/18/07 17:41:48 [Note]: 7026 0
04/18/07 17:41:48 [Note]: 7026 0
04/18/07 17:41:52 [Note]: FSRAW library version 1.7.1021
04/18/07 17:49:16 [Note]: 7007 0

HJT

Logfile of HijackThis v1.99.1
Scan saved at 6:10:18 PM, on 4/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Genie-Soft\GBM7Home\GBMAgent.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Mark Bennett\Desktop\WinPFind3u\WinPFind3U.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Fire-Trust SiteHound - {C86AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\Program Files\FireTrust\SiteHound\SiteHound.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: SiteHound - {73F7F495-A325-4C52-BE48-5F97FA511E89} - C:\Program Files\FireTrust\SiteHound\SiteHound.dll
O4 - HKLM\..\Run: [WinPatrol] "C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe"
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [GBMHome7Agent] "C:\Program Files\Genie-Soft\GBM7Home\GBMAgent.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [GBMHome7Agent] "C:\Program Files\Genie-Soft\GBM7Home\GBMAgent.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {11316B13-33F0-4C9F-BD55-09994CCFA8EB} - C:\Program Files\FireTrust\SiteHound\SiteHound.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://supportsoft.adelphia.net/sdccommon/…ad/tgctlins.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1153183810718
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37680.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: Visual Studio 2005 Remote Debugger (msvsmon80) - Unknown owner - C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: OracleJobSchedulerXE - Unknown owner - c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oraclexe\app\oracle\product\10.2.0\server\BIN\omtsreco.exe
O23 - Service: OracleServiceXE - Oracle Corporation - c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE
O23 - Service: OracleXEClrAgent - Unknown owner - C:\oraclexe\app\oracle\product\10.2.0\server\bin\OraClrAgnt.exe
O23 - Service: OracleXETNSListener - Unknown owner - C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe
O23 - Service: OSCM Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Novatel Wireless\Sprint\Sprint PCS Connection Manager\OSCMUtilityService.exe
O23 - Service: Port Reporter (PortReporter) - Unknown owner - C:\Program Files\PortReporter\portreporter.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
O23 - Service: ProgramCheckerPro (sassvc) - Unknown owner - C:\Program Files\Zenturi\ProgramChecker\sassvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

I'm probably going to remove Adaware. I've got so many other projects. Plus, you seem satisfied with my other security programs.

I was able to finally get ZoneAlarm installed using their support. The GMP109.tmp file was one of the files they had me delete. So it's no longer on my machine. And I finally got sitehound officially installed after a few semi nasty emails to their support team. I tried for four days to get an id so I could register and install the program. I went ahead and purchased it as well. So I don't know if you can get a sitehound id without first buying the program.

Finally, I removed AVG 7.5 and downloaded the Kaspersky antivirus trial version. My first scan produced no threats. It did, though, say I have some corrupted files. But the program didn't tell which ones they were. Plus numerous problems developed after the scan(i.e. it blocked several dll files that disabled firefox). And my machine slowed to a crawl. So I removed the program and went back to purchased AVG. I'm glad I didn't remove the exe file after removing the program. I can now access firefox without any error messages and the performance has noticably improved.
The only thing I can fnd in that log is the following that I'm not sure about.
_____________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


c:/windows/ststem32\bih.dll


Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html


Please post the results from Jottis or Virus total.
I ran the first scan. When it finished, only a note was posted saying it had been scanned before and no threats were found. Therefore it would not be posted in their database. I watched the scan the results for each program said - "found nothing"

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI