This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trying To Work On Son's Computer

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I would appreciate it if someone could take a look at HJT log from my Son's PC. He has an X86HP ( with a new hard drive). His OS is Windows XP SP2. Both his CD drive and Floppy are Kaput,but if we can get the bad stuff off ,we are going to try to install these ,plus some memory ,this weekend.
I have already tried all of these :
AVG Free
Spybot
Adaware
ATF-Cleaner
AVGarkt
SDFix
Catchme
Super Antispyware
CWShredder (None)
Blacklight ( This showed 0 )
Vundo Fix

When we last tried ,he still couldn't get on line,so I would like to know what to try next. Here is the HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 10:38:24 AM, on 5/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Documents and Settings\David\My Documents\Unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5C740BC3-6E64-451E-BDCC-56F4282C5493} - C:\WINDOWS\system32\gebcc.dll (file missing)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7dd89444-248a-4d2c-88ca-5b12fc7df606} - C:\WINDOWS\system32\hnetdir.dll (file missing)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [BootService] rundll32.exe "C:\WINDOWS\fccawt.dll",realset
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB} (Street Technologies ActiveX Control Object) - http://www.tutorials.com/plugins/Plugin050…eetnoagent7.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://mymail.humana.com/iNotes6W.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1109624551750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1152669359626
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/41/install/gtdownls.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} (SAIX) - http://static.zangocash.com/cab/Zango/ie/b…d84c831d43d35df
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/insta…cdetection3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8208ABBE-A468-4911-ADBA-DAE31CF2F43D}: NameServer = 206.141.193.55,66.73.20.40
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxq.dll
O20 - Winlogon Notify: gebcc - C:\WINDOWS\system32\gebcc.dll (file missing)
O20 - Winlogon Notify: hnetdir - hnetdir.dll (file missing)
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

TIA
Hi, oldladywhoand welcome to Tom Coyote forums

I am currently looking over your log. As I am an Undergraduate, everything that I post to you must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.

Thanks for your patience!
dan
Hi oldladywho

Can you create a folder on your desktop and name it "HJT" copy "HijackThis.exe" and paste into the new folder called HJT
We do this because HJT needs it's own folder to create backups, should we need them.
Do this before we continue
____________________________

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a logfile located at C:\ComboFix.txt.
4. Post the contents of that log in your next reply with a new hijackthis log.


Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Please include new HJT log plus combofix report
in your next post
Thanks dan
Hi Dan ,
Here is the ComboFix.txt
"David" - 2007-05-02 18:56:45 Service Pack 2
ComboFix 07-05.03.2.V - Running from: "F:\"


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\vexg3am1et3.exe
C:\WINDOWS\system32\vexg4am1et2.exe
C:\1.exe
C:\WINDOWS\updater.exe
C:\WINDOWS\system32\tmp1.tmp.dll
C:\WINDOWS\system32\tmp185.tmp.dll
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Documents and Settings\All Users.\documents\settings
C:\WINDOWS\system32\a3dxq.dll


((((((((((((((((((((((((((((((( Files Created from 2007-04-02 to 2007-05-02 ))))))))))))))))))))))))))))))))))


2007-04-30 20:59 d——– C:\WINDOWS\pss
2007-04-30 20:47 90,112 –a—— C:\WINDOWS\system32\regdacl.exe
2007-04-30 20:47 53,248 –a—— C:\WINDOWS\system32\process.exe
2007-04-30 20:47 4,096 –a—— C:\WINDOWS\system32\reboot.exe
2007-04-30 20:47 278,902 –a—— C:\win32delfkil.exe
2007-04-30 20:47 16,384 –a—— C:\WINDOWS\system32\restart.exe
2007-04-30 20:47 d——– C:\WINDOWS\system32\regdacl
2007-04-30 20:10 d——– C:\Sample Files
2007-04-30 15:28 d——– C:\VundoFix Backups
2007-04-30 15:21 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2007-04-30 15:21 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2007-04-28 12:02 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-04-28 12:00 d——– C:\Program Files\SUPERAntiSpyware
2007-04-28 12:00 d——– C:\DOCUME~1\David\APPLIC~1\SUPERAntiSpyware.com
2007-04-26 12:45 d——– C:\DOCUME~1\David\APPLIC~1\U3
2007-04-26 12:32 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\U3
2007-04-24 20:27 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
2007-04-21 18:52 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-04-18 21:39 9,526 –a—— C:\xx1232255.exe
2007-04-14 10:06 d——– C:\Program Files\Common Files\Scanner
2007-04-12 23:55 106,767 –a—— C:\WINDOWS\fccawt.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-05-02 23:56:26 ——– d—–w C:\DOCUME~1\David\APPLIC~1.\U3
2007-04-28 20:54:12 ——– d—–w C:\Program Files\Winamp
2007-04-28 20:53:13 ——– d—–w C:\Program Files\Yahoo!
2007-04-28 17:00:46 ——– d—–w C:\DOCUME~1\David\APPLIC~1.\SUPERAntiSpyware.com
2007-04-25 03:21:01 ——– d—–w C:\Program Files\Musicmatch
2007-04-25 03:08:02 ——– d—–w C:\Program Files\Windows Defender
2007-04-24 19:49:16 ——– d—–w C:\DOCUME~1\David\APPLIC~1.\Lavasoft
2007-04-20 02:54:57 ——– d—–w C:\DOCUME~1\David\APPLIC~1.\AdobeUM
2007-03-30 02:19:24 ——– d—–w C:\DOCUME~1\David\APPLIC~1.\AdobeAUM
2007-03-28 14:27:37 ——– d—–w C:\Program Files\QuickTime
2007-03-28 00:26:05 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-03-22 01:08:51 ——– d—–w C:\DOCUME~1\David\APPLIC~1.\MSN6
2007-03-19 22:14:22 27,389 —-a-w C:\WINDOWS\system32\mllmn.exe
2007-03-09 06:02:00 75,512 —-a-w C:\WINDOWS\zllsputility.exe
2007-03-09 06:01:42 1,087,216 —-a-w C:\WINDOWS\system32\zpeng24.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{02478D38-C3F9-4EFB-9B51-7695ECA05670}"="C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll"
"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"="C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll"
"{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}"="C:\Program Files\Yahoo!\Common\yiesrvc.dll"
"{5C740BC3-6E64-451E-BDCC-56F4282C5493}"="C:\WINDOWS\system32\gebcc.dll" [x]
"{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}"="C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll" [x]
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"="C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll"
"{7dd89444-248a-4d2c-88ca-5b12fc7df606}"="C:\WINDOWS\system32\hnetdir.dll" [x]
"{B56A7D7D-6927-48C8-A975-17DF180C71AC}"="C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll" [x]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoColorChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoDispSettingsPage"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSaveSettings"=dword:00000000
"NoThemesTab"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebcc
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hnetdir

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\
Security Packages kerberosmsv1_0schannelwdigest\
Notification Packages scecli\


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ares"="\"C:\\Program Files\\Ares\\Ares.exe\" -h"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Shareaza"="\"C:\\Program Files\\Shareaza\\Shareaza.exe\" -tray"
"Yahoo! Pager"="\"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\YAHOOM~1.EXE\" -quiet"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MMTray"="C:\\Program Files\\Musicmatch\\Musicmatch Jukebox\\mm_tray.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"runner1"="C:\\WINDOWS\\updater.exe 61A847B5BBF72810358B2B27128065E9C084320161C4661227A755E9C2933154389A"
"KernelFaultCheck"="%systemroot%\\system32\\dumprep 0 -k"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MDM"=dword:00000002
"iPodService"=dword:00000003

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService DnsCache\
rpcss RpcSs\
imgsvc StiSvc\
termsvcs TermService\
HTTPFilter HTTPFilter\
DcomLaunch DcomLaunchTermService\


********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-02 19:02:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 2007-05-02 19:04:23 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-05-02 19:04

And here is the HJT log

Logfile of HijackThis v1.99.1
Scan saved at 7:10:12 PM, on 5/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Documents and Settings\David\Application Data\U3\00186F6A62AB3D\LaunchPad.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5C740BC3-6E64-451E-BDCC-56F4282C5493} - C:\WINDOWS\system32\gebcc.dll (file missing)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7dd89444-248a-4d2c-88ca-5b12fc7df606} - C:\WINDOWS\system32\hnetdir.dll (file missing)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB} (Street Technologies ActiveX Control Object) - http://www.tutorials.com/plugins/Plugin050…eetnoagent7.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://mymail.humana.com/iNotes6W.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1109624551750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1152669359626
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/41/install/gtdownls.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} (SAIX) - http://static.zangocash.com/cab/Zango/ie/b…d84c831d43d35df
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/insta…cdetection3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8208ABBE-A468-4911-ADBA-DAE31CF2F43D}: NameServer = 206.141.193.55,66.73.20.40
O20 - Winlogon Notify: gebcc - C:\WINDOWS\system32\gebcc.dll (file missing)
O20 - Winlogon Notify: hnetdir - hnetdir.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Again, Thank YOU

Oldladywho
Hi oldladywho

I see from your log you may have a youngster who uses "peer-to-peer crapola" if for the duration of the fix whilst I'm assisting you clean up can you
knock off the use of that site.

Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath,browse and find the file click open which will place it in the field.

C:\WINDOWS\system32\process.exe
C:\WINDOWS\fccawt.dll

Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html


Ewido is now known as ( AVG Anti-Spyware.)

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

Dont use yet!

Make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.

You will now be presented with a screen similar to the one below:

[external image: Posted Image]

5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.



__________________________

Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present)

O2 - BHO: (no name) - {5C740BC3-6E64-451E-BDCC-56F4282C5493} - C:\WINDOWS\system32\gebcc.dll (file missing)
O2 - BHO: (no name) - {7dd89444-248a-4d2c-88ca-5b12fc7df606} - C:\WINDOWS\system32\hnetdir.dll (file missing)
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)

I noticed you have allowed some sites into your trusted zone!
MusicMatch just automatically sets itself up in the trusted zone and should be removed as there is no reason for it to be there, as for the other site that's up to you, however, realize that you are taking a big security risk by allowing any site to have unfettered access to your Trusted Zone.
This is your call it's your machine, I can only advise you.
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)

O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} (SAIX) - http://static.zangocash.com/cab/Zango/ie/b…d84c831d43d35df
O20 - Winlogon Notify: gebcc - C:\WINDOWS\system32\gebcc.dll (file missing)
O20 - Winlogon Notify: hnetdir - hnetdir.dll (file missing)

WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit

We need to reveal system folders
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon.
  • Select the Tools menu and click Folder Options
  • After the new window appears select the View tab.
  • Place a checkmark in the checkbox labeled Display the contents of system folders
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types
  • Remove the checkmark from the checkbox labeled Hide protected operating system files
  • Press the Apply and then the ok button and shut down my computer
  • Now your computer is configured to show all hidden files.
  • For you and the tools to be able to see appropriate files we need to Show Hidden Files
Re-boot into safe mode

  • Next, please reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear use arrow up to highlight
  • Select the first option, to run Windows in Safe Mode hit enter.
  • For additional help in booting into Safe Mode, see the following site: HERE
Right click start, In the drop down menu click "Explore" Then navigate to each file\ folder in the left hand pane, which will reveal its content in the right hand pane, highlight file or folder right click and Delete, if present:

C:\VundoFix Backups << This folder
C:\WINDOWS\system32\mllmn.exe << This file
C:\xx1232255.exe << This file
C:\WINDOWS\system32\hnetdir.dll << This file
C:\WINDOWS\system32\gebcc.dll << This file

Run ATF cleaner that I see you haveused before
  • Double click ATF-Cleaner.exe to run the program.
  • Check the following boxes:
    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Prefetch
    • Recycle Bin
    • Java Cache
  • The rest are optional - if you want to remove the lot, check Select All.
  • Now click Empty Selected.
  • When you get the Done Cleaning message, click OK.
  • If you use Firefox browser.
    • Click Firefox at the top and choose: Select All
    • If you would like to keep your saved passwords, please click No at the prompt.
    • Click the Empty Selected button.
  • If you use Opera browser.
    • Click Opera at the top and choose: Select All
    • If you would like to keep your saved passwords, please click No at the prompt.
    • Click the Empty Selected button.

Run AVG Anti-Spyware

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)

      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.

________________________

please do an online scan with Kaspersky Online Scanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Extended (If available otherwise Standard)
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

Please include new HJT log, AVG Anti-Spyware log and kaspersky log plus the jotti's results.
in your next post
Thanks dan
Whew!! I have my son's computer at my house ,so I could spend more time on it . He hadn't been able to go online,so to do the Jotti,I tried hooking his computer up to my DSL. I was able to access the site ,but it wouldn't do anything,I also tried the Virustotal with the same result. I spent 2 hours trying. At one point I right clicked the "fccawt.dll and did an AVGas scan. "Trojan horse Generic3.VBL" and it was moved to the vault. However I did the HJT log : Ad-Aware SE Personal Adobe Download Manager 2.0 (Remove Only) Adobe Flash Player 9 ActiveX Adobe Photoshop Album 2.0 Starter Edition Adobe Reader 7.0.7 AVG Anti-Rootkit Free AVG Anti-Spyware 7.5 AVG Free Edition Formatting Solutions Pro 2.2 Google Toolbar for Internet Explorer HijackThis 1.99.1 hp deskjet 630c series Internet Explorer Q903235 iTunes Java™ SE Runtime Environment 6 Update 1 Learn.com Player (Uninstall Only) MetaFrame Presentation Server Web Client for Win32 Microsoft Office XP Professional with FrontPage QuickTime Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893066) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB912919) Shareaza version 2.2.1.0 Spybot - Search & Destroy 1.3 Update for Windows XP (KB898461) Update for Windows XP (KB910437) Winamp (remove only) Windows Defender Signatures Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WinLyrics WinZip Yahoo! Browser Services Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Toolbar ZoneAlarm And here is the AVGas log AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 10:33:37 PM 5/4/2007 + Scan result: C:\SDFix\backups\backups.zip/backups/SAIX.dll -> Adware.180Solutions : Cleaned with backup (quarantined). C:\WINDOWS\system32\gtdownls_95.ocx -> Adware.Gdown : Cleaned with backup (quarantined). C:\Program Files\HijackThis\backups\backup-20070504-205748-414.dll -> Adware.Minibug : Cleaned with backup (quarantined). C:\Program Files\Microsoft AntiSpyware\Quarantine8ACD978-6636-4781-A965-E091D5\3CF7A4C9-A565-464E-86AE-932212 -> Adware.NavExcel : Cleaned with backup (quarantined). C:\Program Files\Microsoft AntiSpyware\Quarantine8ACD978-6636-4781-A965-E091D5\42589B94-A208-42DD-9EAF-F6B647 -> Adware.NavExcel : Cleaned with backup (quarantined). C:\Documents and Settings\David\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine3176E0F-E89F-42AD-9DF1-DAA9CB\8E251126-3F5A-4B13-BA70-D9DADD -> Adware.SpywareStorm : Cleaned with backup (quarantined). C:\Documents and Settings\David\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\D4F2A69B-2653-44B2-824F-19BAA5\6ED26023-33C5-4BF6-B180-B68542 -> Adware.SpywareStrike : Cleaned with backup (quarantined). C:\Documents and Settings\David\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\FE595AF7-8739-46C6-A162-EA82E1\59FF1918-5E3C-4FA1-845E-040675 -> Adware.SpywareStrike : Cleaned with backup (quarantined). C:\Program Files\Microsoft AntiSpyware\Quarantine\221D9B3D-CCA0-450E-8FA2-AAF8A4\63B52120-BF49-403B-9B60-002851 -> Adware.SpywareStrike : Cleaned with backup (quarantined). C:\Program Files\Microsoft AntiSpyware\Quarantine\6237B665-8945-48AB-9793-F0AF11\7E9A6F4D-E406-4ED6-9E35-01BB91 -> Adware.SpywareStrike : Cleaned with backup (quarantined). C:\Program Files\Microsoft AntiSpyware\Quarantine\E2F0BB03-BB84-4BD3-9FF3-2583D0\A02DA441-11BA-48F6-9DE2-B8E8A0 -> Adware.SpywareStrike : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/tmp2.tmp.exe -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/tmpA2.tmp.exe -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/tmp1.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/tmp12.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/tmp65.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/tmpA3.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\updater.exe.vir -> Downloader.Agent.bls : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/sstray.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/vexga5me3.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\1.exe.vir -> Downloader.Small.bve : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/1.exe -> Downloader.Small.bve : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/2.dllb -> Downloader.Small.cpg : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/dlh9jkd1q2.exe -> Downloader.Small.cpg : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/xpupdate.exe -> Downloader.Small.cpg : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/svhost.exe -> Downloader.Small.dxm : Cleaned with backup (quarantined). C:\Documents and Settings\David\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\6E912328-9AB6-4AF7-B17B-5B4AD3\84D78DC9-BC84-4352-90C7-3FF6E3 -> Downloader.Zlob.tj : Cleaned with backup (quarantined). C:\Program Files\Microsoft AntiSpyware\Quarantine\221D9B3D-CCA0-450E-8FA2-AAF8A4\7F8F83F3-5D55-44D9-923C-85556B -> Downloader.Zlob.tj : Cleaned with backup (quarantined). C:\WINDOWS\system32\windev-341-21d6.sy_ -> Not-A-Virus.SpamTool.Win32.Agent.af : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/vexga4me1.exe -> Proxy.Xorpix.ba : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\vexg3am1et3.exe.vir -> Proxy.Xorpix.m : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/tmp75.tmp.exe -> Trojan.Agent.agv : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\tmp1.tmp.dll.vir -> Trojan.BHO.g : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\tmp185.tmp.dll.vir -> Trojan.BHO.o : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/tmp185.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/tmp5.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/tmp27.tmp.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/tmp76.tmp.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/7.dllb -> Worm.Nuwar.gen : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/dlh9jkd1q7.exe -> Worm.Nuwar.gen : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\vexg4am1et2.exe.vir -> Worm.Zhelatin.da : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/6.dllb -> Worm.Zhelatin.da : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/dlh9jkd1q6.exe -> Worm.Zhelatin.da : Cleaned with backup (quarantined). ::Report end We are going to have to take the PC back to his house to do the Jotti,and the Kaspersky.You just can't fool Mother Bell. I did all the other things,though, I couldn't find C:\WINDOWS\system32\hnetdir.dll or C:\WINDOWS\system32\gebcc.dll. I did find "hnetcfg.dll,hnetmon.dll,and hnetwi2.dll in C:WINDOWS\system32\. I will post the Jotti and Kaspersky logs ,as soon as I can.The computer is acting so much better than it was when we started,I can hardly believe it is the same piece of ..stuff. Thank you, oldladywho
Hey Dan,
I am not sure whether I am making progress or spinning my wheels. I still can't get the computer on the internet…exactly. If I try to use the browser,I get the "Page cannot be displayed" error.But I am able to type in some Urls and go to the site . I just can't do anything when I get there. Passwords don't work,for instance,and the Kaspersky,came up but when I clicked the scan button ,I just got a white window,that apparently does nothing.In going through all the files on the computer, I find there is no search,just the blue screen and dog,and in Windows HELP the index is blank. In C:\Windows\system32\ there is something called a "dllcache" that is highlighted.
Now from Virustotal .I got this by using email:

Complete scanning result of "process.exe", processed in VirusTotal at 05/06/2007 22:16:51 (CET).

[ file data ]
* name: process.exe
* size: 53248
* md5.: 7397f6ee4a9601a123b645c0cd428017
* sha1: 890368473ecbc404dcd42ff0c6c38397102f59c0

[ scan result ]
AhnLab-V3 2007.5.4.0/20070504 found [Win-AppCare/PrcViewer.53248]
AntiVir 7.4.0.15/20070506 found nothing
Authentium 4.93.8/20070504 found nothing
Avast 4.7.997.0/20070505 found nothing
AVG 7.5.0.467/20070506 found nothing
BitDefender 7.2/20070506 found nothing
CAT-QuickHeal 9.00/20070505 found nothing
ClamAV devel-20070416/20070506 found nothing
DrWeb 4.33/20070506 found nothing
eSafe 7.0.15.0/20070503 found nothing
eTrust-Vet 30.7.3615/20070505 found nothing
Ewido 4.0/20070506 found nothing
F-Prot 4.3.2.48/20070504 found nothing
F-Secure 6.70.13030.0/20070506 found nothing
FileAdvisor 1/20070506 found [No threat detected]
Fortinet 2.85.0.0/20070506 found [Misc/PrcViewer]
Ikarus T3.1.1.7/20070506 found nothing
Kaspersky 4.0.2.24/20070506 found nothing
McAfee 5024/20070504 found [potentially unwanted program PrcViewer]
Microsoft 1.2503/20070506 found nothing
NOD32v2 2245/20070506 found [Win32/PrcView]
Norman 5.80.02/20070504 found nothing
Panda 9.0.0.4/20070506 found [Application/Processor]
Prevx1 V2/20070506 found nothing
Sophos 4.17.0/20070505 found nothing
Sunbelt 2.2.907.0/20070505 found nothing
Symantec 10/20070506 found nothing
TheHacker 6.1.6.104/20070415 found [Aplicacion/Processor.20]
VBA32 3.11.4/20070504 found nothing
VirusBuster 4.3.7:9/20070506 found nothing
Webwasher-Gateway 6.0.1/20070506 found nothing

[ notes ]
Bit9 info: http://fileadvisor.bit9.com/services/extin…3b645c0cd428017

Here is the latest HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 6:17:37 PM, on 5/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB} (Street Technologies ActiveX Control Object) - http://www.tutorials.com/plugins/Plugin050…eetnoagent7.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://mymail.humana.com/iNotes6W.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1109624551750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1152669359626
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/41/install/gtdownls.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/insta…cdetection3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8208ABBE-A468-4911-ADBA-DAE31CF2F43D}: NameServer = 206.141.193.55,66.73.20.40
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I sure would like to get this thing cleaned up ,I'm thinking I may have to do a reinstall of his Windows XP,but I plan to wait for the word of the expert ,you.

Thank You,

oldladywho
Hi oldladywho

I see from your logs you use p2p "Shareaza" and "Ares" whilst trying to clean you up please refrain from using these sites.
These programs often come with undesirable components bundled in them. Please visit http://p2p.malwareremoval.com/ information on what programs are considered bad along with the related malware they install. Also included are programs considered clean
_________________

You seem to be seriously lacking in xp updates any reason for this, are you having problems with updates?

Download WinPFind3U.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
  • Now click the Run Scan button on the toolbar.
  • The program will be scanning huge amounts of data so depending on your system it could take a long time to complete. Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in. If, after posting, the last line is not < End of Report > then the log is too big to fit into a single post and you will need to split it into multiple posts.

Thanks dan
Hi dan,
Here is the log of fccawt (AVG) :
"","","Trojan horse Generic3.VBL","C:\WINDOWS\fccawt.dll","5/4/2007 8:31:55 PM","fccawt.dll","104.26 KB" It is a CSV file .

Here is the WinPFind3:

WinPFind3 logfile created on: 5/7/2007 12:11:14 PM
WinPFind3U by OldTimer - Version 1.0.35 Folder = C:\Documents and Settings\David\Desktop\WinPFind3u\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 6.0.2900.2180)

126.48 Mb Total Physical Memory | 29.84 Mb Available Physical Memory | 23.59% Memory free
339.28 Mb Paging File | 102.61 Mb Available in Paging File | 30.24% Paging File free
Paging file location(s): C:\pagefile.sys 192 384;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 69.12 Gb Free Space | 92.75% Space Free
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded

Computer Name: LUTHER-LU6WQH3X
Current User Name: David
Logged in as Administrator.
Current Boot Mode: Normal


[Processes - Non-Microsoft Only]
avgamsvr.exe -> %ProgramFiles%\Grisoft\AVG Free\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.453 | Size = 353280 bytes | Modified Date = 5/4/2007 6:11:02 PM | Attr = ]
avgupsvc.exe -> %ProgramFiles%\Grisoft\AVG Free\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 4/4/2007 5:18:32 AM | Attr = ]
guard.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Modified Date = 9/28/2006 9:13:20 AM | Attr = ]
winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.35.0 | Size = 319488 bytes | Modified Date = 5/6/2007 9:38:54 AM | Attr = ]

[Win32 Services - Non-Microsoft Only]
(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Modified Date = 9/28/2006 9:13:20 AM | Attr = ]
(Avg7Alrt) AVG7 Alert Manager Server [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Free\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.453 | Size = 353280 bytes | Modified Date = 5/4/2007 6:11:02 PM | Attr = ]
(Avg7UpdSvc) AVG7 Update Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Free\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 4/4/2007 5:18:32 AM | Attr = ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 2:56:48 AM | Attr = ]
(iPodService) iPod Service [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Computer, Inc. [Ver = 4.9.0.17 | Size = 331776 bytes | Modified Date = 6/24/2005 3:16:26 PM | Attr = ]
(vsmon) TrueVector Internet Monitor [Win32_Own | Auto | Stopped] -> %System32%\ZoneLabs\vsmon.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 75568 bytes | Modified Date = 3/9/2007 1:01:58 AM | Attr = ]

[Registry - Non-Microsoft Only]
< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Zone Labs Client -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 919280 bytes | Modified Date = 3/9/2007 1:02:00 AM | Attr = ]
ZoneAlarm Client -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 919280 bytes | Modified Date = 3/9/2007 1:02:00 AM | Attr = ]
< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\
IMAIL -> Installed = 1 ->
MAPI -> Installed = 1 ->
MSFS -> Installed = 1 ->
< AppInit_DLLs [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
< ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKLM] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 73728 bytes | Modified Date = 9/28/2006 9:13:28 AM | Attr = ]
< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
< HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts
127.0.0.1 localhost -> ->
< Internet Explorer Settings > ->
HKLM: Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome ->
HKLM: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch ->
HKLM: Local Page -> http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome ->
HKLM: Search Bar -> http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm ->
HKLM: Search Page -> http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch ->
HKLM: Start Page -> about:blank ->
HKLM: CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKLM: Search\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch ->
HKLM: SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
HKCU: Local Page -> http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome ->
HKCU: Search Page -> http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch ->
HKCU: Start Page -> http://www.google.com/ ->
HKCU: CustomizeSearch -> http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchcust.htm ->
HKCU: SearchAssistant -> http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm ->
HKCU: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn1\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 4:39:26 PM | Attr = ]
HKCU: ProxyEnable -> 0 ->
< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
msn.com [ - ] -> ->
awbeta_net-nucleus.com [https] -> ->
< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4EFB-9B51-7695ECA05670} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn1\yt.dll [&Yahoo! Toolbar Helper] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 4:39:26 PM | Attr = ]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [AcroIEHlprObj Class] -> Adobe Systems Incorporated [Ver = 7.0.7.2006011200 | Size = 63128 bytes | Modified Date = 1/12/2006 9:38:22 PM | Attr = ]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> %ProgramFiles%\Yahoo!\Common\yiesrvc.dll [Yahoo! IE Services Button] -> Yahoo! Inc. [Ver = 2006, 1, 5, 1 | Size = 181752 bytes | Modified Date = 1/6/2006 12:52:14 PM | Attr = ]
{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} [HKLM] -> %SystemDrive%\PROGRA~1\SPYWAR~2\tools\iesdsg.dll [PCTools Site Guard] -> File not found
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 3/14/2007 3:43:40 AM | Attr = ]
{B56A7D7D-6927-48C8-A975-17DF180C71AC} [HKLM] -> %SystemDrive%\PROGRA~1\SPYWAR~2\tools\iesdpb.dll [PCTools Browser Monitor] -> File not found
< Internet Explorer Bars [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\
{2D51D869-C36B-42BD-AE68-0A81BC771FA5} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
{32683183-48a0-441b-a342-7c2a440a9478} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
< Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn1\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 4:39:26 PM | Attr = ]
< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn1\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 4:39:26 PM | Attr = ]
< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\npjpi160_01.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 132760 bytes | Modified Date = 3/14/2007 3:43:42 AM | Attr = ]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKCU] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 3/14/2007 3:43:40 AM | Attr = ]
{2D663D1A-8670-49D9-A1A5-4C56B4E14E84} -> Reg Data - Value does not exist [ButtonText: Spyware Doctor] -> File not found
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -> Reg Data - Value does not exist [ButtonText: Yahoo! Services] -> File not found
< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\
&Google Search -> %ProgramFiles%\Google\GoogleToolbar1.dll\cmsearch.htm -> File not found
&Yahoo! Search -> %ProgramFiles%\Yahoo!\Common\YCSRCH.HTM -> [Ver = | Size = 605 bytes | Modified Date = 6/3/2005 7:07:38 PM | Attr = ]
Backward Links -> %ProgramFiles%\Google\GoogleToolbar1.dll\cmbacklinks.htm -> File not found
Cached Snapshot of Page -> %ProgramFiles%\Google\GoogleToolbar1.dll\cmcache.htm -> File not found
E&xport to Microsoft Excel -> -> File not found
Similar Pages -> %ProgramFiles%\Google\GoogleToolbar1.dll\cmsimilar.htm -> File not found
Translate into English -> %ProgramFiles%\Google\GoogleToolbar1.dll\cmtrans.htm -> File not found
Yahoo! &Dictionary -> %ProgramFiles%\Yahoo!\Common\YCDICT.HTM -> [Ver = | Size = 616 bytes | Modified Date = 6/3/2005 7:07:16 PM | Attr = ]
Yahoo! &Maps -> %ProgramFiles%\Yahoo!\Common\ycmap.htm -> [Ver = | Size = 690 bytes | Modified Date = 6/3/2005 7:07:44 PM | Attr = ]
Yahoo! &SMS -> %ProgramFiles%\Yahoo!\Common\YCsms.htm -> [Ver = | Size = 1006 bytes | Modified Date = 8/1/2005 6:43:00 PM | Attr = ]
< User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
SV1 -> ->
< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\
{8208ABBE-A468-4911-ADBA-DAE31CF2F43D} -> 206.141.193.55,66.73.20.40 (Realtek RTL8139 Family PCI Fast Ethernet NIC) ->
< Default Protocols [HKCU] - Select to Repair > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
shell -> shell protocol not assigned ->
< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\
http -> Reg Data - Key not found -> File not found
https -> Reg Data - Key not found -> File not found
ipp -> Reg Data - Key not found -> File not found
msdaipp -> Reg Data - Key not found -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\
{02BCC737-B171-4746-94C9-0D8A0B2C0089} -> Microsoft Office Template and Media Control - CodeBase = http://office.microsoft.com/templates/ieawsdc.cab ->
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} -> QuickTime Object - CodeBase = http://www.apple.com/qtactivex/qtplugin.cab ->
{0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB} -> Street Technologies ActiveX Control Object - CodeBase = http://www.tutorials.com/plugins/Plugin050…eetnoagent7.cab ->
{17492023-C23A-453E-A040-C7C580BBF700} -> Windows Genuine Advantage Validation Tool - CodeBase = http://go.microsoft.com/fwlink/?linkid=39204 ->
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -> YInstStarter Class - CodeBase = C:\Program Files\Yahoo!\Common\yinsthelper.dll ->
{33564D57-0000-0010-8000-00AA00389B71} -> - CodeBase = http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB ->
{3BFFE033-BF43-11D5-A271-00A024A51325} -> iNotes6 Class - CodeBase = https://mymail.humana.com/iNotes6W.cab ->
{6414512B-B978-451D-A0D8-FCFDF33E833C} -> WUWebControl Class - CodeBase = http://v5.windowsupdate.microsoft.com/v5co…b?1109624551750 ->
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -> MUWebControl Class - CodeBase = http://update.microsoft.com/microsoftupdat…b?1152669359626 ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab ->
{A93D84FD-641F-43AE-B963-E6FA84BE7FE7} -> LinkSys Content Update - CodeBase = http://www.linksysfix.com/netcheck/41/install/gtdownls.cab ->
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase = http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab ->
{D719897A-B07A-4C0C-AEA9-9B663A28DFCB} -> iTunesDetector Class - CodeBase = http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab ->
{E9348280-2D74-4933-BE25-73D946926795} -> DeviceEnum Class - CodeBase = http://h20270.www2.hp.com/ediags/gmn/insta…cdetection3.cab ->


[Files/Folders - Created Within 30 days]
QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 5/2/2007 5:59:06 PM | Attr = ]
Sample Files -> %SystemDrive%\Sample Files -> [Folder | Created Date = 4/30/2007 7:10:14 PM | Attr = ]
SDFix -> %SystemDrive%\SDFix -> [Folder | Created Date = 4/26/2007 11:48:51 AM | Attr = ]
win32delfkil.exe -> %SystemDrive%\win32delfkil.exe -> Marckie [Ver = 3. 1. 2. 5 | Size = 278902 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
$NtUninstallKB885884$ -> %SystemRoot%\$NtUninstallKB885884$ -> [Folder | Created Date = 5/4/2007 10:06:12 PM | Attr = H ]
$NtUninstallKB886185$ -> %SystemRoot%\$NtUninstallKB886185$ -> [Folder | Created Date = 5/4/2007 10:06:39 PM | Attr = H ]
$NtUninstallKB887472$ -> %SystemRoot%\$NtUninstallKB887472$ -> [Folder | Created Date = 5/4/2007 10:11:04 PM | Attr = H ]
$NtUninstallKB900485$ -> %SystemRoot%\$NtUninstallKB900485$ -> [Folder | Created Date = 5/4/2007 10:11:52 PM | Attr = H ]
$NtUninstallKB908531$ -> %SystemRoot%\$NtUninstallKB908531$ -> [Folder | Created Date = 5/4/2007 10:05:48 PM | Attr = H ]
$NtUninstallKB911280$ -> %SystemRoot%\$NtUninstallKB911280$ -> [Folder | Created Date = 5/4/2007 10:12:29 PM | Attr = H ]
$NtUninstallKB911562$ -> %SystemRoot%\$NtUninstallKB911562$ -> [Folder | Created Date = 5/4/2007 10:12:12 PM | Attr = H ]
$NtUninstallKB911564$ -> %SystemRoot%\$NtUninstallKB911564$ -> [Folder | Created Date = 5/4/2007 10:10:12 PM | Attr = H ]
$NtUninstallKB911927$ -> %SystemRoot%\$NtUninstallKB911927$ -> [Folder | Created Date = 5/4/2007 10:13:33 PM | Attr = H ]
$NtUninstallKB913580$ -> %SystemRoot%\$NtUninstallKB913580$ -> [Folder | Created Date = 5/4/2007 10:05:36 PM | Attr = H ]
$NtUninstallKB914388$ -> %SystemRoot%\$NtUninstallKB914388$ -> [Folder | Created Date = 5/4/2007 10:08:41 PM | Attr = H ]
$NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Created Date = 5/4/2007 10:05:11 PM | Attr = H ]
$NtUninstallKB916595$ -> %SystemRoot%\$NtUninstallKB916595$ -> [Folder | Created Date = 5/4/2007 10:06:32 PM | Attr = H ]
$NtUninstallKB917344$ -> %SystemRoot%\$NtUninstallKB917344$ -> [Folder | Created Date = 5/4/2007 10:08:32 PM | Attr = H ]
$NtUninstallKB917422$ -> %SystemRoot%\$NtUninstallKB917422$ -> [Folder | Created Date = 5/4/2007 10:07:50 PM | Attr = H ]
$NtUninstallKB917734_WMP9$ -> %SystemRoot%\$NtUninstallKB917734_WMP9$ -> [Folder | Created Date = 5/4/2007 10:14:29 PM | Attr = H ]
$NtUninstallKB917953$ -> %SystemRoot%\$NtUninstallKB917953$ -> [Folder | Created Date = 5/4/2007 10:08:24 PM | Attr = H ]
$NtUninstallKB918118$ -> %SystemRoot%\$NtUninstallKB918118$ -> [Folder | Created Date = 5/4/2007 10:07:03 PM | Attr = H ]
$NtUninstallKB918439$ -> %SystemRoot%\$NtUninstallKB918439$ -> [Folder | Created Date = 5/4/2007 10:09:26 PM | Attr = H ]
$NtUninstallKB919007$ -> %SystemRoot%\$NtUninstallKB919007$ -> [Folder | Created Date = 5/4/2007 10:08:50 PM | Attr = H ]
$NtUninstallKB920213$ -> %SystemRoot%\$NtUninstallKB920213$ -> [Folder | Created Date = 5/4/2007 10:06:47 PM | Attr = H ]
$NtUninstallKB920670$ -> %SystemRoot%\$NtUninstallKB920670$ -> [Folder | Created Date = 5/4/2007 10:09:35 PM | Attr = H ]
$NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Created Date = 5/4/2007 10:05:27 PM | Attr = H ]
$NtUninstallKB920685$ -> %SystemRoot%\$NtUninstallKB920685$ -> [Folder | Created Date = 5/4/2007 10:12:49 PM | Attr = H ]
$NtUninstallKB920872$ -> %SystemRoot%\$NtUninstallKB920872$ -> [Folder | Created Date = 5/4/2007 10:09:10 PM | Attr = H ]
$NtUninstallKB922582$ -> %SystemRoot%\$NtUninstallKB922582$ -> [Folder | Created Date = 5/4/2007 10:07:16 PM | Attr = H ]
$NtUninstallKB922819$ -> %SystemRoot%\$NtUninstallKB922819$ -> [Folder | Created Date = 5/4/2007 10:15:23 PM | Attr = H ]
$NtUninstallKB923191$ -> %SystemRoot%\$NtUninstallKB923191$ -> [Folder | Created Date = 5/4/2007 10:08:05 PM | Attr = H ]
$NtUninstallKB923414$ -> %SystemRoot%\$NtUninstallKB923414$ -> [Folder | Created Date = 5/4/2007 10:15:12 PM | Attr = H ]
$NtUninstallKB923689$ -> %SystemRoot%\$NtUninstallKB923689$ -> [Folder | Created Date = 5/4/2007 10:10:47 PM | Attr = H ]
$NtUninstallKB923694$ -> %SystemRoot%\$NtUninstallKB923694$ -> [Folder | Created Date = 5/4/2007 10:06:22 PM | Attr = H ]
$NtUninstallKB923980$ -> %SystemRoot%\$NtUninstallKB923980$ -> [Folder | Created Date = 5/4/2007 10:12:39 PM | Attr = H ]
$NtUninstallKB924191$ -> %SystemRoot%\$NtUninstallKB924191$ -> [Folder | Created Date = 5/4/2007 10:15:32 PM | Attr = H ]
$NtUninstallKB924270$ -> %SystemRoot%\$NtUninstallKB924270$ -> [Folder | Created Date = 5/4/2007 10:11:40 PM | Attr = H ]
$NtUninstallKB924496$ -> %SystemRoot%\$NtUninstallKB924496$ -> [Folder | Created Date = 5/4/2007 10:11:24 PM | Attr = H ]
$NtUninstallKB924667$ -> %SystemRoot%\$NtUninstallKB924667$ -> [Folder | Created Date = 5/4/2007 10:12:02 PM | Attr = H ]
$NtUninstallKB925398_WMP64$ -> %SystemRoot%\$NtUninstallKB925398_WMP64$ -> [Folder | Created Date = 5/4/2007 10:13:14 PM | Attr = H ]
$NtUninstallKB925902$ -> %SystemRoot%\$NtUninstallKB925902$ -> [Folder | Created Date = 5/4/2007 10:09:44 PM | Attr = H ]
$NtUninstallKB926255$ -> %SystemRoot%\$NtUninstallKB926255$ -> [Folder | Created Date = 5/4/2007 10:06:55 PM | Attr = H ]
$NtUninstallKB926436$ -> %SystemRoot%\$NtUninstallKB926436$ -> [Folder | Created Date = 5/4/2007 10:09:19 PM | Attr = H ]
$NtUninstallKB927779$ -> %SystemRoot%\$NtUninstallKB927779$ -> [Folder | Created Date = 5/4/2007 10:15:49 PM | Attr = H ]
$NtUninstallKB927802$ -> %SystemRoot%\$NtUninstallKB927802$ -> [Folder | Created Date = 5/4/2007 10:15:40 PM | Attr = H ]
$NtUninstallKB928090$ -> %SystemRoot%\$NtUninstallKB928090$ -> [Folder | Created Date = 5/4/2007 10:04:25 PM | Attr = H ]
$NtUninstallKB928255$ -> %SystemRoot%\$NtUninstallKB928255$ -> [Folder | Created Date = 5/4/2007 10:14:51 PM | Attr = H ]
$NtUninstallKB928843$ -> %SystemRoot%\$NtUninstallKB928843$ -> [Folder | Created Date = 5/4/2007 10:03:53 PM | Attr = H ]
$NtUninstallKB929969$ -> %SystemRoot%\$NtUninstallKB929969$ -> [Folder | Created Date = 5/4/2007 10:13:43 PM | Attr = H ]
$NtUninstallKB930178$ -> %SystemRoot%\$NtUninstallKB930178$ -> [Folder | Created Date = 5/4/2007 10:08:57 PM | Attr = H ]
$NtUninstallKB931261$ -> %SystemRoot%\$NtUninstallKB931261$ -> [Folder | Created Date = 5/4/2007 10:11:32 PM | Attr = H ]
$NtUninstallKB931784$ -> %SystemRoot%\$NtUninstallKB931784$ -> [Folder | Created Date = 5/4/2007 10:13:55 PM | Attr = H ]
$NtUninstallKB931836$ -> %SystemRoot%\$NtUninstallKB931836$ -> [Folder | Created Date = 5/4/2007 10:11:16 PM | Attr = H ]
$NtUninstallKB932168$ -> %SystemRoot%\$NtUninstallKB932168$ -> [Folder | Created Date = 5/4/2007 10:08:16 PM | Attr = H ]
catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 86528 bytes | Created Date = 5/2/2007 6:04:31 PM | Attr = ]
ddcehk.ini -> %SystemRoot%\ddcehk.ini -> [Ver = | Size = 1457880 bytes | Created Date = 4/8/2007 7:01:32 PM | Attr = HS]
Minidump -> %SystemRoot%\Minidump -> [Folder | Created Date = 4/19/2007 5:39:09 PM | Attr = ]
nircmd.exe -> %SystemRoot%\nircmd.exe -> NirSoft [Ver = 1.85 | Size = 49152 bytes | Created Date = 5/2/2007 6:04:29 PM | Attr = ]
pss -> %SystemRoot%\pss -> [Folder | Created Date = 4/30/2007 7:59:08 PM | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Created Date = 4/8/2007 7:20:56 PM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Created Date = 4/8/2007 7:20:55 PM | Attr = H ]
top10_24h_front.png -> %SystemRoot%\top10_24h_front.png -> [Ver = | Size = 19118 bytes | Created Date = 5/4/2007 6:46:37 PM | Attr = ]
twaccf.ini -> %SystemRoot%\twaccf.ini -> [Ver = | Size = 998339 bytes | Created Date = 4/12/2007 10:55:42 PM | Attr = HS]
update2.html -> %SystemRoot%\update2.html -> [Ver = | Size = 80896 bytes | Created Date = 4/17/2007 8:31:29 AM | Attr = ]
java.exe -> %System32%\java.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 135168 bytes | Created Date = 4/28/2007 2:57:22 PM | Attr = ]
javacpl.cpl -> %System32%\javacpl.cpl -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 69632 bytes | Created Date = 4/28/2007 2:57:22 PM | Attr = ]
javaw.exe -> %System32%\javaw.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 135168 bytes | Created Date = 4/28/2007 2:57:22 PM | Attr = ]
javaws.exe -> %System32%\javaws.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 139264 bytes | Created Date = 4/28/2007 2:57:22 PM | Attr = ]
kernels32.exe_tobedeleted -> %System32%\kernels32.exe_tobedeleted -> [Ver = | Size = 9526 bytes | Created Date = 4/18/2007 8:40:23 PM | Attr = ]
moveex.exe -> %System32%\moveex.exe -> [Ver = | Size = 38400 bytes | Created Date = 5/2/2007 6:04:28 PM | Attr = ]
Pcandis3.vxd -> %System32%\Pcandis3.vxd -> [Ver = | Size = 16073 bytes | Created Date = 5/5/2007 12:21:44 PM | Attr = ]
Pcandis4.sys -> %System32%\Pcandis4.sys -> Printing Communications Assoc., Inc. (PCAUSA) [Ver = 5.03.16.54 | Size = 16848 bytes | Created Date = 5/5/2007 12:21:43 PM | Attr = ]
Pcandis5.sys -> %System32%\Pcandis5.sys -> Printing Communications Assoc., Inc. (PCAUSA) [Ver = 5.03.16.54 | Size = 17162 bytes | Created Date = 5/5/2007 12:21:43 PM | Attr = ]
process.exe -> %System32%\process.exe -> http://www.beyondlogic.org [Ver = 2, 0, 0, 0 | Size = 53248 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
reboot.exe -> %System32%\reboot.exe -> [Ver = | Size = 4096 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
regdacl -> %System32%\regdacl -> [Folder | Created Date = 4/30/2007 7:47:41 PM | Attr = ]
regdacl.exe -> %System32%\regdacl.exe -> Frank Heyne Software [Ver = 5.1.1.195 | Size = 90112 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
restart.exe -> %System32%\restart.exe -> WareSoft Software [Ver = 1.00 | Size = 16384 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.6 | Size = 428032 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
swsc.exe -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 5/2/2007 6:04:28 PM | Attr = ]
vfind.exe -> %System32%\vfind.exe -> [Ver = | Size = 49152 bytes | Created Date = 5/2/2007 6:04:29 PM | Attr = ]
W32n50.dll -> %System32%\W32n50.dll -> Printing Communications Assoc., Inc. (PCAUSA) [Ver = 5.03.16.54 | Size = 81920 bytes | Created Date = 5/5/2007 12:21:43 PM | Attr = ]
windev-peers.in_ -> %System32%\windev-peers.in_ -> [Ver = | Size = 4652 bytes | Created Date = 4/18/2007 8:47:54 PM | Attr = ]
AvgArCln.sys -> %System32%\drivers\AvgArCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 3968 bytes | Created Date = 4/21/2007 5:52:56 PM | Attr = ]
AvgAsCln.sys -> %System32%\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 3968 bytes | Created Date = 5/4/2007 7:40:00 PM | Attr = ]

[Files/Folders - Modified Within 30 days]
$VAULT$.AVG -> %SystemDrive%\$VAULT$.AVG -> [Folder | Modified Date = 5/4/2007 8:31:56 PM | Attr = RH ]
boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 211 bytes | Modified Date = 5/7/2007 12:01:20 PM | Attr = RHS]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 5/7/2007 12:01:34 PM | Attr = ]
DAVES DOCS -> %SystemDrive%\DAVES DOCS -> [Folder | Modified Date = 5/1/2007 10:24:58 AM | Attr = ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 5/4/2007 11:07:40 PM | Attr = R ]
QooBox -> %SystemDrive%\QooBox -> [Folder | Modified Date = 5/2/2007 6:59:08 PM | Attr = ]
RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Modified Date = 4/22/2007 8:33:32 PM | Attr = HS]
Sample Files -> %SystemDrive%\Sample Files -> [Folder | Modified Date = 4/30/2007 8:10:16 PM | Attr = ]
SDFix -> %SystemDrive%\SDFix -> [Folder | Modified Date = 4/26/2007 1:23:08 PM | Attr = ]
System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 5/1/2007 10:02:22 AM | Attr = HS]
win32delfkil.exe -> %SystemDrive%\win32delfkil.exe -> Marckie [Ver = 3. 1. 2. 5 | Size = 278902 bytes | Modified Date = 4/24/2007 6:59:08 PM | Attr = ]
WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 5/6/2007 6:21:40 PM | Attr = ]
$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 5/4/2007 11:07:14 PM | Attr = H ]
$NtUninstallKB885884$ -> %SystemRoot%\$NtUninstallKB885884$ -> [Folder | Modified Date = 5/4/2007 11:06:14 PM | Attr = H ]
$NtUninstallKB886185$ -> %SystemRoot%\$NtUninstallKB886185$ -> [Folder | Modified Date = 5/4/2007 11:06:40 PM | Attr = H ]
$NtUninstallKB887472$ -> %SystemRoot%\$NtUninstallKB887472$ -> [Folder | Modified Date = 5/4/2007 11:11:06 PM | Attr = H ]
$NtUninstallKB900485$ -> %SystemRoot%\$NtUninstallKB900485$ -> [Folder | Modified Date = 5/4/2007 11:11:54 PM | Attr = H ]
$NtUninstallKB908531$ -> %SystemRoot%\$NtUninstallKB908531$ -> [Folder | Modified Date = 5/4/2007 11:05:50 PM | Attr = H ]
$NtUninstallKB911280$ -> %SystemRoot%\$NtUninstallKB911280$ -> [Folder | Modified Date = 5/4/2007 11:12:32 PM | Attr = H ]
$NtUninstallKB911562$ -> %SystemRoot%\$NtUninstallKB911562$ -> [Folder | Modified Date = 5/4/2007 11:12:14 PM | Attr = H ]
$NtUninstallKB911564$ -> %SystemRoot%\$NtUninstallKB911564$ -> [Folder | Modified Date = 5/4/2007 11:10:16 PM | Attr = H ]
$NtUninstallKB911927$ -> %SystemRoot%\$NtUninstallKB911927$ -> [Folder | Modified Date = 5/4/2007 11:13:36 PM | Attr = H ]
$NtUninstallKB913580$ -> %SystemRoot%\$NtUninstallKB913580$ -> [Folder | Modified Date = 5/4/2007 11:05:40 PM | Attr = H ]
$NtUninstallKB914388$ -> %SystemRoot%\$NtUninstallKB914388$ -> [Folder | Modified Date = 5/4/2007 11:08:44 PM | Attr = H ]
$NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Modified Date = 5/4/2007 11:05:14 PM | Attr = H ]
$NtUninstallKB916595$ -> %SystemRoot%\$NtUninstallKB916595$ -> [Folder | Modified Date = 5/4/2007 11:06:34 PM | Attr = H ]
$NtUninstallKB917344$ -> %SystemRoot%\$NtUninstallKB917344$ -> [Folder | Modified Date = 5/4/2007 11:08:34 PM | Attr = H ]
$NtUninstallKB917422$ -> %SystemRoot%\$NtUninstallKB917422$ -> [Folder | Modified Date = 5/4/2007 11:07:52 PM | Attr = H ]
$NtUninstallKB917734_WMP9$ -> %SystemRoot%\$NtUninstallKB917734_WMP9$ -> [Folder | Modified Date = 5/4/2007 11:14:32 PM | Attr = H ]
$NtUninstallKB917953$ -> %SystemRoot%\$NtUninstallKB917953$ -> [Folder | Modified Date = 5/4/2007 11:08:26 PM | Attr = H ]
$NtUninstallKB918118$ -> %SystemRoot%\$NtUninstallKB918118$ -> [Folder | Modified Date = 5/4/2007 11:07:06 PM | Attr = H ]
$NtUninstallKB918439$ -> %SystemRoot%\$NtUninstallKB918439$ -> [Folder | Modified Date = 5/4/2007 11:09:28 PM | Attr = H ]
$NtUninstallKB919007$ -> %SystemRoot%\$NtUninstallKB919007$ -> [Folder | Modified Date = 5/4/2007 11:08:52 PM | Attr = H ]
$NtUninstallKB920213$ -> %SystemRoot%\$NtUninstallKB920213$ -> [Folder | Modified Date = 5/4/2007 11:06:50 PM | Attr = H ]
$NtUninstallKB920670$ -> %SystemRoot%\$NtUninstallKB920670$ -> [Folder | Modified Date = 5/4/2007 11:09:38 PM | Attr = H ]
$NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Modified Date = 5/4/2007 11:05:30 PM | Attr = H ]
$NtUninstallKB920685$ -> %SystemRoot%\$NtUninstallKB920685$ -> [Folder | Modified Date = 5/4/2007 11:12:52 PM | Attr = H ]
$NtUninstallKB920872$ -> %SystemRoot%\$NtUninstallKB920872$ -> [Folder | Modified Date = 5/4/2007 11:09:12 PM | Attr = H ]
$NtUninstallKB922582$ -> %SystemRoot%\$NtUninstallKB922582$ -> [Folder | Modified Date = 5/4/2007 11:07:18 PM | Attr = H ]
$NtUninstallKB922819$ -> %SystemRoot%\$NtUninstallKB922819$ -> [Folder | Modified Date = 5/4/2007 11:15:26 PM | Attr = H ]
$NtUninstallKB923191$ -> %SystemRoot%\$NtUninstallKB923191$ -> [Folder | Modified Date = 5/4/2007 11:08:08 PM | Attr = H ]
$NtUninstallKB923414$ -> %SystemRoot%\$NtUninstallKB923414$ -> [Folder | Modified Date = 5/4/2007 11:15:14 PM | Attr = H ]
$NtUninstallKB923689$ -> %SystemRoot%\$NtUninstallKB923689$ -> [Folder | Modified Date = 5/4/2007 11:10:50 PM | Attr = H ]
$NtUninstallKB923694$ -> %SystemRoot%\$NtUninstallKB923694$ -> [Folder | Modified Date = 5/4/2007 11:06:24 PM | Attr = H ]
$NtUninstallKB923980$ -> %SystemRoot%\$NtUninstallKB923980$ -> [Folder | Modified Date = 5/4/2007 11:12:42 PM | Attr = H ]
$NtUninstallKB924191$ -> %SystemRoot%\$NtUninstallKB924191$ -> [Folder | Modified Date = 5/4/2007 11:15:34 PM | Attr = H ]
$NtUninstallKB924270$ -> %SystemRoot%\$NtUninstallKB924270$ -> [Folder | Modified Date = 5/4/2007 11:11:42 PM | Attr = H ]
$NtUninstallKB924496$ -> %SystemRoot%\$NtUninstallKB924496$ -> [Folder | Modified Date = 5/4/2007 11:11:28 PM | Attr = H ]
$NtUninstallKB924667$ -> %SystemRoot%\$NtUninstallKB924667$ -> [Folder | Modified Date = 5/4/2007 11:12:04 PM | Attr = H ]
$NtUninstallKB925398_WMP64$ -> %SystemRoot%\$NtUninstallKB925398_WMP64$ -> [Folder | Modified Date = 5/4/2007 11:13:18 PM | Attr = H ]
$NtUninstallKB925902$ -> %SystemRoot%\$NtUninstallKB925902$ -> [Folder | Modified Date = 5/4/2007 11:09:46 PM | Attr = H ]
$NtUninstallKB926255$ -> %SystemRoot%\$NtUninstallKB926255$ -> [Folder | Modified Date = 5/4/2007 11:06:58 PM | Attr = H ]
$NtUninstallKB926436$ -> %SystemRoot%\$NtUninstallKB926436$ -> [Folder | Modified Date = 5/4/2007 11:09:22 PM | Attr = H ]
$NtUninstallKB927779$ -> %SystemRoot%\$NtUninstallKB927779$ -> [Folder | Modified Date = 5/4/2007 11:15:52 PM | Attr = H ]
$NtUninstallKB927802$ -> %SystemRoot%\$NtUninstallKB927802$ -> [Folder | Modified Date = 5/4/2007 11:15:42 PM | Attr = H ]
$NtUninstallKB928090$ -> %SystemRoot%\$NtUninstallKB928090$ -> [Folder | Modified Date = 5/4/2007 11:04:30 PM | Attr = H ]
$NtUninstallKB928255$ -> %SystemRoot%\$NtUninstallKB928255$ -> [Folder | Modified Date = 5/4/2007 11:14:54 PM | Attr = H ]
$NtUninstallKB928843$ -> %SystemRoot%\$NtUninstallKB928843$ -> [Folder | Modified Date = 5/4/2007 11:03:56 PM | Attr = H ]
$NtUninstallKB929969$ -> %SystemRoot%\$NtUninstallKB929969$ -> [Folder | Modified Date = 5/4/2007 11:13:46 PM | Attr = H ]
$NtUninstallKB930178$ -> %SystemRoot%\$NtUninstallKB930178$ -> [Folder | Modified Date = 5/4/2007 11:09:00 PM | Attr = H ]
$NtUninstallKB931261$ -> %SystemRoot%\$NtUninstallKB931261$ -> [Folder | Modified Date = 5/4/2007 11:11:36 PM | Attr = H ]
$NtUninstallKB931784$ -> %SystemRoot%\$NtUninstallKB931784$ -> [Folder | Modified Date = 5/4/2007 11:13:58 PM | Attr = H ]
$NtUninstallKB931836$ -> %SystemRoot%\$NtUninstallKB931836$ -> [Folder | Modified Date = 5/4/2007 11:11:18 PM | Attr = H ]
$NtUninstallKB932168$ -> %SystemRoot%\$NtUninstallKB932168$ -> [Folder | Modified Date = 5/4/2007 11:08:18 PM | Attr = H ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 5/7/2007 11:18:38 AM | Attr = S]
catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 86528 bytes | Modified Date = 4/21/2007 3:52:22 AM | Attr = ]
cfgmgr52 -> %SystemRoot%\cfgmgr52 -> [Folder | Modified Date = 5/6/2007 5:56:08 PM | Attr = ]
ddcehk.ini -> %SystemRoot%\ddcehk.ini -> [Ver = | Size = 1457880 bytes | Modified Date = 4/12/2007 11:55:22 PM | Attr = HS]
Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 5/5/2007 1:03:34 PM | Attr = ]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 5/5/2007 1:01:02 PM | Attr = S]
Help -> %SystemRoot%\Help -> [Folder | Modified Date = 5/6/2007 1:29:44 PM | Attr = ]
imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1355 bytes | Modified Date = 5/4/2007 11:15:46 PM | Attr = ]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 5/5/2007 12:59:10 PM | Attr = H ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 5/7/2007 12:01:34 PM | Attr = HS]
Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Modified Date = 5/7/2007 12:08:36 PM | Attr = ]
Minidump -> %SystemRoot%\Minidump -> [Folder | Modified Date = 4/24/2007 3:13:42 PM | Attr = ]
msagent -> %SystemRoot%\msagent -> [Folder | Modified Date = 5/5/2007 9:09:34 AM | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 5/7/2007 12:11:06 PM | Attr = ]
pss -> %SystemRoot%\pss -> [Folder | Modified Date = 4/30/2007 9:01:32 PM | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 4/8/2007 8:20:58 PM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 4/8/2007 8:20:56 PM | Attr = H ]
SxsCaPendDel -> %SystemRoot%\SxsCaPendDel -> [Folder | Modified Date = 4/24/2007 10:33:06 PM | Attr = ]
system -> %SystemRoot%\system -> [Folder | Modified Date = 4/15/2007 6:37:12 AM | Attr = ]
system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 227 bytes | Modified Date = 5/7/2007 12:01:20 PM | Attr = ]
system32 -> %System32% -> [Folder | Modified Date = 5/5/2007 1:21:46 PM | Attr = ]
Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 5/2/2007 7:00:30 PM | Attr = S]
temp -> %SystemRoot%\temp -> [Folder | Modified Date = 5/7/2007 11:21:38 AM | Attr = ]
top10_24h_front.png -> %SystemRoot%\top10_24h_front.png -> [Ver = | Size = 19118 bytes | Modified Date = 5/4/2007 7:38:00 PM | Attr = ]
twaccf.ini -> %SystemRoot%\twaccf.ini -> [Ver = | Size = 998339 bytes | Modified Date = 5/2/2007 6:59:28 PM | Attr = HS]
update2.html -> %SystemRoot%\update2.html -> [Ver = | Size = 80896 bytes | Modified Date = 4/18/2007 9:06:38 PM | Attr = ]
uvuttv.ini -> %SystemRoot%\uvuttv.ini -> [Ver = | Size = 1457567 bytes | Modified Date = 4/8/2007 8:00:46 PM | Attr = HS]
win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 583 bytes | Modified Date = 5/7/2007 12:01:20 PM | Attr = ]
WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 5/4/2007 11:12:04 PM | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 5/7/2007 11:18:48 AM | Attr = H ]
CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 5/6/2007 6:49:56 PM | Attr = ]
dllcache -> %System32%\dllcache -> [Folder | Modified Date = 5/5/2007 12:58:34 PM | Attr = RHS]
drivers -> %System32%\drivers -> [Folder | Modified Date = 5/4/2007 11:15:28 PM | Attr = ]
FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 120544 bytes | Modified Date = 5/5/2007 9:09:38 AM | Attr = ]
kernels32.exe_tobedeleted -> %System32%\kernels32.exe_tobedeleted -> [Ver = | Size = 9526 bytes | Modified Date = 4/18/2007 9:39:40 PM | Attr = ]
perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 39992 bytes | Modified Date = 5/5/2007 9:14:16 AM | Attr = ]
perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 311604 bytes | Modified Date = 5/5/2007 9:14:16 AM | Attr = ]
PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 356120 bytes | Modified Date = 5/5/2007 9:14:16 AM | Attr = ]
process.exe -> %System32%\process.exe -> http://www.beyondlogic.org [Ver = 2, 0, 0, 0 | Size = 53248 bytes | Modified Date = 4/30/2007 8:47:36 PM | Attr = ]
reboot.exe -> %System32%\reboot.exe -> [Ver = | Size = 4096 bytes | Modified Date = 4/30/2007 8:47:36 PM | Attr = ]
regdacl -> %System32%\regdacl -> [Folder | Modified Date = 4/30/2007 8:47:44 PM | Attr = ]
regdacl.exe -> %System32%\regdacl.exe -> Frank Heyne Software [Ver = 5.1.1.195 | Size = 90112 bytes | Modified Date = 4/30/2007 8:47:36 PM | Attr = ]
ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Modified Date = 4/30/2007 5:44:44 PM | Attr = ]
restart.exe -> %System32%\restart.exe -> WareSoft Software [Ver = 1.00 | Size = 16384 bytes | Modified Date = 4/30/2007 8:47:36 PM | Attr = ]
Restore -> %System32%\Restore -> [Folder | Modified Date = 5/1/2007 10:02:22 AM | Attr = ]
swsc.exe -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Modified Date = 4/30/2007 8:47:36 PM | Attr = ]
vsconfig.xml -> %System32%\vsconfig.xml -> [Ver = | Size = 49617 bytes | Modified Date = 5/7/2007 11:22:52 AM | Attr = H ]
windev-peers.in_ -> %System32%\windev-peers.in_ -> [Ver = | Size = 4652 bytes | Modified Date = 4/30/2007 6:35:08 PM | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 13646 bytes | Modified Date = 5/6/2007 5:21:34 PM | Attr = ]
avg7core.sys -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.467 | Size = 777984 bytes | Modified Date = 5/4/2007 6:10:54 PM | Attr = ]
etc -> %System32%\drivers\etc -> [Folder | Modified Date = 5/2/2007 7:00:48 PM | Attr = ]

[File String Scan - Non-Microsoft Only]
UPX! , UPX0 , -> %SystemDrive%\win32delfkil.exe -> Marckie [Ver = 3. 1. 2. 5 | Size = 278902 bytes | Modified Date = 4/24/2007 6:59:08 PM | Attr = ]
MZKERNEL32.DLL , -> %SystemDrive%\~WRF0409.tmp -> [Ver = | Size = 18484 bytes | Modified Date = 1/1/2006 8:06:42 AM | Attr = ]
qoologic , urllogic , urllogic , abetterinternet.com , -> %SystemRoot%\azoav.dll -> [Ver = | Size = 4033 bytes | Modified Date = 5/16/2005 8:43:44 PM | Attr = ]
UpackByDwing , MZKERNEL32.DLL , -> %SystemRoot%\cms32.exe -> [Ver = | Size = 44401 bytes | Modified Date = 2/8/2006 10:37:12 PM | Attr = RHS]
SAHAgent , -> %System32%gshmetq.ini -> [Ver = | Size = 35 bytes | Modified Date = 9/11/2005 1:55:24 PM | Attr = ]
SAHAgent , -> %System32%\c50abr57.ini -> [Ver = | Size = 3438 bytes | Modified Date = 11/9/2005 6:02:48 AM | Attr = ]
PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41397 bytes | Modified Date = 3/31/2003 7:00:00 AM | Attr = ]
SAHAgent , -> %System32%\oje5p896.ini -> [Ver = | Size = 35 bytes | Modified Date = 9/11/2005 1:55:24 PM | Attr = ]
UPX! , UPX0 , -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Modified Date = 4/30/2007 8:47:36 PM | Attr = ]
winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 3/31/2003 7:00:00 AM | Attr = ]
WSUD , UPX0 , -> %System32%\dllcache\hwxjpn.dll -> [Ver = | Size = 13463552 bytes | Modified Date = 3/31/2003 7:00:00 AM | Attr = ]
UPX! , FSG! , PEC2 , aspack , -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.467 | Size = 777984 bytes | Modified Date = 5/4/2007 6:10:54 PM | Attr = ]
PTech , -> %System32%\drivers\mtlstrm.sys -> Smart Link [Ver = 3.80.01MC15 | Size = 1309184 bytes | Modified Date = 8/4/2004 12:41:38 AM | Attr = ]

< End of report >

Thanks
oldladywho
Hi oldladywho

Now start WinPFind3U. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Registry - Non-Microsoft Only]
< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
YN -> awbeta_net-nucleus.com [https] ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\
YN -> {33564D57-0000-0010-8000-00AA00389B71} -> - CodeBase = http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB
[Files/Folders - Created Within 30 days]
NY -> QooBox -> %SystemDrive%\QooBox
NY -> SDFix -> %SystemDrive%\SDFix
NY -> win32delfkil.exe -> %SystemDrive%\win32delfkil.exe
NY -> catchme.exe -> %SystemRoot%\catchme.exe
NY -> kernels32.exe_tobedeleted -> %System32%\kernels32.exe_tobedeleted
[Files/Folders - Modified Within 30 days]
NY -> QooBox -> %SystemDrive%\QooBox
NY -> SDFix -> %SystemDrive%\SDFix
NY -> win32delfkil.exe -> %SystemDrive%\win32delfkil.exe
NY -> catchme.exe -> %SystemRoot%\catchme.exe
NY -> kernels32.exe_tobedeleted -> %System32%\kernels32.exe_tobedeleted
[File String Scan - Non-Microsoft Only]
NY -> UPX! , UPX0 , -> %SystemDrive%\win32delfkil.exe
NY -> MZKERNEL32.DLL , -> %SystemDrive%\~WRF0409.tmp
NY -> qoologic , urllogic , urllogic , abetterinternet.com , -> %SystemRoot%\azoav.dll
NY -> UpackByDwing , MZKERNEL32.DLL , -> %SystemRoot%\cms32.exe
NY -> SAHAgent , -> %System32%gshmetq.ini
NY -> SAHAgent , -> %System32%\c50abr57.ini
NY -> SAHAgent , -> %System32%\oje5p896.ini


The fix should only take a very short time and then you will be asked if you want to reboot. Choose Yes.

Please run me a further winpfind log in your next postand a further HJT log and let me know how things are?
Thanks dan
I've been trying to do the WinPfind all day,and it just goes into one of those "Not responding " things. I even ran it in safe mode,and did get the scan to go ,but I think it is the same as before . It just froze everytime I tried the "fix" I sure hope there is some way I can work around this. Here is the WinPfind log:

WinPFind3 logfile created on: 5/8/2007 1:46:27 PM
WinPFind3U by OldTimer - Version 1.0.35 Folder = C:\Documents and Settings\David\Desktop\WinPFind3u\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 6.0.2900.2180)

126.48 Mb Total Physical Memory | 48.29 Mb Available Physical Memory | 38.18% Memory free
307.27 Mb Paging File | 260.17 Mb Available in Paging File | 84.67% Paging File free
Paging file location(s): C:\pagefile.sys 192 384;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 69.12 Gb Free Space | 92.75% Space Free
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded

Computer Name: LUTHER-LU6WQH3X
Current User Name: David
Logged in as Administrator.
Cannot determine boot mode.


[Processes - Non-Microsoft Only]
winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.35.0 | Size = 319488 bytes | Modified Date = 5/6/2007 9:38:54 AM | Attr = ]

[Win32 Services - Non-Microsoft Only]
(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Modified Date = 9/28/2006 9:13:20 AM | Attr = ]
(Avg7Alrt) AVG7 Alert Manager Server [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Grisoft\AVG Free\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.453 | Size = 353280 bytes | Modified Date = 5/4/2007 6:11:02 PM | Attr = ]
(Avg7UpdSvc) AVG7 Update Service [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Grisoft\AVG Free\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 4/4/2007 5:18:32 AM | Attr = ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 2:56:48 AM | Attr = ]
(iPodService) iPod Service [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Computer, Inc. [Ver = 4.9.0.17 | Size = 331776 bytes | Modified Date = 6/24/2005 3:16:26 PM | Attr = ]
(vsmon) TrueVector Internet Monitor [Win32_Own | Auto | Stopped] -> %System32%\ZoneLabs\vsmon.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 75568 bytes | Modified Date = 3/9/2007 1:01:58 AM | Attr = ]

[Registry - Non-Microsoft Only]
< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Zone Labs Client -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 919280 bytes | Modified Date = 3/9/2007 1:02:00 AM | Attr = ]
ZoneAlarm Client -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 919280 bytes | Modified Date = 3/9/2007 1:02:00 AM | Attr = ]
< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\
IMAIL -> Installed = 1 ->
MAPI -> Installed = 1 ->
MSFS -> Installed = 1 ->
< AppInit_DLLs [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
< ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKLM] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 73728 bytes | Modified Date = 9/28/2006 9:13:28 AM | Attr = ]
< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
< HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts
127.0.0.1 localhost -> ->
< Internet Explorer Settings > ->
HKLM: Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome ->
HKLM: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch ->
HKLM: Local Page -> http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome ->
HKLM: Search Bar -> http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm ->
HKLM: Search Page -> http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch ->
HKLM: Start Page -> about:blank ->
HKLM: CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKLM: Search\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch ->
HKLM: SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
HKCU: Local Page -> http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome ->
HKCU: Search Page -> http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch ->
HKCU: Start Page -> http://www.google.com/ ->
HKCU: CustomizeSearch -> http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchcust.htm ->
HKCU: SearchAssistant -> http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm ->
HKCU: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn1\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 4:39:26 PM | Attr = ]
HKCU: ProxyEnable -> 0 ->
< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
msn.com [ - ] -> ->
awbeta_net-nucleus.com [https] -> ->
< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4EFB-9B51-7695ECA05670} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn1\yt.dll [&Yahoo! Toolbar Helper] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 4:39:26 PM | Attr = ]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [AcroIEHlprObj Class] -> Adobe Systems Incorporated [Ver = 7.0.7.2006011200 | Size = 63128 bytes | Modified Date = 1/12/2006 9:38:22 PM | Attr = ]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> %ProgramFiles%\Yahoo!\Common\yiesrvc.dll [Yahoo! IE Services Button] -> Yahoo! Inc. [Ver = 2006, 1, 5, 1 | Size = 181752 bytes | Modified Date = 1/6/2006 12:52:14 PM | Attr = ]
{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} [HKLM] -> %SystemDrive%\PROGRA~1\SPYWAR~2\tools\iesdsg.dll [PCTools Site Guard] -> File not found
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 3/14/2007 3:43:40 AM | Attr = ]
{B56A7D7D-6927-48C8-A975-17DF180C71AC} [HKLM] -> %SystemDrive%\PROGRA~1\SPYWAR~2\tools\iesdpb.dll [PCTools Browser Monitor] -> File not found
< Internet Explorer Bars [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\
{2D51D869-C36B-42BD-AE68-0A81BC771FA5} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
{32683183-48a0-441b-a342-7c2a440a9478} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
< Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn1\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 4:39:26 PM | Attr = ]
< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn1\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 4:39:26 PM | Attr = ]
< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\npjpi160_01.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 132760 bytes | Modified Date = 3/14/2007 3:43:42 AM | Attr = ]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKCU] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 3/14/2007 3:43:40 AM | Attr = ]
{2D663D1A-8670-49D9-A1A5-4C56B4E14E84} -> Reg Data - Value does not exist [ButtonText: Spyware Doctor] -> File not found
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -> Reg Data - Value does not exist [ButtonText: Yahoo! Services] -> File not found
< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\
&Google Search -> %ProgramFiles%\Google\GoogleToolbar1.dll\cmsearch.htm -> File not found
&Yahoo! Search -> %ProgramFiles%\Yahoo!\Common\YCSRCH.HTM -> [Ver = | Size = 605 bytes | Modified Date = 6/3/2005 7:07:38 PM | Attr = ]
Backward Links -> %ProgramFiles%\Google\GoogleToolbar1.dll\cmbacklinks.htm -> File not found
Cached Snapshot of Page -> %ProgramFiles%\Google\GoogleToolbar1.dll\cmcache.htm -> File not found
E&xport to Microsoft Excel -> -> File not found
Similar Pages -> %ProgramFiles%\Google\GoogleToolbar1.dll\cmsimilar.htm -> File not found
Translate into English -> %ProgramFiles%\Google\GoogleToolbar1.dll\cmtrans.htm -> File not found
Yahoo! &Dictionary -> %ProgramFiles%\Yahoo!\Common\YCDICT.HTM -> [Ver = | Size = 616 bytes | Modified Date = 6/3/2005 7:07:16 PM | Attr = ]
Yahoo! &Maps -> %ProgramFiles%\Yahoo!\Common\ycmap.htm -> [Ver = | Size = 690 bytes | Modified Date = 6/3/2005 7:07:44 PM | Attr = ]
Yahoo! &SMS -> %ProgramFiles%\Yahoo!\Common\YCsms.htm -> [Ver = | Size = 1006 bytes | Modified Date = 8/1/2005 6:43:00 PM | Attr = ]
< User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
SV1 -> ->
< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\
{8208ABBE-A468-4911-ADBA-DAE31CF2F43D} -> 206.141.193.55,66.73.20.40 (Realtek RTL8139 Family PCI Fast Ethernet NIC) ->
< Default Protocols [HKCU] - Select to Repair > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
shell -> shell protocol not assigned ->
< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\
http -> Reg Data - Key not found -> File not found
https -> Reg Data - Key not found -> File not found
ipp -> Reg Data - Key not found -> File not found
msdaipp -> Reg Data - Key not found -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\
{02BCC737-B171-4746-94C9-0D8A0B2C0089} -> Microsoft Office Template and Media Control - CodeBase = http://office.microsoft.com/templates/ieawsdc.cab ->
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} -> QuickTime Object - CodeBase = http://www.apple.com/qtactivex/qtplugin.cab ->
{0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB} -> Street Technologies ActiveX Control Object - CodeBase = http://www.tutorials.com/plugins/Plugin050…eetnoagent7.cab ->
{17492023-C23A-453E-A040-C7C580BBF700} -> Windows Genuine Advantage Validation Tool - CodeBase = http://go.microsoft.com/fwlink/?linkid=39204 ->
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -> YInstStarter Class - CodeBase = C:\Program Files\Yahoo!\Common\yinsthelper.dll ->
{33564D57-0000-0010-8000-00AA00389B71} -> - CodeBase = http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB ->
{3BFFE033-BF43-11D5-A271-00A024A51325} -> iNotes6 Class - CodeBase = https://mymail.humana.com/iNotes6W.cab ->
{6414512B-B978-451D-A0D8-FCFDF33E833C} -> WUWebControl Class - CodeBase = http://v5.windowsupdate.microsoft.com/v5co…b?1109624551750 ->
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -> MUWebControl Class - CodeBase = http://update.microsoft.com/microsoftupdat…b?1152669359626 ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab ->
{A93D84FD-641F-43AE-B963-E6FA84BE7FE7} -> LinkSys Content Update - CodeBase = http://www.linksysfix.com/netcheck/41/install/gtdownls.cab ->
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase = http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab ->
{D719897A-B07A-4C0C-AEA9-9B663A28DFCB} -> iTunesDetector Class - CodeBase = http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab ->
{E9348280-2D74-4933-BE25-73D946926795} -> DeviceEnum Class - CodeBase = http://h20270.www2.hp.com/ediags/gmn/insta…cdetection3.cab ->


[Files/Folders - Created Within 30 days]
QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 5/2/2007 5:59:06 PM | Attr = ]
Sample Files -> %SystemDrive%\Sample Files -> [Folder | Created Date = 4/30/2007 7:10:14 PM | Attr = ]
SDFix -> %SystemDrive%\SDFix -> [Folder | Created Date = 4/26/2007 11:48:51 AM | Attr = ]
win32delfkil.exe -> %SystemDrive%\win32delfkil.exe -> Marckie [Ver = 3. 1. 2. 5 | Size = 278902 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
$NtUninstallKB885884$ -> %SystemRoot%\$NtUninstallKB885884$ -> [Folder | Created Date = 5/4/2007 10:06:12 PM | Attr = H ]
$NtUninstallKB886185$ -> %SystemRoot%\$NtUninstallKB886185$ -> [Folder | Created Date = 5/4/2007 10:06:39 PM | Attr = H ]
$NtUninstallKB887472$ -> %SystemRoot%\$NtUninstallKB887472$ -> [Folder | Created Date = 5/4/2007 10:11:04 PM | Attr = H ]
$NtUninstallKB900485$ -> %SystemRoot%\$NtUninstallKB900485$ -> [Folder | Created Date = 5/4/2007 10:11:52 PM | Attr = H ]
$NtUninstallKB908531$ -> %SystemRoot%\$NtUninstallKB908531$ -> [Folder | Created Date = 5/4/2007 10:05:48 PM | Attr = H ]
$NtUninstallKB911280$ -> %SystemRoot%\$NtUninstallKB911280$ -> [Folder | Created Date = 5/4/2007 10:12:29 PM | Attr = H ]
$NtUninstallKB911562$ -> %SystemRoot%\$NtUninstallKB911562$ -> [Folder | Created Date = 5/4/2007 10:12:12 PM | Attr = H ]
$NtUninstallKB911564$ -> %SystemRoot%\$NtUninstallKB911564$ -> [Folder | Created Date = 5/4/2007 10:10:12 PM | Attr = H ]
$NtUninstallKB911927$ -> %SystemRoot%\$NtUninstallKB911927$ -> [Folder | Created Date = 5/4/2007 10:13:33 PM | Attr = H ]
$NtUninstallKB913580$ -> %SystemRoot%\$NtUninstallKB913580$ -> [Folder | Created Date = 5/4/2007 10:05:36 PM | Attr = H ]
$NtUninstallKB914388$ -> %SystemRoot%\$NtUninstallKB914388$ -> [Folder | Created Date = 5/4/2007 10:08:41 PM | Attr = H ]
$NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Created Date = 5/4/2007 10:05:11 PM | Attr = H ]
$NtUninstallKB916595$ -> %SystemRoot%\$NtUninstallKB916595$ -> [Folder | Created Date = 5/4/2007 10:06:32 PM | Attr = H ]
$NtUninstallKB917344$ -> %SystemRoot%\$NtUninstallKB917344$ -> [Folder | Created Date = 5/4/2007 10:08:32 PM | Attr = H ]
$NtUninstallKB917422$ -> %SystemRoot%\$NtUninstallKB917422$ -> [Folder | Created Date = 5/4/2007 10:07:50 PM | Attr = H ]
$NtUninstallKB917734_WMP9$ -> %SystemRoot%\$NtUninstallKB917734_WMP9$ -> [Folder | Created Date = 5/4/2007 10:14:29 PM | Attr = H ]
$NtUninstallKB917953$ -> %SystemRoot%\$NtUninstallKB917953$ -> [Folder | Created Date = 5/4/2007 10:08:24 PM | Attr = H ]
$NtUninstallKB918118$ -> %SystemRoot%\$NtUninstallKB918118$ -> [Folder | Created Date = 5/4/2007 10:07:03 PM | Attr = H ]
$NtUninstallKB918439$ -> %SystemRoot%\$NtUninstallKB918439$ -> [Folder | Created Date = 5/4/2007 10:09:26 PM | Attr = H ]
$NtUninstallKB919007$ -> %SystemRoot%\$NtUninstallKB919007$ -> [Folder | Created Date = 5/4/2007 10:08:50 PM | Attr = H ]
$NtUninstallKB920213$ -> %SystemRoot%\$NtUninstallKB920213$ -> [Folder | Created Date = 5/4/2007 10:06:47 PM | Attr = H ]
$NtUninstallKB920670$ -> %SystemRoot%\$NtUninstallKB920670$ -> [Folder | Created Date = 5/4/2007 10:09:35 PM | Attr = H ]
$NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Created Date = 5/4/2007 10:05:27 PM | Attr = H ]
$NtUninstallKB920685$ -> %SystemRoot%\$NtUninstallKB920685$ -> [Folder | Created Date = 5/4/2007 10:12:49 PM | Attr = H ]
$NtUninstallKB920872$ -> %SystemRoot%\$NtUninstallKB920872$ -> [Folder | Created Date = 5/4/2007 10:09:10 PM | Attr = H ]
$NtUninstallKB922582$ -> %SystemRoot%\$NtUninstallKB922582$ -> [Folder | Created Date = 5/4/2007 10:07:16 PM | Attr = H ]
$NtUninstallKB922819$ -> %SystemRoot%\$NtUninstallKB922819$ -> [Folder | Created Date = 5/4/2007 10:15:23 PM | Attr = H ]
$NtUninstallKB923191$ -> %SystemRoot%\$NtUninstallKB923191$ -> [Folder | Created Date = 5/4/2007 10:08:05 PM | Attr = H ]
$NtUninstallKB923414$ -> %SystemRoot%\$NtUninstallKB923414$ -> [Folder | Created Date = 5/4/2007 10:15:12 PM | Attr = H ]
$NtUninstallKB923689$ -> %SystemRoot%\$NtUninstallKB923689$ -> [Folder | Created Date = 5/4/2007 10:10:47 PM | Attr = H ]
$NtUninstallKB923694$ -> %SystemRoot%\$NtUninstallKB923694$ -> [Folder | Created Date = 5/4/2007 10:06:22 PM | Attr = H ]
$NtUninstallKB923980$ -> %SystemRoot%\$NtUninstallKB923980$ -> [Folder | Created Date = 5/4/2007 10:12:39 PM | Attr = H ]
$NtUninstallKB924191$ -> %SystemRoot%\$NtUninstallKB924191$ -> [Folder | Created Date = 5/4/2007 10:15:32 PM | Attr = H ]
$NtUninstallKB924270$ -> %SystemRoot%\$NtUninstallKB924270$ -> [Folder | Created Date = 5/4/2007 10:11:40 PM | Attr = H ]
$NtUninstallKB924496$ -> %SystemRoot%\$NtUninstallKB924496$ -> [Folder | Created Date = 5/4/2007 10:11:24 PM | Attr = H ]
$NtUninstallKB924667$ -> %SystemRoot%\$NtUninstallKB924667$ -> [Folder | Created Date = 5/4/2007 10:12:02 PM | Attr = H ]
$NtUninstallKB925398_WMP64$ -> %SystemRoot%\$NtUninstallKB925398_WMP64$ -> [Folder | Created Date = 5/4/2007 10:13:14 PM | Attr = H ]
$NtUninstallKB925902$ -> %SystemRoot%\$NtUninstallKB925902$ -> [Folder | Created Date = 5/4/2007 10:09:44 PM | Attr = H ]
$NtUninstallKB926255$ -> %SystemRoot%\$NtUninstallKB926255$ -> [Folder | Created Date = 5/4/2007 10:06:55 PM | Attr = H ]
$NtUninstallKB926436$ -> %SystemRoot%\$NtUninstallKB926436$ -> [Folder | Created Date = 5/4/2007 10:09:19 PM | Attr = H ]
$NtUninstallKB927779$ -> %SystemRoot%\$NtUninstallKB927779$ -> [Folder | Created Date = 5/4/2007 10:15:49 PM | Attr = H ]
$NtUninstallKB927802$ -> %SystemRoot%\$NtUninstallKB927802$ -> [Folder | Created Date = 5/4/2007 10:15:40 PM | Attr = H ]
$NtUninstallKB928090$ -> %SystemRoot%\$NtUninstallKB928090$ -> [Folder | Created Date = 5/4/2007 10:04:25 PM | Attr = H ]
$NtUninstallKB928255$ -> %SystemRoot%\$NtUninstallKB928255$ -> [Folder | Created Date = 5/4/2007 10:14:51 PM | Attr = H ]
$NtUninstallKB928843$ -> %SystemRoot%\$NtUninstallKB928843$ -> [Folder | Created Date = 5/4/2007 10:03:53 PM | Attr = H ]
$NtUninstallKB929969$ -> %SystemRoot%\$NtUninstallKB929969$ -> [Folder | Created Date = 5/4/2007 10:13:43 PM | Attr = H ]
$NtUninstallKB930178$ -> %SystemRoot%\$NtUninstallKB930178$ -> [Folder | Created Date = 5/4/2007 10:08:57 PM | Attr = H ]
$NtUninstallKB931261$ -> %SystemRoot%\$NtUninstallKB931261$ -> [Folder | Created Date = 5/4/2007 10:11:32 PM | Attr = H ]
$NtUninstallKB931784$ -> %SystemRoot%\$NtUninstallKB931784$ -> [Folder | Created Date = 5/4/2007 10:13:55 PM | Attr = H ]
$NtUninstallKB931836$ -> %SystemRoot%\$NtUninstallKB931836$ -> [Folder | Created Date = 5/4/2007 10:11:16 PM | Attr = H ]
$NtUninstallKB932168$ -> %SystemRoot%\$NtUninstallKB932168$ -> [Folder | Created Date = 5/4/2007 10:08:16 PM | Attr = H ]
catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 86528 bytes | Created Date = 5/2/2007 6:04:31 PM | Attr = ]
LastGood -> %SystemRoot%\LastGood -> [Folder | Created Date = 5/8/2007 12:21:38 PM | Attr = ]
Minidump -> %SystemRoot%\Minidump -> [Folder | Created Date = 4/19/2007 5:39:09 PM | Attr = ]
nircmd.exe -> %SystemRoot%\nircmd.exe -> NirSoft [Ver = 1.85 | Size = 49152 bytes | Created Date = 5/2/2007 6:04:29 PM | Attr = ]
pss -> %SystemRoot%\pss -> [Folder | Created Date = 4/30/2007 7:59:08 PM | Attr = ]
top10_24h_front.png -> %SystemRoot%\top10_24h_front.png -> [Ver = | Size = 19118 bytes | Created Date = 5/4/2007 6:46:37 PM | Attr = ]
twaccf.ini -> %SystemRoot%\twaccf.ini -> [Ver = | Size = 998339 bytes | Created Date = 4/12/2007 10:55:42 PM | Attr = HS]
update2.html -> %SystemRoot%\update2.html -> [Ver = | Size = 80896 bytes | Created Date = 4/17/2007 8:31:29 AM | Attr = ]
java.exe -> %System32%\java.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 135168 bytes | Created Date = 4/28/2007 2:57:22 PM | Attr = ]
javacpl.cpl -> %System32%\javacpl.cpl -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 69632 bytes | Created Date = 4/28/2007 2:57:22 PM | Attr = ]
javaw.exe -> %System32%\javaw.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 135168 bytes | Created Date = 4/28/2007 2:57:22 PM | Attr = ]
javaws.exe -> %System32%\javaws.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 139264 bytes | Created Date = 4/28/2007 2:57:22 PM | Attr = ]
kernels32.exe_tobedeleted -> %System32%\kernels32.exe_tobedeleted -> [Ver = | Size = 9526 bytes | Created Date = 4/18/2007 8:40:23 PM | Attr = ]
moveex.exe -> %System32%\moveex.exe -> [Ver = | Size = 38400 bytes | Created Date = 5/2/2007 6:04:28 PM | Attr = ]
Pcandis3.vxd -> %System32%\Pcandis3.vxd -> [Ver = | Size = 16073 bytes | Created Date = 5/5/2007 12:21:44 PM | Attr = ]
Pcandis4.sys -> %System32%\Pcandis4.sys -> Printing Communications Assoc., Inc. (PCAUSA) [Ver = 5.03.16.54 | Size = 16848 bytes | Created Date = 5/5/2007 12:21:43 PM | Attr = ]
Pcandis5.sys -> %System32%\Pcandis5.sys -> Printing Communications Assoc., Inc. (PCAUSA) [Ver = 5.03.16.54 | Size = 17162 bytes | Created Date = 5/5/2007 12:21:43 PM | Attr = ]
process.exe -> %System32%\process.exe -> http://www.beyondlogic.org [Ver = 2, 0, 0, 0 | Size = 53248 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
reboot.exe -> %System32%\reboot.exe -> [Ver = | Size = 4096 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
regdacl -> %System32%\regdacl -> [Folder | Created Date = 4/30/2007 7:47:41 PM | Attr = ]
regdacl.exe -> %System32%\regdacl.exe -> Frank Heyne Software [Ver = 5.1.1.195 | Size = 90112 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
restart.exe -> %System32%\restart.exe -> WareSoft Software [Ver = 1.00 | Size = 16384 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.6 | Size = 428032 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
swsc.exe -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Created Date = 4/30/2007 7:47:42 PM | Attr = ]
swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 5/2/2007 6:04:28 PM | Attr = ]
vfind.exe -> %System32%\vfind.exe -> [Ver = | Size = 49152 bytes | Created Date = 5/2/2007 6:04:29 PM | Attr = ]
W32n50.dll -> %System32%\W32n50.dll -> Printing Communications Assoc., Inc. (PCAUSA) [Ver = 5.03.16.54 | Size = 81920 bytes | Created Date = 5/5/2007 12:21:43 PM | Attr = ]
windev-peers.in_ -> %System32%\windev-peers.in_ -> [Ver = | Size = 4652 bytes | Created Date = 4/18/2007 8:47:54 PM | Attr = ]
AvgArCln.sys -> %System32%\drivers\AvgArCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 3968 bytes | Created Date = 4/21/2007 5:52:56 PM | Attr = ]
AvgAsCln.sys -> %System32%\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 3968 bytes | Created Date = 5/4/2007 7:40:00 PM | Attr = ]

[Files/Folders - Modified Within 30 days]
$VAULT$.AVG -> %SystemDrive%\$VAULT$.AVG -> [Folder | Modified Date = 5/4/2007 8:31:56 PM | Attr = RH ]
boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 211 bytes | Modified Date = 5/7/2007 12:01:20 PM | Attr = RHS]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 5/7/2007 12:01:34 PM | Attr = ]
DAVES DOCS -> %SystemDrive%\DAVES DOCS -> [Folder | Modified Date = 5/1/2007 10:24:58 AM | Attr = ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 5/4/2007 11:07:40 PM | Attr = R ]
QooBox -> %SystemDrive%\QooBox -> [Folder | Modified Date = 5/2/2007 6:59:08 PM | Attr = ]
RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Modified Date = 4/22/2007 8:33:32 PM | Attr = HS]
Sample Files -> %SystemDrive%\Sample Files -> [Folder | Modified Date = 4/30/2007 8:10:16 PM | Attr = ]
SDFix -> %SystemDrive%\SDFix -> [Folder | Modified Date = 4/26/2007 1:23:08 PM | Attr = ]
System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 5/1/2007 10:02:22 AM | Attr = HS]
win32delfkil.exe -> %SystemDrive%\win32delfkil.exe -> Marckie [Ver = 3. 1. 2. 5 | Size = 278902 bytes | Modified Date = 4/24/2007 6:59:08 PM | Attr = ]
WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 5/8/2007 1:21:40 PM | Attr = ]
$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 5/8/2007 1:21:48 PM | Attr = H ]
$NtUninstallKB885884$ -> %SystemRoot%\$NtUninstallKB885884$ -> [Folder | Modified Date = 5/4/2007 11:06:14 PM | Attr = H ]
$NtUninstallKB886185$ -> %SystemRoot%\$NtUninstallKB886185$ -> [Folder | Modified Date = 5/4/2007 11:06:40 PM | Attr = H ]
$NtUninstallKB887472$ -> %SystemRoot%\$NtUninstallKB887472$ -> [Folder | Modified Date = 5/4/2007 11:11:06 PM | Attr = H ]
$NtUninstallKB900485$ -> %SystemRoot%\$NtUninstallKB900485$ -> [Folder | Modified Date = 5/4/2007 11:11:54 PM | Attr = H ]
$NtUninstallKB908531$ -> %SystemRoot%\$NtUninstallKB908531$ -> [Folder | Modified Date = 5/4/2007 11:05:50 PM | Attr = H ]
$NtUninstallKB911280$ -> %SystemRoot%\$NtUninstallKB911280$ -> [Folder | Modified Date = 5/4/2007 11:12:32 PM | Attr = H ]
$NtUninstallKB911562$ -> %SystemRoot%\$NtUninstallKB911562$ -> [Folder | Modified Date = 5/4/2007 11:12:14 PM | Attr = H ]
$NtUninstallKB911564$ -> %SystemRoot%\$NtUninstallKB911564$ -> [Folder | Modified Date = 5/4/2007 11:10:16 PM | Attr = H ]
$NtUninstallKB911927$ -> %SystemRoot%\$NtUninstallKB911927$ -> [Folder | Modified Date = 5/4/2007 11:13:36 PM | Attr = H ]
$NtUninstallKB913580$ -> %SystemRoot%\$NtUninstallKB913580$ -> [Folder | Modified Date = 5/4/2007 11:05:40 PM | Attr = H ]
$NtUninstallKB914388$ -> %SystemRoot%\$NtUninstallKB914388$ -> [Folder | Modified Date = 5/4/2007 11:08:44 PM | Attr = H ]
$NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Modified Date = 5/4/2007 11:05:14 PM | Attr = H ]
$NtUninstallKB916595$ -> %SystemRoot%\$NtUninstallKB916595$ -> [Folder | Modified Date = 5/4/2007 11:06:34 PM | Attr = H ]
$NtUninstallKB917344$ -> %SystemRoot%\$NtUninstallKB917344$ -> [Folder | Modified Date = 5/4/2007 11:08:34 PM | Attr = H ]
$NtUninstallKB917422$ -> %SystemRoot%\$NtUninstallKB917422$ -> [Folder | Modified Date = 5/4/2007 11:07:52 PM | Attr = H ]
$NtUninstallKB917734_WMP9$ -> %SystemRoot%\$NtUninstallKB917734_WMP9$ -> [Folder | Modified Date = 5/4/2007 11:14:32 PM | Attr = H ]
$NtUninstallKB917953$ -> %SystemRoot%\$NtUninstallKB917953$ -> [Folder | Modified Date = 5/4/2007 11:08:26 PM | Attr = H ]
$NtUninstallKB918118$ -> %SystemRoot%\$NtUninstallKB918118$ -> [Folder | Modified Date = 5/4/2007 11:07:06 PM | Attr = H ]
$NtUninstallKB918439$ -> %SystemRoot%\$NtUninstallKB918439$ -> [Folder | Modified Date = 5/4/2007 11:09:28 PM | Attr = H ]
$NtUninstallKB919007$ -> %SystemRoot%\$NtUninstallKB919007$ -> [Folder | Modified Date = 5/4/2007 11:08:52 PM | Attr = H ]
$NtUninstallKB920213$ -> %SystemRoot%\$NtUninstallKB920213$ -> [Folder | Modified Date = 5/4/2007 11:06:50 PM | Attr = H ]
$NtUninstallKB920670$ -> %SystemRoot%\$NtUninstallKB920670$ -> [Folder | Modified Date = 5/4/2007 11:09:38 PM | Attr = H ]
$NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Modified Date = 5/4/2007 11:05:30 PM | Attr = H ]
$NtUninstallKB920685$ -> %SystemRoot%\$NtUninstallKB920685$ -> [Folder | Modified Date = 5/4/2007 11:12:52 PM | Attr = H ]
$NtUninstallKB920872$ -> %SystemRoot%\$NtUninstallKB920872$ -> [Folder | Modified Date = 5/4/2007 11:09:12 PM | Attr = H ]
$NtUninstallKB922582$ -> %SystemRoot%\$NtUninstallKB922582$ -> [Folder | Modified Date = 5/4/2007 11:07:18 PM | Attr = H ]
$NtUninstallKB922819$ -> %SystemRoot%\$NtUninstallKB922819$ -> [Folder | Modified Date = 5/4/2007 11:15:26 PM | Attr = H ]
$NtUninstallKB923191$ -> %SystemRoot%\$NtUninstallKB923191$ -> [Folder | Modified Date = 5/4/2007 11:08:08 PM | Attr = H ]
$NtUninstallKB923414$ -> %SystemRoot%\$NtUninstallKB923414$ -> [Folder | Modified Date = 5/4/2007 11:15:14 PM | Attr = H ]
$NtUninstallKB923689$ -> %SystemRoot%\$NtUninstallKB923689$ -> [Folder | Modified Date = 5/4/2007 11:10:50 PM | Attr = H ]
$NtUninstallKB923694$ -> %SystemRoot%\$NtUninstallKB923694$ -> [Folder | Modified Date = 5/4/2007 11:06:24 PM | Attr = H ]
$NtUninstallKB923980$ -> %SystemRoot%\$NtUninstallKB923980$ -> [Folder | Modified Date = 5/4/2007 11:12:42 PM | Attr = H ]
$NtUninstallKB924191$ -> %SystemRoot%\$NtUninstallKB924191$ -> [Folder | Modified Date = 5/4/2007 11:15:34 PM | Attr = H ]
$NtUninstallKB924270$ -> %SystemRoot%\$NtUninstallKB924270$ -> [Folder | Modified Date = 5/4/2007 11:11:42 PM | Attr = H ]
$NtUninstallKB924496$ -> %SystemRoot%\$NtUninstallKB924496$ -> [Folder | Modified Date = 5/4/2007 11:11:28 PM | Attr = H ]
$NtUninstallKB924667$ -> %SystemRoot%\$NtUninstallKB924667$ -> [Folder | Modified Date = 5/4/2007 11:12:04 PM | Attr = H ]
$NtUninstallKB925398_WMP64$ -> %SystemRoot%\$NtUninstallKB925398_WMP64$ -> [Folder | Modified Date = 5/4/2007 11:13:18 PM | Attr = H ]
$NtUninstallKB925902$ -> %SystemRoot%\$NtUninstallKB925902$ -> [Folder | Modified Date = 5/4/2007 11:09:46 PM | Attr = H ]
$NtUninstallKB926255$ -> %SystemRoot%\$NtUninstallKB926255$ -> [Folder | Modified Date = 5/4/2007 11:06:58 PM | Attr = H ]
$NtUninstallKB926436$ -> %SystemRoot%\$NtUninstallKB926436$ -> [Folder | Modified Date = 5/4/2007 11:09:22 PM | Attr = H ]
$NtUninstallKB927779$ -> %SystemRoot%\$NtUninstallKB927779$ -> [Folder | Modified Date = 5/4/2007 11:15:52 PM | Attr = H ]
$NtUninstallKB927802$ -> %SystemRoot%\$NtUninstallKB927802$ -> [Folder | Modified Date = 5/4/2007 11:15:42 PM | Attr = H ]
$NtUninstallKB928090$ -> %SystemRoot%\$NtUninstallKB928090$ -> [Folder | Modified Date = 5/4/2007 11:04:30 PM | Attr = H ]
$NtUninstallKB928255$ -> %SystemRoot%\$NtUninstallKB928255$ -> [Folder | Modified Date = 5/4/2007 11:14:54 PM | Attr = H ]
$NtUninstallKB928843$ -> %SystemRoot%\$NtUninstallKB928843$ -> [Folder | Modified Date = 5/4/2007 11:03:56 PM | Attr = H ]
$NtUninstallKB929969$ -> %SystemRoot%\$NtUninstallKB929969$ -> [Folder | Modified Date = 5/4/2007 11:13:46 PM | Attr = H ]
$NtUninstallKB930178$ -> %SystemRoot%\$NtUninstallKB930178$ -> [Folder | Modified Date = 5/4/2007 11:09:00 PM | Attr = H ]
$NtUninstallKB931261$ -> %SystemRoot%\$NtUninstallKB931261$ -> [Folder | Modified Date = 5/4/2007 11:11:36 PM | Attr = H ]
$NtUninstallKB931784$ -> %SystemRoot%\$NtUninstallKB931784$ -> [Folder | Modified Date = 5/4/2007 11:13:58 PM | Attr = H ]
$NtUninstallKB931836$ -> %SystemRoot%\$NtUninstallKB931836$ -> [Folder | Modified Date = 5/4/2007 11:11:18 PM | Attr = H ]
$NtUninstallKB932168$ -> %SystemRoot%\$NtUninstallKB932168$ -> [Folder | Modified Date = 5/4/2007 11:08:18 PM | Attr = H ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 5/8/2007 1:45:46 PM | Attr = S]
catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 86528 bytes | Modified Date = 4/21/2007 3:52:22 AM | Attr = ]
cfgmgr52 -> %SystemRoot%\cfgmgr52 -> [Folder | Modified Date = 5/6/2007 5:56:08 PM | Attr = ]
ddcehk.ini -> %SystemRoot%\ddcehk.ini -> [Ver = | Size = 1457880 bytes | Modified Date = 4/12/2007 11:55:22 PM | Attr = HS]
Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 5/5/2007 1:03:34 PM | Attr = ]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 5/5/2007 1:01:02 PM | Attr = S]
Help -> %SystemRoot%\Help -> [Folder | Modified Date = 5/6/2007 1:29:44 PM | Attr = ]
imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1355 bytes | Modified Date = 5/4/2007 11:15:46 PM | Attr = ]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 5/8/2007 1:23:18 PM | Attr = H ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 5/7/2007 12:01:34 PM | Attr = HS]
Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Modified Date = 5/8/2007 1:39:40 PM | Attr = ]
LastGood -> %SystemRoot%\LastGood -> [Folder | Modified Date = 5/8/2007 1:21:40 PM | Attr = ]
Minidump -> %SystemRoot%\Minidump -> [Folder | Modified Date = 4/24/2007 3:13:42 PM | Attr = ]
msagent -> %SystemRoot%\msagent -> [Folder | Modified Date = 5/5/2007 9:09:34 AM | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 5/8/2007 1:21:18 PM | Attr = ]
pss -> %SystemRoot%\pss -> [Folder | Modified Date = 4/30/2007 9:01:32 PM | Attr = ]
SxsCaPendDel -> %SystemRoot%\SxsCaPendDel -> [Folder | Modified Date = 4/24/2007 10:33:06 PM | Attr = ]
system -> %SystemRoot%\system -> [Folder | Modified Date = 4/15/2007 6:37:12 AM | Attr = ]
system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 227 bytes | Modified Date = 5/7/2007 12:01:20 PM | Attr = ]
system32 -> %System32% -> [Folder | Modified Date = 5/5/2007 1:21:46 PM | Attr = ]
Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 5/2/2007 7:00:30 PM | Attr = S]
temp -> %SystemRoot%\temp -> [Folder | Modified Date = 5/8/2007 12:07:32 PM | Attr = ]
top10_24h_front.png -> %SystemRoot%\top10_24h_front.png -> [Ver = | Size = 19118 bytes | Modified Date = 5/4/2007 7:38:00 PM | Attr = ]
twaccf.ini -> %SystemRoot%\twaccf.ini -> [Ver = | Size = 998339 bytes | Modified Date = 5/2/2007 6:59:28 PM | Attr = HS]
update2.html -> %SystemRoot%\update2.html -> [Ver = | Size = 80896 bytes | Modified Date = 4/18/2007 9:06:38 PM | Attr = ]
win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 583 bytes | Modified Date = 5/7/2007 12:01:20 PM | Attr = ]
WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 5/4/2007 11:12:04 PM | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 5/8/2007 1:44:32 PM | Attr = H ]
CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 5/8/2007 1:44:28 PM | Attr = ]
dllcache -> %System32%\dllcache -> [Folder | Modified Date = 5/5/2007 12:58:34 PM | Attr = RHS]
drivers -> %System32%\drivers -> [Folder | Modified Date = 5/4/2007 11:15:28 PM | Attr = ]
FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 120544 bytes | Modified Date = 5/5/2007 9:09:38 AM | Attr = ]
kernels32.exe_tobedeleted -> %System32%\kernels32.exe_tobedeleted -> [Ver = | Size = 9526 bytes | Modified Date = 4/18/2007 9:39:40 PM | Attr = ]
perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 39992 bytes | Modified Date = 5/5/2007 9:14:16 AM | Attr = ]
perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 311604 bytes | Modified Date = 5/5/2007 9:14:16 AM | Attr = ]
PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 356120 bytes | Modified Date = 5/5/2007 9:14:16 AM | Attr = ]
process.exe -> %System32%\process.exe -> http://www.beyondlogic.org [Ver = 2, 0, 0, 0 | Size = 53248 bytes | Modified Date = 4/30/2007 8:47:36 PM | Attr = ]
reboot.exe -> %System32%\reboot.exe -> [Ver = | Size = 4096 bytes | Modified Date = 4/30/2007 8:47:36 PM | Attr = ]
regdacl -> %System32%\regdacl -> [Folder | Modified Date = 4/30/2007 8:47:44 PM | Attr = ]
regdacl.exe -> %System32%\regdacl.exe -> Frank Heyne Software [Ver = 5.1.1.195 | Size = 90112 bytes | Modified Date = 4/30/2007 8:47:36 PM | Attr = ]
ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Modified Date = 4/30/2007 5:44:44 PM | Attr = ]
restart.exe -> %System32%\restart.exe -> WareSoft Software [Ver = 1.00 | Size = 16384 bytes | Modified Date = 4/30/2007 8:47:36 PM | Attr = ]
Restore -> %System32%\Restore -> [Folder | Modified Date = 5/1/2007 10:02:22 AM | Attr = ]
swsc.exe -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Modified Date = 4/30/2007 8:47:36 PM | Attr = ]
vsconfig.xml -> %System32%\vsconfig.xml -> [Ver = | Size = 49617 bytes | Modified Date = 5/8/2007 12:09:32 PM | Attr = H ]
windev-peers.in_ -> %System32%\windev-peers.in_ -> [Ver = | Size = 4652 bytes | Modified Date = 4/30/2007 6:35:08 PM | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 13646 bytes | Modified Date = 5/8/2007 1:24:44 PM | Attr = ]
avg7core.sys -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.467 | Size = 777984 bytes | Modified Date = 5/4/2007 6:10:54 PM | Attr = ]
etc -> %System32%\drivers\etc -> [Folder | Modified Date = 5/2/2007 7:00:48 PM | Attr = ]

[File String Scan - Non-Microsoft Only]
UPX! , UPX0 , -> %SystemDrive%\win32delfkil.exe -> Marckie [Ver = 3. 1. 2. 5 | Size = 278902 bytes | Modified Date = 4/24/2007 6:59:08 PM | Attr = ]
MZKERNEL32.DLL , -> %SystemDrive%\~WRF0409.tmp -> [Ver = | Size = 18484 bytes | Modified Date = 1/1/2006 8:06:42 AM | Attr = ]
qoologic , urllogic , urllogic , abetterinternet.com , -> %SystemRoot%\azoav.dll -> [Ver = | Size = 4033 bytes | Modified Date = 5/16/2005 8:43:44 PM | Attr = ]
UpackByDwing , MZKERNEL32.DLL , -> %SystemRoot%\cms32.exe -> [Ver = | Size = 44401 bytes | Modified Date = 2/8/2006 10:37:12 PM | Attr = RHS]
SAHAgent , -> %System32%gshmetq.ini -> [Ver = | Size = 35 bytes | Modified Date = 9/11/2005 1:55:24 PM | Attr = ]
SAHAgent , -> %System32%\c50abr57.ini -> [Ver = | Size = 3438 bytes | Modified Date = 11/9/2005 6:02:48 AM | Attr = ]
PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41397 bytes | Modified Date = 3/31/2003 7:00:00 AM | Attr = ]
SAHAgent , -> %System32%\oje5p896.ini -> [Ver = | Size = 35 bytes | Modified Date = 9/11/2005 1:55:24 PM | Attr = ]
UPX! , UPX0 , -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Modified Date = 4/30/2007 8:47:36 PM | Attr = ]
winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 3/31/2003 7:00:00 AM | Attr = ]
WSUD , UPX0 , -> %System32%\dllcache\hwxjpn.dll -> [Ver = | Size = 13463552 bytes | Modified Date = 3/31/2003 7:00:00 AM | Attr = ]
UPX! , FSG! , PEC2 , aspack , -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.467 | Size = 777984 bytes | Modified Date = 5/4/2007 6:10:54 PM | Attr = ]
PTech , -> %System32%\drivers\mtlstrm.sys -> Smart Link [Ver = 3.80.01MC15 | Size = 1309184 bytes | Modified Date = 8/4/2004 12:41:38 AM | Attr = ]

< End of report >

And here is another HJTLog

Logfile of HijackThis v1.99.1
Scan saved at 5:33:15 PM, on 5/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\David\Application Data\U3\00186F6A62AB3D\LaunchPad.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB} (Street Technologies ActiveX Control Object) - http://www.tutorials.com/plugins/Plugin050…eetnoagent7.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://mymail.humana.com/iNotes6W.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1109624551750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1152669359626
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/41/install/gtdownls.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/insta…cdetection3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8208ABBE-A468-4911-ADBA-DAE31CF2F43D}: NameServer = 206.141.193.55,66.73.20.40
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I'm sorry I couldn't follow your instructions. Maybe I will add some prayers ,I think I need them.

Thank you

oldladywho
Hi oldladywho

Re-boot into safe mode

  • Next, please reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear use arrow up to highlight
  • Select the first option, to run Windows in Safe Mode hit enter.
  • For additional help in booting into Safe Mode, see the following site: HERE

Right click start, In the drop down menu click "Explore" Then navigate to each file\ folder in the left hand pane, which will reveal its content in the right hand pane, highlight file or folder right click and Delete, if present:

c:\cms32.exe This file
c:\catchme.exe << This file
c:\windows\System32\c50abr57.ini << This file
c:\windows\System32\oje5p896.ini << This file
c:\windows\System32\gshmetq.ini << This file
c:\windows\System32\kernels32.exe_tobedeleted << This file
c:\win32delfkil.exe << This file
c:\WRF0409.tmp << This file
c:\SDFix << This folder
c:\QooBox << THis folder

Search and delete files
We need to do a search now.Go to
  • Start
  • Search
  • For Files and Folders
  • Expand Search Options, check Advanced Options, check Search system folders, Search hidden files and folders, and Search Subfolders.
  • Paste this into the Search for files and folders named box:
  • MZKERNEL32.DLL
If any of these files are found please delete them.


reboot into normal mode and let me know how things are at this point in time.
Thanks dan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI