Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93104 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Hijackthis Help...


  • Please log in to reply
18 replies to this topic

#1 Kdung

Kdung

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 04 June 2007 - 02:03 AM

I have some problems with my computer of late.. .any help would be greatly appreciated... here is my log... i also run adaware, spyware, and mcafee if that helps any... i hope i do this right... let me know if there is anything else i can do...

thanks in advance

Logfile of HijackThis v1.99.1
Scan saved at 2:07:55 AM, on 6/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sony\Giga Pocket\shwserv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 4.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F 1.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plustek\OpticFilm 7200\QuickScan.exe
C:\Program Files\sony\usbsircs\usbsircs.exe
C:\Program Files\Sony\Giga Pocket\ReserveModule.exe
C:\Program Files\Sony\Giga Pocket\gps.exe
C:\Program Files\Sony\Giga Pocket\RM_SV.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\\Desktop\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.hawaiian...ain/login/Login
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://netmail.verizon.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [VAIO Recovery] "C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 4.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2 F1.EXE" /P30 "EPSON Stylus Photo R300 Series" /O6 "USB002" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [IS CfgWiz] "C:\Documents and Settings\Norton Internet Security 2005 Retail\nav\external\norton\cfgwiz.exe" /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] "C:\Documents and Settings\Norton Internet Security 2005 Retail\setup\pcontrol\app\urllstck.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [setup] "rundll32.exe" "C:\WINDOWS\system32\adsjebxv.dll",realset
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickScan (OpticFilm 7200).lnk = C:\Program Files\Plustek\OpticFilm 7200\QuickScan.exe
O4 - Global Startup: Remocon Driver.lnk = ?
O4 - Global Startup: Timer Recording Manager.lnk = C:\Program Files\Sony\Giga Pocket\ReserveModule.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by120fd.bay12...es/MsnPUpld.cab
O23 - Service: Giga Pocket Hardware Detector - Sony Corporation - C:\Program Files\Sony\Giga Pocket\shwserv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCs\VzHardwareResourceManager\VzHar dwareResourceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

    Advertisements

Register to Remove


#2 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 04 June 2007 - 06:32 AM

Hello Kdung and Welcome to TomCoyote,

Please do the following:

Please perform an online scan with Internet Explorer at
http://www.kaspersky...apter=161739400

* Turn off the real time scanner of any existing antivirus program while performing the online scan
Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      Extended
    • Scan Options:
      Scan Archives
      Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
**Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

Deckard’s System Scanner

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt to your post. in your reply
Please also post the report from Kaspersky.
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

#3 Kdung

Kdung

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 04 June 2007 - 03:23 PM

Thank you for your time... i did as told and here is what i got

Monday, June 04, 2007 11:04:15 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 4/06/2007
Kaspersky Anti-Virus database records: 339567
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
G:\
I:\
Scan Statistics
Total number of scanned objects 72806
Number of viruses found 50
Number of infected objects 118 / 0
Number of suspicious objects 4
Duration of the scan process 00:55:50

Infected Object Name Virus Name Last Action
C:\booterror.pif Infected: Trojan-Downloader.Win32.Adload.bo skipped
C:\bootfix.pif Infected: Trojan-Downloader.Win32.Adload.bo skipped
C:\bootfixor.pif Infected: Trojan-Downloader.Win32.Adload.bo skipped
C:\boothelp.pif Infected: Trojan-Downloader.Win32.Adload.bo skipped
C:\bootload.pif Infected: Trojan-Downloader.Win32.Adload.bo skipped
C:\cntdrv.pif Infected: Trojan-Downloader.Win32.Adload.bm skipped
C:\contacts.pif Infected: Trojan-Downloader.Win32.Adload.bm skipped
C:\dirfix.pif Infected: Trojan-Downloader.Win32.Adload.bo skipped
C:\dirfixer.pif Infected: Trojan-Downloader.Win32.Adload.bo skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2RPC9D2S\lo1[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\BOPDATA\_Date-20070604_Time-092315359_EnterceptExceptions.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\BOPDATA\_Date-20070604_Time-092315359_EnterceptRules.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_KRIS.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_KRIS.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\AccessProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\BufferOverflowProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\OnAccessScanLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.ldb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.mdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\VAIO Entertainment Platform\1.0\VzCdb\MtData.ldb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\VAIO Entertainment Platform\1.0\VzCdb\MtData.mdb Object is locked skipped
C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cert8.db Object is locked skipped
C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\history.dat Object is locked skipped
C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\key3.db Object is locked skipped
C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\parent.lock Object is locked skipped
C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Application Data\Webroot\Spy Sweeper\Logs70604092307.ses Object is locked skipped
C:\Documents and Settings\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Desktop\Comp Fix\aimfix_quarantine\10102_ac2_0003.exe.bak Infected: Trojan-Downloader.Win32.Small.cpu skipped
C:\Documents and Settings\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and SettingsLocal Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Local Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Local Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Local Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\\Local Settings\History\History.IE5\MSHist012007060420070605\index.dat Object is locked skipped
C:\Documents and Settings\Local Settings\Temp\WinAntiVirusPro2007FreeInstall.exe Infected: not-a-virus:Downloader.Win32.WinFixer.u skipped
C:\Documents and Settings\Local Settings\Temp\YazzleBundle-1281.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Documents and Settings\\Local Settings\Temp\YazzleBundle-1281.exe NSIS: infected - 1 skipped
C:\Documents and Settings\\Local Settings\Temp\yazzlesnet.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Documents and Settings\Local Settings\Temp\yazzlesnet.exe NSIS: infected - 1 skipped
C:\Documents and Settings\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\ntuser.dat Object is locked skipped
C:\Documents and Settings\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS055A0344-562E-4927-92F4-11FECE0F26A0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS07850310-9343-4A87-B986-057767AED9D5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0A29259F-F38F-46AC-8E5C-2B172C507368.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS133CC731-FEEE-4169-A1CE-722311899C6F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS138F168C-99EF-41E8-A2A0-7136078F8D94.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1AB80932-A7E4-43A3-A2CC-2358E01DE715.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1C203542-EFD4-462B-8C78-2B11F7C11AF6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1F95FEBE-D81E-4AB8-A1A2-9F9B96ABEB99.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2256B976-7768-4048-8361-64B663E1A89C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2348D15C-F8FF-400A-A5CC-0C4FEF4E67F6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2528393D-56DC-47F8-ABF9-A9E70AFE94EE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS27CABE2F-09F5-4BC0-AE29-D527CA85D1A6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS291B82B6-37F6-44CB-85E0-C6159030EB56.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2B3FF26A-E8F1-40E4-81B3-BFCFD71B4EC6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS30A9B87F-6184-40BC-A324-8F662C72E1E4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS31A5FEF2-4F70-4D57-A9C4-187D3DFB5F98.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS33FE7234-A91F-4466-87A2-FA5FFA706393.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS34C7EE3F-5EA1-4912-AC9F-248A8E7B6930.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS368A8C97-FD42-4D99-B50C-2766360213A2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS373644E6-5CFC-4A6C-8F8C-43A53655DAA4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3E80A1AE-BE16-4BC5-B546-B076B4E884F5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3F58CD48-3FF8-4694-B81A-9E0576ED7A62.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3FACF07F-76B2-487C-A699-EADE624F6E58.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4043A507-DD2F-4F3F-9F22-5C1F2D1A8C8B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4794F3DD-CF18-4851-8D17-C80371DAA4D5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS48C54FA3-1178-4455-A9D7-1B2DF0B06F6B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4A4846D7-E34A-4650-AF94-A27D2AB5350F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4DA5728D-8317-49A8-82BC-D5AEE55023F3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5185CF90-4460-44FE-A177-7A533FBB8A29.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS55921BB9-4893-46D1-A621-B716C8661964.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS597AC419-2B76-4856-82F6-BF5964889825.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5D302BB8-AF97-4D7A-AC7E-CD1671E25194.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS62916892-1997-4BE4-AEA3-C703179A02B7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6693F393-AE4D-4AC1-8002-E96728A0C734.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS69D78ADC-1BBF-477A-B13E-EC7A4AA8C650.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6D9BDD8A-4CCB-4868-B3CD-DD8395C11236.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS707F894D-BCC0-4FFA-82A5-B6A6FAD6D1F3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS70919FD3-490C-47C8-9942-C7283DEA0260.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS743766C4-3543-454E-9D61-C6F12C9A621D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS74BFB860-E63A-4870-AADA-68107A101464.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS776C86C5-4052-4CDC-B443-E8B207A1F82D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7B796A92-7471-452E-9EE6-22D7790918B7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8093C558-C7A7-4E30-B61E-B8FCE2A278B7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS80FC01FB-C45A-488D-8971-224D3AF18AB1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS810E17EB-4217-47C4-AE09-DDCD2B2442F4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8119486D-B264-4C9D-973E-7B2A6543B10C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8132FF3C-CFFA-41B5-AB6D-691DB5DDA3A8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS821CD27A-6C2C-4FD5-99C4-2DEF34538589.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS84F494FC-8B3D-4180-BEBD-C243920DCD69.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS85C810E6-7CF4-42E9-BCB5-081E1508AE7E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS864B6523-8126-4A99-8249-AC7E266F0076.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS87BC086E-4D7E-4C9B-9EB1-3FCDE4F75743.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8C3851C9-AAB9-4E3A-8EA3-19A63262FD04.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8CB7A5A7-F72D-4F5F-9E3B-ACB67BEA7BD3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8EFB5889-EAD6-48F5-9BF4-86F4FCC9B137.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS91463A23-8F0B-4BD7-BC7C-7978A219E7E9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS915E9B47-23C2-461A-8D69-E1077154AEE9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9D4F6940-7F13-4F42-B607-50EB80BDEE28.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA352D945-5D79-4621-A2A0-506C1B813E40.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA68707CC-19C7-4F3F-AA33-62E59ADF247D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA6BF71F9-ADEC-4507-9DF0-2F5A8C99A51D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAA7D49D8-1BAE-4D92-ABF5-B037798091D4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSADA0F8D6-D36B-45FC-AF62-D88283D74936.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAEC8FC79-7056-4518-8549-1792B1EAC9D9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAFEC130D-E28A-4760-B6DA-197EC4EE6AA2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB1160AF6-2C23-47B1-A49E-F194FEFF7EB1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB1BBC3E3-594F-4B09-98D4-B55DB97BF689.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB5AA6C28-966D-493D-ADD9-9A238BB9DE1D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB68EFFEA-3A4B-4FF1-9D9A-BA4F0E8FBCF3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB8D276B4-606F-46BD-9BDE-96A99192F629.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB9B2001A-EEE2-4050-B2A4-62C49437DB9A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBF6C5CE4-4391-4BE5-9711-B4332D6690F8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBF9F26B6-63A9-4271-990C-D314745F5555.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC161E185-02B2-45A0-9502-E0DC62CBDAE4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC25FE3D5-336B-4496-96A2-C74BBA1C688B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC2FD5497-9AED-4D47-9259-C5D5EEB5A30D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC6305E93-F5CD-4A68-93FC-E578077EBF73.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCC8768D4-B183-48EE-845B-C93D659709B9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCDE9F2C3-7CBC-4D5F-B91F-12D8DC8C14DD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD3236353-8679-412B-8397-9DA1BEA27CC5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDD8C5FC9-95B3-4237-AD56-311E0CD91614.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDE47D818-8E6F-4E77-A38F-442E8DFC9513.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDF78E31F-CA24-4E02-8EDB-C512DC78F349.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE00B3655-1A2C-4668-A498-79A2B779C968.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE24891AA-7478-43BF-BBF3-E998F661BB37.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE3CC3448-4685-4E6F-AA6B-F8382879A037.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE55E95BC-D9F0-40BA-8FA8-457F5398E285.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF0077CB7-41FC-4413-B1F5-8F390C402DB5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF6BDDFF0-4CD1-4F7E-BBAB-E42D1F6AB102.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF7B7FEEA-C295-472D-B7D9-DE8A04A17818.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFD891E93-5FB0-48EB-B764-4782AA104377.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Downloads\Monopoly3Setup-dm[1].exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\fixboot.pif Infected: Trojan-Downloader.Win32.Adload.bo skipped
C:\NNSCAA638.EXE Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine1CA2442.exe Infected: Trojan-Downloader.Win32.Dyfuca.de skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine5C87853.dll Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\17021452.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1F280201.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1F280201.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1F280201.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1F280201.zip ZIP: infected - 3 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1F280201.zip CryptFF: infected - 3 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\26DF2698.dll Infected: Trojan-Downloader.Win32.Dyfuca.gen skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2F9F6531.exe Infected: Trojan-Downloader.Win32.Dyfuca.de skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\397B4685.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\397B4685.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\397B4685.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\397B4685.zip ZIP: infected - 3 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\397B4685.zip CryptFF: infected - 3 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\3D956A26.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\513A3653.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\52E36468.exe Infected: Trojan-Downloader.Win32.Dyfuca.dp skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\52E70E64.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\52EA3861.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\52ED625D.dll Infected: Trojan-Downloader.Win32.IstBar.gen skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\52ED625D.exe Infected: Trojan.Win32.Small.cy skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\52ED625D.srg Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\52ED625D.vxd Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\52F00C5A.dll Infected: Trojan-Downloader.Win32.Dyfuca.dc skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5CCB7251.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\61EB5398.exe Infected: not-a-virus:AdWare.Win32.SurfAccuracy.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\61EF7D95.dll Infected: Trojan-Downloader.Win32.Dyfuca.dt skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\65E0797D.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\685B2E50.dll Infected: Trojan-Downloader.Win32.IstBar.gen skipped
C:\Program Files\poolsv\wr-1-0000077.exe Infected: Trojan-Downloader.Win32.Agent.brf skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.mst Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped
C:\quarantine\ar3.jar-2ecf098a-1e574239.zip.Vir/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped
C:\quarantine\ar3.jar-2ecf098a-1e574239.zip.Vir ZIP: infected - 1 skipped
C:\quarantine\ar3.jar-724f57b4-74cacb35.zip.Vir/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped
C:\quarantine\ar3.jar-724f57b4-74cacb35.zip.Vir ZIP: infected - 1 skipped
C:\quarantine\count.jar-f9805df-2f260531.zip.Vir/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\quarantine\count.jar-f9805df-2f260531.zip.Vir/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\quarantine\count.jar-f9805df-2f260531.zip.Vir/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
C:\quarantine\count.jar-f9805df-2f260531.zip.Vir ZIP: infected - 3 skipped
C:\quarantine\jar.jar-3dc6b66e-7bd82b18.zip.Vir/Counter.class Infected: Trojan.Java.Femad skipped
C:\quarantine\jar.jar-3dc6b66e-7bd82b18.zip.Vir/VerifierBug.class Infected: Trojan.Java.Femad skipped
C:\quarantine\jar.jar-3dc6b66e-7bd82b18.zip.Vir/web.exe Infected: Trojan.Win32.Small.ev skipped
C:\quarantine\jar.jar-3dc6b66e-7bd82b18.zip.Vir/Worker.class Infected: Trojan.Java.Femad skipped
C:\quarantine\jar.jar-3dc6b66e-7bd82b18.zip.Vir/Xeyond.class Infected: Trojan.Java.Femad skipped
C:\quarantine\jar.jar-3dc6b66e-7bd82b18.zip.Vir ZIP: infected - 5 skipped
C:\quarantine\loaderadv272.jar-340e62ec-5c2cc296.zip.Vir/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped
C:\quarantine\loaderadv272.jar-340e62ec-5c2cc296.zip.Vir ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP634\A0146688.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP634\A0146689.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kb skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP635\A0146774.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP635\A0146775.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kb skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP636\A0146853.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP636\A0146854.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kb skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP637\A0158275.exe Infected: Trojan-Downloader.Win32.VB.fn skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0169942.exe Infected: Trojan-Downloader.Win32.Zlob.btq skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0169948.exe Infected: Trojan-Downloader.Win32.Zlob.bgs skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0169949.dll Infected: not-a-virus:AdWare.Win32.Agent.cu skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0170356.exe Infected: Trojan-Downloader.Win32.Agent.brf skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0171384.exe Infected: Trojan-Downloader.Win32.Zlob.btq skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0171399.dll Infected: not-a-virus:AdWare.Win32.Agent.cu skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0171400.exe Infected: Trojan-Downloader.Win32.Zlob.bgs skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0174488.exe Infected: Trojan-Downloader.Win32.Agent.brf skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0174492.dll Suspicious: Packed.Win32.Morphine.a skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176649.exe/Stream/data0002 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176649.exe/Stream Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176649.exe Inno: infected - 2 skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176684.exe Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176685.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176691.dll Suspicious: Packed.Win32.Morphine.a skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176692.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176693.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped
C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\change.log Object is locked skipped
C:\Temp\gorPUS.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.co skipped
C:\Temp\gorPUS.exe/data0003 Infected: Trojan.Win32.BHO.ab skipped
C:\Temp\gorPUS.exe/data0004 Infected: Trojan-Dropper.Win32.Agent.bfr skipped
C:\Temp\gorPUS.exe/data0005 Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\Temp\gorPUS.exe NSIS: infected - 4 skipped
C:\warranty.pif Infected: Trojan-Downloader.Win32.Adload.bm skipped
C:\windll.pif Infected: Trojan-Downloader.Win32.Adload.bm skipped
C:\WINDOWS\$NtUninstallKB824141$\user32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\win32k.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\accwiz.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\crypt32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\cryptsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hh.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hhctrl.ocx Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hhsetup.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\html32.cnv Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\itircl.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\itss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\locator.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\magnify.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\migwiz.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\mrxsmb.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\msconv97.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\narrator.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\newdev.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ole32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\pchshell.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\raspptp.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\rpcrt4.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\rpcss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\shdocvw.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\shell32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\shmedia.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\srrstr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\srv.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\urlmon.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\user32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\winsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828028$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\wmp.dll Object is locked skipped
C:\WINDOWS\browserxtras\pn\remove.exe/data0002/data0003 Infected: Trojan-Downloader.Win32.Keenval.f skipped
C:\WINDOWS\browserxtras\pn\remove.exe/data0002 Infected: Trojan-Downloader.Win32.Keenval.f skipped
C:\WINDOWS\browserxtras\pn\remove.exe NSIS: infected - 2 skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\esba-4.exe/WISE0007.BIN Infected: Backdoor.Win32.Ruledor.e skipped
C:\WINDOWS\esba-4.exe/WISE0008.BIN Infected: Trojan-Downloader.Win32.Agent.ab skipped
C:\WINDOWS\esba-4.exe/WISE0009.BIN Infected: not-a-virus:AdWare.Win32.SpecialOffers.a skipped
C:\WINDOWS\esba-4.exe/WISE0010.BIN Infected: Trojan-Dropper.Win32.Small.gj skipped
C:\WINDOWS\esba-4.exe/WISE0011.BIN Infected: Trojan-Downloader.Win32.IstBar.er skipped
C:\WINDOWS\esba-4.exe WiseSFX: infected - 5 skipped
C:\WINDOWS\NDNuninstall6_38.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\WINDOWS\NDNuninstall7_22.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{C1A7527C-A5AE-40F5-B75A-9426E6A59DBC}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\adsjebxv.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\e10ogsvc.exe Infected: Trojan.Win32.Crypt.t skipped
C:\WINDOWS\system32\gibmiryu.dll Suspicious: Packed.Win32.Morphine.a skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\hgggfgf.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\WINDOWS\system32\ibxcsjxm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kb skipped
C:\WINDOWS\system32\jxumebwn.dll Suspicious: Packed.Win32.Morphine.a skipped
C:\WINDOWS\system32\oleext.dll Infected: Trojan.Win32.Small.ev skipped
C:\WINDOWS\system32\tuvsrsp.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\WINDOWS\system32\vtsqr.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\daCF.tmp Infected: not-a-virus:AdWare.Win32.SurfSide.ap skipped
C:\WINDOWS\Temp\JETC88F.tmp Object is locked skipped
C:\WINDOWS\Temp\JETD5DE.tmp Object is locked skipped
C:\WINDOWS\wallpap.exe Infected: Trojan-Clicker.Win32.Agent.gp skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\windows.pif Infected: Trojan-Downloader.Win32.Adload.bm skipped
C:\windowsdll.pif Infected: Trojan-Downloader.Win32.Adload.bm skipped
C:\winntdll.pif Infected: Trojan-Downloader.Win32.Adload.bm skipped
Scan process completed.


Main.txt

Deckard's System Scanner v20070603.47
Run by on 2007-06-04 at 11:06:38
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
71: 2007-06-04 21:06:49 UTC - RP658 - Deckard's System Scanner Restore Point
70: 2007-06-04 07:39:55 UTC - RP657 - Removed VAIO System Information
69: 2007-06-01 13:25:20 UTC - RP656 - Restore Operation
68: 2007-06-01 10:31:02 UTC - RP655 - Removed SonicStage
67: 2007-05-31 10:44:23 UTC - RP654 - Removed OpenMG


-- First Restore Point --
1: 2007-02-25 21:21:33 UTC - RP588 - System Checkpoint


Backed up registry hives.

Performed disk cleanup.


-- HijackThis -------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 11:08:04 AM, on 6/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sony\Giga Pocket\shwserv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plustek\OpticFilm 7200\QuickScan.exe
C:\Program Files\sony\usbsircs\usbsircs.exe
C:\Program Files\Sony\Giga Pocket\ReserveModule.exe
C:\Program Files\Sony\Giga Pocket\RM_SV.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sony\Giga Pocket\gps.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\Desktop\dss.exe
C:\DOCUME~1\KRISTO~1\Desktop\HIJACK~1\.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.hawaiian...ain/login/Login
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://netmail.verizon.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {045CA052-C7C7-4745-BF9E-F6E284866E36} - C:\WINDOWS\system32\jompsujl.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2432F099-F8E2-43C9-B765-3AF002FFC6A7} - C:\WINDOWS\system32\tuvsrsp.dll
O2 - BHO: (no name) - {3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5} - (no file)
O2 - BHO: (no name) - {F634C213-2C16-4845-9D3D-1E5FFFA34494} - C:\WINDOWS\system32\vtsqr.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [VAIO Recovery] "C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" /P30 "EPSON Stylus Photo R300 Series" /O6 "USB002" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [IS CfgWiz] "C:\Documents and Settings\Norton Internet Security 2005 Retail\nav\external\norton\cfgwiz.exe" /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] "C:\Documents and Settings\Norton Internet Security 2005 Retail\setup\pcontrol\app\urllstck.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [setup] "rundll32.exe" "C:\WINDOWS\system32\adsjebxv.dll",realset
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKLM\..\Run: [DC6_Check] "C:\Program Files\Common Files\WinAntiSpyware 2007\uwasdc.exe"
O4 - HKLM\..\Run: [ERS_Check] "C:\Program Files\Common Files\WinAntiSpyware 2007\uwasers.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickScan (OpticFilm 7200).lnk = C:\Program Files\Plustek\OpticFilm 7200\QuickScan.exe
O4 - Global Startup: Remocon Driver.lnk = ?
O4 - Global Startup: Timer Recording Manager.lnk = C:\Program Files\Sony\Giga Pocket\ReserveModule.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by120fd.bay12...es/MsnPUpld.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: tuvsrsp - C:\WINDOWS\SYSTEM32\tuvsrsp.dll
O20 - Winlogon Notify: vtsqr - C:\WINDOWS\system32\vtsqr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O20 - Winlogon Notify: wvutqon - wvutqon.dll (file missing)
O23 - Service: Giga Pocket Hardware Detector - Sony Corporation - C:\Program Files\Sony\Giga Pocket\shwserv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 NaiAvTdi1 - c:\windows\system32\drivers\mvstdi5x.sys <Not Verified; Network Associates, Inc.; VirusScan>
R3 EntDrv51 - c:\windows\system32\drivers\entdrv51.sys <Not Verified; Network Associates, Inc; Virus Scan Enterprise, Entercept>
R3 NaiAvFilter1 - c:\windows\system32\drivers\naiavf5x.sys <Not Verified; Network Associates, Inc.; VirusScan>

S3 l8042pr2 (Logitech PS/2 Mouse Filter Driver) - c:\windows\system32\drivers\l8042pr2.sys <Not Verified; Logitech, Inc.; Logitech MouseWare™>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 McAfeeFramework (McAfee Framework Service) - c:\program files\network associates\common framework\frameworkservice.exe /servicestart <Not Verified; Network Associates, Inc.; McAfee Common Framework>
R2 McTaskManager (Network Associates Task Manager) - "c:\program files\network associates\virusscan\vstskmgr.exe" <Not Verified; Network Associates, Inc.; VirusScan Enterprise>


-- Scheduled Tasks -------------------------------------------------------------

2007-06-02 03:30:01 446 --a------ C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job


-- Files created between 2007-05-04 and 2007-06-04 -----------------------------

2007-06-04 09:50:32 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-06-04 09:50:28 0 d-------- C:\WINDOWS\LastGood
2007-06-03 21:38:29 0 d-------- C:\Program Files\Common Files\WinAntiSpyware 2007
2007-06-03 21:38:26 0 d-------- C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007
2007-06-03 21:36:49 26166 --a------ C:\WINDOWS\system32\hgggfgf.dll
2007-06-03 21:36:39 0 d-------- C:\WINDOWS\system32\T9QaSQ
2007-06-03 21:36:31 0 d-------- C:\Program Files\svhost
2007-06-03 21:36:13 215 --a------ C:\WINDOWS\svhost.exe
2007-06-03 21:35:53 0 d-------- C:\Program Files\poolsv
2007-06-03 21:32:17 23040 --a------ C:\WINDOWS\poolsv.exe <Not Verified; Poolsv; Poolsv>
2007-06-03 01:43:47 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2007-06-03 01:20:36 125460 --a------ C:\WINDOWS\system32\jxumebwn.dll
2007-06-03 01:20:06 0 d-------- C:\Documents and Settings\Application Data\GetRightToGo
2007-06-03 01:12:49 0 d--h----- C:\Documents and Settings\LocalService\SendTo
2007-06-03 01:11:48 0 d--h----- C:\Documents and Settings\LocalService\NetHood
2007-06-03 01:11:48 0 dr------- C:\Documents and Settings\LocalService\My Documents
2007-06-03 01:11:45 0 dr-h----- C:\Documents and Settings\LocalService\Recent
2007-06-03 00:28:35 164 --a------ C:\install.dat
2007-06-02 22:03:11 1661511 ---hs---- C:\WINDOWS\system32\rqstv.ini2
2007-06-02 20:18:42 125460 --a------ C:\WINDOWS\system32\gibmiryu.dll
2007-06-01 03:23:19 0 d-------- C:\WINDOWS\system32\TQ0
2007-06-01 03:23:19 0 d-------- C:\WINDOWS\system32\T6
2007-06-01 03:23:19 0 d-------- C:\WINDOWS\system32\T4
2007-06-01 03:23:19 0 d-------- C:\WINDOWS\system32\T3
2007-06-01 03:23:19 0 d-------- C:\WINDOWS\system32\T1QaSQ
2007-06-01 03:23:19 0 d-------- C:\WINDOWS\system32\pog
2007-05-30 17:59:07 0 d-------- C:\WINDOWS\network diagnostic
2007-05-30 17:41:28 0 d-------- C:\Documents and Settings\Application Data\RegistrySmart
2007-05-29 21:51:45 29206 --a------ C:\WINDOWS\system32\tuvsrsp.dll
2007-05-27 01:10:12 1612093 ---hs---- C:\WINDOWS\system32\rqstv.bak2
2007-05-26 03:14:12 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2007-05-26 03:14:12 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2007-05-26 03:14:12 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2007-05-26 03:14:12 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2007-05-26 03:14:12 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2007-05-26 03:14:12 0 dr------- C:\Documents and Settings\Administrator\My Documents
2007-05-26 03:14:12 0 d-------- C:\Documents and Settings\Administrator\Desktop
2007-05-26 03:14:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-05-26 03:14:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
2007-05-26 03:14:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2007-05-26 03:14:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2007-05-26 01:26:21 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-05-26 01:11:43 132660 --a------ C:\WINDOWS\system32\adsjebxv.dll
2007-05-26 01:09:02 50745 --a------ C:\WINDOWS\system32\ibxcsjxm.dll
2007-05-26 01:09:01 1543908 --ahs---- C:\WINDOWS\system32\rqstv.bak1
2007-05-26 01:08:36 263220 --ahs---- C:\WINDOWS\system32\vtsqr.dll
2007-05-26 01:03:31 0 d-------- C:\Documents and Settings\Administrator\Application Data\Webroot
2007-05-26 01:01:02 0 dr------- C:\Documents and Settings\Administrator\Favorites
2007-05-26 01:01:02 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2007-05-26 01:01:02 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2007-05-26 01:01:02 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2007-05-26 01:01:01 0 d--h----- C:\Documents and Settings\Administrator\Templates
2007-05-26 01:01:01 1048576 --a------ C:\Documents and Settings\Administrator\NTUser.dat
2007-05-26 01:01:01 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2007-05-18 20:57:49 0 d-------- C:\WINDOWS\system32\SBO
2007-05-18 20:57:48 0 d-------- C:\Temp


-- Find3M Report ---------------------------------------------------------------

2007-06-03 21:40:08 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-06-01 03:23:40 0 d-------- C:\Program Files\Common Files\Sony Shared
2007-06-01 03:22:19 0 d-------- C:\Program Files\AIM
2007-06-01 03:22:19 0 d-------- C:\Documents and Settings\Application Data\Aim
2007-06-01 03:19:37 0 d-------- C:\Program Files\Sony
2007-06-01 03:19:03 0 d-------- C:\Program Files\Windows NT
2007-05-31 00:08:33 0 d-------- C:\Documents and Settings\Application Data\Mozilla
2007-05-21 00:11:27 0 d-------- C:\Documents and Settings\Application Data\U3
2007-05-11 10:33:53 0 d--h----- C:\Program Files\Stuff


-- Registry Dump ---------------------------------------------------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{045CA052-C7C7-4745-BF9E-F6E284866E36} C:\WINDOWS\system32\jompsujl.dll [x]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
{2432F099-F8E2-43C9-B765-3AF002FFC6A7} C:\WINDOWS\system32\tuvsrsp.dll
{F634C213-2C16-4845-9D3D-1E5FFFA34494} C:\WINDOWS\system32\vtsqr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"AGRSMMSG"="AGRSMMSG.exe"
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"ezShieldProtector for Px"="C:\\WINDOWS\\System32\\ezSP_Px.exe"
"VAIO Recovery"="\"C:\\WINDOWS\\Sonysys\\VAIO Recovery\\PartSeal.exe\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"EPSON Stylus Photo R300 Series"="\"C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I2F1.EXE\" /P30 \"EPSON Stylus Photo R300 Series\" /O6 \"USB002\" /M \"Stylus Photo R300\""
"IS CfgWiz"="\"C:\\Documents and Settings\\\Norton Internet Security 2005 Retail\\nav\\external\\norton\\cfgwiz.exe\" /GUID NIS /CMDLINE \"REBOOT\""
"URLLSTCK.exe"="\"C:\\Documents and Settings\\\Norton Internet Security 2005 Retail\\setup\\pcontrol\\app\\urllstck.exe\""
"ShStatEXE"="\"C:\\Program Files\\Network Associates\\VirusScan\\SHSTAT.EXE\" /STANDALONE"
"McAfeeUpdaterUI"="\"C:\\Program Files\\Network Associates\\Common Framework\\UpdaterUI.exe\" /StartedFromRunKey"
"Network Associates Error Reporting Service"="\"C:\\Program Files\\Common Files\\Network Associates\\TalkBack\\tbmon.exe\""
"EM_EXEC"="C:\\PROGRA~1\\Logitech\\MOUSEW~1\\SYSTEM\\EM_EXEC.EXE"
"setup"="\"rundll32.exe\" \"C:\\WINDOWS\\system32\\adsjebxv.dll\",realset"
"svhost"="\"C:\\WINDOWS\\svhost.exe\""
"DC6_Check"="\"C:\\Program Files\\Common Files\\WinAntiSpyware 2007\\uwasdc.exe\""
"ERS_Check"="\"C:\\Program Files\\Common Files\\WinAntiSpyware 2007\\uwasers.exe\""
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe\" /startintray"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ares"="\"C:\\Program Files\\Ares\\Ares.exe\" -h"
"Aim6"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ofmf"="C:\\PROGRA~1\\COMMON~1\\ofmf\\ofmfm.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"rare"="C:\\Program Files\\Video ActiveX Access\\imsmain.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{25b7d2fd-4f71-46d1-801a-7de323e4ec82}"="equiparant"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{2432F099-F8E2-43C9-B765-3AF002FFC6A7}"=""

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvsrsp
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtsqr
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvutqon

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\
Notification Packages REG_MULTI_SZ scecli\

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService REG_MULTI_SZ DnsCache\
rpcss REG_MULTI_SZ RpcSs\
imgsvc REG_MULTI_SZ StiSvc\
termsvcs REG_MULTI_SZ TermService\
HTTPFilter REG_MULTI_SZ HTTPFilter\
DcomLaunch REG_MULTI_SZ DcomLaunchTermService\


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I]
Shell\AutoRun\command I:\LaunchU3.exe -a
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_ENTDRV51


-- End of Deckard's System Scanner: finished at 2007-06-04 at 11:09:49 ---------

Extra.txt

Deckard's System Scanner v20070603.47
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Pentium® 4 CPU 3.00GHz
CPU 1: Intel® Pentium® 4 CPU 3.00GHz
Percentage of Memory in Use: 54%
Physical Memory (total/avail): 511.36 MiB / 230.18 MiB
Pagefile Memory (total/avail): 1247.88 MiB / 864.86 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1973.63 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 143.04 GiB total, 76.86 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)
F: is Removable (No Media)
G: is Removable (No Media)
I: is Removable (No Media)


-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.

AntiVirusDisableNotify is set.
FirewallDisableNotify is set.
UpdatesDisableNotify is set.
AntivirusOverride is set.
FirewallOverride is set.


[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\1116561602\ee\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1116561602\ee\AOLServiceHost.exe:*:Enabled:AOL Services"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\Common Files\AOL\1148375632\ee\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1148375632\ee\AOLServiceHost.exe:*:Enabled:AOL Services"
"C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\WINDOWS\\system32\\P2P Networking\\P2P Networking.exe"="C:\\WINDOWS\\system32\\P2P Networking\\P2P Networking.exe:*:Enabled:P2P Networking"
"C:\\Program Files\\Common Files\\AOL\\1116561602\\ee\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1116561602\\ee\\AOLServiceHost.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1148375632\\ee\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1148375632\\ee\\AOLServiceHost.exe:*:Enabled:AOL Services"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=KRIS
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\
LOGONSERVER=\\KRIS
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 3 Stepping 4, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0304
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\1\LOCALS~1\Temp
USERDOMAIN=
USERNAME=
USERPROFILE=C:\Documents and Settings\


-- User Profiles ---------------------------------------------------------------

Administrator (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\system32\UninstIPP.isu
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{93B80FB1-7A23-11D3-B250-00105A1F4184}\setup.exe"
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware SE Personal --> C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
Adobe Download Manager 2.0 (Remove Only) --> "C:\Program Files\Common Files\Adobe\ESD\uninst.exe"
Adobe Photoshop 7.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Adobe Reader 7.0.8 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70800000002}
Agere Systems AC'97 Modem --> agrsmdel
AIM 6.0 --> C:\Program Files\AIM6\uninst.exe
Ares 1.9.0 --> "C:\Program Files\Ares\uninstall.exe"
ATI - Software Uninstall Utility --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver --> rundll32 C:\WINDOWS\System32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Click to DVD 2.0 Menu Data --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98A3A654-3AEF-42D9-BA91-DE5815EA5897}\setup.exe"
Click to DVD 2.0.02 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7C2F71B2-6C73-11D6-B659-00C04F790F76}\setup.exe"
DivX --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Drag'n Drop CD+DVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DDC146FA-73E0-4FA1-A353-841EA14BF600}\Setup.exe" -l0x9 deleteall
DVgate Plus --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{685BCC47-B8EC-45EC-BBCE-77DF2451502C}\setup.exe"
EPSON CardMonitor --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{109D28C7-FB38-483A-9C91-001CB59E2699}\Setup.exe" -l0x9 uninst
EPSON PhotoStarter3.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5983C895-DDA4-45D9-A8D1-877D5DE7693E}\Setup.exe" uninst
EPSON Print CD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}\Setup.exe" -l0x9 -SYSTEM
EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON SPR300 Reference Guide --> C:\Program Files\epson\guide\spr300_e\uninstall.exe
Giga Pocket 5.5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A6BFDF60-FD08-4EF9-8D26-B762A19DB9A0}\Setup.exe"
Giga Pocket Demo Movie --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{979F6A6B-4CB0-424E-8E70-AA2ED38B4CCC}\Setup.exe"
Giga Pocket Hardware Library 5.5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0D490016-5D01-4CB3-A037-55814AC63D2E}\Setup.exe"
HijackThis 1.99.1 --> C:\Documents and Settings\Desktop\HijackThis\HijackThis.exe /uninstall
hp deskjet 920c series (Remove only) --> C:\Program Files\hp deskjet 920c series\hpfiui.exe -c -vdivid=HPF -vpnum=95 -vinstport=USB001 -vproduct=920c -huninstall
Intel® Extreme Graphics Driver --> RUNDLL32.EXE C:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572
Intel® Integrated Performance Primitives RTI 4.0 --> MsiExec.exe /X{51C91B84-7B46-4FE7-8999-8228CFA75F89}
Intel® PRO Network Adapters and Drivers --> Prounstl.exe
InterVideo WinDVD 5 for VAIO --> "C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
iTunes --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{00FC6799-866E-44A1-A60C-DCF394CF56FD}
Java 2 Runtime Environment, SE v1.4.2_01 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142010}
Kaspersky Online Scanner --> C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
LiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VcSetup.exe /REMOVE
Logitech MouseWare 9.71 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5809E7CF-4DCF-11D4-9875-00105ACE7734}\setup.exe" -l0x9 -l0009 UNINSTALL
Macromedia Flash Player 8 --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\swflash.inf,DefaultUninstall,5
Macromedia Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
McAfee VirusScan Enterprise --> MsiExec.exe /I{5DF3D1BB-894E-4DCD-8275-159AC9829B43}
Memory Stick Formatter --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{27337663-2619-11D4-99DC-0000F49094C7}\setup.exe" -l0x9 /UNINSTALL
Microsoft Data Access Components KB870669 --> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Mozilla Firefox (2.0.0.4) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Norton Internet Security --> MsiExec.exe /I{449F3A9E-9903-4a0d-A209-08030D45A935}
Norton Internet Security --> MsiExec.exe /I{A93C9E60-29B6-49da-BA21-F70AC6AADE20}
OpticFilm 7200 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E6D338B-7D32-469F-A8D8-1F279885CEB3}\Setup.exe" -l0x9
Presto! ImageFolio 4 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{783033B0-D8E6-11D5-9293-0050BA073EEC}\Setup.exe" -l0x9
Presto! Mr. Photo 3 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BDD8B3C0-0877-418D-ACC9-2AB0064B901A}\Setup.exe" -l0x9
Presto! PageManager 6.00 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{580183A6-FF92-11D5-9294-0050BA073EEC}\Setup.exe" -l0x9 anything
QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log
Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
SilverFast UScan-SE --> "C:\Program Files\LaserSoft\SilverFast UScan-SE\unins000.exe"
Sony Certificate PCH --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D0448678-1203-4158-A58F-B3D0B616BF9E}\setup.exe"
Spy Sweeper --> "C:\Program Files\Webroot\Spy Sweeper\unins000.exe"
VAIO Entertainment Platform --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D917FD82-6CE5-489A-AAF8-C701AAC85C4D}\Setup.exe" -l0x9
VAIO Help and Support --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{E68B38DE-D7DD-4FB3-A453-3F03A947EA8E}
VAIO Media 3.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1EB317D8-8945-4FD6-B37F-DF470317C6AB}\Setup.exe" -l0x9 UNINSTALL
VAIO Media Redistribution 3.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7128C69B-8F7E-4336-8698-3FD3CDD955EC}\Setup.exe" -l0x9 UNINSTALL
VAIO Registration --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{315BA29D-2644-4760-B5FD-5AC04A52B8C5}
VAIO Remote Commander Utility 6.2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4C75086F-7753-41B9-8B4C-F38DE6CC8C20}\Setup.exe"
VAIO SLIT-C Screen Saver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{01AF4645-78E6-46C4-B528-54863679CC40}\setup.exe" -l0x9
VAIO SLIT Pattern Wallpaper --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{266AEE68-5718-4A31-BDD3-D356B1250C70}\setup.exe" -l0x9
Windows Safety Alert --> C:\DOCUME~1\KRISTO~1\LOCALS~1\Temp\laf41B.tmp /del


-- End of Deckard's System Scanner: finished at 2007-06-04 at 11:09:49 ---------

#4 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 04 June 2007 - 04:49 PM

Hi Kdung,

Please do the following:

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Save the contents of C:\vundofix.txt to post in your next reply.
Combofix by sUBs
  • Download this file - combofix.exe
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Please post the vundofix.txt, the ComboFix log and a new hijackthis log.
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

#5 Kdung

Kdung

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 05 June 2007 - 02:05 AM

Thanks Im on it

Edited by Kdung, 05 June 2007 - 02:07 AM.


#6 Kdung

Kdung

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 05 June 2007 - 02:06 AM

Hi Susan...

New Hijack Log

Logfile of HijackThis v1.99.1
Scan saved at 9:59:47 PM, on 6/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sony\Giga Pocket\shwserv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Ares\Ares.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Plustek\OpticFilm 7200\QuickScan.exe
C:\Program Files\sony\usbsircs\usbsircs.exe
C:\Program Files\Sony\Giga Pocket\ReserveModule.exe
C:\Program Files\Sony\Giga Pocket\gps.exe
C:\Program Files\Sony\Giga Pocket\RM_SV.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Sony\Giga Pocket\gvr.exe
C:\Program Files\Sony\Giga Pocket\halsv.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Desktop\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.hawaiian...ain/login/Login
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://netmail.verizon.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {045CA052-C7C7-4745-BF9E-F6E284866E36} - C:\WINDOWS\system32\jompsujl.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)
O2 - BHO: (no name) - {F634C213-2C16-4845-9D3D-1E5FFFA34494} - C:\WINDOWS\system32\vtsqr.dll (file missing)
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IS CfgWiz] "C:\Documents and Settings\Norton Internet Security 2005 Retail\nav\external\norton\cfgwiz.exe" /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] "C:\Documents and Settings\Norton Internet Security 2005 Retail\setup\pcontrol\app\urllstck.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [DC6_Check] "C:\Program Files\Common Files\WinAntiSpyware 2007\uwasdc.exe"
O4 - HKLM\..\Run: [ERS_Check] "C:\Program Files\Common Files\WinAntiSpyware 2007\uwasers.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickScan (OpticFilm 7200).lnk = C:\Program Files\Plustek\OpticFilm 7200\QuickScan.exe
O4 - Global Startup: Remocon Driver.lnk = ?
O4 - Global Startup: Timer Recording Manager.lnk = C:\Program Files\Sony\Giga Pocket\ReserveModule.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by120fd.bay12...es/MsnPUpld.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O20 - Winlogon Notify: wvutqon - wvutqon.dll (file missing)
O23 - Service: Giga Pocket Hardware Detector - Sony Corporation - C:\Program Files\Sony\Giga Pocket\shwserv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

Vundo log

Symantec Adware.VirtuMonde Removal Tool 1.0.3
Adware.VirtuMonde has not been found on your computer.

Combo Log

- 2007-06-04 21:05:37 Service Pack 2 NTFS
ComboFix 07-06-3 - Running from: "C:\Documents and Settings\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\gibmiryu.dll
C:\WINDOWS\system32\jxumebwn.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\KRISTO~1\APPLIC~1\Sskuknwrd.dll
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\domains.txt
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\log.txt
C:\Tempb9
C:\Tempb9\tmpTF.log
C:\Temp\17O7
C:\Temp\17O7\tmpTF.log
C:\WINDOWS\keyboard191.dat
C:\WINDOWS\NDNuninstall6_38.exe
C:\WINDOWS\NDNuninstall7_22.exe
C:\WINDOWS\newname.dat
C:\WINDOWS\setup.exe
C:\WINDOWS\svhost.exe
C:\WINDOWS\system32\pog
C:\WINDOWS\system32\T3
C:\WINDOWS\system32\T4
C:\WINDOWS\Uninst2.htm
C:\WINDOWS\Unist1.htm
C:\WINDOWS\wallpap.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_NETWORK_MONITOR


((((((((((((((((((((((((( Files Created from 2007-05-05 to 2007-06-05 )))))))))))))))))))))))))))))))


2007-06-04 12:32 <DIR> d-------- C:\VundoFix Backups
2007-06-04 11:06 <DIR> d-------- C:\Deckard
2007-06-04 09:50 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-06-03 21:38 <DIR> d-------- C:\Program Files\Common Files\WinAntiSpyware 2007
2007-06-03 21:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007
2007-06-03 21:36 <DIR> d-------- C:\WINDOWS\system32\T9QaSQ
2007-06-03 21:36 <DIR> d-------- C:\Temp\x2b
2007-06-03 21:36 <DIR> d-------- C:\Program Files\svhost
2007-06-03 21:35 <DIR> d-------- C:\Program Files\poolsv
2007-06-03 21:32 23,040 --a------ C:\WINDOWS\poolsv.exe
2007-06-03 01:43 <DIR> d-------- C:\DOCUME~1\NETWOR~1\APPLIC~1\Webroot
2007-06-03 01:20 <DIR> d-------- C:\DOCUME~1\KRISTO~1\APPLIC~1\GetRightToGo
2007-06-03 00:28 164 --a------ C:\install.dat
2007-06-01 03:23 <DIR> d-------- C:\WINDOWS\system32\TQ0
2007-06-01 03:23 <DIR> d-------- C:\WINDOWS\system32\T6
2007-06-01 03:23 <DIR> d-------- C:\WINDOWS\system32\T1QaSQ
2007-05-30 17:59 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-05-30 17:41 <DIR> d-------- C:\DOCUME~1\KRISTO~1\APPLIC~1\RegistrySmart
2007-05-26 03:14 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-05-26 01:26 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-05-26 01:03 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Webroot
2007-05-26 01:01 1,048,576 --a------ C:\DOCUME~1\ADMINI~1\NTUser.dat
2007-05-18 20:57 335,565 --a------ C:\Temp\gorPUS.exe
2007-05-18 20:57 <DIR> d-------- C:\WINDOWS\system32\SBO
2007-05-18 20:57 <DIR> d-------- C:\Temp


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-04 07:40:08 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-01 13:23:40 -------- d-----w C:\Program Files\Common Files\Sony Shared
2007-06-01 13:22:19 -------- d-----w C:\Program Files\AIM
2007-06-01 13:22:19 -------- d-----w C:\DOCUME~1\KRISTO~1\APPLIC~1\Aim
2007-06-01 13:19:37 -------- d-----w C:\Program Files\Sony
2007-06-01 13:19:03 -------- d-----w C:\Program Files\Windows NT
2007-05-21 10:11:27 -------- d-----w C:\DOCUME~1\KRISTO~1\APPLIC~1\U3
2007-05-11 20:33:53 -------- d--h--w C:\Program Files\Stuff
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{045CA052-C7C7-4745-BF9E-F6E284866E36}=C:\WINDOWS\system32\jompsujl.dll []
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 20:38]
{F634C213-2C16-4845-9D3D-1E5FFFA34494}=C:\WINDOWS\system32\vtsqr.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2003-05-23 08:43 C:\WINDOWS\AGRSMMSG.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-11-15 19:00]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-08-01 09:17]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-06-04 12:38]
"IS CfgWiz"="C:\Documents and Settings\Norton Internet Security 2005 Retail\nav\external\norton\cfgwiz.exe" [2004-08-17 22:36]
"URLLSTCK.exe"="C:\Documents and Settings\Norton Internet Security 2005 Retail\setup\pcontrol\app\urllstck.exe" [2004-08-31 02:29]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 20:00]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 09:48]
"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2002-07-09 09:50]
"DC6_Check"="C:\Program Files\Common Files\WinAntiSpyware 2007\uwasdc.exe" []
"ERS_Check"="C:\Program Files\Common Files\WinAntiSpyware 2007\uwasers.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ares"="C:\Program Files\Ares\Ares.exe" [2006-05-03 05:39]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-10-31 12:49]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 21:56]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ofmf"=C:\PROGRA~1\COMMON~1\ofmf\ofmfm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"rare"=C:\Program Files\Video ActiveX Access\imsmain.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{25b7d2fd-4f71-46d1-801a-7de323e4ec82}"="C:\WINDOWS\system32\indwvm.dll" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvutqon]
wvutqon.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
AutoRun\command- I:\LaunchU3.exe -a

*Newly Created Service* - ENTDRV51

Contents of the 'Scheduled Tasks' folder
2007-06-02 13:30:01 C:\WINDOWS\tasks\RegistrySmart Scheduled Scan.job

**************************************************************************

catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-04 21:09:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-06-04 21:11:34 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-04 21:11

--- E O F ---

Thanks again....

#7 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 05 June 2007 - 10:58 PM

STEP 1.
======
Delete Files with Killbox

Download Pocket Killbox from http://www.downloads...org/KillBox.zip and unzip it; save it to your Desktop. DO NOT RUN IT YET.
==========
Double-click on KillBox.exe to launch the program. It is the red circle with a large white X in it
- Highlight the files in bold RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard
C:\booterror.pif
C:\bootfix.pif
C:\bootfixor.pif
C:\boothelp.pif
C:\bootload.pif
C:\cntdrv.pif
C:\contacts.pif
C:\dirfix.pif
C:\dirfixer.pif
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2RPC9D2S\lo1[1]
C:\Documents and Settings\Desktop\Comp Fix\aimfix_quarantine\10102_ac2_0003.exe.bak
C:\Documents and Settings\Local Settings\Temp\WinAntiVirusPro2007FreeInstall.exe
C:\Documents and Settings\Local Settings\Temp\YazzleBundle-1281.exe
C:\Documents and Settings\\Local Settings\Temp\YazzleBundle-1281.exe
C:\Documents and Settings\\Local Settings\Temp\yazzlesnet.exe
C:\Documents and Settings\Local Settings\Temp\yazzlesnet.exe
C:\Downloads\Monopoly3Setup-dm[1].exe
C:\fixboot.pif
C:\NNSCAA638.EXE
C:\Program Files\poolsv\wr-1-0000077.exe
C:\Temp\gorPUS.exe
C:\warranty.pif
C:\windll.pif
C:\WINDOWS\browserxtras\pn\remove.exe
C:\WINDOWS\esba-4.exe
C:\WINDOWS\NDNuninstall6_38.exe
C:\WINDOWS\NDNuninstall7_22.exe
C:\WINDOWS\system32\adsjebxv.dll
C:\WINDOWS\system32\e10ogsvc.exe
C:\WINDOWS\system32\gibmiryu.dll
C:\WINDOWS\system32\hgggfgf.dll
C:\WINDOWS\system32\ibxcsjxm.dll
C:\WINDOWS\system32\jxumebwn.dll
C:\WINDOWS\system32\oleext.dll
C:\WINDOWS\system32\tuvsrsp.dll
C:\WINDOWS\system32\vtsqr.dll
C:\WINDOWS\Temp\daCF.tmp
C:\WINDOWS\wallpap.exe
C:\windows.pif
C:\windowsdll.pif
C:\winntdll.pif


In Killbox click on the File menu and then the Paste from Clipboard item
in the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.)
  • Click the option to Delete on Reboot
  • Click End Explorer Shell while Killing File
  • Click All Files right of the flashing green "Single files"
  • Click Yes when it asks "Files will be Removed on Reboot, Do you want to reboot now?"
(Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X ...and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.

Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free...mitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

Posted Image

______________________________

Please download the trial version of AVG anti-spyware 7.5from here:
http://www.ewido.net/en/download/
  • Install AVG anti-spyware anti-malware.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu.
  • When you run AVG anti-spyware for the first time, you could get a warning "Database could not be found!". Click Ok.
  • The program will prompt you to update. Click the Ok button.
  • The program will now go to the main screen.
You will need to update AVG anti-spyware to the latest definition files.
  • On the left-hand side of the main screen click the Update Button.
  • Click on Start.
The update will start and a progress bar will show the updates being installed.
Once finished updating, close AVG.

If you are having problems with the updater, you can use this link to manually update ewido.
AVG anti-spyware manual updates. Make sure to close AVG anti-spyware before installing the update.
______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter

Posted Image

This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.


IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

Please post:
C:\rapport.txt
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

#8 Kdung

Kdung

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 06 June 2007 - 12:50 AM

SmitFraudFix v2.192 Scan done at 20:46:41.48, Tue 06/05/2007 Run from C:\Documents and Settings\Local Settings\Temp\SmitfraudFix-1\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\AGRSMMSG.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe C:\Program Files\Ares\Ares.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Plustek\OpticFilm 7200\QuickScan.exe C:\Program Files\sony\usbsircs\usbsircs.exe C:\Program Files\Sony\Giga Pocket\ReserveModule.exe C:\Program Files\Sony\Giga Pocket\gps.exe C:\Program Files\Sony\Giga Pocket\shwserv.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Sony\Giga Pocket\RM_SV.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Application Data C:\Documents and Settings\Application Data\Skinux FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\KRISTO~1\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{25b7d2fd-4f71-46d1-801a-7de323e4ec82}"="equiparant" [HKEY_CLASSES_ROOT\CLSID\{25b7d2fd-4f71-46d1-801a-7de323e4ec82}\InProcServer32] @="C:\WINDOWS\system32\indwvm.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{25b7d2fd-4f71-46d1-801a-7de323e4ec82}\InProcServer32] @="C:\WINDOWS\system32\indwvm.dll" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Intel® PRO/100 VE Network Connection - Packet Scheduler Miniport DNS Server Search Order: 72.235.80.12 DNS Server Search Order: 72.235.80.4 HKLM\SYSTEM\CCS\Services\Tcpip\..\{A4262F63-E660-42C4-A402-5A1A4E2C21F3}: DhcpNameServer=72.235.80.12 72.235.80.4 HKLM\SYSTEM\CS1\Services\Tcpip\..\{A4262F63-E660-42C4-A402-5A1A4E2C21F3}: DhcpNameServer=72.235.80.12 72.235.80.4 HKLM\SYSTEM\CS2\Services\Tcpip\..\{A4262F63-E660-42C4-A402-5A1A4E2C21F3}: DhcpNameServer=72.235.80.12 72.235.80.4 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=72.235.80.12 72.235.80.4 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=72.235.80.12 72.235.80.4 HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=72.235.80.12 72.235.80.4 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End I think i did this right... Thanks again...

#9 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 06 June 2007 - 05:37 AM

Clean

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

Posted Image


The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG Anti-spyware, and run a full scan.
  • Click on Scanner
  • Click on Settings
    • Under How to scan all boxes should be checked
    • Under Unwanted Software all boxes should be checked
    • Under What to scan select Scan every file
    • Click on Ok
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
If AVG Anti-spyware finds anything, it will pop up a notification. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says Perform action on all infections and put a checkmark in the box next to Create encrypted backup, then choose clean and click Ok.

Once the scan has completed, there will be a button located on the bottom of the screen named Save Report.
  • Click Save Report button
  • Save the report to your Desktop
Close AVG Anti-spyware and Reboot in Normal Mode.


Please post:
  • c:\rapport.txt
  • AVG Anti-spyware log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

#10 Kdung

Kdung

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 07 June 2007 - 03:35 AM

Rapport.txt SmitFraudFix v2.192 Scan done at 16:41:17.28, Wed 06/06/2007 Run from C:\Documents and Settings\Kristopher Dung\Desktop\Comp Fix\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{25b7d2fd-4f71-46d1-801a-7de323e4ec82}"="equiparant" [HKEY_CLASSES_ROOT\CLSID\{25b7d2fd-4f71-46d1-801a-7de323e4ec82}\InProcServer32] @="C:\WINDOWS\system32\indwvm.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{25b7d2fd-4f71-46d1-801a-7de323e4ec82}\InProcServer32] @="C:\WINDOWS\system32\indwvm.dll" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\Documents and Settings\Kristopher Dung\Application Data\Skinux\ Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{A4262F63-E660-42C4-A402-5A1A4E2C21F3}: DhcpNameServer=72.235.80.12 72.235.80.4 HKLM\SYSTEM\CS1\Services\Tcpip\..\{A4262F63-E660-42C4-A402-5A1A4E2C21F3}: DhcpNameServer=72.235.80.12 72.235.80.4 HKLM\SYSTEM\CS2\Services\Tcpip\..\{A4262F63-E660-42C4-A402-5A1A4E2C21F3}: DhcpNameServer=72.235.80.12 72.235.80.4 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=72.235.80.12 72.235.80.4 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=72.235.80.12 72.235.80.4 HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=72.235.80.12 72.235.80.4 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End

    Advertisements

Register to Remove


#11 Kdung

Kdung

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 07 June 2007 - 03:38 AM

--------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 5:42:07 PM 6/6/2007 + Scan result: C:\!KillBox\gorPUS.exe -> Adware.Agent : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0169949.dll -> Adware.Agent : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0171399.dll -> Adware.Agent : Ignored. C:\!KillBox\NNSCAA638.EXE -> Adware.NewDotNet : Ignored. C:\QooBox\Quarantine\C\WINDOWS\NDNuninstall6_38.exe.vir -> Adware.NewDotNet : Ignored. C:\QooBox\Quarantine\C\WINDOWS\NDNuninstall7_22.exe.vir -> Adware.NewDotNet : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176751.exe -> Adware.NewDotNet : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176752.exe -> Adware.NewDotNet : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176872.EXE -> Adware.NewDotNet : Ignored. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Ignored. HKU\.DEFAULT\Software\New.net -> Adware.NewDotNet : Ignored. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Ignored. HKU\S-1-5-18\Software\New.net -> Adware.NewDotNet : Ignored. C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007 -> Adware.RogueSuspect : Ignored. C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data -> Adware.RogueSuspect : Ignored. C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr -> Adware.RogueSuspect : Ignored. C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode -> Adware.RogueSuspect : Ignored. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} -> Adware.RogueSuspect : Ignored. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\DC6_Check -> Adware.RogueSuspect : Ignored. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ERS_Check -> Adware.RogueSuspect : Ignored. HKU\S-1-5-21-629695564-1532225126-2096284979-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} -> Adware.RogueSuspect : Ignored. C:\Deckard\System Scanner\backup\WINDOWS\temp\daCF.tmp -> Adware.SurfSide : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176642.exe -> Adware.SystemDoctor : Ignored. C:\!KillBox\Monopoly3Setup-dm[1].exe -> Adware.Trymedia : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176870.exe -> Adware.Trymedia : Ignored. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176692.exe -> Adware.WinFixer : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176693.exe -> Adware.WinFixer : Ignored. C:\!KillBox\cntdrv.pif -> Downloader.Adload.bm : Ignored. C:\!KillBox\contacts.pif -> Downloader.Adload.bm : Ignored. C:\!KillBox\windll.pif -> Downloader.Adload.bm : Ignored. C:\!KillBox\windowsdll.pif -> Downloader.Adload.bm : Ignored. C:\!KillBox\winntdll.pif -> Downloader.Adload.bm : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176866.pif -> Downloader.Adload.bm : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176867.pif -> Downloader.Adload.bm : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176875.pif -> Downloader.Adload.bm : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176881.pif -> Downloader.Adload.bm : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176882.pif -> Downloader.Adload.bm : Ignored. C:\!KillBox\booterror.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\bootfix.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\bootfixor.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\boothelp.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\bootload.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\dirfix.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\dirfixer.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\fixboot.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176861.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176862.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176863.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176864.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176865.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176868.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176869.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176871.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\remove.exe -> Downloader.Keenval.f : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176876.exe -> Downloader.Keenval.f : Ignored. C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\YazzleBundle-1281.exe -> Downloader.PurityScan.eg : Ignored. C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\yazzlesnet.exe -> Downloader.PurityScan.eg : Ignored. C:\Documents and Settings\Desktop\Comp Fix\aimfix_quarantine\10102_ac2_0003.exe.bak -> Downloader.Small.cpu : Ignored. C:\WINDOWS\system32\T9QaSQ\T9QaSQ1099.exe -> Downloader.VB.awj : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0169948.exe -> Downloader.Zlob.bgs : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0171400.exe -> Downloader.Zlob.bgs : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0169942.exe -> Downloader.Zlob.btq : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0169951.exe -> Downloader.Zlob.btq : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0169953.exe -> Downloader.Zlob.btq : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0171384.exe -> Downloader.Zlob.btq : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0171398.exe -> Downloader.Zlob.btq : Ignored. C:\QooBox\Quarantine\C\WINDOWS\wallpap.exe.vir -> Hijacker.Agent.gp : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176755.exe -> Hijacker.Agent.gp : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176685.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored. C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\WinAntiVirusPro2007FreeInstall.exe -> Not-A-Virus.Downloader.Win32.WinFixer.u : Ignored. :mozilla.52:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.53:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.162:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.45:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.46:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.47:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.51:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.74:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Atdmt : Ignored. :mozilla.75:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.76:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.77:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.78:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.79:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.56:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Doubleclick : Ignored. :mozilla.93:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored. :mozilla.95:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Netflame : Ignored. :mozilla.88:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Pointroll : Ignored. :mozilla.89:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Pointroll : Ignored. :mozilla.90:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Pointroll : Ignored. :mozilla.91:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Pointroll : Ignored. :mozilla.159:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Realmedia : Ignored. :mozilla.160:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Realmedia : Ignored. :mozilla.161:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Realmedia : Ignored. :mozilla.100:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.101:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.102:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.103:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.104:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.105:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.96:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.97:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.44:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.49:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Revsci : Ignored. C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\Cookies@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Ignored. :mozilla.150:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.151:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.152:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.153:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.57:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.58:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.59:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.60:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.69:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.70:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.72:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.73:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.126:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored. :mozilla.127:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored. :mozilla.128:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored. :mozilla.143:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Zedo : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176684.exe -> Trojan.Fakealert.fb : Ignored. C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\laf41B.tmp -> Trojan.Renos.nbc : Ignored. C:\!KillBox\oleext.dll -> Trojan.Small.ev : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176879.dll -> Trojan.Small.ev : Ignored. ::Report end

#12 Kdung

Kdung

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 07 June 2007 - 03:40 AM

--------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 5:42:07 PM 6/6/2007 + Scan result: C:\!KillBox\gorPUS.exe -> Adware.Agent : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0169949.dll -> Adware.Agent : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0171399.dll -> Adware.Agent : Ignored. C:\!KillBox\NNSCAA638.EXE -> Adware.NewDotNet : Ignored. C:\QooBox\Quarantine\C\WINDOWS\NDNuninstall6_38.exe.vir -> Adware.NewDotNet : Ignored. C:\QooBox\Quarantine\C\WINDOWS\NDNuninstall7_22.exe.vir -> Adware.NewDotNet : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176751.exe -> Adware.NewDotNet : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176752.exe -> Adware.NewDotNet : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176872.EXE -> Adware.NewDotNet : Ignored. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Ignored. HKU\.DEFAULT\Software\New.net -> Adware.NewDotNet : Ignored. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Ignored. HKU\S-1-5-18\Software\New.net -> Adware.NewDotNet : Ignored. C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007 -> Adware.RogueSuspect : Ignored. C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data -> Adware.RogueSuspect : Ignored. C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr -> Adware.RogueSuspect : Ignored. C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode -> Adware.RogueSuspect : Ignored. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} -> Adware.RogueSuspect : Ignored. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\DC6_Check -> Adware.RogueSuspect : Ignored. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ERS_Check -> Adware.RogueSuspect : Ignored. HKU\S-1-5-21-629695564-1532225126-2096284979-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} -> Adware.RogueSuspect : Ignored. C:\Deckard\System Scanner\backup\WINDOWS\temp\daCF.tmp -> Adware.SurfSide : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176642.exe -> Adware.SystemDoctor : Ignored. C:\!KillBox\Monopoly3Setup-dm[1].exe -> Adware.Trymedia : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176870.exe -> Adware.Trymedia : Ignored. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176692.exe -> Adware.WinFixer : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176693.exe -> Adware.WinFixer : Ignored. C:\!KillBox\cntdrv.pif -> Downloader.Adload.bm : Ignored. C:\!KillBox\contacts.pif -> Downloader.Adload.bm : Ignored. C:\!KillBox\windll.pif -> Downloader.Adload.bm : Ignored. C:\!KillBox\windowsdll.pif -> Downloader.Adload.bm : Ignored. C:\!KillBox\winntdll.pif -> Downloader.Adload.bm : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176866.pif -> Downloader.Adload.bm : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176867.pif -> Downloader.Adload.bm : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176875.pif -> Downloader.Adload.bm : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176881.pif -> Downloader.Adload.bm : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176882.pif -> Downloader.Adload.bm : Ignored. C:\!KillBox\booterror.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\bootfix.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\bootfixor.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\boothelp.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\bootload.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\dirfix.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\dirfixer.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\fixboot.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176861.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176862.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176863.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176864.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176865.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176868.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176869.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176871.pif -> Downloader.Adload.bo : Marked for delete on rebootUnkown Error C:\!KillBox\remove.exe -> Downloader.Keenval.f : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176876.exe -> Downloader.Keenval.f : Ignored. C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\YazzleBundle-1281.exe -> Downloader.PurityScan.eg : Ignored. C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\yazzlesnet.exe -> Downloader.PurityScan.eg : Ignored. C:\Documents and Settings\Desktop\Comp Fix\aimfix_quarantine\10102_ac2_0003.exe.bak -> Downloader.Small.cpu : Ignored. C:\WINDOWS\system32\T9QaSQ\T9QaSQ1099.exe -> Downloader.VB.awj : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0169948.exe -> Downloader.Zlob.bgs : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0171400.exe -> Downloader.Zlob.bgs : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0169942.exe -> Downloader.Zlob.btq : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0169951.exe -> Downloader.Zlob.btq : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0169953.exe -> Downloader.Zlob.btq : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0171384.exe -> Downloader.Zlob.btq : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP656\A0171398.exe -> Downloader.Zlob.btq : Ignored. C:\QooBox\Quarantine\C\WINDOWS\wallpap.exe.vir -> Hijacker.Agent.gp : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176755.exe -> Hijacker.Agent.gp : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176685.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored. C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\WinAntiVirusPro2007FreeInstall.exe -> Not-A-Virus.Downloader.Win32.WinFixer.u : Ignored. :mozilla.52:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.53:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.162:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.45:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.46:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.47:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.51:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.74:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Atdmt : Ignored. :mozilla.75:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.76:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.77:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.78:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.79:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.56:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Doubleclick : Ignored. :mozilla.93:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored. :mozilla.95:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Netflame : Ignored. :mozilla.88:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Pointroll : Ignored. :mozilla.89:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Pointroll : Ignored. :mozilla.90:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Pointroll : Ignored. :mozilla.91:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Pointroll : Ignored. :mozilla.159:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Realmedia : Ignored. :mozilla.160:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Realmedia : Ignored. :mozilla.161:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Realmedia : Ignored. :mozilla.100:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.101:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.102:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.103:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.104:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.105:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.96:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.97:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Reliablestats : Ignored. :mozilla.44:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.49:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Revsci : Ignored. C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\Cookies@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Ignored. :mozilla.150:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.151:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.152:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.153:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.57:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.58:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.59:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.60:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.69:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.70:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.72:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.73:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored. :mozilla.126:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored. :mozilla.127:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored. :mozilla.128:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored. :mozilla.143:C:\Documents and Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt -> TrackingCookie.Zedo : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP657\A0176684.exe -> Trojan.Fakealert.fb : Ignored. C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\laf41B.tmp -> Trojan.Renos.nbc : Ignored. C:\!KillBox\oleext.dll -> Trojan.Small.ev : Ignored. C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP658\A0176879.dll -> Trojan.Small.ev : Ignored. ::Report end

#13 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 07 June 2007 - 10:16 PM

It appears that everything was "Ignored?" in the AVG scan.

Let's run a Panda scan. This scan works with Internet Explorer.

STEP 1.
======
Panda Active Scan
Please go to Panda ActiveScan.
Once you are on the Panda site click the Scan your PC button
A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on Local Disks to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log, by using Add Reply.
Let us know if any problems persist.
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

#14 Kdung

Kdung

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 08 June 2007 - 04:36 AM

heres the latest scan... Incident Status Location Adware:Adware/DollarRevenue Not disinfected C:\!KillBox\cntdrv.pif Adware:Adware/DollarRevenue Not disinfected C:\!KillBox\contacts.pif Virus:Trj/Downloader.MDW Disinfected C:\!KillBox\esba-4.exe Adware:Adware/WebBuying Not disinfected C:\!KillBox\gorPUS.exe[lb2.exe] Adware:Adware/TTC Not disinfected C:\!KillBox\gorPUS.exe[lib67.exe] Adware:Adware/DeluxeComunications Not disinfected C:\!KillBox\gorPUS.exe[lb5.exe] Virus:Trj/Downloader.OJF Not disinfected C:\!KillBox\gorPUS.exe[lib06.exe] Adware:Adware/Trymedia Not disinfected C:\!KillBox\Monopoly3Setup-dm[1].exe Spyware:Spyware/New.net Not disinfected C:\!KillBox\NNSCAA638.EXE Virus:Trj/Downloader.MDW Disinfected C:\!KillBox\oleext.dll Adware:Adware/KeenValue Not disinfected C:\!KillBox\remove.exe Adware:Adware/DollarRevenue Not disinfected C:\!KillBox\warranty.pif Adware:Adware/DollarRevenue Not disinfected C:\!KillBox\windll.pif Adware:Adware/DollarRevenue Not disinfected C:\!KillBox\windows.pif Adware:Adware/DollarRevenue Not disinfected C:\!KillBox\windowsdll.pif Adware:Adware/DollarRevenue Not disinfected C:\!KillBox\winntdll.pif Virus:Trj/Downloader.OBC Disinfected C:\!KillBox\wr-1-0000077.exe Spyware:Cookie/Go Not disinfected C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\Cookies\kristopher dung@go[1].txt Potentially unwanted tool:Application/Processor Not disinfected C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\nsn89.tmp Potentially unwanted tool:Application/Processor Not disinfected C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\nsr8E.tmp Potentially unwanted tool:Application/Processor Not disinfected C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\nsw59.tmp Potentially unwanted tool:Application/WinAntiVirus2007 Not disinfected C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\WinAntiVirusPro2007FreeInstall.exe Adware:Adware/Yazzle Not disinfected C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\YazzleBundle-1281.exe Adware:Adware/Yazzle Not disinfected C:\Deckard\System Scanner\backup\DOCUME~1\KRISTO~1\LOCALS~1\Temp\yazzlesnet.exe Spyware:Spyware/SurfSideKick Not disinfected C:\Deckard\System Scanner\backup\WINDOWS\temp\daCF.tmp Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.atwola.com/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.2o7.net/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.advertising.com/] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.trafficmp.com/] Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.atdmt.com/] Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.casalemedia.com/] Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.ads.pointroll.com/] Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[stats1.reliablestats.com/] Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.winantivirus.com/] Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[stats1.reliablestats.com/] Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.errorsafe.com/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[ad.yieldmanager.com/] Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.go.com/] Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.zedo.com/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.realmedia.com/] Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\cookies.txt[.adrevolver.com/] Adware:adware/tvmedia Not disinfected C:\Documents and Settings\Kristopher Dung\Application Data\tvmcwrd.dll Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Kristopher Dung\Cookies\kristopher dung@ad.yieldmanager[2].txt Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Kristopher Dung\Cookies\kristopher dung@ads.pointroll[2].txt Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Kristopher Dung\Cookies\kristopher dung@adultfriendfinder[2].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Kristopher Dung\Cookies\kristopher dung@advertising[2].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Kristopher Dung\Cookies\kristopher dung@atdmt[2].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Kristopher Dung\Cookies\kristopher dung@bs.serving-sys[2].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Kristopher Dung\Cookies\kristopher dung@doubleclick[1].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Kristopher Dung\Cookies\kristopher dung@fastclick[1].txt Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Kristopher Dung\Cookies\kristopher dung@mediaplex[1].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Kristopher Dung\Cookies\kristopher dung@questionmarket[2].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Kristopher Dung\Cookies\kristopher dung@realmedia[2].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Kristopher Dung\Cookies\kristopher dung@serving-sys[2].txt Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Kristopher Dung\Cookies\kristopher dung@statcounter[1].txt Virus:Trj/Downloader.ILI Disinfected C:\Documents and Settings\Kristopher Dung\Desktop\Comp Fix\aimfix_quarantine\10102_ac2_0003.exe.bak Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Kristopher Dung\Desktop\Comp Fix\ComboFix.exe[ComboFixT\nircmd.exe] Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Kristopher Dung\Desktop\Comp Fix\SmitfraudFix\SmitfraudFix\Process.exe Virus:Trj/Shutdown.Z Disinfected C:\Documents and Settings\Kristopher Dung\Desktop\Comp Fix\SmitfraudFix\SmitfraudFix\restart.exe Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Kristopher Dung\Desktop\Comp Fix\SmitfraudFix.zip[SmitfraudFix/Process.exe] Virus:Trj/Shutdown.Z Disinfected C:\Documents and Settings\Kristopher Dung\Desktop\Comp Fix\SmitfraudFix.zip[SmitfraudFix/restart.exe] Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Kristopher Dung\Desktop\Comp Fix\VundoFix\VundoFix\process.exe Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Kristopher Dung\Local Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\Cache\633285D9d01[SmitfraudFix/Process.exe] Virus:Trj/Shutdown.Z Disinfected C:\Documents and Settings\Kristopher Dung\Local Settings\Application Data\Mozilla\Firefox\Profiles\f7b2dqkv.default\Cache\633285D9d01[SmitfraudFix/restart.exe] Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Kristopher Dung\Local Settings\Temp\SmitfraudFix\SmitfraudFix\Process.exe Virus:Trj/Shutdown.Z Disinfected C:\Documents and Settings\Kristopher Dung\Local Settings\Temp\SmitfraudFix\SmitfraudFix\restart.exe Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Kristopher Dung\Local Settings\Temp\SmitfraudFix-1\SmitfraudFix\Process.exe Virus:Trj/Shutdown.Z Disinfected C:\Documents and Settings\Kristopher Dung\Local Settings\Temp\SmitfraudFix-1\SmitfraudFix\restart.exe Virus:Trj/PiratHack Disinfected C:\Documents and Settings\Kristopher Dung\Norton Anti-virus 2005 +keygen\TMG-Norton Antivirus 2005 Keygen.exe Spyware:Spyware/New.net Not disinfected C:\QooBox\Quarantine\C\WINDOWS\NDNuninstall6_38.exe.vir Spyware:Spyware/New.net Not disinfected C:\QooBox\Quarantine\C\WINDOWS\NDNuninstall7_22.exe.vir Virus:Trj/Downloader.ORT Disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\gibmiryu.dll.vir Virus:Trj/Downloader.ORT Disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\jxumebwn.dll.vir Adware:Adware/Deskwizz Not disinfected C:\QooBox\Quarantine\C\WINDOWS\wallpap.exe.vir Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\adsjebxv.dll.bad Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\ibxcsjxm.dll.bad Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe Potentially unwanted tool:application/altnet Not disinfected C:\WINDOWS\smdat32a.sys Potentially unwanted tool:application/bestoffer Not disinfected C:\WINDOWS\smdat32m.sys Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe

#15 Kdung

Kdung

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 08 June 2007 - 04:40 AM

new hijack this log

Logfile of HijackThis v1.99.1
Scan saved at 12:38:21 AM, on 6/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Ares\Ares.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plustek\OpticFilm 7200\QuickScan.exe
C:\Program Files\sony\usbsircs\usbsircs.exe
C:\Program Files\Sony\Giga Pocket\ReserveModule.exe
C:\Program Files\Sony\Giga Pocket\gps.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Sony\Giga Pocket\shwserv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sony\Giga Pocket\RM_SV.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Desktop\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://netmail.verizon.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {045CA052-C7C7-4745-BF9E-F6E284866E36} - C:\WINDOWS\system32\jompsujl.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)
O2 - BHO: (no name) - {F634C213-2C16-4845-9D3D-1E5FFFA34494} - C:\WINDOWS\system32\vtsqr.dll (file missing)
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IS CfgWiz] "C:\Documents and Settings\Norton Internet Security 2005 Retail\nav\external\norton\cfgwiz.exe" /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] "C:\Documents and Settings\Norton Internet Security 2005 Retail\setup\pcontrol\app\urllstck.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [DC6_Check] "C:\Program Files\Common Files\WinAntiSpyware 2007\uwasdc.exe"
O4 - HKLM\..\Run: [ERS_Check] "C:\Program Files\Common Files\WinAntiSpyware 2007\uwasers.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickScan (OpticFilm 7200).lnk = C:\Program Files\Plustek\OpticFilm 7200\QuickScan.exe
O4 - Global Startup: Remocon Driver.lnk = ?
O4 - Global Startup: Timer Recording Manager.lnk = C:\Program Files\Sony\Giga Pocket\ReserveModule.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by120fd.bay12...es/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O20 - Winlogon Notify: wvutqon - wvutqon.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Giga Pocket Hardware Detector - Sony Corporation - C:\Program Files\Sony\Giga Pocket\shwserv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users