This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Computer Slow And Annoying Popups

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I'm wondering if someone can help me get rid of my annoying popups and computer freezes. Thanks in advance.
Hi! Welcome to the Tom Coyote forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Click here to download HJTsetup.exe
  • Save HJTsetup.exe to your desktop.
  • Double click on the HJTsetup.exe icon on your desktop.
  • By default it will install to C:\Program Files\Hijack This.
  • Continue to click Next in the setup dialogue boxes until you get to the Select Additional Tasks dialogue.
  • Put a check by Create a desktop icon then click Next again.
  • Continue to follow the rest of the prompts from there.
  • At the final dialogue box click Finish and it will launch Hijack This.
  • Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
  • Click Save to save the log file and then the log will open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
Here ya go:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:33:21 AM, on 8/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Keymaestro\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\CFusionMX7\runtime\bin\jrunsvc.exe
C:\CFusionMX7\runtime\bin\jrun.exe
C:\CFusionMX7\db\slserver54\bin\swagent.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\CFusionMX7\db\slserver54\bin\swstrtr.exe
C:\CFusionMX7\db\slserver54\bin\swsoc.exe
C:\CFusionMX7\verity\k2\_nti40\bin\k2admin.exe
C:\Program Files\Borland\InterBase\bin\ibguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\CFusionMX7\verity\k2\_nti40\bin\k2server.exe
C:\CFusionMX7\verity\k2\_nti40\bin\k2index.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Borland\InterBase\bin\ibserver.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Keymaestro\Multimedia Keyboard\MMKeybd.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\AOL\1136443953\ee\AOLSoftware.exe
C:\Program Files\Keymaestro\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Keymaestro\Onscreen Display\OSD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe
c:\program files\common files\aol\1136443953\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1136443953\ee\aolsoftware.exe
C:\Program Files\ArcSoft\TotalMedia\TM Monitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\America Online 9.0\shellmon.exe
C:\WINDOWS\system32\eewkkbfx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=552…cid={SUB_CLCID}
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Keymaestro\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1136443953\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB003" /M "Stylus CX3800"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [4flagvgainside] C:\Documents and Settings\All Users\Application Data\bait dart 4 flag\Magsfile.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\rfpafppa.dll",forkonce
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [phone seek] C:\DOCUME~1\LAURAS~1\APPLIC~1\PROCBU~1\warn love else.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Amazon Unbox.lnk = ?
O4 - Global Startup: TM Monitor.lnk = C:\Program Files\ArcSoft\TotalMedia\TM Monitor.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1094035800062
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143045110723
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {A7ECD556-D6F6-4F41-8C6B-14AB246801A0} (Secure Delivery) - http://cdn.digitalcity.com/video/kdx.cab
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Amazon Unbox Video Service (ADVService) - Amazon.com - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ColdFusion MX 7 Application Server - Macromedia Inc. - C:\CFusionMX7\runtime\bin\jrunsvc.exe
O23 - Service: ColdFusion MX 7 ODBC Agent - Unknown owner - C:\CFusionMX7\db\slserver54\bin\swagent.exe
O23 - Service: ColdFusion MX 7 ODBC Server - Unknown owner - C:\CFusionMX7\db\slserver54\bin\swstrtr.exe
O23 - Service: ColdFusion MX 7 Search Server - Verity, Inc. - C:\CFusionMX7\verity\k2\_nti40\bin\k2admin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation - C:\Program Files\Borland\InterBase\bin\ibguard.exe
O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation - C:\Program Files\Borland\InterBase\bin\ibserver.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Keymaestro\Multimedia Keyboard\nhksrv.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 11813 bytes
Hi Laurasix

Sorry to be a pain but

Rename HijackThis
There is probably an infection which is hiding part of the HijackThis log because it's called hijackthis.exe.
Please rename hijackthis.exe to hello.exe

Now scan again and post a new log, please.
Hi laurasix It will be in the Program Files folder. Enter the Trend Micro folder in there, then the HijackThis folder in that and rename the exe file.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:02:59 PM, on 8/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Keymaestro\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\CFusionMX7\runtime\bin\jrunsvc.exe
C:\CFusionMX7\runtime\bin\jrun.exe
C:\CFusionMX7\db\slserver54\bin\swagent.exe
C:\CFusionMX7\db\slserver54\bin\swstrtr.exe
C:\CFusionMX7\db\slserver54\bin\swsoc.exe
C:\CFusionMX7\verity\k2\_nti40\bin\k2admin.exe
C:\Program Files\Borland\InterBase\bin\ibguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\CFusionMX7\verity\k2\_nti40\bin\k2server.exe
C:\CFusionMX7\verity\k2\_nti40\bin\k2index.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Borland\InterBase\bin\ibserver.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Keymaestro\Multimedia Keyboard\MMKeybd.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\Keymaestro\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\AOL\1136443953\ee\AOLSoftware.exe
C:\Program Files\Keymaestro\Onscreen Display\OSD.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\America Online 9.0\waol.exe
c:\program files\common files\aol\1136443953\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1136443953\ee\aolsoftware.exe
C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe
C:\Program Files\ArcSoft\TotalMedia\TM Monitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\iqyieoan.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Trend Micro\HijackThis\hello.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=552…cid={SUB_CLCID}
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {40270CA7-0C42-4664-84E7-A689234CF369} - C:\WINDOWS\system32\gebca.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O2 - BHO: (no name) - {8EE6BFDE-9534-4F38-98AD-B0B8D48A1990} - (no file)
O2 - BHO: (no name) - {A6807262-1D7A-44AB-947B-23B71E97915C} - C:\WINDOWS\system32\fccdayx.dll
O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\bqwvmstg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Keymaestro\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1136443953\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB003" /M "Stylus CX3800"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [4flagvgainside] C:\Documents and Settings\All Users\Application Data\bait dart 4 flag\Magsfile.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\rfpafppa.dll",forkonce
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [phone seek] C:\DOCUME~1\LAURAS~1\APPLIC~1\PROCBU~1\warn love else.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Amazon Unbox.lnk = ?
O4 - Global Startup: TM Monitor.lnk = C:\Program Files\ArcSoft\TotalMedia\TM Monitor.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1094035800062
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143045110723
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {A7ECD556-D6F6-4F41-8C6B-14AB246801A0} (Secure Delivery) - http://cdn.digitalcity.com/video/kdx.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: fccdayx - C:\WINDOWS\SYSTEM32\fccdayx.dll
O20 - Winlogon Notify: gebca - C:\WINDOWS\system32\gebca.dll
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Amazon Unbox Video Service (ADVService) - Amazon.com - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ColdFusion MX 7 Application Server - Macromedia Inc. - C:\CFusionMX7\runtime\bin\jrunsvc.exe
O23 - Service: ColdFusion MX 7 ODBC Agent - Unknown owner - C:\CFusionMX7\db\slserver54\bin\swagent.exe
O23 - Service: ColdFusion MX 7 ODBC Server - Unknown owner - C:\CFusionMX7\db\slserver54\bin\swstrtr.exe
O23 - Service: ColdFusion MX 7 Search Server - Verity, Inc. - C:\CFusionMX7\verity\k2\_nti40\bin\k2admin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation - C:\Program Files\Borland\InterBase\bin\ibguard.exe
O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation - C:\Program Files\Borland\InterBase\bin\ibserver.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Keymaestro\Multimedia Keyboard\nhksrv.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 12361 bytes
UNINSTALL LIST µTorrent Adobe Flash Player 9 ActiveX Adobe Photoshop 7.0 Adobe Reader 6.0 Amazon Unbox Video AOL Coach Version 2.0(Build:20041026.5 en) AOL Deskbar AOL Hi-Q Video AOL Instant Messenger AOL Toolbar 2.0 AOL Uninstaller (Choose which Products to Remove) AOL You've Got Pictures Screensaver Apple Software Update ArcSoft ShowBiz DVD 2 ArcSoft TotalMedia AT&T Unified Messaging AT&T Yahoo! Applications avast! Antivirus A-Z Video Converter Ultimate 7.35 Business Card Factory Deluxe 2.0 CCleaner (remove only) DivX DivX Converter DivX Player DivX Web Player DVD X Rescue DVDXCopy Platinum 4.0.3 EPSON CardMonitor EPSON PhotoStarter3.0 EPSON Print CD EPSON Printer Software ESSAdpt ESSANUP ESSCAM ESSCDBK ESScore ESSgui ESShelp ESSini ESSPCD ESSSONIC ESSvpaht ESSvpot FileZilla (remove only) Film Factory Flock (Photobucket Edition) 0.7 Google Earth Google Toolbar for Firefox Google Toolbar for Internet Explorer HighMAT Extension to Microsoft Windows XP CD Writing Wizard HijackThis 2.0.2 HLPIndex HLPRFO Hotfix for Windows Media Format SDK (KB902344) Hotfix for Windows Media Format SDK (KB910998) Hotfix for Windows XP (KB896344) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Intel® Graphics Media Accelerator Driver InterBase iPod for Windows 2005-09-23 iTunes J2SE Runtime Environment 5.0 Update 11 J2SE Runtime Environment 5.0 Update 6 J2SE Runtime Environment 5.0 Update 8 Java Media Framework 2.1.1c Java™ 6 Update 2 Keymaestro Office Keyboard Kodak EasyShare software LimeWire 4.12.11 Macromedia ColdFusion MX 7 Macromedia Dreamweaver 8 Macromedia Extension Manager Macromedia Flash 8 Macromedia Flash 8 Video Encoder Macromedia Flash Player 8 Macromedia Flash Player 8 Plugin Macromedia FlashPaper 2 Macromedia Shockwave Player Magic DVD Ripper V3.6 Magic ISO Maker v5.3 (build 0221) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office XP Professional with FrontPage Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (1.5) MSN Music Assistant MSXML 4.0 SP2 (KB927978) Nero Media Player Nero OEM NeroVision Express 2 NetObjects Fusion 8 Nimo Codecs Pack v5.0 (Remove Only) Notifier OneStep Accounting Professional Edition Version 4.0 OTtBP OTtBPSDK P.I.M. II Plug-In PCDADDIN PCDHELP PCDLNCH Pdf995 PdfEdit995 PhotoSite AlbumBuilder Plaxo Toolbar for Outlook and Outlook Express Pure Networks Port Magic QuickBooks Premier 2002: Accountant Edition QuickTime RealPlayer Realtek AC'97 Audio SBC Self Support Tool Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 2.0 (KB928365) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893066) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) SereneScreen Marine Aquarium Fry's Demo SFR SFR2 Spy Sweeper SUPERAntiSpyware Free Edition TaxCut Premium 2006 Ulead PhotoImpact 8 SE Ulead VideoStudio 7 SE DVD Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB900930) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB912945) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB936357) Viewpoint Manager (Remove Only) Viewpoint Media Player VPRINTOL Wal-Mart Music Downloads Store Win AVI HelixSDK WinAVI Video Converter WinAVIVideoConverter Windows Genuine Advantage v1.3.0254.0 Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Connect Windows Media Encoder 9 Series Windows Media Encoder 9 Series Windows Media Format Runtime Windows Media Format SDK Hotfix - KB891122 Windows Media Player 10 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB887797 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 WinRAR archiver WinZip WordPerfect Office 12
Hello

Step 1:
Download AVG Anti-Spyware.
  • Install AVG Anti-Spyware.
  • Launch AVG by double-clicking on the icon.
  • The program will now open to the main screen.
  • You will need to update AVG to the latest definition files.
  • At the top of the main screen click Update.
  • Then in the Manual Update section, click on Start Update.
[*]The update will start and a progress bar will show the updates being installed.

[*]When updates are completed, close AVG.

If you are having problems with the updater, you can use this link to manually update AVG.
AVG manual updates

Step 2
Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it.

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.
(If you dont have Opera or Firefox, those options will be greyed out)

Step 3:
Download and Run ComboFix
  • Download this file from below:

    Here
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Step 4:
Run a scan with AVG.
  • Click on Scanner
    • Click on the Settings tab, and set the following settings.
      • How to act
      • Click on Recommended actions, and set to Quarantine.
    • How to scan
      • Check all options.
    • Possibly unwanted software.
      • Check all options.
    • Reports
      • Check Do not automatically generate reports after every scan.
    • What to scan
      • Check Scan every file.
  • Click on the Scan tab.
    • Click on Complete System Scan and the scan will begin.
    • When the scan has finished
    • Make sure that Set all elements to: shows Quarantine, if not click on the link and choose Quarantine from the popup menu.
    • At the bottom of the window click on the Apply all Actions button.
Note: Don't save the report before you hit the Apply action button.

Close AVG Anti-Spyware.

AVG will save a report in the following location C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports

Step 5:
Run another scan with HijackThis and post the new log in your next reply.

Step 6
In your next reply, please post
  • AVG Report
  • Combofix Log
  • HijackThis log
COMBOFIX LOG

ComboFix 07-07-30.2 - "Laura Sixtos" 2007-08-02 14:18:00.1 [GMT -7:00] - NTFS
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.True
* Created a new restore point


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\acsiqsfs.dll
C:\WINDOWS\system32\ajpxyxqy.dll
C:\WINDOWS\system32\avtjopaa.dll
C:\WINDOWS\system32\bgfkltxj.dll
C:\WINDOWS\system32\bivwcuhc.dll
C:\WINDOWS\system32\bqwvmstg.dll
C:\WINDOWS\system32\bxmvggut.dll
C:\WINDOWS\system32\chonufco.dll
C:\WINDOWS\system32\cmluoeec.dll
C:\WINDOWS\system32\ekeaafih.dll
C:\WINDOWS\system32\eojosftl.dll
C:\WINDOWS\system32\eqpvciht.dll
C:\WINDOWS\system32\ermsyccp.dll
C:\WINDOWS\system32\fvllnrde.dll
C:\WINDOWS\system32\gcofglbi.dll
C:\WINDOWS\system32\ghsqyovq.dll
C:\WINDOWS\system32\gtmfkfhn.dll
C:\WINDOWS\system32\gypujtne.dll
C:\WINDOWS\system32\htnapewv.dll
C:\WINDOWS\system32\hxipywlf.dll
C:\WINDOWS\system32\iiuwlsik.dll
C:\WINDOWS\system32\jsxuljyt.dll
C:\WINDOWS\system32\jvogeijw.dll
C:\WINDOWS\system32\kffxbpnr.dll
C:\WINDOWS\system32\kpbjivip.dll
C:\WINDOWS\system32\lawcrnfp.dll
C:\WINDOWS\system32\livfutlm.dll
C:\WINDOWS\system32\lkfrkrhh.dll
C:\WINDOWS\system32\nivmmghc.dll
C:\WINDOWS\system32\nolncpcw.dll
C:\WINDOWS\system32\ntshncmh.dll
C:\WINDOWS\system32\nuhdvovj.dll
C:\WINDOWS\system32\nxvaifll.dll
C:\WINDOWS\system32\oefosqwn.dll
C:\WINDOWS\system32\oljfiewj.dll
C:\WINDOWS\system32\owqynikd.dll
C:\WINDOWS\system32\pfwynalf.dll
C:\WINDOWS\system32\ptwfknvb.dll
C:\WINDOWS\system32\pvgnokhf.dll
C:\WINDOWS\system32\qdotsnyk.dll
C:\WINDOWS\system32\qlxlnuww.dll
C:\WINDOWS\system32\qvejhmsd.dll
C:\WINDOWS\system32\rlhahsbb.dll
C:\WINDOWS\system32\savmnibn.dll
C:\WINDOWS\system32\texfoohw.dll
C:\WINDOWS\system32\tmavmdxc.dll
C:\WINDOWS\system32\tqgqbsqh.dll
C:\WINDOWS\system32\tuvvutu.dll
C:\WINDOWS\system32\unccfklk.dll
C:\WINDOWS\system32\vdfnipwj.dll
C:\WINDOWS\system32\vojkkdwd.dll
C:\WINDOWS\system32\vokeflda.dll
C:\WINDOWS\system32\voknxgxf.dll
C:\WINDOWS\system32\vxlcqjbr.dll
C:\WINDOWS\system32\whluifuo.dll
C:\WINDOWS\system32\wionurgu.dll
C:\WINDOWS\system32\xhsllifx.dll
C:\WINDOWS\system32\xquverie.dll
C:\WINDOWS\system32\ylcsthyb.dll
C:\WINDOWS\system32\ysyunujv.dll
C:\WINDOWS\system32\ytbxeryi.dll
C:\WINDOWS\system32\acbmkxel.exe
C:\WINDOWS\system32\apgqhqce.exe
C:\WINDOWS\system32\awfnvrrf.exe
C:\WINDOWS\system32\bereruct.exe
C:\WINDOWS\system32\bpqywugj.exe
C:\WINDOWS\system32\bqakjmwg.exe
C:\WINDOWS\system32\cqccwykk.exe
C:\WINDOWS\system32\dvnujdjj.exe
C:\WINDOWS\system32\eatbddio.exe
C:\WINDOWS\system32\ecnrdcxx.exe
C:\WINDOWS\system32\eewkkbfx.exe
C:\WINDOWS\system32\elimtcjc.exe
C:\WINDOWS\system32\eplervll.exe
C:\WINDOWS\system32\fdabtoda.exe
C:\WINDOWS\system32\fgjyvbmp.exe
C:\WINDOWS\system32\fqwkybxf.exe
C:\WINDOWS\system32\gbpxorum.exe
C:\WINDOWS\system32\gbrtduxm.exe
C:\WINDOWS\system32\glusvtpu.exe
C:\WINDOWS\system32\glyavtjn.exe
C:\WINDOWS\system32\gxjxxrnr.exe
C:\WINDOWS\system32\hauralog.exe
C:\WINDOWS\system32\hdxvfvgp.exe
C:\WINDOWS\system32\hgkmstuo.exe
C:\WINDOWS\system32\hjcqabdu.exe
C:\WINDOWS\system32\hnyjottj.exe
C:\WINDOWS\system32\hqmnugdq.exe
C:\WINDOWS\system32\icuxbflw.exe
C:\WINDOWS\system32\imtoawsu.exe
C:\WINDOWS\system32\ioifuxar.exe
C:\WINDOWS\system32\iosigjoc.exe
C:\WINDOWS\system32\iycdwyao.exe
C:\WINDOWS\system32\jbnubllm.exe
C:\WINDOWS\system32\jimerkmb.exe
C:\WINDOWS\system32\jvtsibcn.exe
C:\WINDOWS\system32\kegmjvri.exe
C:\WINDOWS\system32\keshrdjm.exe
C:\WINDOWS\system32\kgpwenmb.exe
C:\WINDOWS\system32\knkoehey.exe
C:\WINDOWS\system32\ktmomicw.exe
C:\WINDOWS\system32\kulxjqpj.exe
C:\WINDOWS\system32\laxihfna.exe
C:\WINDOWS\system32\lbwytgce.exe
C:\WINDOWS\system32\ldvksqwx.exe
C:\WINDOWS\system32\lfgtnwnr.exe
C:\WINDOWS\system32\ljubhyld.exe
C:\WINDOWS\system32\mcafukbf.exe
C:\WINDOWS\system32\mfiifcyv.exe
C:\WINDOWS\system32\mhmaynri.exe
C:\WINDOWS\system32\nfbmcunk.exe
C:\WINDOWS\system32\nnkqmssi.exe
C:\WINDOWS\system32\nseknelq.exe
C:\WINDOWS\system32\obieuoan.exe
C:\WINDOWS\system32\okbsifou.exe
C:\WINDOWS\system32\olgsnutm.exe
C:\WINDOWS\system32\olumcgjs.exe
C:\WINDOWS\system32\pckmyxik.exe
C:\WINDOWS\system32\pupjmqkl.exe
C:\WINDOWS\system32\pxkmvvxq.exe
C:\WINDOWS\system32\qgrbgdpa.exe
C:\WINDOWS\system32\qobmsvfx.exe
C:\WINDOWS\system32\qyfcqhky.exe
C:\WINDOWS\system32\rpqhhosc.exe
C:\WINDOWS\system32\sahidlgh.exe
C:\WINDOWS\system32\spqgeovj.exe
C:\WINDOWS\system32\sstaorqn.exe
C:\WINDOWS\system32\tfciasoq.exe
C:\WINDOWS\system32\tlriiwcx.exe
C:\WINDOWS\system32\vfaxffil.exe
C:\WINDOWS\system32\vpjcjvmn.exe
C:\WINDOWS\system32\vualgkhr.exe
C:\WINDOWS\system32\vwqljhtm.exe
C:\WINDOWS\system32\wsahorug.exe
C:\WINDOWS\system32\xtjplssj.exe
C:\WINDOWS\system32\xtqirklf.exe
C:\WINDOWS\system32\xvtmotow.exe
C:\WINDOWS\system32\xvyygbkv.exe
C:\WINDOWS\system32\ydwuvtnc.exe
C:\WINDOWS\system32\yknvisfj.exe
C:\WINDOWS\system32\ypyjyaiw.exe
C:\WINDOWS\system32\acsiqsfs.dll
C:\WINDOWS\system32\ajpxyxqy.dll
C:\WINDOWS\system32\bxmvggut.dll
C:\WINDOWS\system32\cmluoeec.dll
C:\WINDOWS\system32\ekeaafih.dll
C:\WINDOWS\system32\eqpvciht.dll
C:\WINDOWS\system32\ermsyccp.dll
C:\WINDOWS\system32\ghsqyovq.dll
C:\WINDOWS\system32\gtmfkfhn.dll
C:\WINDOWS\system32\hxipywlf.dll
C:\WINDOWS\system32\iiuwlsik.dll
C:\WINDOWS\system32\jsxuljyt.dll
C:\WINDOWS\system32\lkfrkrhh.dll
C:\WINDOWS\system32\nivmmghc.dll
C:\WINDOWS\system32\nolncpcw.dll
C:\WINDOWS\system32\oefosqwn.dll
C:\WINDOWS\system32\owqynikd.dll
C:\WINDOWS\system32\pfwynalf.dll
C:\WINDOWS\system32\ptwfknvb.dll
C:\WINDOWS\system32\pvgnokhf.dll
C:\WINDOWS\system32\qvejhmsd.dll
C:\WINDOWS\system32\rlhahsbb.dll
C:\WINDOWS\system32\savmnibn.dll
C:\WINDOWS\system32\texfoohw.dll
C:\WINDOWS\system32\tmavmdxc.dll
C:\WINDOWS\system32\unccfklk.dll
C:\WINDOWS\system32\vdfnipwj.dll
C:\WINDOWS\system32\vojkkdwd.dll
C:\WINDOWS\system32\xhsllifx.dll
C:\WINDOWS\system32\ylcsthyb.dll
C:\WINDOWS\system32\tuvvutu.dll
C:\WINDOWS\system32\jxtlkfgb.ini
C:\WINDOWS\system32\chucwvib.ini
C:\WINDOWS\system32\edrnllvf.ini
C:\WINDOWS\system32\iblgfocg.ini
C:\WINDOWS\system32\acbeg.bak1
C:\WINDOWS\system32\acbeg.bak2
C:\WINDOWS\system32\acbeg.ini
C:\WINDOWS\system32\acbeg.ini2
C:\WINDOWS\system32\acbeg.tmp
C:\WINDOWS\system32\entjupyg.ini
C:\WINDOWS\system32\vwepanth.ini
C:\WINDOWS\system32\wjiegovj.tmp
C:\WINDOWS\system32\rnpbxffk.ini
C:\WINDOWS\system32\pivijbpk.ini
C:\WINDOWS\system32\pfnrcwal.ini
C:\WINDOWS\system32\mltufvil.ini
C:\WINDOWS\system32\hmcnhstn.ini
C:\WINDOWS\system32\jvovdhun.ini
C:\WINDOWS\system32\llfiavxn.ini
C:\WINDOWS\system32\jweifjlo.ini
C:\WINDOWS\system32\wwunlxlq.ini
C:\WINDOWS\system32\hqsbqgqt.ini
C:\WINDOWS\system32\adlfekov.ini
C:\WINDOWS\system32\rbjqclxv.ini
C:\WINDOWS\system32\oufiulhw.ini
C:\WINDOWS\system32\ugrunoiw.ini
C:\WINDOWS\system32\eirevuqx.ini
C:\WINDOWS\system32\vjunuysy.ini
C:\WINDOWS\system32\iyrexbty.ini
C:\WINDOWS\system32\acbeg.bak1
C:\WINDOWS\system32\acbeg.bak2
C:\WINDOWS\system32\acbeg.ini
C:\WINDOWS\system32\acbeg.ini2
C:\WINDOWS\system32\acbeg.tmp
C:\WINDOWS\system32\tstwa.bak1
C:\WINDOWS\system32\tstwa.ini2
C:\WINDOWS\system32\tstwa.tmp
C:\WINDOWS\system32\acbeg.bak1
C:\WINDOWS\system32\acbeg.bak2
C:\WINDOWS\system32\acbeg.ini
C:\WINDOWS\system32\acbeg.ini2
C:\WINDOWS\system32\acbeg.tmp
C:\WINDOWS\system32\tstwa.bak1
C:\WINDOWS\system32\tstwa.ini2
C:\WINDOWS\system32\tstwa.tmp
C:\WINDOWS\system32\fccdayx.dll
C:\WINDOWS\system32\gebca.dll
C:\WINDOWS\system32\fccdayx.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\FunWebProducts
C:\WINDOWS\system32\adatyjga.exe
C:\WINDOWS\system32\arsnmoge.exe
C:\WINDOWS\system32\auahexih.exe
C:\WINDOWS\system32\axchhfjk.exe
C:\WINDOWS\system32\bmboqage.exe
C:\WINDOWS\system32\cnofhkjd.exe
C:\WINDOWS\system32\cogpkxpm.exe
C:\WINDOWS\system32\dlofjxys.exe
C:\WINDOWS\system32\ehpokxox.exe
C:\WINDOWS\system32\emncrvpn.exe
C:\WINDOWS\system32\eysfesnj.exe
C:\WINDOWS\system32\fjeaqolt.exe
C:\WINDOWS\system32\fteyjmga.exe
C:\WINDOWS\system32\gmhuxcpc.exe
C:\WINDOWS\system32\gwdadchb.exe
C:\WINDOWS\system32\hadlnuui.exe
C:\WINDOWS\system32\hapwrgnb.exe
C:\WINDOWS\system32\iakaitij.exe
C:\WINDOWS\system32\igwbklbu.exe
C:\WINDOWS\system32\iicfkgrt.exe
C:\WINDOWS\system32\irrjheke.exe
C:\WINDOWS\system32\itdkvkwo.exe
C:\WINDOWS\system32\jlbnxnpu.exe
C:\WINDOWS\system32\jppetvqx.exe
C:\WINDOWS\system32\jxscjvpx.exe
C:\WINDOWS\system32\keeuxyeu.exe
C:\WINDOWS\system32\kjdfgefe.exe
C:\WINDOWS\system32\kpmqdwws.exe
C:\WINDOWS\system32\ksghlrqa.exe
C:\WINDOWS\system32\ktamcjuq.exe
C:\WINDOWS\system32\kyfvjtop.exe
C:\WINDOWS\system32\lfagwxcg.exe
C:\WINDOWS\system32\lloeeqkn.exe
C:\WINDOWS\system32\lyyvhsqu.exe
C:\WINDOWS\system32\mbrrclha.exe
C:\WINDOWS\system32\moyfukgy.exe
C:\WINDOWS\system32\msdcuhky.exe
C:\WINDOWS\system32\ncylqskt.exe
C:\WINDOWS\system32\nrhmjdmc.exe
C:\WINDOWS\system32\ofbefohf.exe
C:\WINDOWS\system32\olcacinh.exe
C:\WINDOWS\system32\opqpumrq.exe
C:\WINDOWS\system32\pgnyovfx.exe
C:\WINDOWS\system32\psctukum.exe
C:\WINDOWS\system32\pyfrklpc.exe
C:\WINDOWS\system32\rhplqkbg.exe
C:\WINDOWS\system32\rlevndhy.exe
C:\WINDOWS\system32\rlosqatw.exe
C:\WINDOWS\system32\sboprkok.exe
C:\WINDOWS\system32\sxuaaibu.exe
C:\WINDOWS\system32\sxyxwjvb.exe
C:\WINDOWS\system32\tapwajgy.exe
C:\WINDOWS\system32\tkarestn.exe
C:\WINDOWS\system32\tldofbpc.exe
C:\WINDOWS\system32\tpbcamqq.exe
C:\WINDOWS\system32\tumjuoci.exe
C:\WINDOWS\system32\ujayshox.exe
C:\WINDOWS\system32\ukwsiaji.exe
C:\WINDOWS\system32\uxojifsy.exe
C:\WINDOWS\system32\uybsylol.exe
C:\WINDOWS\system32\vdjeidop.exe
C:\WINDOWS\system32\vpavbqso.exe
C:\WINDOWS\system32\vyfhxfjp.exe
C:\WINDOWS\system32\wepgpihq.exe
C:\WINDOWS\system32\wqiufnds.exe
C:\WINDOWS\system32\wtbqnqum.exe
C:\WINDOWS\system32\wtcphnex.exe
C:\WINDOWS\system32\wtoqghav.exe
C:\WINDOWS\system32\xaqtbvlx.exe
C:\WINDOWS\system32\xbfdftby.exe
C:\WINDOWS\system32\xbriqmuc.exe
C:\WINDOWS\system32\xchrnruh.exe
C:\WINDOWS\system32\xhoxsudj.exe
C:\WINDOWS\system32\xiiqvbdg.exe
C:\WINDOWS\system32\xkibaosb.exe
C:\WINDOWS\system32\xmpnhcic.exe
C:\WINDOWS\system32\xpfuwoqo.exe
C:\WINDOWS\system32\yberbtkj.exe
C:\WINDOWS\system32\yeoikhod.exe
C:\WINDOWS\system32\yfbrofne.exe
C:\WINDOWS\system32\yhnexyqn.exe
C:\WINDOWS\system32\ypckxqum.exe
C:\WINDOWS\system32\yxxmmuhy.exe


((((((((((((((((((((((((( Files Created from 2007-07-02 to 2007-08-02 )))))))))))))))))))))))))))))))


2007-08-02 14:16 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-02 12:48 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-02 12:48 d——– C:\Program Files\AVG Anti-Spyware 7.5
2007-08-02 12:03 125,504 –a—— C:\WINDOWS\system32\dtvsyffw.dll
2007-08-02 11:31 d——– C:\Program Files\Trend Micro
2007-08-01 19:00 125,504 –a—— C:\WINDOWS\system32\wvwdnixo.dll
2007-08-01 13:53 125,504 –a—— C:\WINDOWS\system32\vqostvvn.dll
2007-08-01 11:13 125,504 –a—— C:\WINDOWS\system32\xeoswehu.dll
2007-07-31 23:58 125,504 –a—— C:\WINDOWS\system32\chdpgwwj.dll
2007-07-31 19:22 125,504 –a—— C:\WINDOWS\system32\ipxvccqp.dll
2007-07-31 15:43 125,504 –a—— C:\WINDOWS\system32\fllcywox.dll
2007-07-31 13:59 125,504 –a—— C:\WINDOWS\system32\nargtxfv.dll
2007-07-30 16:58 125,504 –a—— C:\WINDOWS\system32\drngcelf.dll
2007-07-30 07:44 126,016 –a—— C:\WINDOWS\system32\mjjndaer.dll
2007-07-25 11:58 126,016 –a—— C:\WINDOWS\system32\sjtdhmtu.dll
2007-07-24 17:03 126,016 –a—— C:\WINDOWS\system32\swkrcmuw.dll
2007-07-24 12:56 126,016 –a—— C:\WINDOWS\system32\uvnrmted.dll
2007-07-23 20:53 126,016 –a—— C:\WINDOWS\system32\jlsqysbo.dll
2007-07-23 09:14 126,016 –a—— C:\WINDOWS\system32\efecsfxy.dll
2007-07-02 11:00 90,112 –a—— C:\WINDOWS\system32\NCTAudioFormatSettings3.dll
2007-07-02 11:00 86,016 –a—— C:\WINDOWS\system32\AddiTunes.exe
2007-07-02 11:00 81,920 –a—— C:\WINDOWS\system32\viscomwave.dll
2007-07-02 11:00 780,288 –a—— C:\WINDOWS\system32\NCTVideoCompress.dll
2007-07-02 11:00 778,240 –a—— C:\WINDOWS\system32\NCTAudioCompress2.dll
2007-07-02 11:00 764,416 –a—— C:\WINDOWS\system32\NCTRMFile.dll
2007-07-02 11:00 626,688 –a—— C:\WINDOWS\system32\NCTImageFile.dll
2007-07-02 11:00 61,440 –a—— C:\WINDOWS\system32\cygz.dll
2007-07-02 11:00 495,104 –a—— C:\WINDOWS\system32\NCTVideoCoreM.dll
2007-07-02 11:00 4,755,968 –a—— C:\WINDOWS\system32\apexconverter.exe
2007-07-02 11:00 398,798 –a—— C:\WINDOWS\system32\apexpmp.exe
2007-07-02 11:00 382,464 –a—— C:\WINDOWS\system32\NCTAVIFile.dll
2007-07-02 11:00 312,320 –a—— C:\WINDOWS\system32\NCTVideoView.dll
2007-07-02 11:00 3,138,048 –a—— C:\WINDOWS\system32\apexxbox.exe
2007-07-02 11:00 249,856 –a—— C:\WINDOWS\system32\NCTQuickTimeFile.dll
2007-07-02 11:00 237,568 –a—— C:\WINDOWS\system32\lame_enc.dll
2007-07-02 11:00 215,552 –a—— C:\WINDOWS\system32\NCTWMVFile.dll
2007-07-02 11:00 2,846,720 –a—— C:\WINDOWS\system32\NCTAudioCompress3.dll
2007-07-02 11:00 188,416 –a—— C:\WINDOWS\system32\NCTVideoFile.dll
2007-07-02 11:00 147,456 –a—— C:\WINDOWS\system32\viscomqtenc.dll
2007-07-02 11:00 139,264 –a—— C:\WINDOWS\system32\viscomqtde.dll
2007-07-02 11:00 120,320 –a—— C:\WINDOWS\system32\apexchanger.exe
2007-07-02 11:00 109,568 –a—— C:\WINDOWS\system32\apex3gp.exe
2007-07-02 11:00 1,700,352 –a—— C:\WINDOWS\system32\gdiplus.dll
2007-07-02 11:00 1,295,582 –a—— C:\WINDOWS\system32\cygwin1.dll
2007-07-02 11:00 d——– C:\WINDOWS\system32\RMBin
2007-07-02 11:00 d——– C:\Program Files\A-Z


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-02 14:32 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-08-02 11:58 ——— d——– C:\Program Files\Plaxo
2007-08-01 17:04 ——— d——– C:\DOCUME~1\LAURAS~1\APPLIC~1\AdobeUM
2007-07-17 13:39 ——— d——– C:\Program Files\Yahoo!
2007-07-16 09:37 ——— d——– C:\Program Files\SUPERAntiSpyware
2007-07-14 14:12 ——— dr-h—– C:\DOCUME~1\LAURAS~1\APPLIC~1\yahoo!
2007-07-02 14:46 ——— d——– C:\DOCUME~1\LAURAS~1\APPLIC~1\uTorrent
2007-07-02 11:01 ——— d——– C:\Program Files\XviD
2007-07-02 00:21 ——— d——– C:\Program Files\uTorrent
2007-07-02 00:13 1702 –a—— C:\Program Files\[mininova.org]_WinAVI.Video.Converter.7.7.torrent
2007-07-02 00:07 6350 –a—— C:\Program Files\DVD_Video_Converter_and_Ripper_Avex_-{mininova.org}-.torrent
2007-07-02 00:07 6350 –a—— C:\Program Files\b-mininova.org-d__DVD_Video_Converter_and_Ripper_Avex.torrent
2007-07-01 22:04 ——— d——– C:\DOCUME~1\LAURAS~1\APPLIC~1\ArcSoft
2007-07-01 20:49 ——— d——– C:\Program Files\WinAVI Video Converter
2007-07-01 20:45 ——— d——– C:\Program Files\WinAVI Video Capture
2007-06-30 23:35 ——— d——– C:\Program Files\Windows Media Connect 2
2007-06-30 23:35 ——— d——– C:\Program Files\Wal-Mart Music Downloads Store
2007-06-30 23:35 ——— d——– C:\Program Files\Messenger
2007-06-30 23:35 ——— d——– C:\Program Files\MagicISO
2007-06-30 23:35 ——— d——– C:\Program Files\LimeWire
2007-06-26 08:33 848 –ahs—- C:\WINDOWS\system32\KGyGaAvL.sys
2007-05-16 08:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-11 00:24 81512 –a—— C:\DOCUME~1\LAURAS~1\APPLIC~1\GDIPFONTCACHEV1.DAT
2006-06-07 13:57 1094021 –a—— C:\Program Files\dvdshrink32setup1.zip
2006-06-06 22:54 7180311 –a—— C:\Program Files\HandBrake-0.7.0-GUIAndCLI-20060115.zip
2006-06-04 19:16 359112 –a—— C:\Program Files\LimeWireWin.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8EE6BFDE-9534-4F38-98AD-B0B8D48A1990}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
"SoundMan"="SOUNDMAN.EXE" [2004-06-18 01:31 C:\WINDOWS\SOUNDMAN.EXE]
"MULTIMEDIA KEYBOARD"="C:\Program Files\Keymaestro\Multimedia Keyboard\MMKeybd.exe" [2002-07-30 01:22]
"LTMSG"="LTMSG.exe" [2003-07-14 10:52 C:\WINDOWS\ltmsg.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"HostManager"="C:\Program Files\Common Files\AOL\1136443953\ee\AOLSoftware.exe" [2006-09-25 17:52]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 05:50]
"Pure Networks Port Magic"="C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" [2004-04-05 14:33]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-20 19:00]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" [2005-11-09 11:46]
"NapsterShell"="C:\Program Files\Napster\napster.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
"4flagvgainside"="C:\Documents and Settings\All Users\Application Data\bait dart 4 flag\Magsfile.exe" []
"Motive SmartBridge"="C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe" [2003-12-10 04:52]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 08:42]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kdx"="C:\WINDOWS\kdx\KHost.exe" [2006-07-14 12:26]
"PlaxoUpdate"="C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe" [2006-11-16 13:42]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-07-16 09:37]
"phone seek"="C:\DOCUME~1\LAURAS~1\APPLIC~1\PROCBU~1\warn love else.exe" []
"AOL Fast Start"="C:\Program Files\America Online 9.0\AOL.exe" [2005-07-12 07:17]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-01-04 11:33:56]
Amazon Unbox.lnk - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe [2007-02-19 16:21:56]
TM Monitor.lnk - C:\Program Files\ArcSoft\TotalMedia\TM Monitor.exe [2004-09-01 03:45:56]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-02-21 23:26:41]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2007-06-07 21:02 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\svcWRSSSDK]
@="Service"

R0 SSI;SSI;C:\WINDOWS\system32\Drivers\SSI.SYS
R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys
R1 SASDIFSV;SASDIFSV;\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
R1 SASKUTIL;SASKUTIL;\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
R2 CDRPDACC;Arrowkey Device Access;\??\C:\Program Files\321Studios\Shared\CDRPDACC.SYS
R2 ColdFusion MX 7 Application Server;ColdFusion MX 7 Application Server;"C:\CFusionMX7\runtime\bin\jrunsvc.exe"
R2 ColdFusion MX 7 ODBC Agent;ColdFusion MX 7 ODBC Agent;C:\CFusionMX7\db\slserver54\bin\swagent.exe "ColdFusion MX 7 ODBC Agent"
R2 ColdFusion MX 7 ODBC Server;ColdFusion MX 7 ODBC Server;C:\CFusionMX7\db\slserver54\bin\swstrtr.exe "ColdFusion MX 7 ODBC Server"
R2 ColdFusion MX 7 Search Server;ColdFusion MX 7 Search Server;"C:\CFusionMX7\verity\k2\_nti40\bin\k2admin.exe" -cfg "C:\CFusionMX7\verity\k2\common\verity.cfg" -ntstart 1
R2 InterBaseGuardian;InterBase Guardian;C:\Program Files\Borland\InterBase\bin\ibguard.exe
R2 nhksrv;Netropa NHK Server;C:\Program Files\Keymaestro\Multimedia Keyboard\nhksrv.exe
R3 ALCXSENS;Service for WDM 3D Audio Driver;C:\WINDOWS\system32\drivers\ALCXSENS.SYS
R3 CXTuner;Conexant TVTuner;C:\WINDOWS\system32\drivers\CXTuner.sys
R3 CXVideo;Conexant Capture;C:\WINDOWS\system32\drivers\CXVCap.sys
R3 CXXBar;Conexant Crossbar;C:\WINDOWS\system32\drivers\CXXBar.sys
R3 InterBaseServer;InterBase Server;C:\Program Files\Borland\InterBase\bin\ibserver.exe
R3 ltmodem5;Agere Modem Driver;C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys
R3 wanatw;WAN Miniport (ATW);C:\WINDOWS\system32\DRIVERS\wanatw4.sys
S3 61883;61883 Unit Device;C:\WINDOWS\system32\DRIVERS\61883.sys
S3 Avc;AVC Device;C:\WINDOWS\system32\DRIVERS\avc.sys
S3 MSDV;Microsoft DV Camera and VCR;C:\WINDOWS\system32\DRIVERS\msdv.sys
S3 Pcouffin;Low level access layer for CD devices;C:\WINDOWS\system32\Drivers\Pcouffin.sys
S3 SASENUM;SASENUM;\??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS

*Newly Created Service* - ATWPKT2
*Newly Created Service* - AVGASCLN

Contents of the 'Scheduled Tasks' folder
2007-07-26 22:02:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-02 14:45:38
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

**************************************************************************

Completion time: 2007-08-02 14:48:01 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-02 14:47

— E O F —

HIJACKTHIS LOG #2

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:51:01 PM, on 8/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Keymaestro\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
C:\CFusionMX7\runtime\bin\jrunsvc.exe
C:\CFusionMX7\runtime\bin\jrun.exe
C:\CFusionMX7\db\slserver54\bin\swagent.exe
C:\CFusionMX7\db\slserver54\bin\swstrtr.exe
C:\CFusionMX7\db\slserver54\bin\swsoc.exe
C:\CFusionMX7\verity\k2\_nti40\bin\k2admin.exe
C:\Program Files\Borland\InterBase\bin\ibguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\CFusionMX7\verity\k2\_nti40\bin\k2server.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\CFusionMX7\verity\k2\_nti40\bin\k2index.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Borland\InterBase\bin\ibserver.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Keymaestro\Multimedia Keyboard\MMKeybd.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\AOL\1136443953\ee\AOLSoftware.exe
C:\Program Files\Keymaestro\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Keymaestro\Onscreen Display\OSD.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
c:\program files\common files\aol\1136443953\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1136443953\ee\aolsoftware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe
C:\Program Files\ArcSoft\TotalMedia\TM Monitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Trend Micro\HijackThis\hello.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O2 - BHO: (no name) - {8EE6BFDE-9534-4F38-98AD-B0B8D48A1990} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Keymaestro\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1136443953\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [4flagvgainside] C:\Documents and Settings\All Users\Application Data\bait dart 4 flag\Magsfile.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [phone seek] C:\DOCUME~1\LAURAS~1\APPLIC~1\PROCBU~1\warn love else.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Amazon Unbox.lnk = ?
O4 - Global Startup: TM Monitor.lnk = C:\Program Files\ArcSoft\TotalMedia\TM Monitor.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1094035800062
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143045110723
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {A7ECD556-D6F6-4F41-8C6B-14AB246801A0} (Secure Delivery) - http://cdn.digitalcity.com/video/kdx.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Amazon Unbox Video Service (ADVService) - Amazon.com - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ColdFusion MX 7 Application Server - Macromedia Inc. - C:\CFusionMX7\runtime\bin\jrunsvc.exe
O23 - Service: ColdFusion MX 7 ODBC Agent - Unknown owner - C:\CFusionMX7\db\slserver54\bin\swagent.exe
O23 - Service: ColdFusion MX 7 ODBC Server - Unknown owner - C:\CFusionMX7\db\slserver54\bin\swstrtr.exe
O23 - Service: ColdFusion MX 7 Search Server - Verity, Inc. - C:\CFusionMX7\verity\k2\_nti40\bin\k2admin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation - C:\Program Files\Borland\InterBase\bin\ibguard.exe
O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation - C:\Program Files\Borland\InterBase\bin\ibserver.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Keymaestro\Multimedia Keyboard\nhksrv.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 11564 bytes
Hi Laurasix

I should have mentioned, if you dont have Opera or Firefox installed the options will be greyed out. No matter, lets concentrate on the bad files first, because you have a lot!

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\WINDOWS\system32\dtvsyffw.dll
C:\WINDOWS\system32\wvwdnixo.dll
C:\WINDOWS\system32\vqostvvn.dll
C:\WINDOWS\system32\xeoswehu.dll
C:\WINDOWS\system32\chdpgwwj.dll
C:\WINDOWS\system32\ipxvccqp.dll
C:\WINDOWS\system32\fllcywox.dll
C:\WINDOWS\system32\nargtxfv.dll
C:\WINDOWS\system32\drngcelf.dll
C:\WINDOWS\system32\mjjndaer.dll
C:\WINDOWS\system32\sjtdhmtu.dll
C:\WINDOWS\system32\swkrcmuw.dll
C:\WINDOWS\system32\uvnrmted.dll
C:\WINDOWS\system32\jlsqysbo.dll
C:\WINDOWS\system32\efecsfxy.dll

Folder::
C:\DOCUME~1\LAURAS~1\APPLIC~1\PROCBU~1
C:\Documents and Settings\All Users\Application Data\bait dart 4 flag

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8EE6BFDE-9534-4F38-98AD-B0B8D48A1990}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"4flagvgainside"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"phone seek"=-

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI