This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Assistance Needed

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Yesterday I tried using my disk clean up option and found I couldn't. It kept shutting down stating it was for my computer's own safety etc. I have two user accounts on my computer and found out in both accounts I could not perform a disk clean up. I used AVG anti virus to perform a virus scan last night but I noticed it was not performing a full system scan, no matter how many times I clicked that option. It would only scan the other user account on this computer while ignoring mine. A friend offered various spyware/virus scans (Micro trend and others) to see what the problem might be but they all stopped and the browsers closed (I use FF and IE)

I then removed AVG from my computer and used Avast instead. It did perform a full system scan but nothing came up.

Since them I have tried various anti spyware programs. Including AVG anti spyware which will work on the other user account but shuts down when I am logged into this current user account I am on right now. This morning I noticed though that on the other user account I could do a disk clean up finally, and AVG anti spyware went through a complete scan without shutting down. AVG anti spyware will STILL not scan on this user account (the one I am using now) and when I tried Ad Aware SE as well and in both user accounts, it shuts down after hitting this critical object:

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : vanessa@real[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:[removed]/
Expires : 19-07-2037 8:03:44 PM
LastSync : Hits:3
UseCount : 0
Hits : 3

I don't know what value this has in determining what is wrong with my system but there it is. Here too is my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:56:03 PM, on 05/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Aliant\NETASS~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Documents and Settings\Vanessa\Desktop\HiJackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =

127.0.0.1;dynhost.inetcam.com;register.inetcam.com;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program

Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Aliant\NETASS~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Workflow] I:\Install\Workflow.exe
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Net Assistant.lnk = C:\Program Files\Aliant\Net Assistant\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -

http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/windowsupdate/…b?1144882010222
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -

http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -

http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -

http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -

http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5172C55E-9BC1-44E3-BB5B-3B2ABAB6D60B}: NameServer = 85.255.116.60,85.255.112.203
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A5F88C3-96F2-44A5-B2EC-D0FF4CEEC7A5}: NameServer = 85.255.116.60,85.255.112.203
O17 - HKLM\System\CCS\Services\Tcpip\..\{63DEEBA4-66EA-476C-B8FD-AF6708166174}: NameServer = 85.255.116.60,85.255.112.203
O17 - HKLM\System\CCS\Services\Tcpip\..\{84B16914-4E91-485A-9D39-81882FE59034}: NameServer = 85.255.116.60,85.255.112.203
O17 - HKLM\System\CCS\Services\Tcpip\..\{9E9F2DC3-2511-4EDE-ABEF-B63EB32F7D5F}: NameServer = 85.255.116.60,85.255.112.203
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.60 85.255.112.203
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common

Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia

Shared\Service\Macromedia Licensing.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 8684 bytes
Hi! Welcome to the Tom Coyote forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.

Download and Run FixWarout
Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

At the end of the fix, you may need to restart your computer again.

Remove bad HijackThis entries
  • Run HijackThis
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):


  • Close all open windows and browsers/email, etc…
  • Click on the "Fix Checked" button
  • When completed, close the application.
Finally, please post a fresh HijackThis log, along with the contents of the logfile C:\fixwareout\report.txt

Now lets check some settings on your system.
(2000/XP) Only
In the windows control panel. If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections. Then right click on your default connection, usually local area connection for cable and dsl, and left click on properties. Click the Networking tab. Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically
Press OK twice to get out of the properties screen and reboot if it asks.
That option might not be avaiable on some systems
Next Go start run type cmd and hit OK
type
ipconfig /flushdns
then hit enter, type exit hit enter
(that space between g and / is needed)

Download and Run SmitfraudFix
Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
I did as you instructed and upon reaching this point in the process: Click on the "Fix Checked" button HijackThis began fixing and 2/3 into the way stopped responding. I had to reboot my system once again. I am unsure what to do. Do I restart the process you outlined? Or is this a good indication that perhaps I need to reformat my drive? Thanks for your assistance thus far! VV
I am so sorry. It's been a while since Ive dealt with Wareout. If you have run Fixwareout with out problems, follow the next instruction for the HijackThis bit. I forgot to put the lines in.

Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):
O17 - HKLM\System\CCS\Services\Tcpip\..\{5172C55E-9BC1-44E3-BB5B-3B2ABAB6D60B}: NameServer = 85.255.116.60,85.255.112.203
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A5F88C3-96F2-44A5-B2EC-D0FF4CEEC7A5}: NameServer = 85.255.116.60,85.255.112.203
O17 - HKLM\System\CCS\Services\Tcpip\..\{63DEEBA4-66EA-476C-B8FD-AF6708166174}: NameServer = 85.255.116.60,85.255.112.203
O17 - HKLM\System\CCS\Services\Tcpip\..\{84B16914-4E91-485A-9D39-81882FE59034}: NameServer = 85.255.116.60,85.255.112.203
O17 - HKLM\System\CCS\Services\Tcpip\..\{9E9F2DC3-2511-4EDE-ABEF-B63EB32F7D5F}: NameServer = 85.255.116.60,85.255.112.203
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.60 85.255.112.203



WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis.

Then proceed with the rest of the above fix.
Okay! :wavey: The entries you listed were already gone. I did the remaining steps you outlined in your first response and this is the report:


SmitFraudFix v2.208

Scan done at 19:46:34.03, 05/08/2007
Run from C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Vanessa


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Vanessa\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Vanessa\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"system"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Realtek RTL8139 Family PCI Fast Ethernet NIC - Packet Scheduler Miniport
DNS Server Search Order: 192.168.2.1
DNS Server Search Order: 192.168.2.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{84B16914-4E91-485A-9D39-81882FE59034}: DhcpNameServer=192.168.2.1 192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{5172C55E-9BC1-44E3-BB5B-3B2ABAB6D60B}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\..\{5A5F88C3-96F2-44A5-B2EC-D0FF4CEEC7A5}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\..\{84B16914-4E91-485A-9D39-81882FE59034}: DhcpNameServer=192.168.2.1 192.168.2.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{84B16914-4E91-485A-9D39-81882FE59034}: DhcpNameServer=192.168.2.1 192.168.2.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1 192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1 192.168.2.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1 192.168.2.1


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End



This is the HiJackThis logfile:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:37:26 PM, on 05/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG7\avgwb.dat
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Vanessa\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Net Assistant.lnk = C:\Program Files\Aliant\Net Assistant\bin\matcli.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1144882010222
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 5956 bytes


Hope I included everything
Hello

Download RogueRemover by Rubber Ducky from here
  • Double-click on rr-free-setup.exe to start the installation of RogueRemover
  • Click Next then click I agree and finally click Install
  • Untick Show Readme and click Finish
  • This will now launch RogueRemover
  • Close the help window
  • Click Check for updates
  • If there are any updates found click Download
  • Wait for any updates to finish downloading/installing, then click Close in the update window
  • Click on Scan
  • If nothing is found, then close RogueRemover
  • If RogueRemover did find something, it will present a list of detected items
  • Click Remove selected
  • Click YES at the prompt
  • Click Ok when it informs you it's saved a logfile
  • Wait for removal to complete & then close RogueRemover
  • Use notepad to open this file
    • C:\Program Files\RogueRemover\RRLog******.txt
  • (Note: ****** is the time when you ran RogueRemover)
Post that log along with a new HijackThis log in your next reply, please.
I am sorry I don't quite know what you mean by this:

Use notepad to open this file

* C:\Program Files\RogueRemover\RRLog******.txt

I did run Rogue Remover as you instructed I just don't get that last bit. :unsure:


This is the logfile though:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:20:16 PM, on 05/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe
C:\Documents and Settings\Vanessa\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Net Assistant.lnk = C:\Program Files\Aliant\Net Assistant\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1144882010222
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 5967 bytes
To get that file you will have to go to start>My Computer>Local Drive ©>Program Files then open the RogueRemover folder. Inside will be a text file called RRLog****.txt Where the *** are will be the time you ran the program. Double-click that file to open it and copy/paste it here.
Oh thank you!

Malwarebytes' RogueRemover
Malwarebytes ©2007 http://www.malwarebytes.org
5336 total fingerprints loaded.

Loading database …
Expanding environmental variables …

Scanning files … [ 100% ].
Scanning folders … [ 100% ].
Scanning registry keys … [ 100% ].
Scanning registry values … [ 100% ].

RogueRemover has detected rogue antispyware components! Results below…

Type: Registry Key
Vendor: WinAntiVirus 2007
Location: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FSFLT
Selected for removal: Yes

RogueRemover has found the objects above.
Hi

Download and Run ComboFix
  • Download this file from below:

    Here
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
ComboFix 07-08-06 - "Vanessa" 2007-08-05 20:45:08.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.171 [GMT -3:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WA7P
C:\WINDOWS\system32\MabryObj.dll


((((((((((((((((((((((((( Files Created from 2007-07-05 to 2007-08-05 )))))))))))))))))))))))))))))))


2007-08-05 20:43 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-05 20:16 d——– C:\Program Files\RogueRemover FREE
2007-08-05 19:46 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-08-05 19:46 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-08-05 19:46 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-08-05 19:46 1,690 –a—— C:\WINDOWS\system32\tmp.reg
2007-08-05 17:49 10,736 –a—— C:\dnsbak.reg
2007-08-05 17:37 164 –a—— C:\install.dat
2007-08-04 23:25 99,865 –a–c— C:\WINDOWS\system32\dllcache\xlog.exe
2007-08-04 23:25 87,040 –a–c— C:\WINDOWS\system32\dllcache\wiafbdrv.dll
2007-08-04 23:25 8,832 –a–c— C:\WINDOWS\system32\dllcache\wmiacpi.sys
2007-08-04 23:25 8,192 –a–c— C:\WINDOWS\system32\dllcache\wshirda.dll
2007-08-04 23:25 771,581 –a–c— C:\WINDOWS\system32\dllcache\winacisa.sys
2007-08-04 23:25 701,386 –a–c— C:\WINDOWS\system32\dllcache\wdhaalba.sys
2007-08-04 23:25 53,760 –a–c— C:\WINDOWS\system32\dllcache\wiamsmud.dll
2007-08-04 23:25 4,608 –a–c— C:\WINDOWS\system32\dllcache\xrxflnch.exe
2007-08-04 23:25 35,871 –a–c— C:\WINDOWS\system32\dllcache\wbfirdma.sys
2007-08-04 23:25 34,890 –a–c— C:\WINDOWS\system32\dllcache\wlandrv2.sys
2007-08-04 23:25 33,599 –a–c— C:\WINDOWS\system32\dllcache\watv04nt.sys
2007-08-04 23:25 31,744 –a–c— C:\WINDOWS\system32\dllcache\wceusbsh.sys
2007-08-04 23:25 27,648 –a–c— C:\WINDOWS\system32\dllcache\xrxftplt.exe
2007-08-04 23:25 23,615 –a–c— C:\WINDOWS\system32\dllcache\wch7xxnt.sys
2007-08-04 23:25 23,040 –a–c— C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
2007-08-04 23:25 19,551 –a–c— C:\WINDOWS\system32\dllcache\watv02nt.sys
2007-08-04 23:25 19,455 –a–c— C:\WINDOWS\system32\dllcache\wvchntxx.sys
2007-08-04 23:25 17,408 –a–c— C:\WINDOWS\system32\dllcache\xrxscnui.dll
2007-08-04 23:25 16,970 –a–c— C:\WINDOWS\system32\dllcache\xem336n5.sys
2007-08-04 23:25 154,624 –a–c— C:\WINDOWS\system32\dllcache\wlluc48.sys
2007-08-04 23:25 12,063 –a–c— C:\WINDOWS\system32\dllcache\wsiintxx.sys
2007-08-04 23:25 116,224 –a–c— C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2007-08-04 23:24 94,720 –a–c— C:\WINDOWS\system32\dllcache\umaxud32.dll
2007-08-04 23:24 94,293 –a–c— C:\WINDOWS\system32\dllcache\sxports.dll
2007-08-04 23:24 82,432 –a–c— C:\WINDOWS\system32\dllcache\tp4mon.exe
2007-08-04 23:24 81,408 –a–c— C:\WINDOWS\system32\dllcache\tgiul50.dll
2007-08-04 23:24 794,654 –a–c— C:\WINDOWS\system32\dllcache\usr1801.sys
2007-08-04 23:24 794,399 –a–c— C:\WINDOWS\system32\dllcache\usr1806v.sys
2007-08-04 23:24 793,598 –a–c— C:\WINDOWS\system32\dllcache\usr1806.sys
2007-08-04 23:24 765,884 –a–c— C:\WINDOWS\system32\dllcache\usrti.sys
2007-08-04 23:24 7,556 –a–c— C:\WINDOWS\system32\dllcache\usroslba.sys
2007-08-04 23:24 7,040 –a–c— C:\WINDOWS\system32\dllcache\tandqic.sys
2007-08-04 23:24 69,632 –a–c— C:\WINDOWS\system32\dllcache\umaxu12.dll
2007-08-04 23:24 687,999 –a–c— C:\WINDOWS\system32\dllcache\usrwdxjs.sys
2007-08-04 23:24 64,605 –a–c— C:\WINDOWS\system32\dllcache\vvoice.sys
2007-08-04 23:24 604,253 –a–c— C:\WINDOWS\system32\dllcache\vmodem.sys
2007-08-04 23:24 59,264 –a–c— C:\WINDOWS\system32\dllcache\usbaudio.sys
2007-08-04 23:24 53,760 –a–c— C:\WINDOWS\system32\dllcache\sw_wheel.dll
2007-08-04 23:24 525,568 –a–c— C:\WINDOWS\system32\dllcache\tridxp.dll
2007-08-04 23:24 50,688 –a–c— C:\WINDOWS\system32\dllcache\umaxscan.dll
2007-08-04 23:24 50,176 –a–c— C:\WINDOWS\system32\dllcache\umaxp60.dll
2007-08-04 23:24 5,376 –a–c— C:\WINDOWS\system32\dllcache\viaide.sys
2007-08-04 23:24 47,616 –a–c— C:\WINDOWS\system32\dllcache\umaxcam.dll
2007-08-04 23:24 440,576 –a–c— C:\WINDOWS\system32\dllcache\tridkb.dll
2007-08-04 23:24 42,496 –a–c— C:\WINDOWS\system32\dllcache\tp4res.dll
2007-08-04 23:24 41,472 –a–c— C:\WINDOWS\system32\dllcache\sw_effct.dll
2007-08-04 23:24 4,992 –a–c— C:\WINDOWS\system32\dllcache\toside.sys
2007-08-04 23:24 397,502 –a–c— C:\WINDOWS\system32\dllcache\vpctcom.sys
2007-08-04 23:24 37,961 –a–c— C:\WINDOWS\system32\dllcache\tdk100b.sys
2007-08-04 23:24 36,736 –a–c— C:\WINDOWS\system32\dllcache\ultra.sys
2007-08-04 23:24 36,640 –a–c— C:\WINDOWS\system32\dllcache\t2r4mini.sys
2007-08-04 23:24 34,375 –a–c— C:\WINDOWS\system32\dllcache\tpro4.sys
2007-08-04 23:24 32,640 –a–c— C:\WINDOWS\system32\dllcache\symc8xx.sys
2007-08-04 23:24 32,384 –a–c— C:\WINDOWS\system32\dllcache\usb101et.sys
2007-08-04 23:24 315,520 –a–c— C:\WINDOWS\system32\dllcache\trid3d.dll
2007-08-04 23:24 31,744 –a–c— C:\WINDOWS\system32\dllcache\tp4.dll
2007-08-04 23:24 31,616 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-08-04 23:24 30,688 –a–c— C:\WINDOWS\system32\dllcache\sym_u3.sys
2007-08-04 23:24 30,464 –a–c— C:\WINDOWS\system32\dllcache\tbatm155.sys
2007-08-04 23:24 3,968 –a–c— C:\WINDOWS\system32\dllcache\swusbflt.sys
2007-08-04 23:24 29,311 –a–c— C:\WINDOWS\system32\dllcache\watv01nt.sys
2007-08-04 23:24 28,384 –a–c— C:\WINDOWS\system32\dllcache\sym_hi.sys
2007-08-04 23:24 28,232 –a–c— C:\WINDOWS\system32\dllcache\tos4mo.sys
2007-08-04 23:24 28,160 –a–c— C:\WINDOWS\system32\dllcache\umaxu40.dll
2007-08-04 23:24 26,624 –a–c— C:\WINDOWS\system32\dllcache\umaxu22.dll
2007-08-04 23:24 25,856 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2007-08-04 23:24 25,600 –a–c— C:\WINDOWS\system32\dllcache\usbser.sys
2007-08-04 23:24 249,402 –a–c— C:\WINDOWS\system32\dllcache\vinwm.sys
2007-08-04 23:24 241,664 –a–c— C:\WINDOWS\system32\dllcache\tosdvd02.sys
2007-08-04 23:24 24,576 –a–c— C:\WINDOWS\system32\dllcache\viairda.sys
2007-08-04 23:24 230,912 –a–c— C:\WINDOWS\system32\dllcache\tosdvd03.sys
2007-08-04 23:24 224,802 –a–c— C:\WINDOWS\system32\dllcache\usr1807a.sys
2007-08-04 23:24 222,336 –a–c— C:\WINDOWS\system32\dllcache\trid3dm.sys
2007-08-04 23:24 22,912 –a–c— C:\WINDOWS\system32\dllcache\umaxpcls.sys
2007-08-04 23:24 216,064 –a–c— C:\WINDOWS\system32\dllcache\um34scan.dll
2007-08-04 23:24 211,968 –a–c— C:\WINDOWS\system32\dllcache\um54scan.dll
2007-08-04 23:24 19,528 –a–c— C:\WINDOWS\system32\dllcache\w840nd.sys
2007-08-04 23:24 19,016 –a–c— C:\WINDOWS\system32\dllcache\w926nd.sys
2007-08-04 23:24 172,768 –a–c— C:\WINDOWS\system32\dllcache\t2r4disp.dll
2007-08-04 23:24 17,129 –a–c— C:\WINDOWS\system32\dllcache\tdkcd31.sys
2007-08-04 23:24 17,024 –a–c— C:\WINDOWS\system32\dllcache\usbohci.sys
2007-08-04 23:24 166,784 –a–c— C:\WINDOWS\system32\dllcache\tridxpm.sys
2007-08-04 23:24 16,925 –a–c— C:\WINDOWS\system32\dllcache\w940nd.sys
2007-08-04 23:24 16,256 –a–c— C:\WINDOWS\system32\dllcache\symc810.sys
2007-08-04 23:24 159,232 –a–c— C:\WINDOWS\system32\dllcache\tridkbm.sys
2007-08-04 23:24 149,376 –a–c— C:\WINDOWS\system32\dllcache\tffsport.sys
2007-08-04 23:24 138,528 –a–c— C:\WINDOWS\system32\dllcache\tgiulnt5.sys
2007-08-04 23:24 123,995 –a–c— C:\WINDOWS\system32\dllcache\tjisdn.sys
2007-08-04 23:24 12,415 –a–c— C:\WINDOWS\system32\dllcache\wadv01nt.sys
2007-08-04 23:24 12,127 –a–c— C:\WINDOWS\system32\dllcache\wadv02nt.sys
2007-08-04 23:24 113,762 –a–c— C:\WINDOWS\system32\dllcache\usrpda.sys
2007-08-04 23:24 11,775 –a–c— C:\WINDOWS\system32\dllcache\wadv05nt.sys


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-31 23:49 ——— d——– C:\DOCUME~1\Vanessa\APPLIC~1\SpywareBot
2007-07-30 09:22 ——— d——– C:\Program Files\Trillian
2007-07-30 09:21 ——— d——– C:\Program Files\Common Files\Real
2007-07-30 09:20 ——— d——– C:\DOCUME~1\Vanessa\APPLIC~1\Real
2007-07-27 12:51 ——— d——– C:\Program Files\Google
2007-07-26 12:04 7517 –a—— C:\WINDOWS\mozver.dat
2007-05-16 12:12 86528 –a–c— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 12:12 85504 –a–c— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 12:12 683520 –a–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 12:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 12:12 510976 –a–c— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 12:12 1314816 –a–c— C:\WINDOWS\system32\dllcache\msoe.dll
2007-05-08 06:24 3583488 –a–c— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-04-06 10:56 2874926 –a—— C:\Program Files\FLV PlayerRCATSetup.exe
2007-04-06 10:56 25980320 –a—— C:\Program Files\FLV PlayerRCSetup.exe
2006-04-13 18:14 457 –a—— C:\Program Files\INSTALL.LOG


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 20:07 C:\WINDOWS\system32\HdAShCut.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-08-05 18:35]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 06:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:56]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2006-07-29 19:34]
"SpywareBot"="C:\Program Files\SpywareBot\SpywareBot.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-04-13 01:25:12]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-06 20:52:04]
Net Assistant.lnk - C:\Program Files\Aliant\Net Assistant\bin\matcli.exe [2006-09-20 14:26:08]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe
"IgfxTray"=C:\WINDOWS\System32\igfxtray.exe

S3 ICAM3NT5;Intel® PC Camera CS331;C:\WINDOWS\system32\Drivers\ICAM3D2.SYS
S3 mxnic;Macronix MX987xx Family Fast Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\mxnic.sys

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc

*Newly Created Service* - AVG7ALRT
*Newly Created Service* - AVG7CORE
*Newly Created Service* - AVG7RSXP
*Newly Created Service* - AVG7UPDSVC
*Newly Created Service* - AVGCLEAN

Contents of the 'Scheduled Tasks' folder
2007-08-05 10:34:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-08-05 13:14:58 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job - C:\Program Files\SpywareBot\SpywareBot.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-05 20:47:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts]
"Il\16\x0178A~yr\x2014|\x2039[ ?(?T?r?u?e?T?y?p?e?)?"="HDZB_96.TTF"
"Il\16\x178\x20ac{yr\x2014|\xd1\x17e ?(?T?r?u?e?T?y?p?e?)?"="HDZB_70.TTF"

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-05 20:48:26
C:\ComboFix-quarantined-files.txt … 2007-08-05 20:48

— E O F —






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:54:44 PM, on 05/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Vanessa\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Net Assistant.lnk = C:\Program Files\Aliant\Net Assistant\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1144882010222
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 6078 bytes
Aww what kinda Scotty are you? Star Trek Scotty wouldn't rest till he was done! I'm kidding! :weee: Thank you for your help thus far, my system is running much better than this morning when I first turned it on. Thank you again and hope you have a good morning/day! VV
Good morning

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\Documents and Settings\Vanessa\Desktop\Fixwareout.exe

Folder::
C:\DOCUME~1\Vanessa\APPLIC~1\SpywareBot
C:\Program Files\SpywareBot
C:\Program Files\RogueRemover
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareBot"=-

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.
  • Please go HERE to run PandaActiveScan…

  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)

  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to your desktop.
Post back with the CFScript log, the Pandascan report and a new HijackThis log. (Do them in that order)
ComboFix 07-08-06 - "Vanessa" 2007-08-06 10:11:40.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.153 [GMT -3:00]
Command switches used :: C:\Documents and Settings\Vanessa\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\Documents and Settings\Vanessa\Desktop\Fixwareout.exe


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Vanessa\APPLIC~1\SpywareBot
C:\DOCUME~1\Vanessa\APPLIC~1\SpywareBot\DataBase.ref
C:\DOCUME~1\Vanessa\APPLIC~1\SpywareBot\Log\log_2007_08_05_10_05_04.log
C:\DOCUME~1\Vanessa\APPLIC~1\SpywareBot\Log\log_2007_08_05_10_05_36.log
C:\DOCUME~1\Vanessa\APPLIC~1\SpywareBot\Settings\CustomScan.stg
C:\DOCUME~1\Vanessa\APPLIC~1\SpywareBot\Settings\IgnoreList.stg
C:\DOCUME~1\Vanessa\APPLIC~1\SpywareBot\Settings\ScanInfo.stg
C:\DOCUME~1\Vanessa\APPLIC~1\SpywareBot\Settings\SelectedFolders.stg
C:\DOCUME~1\Vanessa\APPLIC~1\SpywareBot\Settings\Settings.stg
C:\Documents and Settings\Vanessa\Desktop\Fixwareout.exe
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\dumphive.exe
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\GenericRenosFix.exe
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\HostsChk.exe
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\Process.exe
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\Reboot.exe
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\restart.exe
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\SmitfraudFix.cmd
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\SmiUpdate.exe
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\SrchSTS.exe
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\swreg.exe
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\swsc.exe
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\swxcacls.exe
C:\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\unzip.exe


((((((((((((((((((((((((( Files Created from 2007-07-06 to 2007-08-06 )))))))))))))))))))))))))))))))


2007-08-05 20:43 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-05 20:16 d——– C:\Program Files\RogueRemover FREE
2007-08-05 19:46 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-08-05 19:46 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-08-05 19:46 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-08-05 19:46 1,690 –a—— C:\WINDOWS\system32\tmp.reg
2007-08-05 17:49 10,736 –a—— C:\dnsbak.reg
2007-08-05 17:37 164 –a—— C:\install.dat
2007-08-04 23:25 99,865 –a–c— C:\WINDOWS\system32\dllcache\xlog.exe
2007-08-04 23:25 87,040 –a–c— C:\WINDOWS\system32\dllcache\wiafbdrv.dll
2007-08-04 23:25 8,832 –a–c— C:\WINDOWS\system32\dllcache\wmiacpi.sys
2007-08-04 23:25 8,192 –a–c— C:\WINDOWS\system32\dllcache\wshirda.dll
2007-08-04 23:25 771,581 –a–c— C:\WINDOWS\system32\dllcache\winacisa.sys
2007-08-04 23:25 701,386 –a–c— C:\WINDOWS\system32\dllcache\wdhaalba.sys
2007-08-04 23:25 53,760 –a–c— C:\WINDOWS\system32\dllcache\wiamsmud.dll
2007-08-04 23:25 4,608 –a–c— C:\WINDOWS\system32\dllcache\xrxflnch.exe
2007-08-04 23:25 35,871 –a–c— C:\WINDOWS\system32\dllcache\wbfirdma.sys
2007-08-04 23:25 34,890 –a–c— C:\WINDOWS\system32\dllcache\wlandrv2.sys
2007-08-04 23:25 33,599 –a–c— C:\WINDOWS\system32\dllcache\watv04nt.sys
2007-08-04 23:25 31,744 –a–c— C:\WINDOWS\system32\dllcache\wceusbsh.sys
2007-08-04 23:25 27,648 –a–c— C:\WINDOWS\system32\dllcache\xrxftplt.exe
2007-08-04 23:25 23,615 –a–c— C:\WINDOWS\system32\dllcache\wch7xxnt.sys
2007-08-04 23:25 23,040 –a–c— C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
2007-08-04 23:25 19,551 –a–c— C:\WINDOWS\system32\dllcache\watv02nt.sys
2007-08-04 23:25 19,455 –a–c— C:\WINDOWS\system32\dllcache\wvchntxx.sys
2007-08-04 23:25 17,408 –a–c— C:\WINDOWS\system32\dllcache\xrxscnui.dll
2007-08-04 23:25 16,970 –a–c— C:\WINDOWS\system32\dllcache\xem336n5.sys
2007-08-04 23:25 154,624 –a–c— C:\WINDOWS\system32\dllcache\wlluc48.sys
2007-08-04 23:25 12,063 –a–c— C:\WINDOWS\system32\dllcache\wsiintxx.sys
2007-08-04 23:25 116,224 –a–c— C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2007-08-04 23:24 94,720 –a–c— C:\WINDOWS\system32\dllcache\umaxud32.dll
2007-08-04 23:24 94,293 –a–c— C:\WINDOWS\system32\dllcache\sxports.dll
2007-08-04 23:24 82,432 –a–c— C:\WINDOWS\system32\dllcache\tp4mon.exe
2007-08-04 23:24 81,408 –a–c— C:\WINDOWS\system32\dllcache\tgiul50.dll
2007-08-04 23:24 794,654 –a–c— C:\WINDOWS\system32\dllcache\usr1801.sys
2007-08-04 23:24 794,399 –a–c— C:\WINDOWS\system32\dllcache\usr1806v.sys
2007-08-04 23:24 793,598 –a–c— C:\WINDOWS\system32\dllcache\usr1806.sys
2007-08-04 23:24 765,884 –a–c— C:\WINDOWS\system32\dllcache\usrti.sys
2007-08-04 23:24 7,556 –a–c— C:\WINDOWS\system32\dllcache\usroslba.sys
2007-08-04 23:24 7,040 –a–c— C:\WINDOWS\system32\dllcache\tandqic.sys
2007-08-04 23:24 69,632 –a–c— C:\WINDOWS\system32\dllcache\umaxu12.dll
2007-08-04 23:24 687,999 –a–c— C:\WINDOWS\system32\dllcache\usrwdxjs.sys
2007-08-04 23:24 64,605 –a–c— C:\WINDOWS\system32\dllcache\vvoice.sys
2007-08-04 23:24 604,253 –a–c— C:\WINDOWS\system32\dllcache\vmodem.sys
2007-08-04 23:24 59,264 –a–c— C:\WINDOWS\system32\dllcache\usbaudio.sys
2007-08-04 23:24 53,760 –a–c— C:\WINDOWS\system32\dllcache\sw_wheel.dll
2007-08-04 23:24 525,568 –a–c— C:\WINDOWS\system32\dllcache\tridxp.dll
2007-08-04 23:24 50,688 –a–c— C:\WINDOWS\system32\dllcache\umaxscan.dll
2007-08-04 23:24 50,176 –a–c— C:\WINDOWS\system32\dllcache\umaxp60.dll
2007-08-04 23:24 5,376 –a–c— C:\WINDOWS\system32\dllcache\viaide.sys
2007-08-04 23:24 47,616 –a–c— C:\WINDOWS\system32\dllcache\umaxcam.dll
2007-08-04 23:24 440,576 –a–c— C:\WINDOWS\system32\dllcache\tridkb.dll
2007-08-04 23:24 42,496 –a–c— C:\WINDOWS\system32\dllcache\tp4res.dll
2007-08-04 23:24 41,472 –a–c— C:\WINDOWS\system32\dllcache\sw_effct.dll
2007-08-04 23:24 4,992 –a–c— C:\WINDOWS\system32\dllcache\toside.sys
2007-08-04 23:24 397,502 –a–c— C:\WINDOWS\system32\dllcache\vpctcom.sys
2007-08-04 23:24 37,961 –a–c— C:\WINDOWS\system32\dllcache\tdk100b.sys
2007-08-04 23:24 36,736 –a–c— C:\WINDOWS\system32\dllcache\ultra.sys
2007-08-04 23:24 36,640 –a–c— C:\WINDOWS\system32\dllcache\t2r4mini.sys
2007-08-04 23:24 34,375 –a–c— C:\WINDOWS\system32\dllcache\tpro4.sys
2007-08-04 23:24 32,640 –a–c— C:\WINDOWS\system32\dllcache\symc8xx.sys
2007-08-04 23:24 32,384 –a–c— C:\WINDOWS\system32\dllcache\usb101et.sys
2007-08-04 23:24 315,520 –a–c— C:\WINDOWS\system32\dllcache\trid3d.dll
2007-08-04 23:24 31,744 –a–c— C:\WINDOWS\system32\dllcache\tp4.dll
2007-08-04 23:24 31,616 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-08-04 23:24 30,688 –a–c— C:\WINDOWS\system32\dllcache\sym_u3.sys
2007-08-04 23:24 30,464 –a–c— C:\WINDOWS\system32\dllcache\tbatm155.sys
2007-08-04 23:24 3,968 –a–c— C:\WINDOWS\system32\dllcache\swusbflt.sys
2007-08-04 23:24 29,311 –a–c— C:\WINDOWS\system32\dllcache\watv01nt.sys
2007-08-04 23:24 28,384 –a–c— C:\WINDOWS\system32\dllcache\sym_hi.sys
2007-08-04 23:24 28,232 –a–c— C:\WINDOWS\system32\dllcache\tos4mo.sys
2007-08-04 23:24 28,160 –a–c— C:\WINDOWS\system32\dllcache\umaxu40.dll
2007-08-04 23:24 26,624 –a–c— C:\WINDOWS\system32\dllcache\umaxu22.dll
2007-08-04 23:24 25,856 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2007-08-04 23:24 25,600 –a–c— C:\WINDOWS\system32\dllcache\usbser.sys
2007-08-04 23:24 249,402 –a–c— C:\WINDOWS\system32\dllcache\vinwm.sys
2007-08-04 23:24 241,664 –a–c— C:\WINDOWS\system32\dllcache\tosdvd02.sys
2007-08-04 23:24 24,576 –a–c— C:\WINDOWS\system32\dllcache\viairda.sys
2007-08-04 23:24 230,912 –a–c— C:\WINDOWS\system32\dllcache\tosdvd03.sys
2007-08-04 23:24 224,802 –a–c— C:\WINDOWS\system32\dllcache\usr1807a.sys
2007-08-04 23:24 222,336 –a–c— C:\WINDOWS\system32\dllcache\trid3dm.sys
2007-08-04 23:24 22,912 –a–c— C:\WINDOWS\system32\dllcache\umaxpcls.sys
2007-08-04 23:24 216,064 –a–c— C:\WINDOWS\system32\dllcache\um34scan.dll
2007-08-04 23:24 211,968 –a–c— C:\WINDOWS\system32\dllcache\um54scan.dll
2007-08-04 23:24 19,528 –a–c— C:\WINDOWS\system32\dllcache\w840nd.sys
2007-08-04 23:24 19,016 –a–c— C:\WINDOWS\system32\dllcache\w926nd.sys
2007-08-04 23:24 172,768 –a–c— C:\WINDOWS\system32\dllcache\t2r4disp.dll
2007-08-04 23:24 17,129 –a–c— C:\WINDOWS\system32\dllcache\tdkcd31.sys
2007-08-04 23:24 17,024 –a–c— C:\WINDOWS\system32\dllcache\usbohci.sys
2007-08-04 23:24 166,784 –a–c— C:\WINDOWS\system32\dllcache\tridxpm.sys
2007-08-04 23:24 16,925 –a–c— C:\WINDOWS\system32\dllcache\w940nd.sys
2007-08-04 23:24 16,256 –a–c— C:\WINDOWS\system32\dllcache\symc810.sys
2007-08-04 23:24 159,232 –a–c— C:\WINDOWS\system32\dllcache\tridkbm.sys
2007-08-04 23:24 149,376 –a–c— C:\WINDOWS\system32\dllcache\tffsport.sys
2007-08-04 23:24 138,528 –a–c— C:\WINDOWS\system32\dllcache\tgiulnt5.sys
2007-08-04 23:24 123,995 –a–c— C:\WINDOWS\system32\dllcache\tjisdn.sys
2007-08-04 23:24 12,415 –a–c— C:\WINDOWS\system32\dllcache\wadv01nt.sys
2007-08-04 23:24 12,127 –a–c— C:\WINDOWS\system32\dllcache\wadv02nt.sys
2007-08-04 23:24 113,762 –a–c— C:\WINDOWS\system32\dllcache\usrpda.sys
2007-08-04 23:24 11,775 –a–c— C:\WINDOWS\system32\dllcache\wadv05nt.sys


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-30 09:22 ——— d——– C:\Program Files\Trillian
2007-07-30 09:21 ——— d——– C:\Program Files\Common Files\Real
2007-07-30 09:20 ——— d——– C:\DOCUME~1\Vanessa\APPLIC~1\Real
2007-07-27 12:51 ——— d——– C:\Program Files\Google
2007-07-26 12:04 7517 –a—— C:\WINDOWS\mozver.dat
2007-05-16 12:12 86528 –a–c— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 12:12 85504 –a–c— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 12:12 683520 –a–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 12:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 12:12 510976 –a–c— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 12:12 1314816 –a–c— C:\WINDOWS\system32\dllcache\msoe.dll
2007-05-08 06:24 3583488 –a–c— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-04-06 10:56 2874926 –a—— C:\Program Files\FLV PlayerRCATSetup.exe
2007-04-06 10:56 25980320 –a—— C:\Program Files\FLV PlayerRCSetup.exe
2006-04-13 18:14 457 –a—— C:\Program Files\INSTALL.LOG


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 20:07 C:\WINDOWS\system32\HdAShCut.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-08-05 18:35]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 06:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:56]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2006-07-29 19:34]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-04-13 01:25:12]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-06 20:52:04]
Net Assistant.lnk - C:\Program Files\Aliant\Net Assistant\bin\matcli.exe [2006-09-20 14:26:08]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe
"IgfxTray"=C:\WINDOWS\System32\igfxtray.exe

S3 ICAM3NT5;Intel® PC Camera CS331;C:\WINDOWS\system32\Drivers\ICAM3D2.SYS
S3 mxnic;Macronix MX987xx Family Fast Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\mxnic.sys

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc


Contents of the 'Scheduled Tasks' folder
2007-08-05 10:34:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-08-05 13:14:58 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job - C:\Program Files\SpywareBot\SpywareBot.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-06 10:15:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts]
"Il\16\x0178A~yr\x2014|\x2039[ ?(?T?r?u?e?T?y?p?e?)?"="HDZB_96.TTF"
"Il\16\x178\x20ac{yr\x2014|\xd1\x17e ?(?T?r?u?e?T?y?p?e?)?"="HDZB_70.TTF"

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-06 10:16:17
C:\ComboFix-quarantined-files.txt … 2007-08-06 10:16
C:\ComboFix2.txt … 2007-08-05 20:48

— E O F —





Incident Status Location

Potentially unwanted tool:application/myway Not disinfected hkey_local_machine\software\MySearch
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Vanessa\Desktop\ComboFix.exe[nircmd.exe]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\fixwareout\FindT\nircmd.exe
Virus:Generic Malware Disinfected C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
Potentially unwanted tool:Application/Processor Not disinfected C:\QooBox\Quarantine\C\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\Process.exe.vir
Potentially unwanted tool:Application/SuperFast Not disinfected C:\QooBox\Quarantine\C\Documents and Settings\Vanessa\Desktop\SmitfraudFix\SmitfraudFix\restart.exe.vir
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:49:27 AM, on 06/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Vanessa\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Net Assistant.lnk = C:\Program Files\Aliant\Net Assistant\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1144882010222
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 6035 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI