This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Wrong

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Went away for a month leaving my bro to use my computer.. came home to multiple viruses and when trying to run hijack this.. the computer reboots.. cant get a log because of it.. any advice?
Reading over some of the other problems i see on this forum i get the same winantivirus and poker pop ups as some others.. but again.. every time i use hijack this the computer reboots on me.. running AVG antivirus and the stupid thing never finds anything.. ive never had this happen to me in 10 years of useing a computer.. sorry for the repost i just thought i should state that as well.. am i in alot of trouble here? because everything i run is going slower then usual.. all games i play seem to have a lag jump every 3 seconds.. if not more often untill i restart.. im running a duel core processer with a gforce 7800 i believe and 2g ram.. it shouldnt be laggy like it is… never has before.. wow i must be tired, over use of .. thanks to anyone who can help
A friend had told me about a program, Spyware Doctor, and after trying it i found that i had over 800 infections. Now that i have deleted them my computer doesnt restart useing hijack this..
I want to make sure theres nothing left on it so heres my hijack this log

Logfile of HijackThis v1.99.1
Scan saved at 9:54:48 PM, on 25/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\HP_Administrator\Desktop\spyware.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.torncity.com/
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Pop up Blocker] "C:\Program Files\Pop up Blocker\pd.exe" Minimize
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O20 - Winlogon Notify: awtsr - C:\WINDOWS\system32\awtsr.dll (file missing)
O20 - Winlogon Notify: byxvtrr - byxvtrr.dll (file missing)
O20 - Winlogon Notify: gebya - C:\WINDOWS\system32\gebya.dll (file missing)
O20 - Winlogon Notify: gebyv - C:\WINDOWS\system32\gebyv.dll (file missing)
O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
Hi StrikeDogg,

Can you tell me if your AVG Antivirus' real-time protection is active?

Move HijackThis from the desktop to it's own folder:
  • Open My Computer, navigate to C:\ and make a new folder named HJT
  • Move the spyware.exe program file from your desktop to C:\HJT
  • If you wish to place a shortcut to HijackThis on your desktop, then right-click spyware.exe, select Send To and choose Desktop (create shortcut)
Temporarily disable Spyware Doctor
Open Spyware Doctor, click the OnGuard button on the left side, press Click to deactivate OnGuard and OK the prompt
OnGuard will now be deactivated for 15 minutes, either complete the HijackThis instructions within that time or repeat this procedure

Then, open HijackThis, choose Do a system scan only and place a checkmark next to the following lines:

O4 - HKLM\..\Run: [smgr] mgrs.exe
O20 - Winlogon Notify: awtsr - C:\WINDOWS\system32\awtsr.dll (file missing)
O20 - Winlogon Notify: byxvtrr - byxvtrr.dll (file missing)
O20 - Winlogon Notify: gebya - C:\WINDOWS\system32\gebya.dll (file missing)
O20 - Winlogon Notify: gebyv - C:\WINDOWS\system32\gebyv.dll (file missing)
O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll (file missing)

Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

Make hidden/system files and folders visible:
Click Start -> My Computer
Select the Tools menu, click Folder Options and select the View tab
Under the Hidden files and folders heading SELECT Show hidden files and folders
UNCHECK the Hide extensions for known file types option
UNCHECK the Hide protected operating system files (recommended) option
Click Yes to confirm and press OK

Now click Start-> Search and select All files and folders
Copy/type this file name into the search box:
mgrs.exe
Then, under Look in: make sure Local Hard Drives is selected
Then click More advanced options, and ensure Search system folders, Search hidden files and folders and Search subfolders are all checked
Then press Search
When the search is complete, delete all files with the exact filename mgrs.exe

Then, please do an online scan with Kaspersky:

Open Kaspersky Online Scanner in Internet Explorer

You will be prompted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT and then Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • The program will start to scan your system.
  • Once the scan is complete, click on the Save as Text button and save the file to your desktop
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

Once complete, please post the Kaspersky report and a new HijackThis log.
AVG antivirus was only a trial period thing in a desperate attempt to fix my computer.. so im not surprised that its not active.
When i went to do the HJT scan, two of the O20 items you asked me to remove werent there and when i scanned my computer for mgrs.exe i found nothing as well… I even made sure that the files weren't hidden and it was searching every place possible.

Also Shaw provides an Antivirus/firewall program called Shaw Extended. I was wondering if you knew if that would be any good for my computer?

here is my Kapersky and HJT log once again

KASPERSKY ONLINE SCANNER REPORT
Monday, September 03, 2007 9:21:39 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 3/09/2007
Kaspersky Anti-Virus database records: 402881


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics
Total number of scanned objects 165166
Number of viruses found 10
Number of infected objects 20
Number of suspicious objects 0
Duration of the scan process 02:14:17

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\HP_Administrator\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\HP_Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\HP_Administrator\Local Settings\History\History.IE5\MSHist012007082720070903\index.dat Object is locked skipped

C:\Documents and Settings\HP_Administrator\Local Settings\History\History.IE5\MSHist012007090320070904\index.dat Object is locked skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Temp\18019C.tmp Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Temp\hsperfdata_HP_Administrator\3224 Object is locked skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Perflib_Perfdata_420.dat Object is locked skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5VR3U0DP\popup[1].htm Infected: Trojan-Clicker.HTML.Agent.a skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\5Z3B2VTJ\popup[1].htm Infected: Trojan-Clicker.HTML.Agent.a skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\NNP3N1KC\popup[1].htm Infected: Trojan-Clicker.HTML.Agent.a skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\VD09Z1VW\popup[1].htm Infected: Trojan-Clicker.HTML.Agent.a skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Temp\~DF9A30.tmp Object is locked skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\DXPRRVTD\wm[1].htm Object is locked skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ZB2EF23G\wm[1].htm Object is locked skipped

C:\Documents and Settings\HP_Administrator\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\HP_Administrator\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\HP_Administrator\Shared\Top of Charts - 2005.wma Infected: Trojan-Downloader.WMA.Wimad.k skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\hp\bin\KillWind.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped

C:\Program Files\mIRC\backup\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped

C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped

C:\Program Files\Yahoo!\Messenger\logs\billing_HP_Administrator.log Object is locked skipped

C:\Program Files\Yahoo!\Messenger\logs\client_HP_Administrator.log Object is locked skipped

C:\Program Files\Yahoo!\Messenger\logs\GIPS.log Object is locked skipped

C:\Program Files\Yahoo!\Messenger\logs\network_HP_Administrator.log Object is locked skipped

C:\Program Files\Yahoo!\Messenger\logs\p2pce.log Object is locked skipped

C:\Program Files\Yahoo!\Messenger\logs\voice.log Object is locked skipped

C:\Program Files\Yahoo!\Messenger\logs\YSDP.log Object is locked skipped

C:\Program Files\Yahoo!\Messenger\logs\YSIP.log Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP340\A0056680.dll Infected: not-a-virus:AdWare.Win32.HotBar.cc skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP345\A0059994.exe Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP348\A0064038.dll Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP349\A0064380.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.612 skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP351\A0065071.dll Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP351\A0065088.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP353\A0066088.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP353\A0066089.dll Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP359\A0067104.dll Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP359\A0067111.dll Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP359\A0067112.dll Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP360\A0067124.dll Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP360\A0067125.dll Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP366\A0068197.dll Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP370\A0070212.exe Infected: Trojan.Win32.Agent.aoy skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP384\A0077281.exe Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP393\A0083509.sys Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP397\A0083711.dll Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP397\A0083712.dll Object is locked skipped

C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP406\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\pfirewall.log Object is locked skipped

C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{FC9541F2-B22D-4E22-9679-0B934779C57D}.crmlog Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{4817F5C6-977A-4177-AA3C-145E844CCC35}.bin Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\awfyecbm.exe Infected: Trojan.Win32.Agent.aoy skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\IntelDH.evt Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\eeptxwwp.exe Infected: Trojan.Win32.Agent.aoy skipped

C:\WINDOWS\system32\ghneqaqh.exe Infected: Trojan.Win32.Agent.aoy skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped

C:\WINDOWS\system32\lqfruygn.exe Infected: Trojan.Win32.Agent.aoy skipped

C:\WINDOWS\system32\vnebyaiv.exe Infected: Trojan.Win32.Agent.aoy skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\system32\wmbawajf.exe Infected: Trojan.Win32.Agent.aoy skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


Logfile of HijackThis v1.99.1
Scan saved at 8:01:47 PM, on 03/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\LVComsX.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\HJT\spyware.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.torncity.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Pop up Blocker] "C:\Program Files\Pop up Blocker\pd.exe" Minimize
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
Hi StrikeDogg,

You need an active antivirus program installed immediately. Without antivirus software your computer is very vulnerable and can easily be infected at any time so it it is essential you have one active at all times.

I can't say much about Shaw Extended as I am not familiar with it, but if you would like to use it then please go ahead. My personal recommendation is Antivir because it has good detection rates, is light on resources and free - but any reputable antivirus with real-time protection will do.

Please uninstall the inactive AVG program(s) you currently have via Start->Control Panel->Add/Remove programs.
Then, install a new package - there are several free programs available, two of the most popular are here:
Antivir: http://www.free-av.com/
AVG Free Antivirus: http://free.grisoft.com/doc/1

Update the definitions and set the program to update automatically. Then do a full system scan and quarantine/delete anything it finds, and make a note of where the logfile is stored so you can post a copy in your next response.

You have LimeWire, a P2P file sharing program installed on your computer. This program does not come bundled with malware as some similar programs do, but peer-to-peer file sharing networks are one of the biggest sources of malware we see. Anything downloaded from them cannot be trusted to be clean, because even if the file appears to be what it claims to be, it can have malware embedded in it.
I recommend you remove it, but of course the choice is yours.
You can remove Limewire via Add/Remove Programs.

Kaspersky has flagged an IRC chat program called mIRC, this is only a concern if you didn't install this yourself - please let me know if this is the case.

Next click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Recycle Bin, Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Press OK and Yes to confirm

Then download ComboFix to your desktop
  • Double click combofix.exe and follow the prompts.
  • Note: Do not click ComboFix's window while it's running - it may cause it to stall!
  • When finished, it shall produce a log for you, please post it in your next response.
Once complete, please post the antivirus scan log, the ComboFix log and a new HijackThis log.
done done and done

mIRC was installed by me but if it could be a problem it will be gone shortly just let me know

is there a P2P program that maybe scans files before downloading? or recieving a file?


here are the new logs



AntiVir PersonalEdition Classic
Report file date: 2007-09-04 00:31

Scanning for 1043410 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: HP_Administrator
Computer name: TYLER

Version information:
BUILD.DAT : 247 14437 Bytes 5/10/2007 11:55:00
AVSCAN.EXE : 7.0.4.15 282664 Bytes 4/20/2007 19:37:14
AVSCAN.DLL : 7.0.4.4 33832 Bytes 3/27/2007 19:31:54
LUKE.DLL : 7.0.4.11 143400 Bytes 3/27/2007 19:26:04
LUKERES.DLL : 7.0.4.0 10280 Bytes 3/19/2007 19:18:59
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 5/31/2006 21:08:58
ANTIVIR1.VDF : 6.39.0.129 7251968 Bytes 7/10/2007 05:02:26
ANTIVIR2.VDF : 6.39.1.74 1637376 Bytes 9/2/2007 05:02:26
ANTIVIR3.VDF : 6.39.1.81 20992 Bytes 9/3/2007 05:02:26
AVEWIN32.DLL : 7.4.1.66 2789888 Bytes 9/4/2007 05:02:26
AVWINLL.DLL : 1.0.0.7 14376 Bytes 2/26/2007 17:36:26
AVPREF.DLL : 7.0.2.1 24616 Bytes 3/27/2007 19:31:50
AVREP.DLL : 7.0.0.1 155688 Bytes 4/16/2007 20:16:24
AVPACK32.DLL : 7.3.0.15 360488 Bytes 9/4/2007 05:02:26
AVREG.DLL : 7.0.1.2 31784 Bytes 3/15/2007 16:05:08
AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 3/27/2007 19:16:05
AVARKT.DLL : 1.0.0.17 278568 Bytes 5/2/2007 18:32:26
NETNT.DLL : 7.0.0.0 7720 Bytes 3/8/2007 18:09:42
RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 3/13/2007 17:46:18
RCTEXT.DLL : 7.0.45.0 86056 Bytes 3/19/2007 19:42:42

Configuration settings for the scan:
Jobname……………………..: Local Drives
Configuration file……………: C:\Program Files\AntiVir PersonalEdition Classic\alldrives.avp
Logging……………………..: low
Primary action……………….: interactive
Secondary action……………..: ignore
Scan master boot sector……….: off
Scan boot sector……………..: on
Boot sectors…………………: E:,
Scan memory………………….: on
Process scan…………………: on
Scan registry………………..: on
Search for rootkits…………..: off
Scan all files……………….: Intelligent file selection
Scan archives………………..: on
Recursion depth………………: 20
Smart extensions……………..: on
Macro heuristic………………: on
File heuristic……………….: medium

Start of the scan: 2007-09-04 00:31

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'cmd.exe' - '1' Module(s) have been scanned
Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'realsched.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'dllhost.exe' - '1' Module(s) have been scanned
Scan process 'ELService.exe' - '1' Module(s) have been scanned
Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'swdsvc.exe' - '1' Module(s) have been scanned
Scan process 'svcntaux.exe' - '1' Module(s) have been scanned
Scan process 'PnkBstrA.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'MDM.EXE' - '1' Module(s) have been scanned
Scan process 'IAANTMon.exe' - '1' Module(s) have been scanned
Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
40 processes with 40 modules were scanned

Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!
Boot sector 'F:\'
[NOTE] In the drive 'F:\' no data medium is inserted!
Boot sector 'G:\'
[NOTE] In the drive 'G:\' no data medium is inserted!
Boot sector 'H:\'
[NOTE] In the drive 'H:\' no data medium is inserted!
Boot sector 'I:\'
[NOTE] In the drive 'I:\' no data medium is inserted!

Starting to scan the registry.
The registry was scanned ( '15' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5VR3U0DP\popup[1].htm
[DETECTION] Contains signature of the exploits EXP/Agent.B
[INFO] The file was deleted!
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\5Z3B2VTJ\popup[1].htm
[DETECTION] Contains signature of the exploits EXP/Agent.B
[INFO] The file was deleted!
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\NNP3N1KC\popup[1].htm
[DETECTION] Contains signature of the exploits EXP/Agent.B
[INFO] The file was deleted!
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\VD09Z1VW\popup[1].htm
[DETECTION] Contains signature of the exploits EXP/Agent.B
[INFO] The file was deleted!
C:\Documents and Settings\HP_Administrator\Shared4 Track 4 (love).wma
[DETECTION] Is the Trojan horse TR/Wimad.A.Gen
[INFO] The file was deleted!
C:\Documents and Settings\HP_Administrator\Shared5 Track 5 (monkey).wma
[DETECTION] Is the Trojan horse TR/Wimad.A.Gen
[INFO] The file was deleted!
C:\Documents and Settings\HP_Administrator\Shared5 Track 5.wma
[DETECTION] Is the Trojan horse TR/Wimad.A.Gen
[INFO] The file was deleted!
C:\WINDOWS\system32\awfyecbm.exe
[DETECTION] Is the Trojan horse TR/Fotomoto.A
[INFO] The file was deleted!
C:\WINDOWS\system32\eeptxwwp.exe
[DETECTION] Is the Trojan horse TR/Fotomoto.A
[INFO] The file was deleted!
C:\WINDOWS\system32\frdxwwik.dll
[DETECTION] Is the Trojan horse TR/JuanSearch.C.1
[INFO] The file was deleted!
C:\WINDOWS\system32\ghneqaqh.exe
[DETECTION] Is the Trojan horse TR/Fotomoto.A
[INFO] The file was deleted!
C:\WINDOWS\system32\lqfruygn.exe
[DETECTION] Is the Trojan horse TR/Fotomoto.A
[INFO] The file was deleted!
C:\WINDOWS\system32\ovootivk.dll
[DETECTION] Is the Trojan horse TR/JuanSearch.C.1
[INFO] The file was deleted!
C:\WINDOWS\system32\vnebyaiv.exe
[DETECTION] Is the Trojan horse TR/Fotomoto.A
[INFO] The file was deleted!
C:\WINDOWS\system32\wmbawajf.exe
[DETECTION] Is the Trojan horse TR/Fotomoto.A
[INFO] The file was deleted!
C:\WINDOWS\system32\ActiveScan\pskavs.dll
[DETECTION] Contains signature of the Windows virus W95/Blumblebee.1738
[INFO] The file was deleted!
Begin scan in 'D:\'
Begin scan in 'F:\'
Search path F:\ could not be opened!
The device is not ready.

Begin scan in 'G:\'
Search path G:\ could not be opened!
The device is not ready.

Begin scan in 'H:\'
Search path H:\ could not be opened!
The device is not ready.

Begin scan in 'I:\'
Search path I:\ could not be opened!
The device is not ready.

Begin scan in 'E:\'


End of the scan: 2007-09-04 01:33
Used time: 1:01:20 min

The scan has been done completely.

10765 Scanning directories
590164 Files were scanned
16 viruses and/or unwanted programs were found
0 classified as suspicious:
16 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
590148 Files not concerned
16829 Archives were scanned
2 Warnings
28 Notes
0 Hidden objects were found


ComboFix 07-08-30.3 - "HP_Administrator" 2007-09-04 3:53:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1533 [GMT -6:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\cookies.ini
C:\WINDOWS\curity~1
C:\WINDOWS\curity~1\??curity\
C:\WINDOWS\wr.txt
D:\Autorun.inf


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\kprof


((((((((((((((((((((((((( Files Created from 2007-08-04 to 2007-09-04 )))))))))))))))))))))))))))))))


2007-09-03 22:47 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AntiVir PersonalEdition Classic
2007-09-03 22:38 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-09-03 04:35 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-09-03 04:35 d——– C:\WINDOWS\LastGood.Tmp
2007-09-03 04:35 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-03 04:30 d——– C:\HJT
2007-09-01 00:14 d——– C:\Program Files\Pool Buddy Yahoo
2007-09-01 00:14 d——– C:\Program Files\Common Files\eSellerate
2007-08-29 00:17 66,872 –a—— C:\WINDOWS\system32\PnkBstrA.exe
2007-08-29 00:17 22,328 –a—— C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-08-29 00:17 103,736 –a—— C:\WINDOWS\system32\PnkBstrB.exe
2007-08-25 10:33 d——– C:\Program Files\Common Files\xing shared
2007-08-25 09:41 945,629 —hs—- C:\WINDOWS\system32\vybeg.ini2
2007-08-25 09:38 82,248 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-08-25 09:38 57,672 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-08-25 09:38 40,264 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-08-25 09:38 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-08-25 09:38 d——– C:\Program Files\Spyware Doctor
2007-08-25 09:38 d——– C:\DOCUME~1\HP_ADM~1\APPLIC~1\PC Tools
2007-08-25 09:31 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
2007-08-25 09:23 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-08-18 02:33 d——– C:\Program Files\Pop up Blocker
2007-08-18 02:08 d——– C:\Program Files\EndItAll
2007-08-15 03:03 d——– C:\d399028eba6c69d6fbb0d7c5


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-28 23:53 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-25 10:33 ——— d——– C:\Program Files\Common Files\Real
2007-08-25 09:36 ——— d——– C:\Program Files\Google
2007-08-22 22:29 ——— d——– C:\DOCUME~1\HP_ADM~1\APPLIC~1\Ventrilo
2007-08-22 19:20 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-22 19:15 ——— d——– C:\Program Files\Yahoo! Games
2007-08-22 19:15 ——— d——– C:\Program Files\DivX
2007-08-22 19:14 ——— d——– C:\Program Files\Deer Hunter 3
2007-08-22 19:14 ——— d——– C:\Program Files\Conquer 2.0
2007-08-17 18:46 ——— d——– C:\Program Files\World of Warcraft
2007-08-03 20:27 1017361 –ahs—- C:\WINDOWS\system32\aybeg.bak1
2007-08-02 20:27 1021705 –ahs—- C:\WINDOWS\system32\aybeg.bak2
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\dllcache\wups.dll
2007-07-28 08:20 1017499 –ahs—- C:\WINDOWS\system32\rstwa.ini2
2007-07-28 08:18 1019665 –ahs—- C:\WINDOWS\system32\rstwa.bak2
2007-07-19 00:59 3583488 –a—— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-17 16:24 1192262 –ahs—- C:\WINDOWS\system32\rstwa.bak1
2007-07-16 18:40 ——— d——– C:\Program Files\Warcraft III
2007-07-15 10:34 ——— d——– C:\Program Files\WinPcap
2007-07-13 04:54 ——— d——– C:\Program Files\music_now
2007-07-13 04:54 ——— d——– C:\Program Files\Hero_Online
2007-07-12 18:05 ——— d——– C:\Program Files\WinAce
2007-07-12 17:31 765952 –a—— C:\WINDOWS\system32\dllcache\vgx.dll
2007-07-12 13:11 ——— d——– C:\Program Files\Quicken
2007-07-12 04:47 ——— d——– C:\Program Files\Power MP3 WMA Converter
2007-07-12 04:45 ——— d——– C:\Program Files\MSN Messenger
2007-07-12 04:30 ——— d-a—— C:\Program Files\Common Files\LightScribe
2007-07-12 04:29 ——— d——– C:\Program Files\AIM
2007-06-27 08:34 823808 –a—— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 08:34 671232 –a—— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 08:34 6058496 ——— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 08:34 52224 ——— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 08:34 477696 –a—— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 08:34 459264 ——— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 08:34 44544 –a—— C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 08:34 384512 –a—— C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 08:34 383488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 08:34 27648 –a—— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 08:34 267776 ——— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 08:34 232960 –a—— C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 08:34 230400 –a—— C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 08:34 193024 –a—— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 08:34 153088 –a—— C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 08:34 132608 –a—— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 08:34 124928 –a—— C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 08:34 1152000 –a—— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 08:34 105984 –a—— C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 08:34 102400 –a—— C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 02:27 63488 –a—— C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 02:27 625152 –a—— C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 02:27 13824 ——— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 01:00 161792 –a—— C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 22:10 317440 –a—— C:\WINDOWS\system32\dllcache\unregmp2.exe
2007-06-26 00:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-26 00:08 1104896 –a—— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 07:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-19 07:31 282112 –a—— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-13 04:23 1033216 –a—— C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 04:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-06-11 23:51 10834944 –a—— C:\WINDOWS\system32\dllcache\wmp.dll
2007-01-18 18:16 774144 –a—— C:\Program Files\RngInterstitial.dll
2005-09-24 02:49 12288 –a–c— C:\WINDOWS\Fonts.\RandFont.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCDrProfiler"="" []
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-14 08:51]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-08-25 10:32]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-08-14 17:02]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 10:35]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 15:00]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2006-01-24 11:37]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-07-27 01:27]
"AIM"="C:\Program Files\AIM\aim.exe" [2004-08-10 08:37]
"Steam"="" []
"Pop up Blocker"="C:\Program Files\Pop up Blocker\pd.exe" [2007-01-12 15:43]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-25 09:31]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"



[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7d23be63-d96d-11db-aa66-00173135ac37}]
AutoRun\command- J:\JDSecure\Windows\JDSecure20.exe

*Newly Created Service* - SSMDRV

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-04 03:58:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-04 4:02:20 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-04 04:02

— E O F —


Logfile of HijackThis v1.99.1
Scan saved at 4:10:29 AM, on 04/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\spyware.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.torncity.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Pop up Blocker] "C:\Program Files\Pop up Blocker\pd.exe" Minimize
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe




Thanks alot
Hi StrikeDogg,

Great work, things look a lot better :)
No problem whatsoever with mIRC - it's only a worry if you didn't know it was there :)
P2P downloads are inherently dangerous because you don't know the source of the files. Scanning is a good idea but unfortunately it won't catch everything. I recommend you get whatever files you download from other sources for safety reasons.

You have some bad files from an old infection lurking around so we'll get rid of those, I'd also like to check a file:

Please upload a file for scanning:
Open http://virusscan.jotti.org/
Copy/paste this file and path into the white box at the top:

C:\WINDOWS\Fonts.\RandFont.dll

Press Submit - this will submit the file for testing.
Please wait for all the scanners to finish then copy and paste the results in your next response.

Note: If Jotti is busy, you can use VirusTotal instead.

————————————————————————
  • Check that combofix.exe is on your Desktop
  • Then open Notepad: press Start->Run, type notepad and click OK
  • Copy/paste the contents of the below code box into Notepad:
    File::
    C:\Documents and Settings\HP_Administrator\Local Settings\Temp\18019C.tmp
    C:\Documents and Settings\HP_Administrator\Shared\Top of Charts - 2005.wma
    C:\WINDOWS\system32\vybeg.ini2
    C:\WINDOWS\system32\aybeg.bak1
    C:\WINDOWS\system32\aybeg.bak2
    C:\WINDOWS\system32\rstwa.ini2
    C:\WINDOWS\system32\rstwa.bak2
    C:\WINDOWS\system32\rstwa.bak1
    
    DirLook::
    C:\d399028eba6c69d6fbb0d7c5
    C:\WINDOWS\Fonts.
    
    FileLook::
    C:\WINDOWS\Fonts.\RandFont.dll
  • Save this to your Desktop as CFScript.

    [external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
Note: Do not click ComboFix's window while it's running - it may cause it to stall!

————————————————————————

Once complete, please post the new ComboFix report and another HijackThis log.
Also, let me know how your machine is running.
Did everything you said and the computer didnt reboot making me think it didnt find anything..

im heading off to work here soon and havnt really had a chance to test the machiene on how its running in a couple days.. ill let you know tonight

Logs:

Service load: 0% 100%

File: RandFont.dll
Status: OK
MD5: bce1f66d076acbbb7d67dda6656ecf06
Packers detected: -
Bit9 reports: No threat detected (more info)

Scanner results
Scan taken on 04 Sep 2007 13:59:08 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing



ComboFix 07-08-30.3 - "HP_Administrator" 2007-09-04 8:02:46.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1556 [GMT -6:00]
* Created a new restore point

FILE::
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\18019C.tmp
C:\Documents and Settings\HP_Administrator\Shared\Top of Charts - 2005.wma
C:\WINDOWS\system32\vybeg.ini2
C:\WINDOWS\system32\aybeg.bak1
C:\WINDOWS\system32\aybeg.bak2
C:\WINDOWS\system32\rstwa.ini2
C:\WINDOWS\system32\rstwa.bak2
C:\WINDOWS\system32\rstwa.bak1


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\HP_Administrator\Shared\Top of Charts - 2005.wma
C:\WINDOWS\system32\aybeg.bak1
C:\WINDOWS\system32\aybeg.bak2
C:\WINDOWS\system32\rstwa.bak1
C:\WINDOWS\system32\rstwa.bak2
C:\WINDOWS\system32\rstwa.ini2
C:\WINDOWS\system32\vybeg.ini2


((((((((((((((((((((((((( Files Created from 2007-08-04 to 2007-09-04 )))))))))))))))))))))))))))))))


2007-09-03 22:47 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AntiVir PersonalEdition Classic
2007-09-03 22:38 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-09-03 04:35 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-09-03 04:35 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-03 04:30 d——– C:\HJT
2007-09-01 00:14 d——– C:\Program Files\Pool Buddy Yahoo
2007-09-01 00:14 d——– C:\Program Files\Common Files\eSellerate
2007-08-29 00:17 66,872 –a—— C:\WINDOWS\system32\PnkBstrA.exe
2007-08-29 00:17 22,328 –a—— C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-08-29 00:17 103,736 –a—— C:\WINDOWS\system32\PnkBstrB.exe
2007-08-25 10:33 d——– C:\Program Files\Common Files\xing shared
2007-08-25 09:38 82,248 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-08-25 09:38 57,672 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-08-25 09:38 40,264 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-08-25 09:38 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-08-25 09:38 d——– C:\Program Files\Spyware Doctor
2007-08-25 09:38 d——– C:\DOCUME~1\HP_ADM~1\APPLIC~1\PC Tools
2007-08-25 09:31 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
2007-08-25 09:23 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-08-18 02:33 d——– C:\Program Files\Pop up Blocker
2007-08-18 02:08 d——– C:\Program Files\EndItAll
2007-08-15 03:03 d——– C:\d399028eba6c69d6fbb0d7c5


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-28 23:53 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-25 10:33 ——— d——– C:\Program Files\Common Files\Real
2007-08-25 09:36 ——— d——– C:\Program Files\Google
2007-08-22 22:29 ——— d——– C:\DOCUME~1\HP_ADM~1\APPLIC~1\Ventrilo
2007-08-22 19:20 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-22 19:15 ——— d——– C:\Program Files\Yahoo! Games
2007-08-22 19:15 ——— d——– C:\Program Files\DivX
2007-08-22 19:14 ——— d——– C:\Program Files\Deer Hunter 3
2007-08-22 19:14 ——— d——– C:\Program Files\Conquer 2.0
2007-08-17 18:46 ——— d——– C:\Program Files\World of Warcraft
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\dllcache\wups.dll
2007-07-19 00:59 3583488 –a—— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-16 18:40 ——— d——– C:\Program Files\Warcraft III
2007-07-15 10:34 ——— d——– C:\Program Files\WinPcap
2007-07-13 04:54 ——— d——– C:\Program Files\music_now
2007-07-13 04:54 ——— d——– C:\Program Files\Hero_Online
2007-07-12 18:05 ——— d——– C:\Program Files\WinAce
2007-07-12 17:31 765952 –a—— C:\WINDOWS\system32\dllcache\vgx.dll
2007-07-12 13:11 ——— d——– C:\Program Files\Quicken
2007-07-12 04:47 ——— d——– C:\Program Files\Power MP3 WMA Converter
2007-07-12 04:45 ——— d——– C:\Program Files\MSN Messenger
2007-07-12 04:30 ——— d-a—— C:\Program Files\Common Files\LightScribe
2007-07-12 04:29 ——— d——– C:\Program Files\AIM
2007-06-27 08:34 823808 –a—— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 08:34 671232 –a—— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 08:34 6058496 ——— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 08:34 52224 ——— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 08:34 477696 –a—— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 08:34 459264 ——— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 08:34 44544 –a—— C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 08:34 384512 –a—— C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 08:34 383488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 08:34 27648 –a—— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 08:34 267776 ——— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 08:34 232960 –a—— C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 08:34 230400 –a—— C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 08:34 193024 –a—— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 08:34 153088 –a—— C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 08:34 132608 –a—— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 08:34 124928 –a—— C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 08:34 1152000 –a—— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 08:34 105984 –a—— C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 08:34 102400 –a—— C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 02:27 63488 –a—— C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 02:27 625152 –a—— C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 02:27 13824 ——— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 01:00 161792 –a—— C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 22:10 317440 –a—— C:\WINDOWS\system32\dllcache\unregmp2.exe
2007-06-26 00:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-26 00:08 1104896 –a—— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 07:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-19 07:31 282112 –a—— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-13 04:23 1033216 –a—— C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 04:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-06-11 23:51 10834944 –a—— C:\WINDOWS\system32\dllcache\wmp.dll
2007-01-18 18:16 774144 –a—— C:\Program Files\RngInterstitial.dll
2005-09-24 02:49 12288 –a–c— C:\WINDOWS\Fonts.\RandFont.dll


(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))


—- C:\WINDOWS\Fonts.\RandFont.dll —-

Company: Hewlett-Packard Development Company, L.P.
File Description: dll for non-versioned MSI files
File Version: 60.0.155.000
Product Name: hp digital imaging
Copyright: Copyright © Hewlett-Packard Development Company, L.P. 1995-2005
Original file name: hpq00.dll

—- Directory of C:\d399028eba6c69d6fbb0d7c5 —-

2007-08-15 03:03 788 –ah—– C:\d399028eba6c69d6fbb0d7c5\$shtdwn$.req
2007-08-02 21:41 865822 –a—— C:\d399028eba6c69d6fbb0d7c5\mrt.exe._p
2007-08-02 21:34 96216 –a—— C:\d399028eba6c69d6fbb0d7c5\mrtstub.exe

—- Directory of C:\WINDOWS\Fonts. —-

2005-09-24 02:49 12288 –a–c— C:\WINDOWS\Fonts.\RandFont.dll
2005-08-30 15:01 67 –ahs—- C:\WINDOWS\Fonts.\desktop.ini
2005-05-12 20:52 64472 –a—— C:\WINDOWS\Fonts.\TahomSCB.TTF
2005-05-12 20:52 59456 –a—— C:\WINDOWS\Fonts.\SCRIPTBL.TTF
2005-05-12 20:52 183172 –a—— C:\WINDOWS\Fonts.\Verdana.TTF
2005-05-12 20:52 171596 –a—— C:\WINDOWS\Fonts.\Verdanai.TTF
2005-05-12 20:52 170172 –a—— C:\WINDOWS\Fonts.\Verdanaz.TTF
2005-05-12 20:52 162236 –a—— C:\WINDOWS\Fonts.\Georgiaz.TTF
2005-05-12 20:52 160272 –a—— C:\WINDOWS\Fonts.\Georgiai.TTF
2005-05-12 20:52 154960 –a—— C:\WINDOWS\Fonts.\Georgia.TTF
2005-05-12 20:52 150364 –a—— C:\WINDOWS\Fonts.\Verdanab.TTF
2005-05-12 20:52 143836 –a—— C:\WINDOWS\Fonts.\Georgiab.TTF
2005-05-12 20:52 129196 –a—— C:\WINDOWS\Fonts.\Comic.TTF
2005-05-12 20:52 113824 –a—— C:\WINDOWS\Fonts.\Comicbd.TTF
2005-02-24 01:59 57748 -ra—— C:\WINDOWS\Fonts.\STONSSBB.TTF
2005-02-24 01:59 56876 -ra—— C:\WINDOWS\Fonts.\STONSSBA.TTF
2005-02-24 01:59 49644 -ra—— C:\WINDOWS\Fonts.\STONSSBC.TTF
2005-02-24 01:59 47880 -ra—— C:\WINDOWS\Fonts.\FRUTSI_B.TTF
2005-02-24 01:59 47636 -ra—— C:\WINDOWS\Fonts.\FRUTSR_B.TTF
2005-02-24 01:59 47352 -ra—— C:\WINDOWS\Fonts.\FRUTSB_B.TTF
2005-02-24 01:59 47216 -ra—— C:\WINDOWS\Fonts.\FRUTSI_A.TTF
2005-02-24 01:59 47100 -ra—— C:\WINDOWS\Fonts.\FRUTSR_A.TTF
2005-02-24 01:59 46752 -ra—— C:\WINDOWS\Fonts.\FRUTSB_A.TTF
2005-02-24 01:59 41028 -ra—— C:\WINDOWS\Fonts.\FRUTSI_C.TTF
2005-02-24 01:59 41016 -ra—— C:\WINDOWS\Fonts.\FRUTSR_C.TTF
2005-02-24 01:59 40880 -ra—— C:\WINDOWS\Fonts.\FRUTSB_C.TTF
2004-09-23 08:19 152700 –a—— C:\WINDOWS\Fonts.\frabk.ttf
2004-08-09 15:00 9856 –ah-c— C:\WINDOWS\Fonts.\8514sysg.fon
2004-08-09 15:00 98256 –ah-c— C:\WINDOWS\Fonts.\sseriffr.fon
2004-08-09 15:00 9792 –ah-c— C:\WINDOWS\Fonts.\8514syst.fon
2004-08-09 15:00 9504 –ah-c— C:\WINDOWS\Fonts.\8514syse.fon
2004-08-09 15:00 9472 –ah-c— C:\WINDOWS\Fonts.\85s1257.fon
2004-08-09 15:00 9280 –ah-c— C:\WINDOWS\Fonts.\8514sys.fon
2004-08-09 15:00 9248 –ah-c— C:\WINDOWS\Fonts.\ega40869.fon
2004-08-09 15:00 9248 –ah-c— C:\WINDOWS\Fonts.\ega40737.fon
2004-08-09 15:00 9232 –ah-c— C:\WINDOWS\Fonts.\ega40866.fon
2004-08-09 15:00 92032 –ah-c— C:\WINDOWS\Fonts.\sseriffe.fon
2004-08-09 15:00 90736 –ah-c— C:\WINDOWS\Fonts.\seriffr.fon
2004-08-09 15:00 90336 –ah-c— C:\WINDOWS\Fonts.\ssef1257.fon
2004-08-09 15:00 90288 –ah-c— C:\WINDOWS\Fonts.\sseriffg.fon
2004-08-09 15:00 89856 –ah-c— C:\WINDOWS\Fonts.\sseriff.fon
2004-08-09 15:00 89456 –ah-c— C:\WINDOWS\Fonts.\sserifft.fon
2004-08-09 15:00 8704 –ah-c— C:\WINDOWS\Fonts.\ega40857.fon
2004-08-09 15:00 8704 –a—— C:\WINDOWS\Fonts.\modern.fon
2004-08-09 15:00 86256 –ah-c— C:\WINDOWS\Fonts.\seriffg.fon
2004-08-09 15:00 85360 –ah-c— C:\WINDOWS\Fonts.\seriffe.fon
2004-08-09 15:00 84848 –ah-c— C:\WINDOWS\Fonts.\serifft.fon
2004-08-09 15:00 84080 –ah-c— C:\WINDOWS\Fonts.\serf1257.fon
2004-08-09 15:00 8384 –ah-c— C:\WINDOWS\Fonts.\ega40850.fon
2004-08-09 15:00 8368 –ah-c— C:\WINDOWS\Fonts.\ega40852.fon
2004-08-09 15:00 8368 –ah—– C:\WINDOWS\Fonts.\ega40woa.fon
2004-08-09 15:00 81728 –ah-c— C:\WINDOWS\Fonts.\seriff.fon
2004-08-09 15:00 81000 –a—— C:\WINDOWS\Fonts.\wingding.ttf
2004-08-09 15:00 79744 –a—— C:\WINDOWS\Fonts.\estre.ttf
2004-08-09 15:00 73292 –a—— C:\WINDOWS\Fonts.\latha.ttf
2004-08-09 15:00 7280 –ah—– C:\WINDOWS\Fonts.\vgasys.fon
2004-08-09 15:00 7232 –ah-c— C:\WINDOWS\Fonts.\cga40866.fon
2004-08-09 15:00 7216 –ah-c— C:\WINDOWS\Fonts.\cga40869.fon
2004-08-09 15:00 7216 –ah-c— C:\WINDOWS\Fonts.\cga40737.fon
2004-08-09 15:00 7008 –ah-c— C:\WINDOWS\Fonts.\vgasysg.fon
2004-08-09 15:00 69464 –a—— C:\WINDOWS\Fonts.\symbol.ttf
2004-08-09 15:00 6912 –ah-c— C:\WINDOWS\Fonts.\vgasyst.fon
2004-08-09 15:00 6912 –ah-c— C:\WINDOWS\Fonts.\vgasysr.fon
2004-08-09 15:00 68848 –ah-c— C:\WINDOWS\Fonts.\sserifer.fon
2004-08-09 15:00 6672 –ah-c— C:\WINDOWS\Fonts.\cga40857.fon
2004-08-09 15:00 6672 –ah-c— C:\WINDOWS\Fonts.\cga40852.fon
2004-08-09 15:00 6656 –ah-c— C:\WINDOWS\Fonts.\vgas1257.fon
2004-08-09 15:00 66464 –ah-c— C:\WINDOWS\Fonts.\sserifee.fon
2004-08-09 15:00 6608 –ah-c— C:\WINDOWS\Fonts.\vgasyse.fon
2004-08-09 15:00 65456 –ah-c— C:\WINDOWS\Fonts.\ssee1257.fon
2004-08-09 15:00 65328 –ah-c— C:\WINDOWS\Fonts.\sserifeg.fon
2004-08-09 15:00 64656 –ah—– C:\WINDOWS\Fonts.\sserife.fon
2004-08-09 15:00 64400 –ah-c— C:\WINDOWS\Fonts.\sserifet.fon
2004-08-09 15:00 6352 –ah-c— C:\WINDOWS\Fonts.\cga40850.fon
2004-08-09 15:00 6336 –ah—– C:\WINDOWS\Fonts.\cga40woa.fon
2004-08-09 15:00 63296 –ah-c— C:\WINDOWS\Fonts.\serifer.fon
2004-08-09 15:00 6192 –ah-c— C:\WINDOWS\Fonts.\ega80869.fon
2004-08-09 15:00 6192 –ah-c— C:\WINDOWS\Fonts.\ega80737.fon
2004-08-09 15:00 6160 –ah-c— C:\WINDOWS\Fonts.\vga852.fon
2004-08-09 15:00 6128 –ah-c— C:\WINDOWS\Fonts.\vga866.fon
2004-08-09 15:00 6112 –ah-c— C:\WINDOWS\Fonts.\vgafixt.fon
2004-08-09 15:00 6112 –ah-c— C:\WINDOWS\Fonts.\vgafixg.fon
2004-08-09 15:00 61024 –ah-c— C:\WINDOWS\Fonts.\serifet.fon
2004-08-09 15:00 60752 –ah-c— C:\WINDOWS\Fonts.\serifeg.fon
2004-08-09 15:00 59952 –ah-c— C:\WINDOWS\Fonts.\serifee.fon
2004-08-09 15:00 59024 –ah-c— C:\WINDOWS\Fonts.\sere1257.fon
2004-08-09 15:00 57936 –ah—– C:\WINDOWS\Fonts.\serife.fon
2004-08-09 15:00 57348 –a—— C:\WINDOWS\Fonts.\raavi.ttf
2004-08-09 15:00 5648 –ah-c— C:\WINDOWS\Fonts.\ega80857.fon
2004-08-09 15:00 56336 –ah—– C:\WINDOWS\Fonts.\symbole.fon
2004-08-09 15:00 5600 –ah-c— C:\WINDOWS\Fonts.\vgafixr.fon
2004-08-09 15:00 5552 –ah-c— C:\WINDOWS\Fonts.\vga857.fon
2004-08-09 15:00 5376 –ah-c— C:\WINDOWS\Fonts.\vgafixe.fon
2004-08-09 15:00 5376 –ah-c— C:\WINDOWS\Fonts.\vgaf1257.fon
2004-08-09 15:00 5360 –ah—– C:\WINDOWS\Fonts.\vgafix.fon
2004-08-09 15:00 5344 –ah-c— C:\WINDOWS\Fonts.\ega80852.fon
2004-08-09 15:00 5328 –ah-c— C:\WINDOWS\Fonts.\ega80850.fon
2004-08-09 15:00 5312 –ah—– C:\WINDOWS\Fonts.\ega80woa.fon
2004-08-09 15:00 5280 –ah-c— C:\WINDOWS\Fonts.\ega80866.fon
2004-08-09 15:00 5232 –ah-c— C:\WINDOWS\Fonts.\vga850.fon
2004-08-09 15:00 5200 –ah-c— C:\WINDOWS\Fonts.\vga863.fon
2004-08-09 15:00 5200 –ah-c— C:\WINDOWS\Fonts.\cga80852.fon
2004-08-09 15:00 5184 –ah-c— C:\WINDOWS\Fonts.\vga869.fon
2004-08-09 15:00 5184 –ah-c— C:\WINDOWS\Fonts.\vga865.fon
2004-08-09 15:00 5184 –ah-c— C:\WINDOWS\Fonts.\vga860.fon
2004-08-09 15:00 5168 –ah-c— C:\WINDOWS\Fonts.\vga775.fon
2004-08-09 15:00 5168 –ah-c— C:\WINDOWS\Fonts.\vga737.fon
2004-08-09 15:00 5168 –ah-c— C:\WINDOWS\Fonts.\cga80869.fon
2004-08-09 15:00 5168 –ah-c— C:\WINDOWS\Fonts.\cga80866.fon
2004-08-09 15:00 5168 –ah-c— C:\WINDOWS\Fonts.\cga80737.fon
2004-08-09 15:00 5168 –ah—– C:\WINDOWS\Fonts.\vgaoem.fon
2004-08-09 15:00 5120 –ah-c— C:\WINDOWS\Fonts.\vga855.fon
2004-08-09 15:00 489884 –a—— C:\WINDOWS\Fonts.\pala.ttf
2004-08-09 15:00 4640 –ah-c— C:\WINDOWS\Fonts.\cga80857.fon
2004-08-09 15:00 460728 –a—— C:\WINDOWS\Fonts.\micross.ttf
2004-08-09 15:00 434004 –a—— C:\WINDOWS\Fonts.\palab.ttf
2004-08-09 15:00 4320 –ah-c— C:\WINDOWS\Fonts.\cga80850.fon
2004-08-09 15:00 430800 –a—— C:\WINDOWS\Fonts.\palai.ttf
2004-08-09 15:00 4304 –ah—– C:\WINDOWS\Fonts.\cga80woa.fon
2004-08-09 15:00 409280 –a—— C:\WINDOWS\Fonts.\times.ttf
2004-08-09 15:00 40500 –a—— C:\WINDOWS\Fonts.\mvboli.ttf
2004-08-09 15:00 398372 –a—— C:\WINDOWS\Fonts.\timesbd.ttf
2004-08-09 15:00 383140 –a—— C:\WINDOWS\Fonts.\tahoma.ttf
2004-08-09 15:00 37472 –ah-c— C:\WINDOWS\Fonts.\app866.fon
2004-08-09 15:00 37296 –ah-c— C:\WINDOWS\Fonts.\app855.fon
2004-08-09 15:00 367112 –a—— C:\WINDOWS\Fonts.\arial.ttf
2004-08-09 15:00 36672 –ah-c— C:\WINDOWS\Fonts.\app857.fon
2004-08-09 15:00 36672 –ah-c— C:\WINDOWS\Fonts.\app850.fon
2004-08-09 15:00 36656 –ah-c— C:\WINDOWS\Fonts.\app852.fon
2004-08-09 15:00 36656 –ah—– C:\WINDOWS\Fonts.\dosapp.fon
2004-08-09 15:00 36336 –ah-c— C:\WINDOWS\Fonts.\dos737.fon
2004-08-09 15:00 35808 –ah-c— C:\WINDOWS\Fonts.\app775.fon
2004-08-09 15:00 355436 –a—— C:\WINDOWS\Fonts.\tahomabd.ttf
2004-08-09 15:00 352224 –a—— C:\WINDOWS\Fonts.\arialbd.ttf
2004-08-09 15:00 344288 –a—— C:\WINDOWS\Fonts.\palabi.ttf
2004-08-09 15:00 33360 –ah-c— C:\WINDOWS\Fonts.\courft.fon
2004-08-09 15:00 33344 –ah-c— C:\WINDOWS\Fonts.\courfg.fon
2004-08-09 15:00 323980 –a—— C:\WINDOWS\Fonts.\l_10646.ttf
2004-08-09 15:00 31808 –ah-c— C:\WINDOWS\Fonts.\courfr.fon
2004-08-09 15:00 31776 –ah-c— C:\WINDOWS\Fonts.\courfe.fon
2004-08-09 15:00 31760 –ah-c— C:\WINDOWS\Fonts.\couf1257.fon
2004-08-09 15:00 31712 –ah-c— C:\WINDOWS\Fonts.\courf.fon
2004-08-09 15:00 312920 –a—— C:\WINDOWS\Fonts.\courbd.ttf
2004-08-09 15:00 303296 –a—— C:\WINDOWS\Fonts.\cour.ttf
2004-08-09 15:00 29200 –ah-c— C:\WINDOWS\Fonts.\smallet.fon
2004-08-09 15:00 28912 –ah-c— C:\WINDOWS\Fonts.\smalleg.fon
2004-08-09 15:00 26112 –ah—– C:\WINDOWS\Fonts.\smalle.fon
2004-08-09 15:00 252820 –a—— C:\WINDOWS\Fonts.\vrinda.ttf
2004-08-09 15:00 25024 –ah-c— C:\WINDOWS\Fonts.\couret.fon
2004-08-09 15:00 25024 –ah-c— C:\WINDOWS\Fonts.\coureg.fon
2004-08-09 15:00 248368 –a—— C:\WINDOWS\Fonts.\timesi.ttf
2004-08-09 15:00 24832 –ah-c— C:\WINDOWS\Fonts.\smaller.fon
2004-08-09 15:00 24784 –ah-c— C:\WINDOWS\Fonts.\smallee.fon
2004-08-09 15:00 24672 –ah-c— C:\WINDOWS\Fonts.\smae1257.fon
2004-08-09 15:00 245032 –a—— C:\WINDOWS\Fonts.\couri.ttf
2004-08-09 15:00 24124 –ah—– C:\WINDOWS\Fonts.\marlett.ttf
2004-08-09 15:00 239692 –a—— C:\WINDOWS\Fonts.\timesbi.ttf
2004-08-09 15:00 236148 –a—— C:\WINDOWS\Fonts.\courbi.ttf
2004-08-09 15:00 23440 –ah-c— C:\WINDOWS\Fonts.\courer.fon
2004-08-09 15:00 23440 –ah-c— C:\WINDOWS\Fonts.\couree.fon
2004-08-09 15:00 23440 –ah-c— C:\WINDOWS\Fonts.\coue1257.fon
2004-08-09 15:00 234280 –a—— C:\WINDOWS\Fonts.\shruti.ttf
2004-08-09 15:00 23408 –ah—– C:\WINDOWS\Fonts.\coure.fon
2004-08-09 15:00 23120 –ah-c— C:\WINDOWS\Fonts.\smallfg.fon
2004-08-09 15:00 23008 –ah-c— C:\WINDOWS\Fonts.\smallft.fon
2004-08-09 15:00 226748 –a—— C:\WINDOWS\Fonts.\arialbi.ttf
2004-08-09 15:00 221676 –a—— C:\WINDOWS\Fonts.\sylfaen.ttf
2004-08-09 15:00 21504 –ah-c— C:\WINDOWS\Fonts.\smallf.fon
2004-08-09 15:00 214936 –a—— C:\WINDOWS\Fonts.\gautami.ttf
2004-08-09 15:00 207808 –a—— C:\WINDOWS\Fonts.\ariali.ttf
2004-08-09 15:00 19904 –ah-c— C:\WINDOWS\Fonts.\smaf1257.fon
2004-08-09 15:00 19760 –ah-c— C:\WINDOWS\Fonts.\smallfr.fon
2004-08-09 15:00 19600 –ah-c— C:\WINDOWS\Fonts.\smallfe.fon
2004-08-09 15:00 18880 –a—— C:\WINDOWS\Fonts.\wst_swed.fon
2004-08-09 15:00 18880 –a—— C:\WINDOWS\Fonts.\wst_span.fon
2004-08-09 15:00 18880 –a—— C:\WINDOWS\Fonts.\wst_ital.fon
2004-08-09 15:00 18880 –a—— C:\WINDOWS\Fonts.\wst_germ.fon
2004-08-09 15:00 18880 –a—— C:\WINDOWS\Fonts.\wst_fren.fon
2004-08-09 15:00 18880 –a—— C:\WINDOWS\Fonts.\wst_engl.fon
2004-08-09 15:00 18880 –a—— C:\WINDOWS\Fonts.\wst_czec.fon
2004-08-09 15:00 152844 –a—— C:\WINDOWS\Fonts.\framdit.ttf
2004-08-09 15:00 148636 –a—— C:\WINDOWS\Fonts.\tunga.ttf
2004-08-09 15:00 143864 –a—— C:\WINDOWS\Fonts.\mangal.ttf
2004-08-09 15:00 139288 –a—— C:\WINDOWS\Fonts.\trebucit.ttf
2004-08-09 15:00 136076 –a—— C:\WINDOWS\Fonts.\impact.ttf
2004-08-09 15:00 135984 –a—— C:\WINDOWS\Fonts.\framd.ttf
2004-08-09 15:00 134108 –a—— C:\WINDOWS\Fonts.\trebuc.ttf
2004-08-09 15:00 13312 –a—— C:\WINDOWS\Fonts.\roman.fon
2004-08-09 15:00 13248 –ah-c— C:\WINDOWS\Fonts.\8514oeme.fon
2004-08-09 15:00 13200 –ah-c— C:\WINDOWS\Fonts.\8514oemr.fon
2004-08-09 15:00 131188 –a—— C:\WINDOWS\Fonts.\trebucbi.ttf
2004-08-09 15:00 12800 –ah-c— C:\WINDOWS\Fonts.\8514oemg.fon
2004-08-09 15:00 12720 –ah-c— C:\WINDOWS\Fonts.\8514oemt.fon
2004-08-09 15:00 123096 –a—— C:\WINDOWS\Fonts.\trebucbd.ttf
2004-08-09 15:00 12304 –ah-c— C:\WINDOWS\Fonts.\85775.fon
2004-08-09 15:00 12288 –ah-c— C:\WINDOWS\Fonts.\8514oem.fon
2004-08-09 15:00 12288 –a—— C:\WINDOWS\Fonts.\script.fon
2004-08-09 15:00 12256 –ah-c— C:\WINDOWS\Fonts.\85855.fon
2004-08-09 15:00 121452 –a—— C:\WINDOWS\Fonts.\kartika.ttf
2004-08-09 15:00 118752 –a—— C:\WINDOWS\Fonts.\webdings.ttf
2004-08-09 15:00 117028 –a—— C:\WINDOWS\Fonts.\ariblk.ttf
2004-08-09 15:00 11520 –ah-c— C:\WINDOWS\Fonts.\8514fixg.fon
2004-08-09 15:00 115068 –a—— C:\WINDOWS\Fonts.\lucon.ttf
2004-08-09 15:00 11488 –ah-c— C:\WINDOWS\Fonts.\8514fixt.fon
2004-08-09 15:00 10976 –ah-c— C:\WINDOWS\Fonts.\85f1257.fon
2004-08-09 15:00 10976 –ah-c— C:\WINDOWS\Fonts.\8514fixr.fon
2004-08-09 15:00 10976 –ah-c— C:\WINDOWS\Fonts.\8514fixe.fon
2004-08-09 15:00 10976 –ah-c— C:\WINDOWS\Fonts.\8514fix.fon
2004-08-09 15:00 10064 –ah-c— C:\WINDOWS\Fonts.\8514sysr.fon
2004-05-13 04:05 50000 –a—— C:\WINDOWS\Fonts.\MSREF2.TTF
2004-05-13 04:05 42436 –a—— C:\WINDOWS\Fonts.\MSREF1.TTF
2004-05-07 05:56 72236 –a—— C:\WINDOWS\Fonts.\segmcr.ttf
2004-05-07 05:56 69440 –a—— C:\WINDOWS\Fonts.\segmcsb.ttf
2004-04-02 05:01 152700 -ra—— C:\WINDOWS\Fonts.\FRAHVIT.TTF
2004-04-02 05:01 139400 -ra—— C:\WINDOWS\Fonts.\FRAHV.TTF
2004-04-02 05:01 135904 -ra—— C:\WINDOWS\Fonts.\Fradmit.TTF
2004-04-02 05:01 132516 -ra—— C:\WINDOWS\Fonts.\Framdcn.TTF
2004-04-02 05:01 116940 -ra—— C:\WINDOWS\Fonts.\FRADMCN.TTF
2004-03-22 13:41 35504 –a—— C:\WINDOWS\Fonts.\Resegrg_.ttf
2004-03-22 13:40 151668 –a—— C:\WINDOWS\Fonts.\batik.ttf
2004-03-08 10:53 53288 -ra—— C:\WINDOWS\Fonts.\REFSPCL.TTF
2004-03-08 10:53 233620 -ra—— C:\WINDOWS\Fonts.\REFSANBI.TTF
2004-03-08 10:53 226536 -ra—— C:\WINDOWS\Fonts.\REFSANI.TTF
2004-03-08 10:53 220172 -ra—— C:\WINDOWS\Fonts.\REFSAN.TTF
2004-03-08 10:53 218516 -ra—— C:\WINDOWS\Fonts.\REFSANB.TTF
2003-12-17 12:47 59184 –a—— C:\WINDOWS\Fonts.\TT1139M_.TTF
2003-11-05 03:00 82776 –a—— C:\WINDOWS\Fonts.\gloo-gun.ttf
2003-11-05 03:00 80816 –a—— C:\WINDOWS\Fonts.\croobie.ttf
2003-11-05 03:00 79844 –a—— C:\WINDOWS\Fonts.\frosty.ttf
2003-11-05 03:00 79752 –a—— C:\WINDOWS\Fonts.\porky's.ttf
2003-11-05 03:00 79492 –a—— C:\WINDOWS\Fonts.\porkh.ttf
2003-11-05 03:00 76868 –a—— C:\WINDOWS\Fonts.\chick.ttf
2003-11-05 03:00 64176 –a—— C:\WINDOWS\Fonts.\jokewood.ttf
2003-11-05 03:00 58848 –a—— C:\WINDOWS\Fonts.\albas.ttf
2003-11-05 03:00 57820 –a—— C:\WINDOWS\Fonts.\babyk.ttf
2003-11-05 03:00 47932 –a—— C:\WINDOWS\Fonts.\jenkt.ttf
2003-11-05 03:00 47316 –a—— C:\WINDOWS\Fonts.\jenkinsv.ttf
2003-11-05 03:00 44076 –a—— C:\WINDOWS\Fonts.\alba.ttf
2003-11-05 03:00 43104 –a—— C:\WINDOWS\Fonts.\albam.ttf
2003-11-05 03:00 39660 –a—— C:\WINDOWS\Fonts.\fat.ttf
2003-11-05 03:00 36928 –a—— C:\WINDOWS\Fonts.\pusssa.ttf
2003-11-05 03:00 34164 –a—— C:\WINDOWS\Fonts.\pusss.ttf
2003-11-05 03:00 24372 –a—— C:\WINDOWS\Fonts.\poornut_.ttf
2003-11-05 03:00 20040 –a—— C:\WINDOWS\Fonts.\freshbot.ttf
2003-11-05 03:00 157520 –a—— C:\WINDOWS\Fonts.\weltu.ttf
2003-11-04 09:17 56624 -ra—— C:\WINDOWS\Fonts.\OCRAExt.ttf
2003-11-04 09:17 14148 -ra—— C:\WINDOWS\Fonts.\mtextra.ttf
2003-05-23 13:33 76676 –a—— C:\WINDOWS\Fonts.\Neurochr.ttf
2003-05-23 13:33 75364 –a—— C:\WINDOWS\Fonts.\Quigleyw.ttf
2003-05-23 13:33 67704 –a—— C:\WINDOWS\Fonts.\flx_girl.ttf
2003-05-23 13:33 67016 –a—— C:\WINDOWS\Fonts.\Occident.ttf
2003-05-23 13:33 39064 –a—— C:\WINDOWS\Fonts.\Manzanit.ttf
2003-05-23 13:33 37048 –a—— C:\WINDOWS\Fonts.\Outright.ttf
2003-05-23 13:33 148688 –a—— C:\WINDOWS\Fonts.\Austrise.ttf
2003-05-23 13:33 122736 –a—— C:\WINDOWS\Fonts.\Orlando.ttf
2003-05-23 13:33 120804 –a—— C:\WINDOWS\Fonts.\Oldgatel.ttf
2003-05-23 13:33 110644 –a—— C:\WINDOWS\Fonts.\tallpaul.ttf
2003-04-08 15:41 17672 –a—— C:\WINDOWS\Fonts.\OUTLOOK.TTF
2003-01-12 18:21 42084 –a—— C:\WINDOWS\Fonts.\PLCC____.TTF
2002-11-18 19:44 23275812 –a—— C:\WINDOWS\Fonts.\ARIALUNI.TTF
2002-11-12 12:26 165248 –a—— C:\WINDOWS\Fonts.\CENTURY.TTF
2002-05-10 09:19 163476 -ra—— C:\WINDOWS\Fonts.\papyrus.ttf
2002-04-17 06:55 76756 -ra—— C:\WINDOWS\Fonts.\Rocki.TTF
2002-04-17 06:55 76100 -ra—— C:\WINDOWS\Fonts.\TempsITC.TTF
2002-04-17 06:55 76080 -ra—— C:\WINDOWS\Fonts.\Peri____.TTF
2002-04-17 06:55 75620 -ra—— C:\WINDOWS\Fonts.\Perbi___.TTF
2002-04-17 06:55 73700 -ra—— C:\WINDOWS\Fonts.\Rockbi.TTF
2002-04-17 06:55 72272 -ra—— C:\WINDOWS\Fonts.\Rock.TTF
2002-04-17 06:55 70280 -ra—— C:\WINDOWS\Fonts.\Maiandit.TTF
2002-04-17 06:55 69752 -ra—— C:\WINDOWS\Fonts.\Jokerman.TTF
2002-04-17 06:55 69480 -ra—— C:\WINDOWS\Fonts.\Curlz___.TTF
2002-04-17 06:55 68780 -ra—— C:\WINDOWS\Fonts.\Rockb.TTF
2002-04-17 06:55 67648 -ra—— C:\WINDOWS\Fonts.\matisse_.ttf
2002-04-17 06:55 66320 -ra—— C:\WINDOWS\Fonts.\Lsansdi.TTF
2002-04-17 06:55 65412 -ra—— C:\WINDOWS\Fonts.\Lsansi.TTF
2002-04-17 06:55 64748 -ra—— C:\WINDOWS\Fonts.\Vivaldii.TTF
2002-04-17 06:55 64608 -ra—— C:\WINDOWS\Fonts.\Lsans.TTF
2002-04-17 06:55 64056 -ra—— C:\WINDOWS\Fonts.\ITCEdscr.TTF
2002-04-17 06:55 62884 -ra—— C:\WINDOWS\Fonts.\Juice___.TTF
2002-04-17 06:55 62716 -ra—— C:\WINDOWS\Fonts.\Coprgtl.TTF
2002-04-17 06:55 61552 -ra—— C:\WINDOWS\Fonts.\Coprgtb.TTF
2002-04-17 06:55 61384 -ra—— C:\WINDOWS\Fonts.\Maian.TTF
2002-04-17 06:55 60716 -ra—— C:\WINDOWS\Fonts.\Maiandb.TTF
2002-04-17 06:55 60216 -ra—— C:\WINDOWS\Fonts.\Per_____.TTF
2002-04-17 06:55 59976 -ra—— C:\WINDOWS\Fonts.\Lsansd.TTF
2002-04-17 06:55 59712 -ra—— C:\WINDOWS\Fonts.\ITCKrist.TTF
2002-04-17 06:55 58580 -ra—— C:\WINDOWS\Fonts.\Frscript.TTF
2002-04-17 06:55 58512 -ra—— C:\WINDOWS\Fonts.\Perb____.TTF
2002-04-17 06:55 49168 -ra—— C:\WINDOWS\Fonts.\Rockeb.TTF
2002-04-17 06:55 45952 -ra—— C:\WINDOWS\Fonts.\Felixti.TTF
2002-04-17 06:55 44304 -ra—— C:\WINDOWS\Fonts.\Eurostib.TTF
2002-04-17 06:55 43704 -ra—— C:\WINDOWS\Fonts.\Eurosti.TTF
2002-04-17 06:55 191716 -ra—— C:\WINDOWS\Fonts.\Mistral.TTF
2002-04-17 06:55 148520 -ra—— C:\WINDOWS\Fonts.\Gothici.TTF
2002-04-17 06:55 141408 -ra—— C:\WINDOWS\Fonts.\ArialNi.TTF
2002-04-17 06:55 139128 -ra—— C:\WINDOWS\Fonts.\ArialNb.TTF
2002-04-17 06:55 139084 -ra—— C:\WINDOWS\Fonts.\Gothicbi.TTF
2002-04-17 06:55 138568 -ra—— C:\WINDOWS\Fonts.\ArialNbi.TTF
2002-04-17 06:55 137568 -ra—— C:\WINDOWS\Fonts.\Gothic.TTF
2002-04-17 06:55 134200 -ra—— C:\WINDOWS\Fonts.\ArialN.TTF
2002-04-17 06:55 132372 -ra—— C:\WINDOWS\Fonts.\ITCBlkad.TTF
2002-04-17 06:55 129676 -ra—— C:\WINDOWS\Fonts.\Gothicb.TTF
2002-04-17 06:55 105296 -ra—— C:\WINDOWS\Fonts.\BradhITC.TTF
2002-01-22 10:22 65788 -ra—— C:\WINDOWS\Fonts.\WINGDNG2.TTF
2002-01-22 10:22 35328 –a—— C:\WINDOWS\Fonts.\WINGDNG3.TTF
2001-03-28 06:23 143804 –a—— C:\WINDOWS\Fonts.\FtraBkI_.ttf
2001-03-28 06:23 117180 –a—— C:\WINDOWS\Fonts.\FtraLt__.ttf
2001-03-28 06:23 114984 –a—— C:\WINDOWS\Fonts.\FtraHv__.ttf
2001-03-28 06:23 112892 –a—— C:\WINDOWS\Fonts.\FtraBk__.ttf
2001-03-28 06:23 111240 –a—— C:\WINDOWS\Fonts.\FtraMd__.ttf
2001-03-28 06:23 103136 –a—— C:\WINDOWS\Fonts.\FtraBd__.ttf
2001-01-10 08:32 169620 -ra—— C:\WINDOWS\Fonts.\Frabkit.TTF
2000-11-17 04:33 55540 –a—— C:\WINDOWS\Fonts.\BSSYM7.TTF
1999-08-18 15:53 161020 –a—— C:\WINDOWS\Fonts.\BOOKOSI.TTF
1999-06-25 06:23 49768 -ra—— C:\WINDOWS\Fonts.\Engr.TTF
1999-06-25 06:23 43768 -ra—— C:\WINDOWS\Fonts.\Engrb.TTF
1999-04-23 10:22 142932 -ra—— C:\WINDOWS\Fonts.\Fradm.TTF
1999-03-17 09:07 68656 -ra—— C:\WINDOWS\Fonts.\Eraslght.TTF
1999-03-17 09:07 59996 -ra—— C:\WINDOWS\Fonts.\Erasdemi.TTF
1998-11-12 10:18 155528 –a—— C:\WINDOWS\Fonts.\BKANT.TTF
1998-11-12 10:18 151000 –a—— C:\WINDOWS\Fonts.\ANTQUAB.TTF
1998-11-12 10:18 150416 –a—— C:\WINDOWS\Fonts.\ANTQUABI.TTF
1998-11-12 10:18 149092 –a—— C:\WINDOWS\Fonts.\ANTQUAI.TTF
1998-11-10 16:52 198604 –a—— C:\WINDOWS\Fonts.\GARABD.TTF
1998-11-10 16:52 196616 –a—— C:\WINDOWS\Fonts.\GARA.TTF
1998-11-10 16:52 188988 –a—— C:\WINDOWS\Fonts.\GARAIT.TTF
1998-11-10 16:52 157360 –a—— C:\WINDOWS\Fonts.\MTCORSVA.TTF
1998-11-04 19:30 162460 –a—— C:\WINDOWS\Fonts.\BOOKOSBI.TTF
1998-11-04 19:30 160940 –a—— C:\WINDOWS\Fonts.\BOOKOS.TTF
1998-11-04 19:30 154576 –a—— C:\WINDOWS\Fonts.\BOOKOSB.TTF


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCDrProfiler"="" []
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-14 08:51]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-08-25 10:32]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-08-14 17:02]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 10:35]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 15:00]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2006-01-24 11:37]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-07-27 01:27]
"AIM"="C:\Program Files\AIM\aim.exe" [2004-08-10 08:37]
"Steam"="" []
"Pop up Blocker"="C:\Program Files\Pop up Blocker\pd.exe" [2007-01-12 15:43]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-25 09:31]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"



[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7d23be63-d96d-11db-aa66-00173135ac37}]
AutoRun\command- J:\JDSecure\Windows\JDSecure20.exe

*Newly Created Service* - SSMDRV

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-04 08:05:08
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-04 8:05:54
C:\ComboFix-quarantined-files.txt … 2007-09-04 08:05
C:\ComboFix2.txt … 2007-09-04 04:02

— E O F —


Logfile of HijackThis v1.99.1
Scan saved at 8:10:01 AM, on 04/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HJT\spyware.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.torncity.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Pop up Blocker] "C:\Program Files\Pop up Blocker\pd.exe" Minimize
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

Thanks
just was checking out the games i play before leaving for work and im still getting the laggy jumping… its like somthing is running in the backround and i cant figure out what.. it never used to do this before
Hi StrikeDogg,

Download Gmer to your Desktop from here:
http://www.gmer.net/gmer.zip
  • Unzip the program onto your Desktop
  • Disconnect from internet and close all running programs
  • Double click gmer.exe, let the gmer.sys driver load if asked
  • If it gives you a warning at program start about rootkit activity and asks if you want to run scan…say OK
  • If there is no warning, then check that the Rootkit tab is selected and click the Scan button - don't change any settings before you do so
  • Once the scan is complete, click the Copy button
  • Open Notepad and hit Ctrl+V to paste the log and then save the log to your desktop
Once complete, please post the GMER log along with a new HijackThis log.
i downloaded the program like you said and ran it but all it did was give me a blue screen with lines across it and freeze up my computer…
retried it again when i got home and it seemed to work..

here are the logs

GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-09-04 22:05:14
Windows 5.1.2600 Service Pack 2


AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [BA91C742] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [BA91C742] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [BA91C000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [BA9195C2] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [BA91D5D2] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [BA91C000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [BA91C742] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [BA919000] bb-run.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [BA5E01DE] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [BA5E01DE] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [BA5E0454] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [BA5E01DE] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE [BA91C742] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE [BA91C742] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLOSE [BA91C000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_READ [BA9195C2] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_WRITE [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_EA [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL [BA91D5D2] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP [BA91C000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_MAILSLOT [BA91C742] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_SECURITY [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_SECURITY [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_POWER [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SYSTEM_CONTROL [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CHANGE [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_QUOTA [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_QUOTA [BA919000] bb-run.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE [BA5E01DE] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE [BA5E01DE] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLOSE [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_READ [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_WRITE [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_EA [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL [BA5E0454] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_MAILSLOT [BA5E01DE] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_SECURITY [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_SECURITY [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_POWER [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SYSTEM_CONTROL [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CHANGE [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_QUOTA [BA5D3F4C] fltMgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_QUOTA [BA5D3F4C] fltMgr.sys

—- EOF - GMER 1.0.13 —-


Logfile of HijackThis v1.99.1
Scan saved at 10:07:24 PM, on 04/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\HJT\spyware.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.torncity.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Pop up Blocker] "C:\Program Files\Pop up Blocker\pd.exe" Minimize
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

Thanks _silver_ :)
Hi StrikeDogg,

Re-hide hidden/system files and folders:
Click Start -> My Computer
Select the Tools menu, click Folder Options and select the View tab
Under the Hidden files and folders heading SELECT Do not show hidden files and folders
CHECK the Hide extensions for known file types option
CHECK the Hide protected operating system files (recommended) option
Press OK

Create a new, clean System Restore point which you can use in case of future system problems:
Press Start->All Programs->Accessories->System Tools->System Restore
Select Create a restore point, then Next, type a name like All Clean then press the Create button and once it's done press Close

Now remove old, infected System Restore points:
Next click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Select the More Options tab, under System Restore press Clean up… and say Yes to the prompt
Press OK and Yes to confirm


We've had a pretty thorough look at your computer and at this stage it looks clean of malware, so I'd say the slowdown has other causes.
Some suggestions for pinning it down:
  • Uninstall unnecessary applications via Start->Control Panel->Add/Remove Programs
  • Turn off unnecessary auto-starting applications. Look at your HijackThis log for programs which automatically start - many are listed in the O4 section of the log, and turn of the automatic starting functionality from within the program. Note: Please do not use HijackThis to remove the entries.
  • Use Process Explorer to monitor resources on your system. Run Process Explorer minimized and when a slowdown occurs, switch to the Process Explorer window to see which process is using a high percentage of CPU.
  • Post in the Other computer problems forum here at WhatTheTech to get more help.

Here are some tips to help you keep your computer clean:

Operating system vulnerabilities can easily be exploited by malware so please ensure your operating system is automatically kept up to date by using Windows Update:
Go to Start->Control Panel->Automatic Updates
Select Automatic and select a suitable schedule
Also, check that your antivirus and antispyware programs are set to automatically update daily.

You should consider installing a Personal Firewall program. Even if you are behind a NAT router, I recommend you use firewall software as it will improve the security of your computer by monitoring and controlling outbound connections to the internet as well as inbound. There are various free packages available, such as Sunbelt Personal Firewall and Zone Alarm:
http://www.sunbelt-software.com/Home-Home-…sonal-Firewall/
http://www.zonelabs.com/

Spywareblaster is a free program which prevents the download and installation of Internet Explorer ActiveX based malware by immunizing your system against it. You can download Spywareblaster from here and a tutorial to help you get started is available here.

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware - this includes allowing websites to install browser plug-ins orActiveX controls. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Find out more about how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know that you have read this, and if there are any further issues.
Hey _silver_ just been doing some playing around with my computer just to see how its running.. and so far so good.. every once in awhile i get a message saying Antivir found somthing.. but im guessing that a working firewall will stop that.. ill be getting one here later today read and understood everything you had to say about the firewalls and such and will be checking the process scanner shortly.. let you know how that goes.. Thanks again

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI