This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Baseline Hjt Logfile From Snowbound

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Newbie and Novice: When I choose any search engine, I get a list of results. If I click on any result, I get redirected to other search engines. I'm getting extremely frustrated. Here's my Baseline HJT logfile. I'm going to study the self-help section, but I hope someone can find something obvious in my logfile. Thanks for any help you can provide.

Logfile of HijackThis v1.99.1
Scan saved at 7:15:11 PM, on 8/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Bell\Security Manager\fws.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\acer\epm\epm-dm.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\PowerKey.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSDCtrl.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Arcade\PCMService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
C:\Program Files\Bell\Security Manager\Rps.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\vVX1000.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mightyfax\MFNTCTL.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Greetings Workshop\GWREMIND.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Security Manager\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Bell\Security Manager\FBHR.dll
O2 - BHO: WebCGMHlprObj Class - {56B38F40-4E70-11d4-A076-0080AD86BA2F} - C:\WINDOWS\system32\cgmopenbho.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"
O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
O4 - HKLM\..\Run: [LManager] "C:\Program Files\Launch Manager\HotkeyApp.exe"
O4 - HKLM\..\Run: [CtrlVol] "C:\Program Files\Launch Manager\CtrlVol.exe"
O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE /P23 "EPSON Stylus C62 Series" /O6 "USB001" /M "Stylus C62"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe"
O4 - HKLM\..\Run: [Security Manager] "C:\Program Files\Bell\Security Manager\Rps.exe"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [dmisd.exe] C:\WINDOWS\system32\dmisd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Global Startup: MightyFAX Controller.lnk = C:\Program Files\Mightyfax\MFNTCTL.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A4A9040-68A3-46F1-95D0-615FFB2757E3}: NameServer = 85.255.116.157 85.255.112.166
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Security Manager Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\fws.exe
Hi SNOWBOUND and welcome to the forums. Saw you "peeking in" at one of my other threads.

My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • NOTE:Before we start: Please be aware that removing Malware is a hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

    In light of this it would be wise for you to back up any files and folders that you don't want to lose before we start.

STEP 1:

We are going to use HJT to create a list of your currently installed programs.1. Open HijackThis and click on the Config… button in the "Other stuff" section (lower right hand corner).
2. Click on the Misc Tools button.
3. Click on the Open Uninstall Manager… button.
4. Click on the Save list… button.
5. Save the file uninstall_list.txt to a convinient location. This should open Notepad with the list.
6. Please Copy and Paste the list into your next reply.
STEP 2:

Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O4 - HKLM\..\Run: [dmisd.exe] C:\WINDOWS\system32\dmisd.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A4A9040-68A3-46F1-95D0-615FFB2757E3}: NameServer = 85.255.116.157 85.255.112.166

Then close all windows except this one and press Fix checked.


STEP 3:

Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

Once the desktop loads please post the text that will open (report.txt) and a new HijackThis log.

Now lets check some settings on your system.
(2000/XP) Only
In the windows control panel. If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections. Then right click on your default connection, usually local area connection for cable and dsl, and left click on properties. Click the Networking tab. Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically
Press OK twice to get out of the properties screen and reboot if it asks.
That option might not be avaiable on some systems
Next Go start run type cmd and hit OK
type
ipconfig /flushdns
then hit enter, type exit hit enter
(that space between g and / is needed)
Hi Dave,
My name is Tom, in Quebec City. Thanks for helping me. I've done steps 1, 2, & 3 and will next start checking the settings on my system as you specified. Meantime, here are 1) the Fixwareout report and 2 the new HJT logfile.

Fixwareout report:

Username "Tommy" - 2007-08-29 20:30:03 [Fixwareout edited 2007/07/05]

»»»»»Prerun check
HKLM\SOFTWARE\~\CurrentVersion\Run\ ="dmisd"
HKLM\SOFTWARE\~\Winlogon\ "System"="csrhm.exe"

Successfully flushed the DNS Resolver Cache.


System was rebooted successfully.

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
….
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "0mdm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "1mdm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "xevol" Deleted
….
»»»»» Misc files.
….
»»»»» Checking for older varients.
….

Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.

C:\WINDOWS\system32\csfwm.exe 51734 10/22/2006

Click browse, find the file then click submit.
http://www.virustotal.com/flash/index_en.html
Or http://virusscan.jotti.org/

»»»»» Other
C:\WINDOWS\TEMP\dmisd.ren 60956 06/13/2007

»»»»» Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"preload"="C:\\Windows\\RUNXMLPL.exe"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"SoundMan"="SOUNDMAN.EXE"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"EPM-DM"="c:\\acer\\epm\\epm-dm.exe"
"ePowerManagement"="C:\\Acer\\ePM\\ePM.exe boot"
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"LaunchAp"="\"C:\\Program Files\\Launch Manager\\LaunchAp.exe\""
"PowerKey"="\"C:\\Program Files\\Launch Manager\\PowerKey.exe\""
"LManager"="\"C:\\Program Files\\Launch Manager\\HotkeyApp.exe\""
"CtrlVol"="\"C:\\Program Files\\Launch Manager\\CtrlVol.exe\""
"LMgrOSD"="\"C:\\Program Files\\Launch Manager\\OSDCtrl.exe\""
"Wbutton"="\"C:\\Program Files\\Launch Manager\\Wbutton.exe\""
"PCMService"="\"C:\\Program Files\\Arcade\\PCMService.exe\""
"eRecoveryService"="C:\\Windows\\System32\\Check.exe"
"EPSON Stylus C62 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S0BIC1.EXE /P23 \"EPSON Stylus C62 Series\" /O6 \"USB001\" /M \"Stylus C62\""
"NeroCheck"="C:\\WINDOWS\\system32\\\\NeroCheck.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"SSA.exe"="\"C:\\Program Files\\Bell\\Sympatico Security Advisor\\SSA.exe\""
"Security Manager"="\"C:\\Program Files\\Bell\\Security Manager\\Rps.exe\""
"eBayToolbar"="C:\\Program Files\\eBay\\eBay Toolbar2\\eBayTBDaemon.exe"
"Share-to-Web Namespace Daemon"="C:\\Program Files\\Hewlett-Packard\\HP Share-to-Web\\hpgs2wnd.exe"
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""
"LifeCam"="\"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe\""
"VX1000"="C:\\WINDOWS\\vVX1000.exe"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_9 -reboot 1"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
….
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»

New HJT logfile:

Logfile of HijackThis v1.99.1
Scan saved at 8:45:46 PM, on 8/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Bell\Security Manager\fws.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\acer\epm\epm-dm.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\PowerKey.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSDCtrl.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Arcade\PCMService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
C:\Program Files\Bell\Security Manager\Rps.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\vVX1000.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mightyfax\MFNTCTL.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Greetings Workshop\GWREMIND.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\acer\eRecovery\Monitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Security Manager\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Bell\Security Manager\FBHR.dll
O2 - BHO: WebCGMHlprObj Class - {56B38F40-4E70-11d4-A076-0080AD86BA2F} - C:\WINDOWS\system32\cgmopenbho.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"
O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
O4 - HKLM\..\Run: [LManager] "C:\Program Files\Launch Manager\HotkeyApp.exe"
O4 - HKLM\..\Run: [CtrlVol] "C:\Program Files\Launch Manager\CtrlVol.exe"
O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE /P23 "EPSON Stylus C62 Series" /O6 "USB001" /M "Stylus C62"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe"
O4 - HKLM\..\Run: [Security Manager] "C:\Program Files\Bell\Security Manager\Rps.exe"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Global Startup: MightyFAX Controller.lnk = C:\Program Files\Mightyfax\MFNTCTL.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A4A9040-68A3-46F1-95D0-615FFB2757E3}: NameServer = 85.255.116.157 85.255.112.166
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Security Manager Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\fws.exe


By the way, I noticed that after "fixing" the "numbers 04 and 017", my internet connection was lost. when I restarted it, it worked fine. However, now I note that the "line 017" is back again with this new HJT logfile.

I'm going to start on your "system settings" check.

Thanks again,
Tom
Hi Tom,

I'm not too far south of you…in the middle of Vermont. Welcome eh…sorry, couldn't resist.

Please go to http://virusscan.jotti.org, click on Browse, and upload the following file for analysis:

C:\WINDOWS\system32\csfwm.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.

If Jotti is too busy you can try these.

http://www.kaspersky.com/scanforvirus.html
http://www.virustotal.com/en/indexf.html
Dave, I've done the system check as you specified. I know we're probably not done yet, but my redirected searches seem to be gone and, as well, a web site that I use often was EXTREMELY slow (40 - 75 seconds between pages) and now runs normally (3 to 4 seconds). You're a genius, so far!! I'll keep doing what you say to do on my computer until you tell me to stop. Thanks, Tom
Dave, I'm not sure I copied everything you wanted but here are the results of the scan of c:\windows\system32\csfwm.exe file . Tom Service load: 0% 100% File: csfwm.exe Status: INFECTED/MALWARE MD5: c42e9ebe75037d1334921c01ec0a6dfd Packers detected: PE-CRYPT.POLYCRYPTA Bit9 reports: File not found Scanner results Scan taken on 30 Aug 2007 01:53:30 (GMT) A-Squared Found Trojan-Downloader.Win32.Agent.uj AntiVir Found TR/Dldr.Mohbpork.A.65 ArcaVir Found Trojan.Downloader.Agent.Uj Avast Found Win32:ChanCrypt AVG Antivirus Found PSW.Agent.DKF BitDefender Found Trojan.Peed.Gen ClamAV Found nothing CPsecure Found nothing Dr.Web Found Trojan.DnsChange F-Prot Antivirus Found nothing F-Secure Anti-Virus Found Trojan-Downloader.Win32.Agent.uj Fortinet Found Agent.BC!tr.spy Kaspersky Anti-Virus Found Trojan-Downloader.Win32.Agent.uj NOD32 Found Win32/TrojanDownloader.Agent.NNY Norman Virus Control Found W32/Agent.AVXI Panda Antivirus Found nothing Rising Antivirus Found nothing Sophos Antivirus Found Troj/RuinDl-W VirusBuster Found Trojan.DL.Small.Gen!Pac8 VBA32 Found MalwareScope.Trojan.DnsChange.1

You're a genius, so far!!


Now let's not get carried away here…more like well trained.

Glad to hear it's running better. Let's get rid of that file.

Download the Killbox.
Unzip it to the desktop

Double-click Killbox.exe to run it.

Select "Delete on Reboot".
Place the following line (complete path) in bold in the "Full Path of File to Delete" box in Killbox:

C:\WINDOWS\system32\csfwm.exe


Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt.
If your computer does not restart automatically, please restart it manually.

Post a fresh HJT log for review.
Good Morning Dave,
Here's the new HJT logfile after running Killbox.exe .
Tom

Logfile of HijackThis v1.99.1
Scan saved at 11:53:23 AM, on 8/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Bell\Security Manager\fws.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\acer\epm\epm-dm.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\PowerKey.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSDCtrl.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Arcade\PCMService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
C:\Program Files\Bell\Security Manager\Rps.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\vVX1000.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mightyfax\MFNTCTL.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Greetings Workshop\GWREMIND.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\acer\eRecovery\Monitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Security Manager\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Bell\Security Manager\FBHR.dll
O2 - BHO: WebCGMHlprObj Class - {56B38F40-4E70-11d4-A076-0080AD86BA2F} - C:\WINDOWS\system32\cgmopenbho.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"
O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
O4 - HKLM\..\Run: [LManager] "C:\Program Files\Launch Manager\HotkeyApp.exe"
O4 - HKLM\..\Run: [CtrlVol] "C:\Program Files\Launch Manager\CtrlVol.exe"
O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE /P23 "EPSON Stylus C62 Series" /O6 "USB001" /M "Stylus C62"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe"
O4 - HKLM\..\Run: [Security Manager] "C:\Program Files\Bell\Security Manager\Rps.exe"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Global Startup: MightyFAX Controller.lnk = C:\Program Files\Mightyfax\MFNTCTL.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A4A9040-68A3-46F1-95D0-615FFB2757E3}: NameServer = 206.47.244.91 206.47.244.50
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Security Manager Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\fws.exe

I notice that the 017 is still there but the NameServer number is different. It's all Greek to me.
Thanks for your continued effort.
Tom
Hi Tom,

Yes, the 017 is there, but now it is a different IP Address if you notice. This new one is for Bell in Canada. I assume Bell is your ISP and your in Canada, so I think we're safe with that. Wareout comes with certain IP's, usually in Amsterdam or somewhere.

Even though things are running better let's do a Kaspersky scan to make sure nothing is lurking. It takes a while so…

Using Internet Explorer, click on Kaspersky Online Scanner * Click 'Accept' in the window that pops up.
* You will be prompted to install an ActiveX component from Kaspersky, Click on the information bar and select Install ActiveX Control if so. This may happen more than once. That is OK. You also may get a warning from your Windows Firewall. You can tell it to unblock.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save Report As…' button:
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log.
Dave,
I'm not sure if you wanted me to cut and paste the Kaspersky report here but that's what I did. If you want me to do it some other way, let me know.
Tom

KASPERSKY ONLINE SCANNER REPORT
Thursday, August 30, 2007 3:40:21 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 30/08/2007
Kaspersky Anti-Virus database records: 400121


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 50711
Number of viruses found 3
Number of infected objects 243
Number of suspicious objects 0
Duration of the scan process 00:56:57

Infected Object Name Virus Name Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\DEFAULT Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped

C:\WINDOWS\system32\config\SYSTEM Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\Temp\dmisd.ren Infected: Trojan.Win32.Small.fb skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{304EEFDF-3E81-4F39-B6BF-C162DA87F12C}.bin Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Bell\Security Manager\logs\FirewallService08-30-2007–11-45-57.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Bell\Security Manager\logs\ServiceModel08-30-2007–11-47-30.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Bell\Security Manager\logs\Fw_Session.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Bell\Security Manager\logs\SafetyConsoleLog08-30-2007–11-47-31.log Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Tommy\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Temp\~DFDEAC.tmp Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Temp\~DFDEB3.tmp Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Temp\~DF80AD.tmp Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Temp\~DF80B4.tmp Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Temp\~DF96D7.tmp Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Temp\~DF96DE.tmp Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\real\members.stg Object is locked skipped

C:\Documents and Settings\Tommy\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\shadow\members.stg Object is locked skipped

C:\Documents and Settings\Tommy\ntuser.dat Object is locked skipped

C:\Documents and Settings\Tommy\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Tommy\Application Data\Microsoft\MSNLiveFav\LiveFavorites.xml Object is locked skipped

C:\Documents and Settings\Tommy\Application Data\Bell\Sympatico Security Advisor\client_gateway.log Object is locked skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP129\A0021705.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP129\A0021714.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP129\A0021737.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP129\A0021750.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP129\A0021762.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP129\A0021772.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP130\A0021798.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP130\A0021809.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP130\A0021820.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP130\A0021831.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP131\A0021862.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP131\A0021873.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP131\A0021885.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP131\A0021896.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP131\A0021907.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP131\A0021919.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP131\A0021930.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP131\A0021940.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP132\A0021961.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP132\A0021970.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP132\A0021986.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP132\A0022019.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP134\A0022114.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP135\A0022135.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP136\A0022163.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP136\A0022178.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP136\A0022190.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP138\A0022294.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP138\A0022304.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP138\A0022314.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP138\A0022325.EXE Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP138\A0022333.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP138\A0022346.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP138\A0022359.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP138\A0022378.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP138\A0022388.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP138\A0022398.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP138\A0022410.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP139\A0022425.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP139\A0022435.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP139\A0022448.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP139\A0022458.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP139\A0022471.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP139\A0022495.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP139\A0022507.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP139\A0022520.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP140\A0022542.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP140\A0022554.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP140\A0022568.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP141\A0022591.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP141\A0022602.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP141\A0022630.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP141\A0022639.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP141\A0022657.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP141\A0022672.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP141\A0022683.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP141\A0022698.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP142\A0022718.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP142\A0022732.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP142\A0022742.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP142\A0022753.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP142\A0022766.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP142\A0022777.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP142\A0022792.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP142\A0022803.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP142\A0022814.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP142\A0022825.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP142\A0022835.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP142\A0022848.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP143\A0022886.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP143\A0022896.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP143\A0022908.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP143\A0022922.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP144\A0022934.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP144\A0022949.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP144\A0022965.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP144\A0022974.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP144\A0022985.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP145\A0023024.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP145\A0023035.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP146\A0023066.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP146\A0023079.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP146\A0023116.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP146\A0023133.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP147\A0023147.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP147\A0023160.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP147\A0023171.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP147\A0023188.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP148\A0023229.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP148\A0023239.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP148\A0023249.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP148\A0023260.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP148\A0023270.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP148\A0023281.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP148\A0023294.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP148\A0023306.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP148\A0023316.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP148\A0023328.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP148\A0023348.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP148\A0023358.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP148\A0023374.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP149\A0023386.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP150\A0023482.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP150\A0023642.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP150\A0023678.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP151\A0023694.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP151\A0023707.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP151\A0023718.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP151\A0023731.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP151\A0023741.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP151\A0023768.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP151\A0023784.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP151\A0023795.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP151\A0023806.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP152\A0023833.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP152\A0023844.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP152\A0023854.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP152\A0023875.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP153\A0023888.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP153\A0023901.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP154\A0023921.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP154\A0023939.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP154\A0023949.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP154\A0023960.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP155\A0023990.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP155\A0024000.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP155\A0024013.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP156\A0024058.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP156\A0024691.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP156\A0024709.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP156\A0024719.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP156\A0024729.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP156\A0024744.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP157\A0024774.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP157\A0024784.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP157\A0024802.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP157\A0024813.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP157\A0024828.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP157\A0024840.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP157\A0024853.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP157\A0024864.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP157\A0024875.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP157\A0024885.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP157\A0024897.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP157\A0024906.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP157\A0024931.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP158\A0024948.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP158\A0024958.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP158\A0024970.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP159\A0024988.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP159\A0024998.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP159\A0025012.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP159\A0025029.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP159\A0025040.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP159\A0025052.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP159\A0025068.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP159\A0026068.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026102.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026112.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026128.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026139.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026151.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026173.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026183.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026194.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026209.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026221.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026231.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026242.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026257.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026268.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP160\A0026280.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP161\A0026304.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP161\A0026314.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP162\A0026329.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP162\A0026342.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP162\A0026352.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP163\A0026372.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP163\A0026383.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP163\A0026395.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP164\A0026411.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP164\A0026426.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP164\A0026438.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP164\A0026448.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP164\A0026462.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP164\A0026472.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP164\A0026483.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP164\A0026495.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP165\A0026516.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP165\A0026533.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP165\A0026542.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP165\A0026560.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP165\A0026572.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP165\A0026582.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP166\A0026604.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP167\A0026706.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP167\A0026721.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP167\A0026741.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP167\A0026758.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP167\A0026772.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP167\A0026783.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP167\A0026795.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP168\A0026809.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP168\A0026820.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP168\A0026836.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP168\A0026846.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP168\A0026857.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP169\A0026875.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP169\A0026888.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP169\A0026905.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP169\A0026921.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP169\A0026932.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP169\A0026946.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP169\A0026963.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP169\A0026984.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP169\A0026994.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP169\A0027005.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP169\A0027129.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP170\A0027162.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP170\A0027171.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP170\A0027196.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP170\A0027221.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP171\A0027250.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP171\A0027259.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP172\A0027278.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP172\A0027288.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP174\A0027303.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP174\A0027914.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP174\A0027928.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP174\A0027952.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP174\A0027983.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP174\A0027994.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP174\A0028007.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP175\A0028107.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP178\A0028133.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP178\A0028145.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP179\A0028240.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP179\A0028305.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP179\A0028326.exe Infected: Trojan.Win32.Small.fb skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP180\change.log Object is locked skipped

C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP180\A0028365.exe Infected: Trojan-Downloader.Win32.Agent.uj skipped

C:\FOUND.006\FILE0000.CHK Infected: Exploit.JS.CVE-2005-1790.t skipped

C:\!KillBox\csfwm.exe Infected: Trojan-Downloader.Win32.Agent.uj skipped

D:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP180\change.log Object is locked skipped

Scan process completed.


NEW HJT LOGFILE:


Logfile of HijackThis v1.99.1
Scan saved at 3:50:42 PM, on 8/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Bell\Security Manager\fws.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\acer\epm\epm-dm.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\PowerKey.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSDCtrl.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Arcade\PCMService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
C:\Program Files\Bell\Security Manager\Rps.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\vVX1000.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mightyfax\MFNTCTL.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Greetings Workshop\GWREMIND.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\acer\eRecovery\Monitor.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Security Manager\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Bell\Security Manager\FBHR.dll
O2 - BHO: WebCGMHlprObj Class - {56B38F40-4E70-11d4-A076-0080AD86BA2F} - C:\WINDOWS\system32\cgmopenbho.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"
O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
O4 - HKLM\..\Run: [LManager] "C:\Program Files\Launch Manager\HotkeyApp.exe"
O4 - HKLM\..\Run: [CtrlVol] "C:\Program Files\Launch Manager\CtrlVol.exe"
O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE /P23 "EPSON Stylus C62 Series" /O6 "USB001" /M "Stylus C62"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe"
O4 - HKLM\..\Run: [Security Manager] "C:\Program Files\Bell\Security Manager\Rps.exe"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Global Startup: MightyFAX Controller.lnk = C:\Program Files\Mightyfax\MFNTCTL.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A4A9040-68A3-46F1-95D0-615FFB2757E3}: NameServer = 206.47.244.91 206.47.244.50
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Security Manager Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\fws.exe
Hi Tom,

Not too much to worry about there, most all is in your restore points, which we can clean up at the end. You can also remove/delete the killbox tool.

One thing I did just notice was that Security Manager that you have from your ISP. Does that include an Antivirus? I can see it does include at lease a firewall and pop-up blocker, but I don't see an AV as part of it. Please let me know.

Let's have you run ATFCleaner and post a new HJT log to make sure all is well. Let me know how it's running also.

Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
Hi Dave,
Yes, my ISP is Bell Sympatico and an AV is included and turned on. I don't recognise it in the list either. From all this work you're doing, maybe it's not doing very well.
Here's the new HJT logfile after running ATF Cleaner.
Tom

Logfile of HijackThis v1.99.1
Scan saved at 4:32:07 PM, on 8/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Bell\Security Manager\fws.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\acer\epm\epm-dm.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\PowerKey.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSDCtrl.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Arcade\PCMService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
C:\Program Files\Bell\Security Manager\Rps.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\vVX1000.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mightyfax\MFNTCTL.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Greetings Workshop\GWREMIND.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\acer\eRecovery\Monitor.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Security Manager\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Bell\Security Manager\FBHR.dll
O2 - BHO: WebCGMHlprObj Class - {56B38F40-4E70-11d4-A076-0080AD86BA2F} - C:\WINDOWS\system32\cgmopenbho.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"
O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
O4 - HKLM\..\Run: [LManager] "C:\Program Files\Launch Manager\HotkeyApp.exe"
O4 - HKLM\..\Run: [CtrlVol] "C:\Program Files\Launch Manager\CtrlVol.exe"
O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE /P23 "EPSON Stylus C62 Series" /O6 "USB001" /M "Stylus C62"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe"
O4 - HKLM\..\Run: [Security Manager] "C:\Program Files\Bell\Security Manager\Rps.exe"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Global Startup: MightyFAX Controller.lnk = C:\Program Files\Mightyfax\MFNTCTL.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A4A9040-68A3-46F1-95D0-615FFB2757E3}: NameServer = 206.47.244.91 206.47.244.50
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Security Manager Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\fws.exe
OK if all is well then we can finish up.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which may be infected anyway).

Click Start>Help and Support>Undo changes to your computer with System Restore
Select Create A Restore Point then click Next. Give it a name it and then click Create

Click Start>Run and type Cleanmgr
Click the More Options Tab.
Click Clean Up in the System Restore section.


Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly or set your computer to receive automatic updates. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Install SpywareGuard - SpywareGuard provides a real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.
A tutorial on installing & using this product can be found here:
Using SpywareGuard to protect your computer from Spyware and Malware

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

Here is a great link to a post here on securing your PC after an attack.
http://forums.tomcoyote.org/index.php?show…mp;#entry257163

Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help.
Dear Dave, I can't thank you enough for the help you have provided. My computer is running really well and the problems I described at the beginning are gone. Thanks again. Tom
Excellent Tom :thumbup: :thumbup: :thumbup: That's 3 thumbs up! I'll keep this thread open for a couple of days in case you run into any problems or have any other questions. Regards, Dave

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI