This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Pc Running Mega Slow,file Downloaded Off Astalavista Kil

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

StartupList report, 03/09/2007, 02:09:28
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16512)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

VTTimer = VTTimer.exe
VTTrayp = VTtrayp.exe
SoundMan = SOUNDMAN.EXE
AGRSMMSG = AGRSMMSG.exe
4oD = "C:\Program Files\Kontiki\KHost.exe" -all
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
SystemRestoreStatus = rundll32.exe "C:\WINDOWS\system32\itnxctfk.dll",sitypnow
Kaspersky Anti-Virus 2006 = C:\Program Files\Kaspersky Lab\AVP6\avp.exe
BearShare = "C:\Program Files\BearShare\BearShare.exe" /pause

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

CTFMON.EXE = C:\WINDOWS\system32\ctfmon.exe
swg = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
msnmsgr = "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
Ssha = "C:\WINDOWS\YMANTE~1\regsvr32.exe" -vt yazb

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Task Scheduler jobs:

AdsGone.job
AppleSoftwareUpdate.job

————————————————–

Enumerating Download Program Files:

[CKAVWebScan Object]
InProcServer32 = C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
CODEBASE = http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa…director/sw.cab

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\LegitCheckControl.DLL
CODEBASE = http://download.microsoft.com/download/9/b…heckControl.cab

[MSN Photo Upload Tool]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll
CODEBASE = http://by134fd.bay134.hotmail.msn.com/resources/MsnPUpld.cab

[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://www.update.microsoft.com/microsoftu…b?1188663167948

[{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
CODEBASE = http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab

[MessengerStatsClient Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll
CODEBASE = http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx
CODEBASE = http://fpdownload.macromedia.com/get/shock…ash/swflash.cab

————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\DOCUME~1\DARBYS~1\Cookies\DA5B69~1.TXT => C:\DOCUME~1\DARBYS~1\LOCALS~1\Temp\2.txt|C:\DOCUME~1\DARBYS~1\Cookies\DARBYS~1.TXT => C:\DOCUME~1\DARBYS~1\LOCALS~1\Temp\2.txt|C:\DOCUME~1\DARBYS~1\Cookies\DA5DBD~1.TXT => C:\DOCUME~1\DARBYS~1\LOCALS~1\Temp\2.txt|C:\DOCUME~1\DARBYS~1\Cookies\DA5672~1.TXT => C:\DOCUME~1\DARBYS~1\LOCALS~1\Temp\2.txt|C:\DOCUME~1\DARBYS~1\Cookies\DA31E9~1.TXT => C:\DOCUME~1\DARBYS~1\LOCALS~1\Temp\2.txt|C:\DOCUME~1\DARBYS~1\Cookies\DAE475~1.TXT => C:\DOCUME~1\DARBYS~1\LOCALS~1\Temp\2.txt|C:\DOCUME~1\DARBYS~1\Cookies\DA836F~1.TXT => C:\DOCUME~1\DARBYS~1\LOCALS~1\Temp\2.txt|C:\DOCUME~1\DARBYS~1\Cookies\DA0736~1.TXT => C:\DOCUME~1\DARBYS~1\LOCALS~1\Temp\2.txt|||

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll

————————————————–
End of report, 6,392 bytes
Report generated in 0.040 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only




This is so weird. All my scanner softwares seem to show the all clear but my laptop has never run so slow. I downloaded a wack file off astalavista kinda by accident and this has happened. I get the NT authority/system shutdown aswell and my internet is running incredibly slow, Plus my pc is going nuts telling me i have a virus, ( I DID THIS SCAN IN SAFEMODE, WOULD THIS MAKE IT MORE DIFFICULT FOR YOU TO SEE THE PROBLEM?), please help, it would be much appreciated. I cannot afford to format my comp, thanks Kalim
Hello Paul and welcome to the What the Tech

My name is Trevuren and I will be helping you with your problem.


With the little bit of information that you have provided, I can already see two major infections. We need to see a more complete picture to better evaluate the damage.

Download HijackThis from Here .
  • Choose the default location of C:\Program Files\Trend Micro\HijackThis as the destination. HJT needs to be in its own folder so that the program itself isn't deleted by accident. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!
  • Click the Install button.
  • Accept the license agreement .
  • Click Do a system scan and save a log file. A Notepad file will open.
  • Select all the text by hitting the [Ctrl+A] keys, then copy your selection to the clipboard by pressing the [Ctrl+C] keys.
  • Paste the log into this thread by hitting the [Ctrl+V] keys.
  • when you click Save Log) (Ctrl-A to'select all', Ctrl-C to 'copy')
  • POST the log into this thread using 'Add Reply' (Ctrl-V to 'paste')

DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS MOST OF THE FILES ARE LEGIT AND VITAL TO THE FUNCTION OF YOUR COMPUTER
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:45:21, on 03/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SystemRestoreStatus] rundll32.exe "C:\WINDOWS\system32\itnxctfk.dll",sitypnow
O4 - HKLM\..\Run: [Kaspersky Anti-Virus 2006] C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Ssha] "C:\WINDOWS\YMANTE~1\regsvr32.exe" -vt yazb
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to &LinkFox - res://C:\PROGRA~1\TWEAKM~1\TweakBHO.dll/IESCRIPT
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Script Checker - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\AVP6\scieplugin.dll
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - http://www.williamhillcasino.com (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - http://www.williamhillcasino.com (file missing) (HKCU)
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by134fd.bay134.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1188663167948
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVP - Kaspersky Lab - C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

–
End of file - 7716 bytes


Hi, I hope this scan is exactly what you requested, I am new to these procedures. I am also using avg anti virus as we speak hopefully this might aid a speedy recovery. Thanks for your help I hope this is fixable,
B
Hi here also is my AVG evaluation, I hope this may help also . Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4} -> Adware.ActivShopper : Ignored. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456} -> Adware.Generic : Ignored. C:\Program Files\p2pnetworks -> Adware.MediaPipe : Ignored. C:\Program Files\p2pnetworks\amp2pl.exe -> Adware.MediaPipe : Ignored. C:\Documents and Settings\Darbyshire\Application Data\Ultimate Fixer -> Adware.RogueSuspect : Ignored. C:\Documents and Settings\Darbyshire\Application Data\Ultimate Fixer\backup -> Adware.RogueSuspect : Ignored. C:\Documents and Settings\Darbyshire\Application Data\Ultimate Fixer\logs -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\95A14EA6.DLL -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\FE0A588.DLL -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\HS -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\HS\Help -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\HS\Help\English.chm -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\HS\HiJack.exe -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\HS\Language -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\HS\Language\Arabic.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\HS\Language\Arabic.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\HS\Language\English.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\HS\Language\English.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Help -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Help\LSPHelp.htm -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Help\help.chm -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Ini\update.ref -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\LSPFix.exe -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Chinese.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Chinese.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Dutch.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Dutch.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\English.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\English.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Francais.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Francais.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\German.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\German.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Italiano.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Italiano.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Japanese.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Japanese.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Korean.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Korean.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Slovenian.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Slovenian.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Spanish.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Spanish.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Swedish.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Swedish.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Turkish.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\Turkish.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\arabic.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\arabic.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\portugues.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Lang\portugues.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\LiveUpdate.cli -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\LiveUpdate.exe -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Patches -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Remove.reg -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\ScanLog02-09-07-94882.txt -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\ScanLog02-09-07-99049.txt -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Setting.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\SpyWatch.exe -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\Spyware.exe -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\errorlog.txt -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Help -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Help\pwhelp.chm -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Dutch.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Dutch.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\English.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\English.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Français.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Français.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\German.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\German.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Italiano.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Italiano.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Italiano1.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Italiano1.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Slovenian.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Slovenian.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Spanish.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Spanish.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Swedish.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Swedish.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Turkish.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\Turkish.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\arabic.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\arabic.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\português.bmp -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Lang\português.ini -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\PopUpWatch.exe -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound1.wav -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound10.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound11.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound12.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound13.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound14.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound15.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound16.wav -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound17.wav -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound18.wav -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound19.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound2.wav -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound20.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound21.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound22.wav -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound23.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound24.wav -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound25.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound26.wav -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound27.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound28.wav -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound3.wav -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound4.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound5.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound6.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound7.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound8.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\Sounds\Sound9.WAV -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\unins000.dat -> Adware.RogueSuspect : Ignored. C:\Program Files\BulletProofSoft.com\SpywareRemover\unins000.exe -> Adware.RogueSuspect : Ignored. C:\Program Files\Ultimate Cleaner -> Adware.RogueSuspect : Ignored. C:\Program Files\Ultimate Fixer -> Adware.RogueSuspect : Ignored. HKLM\SOFTWARE\Ultimate Fixer -> Adware.RogueSuspect : Ignored. HKU\S-1-5-21-746137067-113007714-1060284298-1005\Software\System Hijack Scanner -> Adware.RogueSuspect : Ignored. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WhenUSave -> Adware.SaveNow : Ignored. C:\Program Files\ucleaner_setup.exe -> Adware.UltimateDefender : Ignored. C:\System Volume Information\_restore{DF9A098D-F79D-496C-9DC5-60B9D2AC759B}\RP166\A0167067.exe -> Adware.UltimateDefender : Ignored. C:\Program Files\WinZix\WinZixManager.dll -> Adware.WinZix : Ignored. C:\Documents and Settings\Darbyshire\Local Settings\Temp\win47.tmp.exe -> Downloader.PurityScan.eg : Ignored. C:\Program Files\Common Files\Yazzle1162OinAdmin.exe -> Downloader.PurityScan.eg : Ignored. C:\System Volume Information\_restore{DF9A098D-F79D-496C-9DC5-60B9D2AC759B}\RP164\A0160163.exe -> Downloader.PurityScan.ej : Ignored. C:\My Downloads\AdsGone.Popup.Killer.2007.v7.0.8.1.WinALL-BRD.rar/AdsGone.Popup.Killer.2007.v7.0.8.1.WinALL-BRD\keygen\keygen.exe -> Dropper.Delf.xo : Ignored. C:\My Downloads\AdsGone.Popup.Killer.2007.v7.0.8.1.WinALL-BRD.rar/AdsGone.Popup.Killer.2007.v7.0.8.1.WinALL-BRD\setup\adsgone.exe -> Dropper.Delf.xo : Ignored. C:\Documents and Settings\Darbyshire\Local Settings\Temp\~DP68.exe -> Proxy.Agent.kj : Ignored. C:\Documents and Settings\Darbyshire\Local Settings\Temp\~DP73.exe -> Proxy.Agent.kj : Ignored. C:\WINDOWS\winlogon.exe -> Proxy.Agent.kj : Ignored. :mozilla.176:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.247realmedia : Ignored. :mozilla.177:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.247realmedia : Ignored. :mozilla.178:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.247realmedia : Ignored. :mozilla.72:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.247realmedia : Ignored. :mozilla.121:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.125:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.227:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.228:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.229:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.230:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.231:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.232:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.233:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.234:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.235:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.236:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.237:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.238:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.239:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.240:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.241:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.242:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.243:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.244:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.245:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.246:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.247:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.248:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.249:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.250:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.251:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.252:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.253:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.254:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.255:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.256:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.257:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.258:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.259:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.260:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.261:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.262:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.263:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.264:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.265:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.266:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.267:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.268:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.269:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.270:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.271:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.272:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.273:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.274:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.660:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.686:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.2o7 : Ignored. :mozilla.182:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.7search : Ignored. :mozilla.183:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.7search : Ignored. :mozilla.136:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Adbrite : Ignored. :mozilla.137:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Adbrite : Ignored. :mozilla.195:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adbrite : Ignored. :mozilla.196:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adbrite : Ignored. :mozilla.197:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adbrite : Ignored. :mozilla.100:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Adjuggler : Ignored. :mozilla.101:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Adjuggler : Ignored. :mozilla.67:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.68:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.74:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.75:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.76:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.77:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.78:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.79:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.83:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.84:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.85:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.86:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.87:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.88:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored. :mozilla.102:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adtech : Ignored. :mozilla.103:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adtech : Ignored. :mozilla.89:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Adtech : Ignored. :mozilla.16:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.17:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.18:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.19:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.82:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.83:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.84:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.85:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.87:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Advertising : Ignored. :mozilla.124:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Adviva : Ignored. :mozilla.690:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Adviva : Ignored. :mozilla.161:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Atdmt : Ignored. :mozilla.20:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Atdmt : Ignored. :mozilla.22:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Atdmt : Ignored. :mozilla.568:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Burstbeacon : Ignored. :mozilla.109:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Burstnet : Ignored. :mozilla.110:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Burstnet : Ignored. :mozilla.298:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Burstnet : Ignored. :mozilla.299:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Burstnet : Ignored. :mozilla.300:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Burstnet : Ignored. :mozilla.112:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.113:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.114:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.115:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.116:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.117:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.118:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.119:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.120:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored. :mozilla.18:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Clickbank : Ignored. :mozilla.212:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Clickhype : Ignored. :mozilla.213:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Clickhype : Ignored. :mozilla.214:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Clickhype : Ignored. :mozilla.289:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Com : Ignored. :mozilla.76:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Com : Ignored. :mozilla.692:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.951:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.952:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.953:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.954:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.955:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.956:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.957:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.958:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.959:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.960:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.961:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.962:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.963:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.964:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.965:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Connextra : Ignored. :mozilla.458:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Cpvfeed : Ignored. :mozilla.459:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Cpvfeed : Ignored. :mozilla.460:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Cpvfeed : Ignored. :mozilla.461:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Cpvfeed : Ignored. :mozilla.133:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Dealtime : Ignored. :mozilla.152:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Doubleclick : Ignored. :mozilla.36:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Doubleclick : Ignored. :mozilla.425:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Esomniture : Ignored. :mozilla.21:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Euroclick : Ignored. :mozilla.22:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Euroclick : Ignored. :mozilla.23:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Euroclick : Ignored. :mozilla.24:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Euroclick : Ignored. :mozilla.25:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Euroclick : Ignored. :mozilla.528:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Euroclick : Ignored. :mozilla.529:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Euroclick : Ignored. :mozilla.200:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Fastclick : Ignored. :mozilla.201:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Fastclick : Ignored. :mozilla.202:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Fastclick : Ignored. :mozilla.203:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Fastclick : Ignored. :mozilla.204:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Fastclick : Ignored. :mozilla.938:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Fortunecity : Ignored. :mozilla.939:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Fortunecity : Ignored. :mozilla.19:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored. :mozilla.785:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored. :mozilla.406:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.407:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.408:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.480:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.604:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.627:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.628:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.629:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.630:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.631:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.632:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.633:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.756:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.766:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.860:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.922:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.923:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.925:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Hitbox : Ignored. :mozilla.146:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Hitslink : Ignored. :mozilla.148:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Imrworldwide : Ignored. :mozilla.149:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Imrworldwide : Ignored. :mozilla.309:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Imrworldwide : Ignored. :mozilla.310:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Imrworldwide : Ignored. :mozilla.648:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Ivwbox : Ignored. :mozilla.477:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Live : Ignored. :mozilla.478:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Live : Ignored. :mozilla.479:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Live : Ignored. :mozilla.176:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored. :mozilla.378:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored. :mozilla.379:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored. :mozilla.637:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Navrcholu : Ignored. :mozilla.651:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Onestat : Ignored. :mozilla.652:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Onestat : Ignored. :mozilla.653:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Onestat : Ignored. :mozilla.63:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Overture : Ignored. :mozilla.678:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Overture : Ignored. :mozilla.680:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Overture : Ignored. :mozilla.682:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Overture : Ignored. :mozilla.111:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Paypal : Ignored. :mozilla.444:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Paypal : Ignored. :mozilla.37:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Pointroll : Ignored. :mozilla.38:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Pointroll : Ignored. :mozilla.39:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Pointroll : Ignored. :mozilla.30:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored. :mozilla.31:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored. :mozilla.521:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored. :mozilla.522:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored. :mozilla.175:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Realmedia : Ignored. :mozilla.694:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.695:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.699:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.700:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.701:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.702:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.703:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.704:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.705:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.706:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.707:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.708:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.709:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.710:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.711:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.71:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.74:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.930:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Revsci : Ignored. :mozilla.836:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Roispy : Ignored. :mozilla.837:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Roispy : Ignored. :mozilla.838:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Roispy : Ignored. :mozilla.389:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored. :mozilla.390:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored. :mozilla.391:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored. :mozilla.392:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored. :mozilla.393:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored. :mozilla.394:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored. :mozilla.65:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored. :mozilla.66:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored. :mozilla.67:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored. :mozilla.68:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored. :mozilla.69:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored. :mozilla.70:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored. :mozilla.360:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Sitestat : Ignored. :mozilla.647:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Sitestat : Ignored. :mozilla.170:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Specificclick : Ignored. :mozilla.171:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Specificclick : Ignored. :mozilla.172:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Specificclick : Ignored. :mozilla.173:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Specificclick : Ignored. :mozilla.174:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Specificclick : Ignored. :mozilla.175:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Specificclick : Ignored. :mozilla.869:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Specificclick : Ignored. :mozilla.870:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Specificclick : Ignored. :mozilla.871:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Specificclick : Ignored. :mozilla.106:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.305:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.311:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.312:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.313:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.314:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.315:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.316:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.317:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.318:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.319:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.320:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.321:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.322:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.323:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.324:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.325:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.326:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.327:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.328:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.329:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.330:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.331:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.332:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.333:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.334:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.335:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.336:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.337:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.338:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.339:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.340:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.341:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.342:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.343:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.344:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.345:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.346:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.347:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.348:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.349:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.350:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.351:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.352:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.353:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.354:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.355:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.356:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.357:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.358:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.359:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Statcounter : Ignored. :mozilla.107:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.108:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.497:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.498:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.499:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.500:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Tacoda : Ignored. :mozilla.636:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Toplist : Ignored. :mozilla.67:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignored. :mozilla.134:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Tribalfusion : Ignored. :mozilla.165:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Tribalfusion : Ignored. :mozilla.58:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Tribalfusion : Ignored. :mozilla.106:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Webtrends : Ignored. :mozilla.46:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Webtrends : Ignored. :mozilla.167:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Webtrendslive : Ignored. :mozilla.22:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Webtrendslive : Ignored. :mozilla.669:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Yadro : Ignored. :mozilla.131:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored. :mozilla.132:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored. :mozilla.133:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored. :mozilla.134:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored. :mozilla.135:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored. :mozilla.136:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored. :mozilla.171:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored. :mozilla.45:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Zedo : Ignored. :mozilla.46:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Zedo : Ignored. :mozilla.47:C:\Documents and Settings\Mum\Application Data\Mozilla\Firefox\Profiles\9f71zfob.default\cookies.txt -> TrackingCookie.Zedo : Ignored. :mozilla.656:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Zedo : Ignored. :mozilla.657:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Zedo : Ignored. :mozilla.658:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Zedo : Ignored. :mozilla.659:C:\Documents and Settings\Darbyshire\Application Data\Mozilla\Firefox\Profiles\bz5r6whm.default\cookies.txt -> TrackingCookie.Zedo : Ignored. :mozilla.79:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pch7669y.default\cookies.txt -> TrackingCookie.Zedo : Ignored. C:\System Volume Information\_restore{DF9A098D-F79D-496C-9DC5-60B9D2AC759B}\RP157\A0156461.exe -> Trojan.Obfuscated.en : Ignored. C:\System Volume Information\_restore{DF9A098D-F79D-496C-9DC5-60B9D2AC759B}\RP160\A0157983.exe -> Trojan.Obfuscated.en : Ignored. C:\System Volume Information\_restore{DF9A098D-F79D-496C-9DC5-60B9D2AC759B}\RP160\A0157988.exe -> Trojan.Obfuscated.en : Ignored. C:\WINDOWS\winh32.exe -> Trojan.Small : Ignored. C:\AddOn\Adobe\ACRO-READER_6.0.2_UPDATE.EXE -> Worm.VB.dz : Ignored. C:\System Volume Information\_restore{DF9A098D-F79D-496C-9DC5-60B9D2AC759B}\RP166\A0171194.exe -> Worm.VB.dz : Ignored. C:\WINDOWS\svchost.exe -> Worm.VB.dz : Ignored. ::Report end
Jeeeez This is getting worse. I now sign on and there is a loud scream or screech. Cat??? animal sound after the windows default sound! My desktop has turned black displaying [my ip address and a warning of a virus that has affected my pc. I have virus software that is going nuts, and it keeps popping up but when i use them there is no affect. What the hell is going on? this is one hell of a virus. Please help,
Please download this file - combofix.exe by sUBs
  • Save it to your Desktop
  • Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)
  • Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box.

    "%userprofile%\desktop\ComboFix.exe" /KillAll



    [external image: Posted Image]

  • Click OK and this will start ComboFix in a special way.
  • When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
I done both scans under the administrator account in safe mode as the normal mode is inoperable and slow.

here is "combofix" log……………………………….

ComboFix 07-09-04 - "Administrator" 2007-09-04 19:28:32.3 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.224 [GMT 1:00]
Command switches used :: /KillAll


((((((((((((((((((((((((( Files Created from 2007-08-04 to 2007-09-04 )))))))))))))))))))))))))))))))


2007-09-03 18:45 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-03 18:26 70,208 –a—— C:\WINDOWS\system32\bvlkernd.dll
2007-09-03 18:20 74,816 –a—— C:\WINDOWS\system32\atscancs.dll
2007-09-03 16:00 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\vlc
2007-09-03 14:45 d——– C:\DOCUME~1\ADMINI~1\Contacts
2007-09-03 02:29 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-02 22:40 d——– C:\Program Files\BulletProofSoft.com
2007-09-02 22:39 d——– C:\BPS Spyware-Adware Remover
2007-09-02 18:53 18,432 –a—— C:\WINDOWS\winh32.exe
2007-09-02 18:38 31,232 –a—— C:\WINDOWS\system32\msole32.exe
2007-09-02 18:38 21,248 –a—— C:\WINDOWS\eventlowg.dll
2007-09-02 18:38 11,776 –a—— C:\WINDOWS\daxtime.dll
2007-09-02 18:37 32,512 –a—— C:\WINDOWS\ngd.dll
2007-09-02 18:37 27,136 –a—— C:\WINDOWS\spredirect.dll
2007-09-02 18:37 17,408 –a—— C:\WINDOWS\ie_32.exe
2007-09-02 18:37 17,152 –a—— C:\WINDOWS\system32\ace16win.dll
2007-09-02 18:37 15,104 –a—— C:\WINDOWS\jd2002.dll
2007-09-02 18:37 13,056 –a—— C:\WINDOWS\system32\ESHOPEE.exe
2007-09-02 18:37 10,496 –a—— C:\WINDOWS\adbar.dll
2007-09-02 18:37 d——– C:\WINDOWS\system32\acespy
2007-09-02 18:37 d——– C:\Program Files\e-zshopper
2007-09-02 18:37 d——– C:\Program Files\amsys
2007-09-02 18:37 d——– C:\Program Files\akl
2007-09-02 18:37 d——– C:\Program Files\Accoona
2007-09-02 18:23 70,208 –a—— C:\WINDOWS\system32\wwasyhtp.dll
2007-09-02 18:19 74,816 –a—— C:\WINDOWS\system32\itnxctfk.dll
2007-09-02 18:16 21,504 –a—— C:\WINDOWS\system32\oembios32.dll
2007-09-01 20:14 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-01 20:10 74,816 –a—— C:\WINDOWS\system32\rsdiblnp.dll
2007-09-01 20:07 70,208 –a—— C:\WINDOWS\system32\tedjgvab.dll
2007-09-01 19:37 d——– C:\WINDOWS\LastGood
2007-09-01 18:54 26,730 –a—— C:\WINDOWS\system32\fssync.dll
2007-09-01 18:54 170,272 –ahs—- C:\WINDOWS\fidbox.dat
2007-09-01 18:54 13,418 –a—— C:\WINDOWS\system32\klogon.dll
2007-09-01 18:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Anti-Virus Personal
2007-09-01 18:15 d——– C:\Program Files\Kaspersky Lab
2007-09-01 17:17 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-09-01 17:17 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-01 14:22 70,208 –a—— C:\WINDOWS\system32\rxcprhva.dll
2007-09-01 14:19 74,816 –a—— C:\WINDOWS\system32\vsstoecf.dll
2007-09-01 13:18 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
2007-09-01 01:51 75,792 –a—— C:\WINDOWS\system32\drivers\tmtdi.sys
2007-09-01 01:51 32,528 –a—— C:\WINDOWS\system32\drivers\tmpreflt.sys
2007-09-01 01:51 300,816 –a—— C:\WINDOWS\system32\drivers\TM_CFW.sys
2007-09-01 01:51 199,440 –a—— C:\WINDOWS\system32\drivers\tmxpflt.sys
2007-09-01 01:51 112,400 –a—— C:\WINDOWS\system32\drivers\tm_mbd_c.sys
2007-09-01 01:51 1,052,472 –a—— C:\WINDOWS\system32\drivers\vsapint.sys
2007-09-01 01:51 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-09-01 01:48 d——– C:\Program Files\Trend Micro
2007-09-01 01:39 74,816 –a—— C:\WINDOWS\system32\qeacpbsc.dll
2007-09-01 01:35 70,208 –a—— C:\WINDOWS\system32\gqrsviox.dll
2007-09-01 01:32 1,257,935 —hs—- C:\WINDOWS\system32\cdefe.bak2
2007-08-31 14:29 22,528 –a—— C:\WINDOWS\system32\winuxh32.dll
2007-08-31 14:07 713 –a—— C:\WINDOWS\eReg.dat
2007-08-28 15:32 d——– C:\NoLopBackups
2007-08-23 21:29 d——– C:\Program Files\TweakMASTER
2007-08-23 21:29 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hagel Technologies
2007-08-23 19:36 d——– C:\Program Files\DivX
2007-08-23 00:30 352,137 –a—— C:\swlist.reg
2007-08-21 00:33 d——– C:\Program Files\Rockstar Games
2007-08-21 00:05 9,600 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys
2007-08-21 00:05 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2007-08-20 20:52 d——– C:\Program Files\GTA
2007-08-19 21:35 d——– C:\Program Files\WinZix
2007-08-18 22:23 d——– C:\Program Files\blackmagic
2007-08-11 19:17 d——– C:\Program Files\iPod
2007-08-11 19:16 d——– C:\Program Files\iTunes
2007-08-11 11:16 d——– C:\Program Files\Sports Interactive
2007-08-10 20:02 d——– C:\Program Files\DaemonTools_WhenUSave_Installer
2007-08-10 20:02 d——– C:\Program Files\DAEMON Tools
2007-08-10 19:55 682,232 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2007-08-10 15:08 d——– C:\Program Files\Smart Projects
2007-08-10 13:59 d——– C:\Program Files\AdsGone


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-04 19:11 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kontiki
2007-09-03 15:04 163644 –a—— C:\WINDOWS\system32\drivers\secdrv.sys
2007-09-02 18:16 821 –a—— C:\WINDOWS\system32\drivers\shadow_bg.gif
2007-09-02 18:16 72 –a—— C:\WINDOWS\system32\drivers\bg_bg.gif
2007-09-02 18:16 64 –a—— C:\WINDOWS\system32\drivers\close_ico.gif
2007-09-02 18:16 3031 –a—— C:\WINDOWS\system32\drivers\spyware_detected.gif
2007-09-02 18:16 1743 –a—— C:\WINDOWS\system32\drivers\remove_spyware_header.gif
2007-09-02 18:16 16941 –a—— C:\WINDOWS\system32\drivers\icon_warning_big.gif
2007-09-02 18:16 1381 –a—— C:\WINDOWS\system32\drivers\warning_ico.gif
2007-09-02 18:16 1014 –a—— C:\WINDOWS\system32\drivers\yellow_warning_ico.gif
2007-09-02 18:15 8852 –a—— C:\WINDOWS\system32\drivers\download_btn.jpg
2007-09-02 18:15 877 –a—— C:\WINDOWS\system32\drivers\header_red_bg.gif
2007-09-02 18:15 838 –a—— C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
2007-09-02 18:15 4448 –a—— C:\WINDOWS\system32\drivers\download_now_btn.gif
2007-09-02 18:15 4008 –a—— C:\WINDOWS\system32\drivers\rating.gif
2007-09-02 18:15 3552 –a—— C:\WINDOWS\system32\drivers\cell_header_remove.gif
2007-09-02 18:15 3479 –a—— C:\WINDOWS\system32\drivers\cell_header_scan.gif
2007-09-02 18:15 3313 –a—— C:\WINDOWS\system32\drivers\cell_header_block.gif
2007-09-02 18:15 3216 –a—— C:\WINDOWS\system32\drivers\header_red_free_scan.gif
2007-09-02 18:15 26487 –a—— C:\WINDOWS\system32\drivers\screenshot.jpg
2007-09-02 18:15 16977 –a—— C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
2007-09-02 18:15 1373 –a—— C:\WINDOWS\system32\drivers\cell_footer.gif
2007-09-02 18:15 1342 –a—— C:\WINDOWS\system32\drivers\cell_bg.gif
2007-08-31 13:53 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-31 13:53 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-28 15:47 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tick Find Close Surf
2007-08-18 22:09 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ball Shim Dupe Tick
2007-08-10 18:24 ——— d——– C:\Program Files\Windows Media Connect 2
2007-08-10 18:24 ——— d——– C:\Program Files\Trickshot
2007-08-10 18:24 ——— d——– C:\Program Files\3wPlayer
2007-08-07 16:31 ——— d——– C:\Program Files\Kontiki
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 207736 –a—— C:\WINDOWS\system32\muweb.dll
2007-07-27 00:06 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-07-27 00:06 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-07-26 22:51 ——— d——– C:\Program Files\CDBurnerXP Pro 3
2007-07-22 15:50 ——— d——– C:\Program Files\QuickTime
2007-07-22 15:48 ——— d——– C:\Program Files\Apple Software Update
2007-07-20 21:18 ——— d——– C:\DOCUME~1\Mum\APPLIC~1\Google
2007-07-20 17:00 ——— d——– C:\Program Files\DesktopNerds
2007-07-09 22:15 ——— d——– C:\Program Files\Common Files\Apple
2007-07-09 22:15 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-06-26 07:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-23 23:43 2560 –a—— C:\WINDOWS\system32\BitCometRes.dll
2007-06-19 14:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 11:23 1033216 –a—— C:\WINDOWS\explorer.exe
2003-08-31 14:32 71526 –a—— C:\Program Files\setup.exe
2003-08-31 14:30 98304 –a—— C:\DOCUME~1\ALLUSE~1\APPLIC~1\xqtylgdm.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39C6B6C8-E01E-3175-B583-04FDA1EE088B}]
2003-08-31 14:30 98304 –a—— C:\Program Files\Xbgiliru\tsefttwp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AB5FE6E5-7C72-4B89-85D0-D57E7AEAC236}]
2007-09-02 18:16 21504 –a—— C:\WINDOWS\system32\oembios32.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C1ADC5ED-FB26-4770-AFE5-BD3A7EB5C148}]
2003-08-31 14:29 43542 –a—— C:\WINDOWS\system32\nnnnnlm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E64F0381-0053-4842-B3E5-08F6C4A0AEB6}]
2007-09-03 18:27 70208 –a—— C:\WINDOWS\system32\bvlkernd.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F3295BF6-C520-4748-A22B-340A373A48BF}]
2003-08-31 14:34 297568 –a—— C:\WINDOWS\system32\efedc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2004-11-08 10:36 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2004-11-08 10:36 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-11-08 10:43 C:\WINDOWS\SOUNDMAN.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-11-08 11:52 C:\WINDOWS\AGRSMMSG.exe]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-16 17:45]
"BearShare"="C:\Program Files\BearShare\BearShare.exe" [2006-02-13 11:48]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"Kaspersky Anti-Virus 2006"="C:\Program Files\Kaspersky Lab\AVP6\avp.exe" [2005-06-10 14:02]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
AdsGone 2004.lnk - C:\Program Files\AdsGone\adsgone.exe [2004-12-06 15:36:26]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{C1ADC5ED-FB26-4770-AFE5-BD3A7EB5C148}"= C:\WINDOWS\system32\nnnnnlm.dll [2003-08-31 14:29 43542]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efedc]
C:\WINDOWS\system32\efedc.dll 2003-08-31 14:34 297568 C:\WINDOWS\system32\efedc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnnnlm]
nnnnnlm.dll 2003-08-31 14:29 43542 C:\WINDOWS\system32\nnnnnlm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winuxh32]
winuxh32.dll 2007-08-31 14:29 22528 C:\WINDOWS\system32\winuxh32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Darbyshire^Start Menu^Programs^Startup^AdsGone.lnk]
path=C:\Documents and Settings\Darbyshire\Start Menu\Programs\Startup\AdsGone.lnk
backup=C:\WINDOWS\pss\AdsGone.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\avp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
"C:\Program Files\BearShare\BearShare.exe" /pause

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
rundll32.exe C:\WINDOWS\system32\drvsom.dll,startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
C:\Program Files\Eraser\eraser.exe -hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kaspersky Anti-Virus 2006]
C:\Program Files\Kaspersky Lab\AVP6\avp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAVPersonal50]
"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
C:\Program Files\ltmoh\Ltmoh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pccguide.exe]
"C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\retadpu2000352.exe 61A847B5BBF72810329B385577FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
mgrs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ssha]
"C:\WINDOWS\YMANTE~1\regsvr32.exe" -vt yazb

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemRestoreStatus]
rundll32.exe "C:\WINDOWS\system32\rsdiblnp.dll",sitypnow

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TweakMASTER]
"C:\PROGRA~1\TWEAKM~1\TMTray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ultimate Fixer]
"C:\Program Files\Ultimate Fixer\UltimateFixer.exe" hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
%systemroot%\system32\dumprep 0 -u

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave]
"C:\Program Files\Save\Save.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xitutcni]
rundll32.exe "C:\Program Files\xitutcni\nsdiredi.dll",Init

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xqtylgdm]
regsvr32 /u "C:\Documents and Settings\All Users\Application Data\xqtylgdm.dll"
R3 PxHelper;PxHelper;\??\C:\WINDOWS\system32\drivers\PxHelper.sys
S1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys
S2 tmxpflt;tmxpflt;C:\WINDOWS\system32\DRIVERS\tmxpflt.sys
S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys


Contents of the 'Scheduled Tasks' folder
2007-08-10 12:59:58 C:\WINDOWS\Tasks\AdsGone.job - C:\Program Files\AdsGone\AdsGone.exe
2007-08-11 17:53:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-04 19:32:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-04 19:35:48
C:\ComboFix-quarantined-files.txt … 2007-09-04 19:35
C:\ComboFix2.txt … 2007-09-04 19:26

— E O F —


And as requested the Hijakthis Log……………………………………………………….


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:45:37, on 04/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Kaspersky Anti-Virus 2006] C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Script Checker - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\AVP6\scieplugin.dll
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by134fd.bay134.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1188663167948
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVP - Kaspersky Lab - C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

–
End of file - 6697 bytes
I used each software "combofix and hijak this" in administrator on safe mode as the normal log in is to slow and basically inopperable.

Here is the combofix log………………………


ComboFix 07-09-04 - "Administrator" 2007-09-04 19:28:32.3 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.224 [GMT 1:00]
Command switches used :: /KillAll


((((((((((((((((((((((((( Files Created from 2007-08-04 to 2007-09-04 )))))))))))))))))))))))))))))))


2007-09-03 18:45 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-03 18:26 70,208 –a—— C:\WINDOWS\system32\bvlkernd.dll
2007-09-03 18:20 74,816 –a—— C:\WINDOWS\system32\atscancs.dll
2007-09-03 16:00 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\vlc
2007-09-03 14:45 d——– C:\DOCUME~1\ADMINI~1\Contacts
2007-09-03 02:29 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-02 22:40 d——– C:\Program Files\BulletProofSoft.com
2007-09-02 22:39 d——– C:\BPS Spyware-Adware Remover
2007-09-02 18:53 18,432 –a—— C:\WINDOWS\winh32.exe
2007-09-02 18:38 31,232 –a—— C:\WINDOWS\system32\msole32.exe
2007-09-02 18:38 21,248 –a—— C:\WINDOWS\eventlowg.dll
2007-09-02 18:38 11,776 –a—— C:\WINDOWS\daxtime.dll
2007-09-02 18:37 32,512 –a—— C:\WINDOWS\ngd.dll
2007-09-02 18:37 27,136 –a—— C:\WINDOWS\spredirect.dll
2007-09-02 18:37 17,408 –a—— C:\WINDOWS\ie_32.exe
2007-09-02 18:37 17,152 –a—— C:\WINDOWS\system32\ace16win.dll
2007-09-02 18:37 15,104 –a—— C:\WINDOWS\jd2002.dll
2007-09-02 18:37 13,056 –a—— C:\WINDOWS\system32\ESHOPEE.exe
2007-09-02 18:37 10,496 –a—— C:\WINDOWS\adbar.dll
2007-09-02 18:37 d——– C:\WINDOWS\system32\acespy
2007-09-02 18:37 d——– C:\Program Files\e-zshopper
2007-09-02 18:37 d——– C:\Program Files\amsys
2007-09-02 18:37 d——– C:\Program Files\akl
2007-09-02 18:37 d——– C:\Program Files\Accoona
2007-09-02 18:23 70,208 –a—— C:\WINDOWS\system32\wwasyhtp.dll
2007-09-02 18:19 74,816 –a—— C:\WINDOWS\system32\itnxctfk.dll
2007-09-02 18:16 21,504 –a—— C:\WINDOWS\system32\oembios32.dll
2007-09-01 20:14 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-01 20:10 74,816 –a—— C:\WINDOWS\system32\rsdiblnp.dll
2007-09-01 20:07 70,208 –a—— C:\WINDOWS\system32\tedjgvab.dll
2007-09-01 19:37 d——– C:\WINDOWS\LastGood
2007-09-01 18:54 26,730 –a—— C:\WINDOWS\system32\fssync.dll
2007-09-01 18:54 170,272 –ahs—- C:\WINDOWS\fidbox.dat
2007-09-01 18:54 13,418 –a—— C:\WINDOWS\system32\klogon.dll
2007-09-01 18:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Anti-Virus Personal
2007-09-01 18:15 d——– C:\Program Files\Kaspersky Lab
2007-09-01 17:17 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-09-01 17:17 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-01 14:22 70,208 –a—— C:\WINDOWS\system32\rxcprhva.dll
2007-09-01 14:19 74,816 –a—— C:\WINDOWS\system32\vsstoecf.dll
2007-09-01 13:18 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
2007-09-01 01:51 75,792 –a—— C:\WINDOWS\system32\drivers\tmtdi.sys
2007-09-01 01:51 32,528 –a—— C:\WINDOWS\system32\drivers\tmpreflt.sys
2007-09-01 01:51 300,816 –a—— C:\WINDOWS\system32\drivers\TM_CFW.sys
2007-09-01 01:51 199,440 –a—— C:\WINDOWS\system32\drivers\tmxpflt.sys
2007-09-01 01:51 112,400 –a—— C:\WINDOWS\system32\drivers\tm_mbd_c.sys
2007-09-01 01:51 1,052,472 –a—— C:\WINDOWS\system32\drivers\vsapint.sys
2007-09-01 01:51 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-09-01 01:48 d——– C:\Program Files\Trend Micro
2007-09-01 01:39 74,816 –a—— C:\WINDOWS\system32\qeacpbsc.dll
2007-09-01 01:35 70,208 –a—— C:\WINDOWS\system32\gqrsviox.dll
2007-09-01 01:32 1,257,935 —hs—- C:\WINDOWS\system32\cdefe.bak2
2007-08-31 14:29 22,528 –a—— C:\WINDOWS\system32\winuxh32.dll
2007-08-31 14:07 713 –a—— C:\WINDOWS\eReg.dat
2007-08-28 15:32 d——– C:\NoLopBackups
2007-08-23 21:29 d——– C:\Program Files\TweakMASTER
2007-08-23 21:29 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hagel Technologies
2007-08-23 19:36 d——– C:\Program Files\DivX
2007-08-23 00:30 352,137 –a—— C:\swlist.reg
2007-08-21 00:33 d——– C:\Program Files\Rockstar Games
2007-08-21 00:05 9,600 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys
2007-08-21 00:05 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2007-08-20 20:52 d——– C:\Program Files\GTA
2007-08-19 21:35 d——– C:\Program Files\WinZix
2007-08-18 22:23 d——– C:\Program Files\blackmagic
2007-08-11 19:17 d——– C:\Program Files\iPod
2007-08-11 19:16 d——– C:\Program Files\iTunes
2007-08-11 11:16 d——– C:\Program Files\Sports Interactive
2007-08-10 20:02 d——– C:\Program Files\DaemonTools_WhenUSave_Installer
2007-08-10 20:02 d——– C:\Program Files\DAEMON Tools
2007-08-10 19:55 682,232 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2007-08-10 15:08 d——– C:\Program Files\Smart Projects
2007-08-10 13:59 d——– C:\Program Files\AdsGone


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-04 19:11 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kontiki
2007-09-03 15:04 163644 –a—— C:\WINDOWS\system32\drivers\secdrv.sys
2007-09-02 18:16 821 –a—— C:\WINDOWS\system32\drivers\shadow_bg.gif
2007-09-02 18:16 72 –a—— C:\WINDOWS\system32\drivers\bg_bg.gif
2007-09-02 18:16 64 –a—— C:\WINDOWS\system32\drivers\close_ico.gif
2007-09-02 18:16 3031 –a—— C:\WINDOWS\system32\drivers\spyware_detected.gif
2007-09-02 18:16 1743 –a—— C:\WINDOWS\system32\drivers\remove_spyware_header.gif
2007-09-02 18:16 16941 –a—— C:\WINDOWS\system32\drivers\icon_warning_big.gif
2007-09-02 18:16 1381 –a—— C:\WINDOWS\system32\drivers\warning_ico.gif
2007-09-02 18:16 1014 –a—— C:\WINDOWS\system32\drivers\yellow_warning_ico.gif
2007-09-02 18:15 8852 –a—— C:\WINDOWS\system32\drivers\download_btn.jpg
2007-09-02 18:15 877 –a—— C:\WINDOWS\system32\drivers\header_red_bg.gif
2007-09-02 18:15 838 –a—— C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
2007-09-02 18:15 4448 –a—— C:\WINDOWS\system32\drivers\download_now_btn.gif
2007-09-02 18:15 4008 –a—— C:\WINDOWS\system32\drivers\rating.gif
2007-09-02 18:15 3552 –a—— C:\WINDOWS\system32\drivers\cell_header_remove.gif
2007-09-02 18:15 3479 –a—— C:\WINDOWS\system32\drivers\cell_header_scan.gif
2007-09-02 18:15 3313 –a—— C:\WINDOWS\system32\drivers\cell_header_block.gif
2007-09-02 18:15 3216 –a—— C:\WINDOWS\system32\drivers\header_red_free_scan.gif
2007-09-02 18:15 26487 –a—— C:\WINDOWS\system32\drivers\screenshot.jpg
2007-09-02 18:15 16977 –a—— C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
2007-09-02 18:15 1373 –a—— C:\WINDOWS\system32\drivers\cell_footer.gif
2007-09-02 18:15 1342 –a—— C:\WINDOWS\system32\drivers\cell_bg.gif
2007-08-31 13:53 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-31 13:53 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-28 15:47 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tick Find Close Surf
2007-08-18 22:09 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ball Shim Dupe Tick
2007-08-10 18:24 ——— d——– C:\Program Files\Windows Media Connect 2
2007-08-10 18:24 ——— d——– C:\Program Files\Trickshot
2007-08-10 18:24 ——— d——– C:\Program Files\3wPlayer
2007-08-07 16:31 ——— d——– C:\Program Files\Kontiki
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 207736 –a—— C:\WINDOWS\system32\muweb.dll
2007-07-27 00:06 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-07-27 00:06 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-07-26 22:51 ——— d——– C:\Program Files\CDBurnerXP Pro 3
2007-07-22 15:50 ——— d——– C:\Program Files\QuickTime
2007-07-22 15:48 ——— d——– C:\Program Files\Apple Software Update
2007-07-20 21:18 ——— d——– C:\DOCUME~1\Mum\APPLIC~1\Google
2007-07-20 17:00 ——— d——– C:\Program Files\DesktopNerds
2007-07-09 22:15 ——— d——– C:\Program Files\Common Files\Apple
2007-07-09 22:15 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-06-26 07:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-23 23:43 2560 –a—— C:\WINDOWS\system32\BitCometRes.dll
2007-06-19 14:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 11:23 1033216 –a—— C:\WINDOWS\explorer.exe
2003-08-31 14:32 71526 –a—— C:\Program Files\setup.exe
2003-08-31 14:30 98304 –a—— C:\DOCUME~1\ALLUSE~1\APPLIC~1\xqtylgdm.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39C6B6C8-E01E-3175-B583-04FDA1EE088B}]
2003-08-31 14:30 98304 –a—— C:\Program Files\Xbgiliru\tsefttwp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AB5FE6E5-7C72-4B89-85D0-D57E7AEAC236}]
2007-09-02 18:16 21504 –a—— C:\WINDOWS\system32\oembios32.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C1ADC5ED-FB26-4770-AFE5-BD3A7EB5C148}]
2003-08-31 14:29 43542 –a—— C:\WINDOWS\system32\nnnnnlm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E64F0381-0053-4842-B3E5-08F6C4A0AEB6}]
2007-09-03 18:27 70208 –a—— C:\WINDOWS\system32\bvlkernd.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F3295BF6-C520-4748-A22B-340A373A48BF}]
2003-08-31 14:34 297568 –a—— C:\WINDOWS\system32\efedc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2004-11-08 10:36 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2004-11-08 10:36 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-11-08 10:43 C:\WINDOWS\SOUNDMAN.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-11-08 11:52 C:\WINDOWS\AGRSMMSG.exe]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-16 17:45]
"BearShare"="C:\Program Files\BearShare\BearShare.exe" [2006-02-13 11:48]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"Kaspersky Anti-Virus 2006"="C:\Program Files\Kaspersky Lab\AVP6\avp.exe" [2005-06-10 14:02]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
AdsGone 2004.lnk - C:\Program Files\AdsGone\adsgone.exe [2004-12-06 15:36:26]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{C1ADC5ED-FB26-4770-AFE5-BD3A7EB5C148}"= C:\WINDOWS\system32\nnnnnlm.dll [2003-08-31 14:29 43542]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efedc]
C:\WINDOWS\system32\efedc.dll 2003-08-31 14:34 297568 C:\WINDOWS\system32\efedc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnnnlm]
nnnnnlm.dll 2003-08-31 14:29 43542 C:\WINDOWS\system32\nnnnnlm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winuxh32]
winuxh32.dll 2007-08-31 14:29 22528 C:\WINDOWS\system32\winuxh32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Darbyshire^Start Menu^Programs^Startup^AdsGone.lnk]
path=C:\Documents and Settings\Darbyshire\Start Menu\Programs\Startup\AdsGone.lnk
backup=C:\WINDOWS\pss\AdsGone.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\avp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
"C:\Program Files\BearShare\BearShare.exe" /pause

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
rundll32.exe C:\WINDOWS\system32\drvsom.dll,startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
C:\Program Files\Eraser\eraser.exe -hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kaspersky Anti-Virus 2006]
C:\Program Files\Kaspersky Lab\AVP6\avp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAVPersonal50]
"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
C:\Program Files\ltmoh\Ltmoh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pccguide.exe]
"C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\retadpu2000352.exe 61A847B5BBF72810329B385577FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
mgrs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ssha]
"C:\WINDOWS\YMANTE~1\regsvr32.exe" -vt yazb

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemRestoreStatus]
rundll32.exe "C:\WINDOWS\system32\rsdiblnp.dll",sitypnow

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TweakMASTER]
"C:\PROGRA~1\TWEAKM~1\TMTray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ultimate Fixer]
"C:\Program Files\Ultimate Fixer\UltimateFixer.exe" hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
%systemroot%\system32\dumprep 0 -u

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave]
"C:\Program Files\Save\Save.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xitutcni]
rundll32.exe "C:\Program Files\xitutcni\nsdiredi.dll",Init

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xqtylgdm]
regsvr32 /u "C:\Documents and Settings\All Users\Application Data\xqtylgdm.dll"
R3 PxHelper;PxHelper;\??\C:\WINDOWS\system32\drivers\PxHelper.sys
S1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys
S2 tmxpflt;tmxpflt;C:\WINDOWS\system32\DRIVERS\tmxpflt.sys
S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys


Contents of the 'Scheduled Tasks' folder
2007-08-10 12:59:58 C:\WINDOWS\Tasks\AdsGone.job - C:\Program Files\AdsGone\AdsGone.exe
2007-08-11 17:53:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-04 19:32:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-04 19:35:48
C:\ComboFix-quarantined-files.txt … 2007-09-04 19:35
C:\ComboFix2.txt … 2007-09-04 19:26

— E O F —


And here is the Hijakthis log as requested…………………………………………….


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:45:37, on 04/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Kaspersky Anti-Virus 2006] C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Script Checker - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\AVP6\scieplugin.dll
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by134fd.bay134.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1188663167948
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVP - Kaspersky Lab - C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

–
End of file - 6697 bytes

Thanks,
I used each software "combofix and hijak this" in administrator on safe mode as the normal log in is to slow and basically inopperable.

Here is the combofix log………………………


ComboFix 07-09-04 - "Administrator" 2007-09-04 19:28:32.3 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.224 [GMT 1:00]
Command switches used :: /KillAll


((((((((((((((((((((((((( Files Created from 2007-08-04 to 2007-09-04 )))))))))))))))))))))))))))))))


2007-09-03 18:45 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-03 18:26 70,208 –a—— C:\WINDOWS\system32\bvlkernd.dll
2007-09-03 18:20 74,816 –a—— C:\WINDOWS\system32\atscancs.dll
2007-09-03 16:00 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\vlc
2007-09-03 14:45 d——– C:\DOCUME~1\ADMINI~1\Contacts
2007-09-03 02:29 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-02 22:40 d——– C:\Program Files\BulletProofSoft.com
2007-09-02 22:39 d——– C:\BPS Spyware-Adware Remover
2007-09-02 18:53 18,432 –a—— C:\WINDOWS\winh32.exe
2007-09-02 18:38 31,232 –a—— C:\WINDOWS\system32\msole32.exe
2007-09-02 18:38 21,248 –a—— C:\WINDOWS\eventlowg.dll
2007-09-02 18:38 11,776 –a—— C:\WINDOWS\daxtime.dll
2007-09-02 18:37 32,512 –a—— C:\WINDOWS\ngd.dll
2007-09-02 18:37 27,136 –a—— C:\WINDOWS\spredirect.dll
2007-09-02 18:37 17,408 –a—— C:\WINDOWS\ie_32.exe
2007-09-02 18:37 17,152 –a—— C:\WINDOWS\system32\ace16win.dll
2007-09-02 18:37 15,104 –a—— C:\WINDOWS\jd2002.dll
2007-09-02 18:37 13,056 –a—— C:\WINDOWS\system32\ESHOPEE.exe
2007-09-02 18:37 10,496 –a—— C:\WINDOWS\adbar.dll
2007-09-02 18:37 d——– C:\WINDOWS\system32\acespy
2007-09-02 18:37 d——– C:\Program Files\e-zshopper
2007-09-02 18:37 d——– C:\Program Files\amsys
2007-09-02 18:37 d——– C:\Program Files\akl
2007-09-02 18:37 d——– C:\Program Files\Accoona
2007-09-02 18:23 70,208 –a—— C:\WINDOWS\system32\wwasyhtp.dll
2007-09-02 18:19 74,816 –a—— C:\WINDOWS\system32\itnxctfk.dll
2007-09-02 18:16 21,504 –a—— C:\WINDOWS\system32\oembios32.dll
2007-09-01 20:14 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-01 20:10 74,816 –a—— C:\WINDOWS\system32\rsdiblnp.dll
2007-09-01 20:07 70,208 –a—— C:\WINDOWS\system32\tedjgvab.dll
2007-09-01 19:37 d——– C:\WINDOWS\LastGood
2007-09-01 18:54 26,730 –a—— C:\WINDOWS\system32\fssync.dll
2007-09-01 18:54 170,272 –ahs—- C:\WINDOWS\fidbox.dat
2007-09-01 18:54 13,418 –a—— C:\WINDOWS\system32\klogon.dll
2007-09-01 18:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Anti-Virus Personal
2007-09-01 18:15 d——– C:\Program Files\Kaspersky Lab
2007-09-01 17:17 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-09-01 17:17 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-01 14:22 70,208 –a—— C:\WINDOWS\system32\rxcprhva.dll
2007-09-01 14:19 74,816 –a—— C:\WINDOWS\system32\vsstoecf.dll
2007-09-01 13:18 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
2007-09-01 01:51 75,792 –a—— C:\WINDOWS\system32\drivers\tmtdi.sys
2007-09-01 01:51 32,528 –a—— C:\WINDOWS\system32\drivers\tmpreflt.sys
2007-09-01 01:51 300,816 –a—— C:\WINDOWS\system32\drivers\TM_CFW.sys
2007-09-01 01:51 199,440 –a—— C:\WINDOWS\system32\drivers\tmxpflt.sys
2007-09-01 01:51 112,400 –a—— C:\WINDOWS\system32\drivers\tm_mbd_c.sys
2007-09-01 01:51 1,052,472 –a—— C:\WINDOWS\system32\drivers\vsapint.sys
2007-09-01 01:51 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-09-01 01:48 d——– C:\Program Files\Trend Micro
2007-09-01 01:39 74,816 –a—— C:\WINDOWS\system32\qeacpbsc.dll
2007-09-01 01:35 70,208 –a—— C:\WINDOWS\system32\gqrsviox.dll
2007-09-01 01:32 1,257,935 —hs—- C:\WINDOWS\system32\cdefe.bak2
2007-08-31 14:29 22,528 –a—— C:\WINDOWS\system32\winuxh32.dll
2007-08-31 14:07 713 –a—— C:\WINDOWS\eReg.dat
2007-08-28 15:32 d——– C:\NoLopBackups
2007-08-23 21:29 d——– C:\Program Files\TweakMASTER
2007-08-23 21:29 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hagel Technologies
2007-08-23 19:36 d——– C:\Program Files\DivX
2007-08-23 00:30 352,137 –a—— C:\swlist.reg
2007-08-21 00:33 d——– C:\Program Files\Rockstar Games
2007-08-21 00:05 9,600 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys
2007-08-21 00:05 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2007-08-20 20:52 d——– C:\Program Files\GTA
2007-08-19 21:35 d——– C:\Program Files\WinZix
2007-08-18 22:23 d——– C:\Program Files\blackmagic
2007-08-11 19:17 d——– C:\Program Files\iPod
2007-08-11 19:16 d——– C:\Program Files\iTunes
2007-08-11 11:16 d——– C:\Program Files\Sports Interactive
2007-08-10 20:02 d——– C:\Program Files\DaemonTools_WhenUSave_Installer
2007-08-10 20:02 d——– C:\Program Files\DAEMON Tools
2007-08-10 19:55 682,232 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2007-08-10 15:08 d——– C:\Program Files\Smart Projects
2007-08-10 13:59 d——– C:\Program Files\AdsGone


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-04 19:11 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kontiki
2007-09-03 15:04 163644 –a—— C:\WINDOWS\system32\drivers\secdrv.sys
2007-09-02 18:16 821 –a—— C:\WINDOWS\system32\drivers\shadow_bg.gif
2007-09-02 18:16 72 –a—— C:\WINDOWS\system32\drivers\bg_bg.gif
2007-09-02 18:16 64 –a—— C:\WINDOWS\system32\drivers\close_ico.gif
2007-09-02 18:16 3031 –a—— C:\WINDOWS\system32\drivers\spyware_detected.gif
2007-09-02 18:16 1743 –a—— C:\WINDOWS\system32\drivers\remove_spyware_header.gif
2007-09-02 18:16 16941 –a—— C:\WINDOWS\system32\drivers\icon_warning_big.gif
2007-09-02 18:16 1381 –a—— C:\WINDOWS\system32\drivers\warning_ico.gif
2007-09-02 18:16 1014 –a—— C:\WINDOWS\system32\drivers\yellow_warning_ico.gif
2007-09-02 18:15 8852 –a—— C:\WINDOWS\system32\drivers\download_btn.jpg
2007-09-02 18:15 877 –a—— C:\WINDOWS\system32\drivers\header_red_bg.gif
2007-09-02 18:15 838 –a—— C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
2007-09-02 18:15 4448 –a—— C:\WINDOWS\system32\drivers\download_now_btn.gif
2007-09-02 18:15 4008 –a—— C:\WINDOWS\system32\drivers\rating.gif
2007-09-02 18:15 3552 –a—— C:\WINDOWS\system32\drivers\cell_header_remove.gif
2007-09-02 18:15 3479 –a—— C:\WINDOWS\system32\drivers\cell_header_scan.gif
2007-09-02 18:15 3313 –a—— C:\WINDOWS\system32\drivers\cell_header_block.gif
2007-09-02 18:15 3216 –a—— C:\WINDOWS\system32\drivers\header_red_free_scan.gif
2007-09-02 18:15 26487 –a—— C:\WINDOWS\system32\drivers\screenshot.jpg
2007-09-02 18:15 16977 –a—— C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
2007-09-02 18:15 1373 –a—— C:\WINDOWS\system32\drivers\cell_footer.gif
2007-09-02 18:15 1342 –a—— C:\WINDOWS\system32\drivers\cell_bg.gif
2007-08-31 13:53 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-31 13:53 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-28 15:47 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tick Find Close Surf
2007-08-18 22:09 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ball Shim Dupe Tick
2007-08-10 18:24 ——— d——– C:\Program Files\Windows Media Connect 2
2007-08-10 18:24 ——— d——– C:\Program Files\Trickshot
2007-08-10 18:24 ——— d——– C:\Program Files\3wPlayer
2007-08-07 16:31 ——— d——– C:\Program Files\Kontiki
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 207736 –a—— C:\WINDOWS\system32\muweb.dll
2007-07-27 00:06 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-07-27 00:06 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-07-26 22:51 ——— d——– C:\Program Files\CDBurnerXP Pro 3
2007-07-22 15:50 ——— d——– C:\Program Files\QuickTime
2007-07-22 15:48 ——— d——– C:\Program Files\Apple Software Update
2007-07-20 21:18 ——— d——– C:\DOCUME~1\Mum\APPLIC~1\Google
2007-07-20 17:00 ——— d——– C:\Program Files\DesktopNerds
2007-07-09 22:15 ——— d——– C:\Program Files\Common Files\Apple
2007-07-09 22:15 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-06-26 07:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-23 23:43 2560 –a—— C:\WINDOWS\system32\BitCometRes.dll
2007-06-19 14:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 11:23 1033216 –a—— C:\WINDOWS\explorer.exe
2003-08-31 14:32 71526 –a—— C:\Program Files\setup.exe
2003-08-31 14:30 98304 –a—— C:\DOCUME~1\ALLUSE~1\APPLIC~1\xqtylgdm.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39C6B6C8-E01E-3175-B583-04FDA1EE088B}]
2003-08-31 14:30 98304 –a—— C:\Program Files\Xbgiliru\tsefttwp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AB5FE6E5-7C72-4B89-85D0-D57E7AEAC236}]
2007-09-02 18:16 21504 –a—— C:\WINDOWS\system32\oembios32.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C1ADC5ED-FB26-4770-AFE5-BD3A7EB5C148}]
2003-08-31 14:29 43542 –a—— C:\WINDOWS\system32\nnnnnlm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E64F0381-0053-4842-B3E5-08F6C4A0AEB6}]
2007-09-03 18:27 70208 –a—— C:\WINDOWS\system32\bvlkernd.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F3295BF6-C520-4748-A22B-340A373A48BF}]
2003-08-31 14:34 297568 –a—— C:\WINDOWS\system32\efedc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2004-11-08 10:36 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2004-11-08 10:36 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-11-08 10:43 C:\WINDOWS\SOUNDMAN.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-11-08 11:52 C:\WINDOWS\AGRSMMSG.exe]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-16 17:45]
"BearShare"="C:\Program Files\BearShare\BearShare.exe" [2006-02-13 11:48]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"Kaspersky Anti-Virus 2006"="C:\Program Files\Kaspersky Lab\AVP6\avp.exe" [2005-06-10 14:02]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
AdsGone 2004.lnk - C:\Program Files\AdsGone\adsgone.exe [2004-12-06 15:36:26]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{C1ADC5ED-FB26-4770-AFE5-BD3A7EB5C148}"= C:\WINDOWS\system32\nnnnnlm.dll [2003-08-31 14:29 43542]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efedc]
C:\WINDOWS\system32\efedc.dll 2003-08-31 14:34 297568 C:\WINDOWS\system32\efedc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnnnlm]
nnnnnlm.dll 2003-08-31 14:29 43542 C:\WINDOWS\system32\nnnnnlm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winuxh32]
winuxh32.dll 2007-08-31 14:29 22528 C:\WINDOWS\system32\winuxh32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Darbyshire^Start Menu^Programs^Startup^AdsGone.lnk]
path=C:\Documents and Settings\Darbyshire\Start Menu\Programs\Startup\AdsGone.lnk
backup=C:\WINDOWS\pss\AdsGone.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\avp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
"C:\Program Files\BearShare\BearShare.exe" /pause

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
rundll32.exe C:\WINDOWS\system32\drvsom.dll,startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
C:\Program Files\Eraser\eraser.exe -hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kaspersky Anti-Virus 2006]
C:\Program Files\Kaspersky Lab\AVP6\avp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAVPersonal50]
"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
C:\Program Files\ltmoh\Ltmoh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pccguide.exe]
"C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\retadpu2000352.exe 61A847B5BBF72810329B385577FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
mgrs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ssha]
"C:\WINDOWS\YMANTE~1\regsvr32.exe" -vt yazb

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemRestoreStatus]
rundll32.exe "C:\WINDOWS\system32\rsdiblnp.dll",sitypnow

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TweakMASTER]
"C:\PROGRA~1\TWEAKM~1\TMTray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ultimate Fixer]
"C:\Program Files\Ultimate Fixer\UltimateFixer.exe" hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
%systemroot%\system32\dumprep 0 -u

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave]
"C:\Program Files\Save\Save.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xitutcni]
rundll32.exe "C:\Program Files\xitutcni\nsdiredi.dll",Init

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xqtylgdm]
regsvr32 /u "C:\Documents and Settings\All Users\Application Data\xqtylgdm.dll"
R3 PxHelper;PxHelper;\??\C:\WINDOWS\system32\drivers\PxHelper.sys
S1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys
S2 tmxpflt;tmxpflt;C:\WINDOWS\system32\DRIVERS\tmxpflt.sys
S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys


Contents of the 'Scheduled Tasks' folder
2007-08-10 12:59:58 C:\WINDOWS\Tasks\AdsGone.job - C:\Program Files\AdsGone\AdsGone.exe
2007-08-11 17:53:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-04 19:32:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-04 19:35:48
C:\ComboFix-quarantined-files.txt … 2007-09-04 19:35
C:\ComboFix2.txt … 2007-09-04 19:26

— E O F —


And here is the Hijakthis log as requested…………………………………………….


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:45:37, on 04/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Kaspersky Anti-Virus 2006] C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Script Checker - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\AVP6\scieplugin.dll
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by134fd.bay134.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1188663167948
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVP - Kaspersky Lab - C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

–
End of file - 6697 bytes

Thanks,
I used each software "combofix and hijak this" in administrator on safe mode as the normal log in is to slow and basically inopperable.

Here is the combofix log………………………


ComboFix 07-09-04 - "Administrator" 2007-09-04 19:28:32.3 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.224 [GMT 1:00]
Command switches used :: /KillAll


((((((((((((((((((((((((( Files Created from 2007-08-04 to 2007-09-04 )))))))))))))))))))))))))))))))


2007-09-03 18:45 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-03 18:26 70,208 –a—— C:\WINDOWS\system32\bvlkernd.dll
2007-09-03 18:20 74,816 –a—— C:\WINDOWS\system32\atscancs.dll
2007-09-03 16:00 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\vlc
2007-09-03 14:45 d——– C:\DOCUME~1\ADMINI~1\Contacts
2007-09-03 02:29 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-02 22:40 d——– C:\Program Files\BulletProofSoft.com
2007-09-02 22:39 d——– C:\BPS Spyware-Adware Remover
2007-09-02 18:53 18,432 –a—— C:\WINDOWS\winh32.exe
2007-09-02 18:38 31,232 –a—— C:\WINDOWS\system32\msole32.exe
2007-09-02 18:38 21,248 –a—— C:\WINDOWS\eventlowg.dll
2007-09-02 18:38 11,776 –a—— C:\WINDOWS\daxtime.dll
2007-09-02 18:37 32,512 –a—— C:\WINDOWS\ngd.dll
2007-09-02 18:37 27,136 –a—— C:\WINDOWS\spredirect.dll
2007-09-02 18:37 17,408 –a—— C:\WINDOWS\ie_32.exe
2007-09-02 18:37 17,152 –a—— C:\WINDOWS\system32\ace16win.dll
2007-09-02 18:37 15,104 –a—— C:\WINDOWS\jd2002.dll
2007-09-02 18:37 13,056 –a—— C:\WINDOWS\system32\ESHOPEE.exe
2007-09-02 18:37 10,496 –a—— C:\WINDOWS\adbar.dll
2007-09-02 18:37 d——– C:\WINDOWS\system32\acespy
2007-09-02 18:37 d——– C:\Program Files\e-zshopper
2007-09-02 18:37 d——– C:\Program Files\amsys
2007-09-02 18:37 d——– C:\Program Files\akl
2007-09-02 18:37 d——– C:\Program Files\Accoona
2007-09-02 18:23 70,208 –a—— C:\WINDOWS\system32\wwasyhtp.dll
2007-09-02 18:19 74,816 –a—— C:\WINDOWS\system32\itnxctfk.dll
2007-09-02 18:16 21,504 –a—— C:\WINDOWS\system32\oembios32.dll
2007-09-01 20:14 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-01 20:10 74,816 –a—— C:\WINDOWS\system32\rsdiblnp.dll
2007-09-01 20:07 70,208 –a—— C:\WINDOWS\system32\tedjgvab.dll
2007-09-01 19:37 d——– C:\WINDOWS\LastGood
2007-09-01 18:54 26,730 –a—— C:\WINDOWS\system32\fssync.dll
2007-09-01 18:54 170,272 –ahs—- C:\WINDOWS\fidbox.dat
2007-09-01 18:54 13,418 –a—— C:\WINDOWS\system32\klogon.dll
2007-09-01 18:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Anti-Virus Personal
2007-09-01 18:15 d——– C:\Program Files\Kaspersky Lab
2007-09-01 17:17 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-09-01 17:17 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-01 14:22 70,208 –a—— C:\WINDOWS\system32\rxcprhva.dll
2007-09-01 14:19 74,816 –a—— C:\WINDOWS\system32\vsstoecf.dll
2007-09-01 13:18 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
2007-09-01 01:51 75,792 –a—— C:\WINDOWS\system32\drivers\tmtdi.sys
2007-09-01 01:51 32,528 –a—— C:\WINDOWS\system32\drivers\tmpreflt.sys
2007-09-01 01:51 300,816 –a—— C:\WINDOWS\system32\drivers\TM_CFW.sys
2007-09-01 01:51 199,440 –a—— C:\WINDOWS\system32\drivers\tmxpflt.sys
2007-09-01 01:51 112,400 –a—— C:\WINDOWS\system32\drivers\tm_mbd_c.sys
2007-09-01 01:51 1,052,472 –a—— C:\WINDOWS\system32\drivers\vsapint.sys
2007-09-01 01:51 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-09-01 01:48 d——– C:\Program Files\Trend Micro
2007-09-01 01:39 74,816 –a—— C:\WINDOWS\system32\qeacpbsc.dll
2007-09-01 01:35 70,208 –a—— C:\WINDOWS\system32\gqrsviox.dll
2007-09-01 01:32 1,257,935 —hs—- C:\WINDOWS\system32\cdefe.bak2
2007-08-31 14:29 22,528 –a—— C:\WINDOWS\system32\winuxh32.dll
2007-08-31 14:07 713 –a—— C:\WINDOWS\eReg.dat
2007-08-28 15:32 d——– C:\NoLopBackups
2007-08-23 21:29 d——– C:\Program Files\TweakMASTER
2007-08-23 21:29 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hagel Technologies
2007-08-23 19:36 d——– C:\Program Files\DivX
2007-08-23 00:30 352,137 –a—— C:\swlist.reg
2007-08-21 00:33 d——– C:\Program Files\Rockstar Games
2007-08-21 00:05 9,600 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys
2007-08-21 00:05 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2007-08-20 20:52 d——– C:\Program Files\GTA
2007-08-19 21:35 d——– C:\Program Files\WinZix
2007-08-18 22:23 d——– C:\Program Files\blackmagic
2007-08-11 19:17 d——– C:\Program Files\iPod
2007-08-11 19:16 d——– C:\Program Files\iTunes
2007-08-11 11:16 d——– C:\Program Files\Sports Interactive
2007-08-10 20:02 d——– C:\Program Files\DaemonTools_WhenUSave_Installer
2007-08-10 20:02 d——– C:\Program Files\DAEMON Tools
2007-08-10 19:55 682,232 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2007-08-10 15:08 d——– C:\Program Files\Smart Projects
2007-08-10 13:59 d——– C:\Program Files\AdsGone


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-04 19:11 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kontiki
2007-09-03 15:04 163644 –a—— C:\WINDOWS\system32\drivers\secdrv.sys
2007-09-02 18:16 821 –a—— C:\WINDOWS\system32\drivers\shadow_bg.gif
2007-09-02 18:16 72 –a—— C:\WINDOWS\system32\drivers\bg_bg.gif
2007-09-02 18:16 64 –a—— C:\WINDOWS\system32\drivers\close_ico.gif
2007-09-02 18:16 3031 –a—— C:\WINDOWS\system32\drivers\spyware_detected.gif
2007-09-02 18:16 1743 –a—— C:\WINDOWS\system32\drivers\remove_spyware_header.gif
2007-09-02 18:16 16941 –a—— C:\WINDOWS\system32\drivers\icon_warning_big.gif
2007-09-02 18:16 1381 –a—— C:\WINDOWS\system32\drivers\warning_ico.gif
2007-09-02 18:16 1014 –a—— C:\WINDOWS\system32\drivers\yellow_warning_ico.gif
2007-09-02 18:15 8852 –a—— C:\WINDOWS\system32\drivers\download_btn.jpg
2007-09-02 18:15 877 –a—— C:\WINDOWS\system32\drivers\header_red_bg.gif
2007-09-02 18:15 838 –a—— C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
2007-09-02 18:15 4448 –a—— C:\WINDOWS\system32\drivers\download_now_btn.gif
2007-09-02 18:15 4008 –a—— C:\WINDOWS\system32\drivers\rating.gif
2007-09-02 18:15 3552 –a—— C:\WINDOWS\system32\drivers\cell_header_remove.gif
2007-09-02 18:15 3479 –a—— C:\WINDOWS\system32\drivers\cell_header_scan.gif
2007-09-02 18:15 3313 –a—— C:\WINDOWS\system32\drivers\cell_header_block.gif
2007-09-02 18:15 3216 –a—— C:\WINDOWS\system32\drivers\header_red_free_scan.gif
2007-09-02 18:15 26487 –a—— C:\WINDOWS\system32\drivers\screenshot.jpg
2007-09-02 18:15 16977 –a—— C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
2007-09-02 18:15 1373 –a—— C:\WINDOWS\system32\drivers\cell_footer.gif
2007-09-02 18:15 1342 –a—— C:\WINDOWS\system32\drivers\cell_bg.gif
2007-08-31 13:53 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-31 13:53 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-28 15:47 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tick Find Close Surf
2007-08-18 22:09 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ball Shim Dupe Tick
2007-08-10 18:24 ——— d——– C:\Program Files\Windows Media Connect 2
2007-08-10 18:24 ——— d——– C:\Program Files\Trickshot
2007-08-10 18:24 ——— d——– C:\Program Files\3wPlayer
2007-08-07 16:31 ——— d——– C:\Program Files\Kontiki
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 207736 –a—— C:\WINDOWS\system32\muweb.dll
2007-07-27 00:06 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-07-27 00:06 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-07-26 22:51 ——— d——– C:\Program Files\CDBurnerXP Pro 3
2007-07-22 15:50 ——— d——– C:\Program Files\QuickTime
2007-07-22 15:48 ——— d——– C:\Program Files\Apple Software Update
2007-07-20 21:18 ——— d——– C:\DOCUME~1\Mum\APPLIC~1\Google
2007-07-20 17:00 ——— d——– C:\Program Files\DesktopNerds
2007-07-09 22:15 ——— d——– C:\Program Files\Common Files\Apple
2007-07-09 22:15 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-06-26 07:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-23 23:43 2560 –a—— C:\WINDOWS\system32\BitCometRes.dll
2007-06-19 14:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 11:23 1033216 –a—— C:\WINDOWS\explorer.exe
2003-08-31 14:32 71526 –a—— C:\Program Files\setup.exe
2003-08-31 14:30 98304 –a—— C:\DOCUME~1\ALLUSE~1\APPLIC~1\xqtylgdm.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39C6B6C8-E01E-3175-B583-04FDA1EE088B}]
2003-08-31 14:30 98304 –a—— C:\Program Files\Xbgiliru\tsefttwp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AB5FE6E5-7C72-4B89-85D0-D57E7AEAC236}]
2007-09-02 18:16 21504 –a—— C:\WINDOWS\system32\oembios32.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C1ADC5ED-FB26-4770-AFE5-BD3A7EB5C148}]
2003-08-31 14:29 43542 –a—— C:\WINDOWS\system32\nnnnnlm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E64F0381-0053-4842-B3E5-08F6C4A0AEB6}]
2007-09-03 18:27 70208 –a—— C:\WINDOWS\system32\bvlkernd.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F3295BF6-C520-4748-A22B-340A373A48BF}]
2003-08-31 14:34 297568 –a—— C:\WINDOWS\system32\efedc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2004-11-08 10:36 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2004-11-08 10:36 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-11-08 10:43 C:\WINDOWS\SOUNDMAN.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-11-08 11:52 C:\WINDOWS\AGRSMMSG.exe]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-16 17:45]
"BearShare"="C:\Program Files\BearShare\BearShare.exe" [2006-02-13 11:48]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"Kaspersky Anti-Virus 2006"="C:\Program Files\Kaspersky Lab\AVP6\avp.exe" [2005-06-10 14:02]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
AdsGone 2004.lnk - C:\Program Files\AdsGone\adsgone.exe [2004-12-06 15:36:26]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{C1ADC5ED-FB26-4770-AFE5-BD3A7EB5C148}"= C:\WINDOWS\system32\nnnnnlm.dll [2003-08-31 14:29 43542]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efedc]
C:\WINDOWS\system32\efedc.dll 2003-08-31 14:34 297568 C:\WINDOWS\system32\efedc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnnnlm]
nnnnnlm.dll 2003-08-31 14:29 43542 C:\WINDOWS\system32\nnnnnlm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winuxh32]
winuxh32.dll 2007-08-31 14:29 22528 C:\WINDOWS\system32\winuxh32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Darbyshire^Start Menu^Programs^Startup^AdsGone.lnk]
path=C:\Documents and Settings\Darbyshire\Start Menu\Programs\Startup\AdsGone.lnk
backup=C:\WINDOWS\pss\AdsGone.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\avp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
"C:\Program Files\BearShare\BearShare.exe" /pause

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
rundll32.exe C:\WINDOWS\system32\drvsom.dll,startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
C:\Program Files\Eraser\eraser.exe -hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kaspersky Anti-Virus 2006]
C:\Program Files\Kaspersky Lab\AVP6\avp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAVPersonal50]
"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
C:\Program Files\ltmoh\Ltmoh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pccguide.exe]
"C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\retadpu2000352.exe 61A847B5BBF72810329B385577FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
mgrs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ssha]
"C:\WINDOWS\YMANTE~1\regsvr32.exe" -vt yazb

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemRestoreStatus]
rundll32.exe "C:\WINDOWS\system32\rsdiblnp.dll",sitypnow

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TweakMASTER]
"C:\PROGRA~1\TWEAKM~1\TMTray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ultimate Fixer]
"C:\Program Files\Ultimate Fixer\UltimateFixer.exe" hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
%systemroot%\system32\dumprep 0 -u

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave]
"C:\Program Files\Save\Save.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xitutcni]
rundll32.exe "C:\Program Files\xitutcni\nsdiredi.dll",Init

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xqtylgdm]
regsvr32 /u "C:\Documents and Settings\All Users\Application Data\xqtylgdm.dll"
R3 PxHelper;PxHelper;\??\C:\WINDOWS\system32\drivers\PxHelper.sys
S1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys
S2 tmxpflt;tmxpflt;C:\WINDOWS\system32\DRIVERS\tmxpflt.sys
S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys


Contents of the 'Scheduled Tasks' folder
2007-08-10 12:59:58 C:\WINDOWS\Tasks\AdsGone.job - C:\Program Files\AdsGone\AdsGone.exe
2007-08-11 17:53:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-04 19:32:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-04 19:35:48
C:\ComboFix-quarantined-files.txt … 2007-09-04 19:35
C:\ComboFix2.txt … 2007-09-04 19:26

— E O F —


And here is the Hijakthis log as requested…………………………………………….


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:45:37, on 04/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Kaspersky Anti-Virus 2006] C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Script Checker - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\AVP6\scieplugin.dll
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by134fd.bay134.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1188663167948
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVP - Kaspersky Lab - C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

–
End of file - 6697 bytes

Thanks,
1. By doing it "your way" the tools did not work at all. If you do not intend to follow directions and believe that you can do it better your way, then I will close the topic. These tools are meant to run in a certain way, specially ComboFix. It is running with particular switches for a reason. If you circumvent the operating procedures you do not get the results that you should. 2. In addition, please be patient with your replies, they show up after a while when things are bogged down. There is seldom any requirement to post the information more than once. 3. Now please run the tools the way I have asked you to. They may take 30 minutes, 40 minutes but usually they are faster. Do not use your system for anything else when the scans are running. Trevuren
Hi, I hope I have done this right this time. I did this is normal mode which did take a while but it got there in the end, here is the log file,

ComboFix 07-09-04.2 - "Darbyshire" 2007-09-04 20:47:57.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.183 [GMT 1:00]
Command switches used :: /KillAll
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\flt.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wml.exe


((((((((((((((((((((((((( Files Created from 2007-08-04 to 2007-09-04 )))))))))))))))))))))))))))))))


2007-09-04 20:38 4 –a—— C:\WINDOWS\system32\stfv.bin
2007-09-03 18:45 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-03 18:26 70,208 –a—— C:\WINDOWS\system32\bvlkernd.dll
2007-09-03 18:20 74,816 –a—— C:\WINDOWS\system32\atscancs.dll
2007-09-03 16:00 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\vlc
2007-09-03 14:45 d——– C:\DOCUME~1\ADMINI~1\Contacts
2007-09-03 02:29 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-02 22:40 d——– C:\Program Files\BulletProofSoft.com
2007-09-02 22:39 d——– C:\BPS Spyware-Adware Remover
2007-09-02 18:53 18,432 –a—— C:\WINDOWS\winh32.exe
2007-09-02 18:38 31,232 –a—— C:\WINDOWS\system32\msole32.exe
2007-09-02 18:38 21,248 –a—— C:\WINDOWS\eventlowg.dll
2007-09-02 18:38 11,776 –a—— C:\WINDOWS\daxtime.dll
2007-09-02 18:37 32,512 –a—— C:\WINDOWS\ngd.dll
2007-09-02 18:37 27,136 –a—— C:\WINDOWS\spredirect.dll
2007-09-02 18:37 17,408 –a—— C:\WINDOWS\ie_32.exe
2007-09-02 18:37 17,152 –a—— C:\WINDOWS\system32\ace16win.dll
2007-09-02 18:37 15,104 –a—— C:\WINDOWS\jd2002.dll
2007-09-02 18:37 13,056 –a—— C:\WINDOWS\system32\ESHOPEE.exe
2007-09-02 18:37 10,496 –a—— C:\WINDOWS\adbar.dll
2007-09-02 18:37 d——– C:\WINDOWS\system32\acespy
2007-09-02 18:37 d——– C:\Program Files\e-zshopper
2007-09-02 18:37 d——– C:\Program Files\amsys
2007-09-02 18:37 d——– C:\Program Files\akl
2007-09-02 18:37 d——– C:\Program Files\Accoona
2007-09-02 18:23 70,208 –a—— C:\WINDOWS\system32\wwasyhtp.dll
2007-09-02 18:19 74,816 –a—— C:\WINDOWS\system32\itnxctfk.dll
2007-09-02 18:16 21,504 –a—— C:\WINDOWS\system32\oembios32.dll
2007-09-01 20:14 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-01 20:10 74,816 –a—— C:\WINDOWS\system32\rsdiblnp.dll
2007-09-01 20:07 70,208 –a—— C:\WINDOWS\system32\tedjgvab.dll
2007-09-01 18:54 26,730 –a—— C:\WINDOWS\system32\fssync.dll
2007-09-01 18:54 240,160 –ahs—- C:\WINDOWS\fidbox.dat
2007-09-01 18:54 13,418 –a—— C:\WINDOWS\system32\klogon.dll
2007-09-01 18:16 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Anti-Virus Personal
2007-09-01 18:15 d——– C:\Program Files\Kaspersky Lab
2007-09-01 17:17 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-09-01 17:17 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-01 14:22 70,208 –a—— C:\WINDOWS\system32\rxcprhva.dll
2007-09-01 14:19 74,816 –a—— C:\WINDOWS\system32\vsstoecf.dll
2007-09-01 13:18 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
2007-09-01 01:51 75,792 –a—— C:\WINDOWS\system32\drivers\tmtdi.sys
2007-09-01 01:51 32,528 –a—— C:\WINDOWS\system32\drivers\tmpreflt.sys
2007-09-01 01:51 300,816 –a—— C:\WINDOWS\system32\drivers\TM_CFW.sys
2007-09-01 01:51 199,440 –a—— C:\WINDOWS\system32\drivers\tmxpflt.sys
2007-09-01 01:51 112,400 –a—— C:\WINDOWS\system32\drivers\tm_mbd_c.sys
2007-09-01 01:51 1,052,472 –a—— C:\WINDOWS\system32\drivers\vsapint.sys
2007-09-01 01:51 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-09-01 01:48 d——– C:\Program Files\Trend Micro
2007-09-01 01:39 74,816 –a—— C:\WINDOWS\system32\qeacpbsc.dll
2007-09-01 01:35 70,208 –a—— C:\WINDOWS\system32\gqrsviox.dll
2007-09-01 01:32 1,257,935 —hs—- C:\WINDOWS\system32\cdefe.bak2
2007-08-31 14:29 22,528 –a—— C:\WINDOWS\system32\winuxh32.dll
2007-08-31 14:07 713 –a—— C:\WINDOWS\eReg.dat
2007-08-28 15:32 d——– C:\NoLopBackups
2007-08-23 21:29 d——– C:\Program Files\TweakMASTER
2007-08-23 21:29 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hagel Technologies
2007-08-23 19:36 d——– C:\Program Files\DivX
2007-08-23 00:30 352,137 –a—— C:\swlist.reg
2007-08-21 00:33 d——– C:\Program Files\Rockstar Games
2007-08-21 00:05 9,600 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys
2007-08-21 00:05 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2007-08-20 20:52 d——– C:\Program Files\GTA
2007-08-19 21:35 d——– C:\Program Files\WinZix
2007-08-18 22:23 d——– C:\Program Files\blackmagic
2007-08-11 19:17 d——– C:\Program Files\iPod
2007-08-11 19:16 d——– C:\Program Files\iTunes
2007-08-11 11:16 d——– C:\Program Files\Sports Interactive
2007-08-10 20:02 d——– C:\Program Files\DaemonTools_WhenUSave_Installer
2007-08-10 20:02 d——– C:\Program Files\DAEMON Tools
2007-08-10 19:55 682,232 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2007-08-10 15:08 d——– C:\Program Files\Smart Projects
2007-08-10 13:59 d——– C:\Program Files\AdsGone


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-04 21:19 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kontiki
2007-09-04 21:18 0 –a—— C:\WINDOWS\system32\gtv_sd.bin
2007-09-04 20:42 9216 –a—— C:\WINDOWS\wbeCheck.exe
2007-09-04 20:42 30976 –a—— C:\WINDOWS\kkcomp.exe
2007-09-04 20:42 29184 –a—— C:\WINDOWS\liqui-Uninstaller.exe
2007-09-04 20:42 25088 –a—— C:\WINDOWS\xadbrk.exe
2007-09-04 20:42 24832 –a—— C:\WINDOWS\liqad.dll
2007-09-04 20:42 24064 –a—— C:\WINDOWS\liqui.exe
2007-09-04 20:42 23552 –a—— C:\WINDOWS\dp0.dll
2007-09-04 20:42 23296 –a—— C:\WINDOWS\kvnab$.exe
2007-09-04 20:42 23040 –a—— C:\WINDOWS\xxxvideo.exe
2007-09-04 20:42 23040 –a—— C:\WINDOWS\fhfmm.exe
2007-09-04 20:42 23040 –a—— C:\WINDOWS\fhfmm-Uninstaller.exe
2007-09-04 20:42 21504 –a—— C:\WINDOWS\liqad.exe
2007-09-04 20:42 21248 –a—— C:\WINDOWS\kvnab.dll
2007-09-04 20:42 21248 –a—— C:\WINDOWS\kkcomp$.exe
2007-09-04 20:42 20480 –a—— C:\WINDOWS\iexplorr23.dll
2007-09-04 20:42 19712 –a—— C:\WINDOWS\pbsysie.dll
2007-09-04 20:42 19712 –a—— C:\WINDOWS\cbinst$.exe
2007-09-04 20:42 19200 –a—— C:\WINDOWS\xadbrk_.exe
2007-09-04 20:42 18944 –a—— C:\WINDOWS\settn.dll
2007-09-04 20:42 17920 –a—— C:\WINDOWS\kvnab.exe
2007-09-04 20:42 15872 –a—— C:\WINDOWS\kkcomp.dll
2007-09-04 20:42 15616 –a—— C:\WINDOWS\liqad$.exe
2007-09-04 20:42 13824 –a—— C:\WINDOWS\liqui.dll
2007-09-04 20:42 13568 –a—— C:\WINDOWS\aconti.exe
2007-09-04 20:42 12544 –a—— C:\WINDOWS\hcwprn.exe
2007-09-04 20:42 11520 –a—— C:\WINDOWS\xadbrk.dll
2007-09-04 20:42 10752 –a—— C:\WINDOWS\wbeInst$.exe
2007-09-04 20:42 10752 –a—— C:\WINDOWS\hotporn.exe
2007-09-04 20:11 163644 –a—— C:\WINDOWS\system32\drivers\secdrv.sys
2007-09-02 18:16 821 –a—— C:\WINDOWS\system32\drivers\shadow_bg.gif
2007-09-02 18:16 72 –a—— C:\WINDOWS\system32\drivers\bg_bg.gif
2007-09-02 18:16 64 –a—— C:\WINDOWS\system32\drivers\close_ico.gif
2007-09-02 18:16 3031 –a—— C:\WINDOWS\system32\drivers\spyware_detected.gif
2007-09-02 18:16 1743 –a—— C:\WINDOWS\system32\drivers\remove_spyware_header.gif
2007-09-02 18:16 16941 –a—— C:\WINDOWS\system32\drivers\icon_warning_big.gif
2007-09-02 18:16 1381 –a—— C:\WINDOWS\system32\drivers\warning_ico.gif
2007-09-02 18:16 1014 –a—— C:\WINDOWS\system32\drivers\yellow_warning_ico.gif
2007-09-02 18:15 8852 –a—— C:\WINDOWS\system32\drivers\download_btn.jpg
2007-09-02 18:15 877 –a—— C:\WINDOWS\system32\drivers\header_red_bg.gif
2007-09-02 18:15 838 –a—— C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
2007-09-02 18:15 4448 –a—— C:\WINDOWS\system32\drivers\download_now_btn.gif
2007-09-02 18:15 4008 –a—— C:\WINDOWS\system32\drivers\rating.gif
2007-09-02 18:15 3552 –a—— C:\WINDOWS\system32\drivers\cell_header_remove.gif
2007-09-02 18:15 3479 –a—— C:\WINDOWS\system32\drivers\cell_header_scan.gif
2007-09-02 18:15 3313 –a—— C:\WINDOWS\system32\drivers\cell_header_block.gif
2007-09-02 18:15 3216 –a—— C:\WINDOWS\system32\drivers\header_red_free_scan.gif
2007-09-02 18:15 26487 –a—— C:\WINDOWS\system32\drivers\screenshot.jpg
2007-09-02 18:15 16977 –a—— C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
2007-09-02 18:15 1373 –a—— C:\WINDOWS\system32\drivers\cell_footer.gif
2007-09-02 18:15 1342 –a—— C:\WINDOWS\system32\drivers\cell_bg.gif
2007-08-31 13:53 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-31 13:53 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-28 15:47 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tick Find Close Surf
2007-08-18 22:09 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ball Shim Dupe Tick
2007-08-10 18:24 ——— d——– C:\Program Files\Windows Media Connect 2
2007-08-10 18:24 ——— d——– C:\Program Files\Trickshot
2007-08-10 18:24 ——— d——– C:\Program Files\3wPlayer
2007-08-07 16:31 ——— d——– C:\Program Files\Kontiki
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 207736 –a—— C:\WINDOWS\system32\muweb.dll
2007-07-27 00:06 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-07-27 00:06 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-07-26 22:51 ——— d——– C:\Program Files\CDBurnerXP Pro 3
2007-07-22 15:50 ——— d——– C:\Program Files\QuickTime
2007-07-22 15:48 ——— d——– C:\Program Files\Apple Software Update
2007-07-20 21:18 ——— d——– C:\DOCUME~1\Mum\APPLIC~1\Google
2007-07-20 17:00 ——— d——– C:\Program Files\DesktopNerds
2007-07-09 22:15 ——— d——– C:\Program Files\Common Files\Apple
2007-07-09 22:15 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-06-26 07:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-23 23:43 2560 –a—— C:\WINDOWS\system32\BitCometRes.dll
2007-06-19 14:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 11:23 1033216 –a—— C:\WINDOWS\explorer.exe
2003-08-31 14:32 71526 –a—— C:\Program Files\setup.exe
2003-08-31 14:30 98304 –a—— C:\DOCUME~1\ALLUSE~1\APPLIC~1\xqtylgdm.dll


((((((((((((((((((((((((((((( snapshot_2007-09-04_192447.61 )))))))))))))))))))))))))))))))))))))))))

—-a-w 169,309 2007-09-04 20:04:31 C:\WINDOWS\system32\drivers\etc\tmvsthfss.bin
—-atw 16,384 2007-09-04 20:01:13 C:\WINDOWS\temp\Perflib_Perfdata_330.dat
—-atw 16,384 2007-09-04 19:25:41 C:\WINDOWS\temp\Perflib_Perfdata_5bc.dat


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39C6B6C8-E01E-3175-B583-04FDA1EE088B}]
2003-08-31 14:30 98304 –a—— C:\Program Files\Xbgiliru\tsefttwp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9A3FCC86-3427-40F4-ADEF-3ACC87EB0B12}]
2003-08-31 14:34 297568 –a—— C:\WINDOWS\system32\efedc.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AB5FE6E5-7C72-4B89-85D0-D57E7AEAC236}]
2007-09-02 18:16 21504 –a—— C:\WINDOWS\system32\oembios32.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C1ADC5ED-FB26-4770-AFE5-BD3A7EB5C148}]
2003-08-31 14:29 43542 –a—— C:\WINDOWS\system32\nnnnnlm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E64F0381-0053-4842-B3E5-08F6C4A0AEB6}]
2007-09-03 18:27 70208 –a—— C:\WINDOWS\system32\bvlkernd.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2004-11-08 10:36 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2004-11-08 10:36 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-11-08 10:43 C:\WINDOWS\SOUNDMAN.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-11-08 11:52 C:\WINDOWS\AGRSMMSG.exe]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-16 17:45]
"BearShare"="C:\Program Files\BearShare\BearShare.exe" [2006-02-13 11:48]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"Kaspersky Anti-Virus 2006"="C:\Program Files\Kaspersky Lab\AVP6\avp.exe" [2005-06-10 14:02]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-23 12:47]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54]
"Ssha"="C:\WINDOWS\YMANTE~1\regsvr32.exe" []

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
AdsGone 2004.lnk - C:\Program Files\AdsGone\adsgone.exe [2004-12-06 15:36:26]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{C1ADC5ED-FB26-4770-AFE5-BD3A7EB5C148}"= C:\WINDOWS\system32\nnnnnlm.dll [2003-08-31 14:29 43542]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efedc]
C:\WINDOWS\system32\efedc.dll 2003-08-31 14:34 297568 C:\WINDOWS\system32\efedc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnnnlm]
nnnnnlm.dll 2003-08-31 14:29 43542 C:\WINDOWS\system32\nnnnnlm.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winuxh32]
winuxh32.dll 2007-08-31 14:29 22528 C:\WINDOWS\system32\winuxh32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Darbyshire^Start Menu^Programs^Startup^AdsGone.lnk]
path=C:\Documents and Settings\Darbyshire\Start Menu\Programs\Startup\AdsGone.lnk
backup=C:\WINDOWS\pss\AdsGone.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\avp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
"C:\Program Files\BearShare\BearShare.exe" /pause

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
rundll32.exe C:\WINDOWS\system32\drvsom.dll,startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
C:\Program Files\Eraser\eraser.exe -hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kaspersky Anti-Virus 2006]
C:\Program Files\Kaspersky Lab\AVP6\avp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAVPersonal50]
"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
C:\Program Files\ltmoh\Ltmoh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pccguide.exe]
"C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\retadpu2000352.exe 61A847B5BBF72810329B385577FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
mgrs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ssha]
"C:\WINDOWS\YMANTE~1\regsvr32.exe" -vt yazb

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemRestoreStatus]
rundll32.exe "C:\WINDOWS\system32\rsdiblnp.dll",sitypnow

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TweakMASTER]
"C:\PROGRA~1\TWEAKM~1\TMTray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ultimate Fixer]
"C:\Program Files\Ultimate Fixer\UltimateFixer.exe" hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
%systemroot%\system32\dumprep 0 -u

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave]
"C:\Program Files\Save\Save.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xitutcni]
rundll32.exe "C:\Program Files\xitutcni\nsdiredi.dll",Init

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xqtylgdm]
regsvr32 /u "C:\Documents and Settings\All Users\Application Data\xqtylgdm.dll"
R1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys
R2 tmxpflt;tmxpflt;C:\WINDOWS\system32\DRIVERS\tmxpflt.sys
R3 PxHelper;PxHelper;\??\C:\WINDOWS\system32\drivers\PxHelper.sys
S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F146C9B1-VMVQ-A9RC-NUFL-D0BA00B4E999}]
C:\WINDOWS\system32\nusrmgr.exe

Contents of the 'Scheduled Tasks' folder
2007-08-10 12:59:58 C:\WINDOWS\Tasks\AdsGone.job - C:\Program Files\AdsGone\AdsGone.exe
2007-08-11 17:53:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-04 21:05:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-04 21:22:22 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-04 21:22
C:\ComboFix2.txt … 2007-09-04 19:35
C:\ComboFix3.txt … 2007-09-04 19:26

— E O F —
And here is the Hijak this………..


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:05, on 2007-09-04
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\AVP6\avp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kontiki\KService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Kaspersky Lab\AVP6\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\nusrmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Kaspersky Anti-Virus 2006] C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to &LinkFox - res://C:\PROGRA~1\TWEAKM~1\TweakBHO.dll/IESCRIPT
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Script Checker - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\AVP6\scieplugin.dll
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - http://www.williamhillcasino.com (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - http://www.williamhillcasino.com (file missing) (HKCU)
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by134fd.bay134.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1188663167948
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVP - Kaspersky Lab - C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

–
End of file - 8116 bytes


Is this what you needed? i followed the instructions as closely as possible.
A. Some trojans have a way of masking their presence from the HijackThis program when they recognize the name. I think that this is the case here because there are no 02 or 020 entries visible in your log.

Please locate the following file on your desktop: HijackThis.exe
Next, right click on the file and from the popup menu that appears, choose the RENAME option and rename the file Killer.exe.

From now on, when I ask you to start HijackThis, just click on the Killer.exe file.


B. Please run the following program:
  • Please download WinHelp2002's DelDomains by right-clicking on the following link, and choosing "Save Target As": DelDomains.inf to your Desktop
    http://www.mvps.org/winhelp2002/DelDomains.inf

  • Then go to the desktop, right click on DelDomains.inf, and choose Install. You may not see any noticeable changes or prompts; this is normal.
  • Then please restart your computer

C. Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.


Note: Make sure you let VundoFix run as many times as required to clear the Vundo trojan infection. This can, at times, require several reboots.
VundoFix V6.5.8

Checking Java version…

Java version is 1.4.2.5
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 03:45:27 2007-09-05

Listing files found while scanning….

C:\WINDOWS\system32\cdefe.bak1
C:\WINDOWS\system32\cdefe.bak2
C:\WINDOWS\system32\cdefe.ini
C:\windows\system32\drvcul.dll
C:\windows\system32\drvculr.dll
C:\windows\system32\drvsom.dll
C:\windows\system32\drvsomr.dll
C:\WINDOWS\system32\efedc.dll
C:\windows\system32\gebbbyx.dll
C:\windows\system32\iifccca.dll
C:\windows\system32\nnnnnlm.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\cdefe.bak1
C:\WINDOWS\system32\cdefe.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\cdefe.bak2
C:\WINDOWS\system32\cdefe.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\cdefe.ini
C:\WINDOWS\system32\cdefe.ini Has been deleted!

Attempting to delete C:\windows\system32\drvcul.dll
C:\windows\system32\drvcul.dll Has been deleted!

Attempting to delete C:\windows\system32\drvculr.dll
C:\windows\system32\drvculr.dll Has been deleted!

Attempting to delete C:\windows\system32\drvsom.dll
C:\windows\system32\drvsom.dll Has been deleted!

Attempting to delete C:\windows\system32\drvsomr.dll
C:\windows\system32\drvsomr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\efedc.dll
C:\WINDOWS\system32\efedc.dll Could not be deleted.

Attempting to delete C:\windows\system32\gebbbyx.dll
C:\windows\system32\gebbbyx.dll Has been deleted!

Attempting to delete C:\windows\system32\iifccca.dll
C:\windows\system32\iifccca.dll Has been deleted!

Attempting to delete C:\windows\system32\nnnnnlm.dll
C:\windows\system32\nnnnnlm.dll Could not be deleted.

Performing Repairs to the registry.
Done!

VundoFix V6.5.8

Checking Java version…

Java version is 1.4.2.5
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 03:53:39 2007-09-05

Listing files found while scanning….

C:\WINDOWS\system32\cdefe.ini
C:\WINDOWS\system32\efedc.dll
C:\windows\system32\nnnnnlm.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\cdefe.ini
C:\WINDOWS\system32\cdefe.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\efedc.dll
C:\WINDOWS\system32\efedc.dll Could not be deleted.

Attempting to delete C:\windows\system32\nnnnnlm.dll
C:\windows\system32\nnnnnlm.dll Could not be deleted.

Performing Repairs to the registry.
Done!

VundoFix V6.5.8

Checking Java version…

Java version is 1.4.2.5
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 03:58:36 2007-09-05

Listing files found while scanning….

C:\WINDOWS\system32\cdefe.ini
C:\WINDOWS\system32\efedc.dll
C:\windows\system32\nnnnnlm.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\cdefe.ini
C:\WINDOWS\system32\cdefe.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\efedc.dll
C:\WINDOWS\system32\efedc.dll Has been deleted!

Attempting to delete C:\windows\system32\nnnnnlm.dll
C:\windows\system32\nnnnnlm.dll Has been deleted!

Performing Repairs to the registry.
Done!

Killer.exe…………………………………………………………….
………………..


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:27, on 2007-09-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kontiki\KService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\nusrmgr.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Image ActiveX Access\iesmn.exe
C:\Program Files\Image ActiveX Access\imsmain.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Image ActiveX Access\imsmn.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Image ActiveX Access\iesmin.exe
C:\WINDOWS\TEMP\win32.tmp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\mgrs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Image ActiveX Access\iesmin.exe
C:\Program Files\VirusProtectPro 3.7\VirusProtectPro 3.7.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Image ActiveX Access\iesmin.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {1031C6FB-1692-4871-AB8D-5EB63CBF7991} - C:\WINDOWS\system32\efedc.dll (file missing)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {1C3C4699-B285-475F-BE47-0B26088CE876} - C:\Program Files\Image ActiveX Access\iesplg.dll
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: (no name) - {39C6B6C8-E01E-3175-B583-04FDA1EE088B} - C:\Program Files\Xbgiliru\tsefttwp.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.6.14.dll
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: TweakMASTER PRO Component - {7DAAC7DE-9EF0-4FF0-BFA5-AFF3E899054C} - C:\PROGRA~1\TWEAKM~1\TweakBHO.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: oembios32.msdn_hlp - {AB5FE6E5-7C72-4B89-85D0-D57E7AEAC236} - C:\WINDOWS\system32\oembios32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {B8E1AD5E-3BBD-6E18-EC59-3B76661A53C2} - C:\WINDOWS\system32\fvrl.dll
O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)
O2 - BHO: (no name) - {C1ADC5ED-FB26-4770-AFE5-BD3A7EB5C148} - C:\WINDOWS\system32\nnnnnlm.dll (file missing)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {E64F0381-0053-4842-B3E5-08F6C4A0AEB6} - C:\WINDOWS\system32\hcpsubea.dll
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Protection Bar - {F06E2ABE-3A50-4079-BE25-FC100D9EAA25} - C:\Program Files\Image ActiveX Access\iesbpl.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Kaspersky Anti-Virus 2006] C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O4 - HKLM\..\Run: [SystemRestoreStatus] rundll32.exe "C:\WINDOWS\system32\oroeugit.dll",sitypnow
O4 - HKLM\..\Run: [avp] C:\WINDOWS\TEMP\win32.tmp.exe
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvcul.dll,startup
O4 - HKLM\..\Run: [jszwxufq] rundll32.exe "C:\Program Files\jszwxufq\lmvclkrw.dll",Init
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [VirusProtectPro 3.7] "C:\Program Files\VirusProtectPro 3.7\VirusProtectPro 3.7.exe" /h
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Ssha] "C:\DOCUME~1\DARBYS~1\APPLIC~1\RACLE~1\spool32.exe" -vt yazb
O4 - HKCU\..\Run: [Tafgusoh] C:\WINDOWS\??stem32\??erinit.exe
O4 - HKLM\..\Policies\Explorer\Run: [user32.dll] C:\Program Files\Image ActiveX Access\iesmn.exe
O4 - HKLM\..\Policies\Explorer\Run: [rare] C:\Program Files\Image ActiveX Access\imsmain.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to &LinkFox - res://C:\PROGRA~1\TWEAKM~1\TweakBHO.dll/IESCRIPT
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Script Checker - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\AVP6\scieplugin.dll
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Darbyshire\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - http://www.williamhillcasino.com (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - http://www.williamhillcasino.com (file missing) (HKCU)
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by134fd.bay134.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1188663167948
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O20 - Winlogon Notify: winuxh32 - C:\WINDOWS\SYSTEM32\winuxh32.dll
O22 - SharedTaskScheduler: fraternalism - {2bb2b2d6-8b86-412e-acca-d656a8979b3e} - C:\WINDOWS\system32\tqcwm.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVP - Kaspersky Lab - C:\Program Files\Kaspersky Lab\AVP6\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

–
End of file - 13203 bytes
Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Double-click smitfraudfix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm


Regards,

Trevuren

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI