This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Check_LSa7

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I hope somebody more technical than me can help me delete this .txt file in my C DRIVE
Since it has been there some programs don't work… adaware wont open. and asks for a debug.
I know it is a file used by phishers and spyware etc and i want it gone

Here is my Hijackthis Log file:
Its path is : C:\check_LSa7.txt

Logfile of HijackThis v1.99.1
Scan saved at 16:20:20, on 10/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator\Desktop\hjt\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6711
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\hqtljetr.dll",sitypnow
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: EXPL0RER.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\sdlrutpe.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Unknown owner - C:\Program Files\KService\KService.exe (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Heres a Combofix log


The check_lsa7 file keeps going up and down in size
for example after i run superantispyware it reduces from 10kb to 1? im so confused?

I want to kill this asap
thanks to anyone who can help
yours sincerely
jack
Hi JACKMORRIS,

It appears that you have two antivirus programs running - Sophos and AVG antivirus (not AVG Antispyware). Running one antivirus program is essential, but having two can cause conflicts, slow your system down and even cause stability problems without improving your security. You should use just one antivirus program and if you want an "2nd opinion", use an online scanner like Kaspersky's.

If you have two antivirus programs installed, then before proceeding, please remove one of them.
Please make sure you choose one currently capable of receiving updates, because an antivirus program without updates cannot protect your system effectively. If you have any problems, please stop and let me know.

————————————————————————

Next press Start->Run, copy/paste the following command into the box and press OK:

cmd /c dir /a /s C:\EXPL0RER.EXE >> "%userprofile%\desktop\look.txt"

A black box will appear and a file called look.txt should appear on your Desktop, don't open it until the black box has disappeared, post the contents of look.txt in your next response.

————————————————————————

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • A log file will be created at C:\vundofix.txt, please post the contents of this in your next response.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

————————————————————————

Then, navigate to the HijackThis program file by opening the hjt folder on your Desktop.
Right-click the HijackThis program file HijackThis and rename it to scan
If you have a shortcut to HijackThis on your Desktop, it will no longer work, so please delete it and make a new one by right-clicking scan.exe and choosing Send To->Desktop (create shortcut)

Now open HijackThis, select Open the Misc Tools section
Press the Open Uninstall Manager… button, then press Save list…
Save the Uninstall log to your Desktop and include a copy in your next response.
Now press Back and Scan and then Save log to create and save a new HijackThis log.

————————————————————————

Once complete, please post the look.txt output, VundoFix report, the uninstall list and a new HijackThis log.
Hi Silver.. .. I am having trouble removing the sophos anti virus program, because there was a bug with it about a year ago and it stopped working anyway so i have chosen to remove it. But when I try to get rid of it in control panel - add or remove programs it says installation error I get this error. "Error: 1721. There is a problem with this Windows Installer package. A program required for this install to complete could not be run. Contact your support personnel or package vendor." and then: "Fatal Error during installation" I didnt move on with Vundo etc until this problem is fixed Thanks Jack
I ran SUPER ANTI SPYWARE AND WAS ABLE TO MANUALLY REMOVE THE CHECK_LSA7 FILE

Here is the LOOK file:

Volume in drive C has no label.
Volume Serial Number is E0C2-EA13

Directory of C:\Documents and Settings\Administrator\Start Menu\Programs\Startup

18/12/2005 11:11 31,232 EXPL0RER.EXE
1 File(s) 31,232 bytes

Directory of C:\Documents and Settings\recovery\Start Menu\Programs\Startup

18/12/2005 11:11 31,232 EXPL0RER.EXE
1 File(s) 31,232 bytes

Directory of C:\Program Files\Microsoft Office\OFFICE11\STARTUP

18/12/2005 11:11 31,232 EXPL0RER.EXE
1 File(s) 31,232 bytes

Total Files Listed:
3 File(s) 93,696 bytes
0 Dir(s) 1,605,107,712 bytes free

VUNDO FIX FOUND NOTHING:


VundoFix V6.5.9

Checking Java version…

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.11

Scan started at 13:55:47 11/10/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…


HERE IS THE UNINSTALL LOG AND HIJACK THIS SCAN


Abexo Free Registry Cleaner
AccessDiver v4.401
Ad-Aware SE Personal
Adobe Download Manager 2.0 (Remove Only)
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Reader 7.0.8
Adobe Shockwave Player
ALPS Touch Pad Driver
ArcSoft VideoImpression 2
AVG 7.5
AVG Anti-Spyware 7.5
BitLord 1.1
Broadcom Gigabit Integrated Controller
CCleaner (remove only)
Conexant HDA D110 MDC V.92 Modem
DivX Web Player
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
High Definition Audio Driver Package - KB835221
HijackThis 1.99.1
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Intel® Graphics Media Accelerator Driver
Intel® PROSet/Wireless Software
iTunes
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java™ 6 Update 2
LimeWire 4.12.11
mCore
mDriver
mDrWiFi
mHlpDell
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office FrontPage 2003
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Reader
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
mIWA
mLogView
mMHouse
Mozilla Firefox (2.0.0.7)
mPfMgr
mPfWiz
mProSafe
mSSO
MSXML 4.0 SP2 (KB936181)
mWlsSafe
mWMI
mXML
mZConfig
PowerDVD 5.1
QuickSet
QuickTime
RealPlayer
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
SA31xx Device Manager & Media Converter
Security Update for Excel 2007 (KB936509)
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Office 2007 (KB934062)
Security Update for Office 2007 (KB936514)
Security Update for Publisher 2007 (KB936646)
Security Update for the 2007 Microsoft Office System (KB936960)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913433)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
SigmaTel Audio
Sonic Update Manager
Sophos Anti-Virus
Spybot - Search & Destroy 1.4
SUPERAntiSpyware Free Edition
Update for Office 2007 (KB932080)
Update for Office 2007 (KB934391)
Update for Office 2007 (KB934393)
Update for Outlook 2007 (KB937608)
Update for Outlook 2007 Junk Email Filter (kb942575)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Word 2007 (KB934173)
Windows Defender
Windows Desktop Search
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WinRAR archiver
Yahoo! Install Manager

HIJACK THIS:


Logfile of HijackThis v1.99.1
Scan saved at 14:05:11, on 11/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Administrator\Desktop\hjt\scan.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6711
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: EXPL0RER.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: hggfgdc - hggfgdc.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: vtuttrp - vtuttrp.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\sdlrutpe.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Unknown owner - C:\Program Files\KService\KService.exe (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Thanks again Silver :thumbup:
Hi JACKMORRIS,

Great, it looks like SAS took care of the infection causing the symptoms :)
However, your machine is still infected so please bear with me.

————————————————————————

Please open Start->Control Panel->Add/Remove Programs, look down the list for these items and remove them:

J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java™ 6 Update 2

These are out of date and now a security risk, you can get the latest update (version 6 update 3) from here

You have LimeWire and BitLord, P2P file sharing programs installed on your computer. These programs do not come bundled with malware as some similar programs do, but peer-to-peer file sharing networks are one of the biggest sources of malware we see. Anything downloaded from them cannot be trusted to be clean, because even if the file appears to be what it claims to be, it can have malware embedded in it.
I recommend you remove them, but of course the choice is yours.
You can remove Limewire and BitLord via Add/Remove Programs.

————————————————————————

Temporarily disable Windows Defender:
Right-click on the Windows Defender icon in the system tray (the grey castle), select Exit and OK the prompt. Windows Defender will automatically start next time you reboot.

Temporarily disable SUPERAntiSpyware
  • Right-click the SUPERAntiSpyware taskbar icon and find Enable Real-Time Protection
  • If this item has a check-mark next to it, select it to disable real-time protection
  • Protection will automatically be re-enabled when your computer is rebooted
————————————————————————

Then, open HijackThis, choose Do a system scan only and place a checkmark next to the following lines:

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - Startup: EXPL0RER.EXE
O20 - Winlogon Notify: hggfgdc - hggfgdc.dll (file missing)
O20 - Winlogon Notify: vtuttrp - vtuttrp.dll (file missing)

Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

————————————————————————

Please download ComboFix to your desktop
  • Double click combofix.exe and follow the prompts.
  • Note: Do not click ComboFix's window while it's running - it may cause it to stall!
  • When finished, it shall produce a log for you, please post it in your next response.
————————————————————————

Once complete, please post the ComboFix report and a new HijackThis log.
Here is Combofix:

ComboFix 07-10-11.1 - 06377262 2007-10-11 15:15:56.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.434 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Application Data\rbap550.dll
C:\Documents and Settings\Administrator\Application Data\rbap550.dll
C:\Documents and Settings\Administrator\Application Data\rbap550.dll
C:\Documents and Settings\Administrator\Application Data\RBInternetEncodings550.dll
C:\Documents and Settings\Administrator\Application Data\RBInternetEncodings550.dll
C:\Documents and Settings\Administrator\Application Data\RBInternetEncodings550.dll
C:\Documents and Settings\Administrator\Application Data\RBShell550.dll
C:\Documents and Settings\Administrator\Application Data\RBShell550.dll
C:\Documents and Settings\Administrator\Application Data\RBShell550.dll
C:\Documents and Settings\Administrator\Application Data\ZZipUtilitiesV02.dll
C:\Documents and Settings\Administrator\Application Data\ZZipUtilitiesV02.dll
C:\Documents and Settings\Administrator\Application Data\ZZipUtilitiesV02.dll
C:\Program Files\Common Files\{E0C2E~1
C:\WINDOWS\cookies.ini
C:\WINDOWS\inet20126
C:\WINDOWS\inet20126\mm.pid
C:\WINDOWS\system32\adeeg.bak1
C:\WINDOWS\system32\adeeg.ini
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\MabryObj.dll
C:\WINDOWS\system32\Packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\WanPacket.dll
C:\WINDOWS\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_NPF
——-\core
——-\DomainService
——-\NPF


((((((((((((((((((((((((( Files Created from 2007-09-11 to 2007-10-11 )))))))))))))))))))))))))))))))
.

2007-10-11 15:20 d——– C:\Temp\WPDNSE
2007-10-11 15:20 53,248 –a—— C:\Temp\wdqgvwmi.dll
2007-10-11 15:17 d——– C:\Program Files\Sun
2007-10-11 15:15 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-11 15:14 d——– C:\Program Files\Java
2007-10-11 13:55 d——– C:\VundoFix Backups
2007-10-11 09:59 d——– C:\Temp\msohtmlclip1
2007-10-11 09:59 d——– C:\Temp\msohtmlclip
2007-10-10 17:49 d——– C:\Temp\hsperfdata_06377262
2007-10-10 17:35 d——– C:\Program Files\Accessdiver
2007-10-10 13:48 388,301 –ahs—- C:\WINDOWS\system32\yccdd.ini2
2007-10-09 22:59 d——– C:\Temp\plugtmp
2007-10-09 17:49 d——– C:\Temp\Google Toolbar
2007-10-09 00:53 d——– C:\Temp\MessengerCache
2007-10-09 00:03 641,536 –a—— C:\WINDOWS\system32\WeUninstall.exe
2007-10-09 00:03 52 –a—— C:\WINDOWS\system32\nwt.sys
2007-10-02 19:35 44,544 –a—— C:\WINDOWS\system32\msxml4a.dll
2007-09-27 01:22 33,792 –a—— C:\WINDOWS\system32\drivers\cledx.sys
2007-09-27 01:21 d——– C:\Program Files\Syncrosoft
2007-09-27 01:21 16,896 –a—— C:\WINDOWS\system32\drivers\synasUSB.sys
2007-09-21 15:50 378,361 –ahs—- C:\WINDOWS\system32\yccdd.bak2
2007-09-21 14:59 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll
2007-09-21 14:49 d——– C:\Program Files\MSBuild
2007-09-21 14:48 d——– C:\Program Files\Microsoft.NET
2007-09-21 14:41 d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-09-21 10:08 227,851 –a—— C:\WINDOWS\uawin.dll
2007-09-21 10:08 40,177 –a—— C:\WINDOWS\ffnsys.dll
2007-09-21 10:08 38,982 –a—— C:\WINDOWS\rsczsys.dll
2007-09-21 10:08 30,559 –a—— C:\WINDOWS\mfnsys.dll
2007-09-21 10:08 13,277 –a—— C:\WINDOWS\snsys.dll
2007-09-21 10:08 12,558 –a—— C:\WINDOWS\gstcore.dll
2007-09-21 10:08 6,017 –a—— C:\WINDOWS\assys.dll
2007-09-20 15:50 512,103 –ahs—- C:\WINDOWS\system32\yccdd.bak1
2007-09-19 12:54 d——– C:\WINDOWS\system32\color

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-11 14:08 ——— d—–w C:\Program Files\SUPERAntiSpyware
2007-10-10 15:41 ——— d—–w C:\Program Files\Skype
2007-10-10 15:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-10-10 15:37 ——— d—–w C:\Documents and Settings\Administrator\Application Data\AVG7
2007-10-10 15:37 ——— d—–w C:\Documents and Settings\Administrator\Application Data\AVG7
2007-10-10 15:37 ——— d—–w C:\Documents and Settings\Administrator\Application Data\AVG7
2007-10-10 15:34 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-08 23:31 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-08 18:40 ——— d—–w C:\Documents and Settings\Administrator\Application Data\LimeWire
2007-10-08 18:40 ——— d—–w C:\Documents and Settings\Administrator\Application Data\LimeWire
2007-10-08 18:40 ——— d—–w C:\Documents and Settings\Administrator\Application Data\LimeWire
2007-09-30 20:28 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Skype
2007-09-30 20:28 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Skype
2007-09-30 20:28 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Skype
2007-09-30 09:14 ——— d—–w C:\Program Files\Sophos
2007-09-27 01:54 ——— d—–w C:\Program Files\MYMA Decoder and Viewer
2007-09-27 00:36 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Steinberg
2007-09-27 00:36 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Steinberg
2007-09-27 00:36 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Steinberg
2007-09-25 07:15 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-09-21 13:50 ——— d—–w C:\Program Files\Microsoft Works
2007-09-19 12:07 ——— d—–w C:\Program Files\MSN Messenger
2007-09-05 18:25 ——— d—–w C:\Program Files\Common Files\Download Manager
2007-08-27 00:35 ——— d—–w C:\Documents and Settings\Administrator\Application Data\ICQ Toolbar
2007-08-27 00:35 ——— d—–w C:\Documents and Settings\Administrator\Application Data\ICQ Toolbar
2007-08-27 00:35 ——— d—–w C:\Documents and Settings\Administrator\Application Data\ICQ Toolbar
2007-08-25 10:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-08-25 10:47 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-08-25 10:47 ——— d—–w C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-08-25 10:47 ——— d—–w C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-08-25 10:47 ——— d—–w C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-08-22 00:09 ——— d—–w C:\Program Files\BitLord
2007-08-17 11:38 ——— d—–w C:\Documents and Settings\Administrator\Application Data\STOIK
2007-08-17 11:38 ——— d—–w C:\Documents and Settings\Administrator\Application Data\STOIK
2007-08-17 11:38 ——— d—–w C:\Documents and Settings\Administrator\Application Data\STOIK
2007-08-16 16:25 ——— d—–w C:\Documents and Settings\All Users\Application Data\NCH Software
2007-08-16 12:22 ——— d—–w C:\Program Files\MSXML 4.0
2007-08-16 11:29 ——— d—–w C:\Program Files\Windows Media Components
2007-08-16 09:32 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-08-16 09:08 65,536 —ha-w C:\Documents and Settings\Administrator\Application Data\WindowsSecurity.dll
2007-08-16 09:08 65,536 —ha-w C:\Documents and Settings\Administrator\Application Data\WindowsSecurity.dll
2007-08-16 09:08 65,536 —ha-w C:\Documents and Settings\Administrator\Application Data\WindowsSecurity.dll
2007-08-16 09:08 53,248 —ha-w C:\Documents and Settings\Administrator\Application Data\Notification.dll
2007-08-16 09:08 53,248 —ha-w C:\Documents and Settings\Administrator\Application Data\Notification.dll
2007-08-16 09:08 53,248 —ha-w C:\Documents and Settings\Administrator\Application Data\Notification.dll
2007-05-29 22:45:57 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012007052920070530\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 15:35 C:\WINDOWS\stsystra.exe]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 17:41]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 17:45]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-10-07 14:13]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-19 21:46]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\recovery\Start Menu\Programs\Startup\
EXPL0RER.EXE [2005-12-18 11:11:20]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 13:11 233472]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Microsoft Office Groove.lnk]
backup=C:\WINDOWS\pss\Microsoft Office Groove.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
backup=C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoUpdate Monitor.lnk]
backup=C:\WINDOWS\pss\AutoUpdate Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EXPL0RER.EXE]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
"D:\Office12\GrooveMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
"C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
"C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
C:\WINDOWS\kdx\KHost.exe -all

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft WPCEmail]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime]
C:\WINDOWS\system32\color\ShellExt\mru\Ltn\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"C:\Program Files\Windows Defender\MSASCui.exe" -hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wupdate]

R2 StudioPro;StudioPro webcam;C:\WINDOWS\system32\DRIVERS\StudioPro.sys
R2 VCAM;Fake Webcam (WDM);C:\WINDOWS\system32\DRIVERS\vcam.sys
R3 USBCCID;USB Smart Card reader;C:\WINDOWS\system32\DRIVERS\usbccid.sys
S1 SAVOnAccess Control;SAVOnAccess Control;C:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys
S1 SAVOnAccess Filter;SAVOnAccess Filter;C:\WINDOWS\system32\DRIVERS\savonaccessfilter.sys
S3 mdxgthkn;mdxgthkn;\??\c:\Temp\mdxgthkn.sys
S3 TASCAM_US122144;TASCAM USB 2.0 Audio Device driver;C:\WINDOWS\system32\Drivers\tascusb2.sys
S3 TASCAM_US144_MIDI;TASCAM US-144 WDM MIDI Device;C:\WINDOWS\system32\drivers\tscusb2m.sys
S3 TASCAM_US144_WDM;TASCAM US-144 WDM;C:\WINDOWS\system32\drivers\tscusb2a.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-11 12:42:20 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-11 15:20:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-11 15:20:54 - machine was rebooted
.
— E O F —


HERE IS HIJACKTHIS:


Logfile of HijackThis v1.99.1
Scan saved at 15:22:24, on 11/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Apoint\HidFind.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator\Desktop\hjt\scan.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6711
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Unknown owner - C:\Program Files\KService\KService.exe (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

THANKS AGAIN
Hi JACKMORRIS,

Please click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Recycle Bin, Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Press OK and Yes to confirm

Check that ComboFix.exe is on your Desktop
  • Then open Notepad: press Start->Run, type notepad and click OK
  • Copy/paste the contents of the below code box into Notepad:
    File::
    C:\check_LSa7.txt
    C:\WINDOWS\system32\hqtljetr.dll
    C:\WINDOWS\system32\sdlrutpe.exe
    C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\EXPL0RER.EXE
    C:\Documents and Settings\recovery\Start Menu\Programs\Startup\EXPL0RER.EXE
    C:\Program Files\Microsoft Office\OFFICE11\STARTUP\EXPL0RER.EXE
    C:\WINDOWS\system32\yccdd.ini2
    C:\WINDOWS\system32\yccdd.bak2
    C:\WINDOWS\uawin.dll
    C:\WINDOWS\ffnsys.dll
    C:\WINDOWS\rsczsys.dll
    C:\WINDOWS\mfnsys.dll
    C:\WINDOWS\snsys.dll
    C:\WINDOWS\gstcore.dll
    C:\WINDOWS\assys.dll
    C:\WINDOWS\system32\yccdd.bak1
    c:\Temp\mdxgthkn.sys
    C:\WINDOWS\system32\color\ShellExt\mru\Ltn\qttask.exe
    
    Folder::
    C:\VundoFix Backups
    
    Driver::
    mdxgthkn
    
    DirLook::
    C:\Temp
    C:\WINDOWS\system32\color
    C:\Program Files\HTTPBruteForcer
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EXPL0RER.EXE]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft WPCEmail]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wupdate]
  • Save this to your Desktop as CFScript.

    [external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
Note: Do not click ComboFix's window while it's running - it may cause it to stall!

Once complete, please post the new ComboFix report and a new HijackThis log.
HJT

Logfile of HijackThis v1.99.1
Scan saved at 11:37:25, on 12/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Apoint\HidFind.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Administrator\Desktop\hjt\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6711
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Unknown owner - C:\Program Files\KService\KService.exe (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Combofix

ComboFix 07-10-12.4 - 06377262 2007-10-12 11:28:00.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.507 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\check_LSa7.txt
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\EXPL0RER.EXE
C:\Documents and Settings\recovery\Start Menu\Programs\Startup\EXPL0RER.EXE
C:\Program Files\Microsoft Office\OFFICE11\STARTUP\EXPL0RER.EXE
c:\Temp\mdxgthkn.sys
C:\WINDOWS\assys.dll
C:\WINDOWS\ffnsys.dll
C:\WINDOWS\gstcore.dll
C:\WINDOWS\mfnsys.dll
C:\WINDOWS\rsczsys.dll
C:\WINDOWS\snsys.dll
C:\WINDOWS\system32\color\ShellExt\mru\Ltn\qttask.exe
C:\WINDOWS\system32\hqtljetr.dll
C:\WINDOWS\system32\sdlrutpe.exe
C:\WINDOWS\system32\yccdd.bak1
C:\WINDOWS\system32\yccdd.bak2
C:\WINDOWS\system32\yccdd.ini2
C:\WINDOWS\uawin.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\recovery\Start Menu\Programs\Startup\EXPL0RER.EXE
C:\Program Files\Microsoft Office\OFFICE11\STARTUP\EXPL0RER.EXE
C:\VundoFix Backups
C:\WINDOWS\assys.dll
C:\WINDOWS\ffnsys.dll
C:\WINDOWS\gstcore.dll
C:\WINDOWS\mfnsys.dll
C:\WINDOWS\rsczsys.dll
C:\WINDOWS\snsys.dll
C:\WINDOWS\system32\color\ShellExt\mru\Ltn\qttask.exe
C:\WINDOWS\system32\yccdd.bak1
C:\WINDOWS\system32\yccdd.bak2
C:\WINDOWS\system32\yccdd.ini2
C:\WINDOWS\uawin.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_MDXGTHKN
——-\mdxgthkn


((((((((((((((((((((((((( Files Created from 2007-09-12 to 2007-10-12 )))))))))))))))))))))))))))))))
.

2007-10-12 11:31 d——– C:\Temp\WPDNSE
2007-10-12 11:31 53,248 –a—— C:\Temp\wdqgvwmi.dll
2007-10-12 11:21 d——– C:\Program Files\Windows Installer Clean Up
2007-10-12 11:21 d——– C:\Program Files\MSECACHE
2007-10-12 11:20 d——– C:\Temp\Google Toolbar
2007-10-11 16:10 d——– C:\Temp\MessengerCache
2007-10-11 15:20 d——– C:\Temp
2007-10-11 15:17 d——– C:\Program Files\Sun
2007-10-11 15:15 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-11 15:14 d——– C:\Program Files\Java
2007-10-10 17:35 d——– C:\Program Files\Accessdiver
2007-10-09 00:03 641,536 –a—— C:\WINDOWS\system32\WeUninstall.exe
2007-10-09 00:03 52 –a—— C:\WINDOWS\system32\nwt.sys
2007-10-02 19:35 44,544 –a—— C:\WINDOWS\system32\msxml4a.dll
2007-09-27 01:22 33,792 –a—— C:\WINDOWS\system32\drivers\cledx.sys
2007-09-27 01:21 d——– C:\Program Files\Syncrosoft
2007-09-27 01:21 16,896 –a—— C:\WINDOWS\system32\drivers\synasUSB.sys
2007-09-21 14:59 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll
2007-09-21 14:49 d——– C:\Program Files\MSBuild
2007-09-21 14:48 d——– C:\Program Files\Microsoft.NET
2007-09-21 14:41 d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-09-19 12:54 d——– C:\WINDOWS\system32\color

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-11 14:08 ——— d—–w C:\Program Files\SUPERAntiSpyware
2007-10-10 15:41 ——— d—–w C:\Program Files\Skype
2007-10-10 15:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-10-10 15:37 ——— d—–w C:\Documents and Settings\Administrator\Application Data\AVG7
2007-10-10 15:34 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-08 23:31 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-08 18:40 ——— d—–w C:\Documents and Settings\Administrator\Application Data\LimeWire
2007-09-30 20:28 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Skype
2007-09-27 01:54 ——— d—–w C:\Program Files\MYMA Decoder and Viewer
2007-09-27 00:36 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Steinberg
2007-09-25 07:15 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-09-21 13:50 ——— d—–w C:\Program Files\Microsoft Works
2007-09-19 12:07 ——— d—–w C:\Program Files\MSN Messenger
2007-09-05 18:25 ——— d—–w C:\Program Files\Common Files\Download Manager
2007-08-27 00:35 ——— d—–w C:\Documents and Settings\Administrator\Application Data\ICQ Toolbar
2007-08-25 10:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-08-25 10:47 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-08-25 10:47 ——— d—–w C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-08-22 00:09 ——— d—–w C:\Program Files\BitLord
2007-08-17 11:38 ——— d—–w C:\Documents and Settings\Administrator\Application Data\STOIK
2007-08-16 16:25 ——— d—–w C:\Documents and Settings\All Users\Application Data\NCH Software
2007-08-16 12:22 ——— d—–w C:\Program Files\MSXML 4.0
2007-08-16 11:29 ——— d—–w C:\Program Files\Windows Media Components
2007-08-16 09:32 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-08-16 09:08 65,536 —ha-w C:\Documents and Settings\Administrator\Application Data\WindowsSecurity.dll
2007-08-16 09:08 53,248 —ha-w C:\Documents and Settings\Administrator\Application Data\Notification.dll
2007-05-29 22:45:57 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012007052920070530\index.dat
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Program Files\HTTPBruteForcer —-

C:\Program Files\HTTPBruteForcer\

—- Directory of C:\Temp —-

2007-10-12 11:24 736 –a—— C:\Temp\MSIb0dd5.LOG
2007-10-12 11:24 1646 –a—— C:\Temp\Sophos Anti-Virus CustomActions Log.txt
2007-10-12 11:23 16384 –a—-t- C:\Temp\Perflib_Perfdata_e40.dat
2007-10-12 11:17 512 –a—-t- C:\Temp\~DF9AF0.tmp
2007-10-12 11:17 512 –a—-t- C:\Temp\~DF9964.tmp
2007-10-12 11:17 438 –a—— C:\Temp\jusched.log
2007-10-12 11:17 32768 –a—— C:\Temp\~DF9AE9.tmp
2007-10-12 11:17 32768 –a—— C:\Temp\~DF995D.tmp
2007-10-11 16:32 3126 –a—— C:\Temp\MessengerCache\KfVCWJyeldK0sgV4I7hx7UFU5bU=
2007-10-11 16:30 3477 –a—— C:\Temp\MessengerCache\JNjLBzqxGDHP1s0hM7i3G7Wapag=
2007-10-11 16:19 3574 –a—— C:\Temp\MessengerCache\UKOhwB+N3EKoiiHXBwrFzg2AsdA=
2007-10-11 16:19 2393 –a—— C:\Temp\MessengerCache\IuVJZc2SAybQXUjAS2FWF+Oric0s=
2007-10-11 16:18 2372 –a—— C:\Temp\MessengerCache\3LGX2FkdQloqkPNnwU8VM3Ky9WaY=
2007-10-11 16:11 2701 –a—— C:\Temp\MessengerCache\jpWh2FHXgokeGQ1cLnwjKDvhqqv4=
2007-10-11 16:11 12037 –a—— C:\Temp\MessengerCache\CnQRUyv6DgAArxd6ztw1oFufyG4=

—- Directory of C:\WINDOWS\system32\color —-

2007-09-22 10:46 562 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\16\#activity.265
2007-09-22 10:46 516 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\15\programs_run.265
2007-09-21 17:41 130702 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\16\#activity.264
2007-09-21 17:41 113826 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\15\programs_run.264
2007-09-21 17:35 4460 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\StarreyBoi Mr BODMAN New Picz On Myspace coment plz - Conversation_1966792.264
2007-09-21 17:35 227 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\l l barlow l l - Conversation_1115696.264
2007-09-21 17:35 131 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\StarreyBoi Mr BODMAN New Picz On Myspace coment plz - Conversation_2950122.264
2007-09-21 17:34 333037 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_173401.jpg
2007-09-21 17:34 1767 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ip a y H Y c37 b c - Conversation_1442786.264
2007-09-21 17:28 4924 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ip a y H Y c37 b c - Conversation_1049418.264
2007-09-21 17:25 119 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\l l barlow l l - Conversation_656820.264
2007-09-21 17:23 1933 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\StarreyBoi Mr BODMAN New Picz On Myspace coment plz - Conversation_1704648.264
2007-09-21 17:21 2429 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ip a y H Y c37 b c - Conversation_1180802.264
2007-09-21 17:21 2081 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\_16319342.264
2007-09-21 17:21 1876 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\StarreyBoi Mr BODMAN New Picz On Myspace coment plz - Conversation_16319342.264
2007-09-21 17:17 21147 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_171754.jpg
2007-09-21 17:14 7635 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ip a y H Y c37 b c - Conversation_852978.264
2007-09-21 17:14 1787 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\StarreyBoi Mr BODMAN New Picz On Myspace coment plz - Conversation_460246.264
2007-09-21 17:14 139 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\StarreyBoi Mr BODMAN New Picz On Myspace coment plz - Conversation_1180324.264
2007-09-21 17:11 1937 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\G so8 ss l ss gg al a a ss lss so8 - Conversation_525774.264
2007-09-21 17:10 449 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ - Conversation_525236.264
2007-09-21 17:05 541 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\G so8 ss l ss gg al a a ss lss so8 - Conversation_1443372.264
2007-09-21 17:05 3249 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ip a y H Y c37 b c - Conversation_263142.264
2007-09-21 17:03 2811 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\- - ScooB - - - Conversation_2360210.264
2007-09-21 17:02 1437 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ Y BRB Gerrin Readii - Conversation_3146648.264
2007-09-21 17:00 295031 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_170001.jpg
2007-09-21 16:56 2565 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ilililliSTEFANililillITS stuff THE BAD THINGS HAPPENS 2 GD PPL BRUCY PARTY WAS SICK - Conversation_132058.264
2007-09-21 16:43 87 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\- - ScooB - - - Conversation_3015602.264
2007-09-21 16:43 85209 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\14\Web_Pages_Displayed.264
2007-09-21 16:43 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\@@@BHenry3Er3B@@@PSingleAndLookingPynAllTheBoisBm4lSafeynLAllTheGirlsL - Conversation_394780.264
2007-09-21 16:43 39 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\bSCOTT b - Conversation_1181198.264
2007-09-21 16:43 28 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ip a y H Y c37 b c - Conversation_8717132.264
2007-09-21 16:43 23 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\E T H A N Porn starY Take my hand lets go somewhere we can rest our souls - Conversation_1115764.264
2007-09-21 16:43 161222 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_164304.jpg
2007-09-21 16:39 803 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ -v- a g -v- so gs s a a sa ss 2 so - Conversation_394802.264
2007-09-21 16:39 61 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\E T H A N Porn starY Take my hand lets go somewhere we can rest our souls - Conversation_132812.264
2007-09-21 16:39 416 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\jordy bey - Conversation_2884530.264
2007-09-21 16:38 2566 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ -v- a g -v- so gs s a a sa ss 2 so - Conversation_459590.264
2007-09-21 16:31 156 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\JORD stil supportin LEEDSash sed sojord now Cos ASH sed collage boy was gaylol bully - Conversation_524996.264
2007-09-21 16:31 139 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\JORD stil supportin LEEDSash sed sojord now Cos ASH sed collage boy was gaylol bully - Conversation_2884530.264
2007-09-21 16:30 6424 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ -v- a g -v- so gs s a a sa ss 2 so - Conversation_11469676.264
2007-09-21 16:29 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\jordy bey - Conversation_2687866.264
2007-09-21 16:29 139 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\jordy bey - Conversation_7603176.264
2007-09-21 16:28 96 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\jordy bey - Conversation_7537640.264
2007-09-21 16:28 403 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\jordy bey - Conversation_2491314.264
2007-09-21 16:28 382684 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_162803.jpg
2007-09-21 16:22 1053 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\jordy bey - Conversation_263688.264
2007-09-21 16:19 2929 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\a a a a s gag-a fs a bd Col X Ls Lzz s - Conversation_5440488.264
2007-09-21 16:13 327310 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_161300.jpg
2007-09-21 16:10 20 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\- - ScooB - - - Conversation_590552.264
2007-09-21 16:10 1260 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ Y - Conversation_1508274.264
2007-09-21 15:58 277537 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_155800.jpg
2007-09-21 15:57 433 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Paul - Conversation_329042.264
2007-09-21 15:43 197276 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_154300.jpg
2007-09-21 15:04 291251 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_150400.jpg
2007-09-21 14:49 294462 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_144903.jpg
2007-09-21 14:33 141632 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_143303.jpg
2007-09-21 14:18 327436 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_141802.jpg
2007-09-21 14:10 4993 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ryan onlineD - Conversation_3277560.264
2007-09-21 14:03 295079 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_140301.jpg
2007-09-21 14:00 595 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\B R s 2 o o 7 B L Ss J L - Conversation_9372748.264
2007-09-21 13:49 190 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ emmi OmgHopeSpainWasBloodyEmmenseFridayNightDodgyDancingCrakeUpPKittiWow Ur Well Too Young Hahax - Conversation_8389476.264
2007-09-21 13:49 190 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ - Conversation_5178050.264
2007-09-21 13:48 193371 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_134802.jpg
2007-09-21 13:48 116 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\MovieScout - Conversation_5112514.264
2007-09-21 13:48 116 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\- Helen F At School H - Conversation_1836208.264
2007-09-21 13:47 223 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ Sweet-Bwoi Ryan - Conversation_3932880.264
2007-09-21 13:45 496 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\FLl KLa N THgFlg LWll Ls BllULRickyL - Conversation_2753866.264
2007-09-21 13:45 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ im ur shiinnnin star beta make a wish n it wil cum truuee b-daii in 5 daii hehe - Conversation_9634888.264
2007-09-21 13:45 186 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\- -Sketchh I Duz Wah Yu Doesnt Cuz-ChloeeL - Conversation_9176006.264
2007-09-21 13:41 111 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\leam - Conversation_3539756.264
2007-09-21 13:39 998 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\l lJ lA lY - lB lR lO lW lN - l0 l7 l - Conversation_6816816.264
2007-09-21 13:39 796 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\im sooo bored ne one wnna chat jst message me - Conversation_4915994.264
2007-09-21 13:33 306314 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_133300.jpg
2007-09-21 13:18 33323 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_131803.jpg
2007-09-21 13:03 33293 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_130303.jpg
2007-09-21 12:48 33215 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_124800.jpg
2007-09-21 12:33 295319 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_123303.jpg
2007-09-21 12:31 49 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\W@ZZ@2K7 - Conversation_1181192.264
2007-09-21 12:31 392 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\mike - Conversation_1115656.264
2007-09-21 12:30 232 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\W@ZZ@2K7 - Conversation_1640078.264
2007-09-21 12:26 1223 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Dante - Conversation_2949928.264
2007-09-21 12:25 313 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\hey - Conversation_12190242.264
2007-09-21 12:23 541 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\I dont think that u know wot uve been missing - Conversation_8847822.264
2007-09-21 12:22 574 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\blownduck - Conversation_2556526.264
2007-09-21 12:18 255818 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_121802.jpg
2007-09-21 12:03 327160 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_120303.jpg
2007-09-21 11:48 252440 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_114802.jpg
2007-09-21 11:33 33435 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_113300.jpg
2007-09-21 11:18 355487 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_111801.jpg
2007-09-21 11:03 200156 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_110302.jpg
2007-09-21 10:56 348 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ryan onlineD - Conversation_19465212.264
2007-09-21 10:54 834 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\david - Conversation_8389108.264
2007-09-21 10:48 153044 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_104802.jpg
2007-09-21 10:46 47 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\leam - Conversation_1114764.264
2007-09-21 10:43 631 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\hairychris7@hotmailcom - Conversation_12518030.264
2007-09-21 10:37 778 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\hairychris7@hotmailcom - Conversation_12386958.264
2007-09-21 10:33 338049 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_103302.jpg
2007-09-21 10:18 118830 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_101801.jpg
2007-09-21 10:07 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\- JeReMySuTeR - Conversation_5768300.264
2007-09-21 10:03 235760 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_100302.jpg
2007-09-21 09:48 224951 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_94801.jpg
2007-09-21 09:33 33368 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_93303.jpg
2007-09-21 09:18 33310 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_91800.jpg
2007-09-21 09:03 32659 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_90303.jpg
2007-09-21 08:48 32627 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_84803.jpg
2007-09-21 08:33 33267 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_83303.jpg
2007-09-21 08:18 33267 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_81803.jpg
2007-09-21 08:03 33148 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_80303.jpg
2007-09-21 07:48 33108 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_74800.jpg
2007-09-21 07:33 33449 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_73300.jpg
2007-09-21 07:18 33256 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_71803.jpg
2007-09-21 07:03 33353 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_70300.jpg
2007-09-21 06:48 33258 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_64800.jpg
2007-09-21 06:33 33175 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_63300.jpg
2007-09-21 06:18 33234 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_61803.jpg
2007-09-21 06:03 33470 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_60303.jpg
2007-09-21 05:48 33449 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_54803.jpg
2007-09-21 05:33 33375 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_53303.jpg
2007-09-21 05:18 33367 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_51803.jpg
2007-09-21 05:03 32625 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_50303.jpg
2007-09-21 04:48 33449 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_44803.jpg
2007-09-21 04:33 33108 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_43303.jpg
2007-09-21 04:18 326867 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_41803.jpg
2007-09-21 04:03 327922 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_40301.jpg
2007-09-21 03:48 67959 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_34802.jpg
2007-09-21 03:47 39 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\the dude - Conversation_525476.264
2007-09-21 03:47 10081 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\the dude - Conversation_394404.264
2007-09-21 03:33 269724 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_33300.jpg
2007-09-21 03:18 257421 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_31801.jpg
2007-09-21 03:03 211894 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_30305.jpg
2007-09-21 02:51 679 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\the dude - Conversation_5505520.264
2007-09-21 02:48 97716 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_24807.jpg
2007-09-21 02:23 358 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Alex - Conversation_656968.264
2007-09-21 02:17 359228 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_21704.jpg
2007-09-21 02:02 253125 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_20202.jpg
2007-09-21 01:47 198515 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_14700.jpg
2007-09-21 01:32 113548 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_13201.jpg
2007-09-21 01:17 64195 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_11700.jpg
2007-09-21 01:14 9850 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\SD - Conversation_132138.264
2007-09-21 01:01 273053 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_10102.jpg
2007-09-21 00:46 276701 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s264_Timed$Screen$Shot_04601.jpg
2007-09-21 00:38 23 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ryan onlineD - Conversation_328614.264
2007-09-20 20:00 54453 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\16\#activity.263
2007-09-20 20:00 48796 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\15\programs_run.263
2007-09-20 20:00 131 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Ryan - Conversation_1115234.263
2007-09-20 19:59 870 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\–L-3-W-1-S–JOE BEST BU0DDY - Conversation_787096.263
2007-09-20 19:59 87 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\–L-3-W-1-S–JOE BEST BU0DDY - Conversation_459404.263
2007-09-20 19:59 330 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\E T H A N Porn starY Take my hand lets go somewhere we can rest our souls - Conversation_197146.263
2007-09-20 19:59 270 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Ryan - Conversation_1180304.263
2007-09-20 19:58 280 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\lildownitlikedowlin - Conversation_852594.263
2007-09-20 19:56 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\xPENNYx i love you so much and getting over you will b so hard 15 days LOL D - Conversation_721560.263
2007-09-20 19:56 37 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\PAsh 2K7 PLooolah u ledgend love ya x - Conversation_590488.263
2007-09-20 19:56 107 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\PAsh 2K7 PLooolah u ledgend love ya x - Conversation_918462.263
2007-09-20 19:56 1007 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\-T RIP grandad Reg ur always wid us n always thinkin of u - Conversation_1376936.263
2007-09-20 19:55 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Andy - Conversation_787058.263
2007-09-20 19:54 45 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Cr4G–ILU EvErYoNe - Conversation_1572970.263
2007-09-20 19:49 123717 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_194904.jpg
2007-09-20 19:42 1026 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\PfRa5r - Conversation_394950.263
2007-09-20 19:41 769 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\sweet and cute - Conversation_393856.263
2007-09-20 19:41 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\_1247106.263
2007-09-20 19:39 330 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\FF0000CC0C0C0iG FF0000MC0C0C0cSiLL FF0000C0C0C01 - Conversation_787080.263
2007-09-20 19:38 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\c12BHAdClMAfc - Conversation_1049920.263
2007-09-20 19:38 289 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Kieron - Conversation_787776.263
2007-09-20 19:37 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\mcneill101@hotmailcouk - Conversation_787080.263
2007-09-20 19:37 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\20–JOSH–WEBB–07 - Conversation_721544.263
2007-09-20 19:35 73 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\E T H A N Porn starY Take my hand lets go somewhere we can rest our souls - Conversation_853892.263
2007-09-20 19:35 28 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\–L-3-W-1-S–LI LOVE G3ORGII3LJOE BEST BUDDY - Conversation_1246194.263
2007-09-20 19:34 4967 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\E T H A N Porn starY Take my hand lets go somewhere we can rest our souls - Conversation_1115122.263
2007-09-20 19:34 324346 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_193403.jpg
2007-09-20 19:32 64 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\SaM ErE 2k7Lsum 1L - Conversation_657386.263
2007-09-20 19:31 145 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\SaM ErE 2k7Lsum 1L - Conversation_525314.263
2007-09-20 19:30 30 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\xPENNYx yea life can b stuff but dont let it put u down 15 days LOL D - Conversation_591616.263
2007-09-20 19:30 201 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\-a29—– WHP till i die 3 s a 8 a ls s 8so6-1 to ussoa47 - Conversation_591586.263
2007-09-20 19:29 705 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\-a29—– WHP till i die 3 s a 8 a ls s 8so6-1 to ussoa47 - Conversation_460656.263
2007-09-20 19:29 660 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\_460656.263
2007-09-20 19:29 268 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\SaM ErE 2k7Lsum 1L - Conversation_329632.263
2007-09-20 19:28 372 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\-a29—– WHP till i die 3 s a 8 a ls s 8so6-1 to ussoa47 - Conversation_526244.263
2007-09-20 19:27 38897 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\14\Web_Pages_Displayed.263
2007-09-20 19:26 35 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\sean - Conversation_591144.263
2007-09-20 19:25 498 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\sean - Conversation_459918.263
2007-09-20 19:21 168 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\sean - Conversation_525552.263
2007-09-20 19:21 1387 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\E T H A N Porn starY Take my hand lets go somewhere we can rest our souls - Conversation_984050.263
2007-09-20 19:19 258954 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_191901.jpg
2007-09-20 19:19 1191 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\sean - Conversation_591126.263
2007-09-20 19:17 546 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\E T H A N Porn starY Take my hand lets go somewhere we can rest our souls - Conversation_590946.263
2007-09-20 19:16 1444 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\E T H A N Porn starY Take my hand lets go somewhere we can rest our souls - Conversation_1049284.263
2007-09-20 19:10 289 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\c12BHAdClMAfc - Conversation_984032.263
2007-09-20 19:09 228 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\- JFFS - Conversation_328110.263
2007-09-20 19:08 45 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\c24aFF0080RACHLsingleL lisa bmfl xxxxxxa80FF00c - Conversation_459762.263
2007-09-20 19:06 4396 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ -v- a g -v- so gs s a a sa ss 2 so - Conversation_656352.263
2007-09-20 19:04 256495 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_190403.jpg
2007-09-20 19:00 950 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\nemisis inferno wit george p ly man xtilly a godess xxxannie my sexy planet girl france soonH - Conversation_263114.263
2007-09-20 18:53 271 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\-T RIP grandad Reg ur always wid us n always thinkin of u - Conversation_132028.263
2007-09-20 18:53 23 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\xPENNYx yea life can b stuff but dont let it put u down 15 days LOL D - Conversation_328656.263
2007-09-20 18:52 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\-a29—– WHP till i die 3 s a 8 a ls s 8so6-1 to ussoa47 - Conversation_263120.263
2007-09-20 18:52 212 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\-a29—– WHP till i die 3 s a 8 a ls s 8so6-1 to ussoa47 - Conversation_66588.263
2007-09-20 16:18 33351 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_161809.jpg
2007-09-20 16:00 66653 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_160029.jpg
2007-09-20 11:47 67182 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_114702.jpg
2007-09-20 11:32 229 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\banksy - Conversation_590566.263
2007-09-20 11:32 202167 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_113206.jpg
2007-09-20 11:17 382306 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_111705.jpg
2007-09-20 11:02 110819 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_110203.jpg
2007-09-20 10:47 201392 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_104701.jpg
2007-09-20 10:32 184253 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_103205.jpg
2007-09-20 10:17 102460 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_101705.jpg
2007-09-20 10:02 217631 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_100200.jpg
2007-09-20 09:47 331966 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_94700.jpg
2007-09-20 09:32 303253 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_93203.jpg
2007-09-20 09:17 218053 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_91702.jpg
2007-09-20 09:02 235794 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_90202.jpg
2007-09-20 01:11 164028 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_11102.jpg
2007-09-20 01:01 458 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\andy - Conversation_721636.263
2007-09-20 00:59 599 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Heffo - Conversation_1639090.263
2007-09-20 00:56 139464 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_05602.jpg
2007-09-20 00:41 210487 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_04103.jpg
2007-09-20 00:26 138896 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_02600.jpg
2007-09-20 00:20 681 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\King Of CrunkxKeep You In The Dark You Know They All Pretendx RIP Colin McRae x - Conversation_1115042.263
2007-09-20 00:11 338069 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s263_Timed$Screen$Shot_01103.jpg
2007-09-19 23:59 45 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\King Of CrunkxKeep You In The Dark You Know They All Pretendx RIP Colin McRae x - Conversation_1180600.262
2007-09-19 23:59 299 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ilililliSTEFANililillITS stuff THE BAD THINGS HAPPENS 2 GD PPL BRUCY PARTY WAS SICK - Conversation_459468.262
2007-09-19 23:59 17251 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\16\#activity.262
2007-09-19 23:59 14044 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\15\programs_run.262
2007-09-19 23:58 493 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\xPeen a lopex - L Sam I LOVE YOU xx Love you xx L 15 days LOL D - Conversation_590740.262
2007-09-19 23:58 1075 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Rhys - Conversation_1245916.262
2007-09-19 23:56 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ - Conversation_6882284.262
2007-09-19 23:56 214641 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s262_Timed$Screen$Shot_235605.jpg
2007-09-19 23:55 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\single guy 4 single girl - Conversation_6816748.262
2007-09-19 23:54 6559 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\14\Web_Pages_Displayed.262
2007-09-19 23:53 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\sam - i love you pennyD - Conversation_6620140.262
2007-09-19 23:53 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Nicole im the one the only Martha D and i L emilie - Conversation_656108.262
2007-09-19 23:53 4 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ChloeDo u wanna go on a bike ride - Conversation_393964.262
2007-09-19 23:52 116 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ - Conversation_328420.262
2007-09-19 23:52 116 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\- Spleak - Type hi to start chatting with me - Conversation_394132.262
2007-09-19 23:51 214 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\- LLOoZiie iiLOVeHiiM- - X iiLOVeMGiiiRLeS - Conversation_1180426.262
2007-09-19 23:51 1893 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Dsilence is golden but SHOUTING IS FUN Dbeing silly is funbut being with them is betterD - Conversation_1114844.262
2007-09-19 23:50 875 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\- LLOoZiie iiLOVeHiiM- - X iiLOVeMGiiiRLeS - Conversation_1049354.262
2007-09-19 23:50 3597 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\- -Sketchh I Duz Wah Yu Doesnt Cuz-ChloeeL - Conversation_1114862.262
2007-09-19 23:50 121 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ Z V - Conversation_1245934.262
2007-09-19 23:48 427 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Dsilence is golden but SHOUTING IS FUN Dbeing silly is funbut being with them is betterD - Conversation_1049308.262
2007-09-19 23:46 55 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\ LYDIA GERMANY WAS THE BEST LOLI gonna miss u richard ily x - Conversation_787136.262
2007-09-19 23:43 410 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\FDs Faal Cs TFLMa I C J B M YsLRicky I Love You DLJamieLGeorge is da sex - Conversation_1311398.262
2007-09-19 23:43 116 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\TAT GURLiiiS STSViiiS SiiNGLS liMSSH AMY KONViiCT WiiFSYZlix - Conversation_721870.262
2007-09-19 23:42 204 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\FDs Faal Cs TFLMa I C J B M YsLRicky I Love You DLJamieLGeorge is da sex - Conversation_459620.262
2007-09-19 23:41 163843 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s262_Timed$Screen$Shot_234102.jpg
2007-09-19 23:40 4312 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Bonzo - Conversation_328548.262
2007-09-19 23:34 2165 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\7\Paul - Conversation_328360.262
2007-09-19 23:26 225916 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s262_Timed$Screen$Shot_232603.jpg
2007-09-19 23:11 209723 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\17\s262_Timed$Screen$Shot_231103.jpg
2007-09-19 12:55 75772 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\mli.exe
2007-06-27 22:04 466944 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\qttask.exe
2007-04-18 16:25 184320 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\find.dll
2006-03-17 15:01 5329 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\help.htm
2005-05-04 01:56 73728 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\DOM.dll
2004-08-10 20:00 18432 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\pm.exe
2004-03-18 16:02 45056 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\dmm.dll
2003-04-14 21:47 54128 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\iambb_screen.gif
2003-04-06 01:53 8696 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\header_main_iambb.gif
2003-02-23 16:11 23278 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\box_kidcontrol.gif
2003-02-23 16:06 17722 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\help_top.gif
2003-02-23 16:00 50301 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\tutorial.gif
2003-02-23 16:00 27984 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\tutorial_2.gif
2003-02-23 16:00 19652 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\tutorial_3.gif
2003-02-23 16:00 10543 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\tutorial_1.gif
2002-02-11 22:10 26011 –a—— C:\WINDOWS\system32\color\ShellExt\mru\Ltn\bigbrotherbox.gif


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 15:35 C:\WINDOWS\stsystra.exe]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 17:41]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 17:45]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-10-07 14:13]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-19 21:46]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 13:11 233472]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Microsoft Office Groove.lnk]
backup=C:\WINDOWS\pss\Microsoft Office Groove.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
backup=C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoUpdate Monitor.lnk]
backup=C:\WINDOWS\pss\AutoUpdate Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
"D:\Office12\GrooveMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
"C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
"C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
C:\WINDOWS\kdx\KHost.exe -all

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"C:\Program Files\Windows Defender\MSASCui.exe" -hide

R2 StudioPro;StudioPro webcam;C:\WINDOWS\system32\DRIVERS\StudioPro.sys
R2 VCAM;Fake Webcam (WDM);C:\WINDOWS\system32\DRIVERS\vcam.sys
R3 USBCCID;USB Smart Card reader;C:\WINDOWS\system32\DRIVERS\usbccid.sys
S3 TASCAM_US122144;TASCAM USB 2.0 Audio Device driver;C:\WINDOWS\system32\Drivers\tascusb2.sys
S3 TASCAM_US144_MIDI;TASCAM US-144 WDM MIDI Device;C:\WINDOWS\system32\drivers\tscusb2m.sys
S3 TASCAM_US144_WDM;TASCAM US-144 WDM;C:\WINDOWS\system32\drivers\tscusb2a.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-12 10:15:33 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-12 11:31:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-12 11:31:46 - machine was rebooted
C:\ComboFix2.txt … 2007-10-11 15:20
.
— E O F —
Hi JACKMORRIS,

Please look at the ComboFix log under where it says "—- Directory of C:\WINDOWS\system32\color —-", does any of this look familiar to you?

I haven't yet looked over your post, but I notice that you have installed Kaspersky online scanner. In my next post I was going to ask you to run a scan with Kaspersky anyway and post the log for me to check, so to save you doing the scan twice, here the instructions I would have posted to help you save the log:

Open Kaspersky Online Scanner in Internet Explorer

You will be prompted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT and then Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • The program will start to scan your system.
  • Once the scan is complete, click on the Save as Text button and save the file to your desktop
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

When complete, please post the Kaspersky report.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI