This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE Defender popup ads

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I thought I was installing a codec to view an online video, and since then I have been receiving the following pop up ad, and it appears my yahoo searches have been redirected. I ran Adaware, but it couldn't find anything…the pop up appears every several minutes.

I also ran spybot, and rebooted computer…ads are still popping up.

I keep receiving a pop up that states this- [external image: Posted Image]

I downloaded and ran Hijack this - here is the result.

Logfile of HijackThis v1.99.1
Scan saved at 4:46:28 PM, on 10/25/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
c:\program files\cisco systems\vpn client\cvpnd.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\DS Clock\dsclock.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\FastStone Capture\FSCapture.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\TimeLeft3\TimeLeft.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
C:\WINNT\system32\hpbpro.exe
C:\WINNT\system32\hpboid.exe
C:\Documents and Settings\paula\My Documents\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: (no name) - {7426C76D-0ADC-0A2C-F4E4-05D58C76ECBB} - C:\WINNT\system32\oqiu.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.netscape.com/"); (C:\Documents and Settings\paula\Application Data\Mozilla\Profiles\default\85wxnc1c.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\paula\Application Data\Mozilla\Profiles\default\85wxnc1c.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: BetaDivX - {48BF2BC0-2945-11D8-8CAC-00080FC65465} - C:\WINNT\system32\IR9V0_QCX.dll
O2 - BHO: (no name) - {7426C76D-0ADC-0A2C-F4E4-05D58C76ECBB} - C:\WINNT\system32\oqiu.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [DemaPostIt1.9.5] "C:\unzipped\pitlig197beta\PitLight.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Acaa] "C:\DOCUME~1\paula\APPLIC~1\SSTEM3~1\ati2evxx.exe" -vt yazr
O4 - HKCU\..\Run: [Ylikrvcs] C:\Program Files\Common Files\??curity\l?gonui.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [SAM] C:\PROGRA~1\SAM\SAM.exe
O4 - HKCU\..\Run: [DS Clock] "C:\Program Files\DS Clock\dsclock.exe"
O4 - Startup: FastStone Capture.lnk = C:\Program Files\FastStone Capture\FSCapture.exe
O4 - Startup: Shortcut to backupdoc.bat.lnk = C:\batch\backupdoc.bat
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Ashley Furniture VPN Client 4.6.0.lnk = C:\Program Files\cisco systems\vpn client\vpngui.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: StumbleUpon: &Blog This - res://StumbleUponIEBar.dll/blogimage
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod4\v6\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod4\v6\yhexbmes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O15 - Trusted Zone: *.stumbleupon.com
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Installer) - http://supportcenter.adelphia.net/sdccommo…ad/tgctlins.cab
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {0348CD18-6EFE-415B-AF32-58F08FA29B33} (WCSAXrview Control) - http://eaglecams.ginncompany.com:8081/wcsarview.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://www.fasturnonline.com/DFSWeb/smsx.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://www.discoveryvillage.net/marshcam/kxhcm10.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsr.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/19.11/uploader2.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/1444be6e5e29fb…ip/RdxIE601.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {65F31DBD-290F-44F8-9B18-47F5AE400A04} (RAS_Watch Control) - http://www.gould.edu.au/wildlifecams/RasWatch.cab
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} (PlayerOCX Control) - http://www.pysoft.com/Downloads/WebCamPlayerOCX.cab
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://69.54.28.120//activex/AMC.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://128.128.32.108/activex/AxisCamControl.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4056/ftp…02/cpbrkpie.cab
O16 - DPF: {A0EAC162-A012-4AD8-B2E1-D5A0BBBCDA51} (PopupSh Control) - http://209.190.5.106/display/PopupSh.ocx
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://nywild4.dyndns.org/plugin/h263ctrl.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://67.86.143.68:81/activex/AMC.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup163.cab
O16 - DPF: {EAA105FE-7BBD-4196-8B96-D46743894195} (MjpegControl Class) - http://69.34.225.3/plugin/mjpegcontrol.cab
O16 - DPF: {FFFFFFFF-CAFE-BABE-BABE-00AA0055595A} - http://www.networksolutionsemailpopwizard….rueSwitchEC.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = routzahn.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = routzahn.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = routzahn.local
O20 - AppInit_DLLs: C:\WINNT\system32\dexplore.dll
O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\program files\cisco systems\vpn client\cvpnd.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINNT\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINNT\system32\hpboid.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • Hello, and welcome to the forum.

    My name is Simon V., and I'll be glad to help you with your computer problems.

    HijackThis logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that happens.

    I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

    I'll get back to you as soon as possible.
I found this information on another tech forum. Certified spyware/foistware, or other malware Field Value GUID {D99BACC6-6289-4D4F-8BAF-4192016AF547} Filename bDivX.dll Object Name BetaDivX Status X BHO Description Parasite, detected by Kaspersky antivirus as Trojan-Downloader.Win32.Delf.cqs - produces "IEDefender", a variant of "Ultimate_Defender" popups Viewed 152 times since 23 May 2005, 1840 Hours UTC-4.STATUS KEY: KEY: "X" - Certified spyware/foistware, or other malware "L" - Legitimate items "O" - Open to debate "?" - Unknown Status "BHO" - Browser Helper Object "TB" - Toolbar "SH" - R3 URL SearchHook And this info also: Here is the only definitive information I have located on this new problem: IEDefender is a variant of "Ultimate Defender" [which is a known rogue anti-spyware program – another Smitfraud variant] it is produced by a BetaDivX BHO (Browser Helper Object): named bDivX.dll , having ClassID D99BACC6-6289-4D4F-8BAF-4192016AF547 , or named IR9V0_QCX.dll , having ClassID 48BF2BC0-2945-11D8-8CAC-00080FC65465 it is detected by Kaspersky antivirus as Trojan-Downloader.Win32.Delf.cqs And this: We now have a third confirmed BHO generating IEDefender: In addition to the two cited above in message 5, IEDfender can be produced by a IntelVideoCodec BHO (Browser Helper Object): named IntelVideoDivX.dll , having ClassID 33A12BEB-3219-4CA8-99B4-733192704C62 I downloaded Kasperky and ran it. It found c:\winnt\system32\oqui.dll And I neutralized it. Pop up add appears to be gone.
That's only one part of the Malware that is present on your system. I will be happy to clean the rest out; please post a new HijackThis log if you still want my help.
Logfile of HijackThis v1.99.1
Scan saved at 10:10:46 AM, on 10/27/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
c:\program files\cisco systems\vpn client\cvpnd.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\DS Clock\dsclock.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\FastStone Capture\FSCapture.exe
C:\Program Files\TimeLeft3\TimeLeft.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Documents and Settings\paula\My Documents\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: (no name) - {7426C76D-0ADC-0A2C-F4E4-05D58C76ECBB} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.netscape.com/"); (C:\Documents and Settings\paula\Application Data\Mozilla\Profiles\default\85wxnc1c.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\paula\Application Data\Mozilla\Profiles\default\85wxnc1c.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: BetaDivX - {48BF2BC0-2945-11D8-8CAC-00080FC65465} - C:\WINNT\system32\IR9V0_QCX.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [DemaPostIt1.9.5] "C:\unzipped\pitlig197beta\PitLight.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Acaa] "C:\DOCUME~1\paula\APPLIC~1\SSTEM3~1\ati2evxx.exe" -vt yazr
O4 - HKCU\..\Run: [Ylikrvcs] C:\Program Files\Common Files\??curity\l?gonui.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [SAM] C:\PROGRA~1\SAM\SAM.exe
O4 - HKCU\..\Run: [DS Clock] "C:\Program Files\DS Clock\dsclock.exe"
O4 - Startup: FastStone Capture.lnk = C:\Program Files\FastStone Capture\FSCapture.exe
O4 - Startup: Shortcut to backupdoc.bat.lnk = C:\batch\backupdoc.bat
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Ashley Furniture VPN Client 4.6.0.lnk = C:\Program Files\cisco systems\vpn client\vpngui.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: StumbleUpon: &Blog This - res://StumbleUponIEBar.dll/blogimage
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod4\v6\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod4\v6\yhexbmes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O15 - Trusted Zone: *.stumbleupon.com
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Installer) - http://supportcenter.adelphia.net/sdccommo…ad/tgctlins.cab
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {0348CD18-6EFE-415B-AF32-58F08FA29B33} (WCSAXrview Control) - http://eaglecams.ginncompany.com:8081/wcsarview.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://www.fasturnonline.com/DFSWeb/smsx.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://www.discoveryvillage.net/marshcam/kxhcm10.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsr.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/19.11/uploader2.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/1444be6e5e29fb…ip/RdxIE601.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {65F31DBD-290F-44F8-9B18-47F5AE400A04} (RAS_Watch Control) - http://www.gould.edu.au/wildlifecams/RasWatch.cab
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} (PlayerOCX Control) - http://www.pysoft.com/Downloads/WebCamPlayerOCX.cab
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://69.54.28.120//activex/AMC.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://128.128.32.108/activex/AxisCamControl.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4056/ftp…02/cpbrkpie.cab
O16 - DPF: {A0EAC162-A012-4AD8-B2E1-D5A0BBBCDA51} (PopupSh Control) - http://209.190.5.106/display/PopupSh.ocx
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://nywild4.dyndns.org/plugin/h263ctrl.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://67.86.143.68:81/activex/AMC.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup163.cab
O16 - DPF: {EAA105FE-7BBD-4196-8B96-D46743894195} (MjpegControl Class) - http://69.34.225.3/plugin/mjpegcontrol.cab
O16 - DPF: {FFFFFFFF-CAFE-BABE-BABE-00AA0055595A} - http://www.networksolutionsemailpopwizard….rueSwitchEC.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = routzahn.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = routzahn.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = routzahn.local
O20 - AppInit_DLLs: C:\WINNT\system32\dexplore.dll
O20 - Winlogon Notify: klogon - C:\WINNT\system32\klogon.dll
O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\program files\cisco systems\vpn client\cvpnd.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINNT\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINNT\system32\hpboid.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • Hi :)

    Do you recognise these domain names?

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = routzahn.local
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = routzahn.local
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = routzahn.local


    Please tell me in your next reply.

    ComboFix
  • Please download Combofix from one of the links below:

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
  • Double-click combofix.exe and follow the prompts.
    • When finished, it shall produce a log for you. Save it to a convenient location.
    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    Make an Uninstall List
  • To access the Uninstall Manager you would do the following:

    1. Start HijackThis
    2. Click on the Config button
    3. Click on the Misc Tools button
    4. Click on the Open Uninstall Manager button.
    5. Click on the Save list… button and save the file to a convenient location. When you press Save, Notepad will open with the contents of that file. Please post the Uninstall List and the report from Combofix (C:\combofix.txt) in your next reply.
The domain names are valid!

Sorry this took so long - combofix got hung up twice…3rd time was the charm :)

Hijack this Unistall list -

3nity Video Convert
ACA Screen Recorder 2.03
Ad-Aware SE Personal
AdelphiaChat_Client
Adobe Download Manager 2.0 (Remove Only)
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0.8
Adobe® Photoshop® Album Starter Edition 3.0
Advanced Batch Converter
Aimersoft Video Converter(Build 1.0.21)
AnyForm
AOL Instant Messenger
AVI Joiner
AXIS Camera Server Control
AXIS Media Control
AXIS Media Control Embedded
CamStudio
CheckMark Payroll 2004/2005
CheckMark Payroll 2005/2006
CheckMark Payroll 2006/2007
CheckMark Payroll 3.8 for Year 2004
CutePDF Writer 2.3
DS Clock
EO Video 1.36
EZTMusicManager
FastStone Capture 5.1
FilmLoop Player
Flock (Photobucket Edition) 0.7
FM Screen Capture Codec (Remove Only)
FotoFusion
Fraps
Frontcam
Genusoft Mediaplayer
Google Earth
HijackThis 1.99.1
Hotfix for MDAC 2.53 (KB911562)
Hotfix for MDAC 2.53 (KB927779)
hp deskjet 5550 series
hp deskjet 5550 series (Remove only)
hp deskjet 5600
HP Deskjet 6800
HP Deskjet 6800
hp instant support
HP Memories Disc
HP Photo & Imaging 4.1
HP Photo and Imaging 2.0 - Deskjet Series
hp print screen utility
HP Software Update
HSP56 MR Drivers
Image Converter pro
Intel® 537EP Modem
iTunes
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 8
J2SE Runtime Environment 5.0 Update 9
Java™ 6 Update 2
Java™ 6 Update 3
Java™ SE Runtime Environment 6 Update 1
Kaspersky Anti-Virus 7.0
Kaspersky Anti-Virus 7.0
KC Softwares AVIToolbox
LiveReg (Symantec Corporation)
LiveUpdate 3.0 (Symantec Corporation)
MGI PhotoSuite III SE (Remove Only)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Encarta Encyclopedia Standard 2002
Microsoft Office 2000 SR-1 Professional
Microsoft Picture It! Photo 2002
Microsoft Word 2002
Microsoft Works 2002 Setup Launcher
Microsoft Works 6.0
Microsoft Works Suite Add-in for Microsoft Word
Microsoft XML Parser and SDK
MSXML 4.0 SP2 (KB927978)
MWSnap 3
My Screen Recorder Pro 2.48
My Wal-Mart Digital Photo Center
Nero - Burning Rom
Netscape (7.2)
Norton WMI Update
ObjectDock
PayClock Pro Ver 3.355G
Pervasive System Analyzer
Pervasive.SQL Client v8.10
Photo Collage 1.44
Post-it® Software Notes Lite
PROFITwindows Client
ProSavageDDR and Utilities
Quick Screen Recorder 1.5
QuickTime
RealPlayer
S3Display
S3Gamma2
S3Info2
S3Overlay
ScreenVirtuoso Pro 2.50
ScreenVirtuoso Pro 3.10
Security Update for Windows 2000 (KB904706)
Security Update for Windows 2000 (KB923689)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Serif PhotoPlus 6.0
Shockwave
Sony USB Driver
Spybot - Search & Destroy 1.4
Stamps.com
StumbleUpon IE Toolbar
Symantec pcAnywhere
Taksi Desktop Video Recorder
Tax-Mate 2004 version 4.1.3
Tax-Mate 5.1.2
Tax-Mate Print 1096 Updater
TaxMate Print 2003 version 3.1.1
TimeLeft
TimeLeft 3 Freeware edition
TMPGEnc 4.0 XPress Trial Version
upapp
Update Rollup 1 for Windows 2000 SP4
Video Master
VPN Client
WeatherBug
Webshots Desktop
Winamp (remove only)
Windows 2000 Hotfix - KB834707
Windows 2000 Hotfix - KB842773
Windows 2000 Hotfix - KB867282
Windows 2000 Hotfix - KB887797
Windows 2000 Hotfix - KB889293
Windows 2000 Hotfix - KB890046
Windows 2000 Hotfix - KB890923
Windows 2000 Hotfix - KB893756
Windows 2000 Hotfix - KB896358
Windows 2000 Hotfix - KB896422
Windows 2000 Hotfix - KB896423
Windows 2000 Hotfix - KB896424
Windows 2000 Hotfix - KB899587
Windows 2000 Hotfix - KB899589
Windows 2000 Hotfix - KB900725
Windows 2000 Hotfix - KB901017
Windows 2000 Hotfix - KB901214
Windows 2000 Hotfix - KB905414
Windows 2000 Hotfix - KB905495
Windows 2000 Hotfix - KB905749
Windows 2000 Hotfix - KB908519
Windows 2000 Hotfix - KB908531
Windows 2000 Hotfix - KB911280
Windows 2000 Hotfix - KB911567
Windows 2000 Hotfix - KB912919
Windows 2000 Hotfix - KB913580
Windows 2000 Hotfix - KB914388
Windows 2000 Hotfix - KB914389
Windows 2000 Hotfix - KB917008
Windows 2000 Hotfix - KB917422
Windows 2000 Hotfix - KB917736
Windows 2000 Hotfix - KB917953
Windows 2000 Hotfix - KB918118
Windows 2000 Hotfix - KB918899
Windows 2000 Hotfix - KB920213
Windows 2000 Hotfix - KB920670
Windows 2000 Hotfix - KB920683
Windows 2000 Hotfix - KB920685
Windows 2000 Hotfix - KB920958
Windows 2000 Hotfix - KB921398
Windows 2000 Hotfix - KB921883
Windows 2000 Hotfix - KB922582
Windows 2000 Hotfix - KB922616
Windows 2000 Hotfix - KB923191
Windows 2000 Hotfix - KB923414
Windows 2000 Hotfix - KB923694
Windows 2000 Hotfix - KB923980
Windows 2000 Hotfix - KB924191
Windows 2000 Hotfix - KB924270
Windows 2000 Hotfix - KB924667
Windows 2000 Hotfix - KB925486
Windows 2000 Hotfix - KB925902
Windows 2000 Hotfix - KB926436
Windows 2000 Hotfix - KB927891
Windows 2000 Hotfix - KB928843
Windows 2000 Hotfix - KB929969
Windows 2000 Hotfix - KB930178
Windows 2000 Hotfix - KB931768
Windows 2000 Hotfix - KB931784
Windows 2000 Hotfix - KB932168
Windows 2000 Hotfix (SP5) Q818043
Windows 2000 Service Pack 4
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Player 9 Hotfix [See KB885492 for more information]
Windows Media Player Hotfix [See Q828026 for more information]
Windows Media Player system update (9 Series)
Windows Media Recorder
WinPcap 3.1
WinZip
Wisdom-soft AutoScreenRecorder 2.1 Pro
Yahoo! Address AutoComplete
Yahoo! Anti-Spy
Yahoo! extras
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Messenger Explorer Bar
Yahoo! Photos Easy Upload Tool 1v7
Yahoo! Toolbar for Internet Explorer

ComboFix Log -

ComboFix 07-10-23.2 - paula 2007-10-27 12:28:55.2 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.757 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\My Documents\Downloads\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Documents and Settings\paula\Application Data\SSTEM3~1
C:\Program Files\Common Files\curity~1
C:\WINNT\system32\wintsu.exe

.
((((((((((((((((((((((((( Files Created from 2007-09-27 to 2007-10-27 )))))))))))))))))))))))))))))))
.

2007-10-27 12:28 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_370.dat
2007-10-27 11:38 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_374.dat
2007-10-27 10:35 51,200 –a—— C:\WINNT\NirCmd.exe
2007-10-26 14:50 82,061 –a—— C:\WINNT\system32\drivers\klick.dat
2007-10-26 14:50 81,549 –a—— C:\WINNT\system32\drivers\klin.dat
2007-10-26 14:49 d——– C:\Program Files\Kaspersky Lab
2007-10-26 14:49 1,284,896 –ahs—- C:\WINNT\system32\drivers\fidbox.dat
2007-10-26 14:49 7,712 –ahs—- C:\WINNT\system32\drivers\fidbox2.dat
2007-10-26 14:35 d——– C:\KAV
2007-10-25 12:20 36,864 –a—— C:\WINNT\system32\sysinit32.exe
2007-10-16 15:58 d——– C:\Program Files\ezt
2007-10-05 11:46 d——– C:\Drivers
2007-10-05 11:46 299,923 –a—— C:\WINNT\system32\drivers\sonyhcs.sys
2007-10-05 11:46 102,220 –a—— C:\WINNT\system32\drivers\sonypvs1.sys
2007-10-05 11:46 53,248 –a—— C:\WINNT\system32\SONYHCY.DLL
2007-10-05 11:46 38,739 –a—— C:\WINNT\system32\drivers\sonyhcc.sys
2007-10-05 11:46 28,224 –a—— C:\WINNT\system32\drivers\SonyPVM1.sys
2007-10-05 11:46 7,921 –a—— C:\WINNT\system32\drivers\SONYPVU1.SYS
2007-10-05 11:46 6,097 –a—— C:\WINNT\system32\drivers\sonyhcb.sys
2007-10-05 11:46 3,654 –a—— C:\WINNT\system32\drivers\Sonyhcp.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-26 22:33 7,292 –sha-w C:\WINNT\system32\drivers\fidbox.idx
2007-10-26 22:33 2,624 –sha-w C:\WINNT\system32\drivers\fidbox2.idx
2007-10-26 15:32 ——— d—–w C:\Program Files\Abacast
2007-10-15 22:28 ——— d—–w C:\Program Files\Java
2007-10-05 16:46 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-09-17 18:59 ——— d—–w C:\Program Files\Winamp
2007-08-29 14:15 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-07-31 00:19 92,504 —-a-w C:\WINNT\system32\cdm.dll
2007-07-31 00:19 549,720 —-a-w C:\WINNT\system32\wuapi.dll
2007-07-31 00:19 53,080 —-a-w C:\WINNT\system32\wuauclt.exe
2007-07-31 00:19 43,352 —-a-w C:\WINNT\system32\wups2.dll
2007-07-31 00:19 325,976 —-a-w C:\WINNT\system32\wucltui.dll
2007-07-31 00:19 203,096 —-a-w C:\WINNT\system32\wuweb.dll
2007-07-31 00:19 1,712,984 —-a-w C:\WINNT\system32\wuaueng.dll
2007-07-31 00:18 33,624 —-a-w C:\WINNT\system32\wups.dll
2006-12-16 18:12 58,288 —-a-w C:\Documents and Settings\paula\Application Data\GDIPFONTCACHEV1.DAT
2006-12-14 14:15 56,912 —-a-w C:\Documents and Settings\paula\g2mdlhlpx.exe
2006-06-26 21:04 34,941 —-a-w C:\Program Files\uninstall.exe
2006-05-01 05:50 55,296 —-a-w C:\Program Files\fraps64.dll
2006-05-01 05:50 289,280 —-a-w C:\Program Files\fraps64.dat
2006-04-30 13:46 774,144 —-a-w C:\Program Files\fraps.exe
2006-04-30 13:45 114,688 —-a-w C:\Program Files\fraps.dll
2006-04-30 13:45 110,592 —-a-w C:\Program Files\frapslcd.dll
2006-04-30 10:07 10,006 —-a-w C:\Program Files\changes.txt
2006-04-27 06:49 1,859 —-a-w C:\Program Files\README.HTM
2004-10-20 00:55 1,994 —-a-w C:\Program Files\INSTALL.LOG
2004-07-02 05:18 271 —h–w C:\Program Files\desktop.ini
2004-07-02 05:18 21,952 —h–w C:\Program Files\folder.htt
2002-07-24 12:00 32,528 —-a-w C:\WINNT\inf\wbfirdma.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{48BF2BC0-2945-11D8-8CAC-00080FC65465}]
C:\WINNT\system32\IR9V0_QCX.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 14:05 C:\WINNT\system32\mobsync.exe]
"VTPreset"="VTPreset.exe" [04-02-24 19:17 C:\WINNT\system32\VTPreset.exe]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [01-08-23 16:52 ]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [01-08-16 23:41 ]
"HPDJ Taskbar Utility"="C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb12.exe" [04-06-25 19:32 ]
"PCTVOICE"="pctspk.exe" [01-10-04 09:48 C:\WINNT\system32\pctspk.exe]
"NeroCheck"="C:\WINNT\system32\NeroCheck.exe" [01-07-09 04:50 ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [04-12-17 23:20 ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06-09-01 15:57 ]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [04-05-12 14:18 ]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [05-02-16 22:11 ]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [03-05-21 17:37 ]
"SSC_UserPrompt"="C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [04-11-02 15:59 ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06-04-14 08:42 ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [07-09-25 01:11 ]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [05-06-06 22:46 ]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [07-06-28 12:51 ]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [01-02-20 12:09 C:\WINNT\system32\CTFMON.EXE]
"DemaPostIt1.9.5"="C:\unzipped\pitlig197beta\PitLight.exe" [03-04-27 15:17 ]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [07-06-07 14:08 ]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [02-01-04 14:36 ]
"Acaa"="C:\DOCUME~1\paula\APPLIC~1\SSTEM3~1\ati2evxx.exe" []
"Ylikrvcs"="C:\Program Files\Common Files\??curity\l?gonui.exe" []
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [06-03-30 15:45 ]
"SAM"="C:\PROGRA~1\SAM\SAM.exe" []
"DS Clock"="C:\Program Files\DS Clock\dsclock.exe" [05-02-14 22:23 ]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop

C:\Documents and Settings\paula\Start Menu\Programs\Startup\
FastStone Capture.lnk - C:\Program Files\FastStone Capture\FSCapture.exe [2007-01-07 15:08:32]
Shortcut to backupdoc.bat.lnk - C:\batch\backupdoc.bat [2004-11-11 10:46:46]
TimeLeft.lnk - C:\Program Files\TimeLeft3\TimeLeft.exe [2006-12-28 17:49:24]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2004-11-16 13:09:40]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
PCANotify.dll 02-02-15 09:51 24638 C:\WINNT\system32\Pcanotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"= C:\WINNT\system32\dexplore.dll

R0 SONYPVM1;Sony Memory Stick Driver(SONYPVM1);C:\WINNT\system32\DRIVERS\SONYPVM1.SYS
R2 SetupNT;SetupNT;C:\WINNT\system32\SetupNT.sys
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINNT\system32\DRIVERS\klim5.sys
R3 usbhub20;USB 2.0 Root Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINNT\system32\drivers\npf.sys
S3 viafilter;VIA USB Filter;C:\WINNT\system32\Drivers\viausb.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-26 18:15:01 C:\WINNT\Tasks\backupdoc.job"
"2007-06-26 15:20:07 C:\WINNT\Tasks\bakcup.job"
- C:\WINNT\system32\NTBACKUP.EXE
.
**************************************************************************

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-27 12:33:58
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-27 12:35:31
.
— E O F —
  • Hi :)

    And any clue how to get my system clock off of Military time? :lol:


    That should be fixed when running Combofix again :)

    Uninstall Programs
  • Click on Start, then Control Panel. Double click on Add or Remove Programs.

    Please remove the following programs:
    • J2SE Runtime Environment 5.0 Update 10
    • J2SE Runtime Environment 5.0 Update 8
    • J2SE Runtime Environment 5.0 Update 9
    • Java 6 Update 2
    • Java SE Runtime Environment 6 Update 1
    • WeatherBug > Alternatives: WeatherPulse, Weather Watcher, ForecastFox (Firefox Addon)
    Combofix
  • Open Notepad, and copy/paste the text in the quotebox below into it:

    File::
    
    C:\WINNT\system32\sysinit32.exe
    C:\WINNT\system32\IR9V0_QCX.dll
    C:\WINNT\system32\dexplore.dll
    
    Folder::
    
    C:\Program Files\Common Files\??curity\
    C:\DOCUME~1\paula\APPLIC~1\SSTEM3~1\
    
    Registry::
    
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{48BF2BC0-2945-11D8-8CAC-00080FC65465}]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Weather"=-
    "Acaa"=-
    "Ylikrvcs"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "appinit_dlls"=""
  • Save this as "CFScript".

    [external image: Posted Image]
  • Referring to the picture above, drag CFScript into ComboFix.exe.
  • It will create a log. Be sure to save it to a convenient location.

    Run Kaspersky Online Scan
  • Please do an online scan with Kaspersky WebScanner

    Click on Kaspersky Online Scanner

    You will be promted to install an ActiveX component from Kaspersky, click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make sure that the following are selected:
      • Scan using the following Anti-Virus database:
      Extended (if available otherwise Standard)
      • Scan Options:
      Scan Archives Scan Mail Bases
    • Click OK
    • Now under select a target to scan:Select My Computer
    • The program will start and scan your system.
    • The scan will take a while so be patient and let it run.
    • Once the scan is complete it will display if your system has been infected.
      • Now click on the Save as Text button:
    • Save the file to your desktop.
    Report Back
  • Please post the reports from Combofix and the Kaspersky Online Scan, along with a new HijackThis log in your next reply. Also tell me how everything is working.
Looks like Kaspersky will not be done before I leave here today..so I will leave my computer up to run…and report back on Monday. BTW, what is the issue with Weatherbug? Spyware, cookies? Also, I noticed about 5 gig freed up on my hard drive. Is that due to Combofix? Thank you so much for your help thus far! :thumbup:

Looks like Kaspersky will not be done before I leave here today..so I will leave my computer up to run…and report back on Monday.

BTW, what is the issue with Weatherbug? Spyware, cookies?

Also, I noticed about 5 gig freed up on my hard drive. Is that due to Combofix?

Thank you so much for your help thus far! :thumbup:


Here is some more info concerning WeatherBug:

WeatherBug is a system tray icon that offers weather information and includes built-in ads. WeatherBug is controlled by AWS Convergence Technologies (weatherbugmedia.com). There is some controversy over whether WeatherBug should be targeted by anti-parasite software. AWS strongly deny their software is ‘spyware’, and by the definition used here, it is not, as it does not leak information back to its controlling servers. However, WeatherBug has in the past been silently installed by the FavoriteMan parasite and Freeze.com screensavers, and more recently has been bundled by software such as AIM and Blubster. This makes it ‘unsolicited’, and since it is installed to raise money for its creators through the built-in ads it is certainly ‘commercial’. So it does meet the definition for ‘parasite’: unsolicited commercial software. It is nonetheless listed as a borderline case because it is not overtly harmful and many people do install it deliberately. WeatherBug bundles the MySearch parasite in its standalone distribution and has in the past, installed Gator and SVAPlayer.

It's an optional removal, but I always recommend to remove it.

It's possible that Combofix freed 5 gigabytes on your Hard Drive. It all depends on what was in the folders that it removed ;)

I'll await your post on Monday.
Combofix is a specific Malware cleaning tool; it doesn't clean out temporary files. The tool normally has created two logs (because of the crashes). To find them, please do the following:

Double-click on My Computer, then on Local Drive (C:), there you will see Combofix.txt and Combofix-2.txt. Please post the contents of Combofix.txt, along with the new Combofix log, and the Kaspersky Online Scan report.
Combofix.txt Log

ComboFix 07-10-23.2 - paula 2007-10-27 14:27:29.3 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.775 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\My Documents\Downloads\ComboFix.exe
Command switches used :: C:\Documents and Settings\paula\My Documents\CFScript.txt

FILE::
C:\WINNT\system32\dexplore.dll
C:\WINNT\system32\IR9V0_QCX.dll
C:\WINNT\system32\sysinit32.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINNT\system32\sysinit32.exe

.
((((((((((((((((((((((((( Files Created from 2007-09-27 to 2007-10-27 )))))))))))))))))))))))))))))))
.

2007-10-27 14:27 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_378.dat
2007-10-27 12:28 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_370.dat
2007-10-27 11:38 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_374.dat
2007-10-27 10:35 51,200 –a—— C:\WINNT\NirCmd.exe
2007-10-26 14:50 82,061 –a—— C:\WINNT\system32\drivers\klick.dat
2007-10-26 14:50 81,549 –a—— C:\WINNT\system32\drivers\klin.dat
2007-10-26 14:49 d——– C:\Program Files\Kaspersky Lab
2007-10-26 14:49 1,854,752 –ahs—- C:\WINNT\system32\drivers\fidbox.dat
2007-10-26 14:49 23,328 –ahs—- C:\WINNT\system32\drivers\fidbox2.dat
2007-10-26 14:35 d——– C:\KAV
2007-10-16 15:58 d——– C:\Program Files\ezt
2007-10-05 11:46 d——– C:\Drivers
2007-10-05 11:46 299,923 –a—— C:\WINNT\system32\drivers\sonyhcs.sys
2007-10-05 11:46 102,220 –a—— C:\WINNT\system32\drivers\sonypvs1.sys
2007-10-05 11:46 53,248 –a—— C:\WINNT\system32\SONYHCY.DLL
2007-10-05 11:46 38,739 –a—— C:\WINNT\system32\drivers\sonyhcc.sys
2007-10-05 11:46 28,224 –a—— C:\WINNT\system32\drivers\SonyPVM1.sys
2007-10-05 11:46 7,921 –a—— C:\WINNT\system32\drivers\SONYPVU1.SYS
2007-10-05 11:46 6,097 –a—— C:\WINNT\system32\drivers\sonyhcb.sys
2007-10-05 11:46 3,654 –a—— C:\WINNT\system32\drivers\Sonyhcp.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-27 19:09 ——— d—–w C:\Program Files\Java
2007-10-26 22:33 7,292 –sha-w C:\WINNT\system32\drivers\fidbox.idx
2007-10-26 22:33 2,624 –sha-w C:\WINNT\system32\drivers\fidbox2.idx
2007-10-26 15:32 ——— d—–w C:\Program Files\Abacast
2007-10-05 16:46 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-09-17 18:59 ——— d—–w C:\Program Files\Winamp
2007-08-29 14:15 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-07-31 00:19 92,504 —-a-w C:\WINNT\system32\cdm.dll
2007-07-31 00:19 549,720 —-a-w C:\WINNT\system32\wuapi.dll
2007-07-31 00:19 53,080 —-a-w C:\WINNT\system32\wuauclt.exe
2007-07-31 00:19 43,352 —-a-w C:\WINNT\system32\wups2.dll
2007-07-31 00:19 325,976 —-a-w C:\WINNT\system32\wucltui.dll
2007-07-31 00:19 203,096 —-a-w C:\WINNT\system32\wuweb.dll
2007-07-31 00:19 1,712,984 —-a-w C:\WINNT\system32\wuaueng.dll
2007-07-31 00:18 33,624 —-a-w C:\WINNT\system32\wups.dll
2006-12-16 18:12 58,288 —-a-w C:\Documents and Settings\paula\Application Data\GDIPFONTCACHEV1.DAT
2006-12-14 14:15 56,912 —-a-w C:\Documents and Settings\paula\g2mdlhlpx.exe
2006-06-26 21:04 34,941 —-a-w C:\Program Files\uninstall.exe
2006-05-01 05:50 55,296 —-a-w C:\Program Files\fraps64.dll
2006-05-01 05:50 289,280 —-a-w C:\Program Files\fraps64.dat
2006-04-30 13:46 774,144 —-a-w C:\Program Files\fraps.exe
2006-04-30 13:45 114,688 —-a-w C:\Program Files\fraps.dll
2006-04-30 13:45 110,592 —-a-w C:\Program Files\frapslcd.dll
2006-04-30 10:07 10,006 —-a-w C:\Program Files\changes.txt
2006-04-27 06:49 1,859 —-a-w C:\Program Files\README.HTM
2004-10-20 00:55 1,994 —-a-w C:\Program Files\INSTALL.LOG
2004-07-02 05:18 271 —h–w C:\Program Files\desktop.ini
2004-07-02 05:18 21,952 —h–w C:\Program Files\folder.htt
2002-07-24 12:00 32,528 —-a-w C:\WINNT\inf\wbfirdma.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 14:05 C:\WINNT\system32\mobsync.exe]
"VTPreset"="VTPreset.exe" [04-02-24 19:17 C:\WINNT\system32\VTPreset.exe]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [01-08-23 16:52 ]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [01-08-16 23:41 ]
"HPDJ Taskbar Utility"="C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb12.exe" [04-06-25 19:32 ]
"PCTVOICE"="pctspk.exe" [01-10-04 09:48 C:\WINNT\system32\pctspk.exe]
"NeroCheck"="C:\WINNT\system32\NeroCheck.exe" [01-07-09 04:50 ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [04-12-17 23:20 ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06-09-01 15:57 ]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [04-05-12 14:18 ]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [05-02-16 22:11 ]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [03-05-21 17:37 ]
"SSC_UserPrompt"="C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [04-11-02 15:59 ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06-04-14 08:42 ]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [05-06-06 22:46 ]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [07-06-28 12:51 ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [07-09-25 01:11 ]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [01-02-20 12:09 C:\WINNT\system32\CTFMON.EXE]
"DemaPostIt1.9.5"="C:\unzipped\pitlig197beta\PitLight.exe" [03-04-27 15:17 ]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [07-06-07 14:08 ]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [06-03-30 15:45 ]
"SAM"="C:\PROGRA~1\SAM\SAM.exe" []
"DS Clock"="C:\Program Files\DS Clock\dsclock.exe" [05-02-14 22:23 ]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop

C:\Documents and Settings\paula\Start Menu\Programs\Startup\
FastStone Capture.lnk - C:\Program Files\FastStone Capture\FSCapture.exe [2007-01-07 15:08:32]
Shortcut to backupdoc.bat.lnk - C:\batch\backupdoc.bat [2004-11-11 10:46:46]
TimeLeft.lnk - C:\Program Files\TimeLeft3\TimeLeft.exe [2006-12-28 17:49:24]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2004-11-16 13:09:40]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
PCANotify.dll 02-02-15 09:51 24638 C:\WINNT\system32\Pcanotify.dll

R0 SONYPVM1;Sony Memory Stick Driver(SONYPVM1);C:\WINNT\system32\DRIVERS\SONYPVM1.SYS
R2 SetupNT;SetupNT;C:\WINNT\system32\SetupNT.sys
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINNT\system32\DRIVERS\klim5.sys
R3 usbhub20;USB 2.0 Root Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINNT\system32\drivers\npf.sys
S3 viafilter;VIA USB Filter;C:\WINNT\system32\Drivers\viausb.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-26 18:15:01 C:\WINNT\Tasks\backupdoc.job"
"2007-06-26 15:20:07 C:\WINNT\Tasks\bakcup.job"
- C:\WINNT\system32\NTBACKUP.EXE
.
**************************************************************************

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-27 14:32:34
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-27 14:36:05
C:\ComboFix2.txt … 07-10-27 12:35
.
— E O F —
Combofix log from second run

ComboFix 07-10-23.2 - paula 2007-10-27 14:27:29.3 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.775 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\My Documents\Downloads\ComboFix.exe
Command switches used :: C:\Documents and Settings\paula\My Documents\CFScript.txt

FILE::
C:\WINNT\system32\dexplore.dll
C:\WINNT\system32\IR9V0_QCX.dll
C:\WINNT\system32\sysinit32.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINNT\system32\sysinit32.exe

.
((((((((((((((((((((((((( Files Created from 2007-09-27 to 2007-10-27 )))))))))))))))))))))))))))))))
.

2007-10-27 14:27 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_378.dat
2007-10-27 12:28 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_370.dat
2007-10-27 11:38 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_374.dat
2007-10-27 10:35 51,200 –a—— C:\WINNT\NirCmd.exe
2007-10-26 14:50 82,061 –a—— C:\WINNT\system32\drivers\klick.dat
2007-10-26 14:50 81,549 –a—— C:\WINNT\system32\drivers\klin.dat
2007-10-26 14:49 d——– C:\Program Files\Kaspersky Lab
2007-10-26 14:49 1,854,752 –ahs—- C:\WINNT\system32\drivers\fidbox.dat
2007-10-26 14:49 23,328 –ahs—- C:\WINNT\system32\drivers\fidbox2.dat
2007-10-26 14:35 d——– C:\KAV
2007-10-16 15:58 d——– C:\Program Files\ezt
2007-10-05 11:46 d——– C:\Drivers
2007-10-05 11:46 299,923 –a—— C:\WINNT\system32\drivers\sonyhcs.sys
2007-10-05 11:46 102,220 –a—— C:\WINNT\system32\drivers\sonypvs1.sys
2007-10-05 11:46 53,248 –a—— C:\WINNT\system32\SONYHCY.DLL
2007-10-05 11:46 38,739 –a—— C:\WINNT\system32\drivers\sonyhcc.sys
2007-10-05 11:46 28,224 –a—— C:\WINNT\system32\drivers\SonyPVM1.sys
2007-10-05 11:46 7,921 –a—— C:\WINNT\system32\drivers\SONYPVU1.SYS
2007-10-05 11:46 6,097 –a—— C:\WINNT\system32\drivers\sonyhcb.sys
2007-10-05 11:46 3,654 –a—— C:\WINNT\system32\drivers\Sonyhcp.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-27 19:09 ——— d—–w C:\Program Files\Java
2007-10-26 22:33 7,292 –sha-w C:\WINNT\system32\drivers\fidbox.idx
2007-10-26 22:33 2,624 –sha-w C:\WINNT\system32\drivers\fidbox2.idx
2007-10-26 15:32 ——— d—–w C:\Program Files\Abacast
2007-10-05 16:46 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-09-17 18:59 ——— d—–w C:\Program Files\Winamp
2007-08-29 14:15 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-07-31 00:19 92,504 —-a-w C:\WINNT\system32\cdm.dll
2007-07-31 00:19 549,720 —-a-w C:\WINNT\system32\wuapi.dll
2007-07-31 00:19 53,080 —-a-w C:\WINNT\system32\wuauclt.exe
2007-07-31 00:19 43,352 —-a-w C:\WINNT\system32\wups2.dll
2007-07-31 00:19 325,976 —-a-w C:\WINNT\system32\wucltui.dll
2007-07-31 00:19 203,096 —-a-w C:\WINNT\system32\wuweb.dll
2007-07-31 00:19 1,712,984 —-a-w C:\WINNT\system32\wuaueng.dll
2007-07-31 00:18 33,624 —-a-w C:\WINNT\system32\wups.dll
2006-12-16 18:12 58,288 —-a-w C:\Documents and Settings\paula\Application Data\GDIPFONTCACHEV1.DAT
2006-12-14 14:15 56,912 —-a-w C:\Documents and Settings\paula\g2mdlhlpx.exe
2006-06-26 21:04 34,941 —-a-w C:\Program Files\uninstall.exe
2006-05-01 05:50 55,296 —-a-w C:\Program Files\fraps64.dll
2006-05-01 05:50 289,280 —-a-w C:\Program Files\fraps64.dat
2006-04-30 13:46 774,144 —-a-w C:\Program Files\fraps.exe
2006-04-30 13:45 114,688 —-a-w C:\Program Files\fraps.dll
2006-04-30 13:45 110,592 —-a-w C:\Program Files\frapslcd.dll
2006-04-30 10:07 10,006 —-a-w C:\Program Files\changes.txt
2006-04-27 06:49 1,859 —-a-w C:\Program Files\README.HTM
2004-10-20 00:55 1,994 —-a-w C:\Program Files\INSTALL.LOG
2004-07-02 05:18 271 —h–w C:\Program Files\desktop.ini
2004-07-02 05:18 21,952 —h–w C:\Program Files\folder.htt
2002-07-24 12:00 32,528 —-a-w C:\WINNT\inf\wbfirdma.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 14:05 C:\WINNT\system32\mobsync.exe]
"VTPreset"="VTPreset.exe" [04-02-24 19:17 C:\WINNT\system32\VTPreset.exe]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [01-08-23 16:52 ]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [01-08-16 23:41 ]
"HPDJ Taskbar Utility"="C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb12.exe" [04-06-25 19:32 ]
"PCTVOICE"="pctspk.exe" [01-10-04 09:48 C:\WINNT\system32\pctspk.exe]
"NeroCheck"="C:\WINNT\system32\NeroCheck.exe" [01-07-09 04:50 ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [04-12-17 23:20 ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06-09-01 15:57 ]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [04-05-12 14:18 ]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [05-02-16 22:11 ]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [03-05-21 17:37 ]
"SSC_UserPrompt"="C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [04-11-02 15:59 ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06-04-14 08:42 ]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [05-06-06 22:46 ]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [07-06-28 12:51 ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [07-09-25 01:11 ]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [01-02-20 12:09 C:\WINNT\system32\CTFMON.EXE]
"DemaPostIt1.9.5"="C:\unzipped\pitlig197beta\PitLight.exe" [03-04-27 15:17 ]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [07-06-07 14:08 ]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [06-03-30 15:45 ]
"SAM"="C:\PROGRA~1\SAM\SAM.exe" []
"DS Clock"="C:\Program Files\DS Clock\dsclock.exe" [05-02-14 22:23 ]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop

C:\Documents and Settings\paula\Start Menu\Programs\Startup\
FastStone Capture.lnk - C:\Program Files\FastStone Capture\FSCapture.exe [2007-01-07 15:08:32]
Shortcut to backupdoc.bat.lnk - C:\batch\backupdoc.bat [2004-11-11 10:46:46]
TimeLeft.lnk - C:\Program Files\TimeLeft3\TimeLeft.exe [2006-12-28 17:49:24]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2004-11-16 13:09:40]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
PCANotify.dll 02-02-15 09:51 24638 C:\WINNT\system32\Pcanotify.dll

R0 SONYPVM1;Sony Memory Stick Driver(SONYPVM1);C:\WINNT\system32\DRIVERS\SONYPVM1.SYS
R2 SetupNT;SetupNT;C:\WINNT\system32\SetupNT.sys
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINNT\system32\DRIVERS\klim5.sys
R3 usbhub20;USB 2.0 Root Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINNT\system32\drivers\npf.sys
S3 viafilter;VIA USB Filter;C:\WINNT\system32\Drivers\viausb.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-26 18:15:01 C:\WINNT\Tasks\backupdoc.job"
"2007-06-26 15:20:07 C:\WINNT\Tasks\bakcup.job"
- C:\WINNT\system32\NTBACKUP.EXE
.
**************************************************************************

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-27 14:32:34
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-27 14:36:05
C:\ComboFix2.txt … 07-10-27 12:35
.
— E O F —
Kaspersky log - I am connected to a server and I noticed it scanned the server, also. Drive F:

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
2007-10-29 09:02
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/10/2007
Kaspersky Anti-Virus database records: 447203
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
P:\

Scan Statistics:
Total number of scanned objects: 136849
Number of viruses found: 6
Number of infected objects: 17
Number of suspicious objects: 0
Duration of the scan process: 02:55:35

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\detected.idx Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\detected.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\eventlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\report.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-10-27_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\paula\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\ApplicationHistory\hpqgalry.exe.f314eb97.ini.inuse Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\Microsoft\Outlook\mailbox.pst/Personal Folders/Inbox/10 Apr 2007 08:11 from Flagstar Bank:Flagstar Bank has assigned .eml Infected: Trojan-Spy.HTML.Flagfraud.a skipped
C:\Documents and Settings\paula\Local Settings\Application Data\Microsoft\Outlook\mailbox.pst Mail MS Mail: infected - 1 skipped
C:\Documents and Settings\paula\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\paula\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\paula\Local Settings\History\History.IE5\MSHist012007102720071028\index.dat Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Temp\hpotdd000.log Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Temp\hpqtra000.log Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Temp\~DF8C96.tmp Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Temp\~DF954D.tmp Object is locked skipped
C:\Documents and Settings\paula\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\paula\My Documents\My Pictures\eztMusicManager_24973834.exe/data0012 Infected: not-a-virus:AdWare.Win32.Eztracks.d skipped
C:\Documents and Settings\paula\My Documents\My Pictures\eztMusicManager_24973834.exe/data0019 Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
C:\Documents and Settings\paula\My Documents\My Pictures\eztMusicManager_24973834.exe NSIS: infected - 2 skipped
C:\Documents and Settings\paula\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\paula\ntuser.dat.LOG Object is locked skipped
C:\Program Files\3M\PSNLite\PSNData Object is locked skipped
C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped
C:\Program Files\Payroll\prdata\ASHLEY.PR0 Object is locked skipped
C:\WINNT\CSC000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\Netlogon.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Internet Logs\tvDebug.log Object is locked skipped
C:\WINNT\ModemLog_Intel® 537EP Modem.txt Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\Sti_Trace.log Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
C:\WINNT\system32\drivers\fidbox.dat Object is locked skipped
C:\WINNT\system32\drivers\fidbox.idx Object is locked skipped
C:\WINNT\system32\drivers\fidbox2.dat Object is locked skipped
C:\WINNT\system32\drivers\fidbox2.idx Object is locked skipped
C:\WINNT\system32\Perflib_Perfdata_378.dat Object is locked skipped
C:\WINNT\TEMP\Cookies\index.dat Object is locked skipped
C:\WINNT\TEMP\History\History.IE5\index.dat Object is locked skipped
C:\WINNT\TEMP\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
F:\Paula's Backup\My Pictures\eztMusicManager_24973834.exe/data0012 Infected: not-a-virus:AdWare.Win32.Eztracks.d skipped
F:\Paula's Backup\My Pictures\eztMusicManager_24973834.exe/data0019 Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
F:\Paula's Backup\My Pictures\eztMusicManager_24973834.exe NSIS: infected - 2 skipped
F:\PestPatrolX\Quarantine\20041123162600.zip/WINDOWS/System32/lmf32.dll Infected: not-a-virus:AdWare.Win32.Suggestor.f skipped
F:\PestPatrolX\Quarantine\20041123162600.zip/WINDOWS/downloaded program files/SAHAgent_.exe Infected: not-a-virus:AdWare.Win32.Sahat.c skipped
F:\PestPatrolX\Quarantine\20041123162600.zip/WINDOWS/downloaded program files/SahHtml_.exe Infected: not-a-virus:AdWare.Win32.Sahat.c skipped
F:\PestPatrolX\Quarantine\20041123162600.zip/WINDOWS/system32/sahagent1019.exe/data0002 Infected: not-a-virus:AdWare.Win32.Sahat.a skipped
F:\PestPatrolX\Quarantine\20041123162600.zip/WINDOWS/system32/sahagent1019.exe Infected: not-a-virus:AdWare.Win32.Sahat.a skipped
F:\PestPatrolX\Quarantine\20041123162600.zip ZIP: infected - 5 skipped
F:\Profit\Data\Live\APOPNFIL.DAT Object is locked skipped
F:\Profit\Data\Live\APVENFIL.DAT Object is locked skipped
F:\Profit\Data\Live\APXCHFIL.DAT Object is locked skipped
F:\Profit\Data\Live\ARCSHAPL.DAT Object is locked skipped
F:\Profit\Data\Live\ARCSHDIS.DAT Object is locked skipped
F:\Profit\Data\Live\ARCSHDRW.DAT Object is locked skipped
F:\Profit\Data\Live\ARCSHTRX.DAT Object is locked skipped
F:\Profit\Data\Live\ARCUSFIL.DAT Object is locked skipped
F:\Profit\Data\Live\ARCUSTYP.DAT Object is locked skipped
F:\Profit\Data\Live\ARHISFIL.DAT Object is locked skipped
F:\Profit\Data\Live\ARINSCOD.DAT Object is locked skipped
F:\Profit\Data\Live\aropnfil.dat Object is locked skipped
F:\Profit\Data\Live\ARSHPCOD.DAT Object is locked skipped
F:\Profit\Data\Live\ARSLMFIL.DAT Object is locked skipped
F:\Profit\Data\Live\ARTAXCOD.DAT Object is locked skipped
F:\Profit\Data\Live\ARTERMS.DAT Object is locked skipped
F:\Profit\Data\Live\GLCOAFIL.DAT Object is locked skipped
F:\Profit\Data\Live\GLMASTER.DAT Object is locked skipped
F:\Profit\Data\Live\INBLDCOD.DAT Object is locked skipped
F:\Profit\Data\Live\INBOMFIL.DAT Object is locked skipped
F:\Profit\Data\Live\INCATCOD.DAT Object is locked skipped
F:\Profit\Data\Live\INCOMCOD.DAT Object is locked skipped
F:\Profit\Data\Live\INDESCOD.DAT Object is locked skipped
F:\Profit\Data\Live\INITMFIL.DAT Object is locked skipped
F:\Profit\Data\Live\INLEASED.DAT Object is locked skipped
F:\Profit\Data\Live\INLOCFIL.DAT Object is locked skipped
F:\Profit\Data\Live\INMKDCOD.DAT Object is locked skipped
F:\Profit\Data\Live\INMTOFIL.DAT Object is locked skipped
F:\Profit\Data\Live\INOPTFIL.DAT Object is locked skipped
F:\Profit\Data\Live\INOPTHIS.DAT Object is locked skipped
F:\Profit\Data\Live\INRECTBL.DAT Object is locked skipped
F:\Profit\Data\Live\INRECTRX.DAT Object is locked skipped
F:\Profit\Data\Live\INSTYLES.DAT Object is locked skipped
F:\Profit\Data\Live\POBUYERS.DAT Object is locked skipped
F:\Profit\Data\Live\PODTLFIL.DAT Object is locked skipped
F:\Profit\Data\Live\PODTLTRX.DAT Object is locked skipped
F:\Profit\Data\Live\POHDRFIL.DAT Object is locked skipped
F:\Profit\Data\Live\POHDRTRX.DAT Object is locked skipped
F:\Profit\Data\Live\PSPFTCTR.DAT Object is locked skipped
F:\Profit\Data\Live\PSPRTFIL.DAT Object is locked skipped
F:\Profit\Data\Live\PSREMARK.DAT Object is locked skipped
F:\Profit\Data\Live\PSSYSCHK.DAT Object is locked skipped
F:\Profit\Data\Live\PSUSRFIL.DAT Object is locked skipped
F:\Profit\Data\Live\SODISFIL.DAT Object is locked skipped
F:\Profit\Data\Live\SODTLFIL.DAT Object is locked skipped
F:\Profit\Data\Live\SOHDRFIL.DAT Object is locked skipped
F:\Profit\Data\Live\SOSALFIL.DAT Object is locked skipped
F:\Profit\Data\Live\SOSHIPTO.DAT Object is locked skipped
F:\Profit\Data\Live\SOSLSHIS.DAT Object is locked skipped
F:\Profit\Data\Live\SOWRITTN.DAT Object is locked skipped
F:\PVSW\Bin\MKDE\LOG002A5A.LOG Object is locked skipped
F:\PVSW\Bin\MKDE\LOG\LAST_SEG.LOG Object is locked skipped
P:\My Pictures\eztMusicManager_24973834.exe/data0012 Infected: not-a-virus:AdWare.Win32.Eztracks.d skipped
P:\My Pictures\eztMusicManager_24973834.exe/data0019 Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
P:\My Pictures\eztMusicManager_24973834.exe NSIS: infected - 2 skipped

Scan process completed.

Hijack this Log

Logfile of HijackThis v1.99.1
Scan saved at 09:10, on 2007-10-29
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
c:\program files\cisco systems\vpn client\cvpnd.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\DS Clock\dsclock.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\TimeLeft3\TimeLeft.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\paula\My Documents\Downloads\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: (no name) - {7426C76D-0ADC-0A2C-F4E4-05D58C76ECBB} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.netscape.com/"); (C:\Documents and Settings\paula\Application Data\Mozilla\Profiles\default\85wxnc1c.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\paula\Application Data\Mozilla\Profiles\default\85wxnc1c.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [DemaPostIt1.9.5] "C:\unzipped\pitlig197beta\PitLight.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [SAM] C:\PROGRA~1\SAM\SAM.exe
O4 - HKCU\..\Run: [DS Clock] "C:\Program Files\DS Clock\dsclock.exe"
O4 - Startup: FastStone Capture.lnk = C:\Program Files\FastStone Capture\FSCapture.exe
O4 - Startup: Shortcut to backupdoc.bat.lnk = C:\batch\backupdoc.bat
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Ashley Furniture VPN Client 4.6.0.lnk = C:\Program Files\cisco systems\vpn client\vpngui.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: StumbleUpon: &Blog; This - res://StumbleUponIEBar.dll/blogimage
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod4\v6\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod4\v6\yhexbmes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O15 - Trusted Zone: *.stumbleupon.com
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Installer) - http://supportcenter.adelphia.net/sdccommo…ad/tgctlins.cab
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {0348CD18-6EFE-415B-AF32-58F08FA29B33} (WCSAXrview Control) - http://eaglecams.ginncompany.com:8081/wcsarview.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://www.fasturnonline.com/DFSWeb/smsx.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://www.discoveryvillage.net/marshcam/kxhcm10.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsr.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/19.11/uploader2.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/1444be6e5e29fb…ip/RdxIE601.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {65F31DBD-290F-44F8-9B18-47F5AE400A04} (RAS_Watch Control) - http://www.gould.edu.au/wildlifecams/RasWatch.cab
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} (PlayerOCX Control) - http://www.pysoft.com/Downloads/WebCamPlayerOCX.cab
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://69.54.28.120//activex/AMC.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://128.128.32.108/activex/AxisCamControl.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4056/ftp…02/cpbrkpie.cab
O16 - DPF: {A0EAC162-A012-4AD8-B2E1-D5A0BBBCDA51} (PopupSh Control) - http://209.190.5.106/display/PopupSh.ocx
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://nywild4.dyndns.org/plugin/h263ctrl.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://67.86.143.68:81/activex/AMC.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup163.cab
O16 - DPF: {EAA105FE-7BBD-4196-8B96-D46743894195} (MjpegControl Class) - http://69.34.225.3/plugin/mjpegcontrol.cab
O16 - DPF: {FFFFFFFF-CAFE-BABE-BABE-00AA0055595A} - http://www.networksolutionsemailpopwizard….rueSwitchEC.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = routzahn.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = routzahn.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = routzahn.local
O20 - Winlogon Notify: klogon - C:\WINNT\system32\klogon.dll
O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\program files\cisco systems\vpn client\cvpnd.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINNT\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINNT\system32\hpboid.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

I haven't had any pop up ads, computer seems to be running good :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI