This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]  I really need help

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Click on reply, and look for the "UPLOAD" button in the lower right corner or post it over several posts depending on the length. (If you decide to use several posts, make sure that all the entries are present, i-e, that one starts off where the previous one ended. Trevuren
can i emial it to you? if not i will start posting. its 3.5 mb adn 1080 pages long. thanks. let me know i am happy to do either. if you need me ot post it how many pages do you think i can put in a post?
Hey Dan,

That is not very practical under the circumstances. Please do the fllowing instead:


A. Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.

B. Reboot into Safe Mode


How to use the F8 method to Start Your Computer in Safe Mode*Restart the computer.
*as soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
*Use the arrow keys to select the Safe mode menu item
*press Enter.
C. Double-click SUPERAntiSpyware.exe to start the tool again
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply along with a fresh HJT log.
  • Click Close to exit the program.
ok thanks. things are really looking up here!
i am goign to still update java just havent got around to it as that scan took almsot 6 hours.
thanks

heres the scan log
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/28/2007 at 05:34 PM

Application Version : 3.9.1008

Core Rules Database Version : 3332
Trace Rules Database Version: 1333

Scan type : Complete Scan
Total Scan Time : 05:52:40

Memory items scanned : 183
Memory threats detected : 0
Registry items scanned : 6247
Registry threats detected : 0
File items scanned : 75405
File threats detected : 248

Adware.Tracking Cookie
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@nextag[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@focalex[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@primediamags[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\[removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@atwola[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@advertising[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@html[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@ford.112.2o7[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@revenue[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@regalinteractive[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@adknowledge[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@azjmp[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@89178482[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@cgi-bin[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@adtech[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@trafficmp[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@cgi-bin[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@edge.ru4[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@43682891[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@qnsr[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@msnportal.112.2o7[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@tribalfusion[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@superstats[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@m1.webstats4u[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@estat[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@belnk[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@admarketplace[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@cnetaustralia.122.2o7[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@clicktorrent[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@atdmt[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan_nelson@2o7[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@usenext[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@microsofteup.112.2o7[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@maxserving[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@34419056[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@webstat[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@tacoda[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@please[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@overture[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@adlegend[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@mediaonenetwork[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@serving-sys[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@ad[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@specificclick[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@revsci[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@advertisingcom.122.2o7[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@login.tracking101[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@realmedia[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@questionmarket[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@1063815052[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@highbeam.122.2o7[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@mb[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@kanoodle[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@1071905283[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@bizrate[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@partner2profit[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@oasc02.247realmedia[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@indextools[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@powellsbooks.122.2o7[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@interclick[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@cgi-bin[5].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed]-sys[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@1071739099[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@44153975[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@67428397[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@epson.112.2o7[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@76226072[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@169841[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@www.0stats[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@pbteen[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@cgi-bin[3].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@adinterax[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@tripod[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan_nelson@hitbox[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@clickability[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@pro-market[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@67.15.239[3].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@43836137[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@82475223[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@mb[3].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@stats[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@1066622017[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@adbrite[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@list[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@247realmedia[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@9758056[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@1069856265[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@yadro[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@cgi-bin[4].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@serialz[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@turnersports.112.2o7[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@rambler[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\[removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@roiservice[1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@bestsellerantivirus[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan [removed][1].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@67.15.239[2].txt
C:\Documents and Settings\Cindi Nelson.PC270429458147\Cookies\cindi nelson@2o7[2].txt
C:\Documents and Settings\Cindi Nelson.PC270429458147\Cookies\cindi nelson@atwola[2].txt
C:\Documents and Settings\Dan Nelson\Cookies\dan nelson@stats[1].txt
C:\Documents and Settings\Daniel Nelson\Cookies\daniel nelson@2o7[2].txt
C:\Documents and Settings\Daniel Nelson\Cookies\daniel [removed][1].txt
C:\Documents and Settings\Daniel Nelson\Cookies\daniel [removed][2].txt
C:\Documents and Settings\Daniel Nelson\Cookies\daniel nelson@atwola[1].txt
C:\Documents and Settings\Daniel Nelson\Cookies\daniel nelson@banner[1].txt
C:\Documents and Settings\Daniel Nelson\Cookies\daniel nelson@burstnet[1].txt
C:\Documents and Settings\Daniel Nelson\Cookies\daniel nelson@nextag[2].txt
C:\Documents and Settings\Emily\Cookies\dan nelson@2o7[2].txt
C:\Documents and Settings\Emily\Cookies\emily@2o7[1].txt
C:\Documents and Settings\Emily\Cookies\emily@67.15.239[1].txt
C:\Documents and Settings\Emily\Cookies\[removed][2].txt
C:\Documents and Settings\Emily\Cookies\[removed][2].txt
C:\Documents and Settings\Emily\Cookies\[removed][2].txt
C:\Documents and Settings\Emily\Cookies\[removed][2].txt
C:\Documents and Settings\Emily\Cookies\emily@adrevolver[1].txt
C:\Documents and Settings\Emily\Cookies\emily@adrevolver[2].txt
C:\Documents and Settings\Emily\Cookies\[removed][1].txt
C:\Documents and Settings\Emily\Cookies\[removed][1].txt
C:\Documents and Settings\Emily\Cookies\[removed][2].txt
C:\Documents and Settings\Emily\Cookies\[removed][2].txt
C:\Documents and Settings\Emily\Cookies\emily@advertising[1].txt
C:\Documents and Settings\Emily\Cookies\emily@alivemedia[1].txt
C:\Documents and Settings\Emily\Cookies\[removed][2].txt
C:\Documents and Settings\Emily\Cookies\[removed][2].txt
C:\Documents and Settings\Emily\Cookies\emily@atdmt[2].txt
C:\Documents and Settings\Emily\Cookies\emily@atwola[1].txt
C:\Documents and Settings\Emily\Cookies\emily@bluestreak[2].txt
C:\Documents and Settings\Emily\Cookies\[removed]-sys[1].txt
C:\Documents and Settings\Emily\Cookies\emily@burstnet[2].txt
C:\Documents and Settings\Emily\Cookies\emily@casalemedia[2].txt
C:\Documents and Settings\Emily\Cookies\[removed][1].txt
C:\Documents and Settings\Emily\Cookies\emily@clickhandbags[1].txt
C:\Documents and Settings\Emily\Cookies\emily@doubleclick[1].txt
C:\Documents and Settings\Emily\Cookies\emily@edge.ru4[1].txt
C:\Documents and Settings\Emily\Cookies\emily@fastclick[1].txt
C:\Documents and Settings\Emily\Cookies\emily@hitbox[2].txt
C:\Documents and Settings\Emily\Cookies\[removed][1].txt
C:\Documents and Settings\Emily\Cookies\emily@mediaplex[2].txt
C:\Documents and Settings\Emily\Cookies\emily@nextag[1].txt
C:\Documents and Settings\Emily\Cookies\emily@partner2profit[1].txt
C:\Documents and Settings\Emily\Cookies\[removed][1].txt
C:\Documents and Settings\Emily\Cookies\emily@pro-market[2].txt
C:\Documents and Settings\Emily\Cookies\emily@questionmarket[2].txt
C:\Documents and Settings\Emily\Cookies\emily@realmedia[2].txt
C:\Documents and Settings\Emily\Cookies\emily@revsci[1].txt
C:\Documents and Settings\Emily\Cookies\[removed][2].txt
C:\Documents and Settings\Emily\Cookies\[removed][1].txt
C:\Documents and Settings\Emily\Cookies\emily@serving-sys[1].txt
C:\Documents and Settings\Emily\Cookies\emily@smileycentral[1].txt
C:\Documents and Settings\Emily\Cookies\emily@stats.channel4[1].txt
C:\Documents and Settings\Emily\Cookies\emily@tacoda[2].txt
C:\Documents and Settings\Emily\Cookies\[removed][1].txt
C:\Documents and Settings\Emily\Cookies\emily@toseeka[2].txt
C:\Documents and Settings\Emily\Cookies\[removed][2].txt
C:\Documents and Settings\Emily\Cookies\emily@tradedoubler[1].txt
C:\Documents and Settings\Emily\Cookies\emily@trafficmp[1].txt
C:\Documents and Settings\Emily\Cookies\[removed][2].txt
C:\Documents and Settings\Emily\Cookies\emily@tribalfusion[1].txt
C:\Documents and Settings\Emily\Cookies\[removed][2].txt
C:\Documents and Settings\Emily\Cookies\[removed][1].txt
C:\Documents and Settings\Emily\Cookies\[removed][1].txt
C:\Documents and Settings\Emily\Cookies\emily@zedo[2].txt
C:\Documents and Settings\NetworkService\Cookies\dan nelson@2o7[2].txt
C:\Documents and Settings\NetworkService\Cookies\emily@2o7[1].txt

Trojan.Unknown Origin
C:\DOCUMENTS AND SETTINGS\DAN NELSON\DESKTOP\INSTALL.EXE

Adware.ClickSpring
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\DAN NELSON\APPLICATION DATA\WNSXS~1\DVDPLAY.EXE~.VIR

Adware.eZula
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\GXPTOYVT.EXE.VIR

Trojan.XPDX-Rootkit
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\XPDX.SYS.VIR

Adware.Vundo Variant
C:\VUNDOFIX BACKUPS\EFCDAXU.DLL.BAD

Adware.ClickSpring/Yazzle
C:\WINDOWS\PREFETCH\YAZZLE1162OINADMIN.EXE-04B49B8B.PF

and heres a new hjt log.
Logfile of HijackThis v1.99.1
Scan saved at 7:03:03 PM, on 10/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\AirPort\APAgent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\Common Files\AOL\1140899242\ee\AOLHostManager.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\AOL\1140899242\ee\AOLServiceHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1140899242\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [AirPort Base Station Agent] "C:\Program Files\AirPort\APAgent.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location Finder\LocationFinder.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 4.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {38F5F92F-BD40-40DF-A569-6C1FCB638190} (InSPECS3_0 Control) - http://www.powerleap.com/cab_files/InSPECS3_0.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

thanks agian
dan
Congratulations, your logs look CLEAN

There are a few things you must do once you system is completely clean:

Time for some housekeeping
  • DELETE all traces of WareOutFix from your machine.
  • Next, click START then RUN
  • Now type Combofix /u in the runbox and click OK

    • [external image: Posted Image]
  • When shown the disclaimer, Select "2"
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

Here are some tips to reduce the potential for spyware infection in the future:

1. Make sure you keep your Windows OS currentby visiting Windows update
regularly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.

2. I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
And also see TonyKlein's good advice
So how did I get infected in the first place?

Regards,

Trevuren
great!! thanks a ton!! so theres no viruses or anything anymore? thanks!! also when i try to download the java thing… it says bad instillation… not jre found in configuration file. dan
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.
Please describe your latest problem in minute detail with direct quotes of error messages if possible. The problems that I now see in your log appear to be totally different than the ones that we weredealing with before. Methinks Dan or someone using his computer visited a "bad" site.


Please download this file - combofix.exe by sUBs
  • You must download it to and run it from your Desktop
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

Regards,

Trevuren
hello and thx for the help agian.
ok heres the combo fix report
ComboFix 07-10-27.4 - Dan Nelson 2007-11-04 8:47:36.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ad-a war\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data.\dehwnaxq.dll
C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Startup\TA_Start.lnk
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\microsoft frontpage\rterter.html
C:\Program Files\network monitor
C:\Program Files\network monitor\netmon.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\RGFuIE5lbHNvbg\asappsrv.dll
C:\WINDOWS\RGFuIE5lbHNvbg\command.exe
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\.exe
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\bvgevqai
C:\WINDOWS\system32\bvgevqai\bg1.gif
C:\WINDOWS\system32\bvgevqai\bgtop.gif
C:\WINDOWS\system32\bvgevqai\bottom1.gif
C:\WINDOWS\system32\bvgevqai\bvgevqai1.exe
C:\WINDOWS\system32\bvgevqai\bvgevqai2.exe
C:\WINDOWS\system32\bvgevqai\bvgevqai3.exe
C:\WINDOWS\system32\bvgevqai\essentials.gif
C:\WINDOWS\system32\bvgevqai\icon1.ico
C:\WINDOWS\system32\bvgevqai\install1.gif
C:\WINDOWS\system32\bvgevqai\left1.gif
C:\WINDOWS\system32\bvgevqai\li.gif
C:\WINDOWS\system32\bvgevqai\logo.gif
C:\WINDOWS\system32\bvgevqai\main.htm
C:\WINDOWS\system32\bvgevqai\mainframe.htm
C:\WINDOWS\system32\bvgevqai\reinstall1.gif
C:\WINDOWS\system32\bvgevqai\right1.gif
C:\WINDOWS\system32\bvgevqai\s1.htm
C:\WINDOWS\system32\bvgevqai\s2.htm
C:\WINDOWS\system32\bvgevqai\s3.htm
C:\WINDOWS\system32\bvgevqai\SMTop1.gif
C:\WINDOWS\system32\bvgevqai\SMTop2.gif
C:\WINDOWS\system32\bvgevqai\SMTop3.gif
C:\WINDOWS\system32\bvgevqai\SMTop4.gif
C:\WINDOWS\system32\bvgevqai\soft1_off.gif
C:\WINDOWS\system32\bvgevqai\soft1_off_ext.gif
C:\WINDOWS\system32\bvgevqai\soft1_on.gif
C:\WINDOWS\system32\bvgevqai\soft1_on_ext.gif
C:\WINDOWS\system32\bvgevqai\soft2_off.gif
C:\WINDOWS\system32\bvgevqai\soft2_off_ext.gif
C:\WINDOWS\system32\bvgevqai\soft2_on.gif
C:\WINDOWS\system32\bvgevqai\soft2_on_ext.gif
C:\WINDOWS\system32\bvgevqai\soft3_off.gif
C:\WINDOWS\system32\bvgevqai\soft3_off_ext.gif
C:\WINDOWS\system32\bvgevqai\soft3_on.gif
C:\WINDOWS\system32\bvgevqai\soft3_on_ext.gif
C:\WINDOWS\system32\bvgevqai\softbottom_off.gif
C:\WINDOWS\system32\bvgevqai\softbottom_on.gif
C:\WINDOWS\system32\bvgevqai\softleft_off.gif
C:\WINDOWS\system32\bvgevqai\softleft_on.gif
C:\WINDOWS\system32\bvgevqai\top1.gif
C:\WINDOWS\system32\bvgevqai\top2.gif
C:\WINDOWS\system32\bvgevqai\turnoff1.gif
C:\WINDOWS\system32\bvgevqai\turnon1.gif
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\dobe~1\?hkntfs.exe
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\drvhapr.dll
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\iawl.dll
C:\WINDOWS\system32\ldcore.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\winrvc32.dll
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\system32\wnsapisv.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\wnsxs~1
C:\WINDOWS\wnsxs~1\msdtc.exe
C:\WINDOWS\wnsxs~1\W?nSxS\
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xpupdate.exe
C:\WINDOWS\xxxvideo.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\cmdService
——-\Network Monitor


((((((((((((((((((((((((( Files Created from 2007-10-04 to 2007-11-04 )))))))))))))))))))))))))))))))
.

2007-11-03 21:25 18,432 –a—— C:\WINDOWS\fkwggshm.exe
2007-11-03 21:22 d——– C:\Program Files\yhaxuxgh
2007-11-03 21:22 d——– C:\Program Files\Wjsltbcq
2007-11-03 21:22 36,864 –a—— C:\WINDOWS\system32\xxyywxx.dll
2007-11-03 21:21 104,960 –a—— C:\WINDOWS\system32\drvhap.dll
2007-11-03 21:09 4 –a—— C:\WINDOWS\system32\stfv.bin
2007-11-03 21:07 d——– C:\WINDOWS\system32\acespy
2007-11-03 21:07 16,640 –a—— C:\WINDOWS\system32\ace16win.dll
2007-10-30 19:23 12 –a—— C:\WINDOWS\system32\dpqaqlqx.bin
2007-10-30 19:22 d–hs—- C:\WINDOWS\RGFuIE5lbHNvbg
2007-10-30 19:22 123,908 –a—— C:\WINDOWS\system32\vvgeowbv.exe
2007-10-30 19:22 21,504 –a—— C:\WINDOWS\system32\aivskurq.dll
2007-10-28 19:14 d——– C:\Program Files\LBT
2007-10-28 10:29 d——– C:\Program Files\SUPERAntiSpyware
2007-10-28 10:29 d——– C:\Documents and Settings\Dan Nelson\Application Data\SUPERAntiSpyware.com
2007-10-28 10:29 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-26 22:13 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-10-26 22:13 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-26 18:20 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-26 11:46 4,528 –a—— C:\WINDOWS\system32\tmp.reg
2007-10-26 11:44 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-10-26 11:44 61,440 –a—— C:\WINDOWS\system32\Process.exe
2007-10-26 11:44 57,856 –a—— C:\WINDOWS\system32\dumphive.exe
2007-10-26 11:14 d——– C:\Program Files\Lavasoft
2007-10-26 11:14 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-26 11:12 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-25 19:37 d——– C:\VundoFix Backups
2007-10-09 13:17 584,192 ——— C:\WINDOWS\system32\dllcache\rpcrt4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-04 16:56 ——— d—–w C:\Program Files\microsoft frontpage
2007-10-27 02:36 ——— d—–w C:\Program Files\QuickTime
2007-10-27 02:35 ——— d—–w C:\Program Files\Microsoft Streets & Trips
2007-10-27 02:35 ——— d—–w C:\Program Files\Microsoft Location Finder
2007-10-27 02:34 ——— d—–w C:\Program Files\ICopyDVDs2(2)
2007-10-27 02:34 ——— d—–w C:\Program Files\Easy Internet signup
2007-10-27 02:32 ——— d—–w C:\Program Files\AIM
2007-10-26 20:17 ——— d—–w C:\Program Files\Microsoft Works
2007-10-26 19:13 ——— d—–w C:\Documents and Settings\Dan Nelson\Application Data\Lavasoft
2007-10-19 02:33 ——— d—–w C:\Program Files\AirPort
2007-10-16 00:49 ——— d—–w C:\Documents and Settings\Emily\Application Data\U3
2007-09-12 14:05 ——— d—–w C:\Program Files\iTunes
2007-09-12 14:05 ——— d—–w C:\Program Files\iPod
2007-09-12 14:01 ——— d—–w C:\Program Files\Common Files\Apple
2007-09-09 01:07 ——— d—–w C:\Program Files\Joost
2007-08-22 13:12 474,112 ——w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-08-22 13:12 151,040 ——w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-08-22 13:12 1,494,528 ——w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-08-22 13:12 1,054,208 ——w C:\WINDOWS\system32\dllcache\danim.dll
2007-08-22 13:12 1,022,976 ——w C:\WINDOWS\system32\dllcache\browseui.dll
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ——w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 10:04 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 6,058,496 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 10:04 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 10:04 477,696 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 10:04 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 10:04 3,584,512 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 10:04 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 631,808 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 70,144 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:20 20,480 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-08-14 01:54 413,696 —-a-w C:\WINDOWS\system32\vbscript.dll
2007-08-14 01:54 413,696 ——w C:\WINDOWS\system32\dllcache\vbscript.dll
2007-08-14 01:54 33,792 —-a-w C:\WINDOWS\system32\dllcache\custsat.dll
2007-08-14 01:54 191,488 —-a-w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-08-14 01:54 156,160 —-a-w C:\WINDOWS\system32\msls31.dll
2007-08-14 01:54 156,160 ——w C:\WINDOWS\system32\dllcache\msls31.dll
2007-08-14 01:45 78,336 —-a-w C:\WINDOWS\system32\ieencode.dll
2007-08-14 01:45 78,336 ——w C:\WINDOWS\system32\dllcache\ieencode.dll
2007-08-14 01:44 75,776 —-a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-08-14 01:44 40,960 —-a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-14 01:44 40,960 ——w C:\WINDOWS\system32\dllcache\licmgr10.dll
2007-08-14 01:42 17,408 —-a-w C:\WINDOWS\system32\corpol.dll
2007-08-14 01:42 17,408 ——w C:\WINDOWS\system32\dllcache\corpol.dll
2007-08-14 01:39 92,672 —-a-w C:\WINDOWS\system32\dllcache\inseng.dll
2007-08-14 01:39 71,680 —-a-w C:\WINDOWS\system32\admparse.dll
2007-08-14 01:39 71,680 ——w C:\WINDOWS\system32\dllcache\admparse.dll
2007-08-14 01:39 55,296 —-a-w C:\WINDOWS\system32\iesetup.dll
2007-08-14 01:39 55,296 ——w C:\WINDOWS\system32\dllcache\iesetup.dll
2007-08-14 01:38 491,520 —-a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-08-14 01:36 44,544 —-a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-08-14 01:36 36,352 —-a-w C:\WINDOWS\system32\imgutil.dll
2007-08-14 01:36 36,352 ——w C:\WINDOWS\system32\dllcache\imgutil.dll
2007-08-14 01:35 346,624 —-a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-08-14 01:32 52,224 —-a-w C:\WINDOWS\system32\mshta.exe
2007-08-14 01:32 52,224 ——w C:\WINDOWS\system32\dllcache\mshta.exe
2007-08-14 01:18 60,416 ——w C:\WINDOWS\system32\dllcache\hmmapi.dll
2007-08-14 01:01 48,128 —-a-w C:\WINDOWS\system32\mshtmler.dll
2007-08-14 01:01 48,128 ——w C:\WINDOWS\system32\dllcache\mshtmler.dll
2005-07-29 23:24:26 472 –sha-r C:\WINDOWS\RGFuIE5lbHNvbg\l3IRKHc5vJhSv0.vbs
.

((((((((((((((((((((((((((((( snapshot@2007-10-26_19.58.04.93 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-07-12 23:28:55 765,952 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\SP2QFE\vgx.dll
+ 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\updspapi.dll
+ 2007-08-20 10:02:09 124,928 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\advpack.dll
+ 2007-08-20 10:02:11 214,528 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\dxtrans.dll
+ 2007-08-20 10:02:09 132,608 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\extmgr.dll
+ 2007-08-20 10:02:09 63,488 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\icardie.dll
+ 2007-08-17 10:12:34 77,312 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ie4uinit.exe
+ 2007-08-20 10:02:09 153,088 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieakeng.dll
+ 2007-08-20 10:02:09 230,400 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieaksie.dll
+ 2007-08-17 07:29:55 161,792 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:24:57 2,455,488 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieapfltr.dat
+ 2007-08-20 10:02:09 383,488 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieapfltr.dll
+ 2007-08-20 10:02:09 387,584 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iedkcs32.dll
+ 2007-08-20 10:02:10 6,066,176 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieframe.dll
+ 2007-08-20 10:02:10 44,544 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iernonce.dll
+ 2007-08-20 10:02:10 267,776 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iertutil.dll
+ 2007-08-17 10:12:35 20,480 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieudinit.exe
+ 2007-08-17 10:12:49 631,808 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
+ 2007-08-20 10:02:10 27,648 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\jsproxy.dll
+ 2007-08-20 10:02:10 459,264 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\msfeeds.dll
+ 2007-08-20 10:02:10 52,224 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\msfeedsbs.dll
+ 2007-08-20 10:02:11 3,592,192 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\mshtml.dll
+ 2007-08-20 10:02:11 478,208 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\mshtmled.dll
+ 2007-08-20 10:02:11 193,024 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\msrating.dll
+ 2007-08-20 10:02:11 671,232 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\mstime.dll
+ 2007-08-20 10:02:11 102,400 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\occache.dll
+ 2007-08-20 10:02:11 105,984 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\url.dll
+ 2007-08-20 10:02:11 1,161,728 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\urlmon.dll
+ 2007-08-20 10:02:11 232,960 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\webcheck.dll
+ 2007-08-20 10:02:11 825,344 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\update\updspapi.dll
- 2007-10-26 16:51:17 145,920 —-a-w C:\WINDOWS\catchme.exe
+ 2007-10-26 17:51:17 136,192 —-a-w C:\WINDOWS\catchme.exe
- 2007-03-13 17:57:10 163,328 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2007-03-13 18:57:10 163,328 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2004-08-04 08:00:00 61,440 -c–a-w C:\WINDOWS\ie7\admparse.dll
+ 2004-08-04 08:00:00 99,840 -c–a-w C:\WINDOWS\ie7\advpack.dll
+ 2004-08-04 08:00:00 35,328 -c–a-w C:\WINDOWS\ie7\corpol.dll
+ 2004-08-11 08:45:04 28,672 -c–a-w C:\WINDOWS\ie7\custsat.dll
+ 2007-08-22 13:12:16 357,888 -c–a-w C:\WINDOWS\ie7\dxtmsft.dll
+ 2007-08-22 13:12:16 205,312 -c–a-w C:\WINDOWS\ie7\dxtrans.dll
+ 2007-08-22 13:12:16 55,808 -c–a-w C:\WINDOWS\ie7\extmgr.dll
+ 2004-08-04 08:00:00 40,960 -c–a-w C:\WINDOWS\ie7\ie4uinit.exe
+ 2004-08-04 08:00:00 139,264 -c–a-w C:\WINDOWS\ie7\ieakeng.dll
+ 2004-08-04 08:00:00 216,576 -c–a-w C:\WINDOWS\ie7\ieaksie.dll
+ 2004-08-04 08:00:00 221,184 -c–a-w C:\WINDOWS\ie7\ieakui.dll
+ 2004-08-04 08:00:00 323,584 -c–a-w C:\WINDOWS\ie7\iedkcs32.dll
+ 2007-08-21 10:30:45 25,088 -c–a-w C:\WINDOWS\ie7\iedw.exe
+ 2004-08-04 08:00:00 81,920 -c–a-w C:\WINDOWS\ie7\ieencode.dll
+ 2007-08-22 13:12:16 251,392 -c–a-w C:\WINDOWS\ie7\iepeers.dll
+ 2004-08-04 08:00:00 48,640 -c–a-w C:\WINDOWS\ie7\iernonce.dll
+ 2004-08-04 08:00:00 62,976 -c–a-w C:\WINDOWS\ie7\iesetup.dll
+ 2004-08-04 08:00:00 35,840 -c–a-w C:\WINDOWS\ie7\imgutil.dll
+ 2007-08-22 13:12:16 96,256 -c–a-w C:\WINDOWS\ie7\inseng.dll
+ 2006-05-18 05:24:25 450,560 -c–a-w C:\WINDOWS\ie7\jscript.dll
+ 2007-08-22 13:12:16 16,384 -c–a-w C:\WINDOWS\ie7\jsproxy.dll
+ 2004-08-04 08:00:00 22,016 -c–a-w C:\WINDOWS\ie7\licmgr10.dll
+ 2004-08-04 08:00:00 35,840 -c–a-w C:\WINDOWS\ie7\mshta.exe
+ 2007-08-22 13:12:17 3,058,176 -c–a-w C:\WINDOWS\ie7\mshtml.dll
+ 2007-08-22 13:12:17 449,024 -c–a-w C:\WINDOWS\ie7\mshtmled.dll
+ 2004-08-04 08:00:00 56,832 -c–a-w C:\WINDOWS\ie7\mshtmler.dll
+ 2004-08-04 08:00:00 146,432 -c–a-w C:\WINDOWS\ie7\msls31.dll
+ 2007-08-22 13:12:17 146,432 -c–a-w C:\WINDOWS\ie7\msrating.dll
+ 2007-08-22 13:12:17 532,480 -c–a-w C:\WINDOWS\ie7\mstime.dll
+ 2004-08-04 08:00:00 96,256 -c–a-w C:\WINDOWS\ie7\occache.dll
+ 2007-08-22 13:12:17 39,424 -c–a-w C:\WINDOWS\ie7\pngfilt.dll
+ 2007-08-14 01:54:42 32,960 -c–a-w C:\WINDOWS\ie7\spuninst\iecustom.dll
+ 2007-08-14 01:52:06 72,704 -c–a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
+ 2006-09-07 00:43:16 213,216 -c–a-w C:\WINDOWS\ie7\spuninst\spuninst.exe
+ 2006-09-07 00:43:18 371,424 -c–a-w C:\WINDOWS\ie7\spuninst\updspapi.dll
+ 2004-08-04 08:00:00 37,888 -c–a-w C:\WINDOWS\ie7\url.dll
+ 2007-08-22 13:12:18 615,424 -c–a-w C:\WINDOWS\ie7\urlmon.dll
+ 2004-08-04 08:00:00 417,792 -c–a-w C:\WINDOWS\ie7\vbscript.dll
+ 2007-06-26 15:13:22 851,968 -c–a-w C:\WINDOWS\ie7\vgx.dll
+ 2004-08-04 08:00:00 276,480 -c–a-w C:\WINDOWS\ie7\webcheck.dll
+ 2007-08-22 13:12:18 658,944 -c–a-w C:\WINDOWS\ie7\wininet.dll
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
+ 2007-08-14 01:54:10 765,952 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
+ 2007-08-14 01:39:00 123,904 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\advpack.dll
+ 2007-08-14 01:35:38 214,528 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\dxtrans.dll
+ 2007-08-14 01:54:10 131,584 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\extmgr.dll
+ 2007-08-14 01:36:26 61,952 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\icardie.dll
+ 2007-08-14 01:39:06 61,440 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ie4uinit.exe
+ 2007-08-14 01:39:06 61,440 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ie4uinit.exe.000
+ 2007-08-14 01:39:26 152,064 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieakeng.dll
+ 2007-08-14 01:39:54 229,376 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieaksie.dll
+ 2007-08-14 00:56:54 161,792 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieakui.dll
+ 2007-02-12 23:10:12 2,451,312 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieapfltr.dat
+ 2007-07-11 19:27:48 383,488 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieapfltr.dll
+ 2007-08-14 01:39:50 382,976 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iedkcs32.dll
+ 2007-08-14 01:54:10 6,049,280 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieframe.dll
+ 2007-08-14 01:39:10 43,008 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iernonce.dll
+ 2007-08-14 01:34:04 266,752 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iertutil.dll
+ 2007-08-14 01:39:10 19,968 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieudinit.exe
+ 2007-08-14 01:43:56 628,736 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
+ 2007-08-14 01:43:56 628,736 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe.000
+ 2007-08-14 01:54:10 27,136 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\jsproxy.dll
+ 2007-08-14 01:54:10 458,752 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msfeeds.dll
+ 2007-08-14 01:54:10 50,688 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msfeedsbs.dll
+ 2007-08-14 01:54:12 3,578,368 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtml.dll
+ 2007-08-14 01:54:10 475,648 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtmled.dll
+ 2007-08-14 01:44:26 192,000 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msrating.dll
+ 2007-08-14 01:54:10 670,720 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mstime.dll
+ 2007-08-14 01:44:06 101,376 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\occache.dll
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\updspapi.dll
+ 2007-08-14 01:44:30 105,984 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\url.dll
+ 2007-08-14 01:54:10 1,162,240 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\urlmon.dll
+ 2007-08-14 01:54:10 231,424 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\webcheck.dll
+ 2007-08-14 01:54:10 818,688 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\wininet.dll
+ 2007-10-28 18:29:07 36,352 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
+ 2007-10-28 18:29:07 25,600 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2007-10-28 18:29:07 71,680 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2007-11-04 05:07:56 25,344 —-a-w C:\WINDOWS\system32\acespy\systune.exe
- 2004-08-04 08:00:00 99,840 —-a-w C:\WINDOWS\system32\advpack.dll
+ 2007-08-20 10:04:34 124,928 —-a-w C:\WINDOWS\system32\advpack.dll
- 2005-04-01 10:02:36 360,448 —-a-w C:\WINDOWS\system32\ati2evxx.exe
+ 2005-04-01 10:02:36 368,640 —-a-w C:\WINDOWS\system32\ati2evxx.exe
- 2007-10-27 02:49:41 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-11-04 16:59:26 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-10-27 02:49:41 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-04 16:59:26 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-10-27 02:49:41 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-04 16:59:26 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-04-17 09:32:38 2,455,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dat
- 2007-06-26 15:13:22 851,968 ——w C:\WINDOWS\system32\dllcache\vgx.dll
+ 2007-07-12 23:31:54 765,952 —-a-w C:\WINDOWS\system32\dllcache\vgx.dll
- 2007-08-22 13:12:16 357,888 —-a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2007-08-14 01:35:46 346,624 —-a-w C:\WINDOWS\system32\dxtmsft.dll
- 2007-08-22 13:12:16 205,312 —-a-w C:\WINDOWS\system32\dxtrans.dll
+ 2007-08-20 10:04:34 214,528 —-a-w C:\WINDOWS\system32\dxtrans.dll
- 2007-08-22 13:12:16 55,808 —-a-w C:\WINDOWS\system32\extmgr.dll
+ 2007-08-20 10:04:34 132,608 —-a-w C:\WINDOWS\system32\extmgr.dll
+ 2007-08-20 10:04:34 63,488 —-a-w C:\WINDOWS\system32\icardie.dll
+ 2006-06-29 15:05:44 26,112 ——w C:\WINDOWS\system32\idndl.dll
- 2004-08-04 08:00:00 40,960 —-a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2007-08-17 10:20:54 70,144 —-a-w C:\WINDOWS\system32\ie4uinit.exe
- 2004-08-04 08:00:00 139,264 —-a-w C:\WINDOWS\system32\ieakeng.dll
+ 2007-08-20 10:04:34 153,088 —-a-w C:\WINDOWS\system32\ieakeng.dll
- 2004-08-04 08:00:00 216,576 —-a-w C:\WINDOWS\system32\ieaksie.dll
+ 2007-08-20 10:04:35 230,400 —-a-w C:\WINDOWS\system32\ieaksie.dll
- 2004-08-04 08:00:00 221,184 —-a-w C:\WINDOWS\system32\ieakui.dll
+ 2007-08-17 07:34:25 161,792 —-a-w C:\WINDOWS\system32\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 —-a-w C:\WINDOWS\system32\ieapfltr.dat
+ 2007-08-20 10:04:35 383,488 —-a-w C:\WINDOWS\system32\ieapfltr.dll
- 2004-08-04 08:00:00 323,584 —-a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2007-08-20 10:04:35 384,512 —-a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2007-08-20 10:04:37 6,058,496 —-a-w C:\WINDOWS\system32\ieframe.dll
- 2007-08-22 13:12:16 251,392 —-a-w C:\WINDOWS\system32\iepeers.dll
+ 2007-08-14 01:54:10 191,488 —-a-w C:\WINDOWS\system32\iepeers.dll
- 2004-08-04 08:00:00 48,640 —-a-w C:\WINDOWS\system32\iernonce.dll
+ 2007-08-20 10:04:38 44,544 —-a-w C:\WINDOWS\system32\iernonce.dll
+ 2007-08-20 10:04:38 267,776 —-a-w C:\WINDOWS\system32\iertutil.dll
+ 2007-08-17 10:20:54 20,480 —-a-w C:\WINDOWS\system32\ieudinit.exe
+ 2007-08-14 01:54:10 180,736 ——w C:\WINDOWS\system32\ieui.dll
- 2007-08-22 13:12:16 96,256 —-a-w C:\WINDOWS\system32\inseng.dll
+ 2007-08-14 01:39:02 92,672 —-a-w C:\WINDOWS\system32\inseng.dll
- 2006-05-18 05:24:25 450,560 —-a-w C:\WINDOWS\system32\jscript.dll
+ 2007-08-14 01:38:04 491,520 —-a-w C:\WINDOWS\system32\jscript.dll
- 2007-08-22 13:12:16 16,384 —-a-w C:\WINDOWS\system32\jsproxy.dll
+ 2007-08-20 10:04:39 27,648 —-a-w C:\WINDOWS\system32\jsproxy.dll
+ 2005-05-24 19:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 22:47:20 102,400 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 22:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2007-08-20 10:04:39 459,264 —-a-w C:\WINDOWS\system32\msfeeds.dll
+ 2007-08-20 10:04:39 52,224 —-a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2007-08-14 01:36:40 18,944 ——w C:\WINDOWS\system32\msfeedssync.exe
- 2007-08-22 13:12:17 3,058,176 —-a-w C:\WINDOWS\system32\mshtml.dll
+ 2007-08-20 10:04:41 3,584,512 —-a-w C:\WINDOWS\system32\mshtml.dll
- 2007-08-22 13:12:17 449,024 —-a-w C:\WINDOWS\system32\mshtmled.dll
+ 2007-08-20 10:04:41 477,696 —-a-w C:\WINDOWS\system32\mshtmled.dll
- 2007-08-22 13:12:17 146,432 —-a-w C:\WINDOWS\system32\msrating.dll
+ 2007-08-20 10:04:41 193,024 —-a-w C:\WINDOWS\system32\msrating.dll
- 2007-08-22 13:12:17 532,480 —-a-w C:\WINDOWS\system32\mstime.dll
+ 2007-08-20 10:04:42 671,232 —-a-w C:\WINDOWS\system32\mstime.dll
+ 2006-06-29 00:59:26 24,576 ——w C:\WINDOWS\system32\nlsdl.dll
+ 2006-06-29 15:05:44 23,552 ——w C:\WINDOWS\system32\normaliz.dll
- 2004-08-04 08:00:00 96,256 —-a-w C:\WINDOWS\system32\occache.dll
+ 2007-08-20 10:04:42 102,400 —-a-w C:\WINDOWS\system32\occache.dll
- 2007-03-28 23:24:03 54,010 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-11-04 16:38:52 54,010 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2007-03-28 23:24:03 383,822 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-04 16:38:53 383,822 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2007-08-22 13:12:17 39,424 —-a-w C:\WINDOWS\system32\pngfilt.dll
+ 2007-08-14 01:36:12 44,544 —-a-w C:\WINDOWS\system32\pngfilt.dll
- 2005-10-12 23:12:25 14,048 —-a-w C:\WINDOWS\system32\spmsg.dll
+ 2007-03-06 01:22:36 14,048 ——w C:\WINDOWS\system32\spmsg.dll
- 2005-06-10 23:53:32 57,856 —-a-w C:\WINDOWS\system32\spoolsv.exe
+ 2005-06-10 23:53:32 64,512 —-a-w C:\WINDOWS\system32\spoolsv.exe
- 2005-06-28 17:21:34 22,752 —-a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2006-09-07 00:43:16 22,752 —-a-w C:\WINDOWS\system32\spupdsvc.exe
- 2007-07-23 01:39:27 289,280 —-a-w C:\WINDOWS\system32\swreg.exe
+ 2007-07-23 02:39:27 279,552 —-a-w C:\WINDOWS\system32\swreg.exe
- 2004-08-04 08:00:00 37,888 —-a-w C:\WINDOWS\system32\url.dll
+ 2007-08-20 10:04:42 105,984 —-a-w C:\WINDOWS\system32\url.dll
- 2007-08-22 13:12:18 615,424 —-a-w C:\WINDOWS\system32\urlmon.dll
+ 2007-08-20 10:04:42 1,152,000 —-a-w C:\WINDOWS\system32\urlmon.dll
- 2004-08-04 08:00:00 218,112 —-a-w C:\WINDOWS\system32\wbem\wmiprvse.exe
+ 2004-08-04 08:00:00 224,768 —-a-w C:\WINDOWS\system32\wbem\wmiprvse.exe
- 2005-01-28 21:44:28 38,912 —-a-w C:\WINDOWS\system32\wdfmgr.exe
+ 2005-01-28 21:44:28 45,568 —-a-w C:\WINDOWS\system32\wdfmgr.exe
- 2004-08-04 08:00:00 49,152 —-a-w C:\WINDOWS\system32\wdigest.dll
+ 2006-03-24 04:37:50 49,152 —-a-w C:\WINDOWS\system32\wdigest.dll
- 2004-08-04 08:00:00 276,480 —-a-w C:\WINDOWS\system32\webcheck.dll
+ 2007-08-20 10:04:42 232,960 —-a-w C:\WINDOWS\system32\webcheck.dll
+ 2007-08-14 01:45:16 212,992 ——w C:\WINDOWS\system32\WinFXDocObj.exe
- 2007-08-22 13:12:18 658,944 —-a-w C:\WINDOWS\system32\wininet.dll
+ 2007-08-20 10:04:43 824,832 —-a-w C:\WINDOWS\system32\wininet.dll
+ 2006-07-14 15:51:51 121,856 ——w C:\WINDOWS\system32\xmllite.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{391B174C-A6B7-C9D7-6743-01F7A0D663D6}]
2007-11-03 21:22 106496 –a—— C:\Program Files\Wjsltbcq\bgskgnpz.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{57F0A11D-9DE0-43A3-91FD-4DFCAEB67BB8}]
2007-08-02 05:43 282624 –a—— C:\Program Files\MSN\mezokepow555077.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{89032A20-4370-487E-AB80-2251EC374249}]
2007-11-03 21:22 36864 –a—— C:\WINDOWS\system32\xxyywxx.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6E432B4-D4C2-43B3-BF55-C364F8F7362A}]
2007-10-30 19:22 21504 –a—— C:\WINDOWS\system32\aivskurq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 20:05]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 02:36]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-11 14:21]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 04:12]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 04:11]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 12:24]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 12:54]
"EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2005-02-07 11:00]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2006-01-06 11:07]
"HPHmon04"="C:\WINDOWS\system32\hphmon04.exe" [2006-01-06 11:07]
"HPHUPD04"="C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" []
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40]
"HostManager"="C:\Program Files\Common Files\AOL\1140899242\ee\AOLHostManager.exe" [2005-08-02 11:33]
"AIMPro"="C:\Program Files\AIM\AIM Pro\aimpro.exe" []
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 06:55]
"AirPort Base Station Agent"="C:\Program Files\AirPort\APAgent.exe" [2007-07-11 15:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-07 15:55]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24]
"{17-75-5B-BE-ZN}"="C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe" [2007-10-30 19:21]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24]
"Microsoft Location Finder"="C:\Program Files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 18:25]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-07-31 10:45]
"Nero PhotoShow Media Manager"="C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [2006-05-10 11:52]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-14 12:13]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:00]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 13:06]
"Tbsa"="C:\WINDOWS\WNSXS~1\msdtc.exe" []
"Kjwfty"="C:\WINDOWS\system32\?dobe\?hkntfs.exe" []

C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Startup\
TA_Start.lnk - C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe [2007-10-30 19:21:41]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
"{89032A20-4370-487E-AB80-2251EC374249}"= C:\WINDOWS\system32\xxyywxx.dll [2007-11-03 21:22 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyywxx]
xxyywxx.dll 2007-11-03 21:22 36864 C:\WINDOWS\system32\xxyywxx.dll


.
Contents of the 'Scheduled Tasks' folder
"2007-10-20 19:41:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-10-27 16:08:24 C:\WINDOWS\Tasks\Symantec NetDetect.job"
.
**************************************************************************

catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-04 09:01:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\system32\msnav32.ax 17 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2007-11-04 9:07:03 - machine was rebooted
C:\ComboFix2.txt … 2007-10-26 20:37
C:\ComboFix3.txt … 2007-10-26 19:00
.
— E O F —



heres the hjt report
Logfile of HijackThis v1.99.1
Scan saved at 9:08:51 AM, on 11/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\AirPort\APAgent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\AOL\1140899242\ee\AOLHostManager.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\AOL\1140899242\ee\AOLServiceHost.exe
C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\dwwin.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: (no name) - {391B174C-A6B7-C9D7-6743-01F7A0D663D6} - C:\Program Files\Wjsltbcq\bgskgnpz.dll
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {57F0A11D-9DE0-43A3-91FD-4DFCAEB67BB8} - C:\Program Files\MSN\mezokepow555077.dll
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O2 - BHO: (no name) - {89032A20-4370-487E-AB80-2251EC374249} - C:\WINDOWS\system32\xxyywxx.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: aivskurq.msdn_hlp - {A6E432B4-D4C2-43B3-BF55-C364F8F7362A} - C:\WINDOWS\system32\aivskurq.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1140899242\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [AirPort Base Station Agent] "C:\Program Files\AirPort\APAgent.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{17-75-5B-BE-ZN}] C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe CHD001
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location Finder\LocationFinder.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\WNSXS~1\msdtc.exe" -vt yazb
O4 - HKCU\..\Run: [Kjwfty] C:\WINDOWS\system32\?dobe\?hkntfs.exe
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 4.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {38F5F92F-BD40-40DF-A569-6C1FCB638190} (InSPECS3_0 Control) - http://www.powerleap.com/cab_files/InSPECS3_0.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: xxyywxx - C:\WINDOWS\SYSTEM32\xxyywxx.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

thanks!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI