This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]  I really need help

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello and thx for the help agian.
ok heres the combo fix report
ComboFix 07-10-27.4 - Dan Nelson 2007-11-04 8:47:36.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ad-a war\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data.\dehwnaxq.dll
C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Startup\TA_Start.lnk
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\microsoft frontpage\rterter.html
C:\Program Files\network monitor
C:\Program Files\network monitor\netmon.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\RGFuIE5lbHNvbg\asappsrv.dll
C:\WINDOWS\RGFuIE5lbHNvbg\command.exe
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\.exe
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\bvgevqai
C:\WINDOWS\system32\bvgevqai\bg1.gif
C:\WINDOWS\system32\bvgevqai\bgtop.gif
C:\WINDOWS\system32\bvgevqai\bottom1.gif
C:\WINDOWS\system32\bvgevqai\bvgevqai1.exe
C:\WINDOWS\system32\bvgevqai\bvgevqai2.exe
C:\WINDOWS\system32\bvgevqai\bvgevqai3.exe
C:\WINDOWS\system32\bvgevqai\essentials.gif
C:\WINDOWS\system32\bvgevqai\icon1.ico
C:\WINDOWS\system32\bvgevqai\install1.gif
C:\WINDOWS\system32\bvgevqai\left1.gif
C:\WINDOWS\system32\bvgevqai\li.gif
C:\WINDOWS\system32\bvgevqai\logo.gif
C:\WINDOWS\system32\bvgevqai\main.htm
C:\WINDOWS\system32\bvgevqai\mainframe.htm
C:\WINDOWS\system32\bvgevqai\reinstall1.gif
C:\WINDOWS\system32\bvgevqai\right1.gif
C:\WINDOWS\system32\bvgevqai\s1.htm
C:\WINDOWS\system32\bvgevqai\s2.htm
C:\WINDOWS\system32\bvgevqai\s3.htm
C:\WINDOWS\system32\bvgevqai\SMTop1.gif
C:\WINDOWS\system32\bvgevqai\SMTop2.gif
C:\WINDOWS\system32\bvgevqai\SMTop3.gif
C:\WINDOWS\system32\bvgevqai\SMTop4.gif
C:\WINDOWS\system32\bvgevqai\soft1_off.gif
C:\WINDOWS\system32\bvgevqai\soft1_off_ext.gif
C:\WINDOWS\system32\bvgevqai\soft1_on.gif
C:\WINDOWS\system32\bvgevqai\soft1_on_ext.gif
C:\WINDOWS\system32\bvgevqai\soft2_off.gif
C:\WINDOWS\system32\bvgevqai\soft2_off_ext.gif
C:\WINDOWS\system32\bvgevqai\soft2_on.gif
C:\WINDOWS\system32\bvgevqai\soft2_on_ext.gif
C:\WINDOWS\system32\bvgevqai\soft3_off.gif
C:\WINDOWS\system32\bvgevqai\soft3_off_ext.gif
C:\WINDOWS\system32\bvgevqai\soft3_on.gif
C:\WINDOWS\system32\bvgevqai\soft3_on_ext.gif
C:\WINDOWS\system32\bvgevqai\softbottom_off.gif
C:\WINDOWS\system32\bvgevqai\softbottom_on.gif
C:\WINDOWS\system32\bvgevqai\softleft_off.gif
C:\WINDOWS\system32\bvgevqai\softleft_on.gif
C:\WINDOWS\system32\bvgevqai\top1.gif
C:\WINDOWS\system32\bvgevqai\top2.gif
C:\WINDOWS\system32\bvgevqai\turnoff1.gif
C:\WINDOWS\system32\bvgevqai\turnon1.gif
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\dobe~1\?hkntfs.exe
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\drvhapr.dll
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\iawl.dll
C:\WINDOWS\system32\ldcore.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\winrvc32.dll
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\system32\wnsapisv.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\wnsxs~1
C:\WINDOWS\wnsxs~1\msdtc.exe
C:\WINDOWS\wnsxs~1\W?nSxS\
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xpupdate.exe
C:\WINDOWS\xxxvideo.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\cmdService
——-\Network Monitor


((((((((((((((((((((((((( Files Created from 2007-10-04 to 2007-11-04 )))))))))))))))))))))))))))))))
.

2007-11-03 21:25 18,432 –a—— C:\WINDOWS\fkwggshm.exe
2007-11-03 21:22 d——– C:\Program Files\yhaxuxgh
2007-11-03 21:22 d——– C:\Program Files\Wjsltbcq
2007-11-03 21:22 36,864 –a—— C:\WINDOWS\system32\xxyywxx.dll
2007-11-03 21:21 104,960 –a—— C:\WINDOWS\system32\drvhap.dll
2007-11-03 21:09 4 –a—— C:\WINDOWS\system32\stfv.bin
2007-11-03 21:07 d——– C:\WINDOWS\system32\acespy
2007-11-03 21:07 16,640 –a—— C:\WINDOWS\system32\ace16win.dll
2007-10-30 19:23 12 –a—— C:\WINDOWS\system32\dpqaqlqx.bin
2007-10-30 19:22 d–hs—- C:\WINDOWS\RGFuIE5lbHNvbg
2007-10-30 19:22 123,908 –a—— C:\WINDOWS\system32\vvgeowbv.exe
2007-10-30 19:22 21,504 –a—— C:\WINDOWS\system32\aivskurq.dll
2007-10-28 19:14 d——– C:\Program Files\LBT
2007-10-28 10:29 d——– C:\Program Files\SUPERAntiSpyware
2007-10-28 10:29 d——– C:\Documents and Settings\Dan Nelson\Application Data\SUPERAntiSpyware.com
2007-10-28 10:29 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-26 22:13 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-10-26 22:13 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-26 18:20 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-26 11:46 4,528 –a—— C:\WINDOWS\system32\tmp.reg
2007-10-26 11:44 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-10-26 11:44 61,440 –a—— C:\WINDOWS\system32\Process.exe
2007-10-26 11:44 57,856 –a—— C:\WINDOWS\system32\dumphive.exe
2007-10-26 11:14 d——– C:\Program Files\Lavasoft
2007-10-26 11:14 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-26 11:12 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-25 19:37 d——– C:\VundoFix Backups
2007-10-09 13:17 584,192 ——— C:\WINDOWS\system32\dllcache\rpcrt4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-04 16:56 ——— d—–w C:\Program Files\microsoft frontpage
2007-10-27 02:36 ——— d—–w C:\Program Files\QuickTime
2007-10-27 02:35 ——— d—–w C:\Program Files\Microsoft Streets & Trips
2007-10-27 02:35 ——— d—–w C:\Program Files\Microsoft Location Finder
2007-10-27 02:34 ——— d—–w C:\Program Files\ICopyDVDs2(2)
2007-10-27 02:34 ——— d—–w C:\Program Files\Easy Internet signup
2007-10-27 02:32 ——— d—–w C:\Program Files\AIM
2007-10-26 20:17 ——— d—–w C:\Program Files\Microsoft Works
2007-10-26 19:13 ——— d—–w C:\Documents and Settings\Dan Nelson\Application Data\Lavasoft
2007-10-19 02:33 ——— d—–w C:\Program Files\AirPort
2007-10-16 00:49 ——— d—–w C:\Documents and Settings\Emily\Application Data\U3
2007-09-12 14:05 ——— d—–w C:\Program Files\iTunes
2007-09-12 14:05 ——— d—–w C:\Program Files\iPod
2007-09-12 14:01 ——— d—–w C:\Program Files\Common Files\Apple
2007-09-09 01:07 ——— d—–w C:\Program Files\Joost
2007-08-22 13:12 474,112 ——w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-08-22 13:12 151,040 ——w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-08-22 13:12 1,494,528 ——w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-08-22 13:12 1,054,208 ——w C:\WINDOWS\system32\dllcache\danim.dll
2007-08-22 13:12 1,022,976 ——w C:\WINDOWS\system32\dllcache\browseui.dll
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ——w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 10:04 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 6,058,496 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 10:04 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 10:04 477,696 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 10:04 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 10:04 3,584,512 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 10:04 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 631,808 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 70,144 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:20 20,480 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-08-14 01:54 413,696 —-a-w C:\WINDOWS\system32\vbscript.dll
2007-08-14 01:54 413,696 ——w C:\WINDOWS\system32\dllcache\vbscript.dll
2007-08-14 01:54 33,792 —-a-w C:\WINDOWS\system32\dllcache\custsat.dll
2007-08-14 01:54 191,488 —-a-w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-08-14 01:54 156,160 —-a-w C:\WINDOWS\system32\msls31.dll
2007-08-14 01:54 156,160 ——w C:\WINDOWS\system32\dllcache\msls31.dll
2007-08-14 01:45 78,336 —-a-w C:\WINDOWS\system32\ieencode.dll
2007-08-14 01:45 78,336 ——w C:\WINDOWS\system32\dllcache\ieencode.dll
2007-08-14 01:44 75,776 —-a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-08-14 01:44 40,960 —-a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-14 01:44 40,960 ——w C:\WINDOWS\system32\dllcache\licmgr10.dll
2007-08-14 01:42 17,408 —-a-w C:\WINDOWS\system32\corpol.dll
2007-08-14 01:42 17,408 ——w C:\WINDOWS\system32\dllcache\corpol.dll
2007-08-14 01:39 92,672 —-a-w C:\WINDOWS\system32\dllcache\inseng.dll
2007-08-14 01:39 71,680 —-a-w C:\WINDOWS\system32\admparse.dll
2007-08-14 01:39 71,680 ——w C:\WINDOWS\system32\dllcache\admparse.dll
2007-08-14 01:39 55,296 —-a-w C:\WINDOWS\system32\iesetup.dll
2007-08-14 01:39 55,296 ——w C:\WINDOWS\system32\dllcache\iesetup.dll
2007-08-14 01:38 491,520 —-a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-08-14 01:36 44,544 —-a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-08-14 01:36 36,352 —-a-w C:\WINDOWS\system32\imgutil.dll
2007-08-14 01:36 36,352 ——w C:\WINDOWS\system32\dllcache\imgutil.dll
2007-08-14 01:35 346,624 —-a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-08-14 01:32 52,224 —-a-w C:\WINDOWS\system32\mshta.exe
2007-08-14 01:32 52,224 ——w C:\WINDOWS\system32\dllcache\mshta.exe
2007-08-14 01:18 60,416 ——w C:\WINDOWS\system32\dllcache\hmmapi.dll
2007-08-14 01:01 48,128 —-a-w C:\WINDOWS\system32\mshtmler.dll
2007-08-14 01:01 48,128 ——w C:\WINDOWS\system32\dllcache\mshtmler.dll
2005-07-29 23:24:26 472 –sha-r C:\WINDOWS\RGFuIE5lbHNvbg\l3IRKHc5vJhSv0.vbs
.

((((((((((((((((((((((((((((( snapshot@2007-10-26_19.58.04.93 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-07-12 23:28:55 765,952 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\SP2QFE\vgx.dll
+ 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\updspapi.dll
+ 2007-08-20 10:02:09 124,928 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\advpack.dll
+ 2007-08-20 10:02:11 214,528 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\dxtrans.dll
+ 2007-08-20 10:02:09 132,608 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\extmgr.dll
+ 2007-08-20 10:02:09 63,488 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\icardie.dll
+ 2007-08-17 10:12:34 77,312 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ie4uinit.exe
+ 2007-08-20 10:02:09 153,088 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieakeng.dll
+ 2007-08-20 10:02:09 230,400 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieaksie.dll
+ 2007-08-17 07:29:55 161,792 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:24:57 2,455,488 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieapfltr.dat
+ 2007-08-20 10:02:09 383,488 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieapfltr.dll
+ 2007-08-20 10:02:09 387,584 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iedkcs32.dll
+ 2007-08-20 10:02:10 6,066,176 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieframe.dll
+ 2007-08-20 10:02:10 44,544 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iernonce.dll
+ 2007-08-20 10:02:10 267,776 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iertutil.dll
+ 2007-08-17 10:12:35 20,480 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieudinit.exe
+ 2007-08-17 10:12:49 631,808 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
+ 2007-08-20 10:02:10 27,648 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\jsproxy.dll
+ 2007-08-20 10:02:10 459,264 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\msfeeds.dll
+ 2007-08-20 10:02:10 52,224 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\msfeedsbs.dll
+ 2007-08-20 10:02:11 3,592,192 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\mshtml.dll
+ 2007-08-20 10:02:11 478,208 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\mshtmled.dll
+ 2007-08-20 10:02:11 193,024 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\msrating.dll
+ 2007-08-20 10:02:11 671,232 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\mstime.dll
+ 2007-08-20 10:02:11 102,400 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\occache.dll
+ 2007-08-20 10:02:11 105,984 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\url.dll
+ 2007-08-20 10:02:11 1,161,728 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\urlmon.dll
+ 2007-08-20 10:02:11 232,960 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\webcheck.dll
+ 2007-08-20 10:02:11 825,344 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\update\updspapi.dll
- 2007-10-26 16:51:17 145,920 —-a-w C:\WINDOWS\catchme.exe
+ 2007-10-26 17:51:17 136,192 —-a-w C:\WINDOWS\catchme.exe
- 2007-03-13 17:57:10 163,328 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2007-03-13 18:57:10 163,328 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2004-08-04 08:00:00 61,440 -c–a-w C:\WINDOWS\ie7\admparse.dll
+ 2004-08-04 08:00:00 99,840 -c–a-w C:\WINDOWS\ie7\advpack.dll
+ 2004-08-04 08:00:00 35,328 -c–a-w C:\WINDOWS\ie7\corpol.dll
+ 2004-08-11 08:45:04 28,672 -c–a-w C:\WINDOWS\ie7\custsat.dll
+ 2007-08-22 13:12:16 357,888 -c–a-w C:\WINDOWS\ie7\dxtmsft.dll
+ 2007-08-22 13:12:16 205,312 -c–a-w C:\WINDOWS\ie7\dxtrans.dll
+ 2007-08-22 13:12:16 55,808 -c–a-w C:\WINDOWS\ie7\extmgr.dll
+ 2004-08-04 08:00:00 40,960 -c–a-w C:\WINDOWS\ie7\ie4uinit.exe
+ 2004-08-04 08:00:00 139,264 -c–a-w C:\WINDOWS\ie7\ieakeng.dll
+ 2004-08-04 08:00:00 216,576 -c–a-w C:\WINDOWS\ie7\ieaksie.dll
+ 2004-08-04 08:00:00 221,184 -c–a-w C:\WINDOWS\ie7\ieakui.dll
+ 2004-08-04 08:00:00 323,584 -c–a-w C:\WINDOWS\ie7\iedkcs32.dll
+ 2007-08-21 10:30:45 25,088 -c–a-w C:\WINDOWS\ie7\iedw.exe
+ 2004-08-04 08:00:00 81,920 -c–a-w C:\WINDOWS\ie7\ieencode.dll
+ 2007-08-22 13:12:16 251,392 -c–a-w C:\WINDOWS\ie7\iepeers.dll
+ 2004-08-04 08:00:00 48,640 -c–a-w C:\WINDOWS\ie7\iernonce.dll
+ 2004-08-04 08:00:00 62,976 -c–a-w C:\WINDOWS\ie7\iesetup.dll
+ 2004-08-04 08:00:00 35,840 -c–a-w C:\WINDOWS\ie7\imgutil.dll
+ 2007-08-22 13:12:16 96,256 -c–a-w C:\WINDOWS\ie7\inseng.dll
+ 2006-05-18 05:24:25 450,560 -c–a-w C:\WINDOWS\ie7\jscript.dll
+ 2007-08-22 13:12:16 16,384 -c–a-w C:\WINDOWS\ie7\jsproxy.dll
+ 2004-08-04 08:00:00 22,016 -c–a-w C:\WINDOWS\ie7\licmgr10.dll
+ 2004-08-04 08:00:00 35,840 -c–a-w C:\WINDOWS\ie7\mshta.exe
+ 2007-08-22 13:12:17 3,058,176 -c–a-w C:\WINDOWS\ie7\mshtml.dll
+ 2007-08-22 13:12:17 449,024 -c–a-w C:\WINDOWS\ie7\mshtmled.dll
+ 2004-08-04 08:00:00 56,832 -c–a-w C:\WINDOWS\ie7\mshtmler.dll
+ 2004-08-04 08:00:00 146,432 -c–a-w C:\WINDOWS\ie7\msls31.dll
+ 2007-08-22 13:12:17 146,432 -c–a-w C:\WINDOWS\ie7\msrating.dll
+ 2007-08-22 13:12:17 532,480 -c–a-w C:\WINDOWS\ie7\mstime.dll
+ 2004-08-04 08:00:00 96,256 -c–a-w C:\WINDOWS\ie7\occache.dll
+ 2007-08-22 13:12:17 39,424 -c–a-w C:\WINDOWS\ie7\pngfilt.dll
+ 2007-08-14 01:54:42 32,960 -c–a-w C:\WINDOWS\ie7\spuninst\iecustom.dll
+ 2007-08-14 01:52:06 72,704 -c–a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
+ 2006-09-07 00:43:16 213,216 -c–a-w C:\WINDOWS\ie7\spuninst\spuninst.exe
+ 2006-09-07 00:43:18 371,424 -c–a-w C:\WINDOWS\ie7\spuninst\updspapi.dll
+ 2004-08-04 08:00:00 37,888 -c–a-w C:\WINDOWS\ie7\url.dll
+ 2007-08-22 13:12:18 615,424 -c–a-w C:\WINDOWS\ie7\urlmon.dll
+ 2004-08-04 08:00:00 417,792 -c–a-w C:\WINDOWS\ie7\vbscript.dll
+ 2007-06-26 15:13:22 851,968 -c–a-w C:\WINDOWS\ie7\vgx.dll
+ 2004-08-04 08:00:00 276,480 -c–a-w C:\WINDOWS\ie7\webcheck.dll
+ 2007-08-22 13:12:18 658,944 -c–a-w C:\WINDOWS\ie7\wininet.dll
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
+ 2007-08-14 01:54:10 765,952 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
+ 2007-08-14 01:39:00 123,904 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\advpack.dll
+ 2007-08-14 01:35:38 214,528 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\dxtrans.dll
+ 2007-08-14 01:54:10 131,584 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\extmgr.dll
+ 2007-08-14 01:36:26 61,952 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\icardie.dll
+ 2007-08-14 01:39:06 61,440 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ie4uinit.exe
+ 2007-08-14 01:39:06 61,440 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ie4uinit.exe.000
+ 2007-08-14 01:39:26 152,064 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieakeng.dll
+ 2007-08-14 01:39:54 229,376 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieaksie.dll
+ 2007-08-14 00:56:54 161,792 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieakui.dll
+ 2007-02-12 23:10:12 2,451,312 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieapfltr.dat
+ 2007-07-11 19:27:48 383,488 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieapfltr.dll
+ 2007-08-14 01:39:50 382,976 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iedkcs32.dll
+ 2007-08-14 01:54:10 6,049,280 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieframe.dll
+ 2007-08-14 01:39:10 43,008 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iernonce.dll
+ 2007-08-14 01:34:04 266,752 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iertutil.dll
+ 2007-08-14 01:39:10 19,968 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieudinit.exe
+ 2007-08-14 01:43:56 628,736 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
+ 2007-08-14 01:43:56 628,736 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe.000
+ 2007-08-14 01:54:10 27,136 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\jsproxy.dll
+ 2007-08-14 01:54:10 458,752 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msfeeds.dll
+ 2007-08-14 01:54:10 50,688 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msfeedsbs.dll
+ 2007-08-14 01:54:12 3,578,368 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtml.dll
+ 2007-08-14 01:54:10 475,648 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtmled.dll
+ 2007-08-14 01:44:26 192,000 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msrating.dll
+ 2007-08-14 01:54:10 670,720 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mstime.dll
+ 2007-08-14 01:44:06 101,376 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\occache.dll
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\updspapi.dll
+ 2007-08-14 01:44:30 105,984 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\url.dll
+ 2007-08-14 01:54:10 1,162,240 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\urlmon.dll
+ 2007-08-14 01:54:10 231,424 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\webcheck.dll
+ 2007-08-14 01:54:10 818,688 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\wininet.dll
+ 2007-10-28 18:29:07 36,352 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
+ 2007-10-28 18:29:07 25,600 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2007-10-28 18:29:07 71,680 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2007-11-04 05:07:56 25,344 —-a-w C:\WINDOWS\system32\acespy\systune.exe
- 2004-08-04 08:00:00 99,840 —-a-w C:\WINDOWS\system32\advpack.dll
+ 2007-08-20 10:04:34 124,928 —-a-w C:\WINDOWS\system32\advpack.dll
- 2005-04-01 10:02:36 360,448 —-a-w C:\WINDOWS\system32\ati2evxx.exe
+ 2005-04-01 10:02:36 368,640 —-a-w C:\WINDOWS\system32\ati2evxx.exe
- 2007-10-27 02:49:41 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-11-04 16:59:26 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-10-27 02:49:41 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-04 16:59:26 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-10-27 02:49:41 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-04 16:59:26 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-04-17 09:32:38 2,455,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dat
- 2007-06-26 15:13:22 851,968 ——w C:\WINDOWS\system32\dllcache\vgx.dll
+ 2007-07-12 23:31:54 765,952 —-a-w C:\WINDOWS\system32\dllcache\vgx.dll
- 2007-08-22 13:12:16 357,888 —-a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2007-08-14 01:35:46 346,624 —-a-w C:\WINDOWS\system32\dxtmsft.dll
- 2007-08-22 13:12:16 205,312 —-a-w C:\WINDOWS\system32\dxtrans.dll
+ 2007-08-20 10:04:34 214,528 —-a-w C:\WINDOWS\system32\dxtrans.dll
- 2007-08-22 13:12:16 55,808 —-a-w C:\WINDOWS\system32\extmgr.dll
+ 2007-08-20 10:04:34 132,608 —-a-w C:\WINDOWS\system32\extmgr.dll
+ 2007-08-20 10:04:34 63,488 —-a-w C:\WINDOWS\system32\icardie.dll
+ 2006-06-29 15:05:44 26,112 ——w C:\WINDOWS\system32\idndl.dll
- 2004-08-04 08:00:00 40,960 —-a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2007-08-17 10:20:54 70,144 —-a-w C:\WINDOWS\system32\ie4uinit.exe
- 2004-08-04 08:00:00 139,264 —-a-w C:\WINDOWS\system32\ieakeng.dll
+ 2007-08-20 10:04:34 153,088 —-a-w C:\WINDOWS\system32\ieakeng.dll
- 2004-08-04 08:00:00 216,576 —-a-w C:\WINDOWS\system32\ieaksie.dll
+ 2007-08-20 10:04:35 230,400 —-a-w C:\WINDOWS\system32\ieaksie.dll
- 2004-08-04 08:00:00 221,184 —-a-w C:\WINDOWS\system32\ieakui.dll
+ 2007-08-17 07:34:25 161,792 —-a-w C:\WINDOWS\system32\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 —-a-w C:\WINDOWS\system32\ieapfltr.dat
+ 2007-08-20 10:04:35 383,488 —-a-w C:\WINDOWS\system32\ieapfltr.dll
- 2004-08-04 08:00:00 323,584 —-a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2007-08-20 10:04:35 384,512 —-a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2007-08-20 10:04:37 6,058,496 —-a-w C:\WINDOWS\system32\ieframe.dll
- 2007-08-22 13:12:16 251,392 —-a-w C:\WINDOWS\system32\iepeers.dll
+ 2007-08-14 01:54:10 191,488 —-a-w C:\WINDOWS\system32\iepeers.dll
- 2004-08-04 08:00:00 48,640 —-a-w C:\WINDOWS\system32\iernonce.dll
+ 2007-08-20 10:04:38 44,544 —-a-w C:\WINDOWS\system32\iernonce.dll
+ 2007-08-20 10:04:38 267,776 —-a-w C:\WINDOWS\system32\iertutil.dll
+ 2007-08-17 10:20:54 20,480 —-a-w C:\WINDOWS\system32\ieudinit.exe
+ 2007-08-14 01:54:10 180,736 ——w C:\WINDOWS\system32\ieui.dll
- 2007-08-22 13:12:16 96,256 —-a-w C:\WINDOWS\system32\inseng.dll
+ 2007-08-14 01:39:02 92,672 —-a-w C:\WINDOWS\system32\inseng.dll
- 2006-05-18 05:24:25 450,560 —-a-w C:\WINDOWS\system32\jscript.dll
+ 2007-08-14 01:38:04 491,520 —-a-w C:\WINDOWS\system32\jscript.dll
- 2007-08-22 13:12:16 16,384 —-a-w C:\WINDOWS\system32\jsproxy.dll
+ 2007-08-20 10:04:39 27,648 —-a-w C:\WINDOWS\system32\jsproxy.dll
+ 2005-05-24 19:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 22:47:20 102,400 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 22:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2007-08-20 10:04:39 459,264 —-a-w C:\WINDOWS\system32\msfeeds.dll
+ 2007-08-20 10:04:39 52,224 —-a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2007-08-14 01:36:40 18,944 ——w C:\WINDOWS\system32\msfeedssync.exe
- 2007-08-22 13:12:17 3,058,176 —-a-w C:\WINDOWS\system32\mshtml.dll
+ 2007-08-20 10:04:41 3,584,512 —-a-w C:\WINDOWS\system32\mshtml.dll
- 2007-08-22 13:12:17 449,024 —-a-w C:\WINDOWS\system32\mshtmled.dll
+ 2007-08-20 10:04:41 477,696 —-a-w C:\WINDOWS\system32\mshtmled.dll
- 2007-08-22 13:12:17 146,432 —-a-w C:\WINDOWS\system32\msrating.dll
+ 2007-08-20 10:04:41 193,024 —-a-w C:\WINDOWS\system32\msrating.dll
- 2007-08-22 13:12:17 532,480 —-a-w C:\WINDOWS\system32\mstime.dll
+ 2007-08-20 10:04:42 671,232 —-a-w C:\WINDOWS\system32\mstime.dll
+ 2006-06-29 00:59:26 24,576 ——w C:\WINDOWS\system32\nlsdl.dll
+ 2006-06-29 15:05:44 23,552 ——w C:\WINDOWS\system32\normaliz.dll
- 2004-08-04 08:00:00 96,256 —-a-w C:\WINDOWS\system32\occache.dll
+ 2007-08-20 10:04:42 102,400 —-a-w C:\WINDOWS\system32\occache.dll
- 2007-03-28 23:24:03 54,010 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-11-04 16:38:52 54,010 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2007-03-28 23:24:03 383,822 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-04 16:38:53 383,822 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2007-08-22 13:12:17 39,424 —-a-w C:\WINDOWS\system32\pngfilt.dll
+ 2007-08-14 01:36:12 44,544 —-a-w C:\WINDOWS\system32\pngfilt.dll
- 2005-10-12 23:12:25 14,048 —-a-w C:\WINDOWS\system32\spmsg.dll
+ 2007-03-06 01:22:36 14,048 ——w C:\WINDOWS\system32\spmsg.dll
- 2005-06-10 23:53:32 57,856 —-a-w C:\WINDOWS\system32\spoolsv.exe
+ 2005-06-10 23:53:32 64,512 —-a-w C:\WINDOWS\system32\spoolsv.exe
- 2005-06-28 17:21:34 22,752 —-a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2006-09-07 00:43:16 22,752 —-a-w C:\WINDOWS\system32\spupdsvc.exe
- 2007-07-23 01:39:27 289,280 —-a-w C:\WINDOWS\system32\swreg.exe
+ 2007-07-23 02:39:27 279,552 —-a-w C:\WINDOWS\system32\swreg.exe
- 2004-08-04 08:00:00 37,888 —-a-w C:\WINDOWS\system32\url.dll
+ 2007-08-20 10:04:42 105,984 —-a-w C:\WINDOWS\system32\url.dll
- 2007-08-22 13:12:18 615,424 —-a-w C:\WINDOWS\system32\urlmon.dll
+ 2007-08-20 10:04:42 1,152,000 —-a-w C:\WINDOWS\system32\urlmon.dll
- 2004-08-04 08:00:00 218,112 —-a-w C:\WINDOWS\system32\wbem\wmiprvse.exe
+ 2004-08-04 08:00:00 224,768 —-a-w C:\WINDOWS\system32\wbem\wmiprvse.exe
- 2005-01-28 21:44:28 38,912 —-a-w C:\WINDOWS\system32\wdfmgr.exe
+ 2005-01-28 21:44:28 45,568 —-a-w C:\WINDOWS\system32\wdfmgr.exe
- 2004-08-04 08:00:00 49,152 —-a-w C:\WINDOWS\system32\wdigest.dll
+ 2006-03-24 04:37:50 49,152 —-a-w C:\WINDOWS\system32\wdigest.dll
- 2004-08-04 08:00:00 276,480 —-a-w C:\WINDOWS\system32\webcheck.dll
+ 2007-08-20 10:04:42 232,960 —-a-w C:\WINDOWS\system32\webcheck.dll
+ 2007-08-14 01:45:16 212,992 ——w C:\WINDOWS\system32\WinFXDocObj.exe
- 2007-08-22 13:12:18 658,944 —-a-w C:\WINDOWS\system32\wininet.dll
+ 2007-08-20 10:04:43 824,832 —-a-w C:\WINDOWS\system32\wininet.dll
+ 2006-07-14 15:51:51 121,856 ——w C:\WINDOWS\system32\xmllite.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{391B174C-A6B7-C9D7-6743-01F7A0D663D6}]
2007-11-03 21:22 106496 –a—— C:\Program Files\Wjsltbcq\bgskgnpz.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{57F0A11D-9DE0-43A3-91FD-4DFCAEB67BB8}]
2007-08-02 05:43 282624 –a—— C:\Program Files\MSN\mezokepow555077.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{89032A20-4370-487E-AB80-2251EC374249}]
2007-11-03 21:22 36864 –a—— C:\WINDOWS\system32\xxyywxx.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6E432B4-D4C2-43B3-BF55-C364F8F7362A}]
2007-10-30 19:22 21504 –a—— C:\WINDOWS\system32\aivskurq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 20:05]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 02:36]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-11 14:21]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 04:12]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 04:11]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 12:24]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 12:54]
"EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2005-02-07 11:00]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2006-01-06 11:07]
"HPHmon04"="C:\WINDOWS\system32\hphmon04.exe" [2006-01-06 11:07]
"HPHUPD04"="C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" []
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40]
"HostManager"="C:\Program Files\Common Files\AOL\1140899242\ee\AOLHostManager.exe" [2005-08-02 11:33]
"AIMPro"="C:\Program Files\AIM\AIM Pro\aimpro.exe" []
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 06:55]
"AirPort Base Station Agent"="C:\Program Files\AirPort\APAgent.exe" [2007-07-11 15:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-07 15:55]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24]
"{17-75-5B-BE-ZN}"="C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe" [2007-10-30 19:21]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24]
"Microsoft Location Finder"="C:\Program Files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 18:25]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-07-31 10:45]
"Nero PhotoShow Media Manager"="C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [2006-05-10 11:52]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-14 12:13]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:00]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 13:06]
"Tbsa"="C:\WINDOWS\WNSXS~1\msdtc.exe" []
"Kjwfty"="C:\WINDOWS\system32\?dobe\?hkntfs.exe" []

C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Startup\
TA_Start.lnk - C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe [2007-10-30 19:21:41]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
"{89032A20-4370-487E-AB80-2251EC374249}"= C:\WINDOWS\system32\xxyywxx.dll [2007-11-03 21:22 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyywxx]
xxyywxx.dll 2007-11-03 21:22 36864 C:\WINDOWS\system32\xxyywxx.dll


.
Contents of the 'Scheduled Tasks' folder
"2007-10-20 19:41:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-10-27 16:08:24 C:\WINDOWS\Tasks\Symantec NetDetect.job"
.
**************************************************************************

catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-04 09:01:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\system32\msnav32.ax 17 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2007-11-04 9:07:03 - machine was rebooted
C:\ComboFix2.txt … 2007-10-26 20:37
C:\ComboFix3.txt … 2007-10-26 19:00
.
— E O F —



heres the hjt report
Logfile of HijackThis v1.99.1
Scan saved at 9:08:51 AM, on 11/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\AirPort\APAgent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\AOL\1140899242\ee\AOLHostManager.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\AOL\1140899242\ee\AOLServiceHost.exe
C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\dwwin.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: (no name) - {391B174C-A6B7-C9D7-6743-01F7A0D663D6} - C:\Program Files\Wjsltbcq\bgskgnpz.dll
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {57F0A11D-9DE0-43A3-91FD-4DFCAEB67BB8} - C:\Program Files\MSN\mezokepow555077.dll
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O2 - BHO: (no name) - {89032A20-4370-487E-AB80-2251EC374249} - C:\WINDOWS\system32\xxyywxx.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: aivskurq.msdn_hlp - {A6E432B4-D4C2-43B3-BF55-C364F8F7362A} - C:\WINDOWS\system32\aivskurq.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1140899242\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [AirPort Base Station Agent] "C:\Program Files\AirPort\APAgent.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{17-75-5B-BE-ZN}] C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe CHD001
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location Finder\LocationFinder.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\WNSXS~1\msdtc.exe" -vt yazb
O4 - HKCU\..\Run: [Kjwfty] C:\WINDOWS\system32\?dobe\?hkntfs.exe
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 4.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {38F5F92F-BD40-40DF-A569-6C1FCB638190} (InSPECS3_0 Control) - http://www.powerleap.com/cab_files/InSPECS3_0.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: xxyywxx - C:\WINDOWS\SYSTEM32\xxyywxx.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

thanks!!
A. You don't appear to be running any anti-virus software

Anti-virus software are programs that detect, clean, and/or erase harmful virus files on a computer. Unchecked, virus files can unintentionally be forwarded to others, and thereby spread infection. Keeping your anti-virus updated is essential.

Please download a free anti-virus software from one these excellent vendors NOW: It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts.

Once it is downloaded and installed, update the definitions and run the program and let it eliminate everything it wants to.



B. You don't appear to have a software firewall running

It is important that you use a software firewall, to prevent unauthorized traffic both out of and into your computer.
If you have disabled it, please re-enable it.
If you do not have a firewall installed, please download and install one of these excellent (and free) products: It is important to note that you should only have one firewall installed at a time.


C. Download this tool to your desktop:
http://www.uploads.ejvindh.net/rootchk.exe
Run the program. After a short time a logfile will turn up. Copy the contents of the log into the thread.


D. Please download Deckard's System Scanner (DSS) to your desktop.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, a text file will open - Main.txt
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of Main.txt in your thread in the HijackThis Log Help Forum.
  • An additional text file, Extra.txt,will also be available (by default) in the following FOLDER, C:\Deckard\System Scanner.
  • Please go to that FOLDER and also copy the contents of Extra.txt to your post as well.
Note: some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so.

What DSS will do:

  • Create a new System Restore point in Windows XP and Vista.
  • Clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
  • Check some important areas of your system and produce a report for your analyst to review. DSS automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have it installed.

Post Logs:
  • DSS Scan Results: contents of 1) Main.txt and 2) Extra.txt
hello and thanks

heres the main
Deckard's System Scanner v20071014.68
Run by [removed] on 2007-11-04 17:44:27
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–



– Last 3 Restore Point(s) –
3: 2007-11-05 01:27:47 UTC - RP435 - Deckard's System Scanner Restore Point
2: 2007-11-05 01:15:51 UTC - RP434 - Last known good configuration
1: 2007-11-04 20:52:16 UTC - RP433 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Percentage of Memory in Use: 79% (more than 75%).
Total Physical Memory: 511 MiB (512 MiB recommended).
System Drive C: has 4.93 GiB (less than 15%) free.


– HijackThis Clone ————————————————————


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-11-04 17:45:46
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\eabservr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIACA.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\AirPort\APAgent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\AOL\1140899242\ee\AOLHostManager.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Nero\Nero PhotoShow 4\data\Xtras\mssysmgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\AOL\1140899242\ee\AOLServiceHost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HPQ\Shared\hpqwmi.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Dan Nelson\Desktop\dss.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2195A4D3-C390-4F40-9319-64D9CF0F7655} - C:\WINDOWS\system32\ddabx.dll
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O2 - BHO: (no name) - {89032A20-4370-487E-AB80-2251EC374249} - C:\WINDOWS\system32\xxyywxx.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: aivskurq.msdn_hlp - {A6E432B4-D4C2-43B3-BF55-C364F8F7362A} - C:\WINDOWS\system32\aivskurq.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1140899242\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [AirPort Base Station Agent] "C:\Program Files\AirPort\APAgent.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{17-75-5B-BE-ZN}] C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe CHD001
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location Finder\LocationFinder.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\WNSXS~1\msdtc.exe" -vt yazb
O4 - HKCU\..\Run: [Kjwfty] C:\WINDOWS\system32\?dobe\?hkntfs.exe
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe
O8 - Extra context menu item: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 4.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {38F5F92F-BD40-40DF-A569-6C1FCB638190} (InSPECS3_0 Control) - http://www.powerleap.com/cab_files/InSPECS3_0.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O17 - HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: xxyywxx - C:\WINDOWS\system32\xxyywxx.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\Shared\hpqwmi.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\hphipm11.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


–
End of file - 13781 bytes

– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - c:\program files\superantispyware\saskutil.sys
R3 catchme - c:\docume~1\dannel~1\locals~1\temp\catchme.sys (file missing)
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys
now i got a big problem… when i go to log on it says loading your setting… it starts loading and my desktop background comes up. (no icons task-bar or anything like that.) then it says logging off. i cant get it to log on. it will just load up and quickly log off on all users. thanks. hope we can get it all fixed up.
Perform the following procedures in Normal Mode. If you are unable to do so, boot into Safe Mode and perform them whilst in Safe Mode.

Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
    O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
    O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
    O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
    O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
    O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
    O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
    O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
    O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
    O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
    O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
    O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
    O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
    O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
    O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
    O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
    O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
    O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
    O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
    O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
    O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
    O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
    O4 - HKLM\..\Run: [{17-75-5B-BE-ZN}] C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe CHD001
    O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\WNSXS~1\msdtc.exe" -vt yazb
    O4 - HKCU\..\Run: [Kjwfty] C:\WINDOWS\system32\?dobe\?hkntfs.exe
    O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

Rootkit::
C:\WINDOWS\system32\msnav32.ax

Folder::
C:\Program Files\Wjsltbcq
C:\WINDOWS\system32\acespy
C:\WINDOWS\RGFuIE5lbHNvbg
C:\Program Files\LBT
C:\1973515710

File::
C:\WINDOWS\system32\xbadd.bak1
C:\WINDOWS\system32\ddabx.dll
C:\WINDOWS\system32\xxyywxx.dll
C:\Program Files\yhaxuxgh
C:\WINDOWS\system32\drvhap.dll
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\system32\aivskurq.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2195A4D3-C390-4F40-9319-64D9CF0F7655}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{89032A20-4370-487E-AB80-2251EC374249}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6E432B4-D4C2-43B3-BF55-C364F8F7362A}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyywxx]


3. Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)


4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
6. When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
can boot in safe mode cant boot in normal mode cant boot in any mode =( when i start to logon i logon on and it says loading your setting, then it says loggin off saving your setting. i cant logon with safe mode or regular mode. THANK YOU
You can try this. Your registry will be heavily infected again but you MAY regain the ability to logon.

Restore from Erunt Backups via Recovery Console


If Windows will not load, the user will need to boot from the Windows Install disc. The erunt backups can then be accessed via the Recovery Console.

If the user does not have a Windows Install disc, they can create a bootable disc. The simplest way is to download & burn this onto a cd > http://www.atribune.org/downloads/rc.iso


1. Insert Windows Install disc to boot from CD.
2. Press any key on the keyboard when prompted.
3. Press R to load the Recovery Console.
4. Enter your password when prompted.
5. You must enter which Windows installation to log onto. Type 1 and press enter.
6. At the C:\Windows prompt, type the following bolded text, and press Enter:

cd erdnt\subs

7. At the next prompt, type the following bolded text, and press Enter:

batch erdnt.con

8. The erunt backups will begin copying.

9. At the next prompt, type the following bolded text, and press Enter:

exit

Windows will now begin loading.


If you get it working, then please run ComboFix again and post the ComboFix text.

Regards,

Paul
all right. it dint work. when i go to log on it wait a little bit longer before logging off… but still cant get in if it helps i am not using the welcome screen i am using the cntrl alt del then user name. i am thinking.. from some further reading… that some of the logon files got deleted. also i do have the original cd of oem version of the windows xp home edition. thanks!! dan

can boot in safe mode
cant boot in normal mode

Is this a typo? Can you OR Can't you boot into Safe Mode?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI