This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please help me remove Adware.Agent.BN and who knows wh

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My ASUS-motherboard Win XP SP2 computer has been attacked. When I boot in normal mode, after startup I get an assortment of bogus popups, such as "Windows Security Alert", which opens IE and tries to access "www.safenavweb-dot-com". Within a couple of minutes, the CPU is tied up 100% and the computer freezes for all practical purposes. It boots okay in Safe Mode. Spyware Doctor found "Adware.Agent.BN", and claimed to have cleaned it, but the above symptoms remain. Norton AV and Norton AntiSpyware find nothing, and now neither does Spyware Doctor.

Naively I had downloaded some free spyware removal tools, including Ad-Aware 2007 from LavaSoft, "Spyware&Malware Protection" from "viruswebprotect-dot-com", and "Error Cleaner" from the same site. Dumb. These are still on the computer. I'll remove them when and how instructed.

I am sending this from my notebook computer, as I have the ASUS offline. I can run ithe ASUS in Safe Mode, and transfer log files to this computer via a flash drive.

Any help you can give me will be enormously appreciated. I really need the computer back up as I use it for my consulting business.

Thank you.

John

Here are SmitFraudFix, HijackThis Uninstall_list, and HijackThis scan logs, all run in Safe Mode:

**********************************************************************

SmitFraudFix v2.252

Scan done at 15:40:58.09, Tue 11/20/2007
Run from C:\Computer problems and maintenance records\Antivirus and antispyware tools and free download utilities\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

C:\WINDOWS\bxsbang.dll FOUND !
C:\WINDOWS\kthemup.exe FOUND !
C:\WINDOWS\movctrlswd.dll FOUND !
C:\WINDOWS\nssfrch.dll FOUND !
C:\WINDOWS\ocgrep.dll FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS



»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

*****************************************************************************

HijackThis 2.0.2
uninstall_list01:

Ad-Aware 2007
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Creative Suite 2
Adobe Flash Player 9 ActiveX
Adobe Flash Player Plugin
Adobe Help Center 1.0
Adobe Photoshop CS
Adobe Reader 8.1.0
Adobe Stock Photos 1.0
Adobe SVG Viewer 3.0
Advanced Media Extension v1.5
Alibre Design
Alibre Design Help
AppCore
Apple Mobile Device Support
Apple Software Update
AsusUpdate
AT&T Yahoo! Applications
AutoQ3D STD 2.01
AV
CameraMate Real-Time Video Driver
CamStudio
CamStudio Lossless Codec
Canon PC1200/iC D700
ccCommon
Compatibility Pack for the 2007 Office system
Data Lifeguard Tools
DesignWorkshop Lite
DivX
DivX Player
Dragon NaturallySpeaking 9
Easy CD & DVD Creator 6
eDrawings 2003
Files Search Assistant 3.1
Flux Player
GC-Prevue 15.1.4
Google Earth
Google SketchUp
Google SketchUp 6
Google SketchUp 6
Google Updater
GTCO CalComp Tablet Driver
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB935448)
iolo technologies' System Mechanic 6
IrfanView (remove only)
IsoBuster 1.9
ItsDeductible Express
iTunes
LiveUpdate 3.2 (Symantec Corporation)
LiveUpdate BVRP Software
LiveUpdate Notice (Symantec Corporation)
Logitech Audio Echo Cancellation Component
Logitech Desktop Messenger
Logitech QuickCam
Logitech® Camera Driver
Macromedia Dreamweaver 4
Macromedia Extension Manager
March Networks DVR Player
Marvell Miniport Driver
MATLAB 6.1
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft MSDN 2005 Express Edition - ENU
Microsoft National Language Support Downlevel APIs
Microsoft Office Access 2.0 Converter
Microsoft Office Live Meeting 2005
Microsoft Office Live Meeting 2005 Replay Wrapper
Microsoft Office Professional Edition 2003
Microsoft Plus! Dancer LE
Microsoft SQL Server 2000 Sample Database Scripts
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
Microsoft SQL Server 2005 Tools Express Edition
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual Web Developer 2005 Express Edition - ENU
Microsoft Visual Web Developer 2005 Express Edition - ENU
Mindjet MindManager Viewer 6
mobile PhoneTools
MSN
MSN Music Assistant
MSRedist
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 6.0 Parser (KB933579)
MVision
NETGEAR WG111 Software
Norton AntiVirus
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Protection Center
NVIDIA nForce Drivers
Nvu 1.0
Olympus DSS Player
OSLO Light Edition 6.1
PDF Index Assistant 3.1
Pdf995
PdfEdit995
Photo Story 3 for Windows
PhotoModeler Lite
PhotoModeler Pro 5 - Demo
Plaxo Toolbar for Outlook and Outlook Express
PreDesigner [English]
ProPix DVD
Quicken 2005
QuickTime
RealPlayer
Replay 7.0
Replay Converter 2.20
Replay Radio and Replay A/V 7
Retrospect 7.5
Roxio DVDMAX Player
S801TFN
Safari
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Skype™ 3.5
Smart Link 56K Voice Modem
SmartFTP Client 2.0
SmartFTP Client 2.0 Setup Files (remove only)
SolidWorks 2003
SolidWorks 2003 Toolbox
SolidWorks 2003 Viewer
SolidWorks Explorer
SPBBC 32bit
Spyware Doctor 5.0
StuffIt 11
Suite Specific
SuperVoice
Symantec Technical Support Web Controls
SymNet
TaxCut 2003
TaxCut Premium 2006
The Sleuthhound! Pro 4.6
The Sleuthhound! Pro Power Pack 4.6
TUGZip 3.4
TurboTax Deluxe 2004
TurboTax Deluxe 2005
TurboTax ItsDeductible 2005
TurboTax Premier Home & Business 2003
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB900930)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
ViewMate 9.6
Viewpoint Manager (Remove Only)
Viewpoint Media Player (Remove Only)
Visioneer 5300 USB Scanner Driver
Voice Editor
WebEx
WebVideo Support
WexTech AnswerWorks
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Media Tools 4.0
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887797
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
WinLens 4.4
WinTVR3
XnView 1.90.2
XviD MPEG-4 Video Codec

*************************************************************************

HijackThis SCAN LOG 01:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:32:27 PM, on 11/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Computer problems and maintenance records\Antivirus and antispyware tools and free download utilities\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: MSVPS System - {64DE95E5-0A25-4DD9-A472-97BC1D419101} - C:\WINDOWS\movctrlswd.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: The nssfrch - {2106BEDE-F5E8-4DE8-A081-A7E5EAD1529B} - C:\WINDOWS\nssfrch.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CalCompUtil] ccwtup32.exe
O4 - HKLM\..\Run: [ioloDelayModule] "C:\Program Files\iolo\System Mechanic 6\delay.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PP5300usb] c:\paprport\FBDirect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [Data Lifeguard Tools] "C:\Program Files\Western Digital\Data Lifeguard Tools\DataLifeguard.exe" Setup
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - http://components.metastream.com/MTSInstal…MetaStream3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/XSL/mb_us/ht…ALStreaming.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132698770046
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab
O16 - DPF: {918B202D-8E8F-4649-A70B-E9B178FEDC58} (X3D Scene) - http://www.mediamachines.com/download/flux.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://webexevents.webex.com/client/v_mywe…ent/ieatgpc.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: bxsbang - {39679FD3-1C72-4B8A-BA9D-D59F5FF8B5DE} - C:\WINDOWS\bxsbang.dll
O21 - SSODL: ocgrep - {B6CE0199-151E-481A-9A30-7AE61CDDD067} - C:\WINDOWS\ocgrep.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DM1Service - OLYMPUS Corporation - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
O23 - Service: Retrospect Helper - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\rthlpsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Stuffit Archive Name Service - Smith Micro Software, Inc. - C:\Program Files\Smith Micro\StuffIt11\ArcNameService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Wintab32 - Unknown owner - C:\WINDOWS\system32\Wintab32.exe

–
End of file - 11509 bytes

*****************************************************************
Running the Clean

Warning: running option #2 on a non infected computer will remove your Desktop background.


Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

[external image: Posted Image]


The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Reboot Normal

Please post:
1.c:\rapport.txt
2.A new HijackThis log
LD,

The Bogus Popups are gone! After running SmitFraudFix registry cleaner as you instructed, the computer has been running in normal mode for several minutes now, and no popups have appeared. I can now run applications and the CPU is no longer frozen by 100% usage. I'm not sure that I am totally out of the woods yet, but this is great!

New Rapport and HJT scan files are copied below. I was able to follow the directions in your post, with the following exceptions:
1. SmitFraudFix did not report anything about wininet.dll
2. In cleaning temporary internet files, I could not find any check box labeled "Delete offline content" or anything similar.
3. Also in cleaning temporary internet files, there was no "Reset Web Settings" button in the Programs tab, or anywhere I could find.
4. There was no "Security Info" or any similar checkbox entry.

I still have suspect free spyware applications installed, and a lot of junk running in the background.

Thank you SO MUCH for your help!

John

______________________________

SmitFraudFix v2.252

Scan done at 0:05:21.76, Tue 01/01/2002
Run from C:\Computer problems and maintenance records\Antivirus and antispyware tools and free download utilities\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\bxsbang.dll Deleted
Deleting [HKEY_CLASSES_ROOT\CLSID\{39679FD3-1C72-4B8A-BA9D-D59F5FF8B5DE}]
C:\WINDOWS\kthemup.exe Deleted
C:\WINDOWS\movctrlswd.dll Deleted
C:\WINDOWS\nssfrch.dll Deleted
C:\WINDOWS\ocgrep.dll Deleted
Deleting [HKEY_CLASSES_ROOT\CLSID\{B6CE0199-151E-481A-9A30-7AE61CDDD067}]

»»»»»»»»»»»»»»»»»»»»»»»» DNS



»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

________________________________________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:48:04 AM, on 1/1/2002
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Wintab32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\CAPM3RSK.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Smith Micro\StuffIt11\ArcNameService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ccwtup32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\paprport\FBDirect.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Computer problems and maintenance records\Antivirus and antispyware tools and free download utilities\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CalCompUtil] ccwtup32.exe
O4 - HKLM\..\Run: [ioloDelayModule] "C:\Program Files\iolo\System Mechanic 6\delay.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PP5300usb] c:\paprport\FBDirect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [moqq] C:\Program Files\Common Files\moqq\moqqm.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - http://components.metastream.com/MTSInstal…MetaStream3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/XSL/mb_us/ht…ALStreaming.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132698770046
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab
O16 - DPF: {918B202D-8E8F-4649-A70B-E9B178FEDC58} (X3D Scene) - http://www.mediamachines.com/download/flux.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://webexevents.webex.com/client/v_mywe…ent/ieatgpc.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DM1Service - OLYMPUS Corporation - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
O23 - Service: Retrospect Helper - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\rthlpsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Stuffit Archive Name Service - Smith Micro Software, Inc. - C:\Program Files\Smith Micro\StuffIt11\ArcNameService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Wintab32 - Unknown owner - C:\WINDOWS\system32\Wintab32.exe

–
End of file - 14605 bytes
We're not finished yet.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
LD,

Here are the Combofix and HJT logs you requested. Also, after running SmitFraudFix registry cleaner last night, I ran a Norton Internet Security scan, with the results log copied below. This is a Norton Online version provided by AT&T free with my DSL account – not sure if it is equivalent to a boxed version, although it downloads the application to my computer and I can run it offline.

The date and time on my computer got changed somewhere along the line, which i didn't notice until later, so the logs show the wrong date.

All runs were in Normal boot mode. I rebooted after running ATF Cleaner.

I noticed that Combofix flagged the suspicious antispyware applications that I had mentioned in my earlier post.

A Symantec reminder window poped up during the combofix run, which I left open until the run completed.

Loking forward to thearing from you for the next step.

Thanks,

John
_________________________________________________
Norton Internet Security Online scan (Norton Internet Security Online provided by AT&T DSL):

Scan Stats:
Scan Time: 14605
Scan Options:
Scan Targets: C:
Counts:
Total items scanned: 901739
- Files & Directories: 898231
- Registry Entries: 367
- Processes & Start-up Items: 3085
- Network & Browser Items: 51
- Other: 5

Total security risks detected: 0
Total items resolved: 0
Total items that require attention: 0

Resolved Threats:


Unresolved Threats:

____________________________________________________________________

ComboFix 07-11-08.1 - Admin 2002-01-01 13:00:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1396 [GMT -6:00]
Running from: C:\Computer problems and maintenance records\Antivirus and antispyware tools and free download utilities\ComboFix\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Admin\Desktop\Error Cleaner.url
C:\Documents and Settings\Admin\Desktop\Privacy Protector.url
C:\Documents and Settings\Admin\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Admin\Favorites\Error Cleaner.url
C:\Documents and Settings\Admin\Favorites\Privacy Protector.url
C:\Documents and Settings\Admin\Favorites\Spyware&Malware Protection.url
C:\temp\tn3
C:\WINDOWS\dat.txt
C:\WINDOWS\rs.txt
C:\WINDOWS\wr.txt

.
((((((((((((((((((((((((( Files Created from 2007-10-08 to 2007-11-08 )))))))))))))))))))))))))))))))
.

2007-11-24 14:25 d——– C:\Documents and Settings\Administrator\Application Data\U3
2007-11-20 18:36 d——– C:\Documents and Settings\Administrator\Application Data\Yahoo!
2007-11-20 15:41 4,540 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-08 09:22 d——– C:\Documents and Settings\Admin\Application Data\Yahoo!
2007-10-26 16:55 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2007-10-26 16:55 12,160 –a–c— C:\WINDOWS\system32\dllcache\mouhid.sys
2007-10-22 10:56 d——– C:\Program Files\MSECache
2007-10-15 16:48 d——– C:\Documents and Settings\LocalService\Application Data\pdf995

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-20 22:54 ——— d—–w C:\Program Files\Viewpoint
2007-11-15 23:17 ——— d—–w C:\Program Files\Plaxo
2007-11-08 02:39 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-04 21:39 ——— d—–w C:\Program Files\Common Files\Ulead Systems
2007-11-04 21:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2007-11-04 21:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-04 19:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\Retrospect
2007-10-26 23:03 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-10-25 17:46 ——— d—–w C:\Program Files\Spyware Doctor
2007-10-24 16:31 ——— d—–w C:\Program Files\Alibre Design
2007-10-24 14:17 0 —-a-w C:\WINDOWS\system32\drivers\lvuvc.hs
2007-10-23 16:45 ——— d—–w C:\Program Files\Replay7
2007-10-15 22:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\pdf995
2007-10-04 18:15 ——— d—–w C:\Program Files\Google
2007-10-04 17:57 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-04 17:57 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-04 17:57 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-04 17:57 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-04 17:57 ——— d—–w C:\Program Files\Symantec
2007-10-04 17:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-09-29 23:44 ——— d—–w C:\Program Files\Yahoo!
2007-09-29 23:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-09-28 23:10 ——— d—–w C:\Program Files\Common Files\Scanner
2007-09-18 19:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-09-18 19:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-09-18 19:44 10,658 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-09-18 19:44 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-09-18 19:44 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-09-18 19:44 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-09-18 19:43 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-09-18 19:43 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-09-18 19:43 278,576 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-09-17 18:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\SMSI
2007-09-17 18:20 ——— d—–w C:\Program Files\Smith Micro
2007-09-13 21:35 ——— d—–w C:\Program Files\Common Files\xing shared
2007-09-13 21:35 ——— d—–w C:\Program Files\Common Files\Real
2007-09-12 20:24 ——— d—–w C:\Program Files\Skype
2007-09-12 20:24 ——— d—–w C:\Program Files\Common Files\Skype
2007-09-12 20:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-17 17:43 73,216 —-a-w C:\WINDOWS\ST6UNST.EXE
2007-08-17 17:43 249,856 ——w C:\WINDOWS\Setup1.exe
2007-08-11 22:16 127,034 ——r C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2006-12-11 16:53 1,861 —-a-w C:\Program Files\INSTALL.LOG
2004-06-18 04:41 386,688 ——w C:\WINDOWS\inf\WG311v2\netwg311_XP.sys
2004-04-04 18:07 84,912 ——w C:\WINDOWS\inf\WG311v2\FwRad17.bin
2004-04-04 18:07 83,320 ——w C:\WINDOWS\inf\WG311v2\FwRad16.bin
2003-06-19 16:05 431,888 –s-a-w C:\Program Files\Common Files\riched20.dll
2000-02-04 09:19 40,960 —-a-w C:\WINDOWS\inf\vizPnP\Vipersti.dll
2000-02-04 09:19 18,112 —-a-w C:\WINDOWS\inf\vizPnP\Pmxscan.sys
2005-07-14 19:31:20 27,648 –sha-w C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 22:32:28 616,448 –sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-22 05:37:42 45,568 –sha-r C:\WINDOWS\system32\cygz.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" []
"CalCompUtil"="ccwtup32.exe" [2002-02-25 01:11 C:\WINDOWS\system32\ccwtup32.exe]
"ioloDelayModule"="C:\Program Files\iolo\System Mechanic 6\delay.exe" [2005-06-08 13:31]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 15:16]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 08:03]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 15:15]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 15:15]
"PP5300usb"="c:\paprport\FBDirect.exe" [1998-11-17 18:10]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-10 08:18]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 15:02]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 15:06]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 17:30]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-06-26 12:48]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59]
"osCheck"="C:\PROGRA~1\Symantec\osCheck.exe" [2007-01-14 01:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-08-14 16:02]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-05-16 13:43:30]
Device Detector 3.lnk - C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe [2005-12-16 12:14:45]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-07-21 16:52:19]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-08-11 16:16:36]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

R1 DVDVRRdr_xp;DVDVRRdr_xp;C:\WINDOWS\system32\drivers\DVDVRRdr_xp.sys
R2 RapidPortM3;RapidPortM3;\??\C:\WINDOWS\system32\Drivers\CAPM3LP.SYS
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
R2 Stuffit Archive Name Service;Stuffit Archive Name Service;"C:\Program Files\Smith Micro\StuffIt11\ArcNameService.exe"
R3 odysseyIM3;Odyssey Network Services Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM3.sys
R3 W2gtcc;W2gtcc;C:\WINDOWS\system32\DRIVERS\W2gtcc.sys
R3 Wtcls2k;Wtcls2k;C:\WINDOWS\system32\DRIVERS\Wtcls2k.sys
S2 CX23880;Conexant 23880 Video Capture;C:\WINDOWS\system32\drivers\cx88vid.sys
S3 APLMp50;APLMp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\APLMp50.sys
S3 ASUSHWIO;ASUSHWIO;\??\C:\WINDOWS\system32\drivers\ASUSHWIO.sys
S3 DSSUSBF;DSSUSBF Device;C:\WINDOWS\system32\DRIVERS\DSSUSBF.sys
S3 pmxscan;Visioneer USB Service;C:\WINDOWS\system32\DRIVERS\usbscan.sys
S3 XIRLINK;Veo PC Camera;C:\WINDOWS\system32\DRIVERS\ucdnt.sys

*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-06-13 16:54:16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-09-29 23:52:06 C:\WINDOWS\Tasks\Norton Security Online - Run Full System Scan - John.job"
- C:\PROGRA~1\Symantec\Norton AntiVirus\Navw32.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-08 13:05:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-08 13:06:45
.
— E O F —

___________________________________________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:16:13 PM, on 11/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Wintab32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\ccwtup32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\paprport\FBDirect.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\CAPM3RSK.EXE
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Smith Micro\StuffIt11\ArcNameService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\explorer.exe
C:\Computer problems and maintenance records\Antivirus and antispyware tools and free download utilities\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CalCompUtil] ccwtup32.exe
O4 - HKLM\..\Run: [ioloDelayModule] "C:\Program Files\iolo\System Mechanic 6\delay.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PP5300usb] c:\paprport\FBDirect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - http://components.metastream.com/MTSInstal…MetaStream3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/XSL/mb_us/ht…ALStreaming.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132698770046
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab
O16 - DPF: {918B202D-8E8F-4649-A70B-E9B178FEDC58} (X3D Scene) - http://www.mediamachines.com/download/flux.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://webexevents.webex.com/client/v_mywe…ent/ieatgpc.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DM1Service - OLYMPUS Corporation - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
O23 - Service: Retrospect Helper - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\rthlpsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Stuffit Archive Name Service - Smith Micro Software, Inc. - C:\Program Files\Smith Micro\StuffIt11\ArcNameService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Wintab32 - Unknown owner - C:\WINDOWS\system32\Wintab32.exe

–
End of file - 13241 bytes
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\drivers\lvuvc.hs

Folder::
C:\Program Files\Viewpoint

Driver::
lvuvc


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log
LD, ComboFix randomly self-aborts prior to completion, whether using the script file or not. Out of many attempted runs over several hours, once it got so far as to start preparing the log file, but aborted before completing it. That partial log file is enclosed below for what it is worth. No other applications are running, and I have the DSL cable unplugged, I did not touch the mouse, keyboard or any part of the computer. i downloaded a fresh copy of Combofix and got the same result. Norton and Spyware doctor are on the taskbar but not actively scanning. Any ideas appreciated. In other matters, I tried an MS live update of critical patches for Windows and Office. Most downloaded and installed, but these two failed repeatedly during installation: Office 2003 Service pack 3 (SP3) Update for Outlook Junk Email Filter 2003 (KB943552) Error code is 0x52F, which MS knowledge base says is a registry problem. They suggest a fix which I have not yet tried, but will when the computer is okay otherwise. Once while rebooting I got the message "System has just recovered from a serious error", but there had not been any blue screen previous to that. Otherwise, it boots and runs applications fine. When running IE7 for the first time after the previous cleaning operations, it tried to go to the "uclean" website, which I understand is a rogue antispyware spyware. I changed my home page to google and uclean has not reappeared. I think we're close. The computer is now able to run applications at normal speed. Thanks for your continuing help, John ComboFix 07-11-19.4C - Admin 2007-11-30 18:27:27.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1324 [GMT -6:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe . /wow section - STAGE 4 /wow section - STAGE 8 /wow section - STAGE 19 ((((((((((((((((((((((((( Files Created from 2007-11-01 to 2007-12-01 ))))))))))))))))))))))))))))))) . 2007-11-30 11:35 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP 2007-11-24 14:25 d——– C:\Documents and Settings\Administrator\Application Data\U3 2007-11-20 18:36 d——– C:\Documents and Settings\Administrator\Application Data\Yahoo! 2007-11-20 15:41 4,540 –a—— C:\WINDOWS\system32\tmp.reg 2007-11-08 09:22 d——– C:\Documents and Settings\Admin\Application Data\Yahoo! . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-30 22:54 ——— d—–w C:\Program Files\Common Files\Symantec Shared 2007-11-30 18:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help 2007-11-30 18:25 ——— d—–w C:\Program Files\Spyware Doctor 2007-11-30 17:06 79,688 —-a-w C:\WINDOWS\system32\drivers\iksyssec.sys 2007-11-30 17:06 62,280 —-a-w C:\WINDOWS\system32\drivers\iksysflt.sys 2007-11-30 17:06 41,288 —-a-w C:\WINDOWS\system32\drivers\ikfilesec.sys 2007-11-30 17:06 29,000 —-a-w C:\WINDOWS\system32\drivers\kcom.sys 2007-11-30 16:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater 2007-11-20 22:54 ——— d—–w C:\Program Files\Viewpoint 2007-11-15 23:17 ——— d—–w C:\Program Files\Plaxo 2007-11-04 21:39 ——— d—–w C:\Program Files\Common Files\Ulead Systems 2007-11-04 21:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Ulead Systems 2007-11-04 21:29 ——— d–h–w C:\Program Files\InstallShield Installation Information 2007-11-04 19:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\Retrospect 2007-10-24 16:31 ——— d—–w C:\Program Files\Alibre Design 2007-10-24 14:17 0 —-a-w C:\WINDOWS\system32\drivers\lvuvc.hs 2007-10-23 16:45 ——— d—–w C:\Program Files\Replay7 2007-10-22 16:56 ——— d—–w C:\Program Files\MSECache 2007-10-15 22:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\pdf995 2007-10-15 22:48 ——— d—–w C:\Documents and Settings\LocalService\Application Data\pdf995 2007-10-04 18:15 ——— d—–w C:\Program Files\Google 2007-10-04 17:57 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF 2007-10-04 17:57 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL 2007-10-04 17:57 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2007-10-04 17:57 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT 2007-10-04 17:57 ——— d—–w C:\Program Files\Symantec 2007-10-04 17:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec 2006-12-11 16:53 1,861 —-a-w C:\Program Files\INSTALL.LOG 2004-06-18 04:41 386,688 ——w C:\WINDOWS\inf\WG311v2\netwg311_XP.sys 2004-04-04 18:07 84,912 ——w C:\WINDOWS\inf\WG311v2\FwRad17.bin 2004-04-04 18:07 83,320 ——w C:\WINDOWS\inf\WG311v2\FwRad16.bin 2003-06-19 16:05 431,888 –s-a-w C:\Program Files\Common Files\riched20.dll 2000-02-04 09:19 40,960 —-a-w C:\WINDOWS\inf\vizPnP\Vipersti.dll 2000-02-04 09:19 18,112 —-a-w C:\WINDOWS\inf\vizPnP\Pmxscan.sys 2005-07-14 19:31 27,648 –sha-w C:\WINDOWS\system32\AVSredirect.dll 2005-06-26 22:32 616,448 –sha-r C:\WINDOWS\system32\cygwin1.dll 2005-06-22 05:37 45,568 –sha-r C:\WINDOWS\system32\cygz.dll . ((((((((((((((((((((((((((((( snapshot@2007-11-08_13.06.04.24 ))))))))))))))))))))))))))))))))))))))))) . - 2006-03-04 23:43:52 49,152 —-a-w C:\WINDOWS\assembly\GAC\VsWebSite.Interop\8.0.0.0__b03f5f7f11d50a3a\VsWebSite.Interop.dll + 2007-11-30 18:36:27 49,152 —-a-w C:\WINDOWS\assembly\GAC\VsWebSite.Interop\8.0.0.0__b03f5f7f11d50a3a\VsWebSite.Interop.dll - 2006-03-04 23:43:41 733,184 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.CommonIDE\8.0.0.0__b03f5f7f11d50a3a\microsoft.visualstudio.commonide.dll + 2007-11-30 18:36:03 753,664 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.CommonIDE\8.0.0.0__b03f5f7f11d50a3a\microsoft.visualstudio.commonide.dll - 2006-03-04 23:43:54 434,176 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Design\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Design.dll + 2007-11-30 18:36:04 434,176 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Design\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Design.dll - 2006-03-04 23:43:40 1,859,584 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Editors\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Editors.dll + 2007-11-30 18:36:05 1,867,776 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Editors\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Editors.dll - 2006-03-04 23:43:45 344,064 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Package.LanguageService\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Package.LanguageService.dll + 2007-11-30 18:36:06 344,064 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Package.LanguageService\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Package.LanguageService.dll - 2006-03-04 23:44:29 376,832 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Shell\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Shell.dll + 2007-11-30 18:36:06 380,928 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Shell\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Shell.dll - 2006-03-04 23:44:32 53,248 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Zip\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Zip.dll + 2007-11-30 18:36:08 61,440 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Zip\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Zip.dll - 2006-03-04 23:43:20 4,202,496 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VSDesigner\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VSDesigner.dll + 2007-11-30 18:36:10 4,202,496 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VSDesigner\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VSDesigner.dll + 2007-11-30 18:45:40 868,352 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\152eef3407ab1dc83652fd3fc18e923d\Microsoft.VisualStudio.Windows.Forms.ni.dll + 2007-11-30 18:45:37 655,360 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\18c41fd55bf657a766120b03c6dbecf1\Microsoft.VisualStudio.Shell.Design.ni.dll + 2007-11-30 18:44:59 708,608 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\27c8d4716ce8276cb4f9d5a22d4c2fc8\Microsoft.VisualStudio.ni.dll + 2007-11-30 18:45:36 901,120 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\61e39b93aeaa210eebe54e3ab75a6982\Microsoft.VisualStudio.Shell.ni.dll + 2007-11-30 18:45:33 3,309,568 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\7438f7de43c40a020f75620a27300556\Microsoft.VisualStudio.Editors.ni.dll + 2007-11-30 18:45:07 241,664 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\8016b2b105961543f6f3c6f75297738f\Microsoft.VisualStudio.Configuration.ni.dll + 2007-11-30 18:45:06 2,129,920 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\d89f4ddc69f950a01f301fe416de6381\Microsoft.VisualStudio.CommonIDE.ni.dll + 2007-11-30 18:45:11 1,196,032 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\e3bfd1a1664b4eb5d55648f562143426\Microsoft.VisualStudio.Design.ni.dll - 2007-10-30 00:56:19 136,192 —-a-w C:\WINDOWS\catchme.exe + 2007-11-08 22:59:01 136,704 —-a-w C:\WINDOWS\catchme.exe - 2005-09-23 12:56:16 118,784 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WebDev.WebServer.EXE + 2006-12-02 12:27:56 125,720 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WebDev.WebServer.EXE + 2007-11-30 22:39:03 11,018 —-a-w C:\WINDOWS\SoftwareDistribution\EventCache\{1B250665-377E-4657-8D49-407538605735}.bin - 2007-05-11 21:23:56 516,832 —-a-w C:\WINDOWS\system32\capicom.dll + 2007-09-13 00:27:24 511,328 —-a-w C:\WINDOWS\system32\capicom.dll - 2006-12-19 21:52:18 8,453,632 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll + 2007-10-26 03:34:01 8,460,288 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll - 2007-03-15 23:16:42 236,928 -c—-w C:\WINDOWS\system32\dllcache\WgaLogon.dll + 2007-04-10 20:00:46 236,928 -c—-w C:\WINDOWS\system32\dllcache\WgaLogon.dll - 2007-03-15 23:17:08 336,768 -c—-w C:\WINDOWS\system32\dllcache\WgaTray.exe + 2007-04-10 20:01:18 336,768 -c—-w C:\WINDOWS\system32\dllcache\WgaTray.exe - 2007-03-15 23:19:28 1,476,992 —-a-w C:\WINDOWS\system32\LegitCheckControl.dll + 2007-10-11 20:12:48 1,468,968 —-a-w C:\WINDOWS\system32\LegitCheckControl.dll - 2003-03-19 03:20:00 1,060,864 —-a-w C:\WINDOWS\system32\mfc71.dll + 2007-03-22 02:39:00 1,060,864 —-a-w C:\WINDOWS\system32\MFC71.DLL - 2007-09-28 05:19:39 18,089,592 —-a-w C:\WINDOWS\system32\MRT.exe + 2007-11-02 07:12:57 18,238,072 —-a-w C:\WINDOWS\system32\MRT.exe - 2006-08-06 17:13:08 503,808 ——w C:\WINDOWS\system32\msvcp71.dll + 2007-03-22 02:33:00 503,808 —-a-w C:\WINDOWS\system32\MSVCP71.DLL - 2006-08-06 17:13:09 348,160 ——w C:\WINDOWS\system32\msvcr71.dll + 2007-03-22 02:33:00 348,160 —-a-w C:\WINDOWS\system32\MSVCR71.DLL - 2002-01-01 19:00:39 77,082 —-a-w C:\WINDOWS\system32\perfc009.dat + 2007-11-30 22:55:14 77,082 —-a-w C:\WINDOWS\system32\perfc009.dat - 2002-01-01 19:00:39 441,908 —-a-w C:\WINDOWS\system32\perfh009.dat + 2007-11-30 22:55:14 441,908 —-a-w C:\WINDOWS\system32\perfh009.dat - 2006-12-19 21:52:18 8,453,632 —-a-w C:\WINDOWS\system32\shell32.dll + 2007-10-26 03:34:01 8,460,288 —-a-w C:\WINDOWS\system32\shell32.dll - 2006-12-10 19:10:02 14,640 ——w C:\WINDOWS\system32\spmsg.dll + 2006-12-10 20:10:02 14,640 ——w C:\WINDOWS\system32\spmsg.dll - 2007-03-15 23:16:42 236,928 —-a-w C:\WINDOWS\system32\WgaLogon.dll + 2007-04-10 20:00:46 236,928 —-a-w C:\WINDOWS\system32\WgaLogon.dll - 2007-03-15 23:17:08 336,768 ——w C:\WINDOWS\system32\WgaTray.exe + 2007-04-10 20:01:18 336,768 ——w C:\WINDOWS\system32\WgaTray.exe - 2007-06-19 07:24:36 350,720 —-a-w C:\WINDOWS\system32\xpsp3res.dll + 2007-10-29 10:04:03 350,720 —-a-w C:\WINDOWS\system32\xpsp3res.dll . (ComboFix aborted before completing log file)
Restart your computer in Safe Mode. Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen. Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter. This can take several miniutes to load. Now try the combofix I posted
I booted in Safe mode, and dragged the CFScript file onto the ComboFix icon on the desktop. ComboFix starts, then displays "ComboFix is preparing to run", and in a few seconds the DOS window suddenly disappears without a trace. I tried this many times, still in Safe mode, both dragging the script file to start ComboFix, and just starting comboFix directly, and in each case ComboFix self-aborts. Sometimes when ComboFix starts, it displays "access denied", "please wait", "ComboFix is preparing to run", and then aborts. I tried first deleting the folder previous aborted runs of comboFix created in the root directory and then running ComboFix, but same result. Note that the first time you asked me to run ComboFix, without the script file, it ran okay and I posted the log. That was in normal mode.

Any ideas appreciated.
Thanks.

John

Here is another HJT log file, in safe mode.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:21, on 2007-12-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Computer problems and maintenance records\Antivirus and antispyware tools and free download utilities\HijackThis\HiJackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CalCompUtil] ccwtup32.exe
O4 - HKLM\..\Run: [ioloDelayModule] "C:\Program Files\iolo\System Mechanic 6\delay.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PP5300usb] c:\paprport\FBDirect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - http://components.metastream.com/MTSInstal…MetaStream3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/XSL/mb_us/ht…ALStreaming.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132698770046
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab
O16 - DPF: {918B202D-8E8F-4649-A70B-E9B178FEDC58} (X3D Scene) - http://www.mediamachines.com/download/flux.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://webexevents.webex.com/client/v_mywe…ent/ieatgpc.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DM1Service - OLYMPUS Corporation - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
O23 - Service: Retrospect Helper - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\rthlpsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Stuffit Archive Name Service - Smith Micro Software, Inc. - C:\Program Files\Smith Micro\StuffIt11\ArcNameService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Wintab32 - Unknown owner - C:\WINDOWS\system32\Wintab32.exe

–
End of file - 10958 bytes
Lets try this first.

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Good morning! I ran a Dr Web viurus scan overnight. Log is below. I notice Adware.Adrep, which Dr. Web reported as "Adware". I assume the two SmitFraud hits of the three total hits are not actual viruses. Dr. web reported them as "hacktools". I selected all hitsand "move incurable". Curiously, Dr Web scanned only 330,619 files, whereas Norton reports about 900,000 files and directories scanned. The last Nortin IS scan I did on 11/29 reported no viruses or spyware. A0001039.dll;C:\System Volume Information\_restore{A50E4424-C2A5-4C8D-A111-FE86CDE5DE57}\RP1;Adware.Adrep;Incurable.Moved.; Process.exe;C:\Computer problems and maintenance records\Antivirus and antispyware tools and free download utilities\SmitfraudFix\Smitfraud;Tool.ShutDown.11;Incurable.Moved.; restart.exe;C:\Computer problems and maintenance records\Antivirus and antispyware tools and free download utilities\SmitfraudFix\Smitfraud;Tool.ShutDown.11;Incurable.Moved.; What next? John

C:\System Volume Information\_restore

Don't worry about that one. We'll be creating a new restore point and that will remove that.

The other 2 from Smitfraud are OK.



go to start –> run and copy/paste in the following:

"%userprofile%\desktop\combofix.exe"

When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

In your next post, please include
new hijackthis log
combofix log
Here is a (I think) partial ComboFix log, an HJT log, and a log of several Spyware Doctor scans from yesterday and today. HJT was in safe mode. Let me know if it should be in normal mode. Note that Spyware Doctor found some trojans, and multiple copies of AdwareAgent, and etc., some of which it had cleaned a few days ago and which returned. Combofix still will not run to completion, whether in safe or normal boot mode, even from the Run command line. Normal mode gets further, usually part way into the log preparetion, whereas safe mode aborts almost immediately. After starting Combofix, I now unplug the mouse to be sure that no movement signals reached the computer.

Thanks,

John
____________________________________________________
COMBOFIX (probably a partial log):

ComboFix 07-11-19.4C - Admin 2007-12-02 11:32:46.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1440 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
.
/wow section - STAGE 7

((((((((((((((((((((((((( Files Created from 2007-11-02 to 2007-12-02 )))))))))))))))))))))))))))))))
.

2007-11-30 11:35 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-24 14:25 d——– C:\Documents and Settings\Administrator\Application Data\U3
2007-11-20 18:36 d——– C:\Documents and Settings\Administrator\Application Data\Yahoo!
2007-11-20 15:41 4,540 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-08 09:22 d——– C:\Documents and Settings\Admin\Application Data\Yahoo!

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-02 04:02 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-30 22:54 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-30 18:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-30 18:25 ——— d—–w C:\Program Files\Spyware Doctor
2007-11-30 17:06 79,688 —-a-w C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-30 17:06 62,280 —-a-w C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-30 17:06 41,288 —-a-w C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-30 17:06 29,000 —-a-w C:\WINDOWS\system32\drivers\kcom.sys
2007-11-20 22:54 ——— d—–w C:\Program Files\Viewpoint
2007-11-15 23:17 ——— d—–w C:\Program Files\Plaxo
2007-11-04 21:39 ——— d—–w C:\Program Files\Common Files\Ulead Systems
2007-11-04 21:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2007-11-04 21:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-04 19:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\Retrospect
2007-10-24 16:31 ——— d—–w C:\Program Files\Alibre Design
2007-10-24 14:17 0 —-a-w C:\WINDOWS\system32\drivers\lvuvc.hs
2007-10-23 16:45 ——— d—–w C:\Program Files\Replay7
2007-10-22 16:56 ——— d—–w C:\Program Files\MSECache
2007-10-15 22:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\pdf995
2007-10-15 22:48 ——— d—–w C:\Documents and Settings\LocalService\Application Data\pdf995
2007-10-04 18:15 ——— d—–w C:\Program Files\Google
2007-10-04 17:57 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-04 17:57 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-04 17:57 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-04 17:57 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-04 17:57 ——— d—–w C:\Program Files\Symantec
2007-10-04 17:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2006-12-11 16:53 1,861 —-a-w C:\Program Files\INSTALL.LOG
2004-06-18 04:41 386,688 ——w C:\WINDOWS\inf\WG311v2\netwg311_XP.sys
2004-04-04 18:07 84,912 ——w C:\WINDOWS\inf\WG311v2\FwRad17.bin
2004-04-04 18:07 83,320 ——w C:\WINDOWS\inf\WG311v2\FwRad16.bin
2003-06-19 16:05 431,888 –s-a-w C:\Program Files\Common Files\riched20.dll
2000-02-04 09:19 40,960 —-a-w C:\WINDOWS\inf\vizPnP\Vipersti.dll
2000-02-04 09:19 18,112 —-a-w C:\WINDOWS\inf\vizPnP\Pmxscan.sys
2005-07-14 19:31 27,648 –sha-w C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 22:32 616,448 –sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-22 05:37 45,568 –sha-r C:\WINDOWS\system32\cygz.dll
.

((((((((((((((((((((((((((((( snapshot@2007-11-08_13.06.04.24 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-03-04 23:43:52 49,152 —-a-w C:\WINDOWS\assembly\GAC\VsWebSite.Interop\8.0.0.0__b03f5f7f11d50a3a\VsWebSite.Interop.dll
+ 2007-11-30 18:36:27 49,152 —-a-w C:\WINDOWS\assembly\GAC\VsWebSite.Interop\8.0.0.0__b03f5f7f11d50a3a\VsWebSite.Interop.dll
- 2006-03-04 23:43:41 733,184 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.CommonIDE\8.0.0.0__b03f5f7f11d50a3a\microsoft.visualstudio.commonide.dll
+ 2007-11-30 18:36:03 753,664 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.CommonIDE\8.0.0.0__b03f5f7f11d50a3a\microsoft.visualstudio.commonide.dll
- 2006-03-04 23:43:54 434,176 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Design\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Design.dll
+ 2007-11-30 18:36:04 434,176 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Design\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Design.dll
- 2006-03-04 23:43:40 1,859,584 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Editors\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Editors.dll
+ 2007-11-30 18:36:05 1,867,776 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Editors\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Editors.dll
- 2006-03-04 23:43:45 344,064 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Package.LanguageService\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Package.LanguageService.dll
+ 2007-11-30 18:36:06 344,064 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Package.LanguageService\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Package.LanguageService.dll
- 2006-03-04 23:44:29 376,832 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Shell\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Shell.dll
+ 2007-11-30 18:36:06 380,928 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Shell\2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Shell.dll
- 2006-03-04 23:44:32 53,248 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Zip\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Zip.dll
+ 2007-11-30 18:36:08 61,440 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Zip\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Zip.dll
- 2006-03-04 23:43:20 4,202,496 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VSDesigner\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VSDesigner.dll
+ 2007-11-30 18:36:10 4,202,496 —-a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VSDesigner\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VSDesigner.dll
+ 2007-11-30 18:45:40 868,352 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\152eef3407ab1dc83652fd3fc18e923d\Microsoft.VisualStudio.Windows.Forms.ni.dll
+ 2007-11-30 18:45:37 655,360 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\18c41fd55bf657a766120b03c6dbecf1\Microsoft.VisualStudio.Shell.Design.ni.dll
+ 2007-11-30 18:44:59 708,608 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\27c8d4716ce8276cb4f9d5a22d4c2fc8\Microsoft.VisualStudio.ni.dll
+ 2007-11-30 18:45:36 901,120 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\61e39b93aeaa210eebe54e3ab75a6982\Microsoft.VisualStudio.Shell.ni.dll
+ 2007-11-30 18:45:33 3,309,568 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\7438f7de43c40a020f75620a27300556\Microsoft.VisualStudio.Editors.ni.dll
+ 2007-11-30 18:45:07 241,664 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\8016b2b105961543f6f3c6f75297738f\Microsoft.VisualStudio.Configuration.ni.dll
+ 2007-11-30 18:45:06 2,129,920 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\d89f4ddc69f950a01f301fe416de6381\Microsoft.VisualStudio.CommonIDE.ni.dll
+ 2007-11-30 18:45:11 1,196,032 —-a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\e3bfd1a1664b4eb5d55648f562143426\Microsoft.VisualStudio.Design.ni.dll
- 2007-10-30 00:56:19 136,192 —-a-w C:\WINDOWS\catchme.exe
+ 2007-11-08 22:59:01 136,704 —-a-w C:\WINDOWS\catchme.exe
- 2005-09-23 12:56:16 118,784 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WebDev.WebServer.EXE
+ 2006-12-02 12:27:56 125,720 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WebDev.WebServer.EXE
+ 2007-11-30 22:39:03 11,018 —-a-w C:\WINDOWS\SoftwareDistribution\EventCache\{1B250665-377E-4657-8D49-407538605735}.bin
- 2007-05-11 21:23:56 516,832 —-a-w C:\WINDOWS\system32\capicom.dll
+ 2007-09-13 00:27:24 511,328 —-a-w C:\WINDOWS\system32\capicom.dll
- 2006-12-19 21:52:18 8,453,632 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll
+ 2007-10-26 03:34:01 8,460,288 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll
- 2007-03-15 23:16:42 236,928 -c—-w C:\WINDOWS\system32\dllcache\WgaLogon.dll
+ 2007-04-10 20:00:46 236,928 -c—-w C:\WINDOWS\system32\dllcache\WgaLogon.dll
- 2007-03-15 23:17:08 336,768 -c—-w C:\WINDOWS\system32\dllcache\WgaTray.exe
+ 2007-04-10 20:01:18 336,768 -c—-w C:\WINDOWS\system32\dllcache\WgaTray.exe
- 2007-03-15 23:19:28 1,476,992 —-a-w C:\WINDOWS\system32\LegitCheckControl.dll
+ 2007-10-11 20:12:48 1,468,968 —-a-w C:\WINDOWS\system32\LegitCheckControl.dll
- 2003-03-19 03:20:00 1,060,864 —-a-w C:\WINDOWS\system32\mfc71.dll
+ 2007-03-22 02:39:00 1,060,864 —-a-w C:\WINDOWS\system32\MFC71.DLL
- 2007-09-28 05:19:39 18,089,592 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2007-11-02 07:12:57 18,238,072 —-a-w C:\WINDOWS\system32\MRT.exe
- 2006-08-06 17:13:08 503,808 ——w C:\WINDOWS\system32\msvcp71.dll
+ 2007-03-22 02:33:00 503,808 —-a-w C:\WINDOWS\system32\MSVCP71.DLL
- 2006-08-06 17:13:09 348,160 ——w C:\WINDOWS\system32\msvcr71.dll
+ 2007-03-22 02:33:00 348,160 —-a-w C:\WINDOWS\system32\MSVCR71.DLL
- 2002-01-01 19:00:39 77,082 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-12-02 15:17:06 77,082 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2002-01-01 19:00:39 441,908 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-12-02 15:17:06 441,908 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2006-12-19 21:52:18 8,453,632 —-a-w C:\WINDOWS\system32\shell32.dll
+ 2007-10-26 03:34:01 8,460,288 —-a-w C:\WINDOWS\system32\shell32.dll
- 2006-12-10 19:10:02 14,640 ——w C:\WINDOWS\system32\spmsg.dll
+ 2006-12-10 20:10:02 14,640 ——w C:\WINDOWS\system32\spmsg.dll
- 2007-03-15 23:16:42 236,928 —-a-w C:\WINDOWS\system32\WgaLogon.dll
+ 2007-04-10 20:00:46 236,928 —-a-w C:\WINDOWS\system32\WgaLogon.dll
- 2007-03-15 23:17:08 336,768 ——w C:\WINDOWS\system32\WgaTray.exe
+ 2007-04-10 20:01:18 336,768 ——w C:\WINDOWS\system32\WgaTray.exe
- 2007-06-19 07:24:36 350,720 —-a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2007-10-29 10:04:03 350,720 —-a-w C:\WINDOWS\system32\xpsp3res.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" []
"CalCompUtil"="ccwtup32.exe" [2002-02-25 01:11 C:\WINDOWS\system32\ccwtup32.exe]
"ioloDelayModule"="C:\Program Files\iolo\System Mechanic 6\delay.exe" [2005-06-08 13:31]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 15:16]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 08:03]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 15:15]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 15:15]
"PP5300usb"="c:\paprport\FBDirect.exe" [1998-11-17 18:10]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-10 08:18]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 15:02]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 15:06]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 17:30]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-06-26 12:48]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59]
"osCheck"="C:\PROGRA~1\Symantec\osCheck.exe" [2007-01-14 01:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-30 11:45]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-05-16 13:43:30]
Device Detector 3.lnk - C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe [2005-12-16 12:14:45]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-07-21 16:52:19]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-08-11 16:16:36]


___________________________________________________________________

HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:05, on 2007-12-02
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CalCompUtil] ccwtup32.exe
O4 - HKLM\..\Run: [ioloDelayModule] "C:\Program Files\iolo\System Mechanic 6\delay.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PP5300usb] c:\paprport\FBDirect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - http://components.metastream.com/MTSInstal…MetaStream3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/XSL/mb_us/ht…ALStreaming.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132698770046
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab
O16 - DPF: {918B202D-8E8F-4649-A70B-E9B178FEDC58} (X3D Scene) - http://www.mediamachines.com/download/flux.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://webexevents.webex.com/client/v_mywe…ent/ieatgpc.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DM1Service - OLYMPUS Corporation - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
O23 - Service: Retrospect Helper - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\rthlpsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Stuffit Archive Name Service - Smith Micro Software, Inc. - C:\Program Files\Smith Micro\StuffIt11\ArcNameService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Wintab32 - Unknown owner - C:\WINDOWS\system32\Wintab32.exe

–
End of file - 10914 bytes

__________________________________________________________

SPYWARE DOCTOR:

Spyware Doctor scans 2007 12 01-02
2007-12-01 18:00:03:968
Scheduled task started
Initializing Scheduled task: Intelli-Scan of this computer
2007-12-01 18:00:20:453
Infection was detected on this computer


Threat Name - Trojan-PWS.Tanspy
Type - Registry Key
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load
2007-12-01 18:00:26:406
Infection was detected on this computer


Threat Name - Trojan.Generic
Type - Registry Key
Risk Level - Medium
Infection - HKEY_USERS\S-1-5-21-1606980848-261903793-725345543-1004\Software\Wget
2007-12-01 18:00:26:640
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}, (Default)
2007-12-01 18:00:26:656
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid, (Default)
2007-12-01 18:00:26:656
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid
2007-12-01 18:00:26:656
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid32, (Default)
2007-12-01 18:00:26:656
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid32
2007-12-01 18:00:26:656
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\TypeLib, (Default)
2007-12-01 18:00:26:656
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\TypeLib, Version
2007-12-01 18:00:26:656
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\TypeLib
2007-12-01 18:00:26:671
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}
2007-12-01 18:00:26:703
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}, (Default)
2007-12-01 18:00:26:703
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid, (Default)
2007-12-01 18:00:26:703
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid
2007-12-01 18:00:26:703
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid32, (Default)
2007-12-01 18:00:26:703
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid32
2007-12-01 18:00:26:703
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\TypeLib, (Default)
2007-12-01 18:00:26:718
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\TypeLib, Version
2007-12-01 18:00:26:718
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\TypeLib
2007-12-01 18:00:26:718
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}
2007-12-01 18:00:26:718
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}, (Default)
2007-12-01 18:00:26:734
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid, (Default)
2007-12-01 18:00:26:734
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid
2007-12-01 18:00:26:734
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid32, (Default)
2007-12-01 18:00:26:734
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid32
2007-12-01 18:00:26:734
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\TypeLib, (Default)
2007-12-01 18:00:26:750
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\TypeLib, Version
2007-12-01 18:00:26:750
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\TypeLib
2007-12-01 18:00:26:750
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}
2007-12-01 18:00:26:796
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0, (Default)
2007-12-01 18:00:26:812
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0\win32, (Default)
2007-12-01 18:00:26:812
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0\win32
2007-12-01 18:00:26:812
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0
2007-12-01 18:00:26:812
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\FLAGS, (Default)
2007-12-01 18:00:26:812
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\FLAGS
2007-12-01 18:00:26:812
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\HELPDIR, (Default)
2007-12-01 18:00:26:812
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\HELPDIR
2007-12-01 18:00:26:828
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0
2007-12-01 18:00:26:828
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}
2007-12-01 18:00:26:859
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0, (Default)
2007-12-01 18:00:26:859
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0\win32, (Default)
2007-12-01 18:00:26:859
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0\win32
2007-12-01 18:00:26:875
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0
2007-12-01 18:00:26:875
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\FLAGS, (Default)
2007-12-01 18:00:26:875
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\FLAGS
2007-12-01 18:00:26:875
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\HELPDIR, (Default)
2007-12-01 18:00:27:15
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\HELPDIR
2007-12-01 18:00:27:15
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0
2007-12-01 18:00:27:15
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}
2007-12-01 18:04:31:484
Scan Finished


Scan Type - Intelli-Scan
Items Processed - 105933
Threats Detected - 3
Infections Detected - 49
Infections Ignored - 0
2007-12-01 18:38:01:312
Service Stopped


Spyware Doctor Service Application Stopped
2002-01-01 00:05:13:500
Service Started


Spyware Doctor Service Application started
2002-01-01 00:05:14:343
Immunizer Results


ActiveX section has been immunized. No items were processed.
2002-01-01 00:05:14:640
OnGuards status


All OnGuards were Enabled
2002-01-01 00:32:28:765
Service Stopped


Spyware Doctor Service Application Stopped
2002-01-01 00:35:51:78
Service Started


Spyware Doctor Service Application started
2002-01-01 00:35:51:843
Immunizer Results


ActiveX section has been immunized. No items were processed.
2002-01-01 00:35:52:296
OnGuards status


All OnGuards were Enabled
2007-12-01 21:54:03:406
Service Stopped


Spyware Doctor Service Application Stopped
2007-12-01 21:57:16:296
Service Started


Spyware Doctor Service Application started
2007-12-01 21:57:17:46
Immunizer Results


ActiveX section has been immunized. No items were processed.
2007-12-01 21:57:17:406
OnGuards status


All OnGuards were Enabled
2007-12-02 09:10:53:500
Service Stopped


Spyware Doctor Service Application Stopped
2007-12-02 09:13:18:375
Service Started


Spyware Doctor Service Application started
2007-12-02 09:13:19:218
Immunizer Results


ActiveX section has been immunized. No items were processed.
2007-12-02 09:13:19:500
OnGuards status


All OnGuards were Enabled
2007-12-02 10:30:10:500
Scan Started


Scan Type - Intelli-Scan
2007-12-02 10:30:19:640
Infection was detected on this computer


Threat Name - Trojan-PWS.Tanspy
Type - Registry Key
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load
2007-12-02 10:30:23:578
Infection was detected on this computer


Threat Name - Trojan.Generic
Type - Registry Key
Risk Level - Medium
Infection - HKEY_USERS\S-1-5-21-1606980848-261903793-725345543-1004\Software\Wget
2007-12-02 10:30:23:718
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}, (Default)
2007-12-02 10:30:23:718
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid, (Default)
2007-12-02 10:30:23:718
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid
2007-12-02 10:30:23:718
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid32, (Default)
2007-12-02 10:30:23:718
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid32
2007-12-02 10:30:23:734
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\TypeLib, (Default)
2007-12-02 10:30:23:734
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\TypeLib, Version
2007-12-02 10:30:23:734
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\TypeLib
2007-12-02 10:30:23:734
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}
2007-12-02 10:30:23:750
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}, (Default)
2007-12-02 10:30:23:750
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid, (Default)
2007-12-02 10:30:23:750
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid
2007-12-02 10:30:23:750
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid32, (Default)
2007-12-02 10:30:23:750
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid32
2007-12-02 10:30:23:750
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\TypeLib, (Default)
2007-12-02 10:30:23:750
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\TypeLib, Version
2007-12-02 10:30:23:765
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\TypeLib
2007-12-02 10:30:23:765
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}
2007-12-02 10:30:23:765
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}, (Default)
2007-12-02 10:30:23:765
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid, (Default)
2007-12-02 10:30:23:765
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid
2007-12-02 10:30:23:765
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid32, (Default)
2007-12-02 10:30:23:765
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid32
2007-12-02 10:30:23:781
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\TypeLib, (Default)
2007-12-02 10:30:23:781
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\TypeLib, Version
2007-12-02 10:30:23:781
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\TypeLib
2007-12-02 10:30:23:781
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}
2007-12-02 10:30:23:812
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0, (Default)
2007-12-02 10:30:23:812
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0\win32, (Default)
2007-12-02 10:30:23:812
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0\win32
2007-12-02 10:30:23:812
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0
2007-12-02 10:30:23:812
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\FLAGS, (Default)
2007-12-02 10:30:23:828
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\FLAGS
2007-12-02 10:30:23:828
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\HELPDIR, (Default)
2007-12-02 10:30:23:828
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\HELPDIR
2007-12-02 10:30:23:828
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0
2007-12-02 10:30:23:828
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}
2007-12-02 10:30:23:843
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0, (Default)
2007-12-02 10:30:23:843
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0\win32, (Default)
2007-12-02 10:30:23:843
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0\win32
2007-12-02 10:30:23:843
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0
2007-12-02 10:30:23:859
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\FLAGS, (Default)
2007-12-02 10:30:23:859
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\FLAGS
2007-12-02 10:30:23:859
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\HELPDIR, (Default)
2007-12-02 10:30:24:15
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\HELPDIR
2007-12-02 10:30:24:15
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0
2007-12-02 10:30:24:15
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}
2007-12-02 10:31:52:781
Scan Finished


Scan Type - Intelli-Scan
Items Processed - 155171
Threats Detected - 3
Infections Detected - 49
Infections Ignored - 0
2007-12-02 10:37:29:968
Infection quarantined


Threat Name - Trojan-PWS.Tanspy
Type - Registry Key
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load
2007-12-02 10:37:30:93
Infection cleaned


Threat Name - Trojan-PWS.Tanspy
Type - Registry Key
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load
2007-12-02 10:37:30:265
Infection quarantined


Threat Name - Trojan.Generic
Type - Registry Key
Risk Level - Medium
Infection - HKEY_USERS\S-1-5-21-1606980848-261903793-725345543-1004\Software\Wget
2007-12-02 10:37:30:375
Infection cleaned


Threat Name - Trojan.Generic
Type - Registry Key
Risk Level - Medium
Infection - HKEY_USERS\S-1-5-21-1606980848-261903793-725345543-1004\Software\Wget
2007-12-02 10:37:30:578
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}
2007-12-02 10:37:30:578
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0
2007-12-02 10:37:30:578
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\HELPDIR
2007-12-02 10:37:30:593
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\HELPDIR, (Default)
2007-12-02 10:37:30:593
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\FLAGS
2007-12-02 10:37:30:593
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\FLAGS, (Default)
2007-12-02 10:37:30:609
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0
2007-12-02 10:37:30:609
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0\win32
2007-12-02 10:37:30:625
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0\win32, (Default)
2007-12-02 10:37:30:625
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0, (Default)
2007-12-02 10:37:30:640
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}
2007-12-02 10:37:30:640
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0
2007-12-02 10:37:30:640
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\HELPDIR
2007-12-02 10:37:30:656
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\HELPDIR, (Default)
2007-12-02 10:37:30:656
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\FLAGS
2007-12-02 10:37:30:656
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\FLAGS, (Default)
2007-12-02 10:37:30:671
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0
2007-12-02 10:37:30:671
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0\win32
2007-12-02 10:37:30:671
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0\win32, (Default)
2007-12-02 10:37:30:687
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0, (Default)
2007-12-02 10:37:30:687
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}
2007-12-02 10:37:30:703
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\TypeLib
2007-12-02 10:37:30:703
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\TypeLib, Version
2007-12-02 10:37:30:703
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\TypeLib, (Default)
2007-12-02 10:37:30:718
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid32
2007-12-02 10:37:30:718
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid32, (Default)
2007-12-02 10:37:30:718
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid
2007-12-02 10:37:30:734
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid, (Default)
2007-12-02 10:37:30:734
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}, (Default)
2007-12-02 10:37:30:750
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}
2007-12-02 10:37:30:750
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\TypeLib
2007-12-02 10:37:30:750
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\TypeLib, Version
2007-12-02 10:37:30:765
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\TypeLib, (Default)
2007-12-02 10:37:30:765
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid32
2007-12-02 10:37:30:781
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid32, (Default)
2007-12-02 10:37:30:781
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid
2007-12-02 10:37:30:796
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid, (Default)
2007-12-02 10:37:30:796
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}, (Default)
2007-12-02 10:37:30:812
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}
2007-12-02 10:37:30:812
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\TypeLib
2007-12-02 10:37:30:828
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\TypeLib, Version
2007-12-02 10:37:30:828
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\TypeLib, (Default)
2007-12-02 10:37:30:875
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid32
2007-12-02 10:37:30:890
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid32, (Default)
2007-12-02 10:37:30:921
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid
2007-12-02 10:37:30:921
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid, (Default)
2007-12-02 10:37:30:937
Infection quarantined


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}, (Default)
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\HELPDIR
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\HELPDIR, (Default)
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\FLAGS
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\FLAGS, (Default)
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0\win32
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0\win32, (Default)
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0, (Default)
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\HELPDIR
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\HELPDIR, (Default)
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\FLAGS
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\FLAGS, (Default)
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0\win32
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0\win32, (Default)
2007-12-02 10:37:31:281
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0, (Default)
2007-12-02 10:37:31:296
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}
2007-12-02 10:37:31:296
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\TypeLib
2007-12-02 10:37:31:296
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\TypeLib, Version
2007-12-02 10:37:31:296
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\TypeLib, (Default)
2007-12-02 10:37:31:296
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid32
2007-12-02 10:37:31:296
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid32, (Default)
2007-12-02 10:37:31:296
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid
2007-12-02 10:37:31:296
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid, (Default)
2007-12-02 10:37:31:296
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}, (Default)
2007-12-02 10:37:31:296
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\TypeLib
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\TypeLib, Version
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\TypeLib, (Default)
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid32
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid32, (Default)
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid, (Default)
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}, (Default)
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\TypeLib
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\TypeLib, Version
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\TypeLib, (Default)
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid32
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid32, (Default)
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Key
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid, (Default)
2007-12-02 10:37:31:312
Infection cleaned


Threat Name - Adware.Agent.BN
Type - Registry Value
Risk Level - High
Infection - HKEY_CLASSES_ROOT\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}, (Default)
2007-12-02 10:37:33:359
Infections Quarantined/Removed Summary


Quarantined - 49
Quarantine Failed - 0
Removed - 49
Remove Failed - 0
2007-12-02 10:38:35:656
Scan Started


Scan Type - Full Scan
2007-12-02 10:43:47:687
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - File
Risk Level - High
Infection - C:\Documents and Settings\Admin\DoctorWeb\Quarantine\A0001039.dll
2007-12-02 11:13:36:328
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - File
Risk Level - High
Infection - C:\System Volume Information\_restore{A50E4424-C2A5-4C8D-A111-FE86CDE5DE57}\RP1\A0001035.dll
2007-12-02 11:13:36:406
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - File
Risk Level - High
Infection - C:\System Volume Information\_restore{A50E4424-C2A5-4C8D-A111-FE86CDE5DE57}\RP1\A0001037.dll
2007-12-02 11:13:36:437
Infection was detected on this computer


Threat Name - Adware.Agent.BN
Type - File
Risk Level - High
Infection - C:\System Volume Information\_restore{A50E4424-C2A5-4C8D-A111-FE86CDE5DE57}\RP1\A0001038.dll
2007-12-02 11:24:11:765
Scan Finished


Scan Type - Full Scan
Items Processed - 313923
Threats Detected - 1
Infections Detected - 4
Infections Ignored - 0
2007-12-02 11:28:03:468
Infection quarantined


Threat Name - Adware.Agent.BN
Type - File
Risk Level - High
Infection - C:\System Volume Information\_restore{A50E4424-C2A5-4C8D-A111-FE86CDE5DE57}\RP1\A0001038.dll
2007-12-02 11:28:03:734
Infection quarantined


Threat Name - Adware.Agent.BN
Type - File
Risk Level - High
Infection - C:\System Volume Information\_restore{A50E4424-C2A5-4C8D-A111-FE86CDE5DE57}\RP1\A0001037.dll
2007-12-02 11:28:03:984
Infection quarantined


Threat Name - Adware.Agent.BN
Type - File
Risk Level - High
Infection - C:\System Volume Information\_restore{A50E4424-C2A5-4C8D-A111-FE86CDE5DE57}\RP1\A0001035.dll
2007-12-02 11:28:04:343
Infection quarantined


Threat Name - Adware.Agent.BN
Type - File
Risk Level - High
Infection - C:\Documents and Settings\Admin\DoctorWeb\Quarantine\A0001039.dll
2007-12-02 11:28:04:468
Infection cleaned


Threat Name - Adware.Agent.BN
Type - File
Risk Level - High
Infection - C:\System Volume Information\_restore{A50E4424-C2A5-4C8D-A111-FE86CDE5DE57}\RP1\A0001038.dll
2007-12-02 11:28:04:484
Infection cleaned


Threat Name - Adware.Agent.BN
Type - File
Risk Level - High
Infection - C:\System Volume Information\_restore{A50E4424-C2A5-4C8D-A111-FE86CDE5DE57}\RP1\A0001037.dll
2007-12-02 11:28:04:484
Infection cleaned


Threat Name - Adware.Agent.BN
Type - File
Risk Level - High
Infection - C:\System Volume Information\_restore{A50E4424-C2A5-4C8D-A111-FE86CDE5DE57}\RP1\A0001035.dll
2007-12-02 11:28:04:484
Infection cleaned


Threat Name - Adware.Agent.BN
Type - File
Risk Level - High
Infection - C:\Documents and Settings\Admin\DoctorWeb\Quarantine\A0001039.dll
2007-12-02 11:28:06:562
Infections Quarantined/Removed Summary


Quarantined - 4
Quarantine Failed - 0
Removed - 4
Remove Failed - 0
2007-12-02 12:26:52:406
Scan Started


Scan Type - Intelli-Scan
2007-12-02 12:26:58:609
Infection was detected on this computer


Threat Name - Trojan-PWS.Tanspy
Type - Registry Key
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load
2007-12-02 12:27:02:671
Infection was detected on this computer


Threat Name - Trojan.Generic
Type - Registry Key
Risk Level - Medium
Infection - HKEY_USERS\S-1-5-21-1606980848-261903793-725345543-1004\Software\Wget
2007-12-02 12:28:18:546
Scan Finished


Scan Type - Intelli-Scan
Items Processed - 155010
Threats Detected - 2
Infections Detected - 2
Infections Ignored - 0
2007-12-02 12:44:05:421
Infection quarantined


Threat Name - Trojan-PWS.Tanspy
Type - Registry Key
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load
2007-12-02 12:44:05:515
Infection cleaned


Threat Name - Trojan-PWS.Tanspy
Type - Registry Key
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load
2007-12-02 12:44:05:578
Infection quarantined


Threat Name - Trojan.Generic
Type - Registry Key
Risk Level - Medium
Infection - HKEY_USERS\S-1-5-21-1606980848-261903793-725345543-1004\Software\Wget
2007-12-02 12:44:05:656
Infection cleaned


Threat Name - Trojan.Generic
Type - Registry Key
Risk Level - Medium
Infection - HKEY_USERS\S-1-5-21-1606980848-261903793-725345543-1004\Software\Wget
2007-12-02 12:44:07:718
Infections Quarantined/Removed Summary


Quarantined - 2
Quarantine Failed - 0
Removed - 2
Remove Failed - 0
I don't see it anymore but delete this file if listed:
C:\WINDOWS\system32\drivers\lvuvc.hs


Good job :thumbup:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]
  • If shown the disclaimer, Select "2"


Here's my usual all clean post

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide realtime spyware & hijacker protection on your computer alongside your virus protection.
    You should also scan your computer with this program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
    settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

    Using IE-SPYAD to help block unwanted sites and activities

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI