This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Spyware Alert Pop Up

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Every minute or so a security alert pop up appears. In addition, my desktop background has been change to red with a warning that my privacy is in danger. My hijackthis log follows:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:57:32 PM, on 11/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MSVPS System - {A716011B-4637-44D0-922B-F1E88CC7CC73} - C:\WINDOWS\werbetpql.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: The hdtip - {F4BEC60B-9CEE-4A91-91FB-8DA8DE3CA166} - C:\WINDOWS\hdtip.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.87.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/bingame/dsh2/default/D…h2.1.0.0.68.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135130886812
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/bingame/dash/default/D…sh.1.0.0.94.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://www.shockwave.com/content/weddingda…sh.1.0.0.47.cab
O21 - SSODL: gormet - {3D4C79ED-A863-48B4-BF01-53D908E66668} - C:\WINDOWS\gormet.dll
O21 - SSODL: pmkret - {EE39FE72-ABE5-4A57-908B-61D54697E75C} - C:\WINDOWS\pmkret.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

–
End of file - 11575 bytes
Hello Bill35241 and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.

A. Please provide a list of uninstallable programs.

To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.


B. Please download this file - combofix.exe by sUBs
  • You must download it to and run it from your Desktop
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT logand the uninstall list that I requested above.

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

Regards,

Trevuren
Hey Trevuren,

Thanks for your reply. A bit of additional information:

1) This morning my computer took 6 or 7 minutes to boot. My computer usually takes about 1 minute to boot. The combofix reboot seemed to be in the 1 minute area.
2) I ran Adaware this morning and it found absolutely nothing. Yesterday, Adaware had found numerous items including "critical" malware.
3) After having run combofix my IE home page came up in 3 or 4 seconds (the 1st time) and 9 or 10 seconds the second time. It had been taking 20 or 30 seconds. Normal was 3 or 4 seconds.
4) When combofix was running I did get a couple of pop up messages from the tool tray that google had disallowed a change in search criteria. (or something like that)

Again, thanks for your help. The logs you requested follow:



ComboFix 07-12-01.4 - HP_Administrator 2007-12-01 9:13:40.1 - NTFSx86

Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\dat.txt
C:\WINDOWS\search_res.txt
C:\WINDOWS\werbetpql.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-01 to 2007-12-01 )))))))))))))))))))))))))))))))
.

2007-12-01 09:13 . 2004-08-10 07:00 185,856 –a—— C:\WINDOWS\system32\framedyn.dll
2007-11-30 18:57 . 2007-11-30 18:57 d——– C:\Program Files\Trend Micro
2007-11-30 13:13 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-30 12:40 . 2007-11-30 12:40 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-30 12:38 . 2007-11-30 12:38 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-11-30 08:06 . 2007-11-30 08:07 125 –a—— C:\ioSpecial.ini
2007-11-30 00:46 . 2007-11-29 13:17 323,584 –a—— C:\WINDOWS\gormet.dll
2007-11-30 00:46 . 2007-11-29 13:17 262,144 –a—— C:\WINDOWS\pmkret.dll
2007-11-30 00:46 . 2007-11-29 13:17 192,512 –a—— C:\WINDOWS\hdtip.dll
2007-11-30 00:46 . 2007-11-29 13:17 101,710 –a—— C:\WINDOWS\monhop.exe
2007-11-30 00:45 . 2007-11-30 00:45 d——– C:\Program Files\RichVideoCodec
2007-11-28 23:17 . 2007-11-28 23:17 d——– C:\Documents and Settings\HP_Administrator\Application Data\Jane s Hotel

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-01 13:11 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-30 17:40 ——— d—–w C:\Program Files\Lavasoft
2007-11-30 17:36 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-30 13:06 ——— d—–w C:\Program Files\Wedding Dash
2007-10-25 23:28 ——— d—–w C:\Program Files\Burger Shop
2007-10-18 22:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\NannyMania
2007-10-18 22:18 ——— d—–w C:\Program Files\Shockwave.com
2007-10-10 22:13 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\PlayFirst
2007-07-29 15:02 52,744 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
2006-01-27 19:32 0 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2005-05-12 06:36 12,288 —-a-w C:\WINDOWS\Fonts\RandFont.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F4BEC60B-9CEE-4A91-91FB-8DA8DE3CA166}"= C:\WINDOWS\hdtip.dll [2007-11-29 13:17 192512]

[HKEY_CLASSES_ROOT\clsid\{f4bec60b-9cee-4a91-91fb-8da8de3ca166}]
[HKEY_CLASSES_ROOT\hdtip.ToolBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{8C5E2A3D-73CF-41EE-9B53-E2F56FB0F0D1}]
[HKEY_CLASSES_ROOT\hdtip.ToolBar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"Express ClickYes"="C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe" [2005-07-27 03:39]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-20 11:51]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 14:04]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 18:35]
"PCDrProfiler"="" []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-10-05 18:06]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [2005-03-29 12:03]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 17:34]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-10 12:50]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 01:12]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-10-10 11:50]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-12-20 20:53]
"SpywareBot"="C:\Program Files\SpywareBot\SpywareBot.exe" [2006-09-23 13:02]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 18:05]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 01:23:26]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
Updates from HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2005-10-10 12:10:07]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"gormet"= {3D4C79ED-A863-48B4-BF01-53D908E66668} - C:\WINDOWS\gormet.dll [2007-11-29 13:17 323584]
"pmkret"= {EE39FE72-ABE5-4A57-908B-61D54697E75C} - C:\WINDOWS\pmkret.dll [2007-11-29 13:17 262144]


.
Contents of the 'Scheduled Tasks' folder
"2007-11-27 17:31:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-01 02:27:56 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - HP_Administrator.job"
- c:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task:
"2007-12-01 14:06:32 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-01 09:17:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-01 9:18:54 - machine was rebooted
.
— E O F —





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:03:46 AM, on 12/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MSVPS System - {A716011B-4637-44D0-922B-F1E88CC7CC73} - C:\WINDOWS\werbetpql.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: The hdtip - {F4BEC60B-9CEE-4A91-91FB-8DA8DE3CA166} - C:\WINDOWS\hdtip.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.87.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/bingame/dsh2/default/D…h2.1.0.0.68.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135130886812
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/bingame/dash/default/D…sh.1.0.0.94.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://www.shockwave.com/content/weddingda…sh.1.0.0.47.cab
O21 - SSODL: gormet - {3D4C79ED-A863-48B4-BF01-53D908E66668} - C:\WINDOWS\gormet.dll
O21 - SSODL: pmkret - {EE39FE72-ABE5-4A57-908B-61D54697E75C} - C:\WINDOWS\pmkret.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)

–
End of file - 11349 bytes



_______________________________________________


Ad-Aware 2007
Ad-Aware SE Personal
Adobe Download Manager 2.0 (Remove Only)
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0
Adobe Shockwave Player
Agere Systems PCI-SV92PP Soft Modem
Apple Software Update
ATI Control Panel
ATI Display Driver
Axis & Allies
Barnyard Invasion from HP Media Center (remove only)
Bejeweled 2 Deluxe from HP Media Center (remove only)
Big Fish Games Client
Big Kahuna Reef from HP Media Center (remove only)
Blackhawk Striker 2 from HP Media Center (remove only)
Blasterball 2 from HP Media Center (remove only)
Blasterball 2 Holidays from HP Media Center (remove only)
Boggle Supreme from HP Media Center (remove only)
Bookworm Deluxe from HP Media Center (remove only)
Bounce Symphony from HP Media Center (remove only)
Burger Shop (remove only)
CC_ccProxyExt
ccCommon
ccPxyCore
Crystal Maze from HP Media Center (remove only)
Digby's Donuts from HP Media Center (remove only)
Easy Internet Sign-up
Express ClickYes 1.2
FATE Demo from HP Media Center (remove only)
Flip Words from HP Media Center (remove only)
GemMaster Mystic
Google Toolbar for Internet Explorer
Happy Hour
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
HP Boot Optimizer
HP Deskjet Printer Preload
HP DigitalMedia Archive
HP Document Viewer 5.3
HP Game Console and games
HP Image Zone 5.3
HP Image Zone for Media Center PC
HP Imaging Device Functions 5.3
HP Multimedia Keyboard Software
HP Photosmart 330,380,420,470,7800,8000,8200 Series
HP Photosmart Cameras 5.0
HP PSC & OfficeJet 5.3.B
HP PSC 1500 series
HP Software Update
HP Solution Center & Imaging Support Tools 5.3
HP Tunes
Insaniquarium Deluxe from HP Media Center (remove only)
IntelliMover Data Transfer Demo
InterVideo WinDVD Player
iPod for Windows 2006-03-23
iTunes
J2SE Runtime Environment 5.0
Jewel Quest from HP Media Center (remove only)
LiveReg (Symantec Corporation)
LiveUpdate 2.6 (Symantec Corporation)
Mah Jong Quest from HP Media Center (remove only)
MetaFrame Presentation Server Web Client for Win32
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Money 2005
Microsoft Office XP Media Content
Microsoft Office XP Professional
Microsoft Plus! Dancer LE
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Works
MSRedist
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
muvee autoProducer 4.0
muvee autoProducer unPlugged 1.1 - HPD
Nanny Mania
Norton AntiSpam
Norton AntiVirus 2005
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security 2005 (Symantec Corporation)
Norton Security Center
Norton WMI Update
Norton WMI Update
Otto
PartyPoker
PC-Doctor 5 for Windows
Polar Bowler from HP Media Center (remove only)
Polar Golfer from HP Media Center (remove only)
PS2
Puzzle Express from HP Media Center (remove only)
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
Quicken 2005
QuickTime
RealPlayer
Ricochet Lost Worlds from HP Media Center (remove only)
SCRABBLE Blast from HP Media Center (remove only)
SCRABBLE from HP Media Center (remove only)
SCRABBLE Rack Attack from HP Media Center (remove only)
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB943460)
Shrek 2 Ogre Bowler from HP Media Center (remove only)
Sid Meier's Civilization 4
Slingo Deluxe from HP Media Center (remove only)
Slyder from HP Media Center (remove only)
Sonic Encoders
Sonic Express Labeler
Sonic MyDVD Plus
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
SPBBC
Stand O Food
Stand O`Food (remove only)
Super Granny from HP Media Center (remove only)
Swarm from HP Media Center (remove only)
SymNet
Tradewinds from HP Media Center (remove only)
Turbo Pizza (remove only)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update Rollup 1 for Windows XP Media Center Edition 2005 with HDTV Support (KB873369)
Updates from HP (remove only)
WildTangent Web Driver
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10 Hotfix [See KB889858 for more information]
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885354
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891220
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Media Center Edition 2005 KB888316
Windows XP Media Center Edition 2005 KB895678
Xfire (remove only)
Things are progressing well.

A. Using the Add/Remove Program module in your Control Panel please UNINSTALL the following programs:

PartyPoker
WildTangent Web Driver


Justification for the above can be found in this database: http://www.bleepingcomputer.com/uninstall/Cat-P.html


I also recommend that you UNINSTALL the following program which is know to not have the best reputation. There are many others out there that are MUCH better:

SpywareBot


B. Now run HijackThis, click SCAN and place a checkmark beside the following entries:

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe


Now with all programs and browsers closed except for HijackThis, click Fix checked and EXIT the program.


C. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\gormet.dll
C:\WINDOWS\pmkret.dll
C:\WINDOWS\hdtip.dll
C:\WINDOWS\monhop.exe
C:\Program Files\PartyGaming 

Folder::
C:\Program Files\RichVideoCodec
C:\Program Files\SpywareBot
C:\Program Files\PartyGaming

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A716011B-4637-44D0-922B-F1E88CC7CC73}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F4BEC60B-9CEE-4A91-91FB-8DA8DE3CA166}"=-
[-HKEY_CLASSES_ROOT\clsid\{f4bec60b-9cee-4a91-91fb-8da8de3ca166}]
[-HKEY_CLASSES_ROOT\hdtip.ToolBar.1]
[-HKEY_CLASSES_ROOT\TypeLib\{8C5E2A3D-73CF-41EE-9B53-E2F56FB0F0D1}]
[-HKEY_CLASSES_ROOT\hdtip.ToolBar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"gormet"=-
"pmkret"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareBot"=-


3. Next physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)


4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.


Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

7. After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

8. Reconnect to the internet

9. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
Hey Trevuren,

I did the following:

1) I Uninstalled both PartyPoker and WldTangent Web Driver
2) I was not able to find SpywareBot in Add/Remove Programs; however, combofix seemed to find it.
3) I completed Step B successfully.
4) I think I completed Step C correctly; however, I ended up doing that step twice because I missed the "STOP all mointoring programs" part of Step C3. During the first run of combofix in Step C, I get a pop up message from the tool tray that google had disallowed a change in search criteria. (or something like that). During the second run of combofix in Step C, I did not get the above mentioned message.

I'm attaching the following:

1) First run of Step C - combofix log with Norton Antivirus Enabled
2) First run of Step C - HJT log with Norton Antivirus Enabled
3) Second run of Step C - combofix log with Norton Antivirus Disabled
4) Second run of Step C - HJT log with Norton Antivirus Disabled




1) First run of Step C - combofix log with Norton Antivirus Enabled:

ComboFix 07-12-01.4 - HP_Administrator 2007-12-01 12:04:38.2 - NTFSx86

Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Administrator\Desktop\CFScript.txt

FILE
C:\Program Files\PartyGaming
C:\WINDOWS\gormet.dll
C:\WINDOWS\hdtip.dll
C:\WINDOWS\monhop.exe
C:\WINDOWS\pmkret.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\PartyGaming
C:\Program Files\PartyGaming\announce.txt
C:\Program Files\PartyGaming\PartyCasino\Images\games\cardgames\blackjack\split_button.png
C:\Program Files\PartyGaming\PartyCasino\Images\games\cardgames\pointer_R.gif
C:\Program Files\PartyGaming\PartyCasino\Images\games\cardgames\rules_button.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\games\cashier_button.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\games\exit_button.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\games\game_topbar_pff.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\games\gamebalance_free.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\games\gamelogs_button.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\games\version_button.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\sys_icons.jpg
C:\Program Files\PartyGaming\PartyGaming.RPT
C:\Program Files\PartyGaming\PartyPoker\Articles\1072.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1082.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1224.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1304.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1338.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1346.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1348.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1376.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1392.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1418.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1420.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1422.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1448.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1478.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1522.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1530.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1538.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1546.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1550.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1558.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1566.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1586.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1588.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1608.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1624.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1628.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1630.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1632.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1636.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1640.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1670.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1672.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1676.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1680.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1718.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1722.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1724.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1726.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1748.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1756.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1772.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1780.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1788.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1804.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1810.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1812.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1816.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1818.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1854.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1860.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1862.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1864.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1866.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1868.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1870.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1872.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1878.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1880.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1882.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1902.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1936.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1938.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1986.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2.html
C:\Program Files\PartyGaming\PartyPoker\Articles\2010.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2016.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2018.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2020.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2024.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2026.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2032.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2038.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2150.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2152.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2166.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2176.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2178.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2190.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2196.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2198.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2200.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2202.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2270.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2332.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2334.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2336.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2338.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2342.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2344.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2348.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2352.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2358.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2368.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2370.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2390.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2392.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2402.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2484.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2494.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2610.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2612.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2648.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2800.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2806.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2812.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2840.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2874.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2906.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\3010.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\3204.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\3262.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\3264.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\3538.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\3562.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\3564.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\3566.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\3568.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\3570.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\3894.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\3984.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4.html
C:\Program Files\PartyGaming\PartyPoker\Articles\4136.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4152.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4160.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4166.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4174.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4176.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4256.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4330.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4334.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4336.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4340.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4342.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4344.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4492.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4498.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4500.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4510.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4514.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4516.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4518.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4524.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4526.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4532.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4546.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4608.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4616.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4618.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4646.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4648.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4650.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4652.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4654.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4656.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4658.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4776.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4778.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4782.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4816.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4824.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4836.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4844.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4848.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4860.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4870.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4876.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4882.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4884.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4886.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4888.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4912.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4938.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4944.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4946.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4948.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4950.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4952.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4954.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4968.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5000.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5006.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5018.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5058.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\516.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5236.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5244.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5252.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5260.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5262.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5264.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5272.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5294.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5300.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5308.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5312.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5314.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5354.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5356.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5360.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5394.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5454.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5468.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5470.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5474.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5478.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5506.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5544.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5586.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5602.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5626.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5640.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5642.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5644.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5646.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5650.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5652.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5654.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\566.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\5696.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\590.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\592.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6096.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6294.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6302.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\758.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\822.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\852.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\880.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\964.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\968.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\972.atc
C:\Program Files\PartyGaming\PartyPoker\DM.dll
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060818\Table 111625.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060820\Table 111789.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060820\Table 112143.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060824\Table 112870.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060825\Table 112219.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060827\Table 111874.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060830\Table 112538.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060831\Table 111884.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060831\Table 112170.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060831\Table 112219.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060831\Table 112259.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060831\Table 112316.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060901\Table 112705.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060901\Table 114228.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060908\Table 112838.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060911\Table 113522.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060912\Table 114229.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Big_Bill_100\20060915\Table 113011.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Maggban\20060928\Table 111884.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Maggban\20060928\Table 112353.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Maggban\20060928\Table 112534.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Maggban\20060928\Table 112555.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Maggban\20060928\Table 112697.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Maggban\20060929\Table 111872.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Maggban\20060929\Table 113356.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Maggban\20061001\Table 112219.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Maggban\20061002\Table 112188.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Maggban\20061002\Table 113338.txt
C:\Program Files\PartyGaming\PartyPoker\HandHistory\Maggban\20061002\Table 113339.txt
C:\Program Files\PartyGaming\PartyPoker\Images\lhn_bar_prize.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\popup.css
C:\Program Files\PartyGaming\PartyPoker\Images\popup_logo_monster.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\popup_logo_monster_buyin.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\prize_numbers.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\system_but_bingo.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\system_but_gammon.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\table_jp_pin.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\table_jp_pin_tacked.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_dollar.bmp
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_dollar_comma.bmp
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_label.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_pin.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_pin_tacked.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_stip_bottom.bmp
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_stip_left.bmp
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_stip_right.bmp
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_stip_top.bmp
C:\Program Files\PartyGaming\PartyPoker\Images\title_add_take_money.gif
C:\Program Files\PartyGaming\PartyPoker\llh.dll
C:\Program Files\PartyGaming\PartyPoker\Notes.txt
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\INSTALL.LOG
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp94-95man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp95-96man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp96-97man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp97-98man.exe
C:\Program Files\PartyGaming\PartyPoker\TourneyDescription.html
C:\Program Files\PartyGaming\PartyPoker\Uninstall.exe
C:\Program Files\PartyGaming\tmpUpgrade\INSTALL.LOG
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG93-94man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG94-95man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG95-96man.exe
C:\Program Files\RichVideoCodec
C:\Program Files\RichVideoCodec\install.ico
C:\Program Files\SpywareBot
C:\Program Files\SpywareBot\DataBaseNew.ref
C:\Program Files\SpywareBot\Log\log_2006_09_27_10_22_14.log
C:\Program Files\SpywareBot\Log\log_2006_09_27_10_22_15.log
C:\Program Files\SpywareBot\Log\log_2006_09_28_08_53_30.log
C:\Program Files\SpywareBot\Log\log_2006_09_29_06_29_10.log
C:\Program Files\SpywareBot\Log\log_2006_09_30_07_26_34.log
C:\Program Files\SpywareBot\Log\log_2006_10_01_08_39_02.log
C:\Program Files\SpywareBot\Log\log_2006_10_02_07_13_10.log
C:\Program Files\SpywareBot\Log\log_2006_10_03_07_55_12.log
C:\Program Files\SpywareBot\Log\log_2006_10_04_07_33_54.log
C:\Program Files\SpywareBot\Log\log_2006_10_05_07_38_55.log
C:\Program Files\SpywareBot\Log\log_2006_10_06_14_23_12.log
C:\Program Files\SpywareBot\Log\log_2006_10_07_20_24_28.log
C:\Program Files\SpywareBot\Log\log_2006_10_08_08_20_56.log
C:\Program Files\SpywareBot\Log\log_2006_10_09_04_31_08.log
C:\Program Files\SpywareBot\Log\log_2006_10_11_09_34_08.log
C:\Program Files\SpywareBot\Log\log_2006_10_11_15_30_34.log
C:\Program Files\SpywareBot\Log\log_2006_10_12_09_05_03.log
C:\Program Files\SpywareBot\Log\log_2006_10_13_08_02_00.log
C:\Program Files\SpywareBot\Log\log_2006_10_16_08_56_40.log
C:\Program Files\SpywareBot\Log\log_2006_10_17_07_47_44.log
C:\Program Files\SpywareBot\Log\log_2006_10_18_06_57_39.log
C:\Program Files\SpywareBot\Log\log_2006_10_19_07_47_07.log
C:\Program Files\SpywareBot\Log\log_2006_10_20_06_17_16.log
C:\Program Files\SpywareBot\Log\log_2006_10_20_09_45_17.log
C:\Program Files\SpywareBot\Log\log_2006_10_22_07_13_55.log
C:\Program Files\SpywareBot\Log\log_2006_10_23_03_47_29.log
C:\Program Files\SpywareBot\Log\log_2006_10_24_05_50_05.log
C:\Program Files\SpywareBot\Log\log_2006_10_25_08_24_25.log
C:\Program Files\SpywareBot\Log\log_2006_10_26_07_28_10.log
C:\Program Files\SpywareBot\Log\log_2006_10_27_09_06_07.log
C:\Program Files\SpywareBot\Log\log_2006_10_28_05_45_37.log
C:\Program Files\SpywareBot\Log\log_2006_10_29_06_28_09.log
C:\Program Files\SpywareBot\Log\log_2006_10_30_09_19_27.log
C:\Program Files\SpywareBot\Log\log_2006_10_30_18_30_49.log
C:\Program Files\SpywareBot\Log\log_2006_10_31_02_29_06.log
C:\Program Files\SpywareBot\Log\log_2006_10_31_07_21_43.log
C:\Program Files\SpywareBot\Log\log_2006_11_01_03_10_03.log
C:\Program Files\SpywareBot\Log\log_2006_11_02_06_18_32.log
C:\Program Files\SpywareBot\Log\log_2006_11_03_05_40_37.log
C:\Program Files\SpywareBot\Log\log_2006_11_04_20_06_49.log
C:\Program Files\SpywareBot\Log\log_2006_11_04_20_12_56.log
C:\Program Files\SpywareBot\Log\log_2006_11_05_08_44_06.log
C:\Program Files\SpywareBot\Log\log_2006_11_06_06_03_24.log
C:\Program Files\SpywareBot\Log\log_2006_11_08_05_49_29.log
C:\Program Files\SpywareBot\Log\log_2006_11_09_05_40_29.log
C:\Program Files\SpywareBot\Log\log_2006_11_10_07_23_19.log
C:\Program Files\SpywareBot\Log\log_2006_11_12_08_19_19.log
C:\Program Files\SpywareBot\Log\log_2006_11_13_05_59_22.log
C:\Program Files\SpywareBot\Log\log_2006_11_14_06_29_12.log
C:\Program Files\SpywareBot\Log\log_2006_11_16_05_51_41.log
C:\Program Files\SpywareBot\Log\log_2006_11_16_05_58_54.log
C:\Program Files\SpywareBot\Log\log_2006_11_17_05_56_28.log
C:\Program Files\SpywareBot\Log\log_2006_11_17_06_47_33.log
C:\Program Files\SpywareBot\Log\log_2006_11_19_07_30_25.log
C:\Program Files\SpywareBot\Log\log_2006_11_20_05_33_58.log
C:\Program Files\SpywareBot\Log\log_2006_11_21_05_38_15.log
C:\Program Files\SpywareBot\Log\log_2006_11_22_05_36_54.log
C:\Program Files\SpywareBot\Log\log_2006_11_24_06_10_46.log
C:\Program Files\SpywareBot\Log\log_2006_11_25_06_34_36.log
C:\Program Files\SpywareBot\Log\log_2006_11_25_11_59_22.log
C:\Program Files\SpywareBot\Log\log_2006_11_26_09_14_44.log
C:\Program Files\SpywareBot\Log\log_2006_11_27_06_02_06.log
C:\Program Files\SpywareBot\Log\log_2006_11_28_05_21_05.log
C:\Program Files\SpywareBot\Log\log_2006_11_29_05_22_05.log
C:\Program Files\SpywareBot\Log\log_2006_12_03_12_38_14.log
C:\Program Files\SpywareBot\Log\log_2006_12_03_20_08_26.log
C:\Program Files\SpywareBot\Log\log_2006_12_04_06_33_07.log
C:\Program Files\SpywareBot\Log\log_2006_12_04_23_17_09.log
C:\Program Files\SpywareBot\Log\log_2006_12_05_05_23_59.log
C:\Program Files\SpywareBot\Log\log_2006_12_06_05_20_56.log
C:\Program Files\SpywareBot\Log\log_2006_12_07_06_40_51.log
C:\Program Files\SpywareBot\Log\log_2006_12_08_05_27_40.log
C:\Program Files\SpywareBot\Log\log_2006_12_10_09_10_18.log
C:\Program Files\SpywareBot\Log\log_2006_12_11_05_24_07.log
C:\Program Files\SpywareBot\Log\log_2006_12_12_05_23_29.log
C:\Program Files\SpywareBot\Log\log_2006_12_13_06_20_45.log
C:\Program Files\SpywareBot\Log\log_2006_12_13_21_49_08.log
C:\Program Files\SpywareBot\Log\log_2006_12_15_05_23_07.log
C:\Program Files\SpywareBot\Log\log_2006_12_16_03_08_43.log
C:\Program Files\SpywareBot\Log\log_2006_12_16_11_21_21.log
C:\Program Files\SpywareBot\Log\log_2006_12_17_08_43_48.log
C:\Program Files\SpywareBot\Log\log_2006_12_17_17_51_19.log
C:\Program Files\SpywareBot\Log\log_2006_12_18_05_22_28.log
C:\Program Files\SpywareBot\Log\log_2006_12_18_21_11_14.log
C:\Program Files\SpywareBot\Log\log_2006_12_19_04_46_30.log
C:\Program Files\SpywareBot\Log\log_2006_12_20_05_23_16.log
C:\Program Files\SpywareBot\Log\log_2006_12_21_04_19_31.log
C:\Program Files\SpywareBot\Log\log_2006_12_22_05_20_56.log
C:\Program Files\SpywareBot\Log\log_2006_12_25_08_34_21.log
C:\Program Files\SpywareBot\Log\log_2006_12_26_05_20_50.log
C:\Program Files\SpywareBot\Log\log_2006_12_26_19_09_56.log
C:\Program Files\SpywareBot\Log\log_2006_12_28_05_22_34.log
C:\Program Files\SpywareBot\Log\log_2006_12_29_05_23_54.log
C:\Program Files\SpywareBot\Log\log_2006_12_31_07_56_57.log
C:\Program Files\SpywareBot\Log\log_2007_01_01_11_31_35.log
C:\Program Files\SpywareBot\Log\log_2007_01_02_08_07_23.log
C:\Program Files\SpywareBot\Log\log_2007_01_03_05_22_19.log
C:\Program Files\SpywareBot\Log\log_2007_01_04_05_10_56.log
C:\Program Files\SpywareBot\Log\log_2007_01_05_04_06_04.log
C:\Program Files\SpywareBot\Log\log_2007_01_08_05_06_01.log
C:\Program Files\SpywareBot\Log\log_2007_01_09_05_36_07.log
C:\Program Files\SpywareBot\Log\log_2007_01_10_05_23_08.log
C:\Program Files\SpywareBot\Log\log_2007_01_11_03_08_01.log
C:\Program Files\SpywareBot\Log\log_2007_01_12_05_04_51.log
C:\Program Files\SpywareBot\Log\log_2007_01_15_22_05_01.log
C:\Program Files\SpywareBot\Log\log_2007_01_16_05_20_27.log
C:\Program Files\SpywareBot\Log\log_2007_01_17_05_21_49.log
C:\Program Files\SpywareBot\Log\log_2007_01_18_05_23_13.log
C:\Program Files\SpywareBot\Log\log_2007_01_19_05_21_02.log
C:\Program Files\SpywareBot\Log\log_2007_01_22_05_22_28.log
C:\Program Files\SpywareBot\Log\log_2007_01_23_05_29_19.log
C:\Program Files\SpywareBot\Log\log_2007_01_24_06_09_46.log
C:\Program Files\SpywareBot\Log\log_2007_01_25_04_34_13.log
C:\Program Files\SpywareBot\Log\log_2007_01_26_04_35_59.log
C:\Program Files\SpywareBot\Log\log_2007_01_27_05_39_55.log
C:\Program Files\SpywareBot\Log\log_2007_01_27_08_54_18.log
C:\Program Files\SpywareBot\Log\log_2007_01_29_06_56_51.log
C:\Program Files\SpywareBot\Log\log_2007_01_30_11_10_06.log
C:\Program Files\SpywareBot\Log\log_2007_01_30_13_04_18.log
C:\Program Files\SpywareBot\Log\log_2007_01_31_05_15_40.log
C:\Program Files\SpywareBot\Log\log_2007_02_01_05_24_59.log
C:\Program Files\SpywareBot\Log\log_2007_02_01_08_27_42.log
C:\Program Files\SpywareBot\Log\log_2007_02_01_08_39_05.log
C:\Program Files\SpywareBot\Log\log_2007_02_02_12_34_55.log
C:\Program Files\SpywareBot\Log\log_2007_02_04_09_06_35.log
C:\Program Files\SpywareBot\Log\log_2007_02_05_05_27_46.log
C:\Program Files\SpywareBot\Log\log_2007_02_06_05_18_15.log
C:\Program Files\SpywareBot\Log\log_2007_02_07_05_22_34.log
C:\Program Files\SpywareBot\Log\log_2007_02_08_04_24_31.log
C:\Program Files\SpywareBot\Log\log_2007_02_09_05_20_31.log
C:\Program Files\SpywareBot\Log\log_2007_02_12_05_25_55.log
C:\Program Files\SpywareBot\Log\log_2007_02_13_07_36_20.log
C:\Program Files\SpywareBot\Log\log_2007_02_14_05_42_32.log
C:\Program Files\SpywareBot\Log\log_2007_02_15_05_27_08.log
C:\Program Files\SpywareBot\Log\log_2007_02_16_05_40_27.log
C:\Program Files\SpywareBot\Log\log_2007_02_19_05_36_33.log
C:\Program Files\SpywareBot\Log\log_2007_02_20_05_33_48.log
C:\Program Files\SpywareBot\Log\log_2007_02_21_05_36_06.log
C:\Program Files\SpywareBot\Log\log_2007_02_22_07_26_04.log
C:\Program Files\SpywareBot\Log\log_2007_02_23_05_45_09.log
C:\Program Files\SpywareBot\Log\log_2007_02_26_07_19_03.log
C:\Program Files\SpywareBot\Log\log_2007_02_27_14_10_54.log
C:\Program Files\SpywareBot\Log\log_2007_02_28_14_39_51.log
C:\Program Files\SpywareBot\Log\log_2007_03_01_05_40_26.log
C:\Program Files\SpywareBot\Log\log_2007_03_02_14_15_59.log
C:\Program Files\SpywareBot\Log\log_2007_03_05_15_05_39.log
C:\Program Files\SpywareBot\Log\log_2007_03_06_07_43_59.log
C:\Program Files\SpywareBot\Log\log_2007_03_07_07_58_26.log
C:\Program Files\SpywareBot\Log\log_2007_03_08_06_26_19.log
C:\Program Files\SpywareBot\Log\log_2007_03_09_07_55_54.log
C:\Program Files\SpywareBot\Log\log_2007_03_11_07_31_18.log
C:\Program Files\SpywareBot\Log\log_2007_03_12_04_53_14.log
C:\Program Files\SpywareBot\Log\log_2007_03_13_05_40_21.log
C:\Program Files\SpywareBot\Log\log_2007_03_14_05_56_02.log
C:\Program Files\SpywareBot\Log\log_2007_03_15_05_55_37.log
C:\Program Files\SpywareBot\Log\log_2007_03_16_13_34_20.log
C:\Program Files\SpywareBot\Log\log_2007_03_17_07_02_03.log
C:\Program Files\SpywareBot\Log\log_2007_03_19_06_24_28.log
C:\Program Files\SpywareBot\Log\log_2007_03_20_05_44_52.log
C:\Program Files\SpywareBot\Log\log_2007_03_21_07_23_04.log
C:\Program Files\SpywareBot\Log\log_2007_03_22_08_45_20.log
C:\Program Files\SpywareBot\Log\log_2007_03_23_07_36_06.log
C:\Program Files\SpywareBot\Log\log_2007_03_26_05_13_36.log
C:\Program Files\SpywareBot\Log\log_2007_03_27_04_49_04.log
C:\Program Files\SpywareBot\Log\log_2007_03_29_05_46_33.log
C:\Program Files\SpywareBot\Log\log_2007_03_30_14_33_07.log
C:\Program Files\SpywareBot\Log\log_2007_03_31_11_19_29.log
C:\Program Files\SpywareBot\Log\log_2007_04_02_05_31_41.log
C:\Program Files\SpywareBot\Log\log_2007_04_02_14_11_50.log
C:\Program Files\SpywareBot\Log\log_2007_04_02_14_20_51.log
C:\Program Files\SpywareBot\Log\log_2007_04_03_07_43_59.log
C:\Program Files\SpywareBot\Log\log_2007_04_04_05_38_07.log
C:\Program Files\SpywareBot\Log\log_2007_04_05_05_33_19.log
C:\Program Files\SpywareBot\Log\log_2007_04_05_05_39_12.log
C:\Program Files\SpywareBot\Log\log_2007_04_06_18_01_08.log
C:\Program Files\SpywareBot\Log\log_2007_04_08_09_12_29.log
C:\Program Files\SpywareBot\Log\log_2007_04_09_07_07_39.log
C:\Program Files\SpywareBot\Log\log_2007_04_10_07_44_33.log
C:\Program Files\SpywareBot\Log\log_2007_04_11_07_17_29.log
C:\Program Files\SpywareBot\Log\log_2007_04_12_07_51_23.log
C:\Program Files\SpywareBot\Log\log_2007_04_13_07_08_54.log
C:\Program Files\SpywareBot\Log\log_2007_04_14_10_48_39.log
C:\Program Files\SpywareBot\Log\log_2007_04_16_05_56_46.log
C:\Program Files\SpywareBot\Log\log_2007_04_17_08_17_43.log
C:\Program Files\SpywareBot\Log\log_2007_04_18_07_23_07.log
C:\Program Files\SpywareBot\Log\log_2007_04_19_05_51_35.log
C:\Program Files\SpywareBot\Log\log_2007_04_20_07_42_02.log
C:\Program Files\SpywareBot\Log\log_2007_04_22_13_50_32.log
C:\Program Files\SpywareBot\Log\log_2007_04_23_14_38_14.log
C:\Program Files\SpywareBot\Log\log_2007_04_24_06_14_53.log
C:\Program Files\SpywareBot\Log\log_2007_04_25_07_10_46.log
C:\Program Files\SpywareBot\Log\log_2007_04_26_07_25_43.log
C:\Program Files\SpywareBot\Log\log_2007_04_26_21_07_42.log
C:\Program Files\SpywareBot\Log\log_2007_04_27_13_18_44.log
C:\Program Files\SpywareBot\Log\log_2007_04_27_13_45_40.log
C:\Program Files\SpywareBot\Log\log_2007_04_29_09_10_49.log
C:\Program Files\SpywareBot\Log\log_2007_04_30_05_41_57.log
C:\Program Files\SpywareBot\Log\log_2007_05_01_07_22_23.log
C:\Program Files\SpywareBot\Log\log_2007_05_01_07_53_32.log
C:\Program Files\SpywareBot\Log\log_2007_05_01_07_58_36.log
C:\Program Files\SpywareBot\Log\log_2007_05_01_08_06_40.log
C:\Program Files\SpywareBot\Log\log_2007_05_02_06_59_55.log
C:\Program Files\SpywareBot\Log\log_2007_05_03_07_39_04.log
C:\Program Files\SpywareBot\Log\log_2007_05_04_12_49_39.log
C:\Program Files\SpywareBot\Log\log_2007_05_07_06_38_19.log
C:\Program Files\SpywareBot\Log\log_2007_05_08_06_14_51.log
C:\Program Files\SpywareBot\Log\log_2007_05_09_06_40_34.log
C:\Program Files\SpywareBot\Log\log_2007_05_10_07_27_35.log
C:\Program Files\SpywareBot\Log\log_2007_05_11_06_32_30.log
C:\Program Files\SpywareBot\Log\log_2007_05_14_12_53_37.log
C:\Program Files\SpywareBot\Log\log_2007_05_15_07_25_53.log
C:\Program Files\SpywareBot\Log\log_2007_05_16_06_15_14.log
C:\Program Files\SpywareBot\Log\log_2007_05_17_05_50_15.log
C:\Program Files\SpywareBot\Log\log_2007_05_17_13_28_13.log
C:\Program Files\SpywareBot\Log\log_2007_05_18_13_11_57.log
C:\Program Files\SpywareBot\Log\log_2007_05_21_04_46_26.log
C:\Program Files\SpywareBot\Log\log_2007_05_21_08_19_48.log
C:\Program Files\SpywareBot\Log\log_2007_05_21_19_43_15.log
C:\Program Files\SpywareBot\Log\log_2007_05_22_05_29_00.log
C:\Program Files\SpywareBot\Log\log_2007_05_24_08_09_45.log
C:\Program Files\SpywareBot\Log\log_2007_05_25_15_43_35.log
C:\Program Files\SpywareBot\Log\log_2007_05_28_12_35_37.log
C:\Program Files\SpywareBot\Log\log_2007_05_29_05_12_36.log
C:\Program Files\SpywareBot\Log\log_2007_05_30_12_37_43.log
C:\Program Files\SpywareBot\Log\log_2007_05_31_07_54_10.log
C:\Program Files\SpywareBot\Log\log_2007_06_01_06_10_21.log
C:\Program Files\SpywareBot\Log\log_2007_06_03_21_56_23.log
C:\Program Files\SpywareBot\Log\log_2007_06_04_21_47_02.log
C:\Program Files\SpywareBot\Log\log_2007_06_05_07_42_15.log
C:\Program Files\SpywareBot\Log\log_2007_06_06_13_23_47.log
C:\Program Files\SpywareBot\Log\log_2007_06_06_21_30_49.log
C:\Program Files\SpywareBot\Log\log_2007_06_07_06_21_08.log
C:\Program Files\SpywareBot\Log\log_2007_06_08_12_24_40.log
C:\Program Files\SpywareBot\Log\log_2007_06_09_08_52_03.log
C:\Program Files\SpywareBot\Log\log_2007_06_11_10_33_34.log
C:\Program Files\SpywareBot\Log\log_2007_06_12_06_26_30.log
C:\Program Files\SpywareBot\Log\log_2007_06_13_12_51_28.log
C:\Program Files\SpywareBot\Log\log_2007_06_14_06_38_04.log
C:\Program Files\SpywareBot\Log\log_2007_06_15_06_22_10.log
C:\Program Files\SpywareBot\Log\log_2007_06_15_12_30_18.log
C:\Program Files\SpywareBot\Log\log_2007_06_18_07_35_20.log
C:\Program Files\SpywareBot\Log\log_2007_06_19_07_39_18.log
C:\Program Files\SpywareBot\Log\log_2007_06_20_12_33_00.log
C:\Program Files\SpywareBot\Log\log_2007_06_21_07_42_23.log
C:\Program Files\SpywareBot\Log\log_2007_06_22_10_56_55.log
C:\Program Files\SpywareBot\Log\log_2007_06_24_06_58_25.log
C:\Program Files\SpywareBot\Log\log_2007_06_25_07_49_20.log
C:\Program Files\SpywareBot\Log\log_2007_06_26_06_26_18.log
C:\Program Files\SpywareBot\Log\log_2007_06_27_07_40_55.log
C:\Program Files\SpywareBot\Log\log_2007_06_28_06_39_49.log
C:\Program Files\SpywareBot\Log\log_2007_06_29_07_42_36.log
C:\Program Files\SpywareBot\Log\log_2007_06_30_07_35_26.log
C:\Program Files\SpywareBot\Log\log_2007_07_02_05_34_29.log
C:\Program Files\SpywareBot\Log\log_2007_07_03_05_59_52.log
C:\Program Files\SpywareBot\Log\log_2007_07_03_07_56_52.log
C:\Program Files\SpywareBot\Log\log_2007_07_04_11_01_36.log
C:\Program Files\SpywareBot\Log\log_2007_07_05_06_14_50.log
C:\Program Files\SpywareBot\Log\log_2007_07_06_07_33_40.log
C:\Program Files\SpywareBot\Log\log_2007_07_07_18_35_24.log
C:\Program Files\SpywareBot\Log\log_2007_07_08_09_40_39.log
C:\Program Files\SpywareBot\Log\log_2007_07_09_07_59_56.log
C:\Program Files\SpywareBot\Log\log_2007_07_10_05_47_23.log
C:\Program Files\SpywareBot\Log\log_2007_07_11_06_04_28.log
C:\Program Files\SpywareBot\Log\log_2007_07_12_06_06_29.log
C:\Program Files\SpywareBot\Log\log_2007_07_13_06_06_54.log
C:\Program Files\SpywareBot\Log\log_2007_07_14_09_59_09.log
C:\Program Files\SpywareBot\Log\log_2007_07_15_08_32_13.log
C:\Program Files\SpywareBot\Log\log_2007_07_16_06_02_54.log
C:\Program Files\SpywareBot\Log\log_2007_07_16_18_08_14.log
C:\Program Files\SpywareBot\Log\log_2007_07_17_07_43_07.log
C:\Program Files\SpywareBot\Log\log_2007_07_18_08_01_52.log
C:\Program Files\SpywareBot\Log\log_2007_07_19_06_35_34.log
C:\Program Files\SpywareBot\Log\log_2007_07_19_18_32_34.log
C:\Program Files\SpywareBot\Log\log_2007_07_20_07_53_37.log
C:\Program Files\SpywareBot\Log\log_2007_07_21_09_49_29.log
C:\Program Files\SpywareBot\Log\log_2007_07_21_12_57_25.log
C:\Program Files\SpywareBot\Log\log_2007_07_22_10_32_26.log
C:\Program Files\SpywareBot\Log\log_2007_07_23_06_36_36.log
C:\Program Files\SpywareBot\Log\log_2007_07_24_07_36_33.log
C:\Program Files\SpywareBot\Log\log_2007_07_25_07_42_27.log
C:\Program Files\SpywareBot\Log\log_2007_07_26_07_40_30.log
C:\Program Files\SpywareBot\Log\log_2007_07_27_06_59_17.log
C:\Program Files\SpywareBot\Log\log_2007_07_28_07_28_03.log
C:\Program Files\SpywareBot\Log\log_2007_07_29_09_45_59.log
C:\Program Files\SpywareBot\Log\log_2007_07_30_06_03_01.log
C:\Program Files\SpywareBot\Log\log_2007_07_30_12_43_06.log
C:\Program Files\SpywareBot\Log\log_2007_07_30_14_18_13.log
C:\Program Files\SpywareBot\Log\log_2007_07_31_07_54_26.log
C:\Program Files\SpywareBot\Log\log_2007_08_01_04_49_00.log
C:\Program Files\SpywareBot\Log\log_2007_08_01_07_02_33.log
C:\Program Files\SpywareBot\Log\log_2007_08_02_07_42_01.log
C:\Program Files\SpywareBot\Log\log_2007_08_03_12_58_41.log
C:\Program Files\SpywareBot\Log\log_2007_08_06_12_45_39.log
C:\Program Files\SpywareBot\Log\log_2007_08_07_05_46_45.log
C:\Program Files\SpywareBot\Log\log_2007_08_07_17_52_55.log
C:\Program Files\SpywareBot\Log\log_2007_08_08_05_38_26.log
C:\Program Files\SpywareBot\Log\log_2007_08_09_07_23_51.log
C:\Program Files\SpywareBot\Log\log_2007_08_10_05_37_50.log
C:\Program Files\SpywareBot\Log\log_2007_08_11_07_35_44.log
C:\Program Files\SpywareBot\Log\log_2007_08_12_06_48_06.log
C:\Program Files\SpywareBot\Log\log_2007_08_13_05_48_07.log
C:\Program Files\SpywareBot\Log\log_2007_08_14_05_45_00.log
C:\Program Files\SpywareBot\Log\log_2007_08_14_13_31_39.log
C:\Program Files\SpywareBot\Log\log_2007_08_15_13_26_48.log
C:\Program Files\SpywareBot\Log\log_2007_08_16_06_21_59.log
C:\Program Files\SpywareBot\Log\log_2007_08_17_06_15_34.log
C:\Program Files\SpywareBot\Log\log_2007_08_18_10_11_59.log
C:\Program Files\SpywareBot\Log\log_2007_08_19_06_41_43.log
C:\Program Files\SpywareBot\Log\log_2007_08_20_05_30_22.log
C:\Program Files\SpywareBot\Log\log_2007_08_21_07_50_22.log
C:\Program Files\SpywareBot\Log\log_2007_08_22_13_36_20.log
C:\Program Files\SpywareBot\Log\log_2007_08_23_07_37_12.log
C:\Program Files\SpywareBot\Log\log_2007_08_23_07_49_30.log
C:\Program Files\SpywareBot\Log\log_2007_08_23_07_55_57.log
C:\Program Files\SpywareBot\Log\log_2007_08_24_07_09_55.log
C:\Program Files\SpywareBot\Log\log_2007_08_25_07_10_14.log
C:\Program Files\SpywareBot\Log\log_2007_08_27_13_58_58.log
C:\Program Files\SpywareBot\Log\log_2007_08_28_07_58_00.log
C:\Program Files\SpywareBot\Log\log_2007_08_29_07_02_03.log
C:\Program Files\SpywareBot\Log\log_2007_08_30_07_44_09.log
C:\Program Files\SpywareBot\Log\log_2007_08_31_13_10_06.log
C:\Program Files\SpywareBot\Log\log_2007_09_01_07_11_34.log
C:\Program Files\SpywareBot\Log\log_2007_09_04_07_43_10.log
C:\Program Files\SpywareBot\Log\log_2007_09_05_13_34_29.log
C:\Program Files\SpywareBot\Log\log_2007_09_06_07_43_50.log
C:\Program Files\SpywareBot\Log\log_2007_09_07_13_03_22.log
C:\Program Files\SpywareBot\Log\log_2007_09_08_07_52_54.log
C:\Program Files\SpywareBot\Log\log_2007_09_09_07_08_37.log
C:\Program Files\SpywareBot\Log\log_2007_09_10_06_39_18.log
C:\Program Files\SpywareBot\Log\log_2007_09_11_14_11_10.log
C:\Program Files\SpywareBot\Log\log_2007_09_11_17_13_38.log
C:\Program Files\SpywareBot\Log\log_2007_09_13_06_10_45.log
C:\Program Files\SpywareBot\Log\log_2007_09_14_02_55_38.log
C:\Program Files\SpywareBot\Log\log_2007_09_14_09_37_30.log
C:\Program Files\SpywareBot\Log\log_2007_09_15_07_34_38.log
C:\Program Files\SpywareBot\Log\log_2007_09_16_05_01_51.log
C:\Program Files\SpywareBot\Log\log_2007_09_16_09_17_31.log
C:\Program Files\SpywareBot\Log\log_2007_09_16_18_25_32.log
C:\Program Files\SpywareBot\Log\log_2007_09_16_18_31_48.log
C:\Program Files\SpywareBot\Log\log_2007_09_16_20_15_09.log
C:\Program Files\SpywareBot\Log\log_2007_09_16_21_06_47.log
C:\Program Files\SpywareBot\Log\log_2007_09_17_04_47_35.log
C:\Program Files\SpywareBot\Log\log_2007_09_17_21_59_18.log
C:\Program Files\SpywareBot\Log\log_2007_09_18_17_54_16.log
C:\Program Files\SpywareBot\Log\log_2007_09_19_17_56_08.log
C:\Program Files\SpywareBot\Log\log_2007_09_20_10_14_07.log
C:\Program Files\SpywareBot\Log\log_2007_09_21_06_12_31.log
C:\Program Files\SpywareBot\Log\log_2007_09_21_08_36_17.log
C:\Program Files\SpywareBot\Log\log_2007_09_22_08_29_52.log
C:\Program Files\SpywareBot\Log\log_2007_09_23_09_17_28.log
C:\Program Files\SpywareBot\Log\log_2007_09_24_07_47_22.log
C:\Program Files\SpywareBot\Log\log_2007_09_25_17_42_12.log
C:\Program Files\SpywareBot\Log\log_2007_09_26_13_41_50.log
C:\Program Files\SpywareBot\Log\log_2007_09_27_08_50_43.log
C:\Program Files\SpywareBot\Log\log_2007_09_28_07_49_26.log
C:\Program Files\SpywareBot\Log\log_2007_09_30_08_28_49.log
C:\Program Files\SpywareBot\Log\log_2007_09_30_19_47_37.log
C:\Program Files\SpywareBot\Log\log_2007_10_01_05_17_48.log
C:\Program Files\SpywareBot\Log\log_2007_10_01_07_49_25.log
C:\Program Files\SpywareBot\Log\log_2007_10_02_07_47_03.log
C:\Program Files\SpywareBot\Log\log_2007_10_02_17_30_53.log
C:\Program Files\SpywareBot\Log\log_2007_10_03_06_15_24.log
C:\Program Files\SpywareBot\Log\log_2007_10_04_07_44_25.log
C:\Program Files\SpywareBot\Log\log_2007_10_05_03_51_50.log
C:\Program Files\SpywareBot\Log\log_2007_10_05_07_39_30.log
C:\Program Files\SpywareBot\Log\log_2007_10_06_05_58_02.log
C:\Program Files\SpywareBot\Log\log_2007_10_08_06_53_44.log
C:\Program Files\SpywareBot\Log\log_2007_10_08_07_58_05.log
C:\Program Files\SpywareBot\Log\log_2007_10_09_08_01_46.log
C:\Program Files\SpywareBot\Log\log_2007_10_09_23_05_55.log
C:\Program Files\SpywareBot\Log\log_2007_10_10_07_49_55.log
C:\Program Files\SpywareBot\Log\log_2007_10_10_14_56_12.log
C:\Program Files\SpywareBot\Log\log_2007_10_10_15_02_43.log
C:\Program Files\SpywareBot\Log\log_2007_10_10_17_03_35.log
C:\Program Files\SpywareBot\Log\log_2007_10_11_05_27_50.log
C:\Program Files\SpywareBot\Log\log_2007_10_11_07_45_51.log
C:\Program Files\SpywareBot\Log\log_2007_10_12_05_29_46.log
C:\Program Files\SpywareBot\Log\log_2007_10_12_07_52_58.log
C:\Program Files\SpywareBot\Log\log_2007_10_14_08_17_56.log
C:\Program Files\SpywareBot\Log\log_2007_10_15_05_26_52.log
C:\Program Files\SpywareBot\Log\log_2007_10_15_17_27_38.log
C:\Program Files\SpywareBot\Log\log_2007_10_16_06_27_18.log
C:\Program Files\SpywareBot\Log\log_2007_10_16_07_55_35.log
C:\Program Files\SpywareBot\Log\log_2007_10_17_06_57_01.log
C:\Program Files\SpywareBot\Log\log_2007_10_17_09_16_08.log
C:\Program Files\SpywareBot\Log\log_2007_10_17_17_21_50.log
C:\Program Files\SpywareBot\Log\log_2007_10_18_04_39_08.log
C:\Program Files\SpywareBot\Log\log_2007_10_18_07_55_43.log
C:\Program Files\SpywareBot\Log\log_2007_10_19_11_44_00.log
C:\Program Files\SpywareBot\Log\log_2007_10_22_05_43_13.log
C:\Program Files\SpywareBot\Log\log_2007_10_22_07_43_54.log
C:\Program Files\SpywareBot\Log\log_2007_10_23_05_42_59.log
C:\Program Files\SpywareBot\Log\log_2007_10_23_07_47_54.log
C:\Program Files\SpywareBot\Log\log_2007_10_24_06_07_37.log
C:\Program Files\SpywareBot\Log\log_2007_10_24_17_35_14.log
C:\Program Files\SpywareBot\Log\log_2007_10_24_20_05_48.log
C:\Program Files\SpywareBot\Log\log_2007_10_25_06_31_08.log
C:\Program Files\SpywareBot\Log\log_2007_10_25_17_27_48.log
C:\Program Files\SpywareBot\Log\log_2007_10_26_07_36_37.log
C:\Program Files\SpywareBot\Log\log_2007_10_27_09_13_20.log
C:\Program Files\SpywareBot\Log\log_2007_10_28_18_14_25.log
C:\Program Files\SpywareBot\Log\log_2007_10_29_07_38_05.log
C:\Program Files\SpywareBot\Log\log_2007_10_29_14_54_41.log
C:\Program Files\SpywareBot\Log\log_2007_10_30_06_06_09.log
C:\Program Files\SpywareBot\Log\log_2007_10_30_07_46_37.log
C:\Program Files\SpywareBot\Log\log_2007_10_30_08_33_11.log
C:\Program Files\SpywareBot\Log\log_2007_10_30_11_02_46.log
C:\Program Files\SpywareBot\Log\log_2007_10_31_06_05_43.log
C:\Program Files\SpywareBot\Log\log_2007_10_31_17_31_45.log
C:\Program Files\SpywareBot\Log\log_2007_11_01_05_40_55.log
C:\Program Files\SpywareBot\Log\log_2007_11_01_08_00_36.log
C:\Program Files\SpywareBot\Log\log_2007_11_02_06_32_36.log
C:\Program Files\SpywareBot\Log\log_2007_11_02_08_03_05.log
C:\Program Files\SpywareBot\Log\log_2007_11_04_06_57_29.log
C:\Program Files\SpywareBot\Log\log_2007_11_05_05_25_11.log
C:\Program Files\SpywareBot\Log\log_2007_11_05_19_03_24.log
C:\Program Files\SpywareBot\Log\log_2007_11_06_06_06_04.log
C:\Program Files\SpywareBot\Log\log_2007_11_06_07_13_56.log
C:\Program Files\SpywareBot\Log\log_2007_11_06_08_55_59.log
C:\Program Files\SpywareBot\Log\log_2007_11_07_06_13_16.log
C:\Program Files\SpywareBot\Log\log_2007_11_07_17_46_30.log
C:\Program Files\SpywareBot\Log\log_2007_11_08_05_55_05.log
C:\Program Files\SpywareBot\Log\log_2007_11_08_07_50_41.log
C:\Program Files\SpywareBot\Log\log_2007_11_09_06_20_13.log
C:\Program Files\SpywareBot\Log\log_2007_11_09_07_35_41.log
C:\Program Files\SpywareBot\Log\log_2007_11_10_02_43_15.log
C:\Program Files\SpywareBot\Log\log_2007_11_10_08_25_03.log
C:\Program Files\SpywareBot\Log\log_2007_11_11_14_21_59.log
C:\Program Files\SpywareBot\Log\log_2007_11_12_05_36_55.log
C:\Program Files\SpywareBot\Log\log_2007_11_12_17_46_44.log
C:\Program Files\SpywareBot\Log\log_2007_11_13_06_41_15.log
C:\Program Files\SpywareBot\Log\log_2007_11_13_07_44_01.log
C:\Program Files\SpywareBot\Log\log_2007_11_14_06_00_54.log
C:\Program Files\SpywareBot\Log\log_2007_11_14_17_30_46.log
C:\Program Files\SpywareBot\Log\log_2007_11_15_06_20_37.log
C:\Program Files\SpywareBot\Log\log_2007_11_15_07_38_51.log
C:\Program Files\SpywareBot\Log\log_2007_11_16_05_32_38.log
C:\Program Files\SpywareBot\Log\log_2007_11_16_07_39_38.log
C:\Program Files\SpywareBot\Log\log_2007_11_17_09_22_44.log
C:\Program Files\SpywareBot\Log\log_2007_11_18_07_52_58.log
C:\Program Files\SpywareBot\Log\log_2007_11_19_05_41_57.log
C:\Program Files\SpywareBot\Log\log_2007_11_19_07_10_17.log
C:\Program Files\SpywareBot\Log\log_2007_11_19_14_39_53.log
C:\Program Files\SpywareBot\Log\log_2007_11_20_06_11_35.log
C:\Program Files\SpywareBot\Log\log_2007_11_20_07_45_44.log
C:\Program Files\SpywareBot\Log\log_2007_11_21_06_06_02.log
C:\Program Files\SpywareBot\Log\log_2007_11_21_17_37_03.log
C:\Program Files\SpywareBot\Log\log_2007_11_23_08_38_20.log
C:\Program Files\SpywareBot\Log\log_2007_11_24_07_53_06.log
C:\Program Files\SpywareBot\Log\log_2007_11_25_08_26_39.log
C:\Program Files\SpywareBot\Log\log_2007_11_25_17_05_48.log
C:\Program Files\SpywareBot\Log\log_2007_11_25_22_13_49.log
C:\Program Files\SpywareBot\Log\log_2007_11_25_22_33_32.log
C:\Program Files\SpywareBot\Log\log_2007_11_26_07_02_06.log
C:\Program Files\SpywareBot\Log\log_2007_11_26_17_20_52.log
C:\Program Files\SpywareBot\Log\log_2007_11_27_07_38_45.log
C:\Program Files\SpywareBot\Log\log_2007_11_27_18_21_49.log
C:\Program Files\SpywareBot\Log\log_2007_11_28_17_02_12.log
C:\Program Files\SpywareBot\Log\log_2007_11_29_06_43_08.log
C:\Program Files\SpywareBot\Log\log_2007_11_30_07_36_15.log
C:\Program Files\SpywareBot\Log\log_2007_11_30_18_27_57.log
C:\Program Files\SpywareBot\Log\log_2007_11_30_18_51_43.log
C:\Program Files\SpywareBot\Log\log_2007_11_30_19_47_08.log
C:\Program Files\SpywareBot\Log\log_2007_12_01_08_08_23.log
C:\Program Files\SpywareBot\Log\log_2007_12_01_09_17_08.log
C:\Program Files\SpywareBot\Log\spywarelog.txt
C:\Program Files\SpywareBot\Settings\CustomScan.stg
C:\Program Files\SpywareBot\Settings\IgnoreList.stg
C:\Program Files\SpywareBot\Settings\ScanInfo.stg
C:\Program Files\SpywareBot\Settings\ScanResults.stg
C:\Program Files\SpywareBot\Settings\SelectedFolders.stg
C:\Program Files\SpywareBot\Settings\Settings.stg
C:\Program Files\SpywareBot\SpywareBot.exe
C:\WINDOWS\dat.txt
C:\WINDOWS\gormet.dll
C:\WINDOWS\main_uninstaller.exe
C:\WINDOWS\monhop.exe
C:\WINDOWS\msmdev.dll
C:\WINDOWS\msmhost.dll
C:\WINDOWS\nsduo.dll
C:\WINDOWS\pmkret.dll
C:\WINDOWS\rs.txt

.
((((((((((((((((((((((((( Files Created from 2007-11-01 to 2007-12-01 )))))))))))))))))))))))))))))))
.

2007-12-01 09:13 . 2004-08-10 07:00 185,856 –a—— C:\WINDOWS\system32\framedyn.dll
2007-11-30 18:57 . 2007-11-30 18:57 d——– C:\Program Files\Trend Micro
2007-11-30 13:13 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-30 12:40 . 2007-11-30 12:40 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-30 12:38 . 2007-11-30 12:38 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-11-30 08:06 . 2007-11-30 08:07 125 –a—— C:\ioSpecial.ini
2007-11-28 23:17 . 2007-11-28 23:17 d——– C:\Documents and Settings\HP_Administrator\Application Data\Jane s Hotel

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-01 16:51 ——— d—–w C:\Program Files\WildTangent
2007-12-01 13:11 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-30 17:40 ——— d—–w C:\Program Files\Lavasoft
2007-11-30 17:36 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-30 13:06 ——— d—–w C:\Program Files\Wedding Dash
2007-10-25 23:28 ——— d—–w C:\Program Files\Burger Shop
2007-10-18 22:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\NannyMania
2007-10-18 22:18 ——— d—–w C:\Program Files\Shockwave.com
2007-10-10 22:13 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\PlayFirst
2007-07-29 15:02 52,744 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
2006-01-27 19:32 0 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((( snapshot@2007-12-01_ 9.18.36.42 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-01 01:40:31 43,520 —-a-w C:\WINDOWS\system32\CmdLineExt03.dll
+ 2007-12-01 14:58:15 43,520 —-a-w C:\WINDOWS\system32\CmdLineExt03.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"Express ClickYes"="C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe" [2005-07-27 03:39]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-20 11:51]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 14:04]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 18:35]
"PCDrProfiler"="" []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-10-05 18:06]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [2005-03-29 12:03]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 17:34]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-10 12:50]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 01:12]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-10-10 11:50]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-12-20 20:53]
"SpywareBot"="C:\Program Files\SpywareBot\SpywareBot.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 18:05]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 01:23:26]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
Updates from HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2005-10-10 12:10:07]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme


.
Contents of the 'Scheduled Tasks' folder
"2007-11-27 17:31:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-01 02:27:56 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - HP_Administrator.job"
- c:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task:
"2007-12-01 14:06:32 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-01 12:11:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-01 12:12:26 - machine was rebooted
C:\ComboFix2.txt … 2007-12-01 09:18
.
— E O F —




2) First run of Step C - HJT log with Norton Antivirus Enabled

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:13:55 PM, on 12/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.87.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/bingame/dsh2/default/D…h2.1.0.0.68.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135130886812
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/bingame/dash/default/D…sh.1.0.0.94.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://www.shockwave.com/content/weddingda…sh.1.0.0.47.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)

–
End of file - 10563 bytes



3) Second run of Step C - combofix log with Norton Antivirus Disabled.

ComboFix 07-12-01.4 - HP_Administrator 2007-12-01 12:24:31.3 - NTFSx86

Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Administrator\Desktop\CFScript.txt

FILE
C:\Program Files\PartyGaming
C:\WINDOWS\gormet.dll
C:\WINDOWS\hdtip.dll
C:\WINDOWS\monhop.exe
C:\WINDOWS\pmkret.dll
.

((((((((((((((((((((((((( Files Created from 2007-11-01 to 2007-12-01 )))))))))))))))))))))))))))))))
.

2007-12-01 09:13 . 2004-08-10 07:00 185,856 –a—— C:\WINDOWS\system32\framedyn.dll
2007-11-30 18:57 . 2007-11-30 18:57 d——– C:\Program Files\Trend Micro
2007-11-30 13:13 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-30 12:40 . 2007-11-30 12:40 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-30 12:38 . 2007-11-30 12:38 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-11-30 08:06 . 2007-11-30 08:07 125 –a—— C:\ioSpecial.ini
2007-11-28 23:17 . 2007-11-28 23:17 d——– C:\Documents and Settings\HP_Administrator\Application Data\Jane s Hotel

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-01 16:51 ——— d—–w C:\Program Files\WildTangent
2007-12-01 13:11 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-30 17:40 ——— d—–w C:\Program Files\Lavasoft
2007-11-30 17:36 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-30 13:06 ——— d—–w C:\Program Files\Wedding Dash
2007-10-25 23:28 ——— d—–w C:\Program Files\Burger Shop
2007-10-18 22:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\NannyMania
2007-10-18 22:18 ——— d—–w C:\Program Files\Shockwave.com
2007-10-10 22:13 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\PlayFirst
2007-07-29 15:02 52,744 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
2006-01-27 19:32 0 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((( snapshot@2007-12-01_ 9.18.36.42 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-01 01:40:31 43,520 —-a-w C:\WINDOWS\system32\CmdLineExt03.dll
+ 2007-12-01 14:58:15 43,520 —-a-w C:\WINDOWS\system32\CmdLineExt03.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"Express ClickYes"="C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe" [2005-07-27 03:39]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-20 11:51]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 14:04]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 18:35]
"PCDrProfiler"="" []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-10-05 18:06]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [2005-03-29 12:03]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 17:34]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-10 12:50]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 01:12]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-10-10 11:50]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-12-20 20:53]
"SpywareBot"="C:\Program Files\SpywareBot\SpywareBot.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 18:05]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 01:23:26]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
Updates from HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2005-10-10 12:10:07]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme


.
Contents of the 'Scheduled Tasks' folder
"2007-11-27 17:31:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-01 02:27:56 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - HP_Administrator.job"
- c:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task:
"2007-12-01 14:06:32 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-01 12:29:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-01 12:30:26 - machine was rebooted
C:\ComboFix2.txt … 2007-12-01 12:12
C:\ComboFix3.txt … 2007-12-01 09:18
.
— E O F —



4) Second run of Step C - HJT log with Norton Antivirus Disnabled

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:04 PM, on 12/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.87.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/bingame/dsh2/default/D…h2.1.0.0.68.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135130886812
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/bingame/dash/default/D…sh.1.0.0.94.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://www.shockwave.com/content/weddingda…sh.1.0.0.47.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)

–
End of file - 10497 bytes
Things are starting to look pretty darn good. A couple of registry changes still need to be made but we will do them when we have looked at your whole system. So far, what we were able to see is now malware free. However, the rest of your system may be harboring some "baddies" that are just waiting to get into action so it is best that we give your whole system a good once over and remove and lurkers. This scan takes about an hour so you can go have a coffee.

Please use the Internet Explorer browser, and do an online scan with Kaspersky Online Scanner
Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click on Scan Settings and configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:Scan Archives
      Scan Mail Bases
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
[external image: Posted Image]
[external image: Posted Image]
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply, along with a fresh HijackThis log
Hey Trevuren,

Glad to hear we are progressing. I've attached the Kscan and a new HJT log:

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, December 01, 2007 8:11:17 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 1/12/2007
Kaspersky Anti-Virus database records: 470005
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan Statistics:
Total number of scanned objects: 96030
Number of viruses found: 6
Number of infected objects: 9
Number of suspicious objects: 0
Duration of the scan process: 01:37:11

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped
C:\Documents and Settings\HP_Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nRT.jar-2e8f809-43121e47.zip/HiPointInstallShieldRT.class Infected: Trojan-Downloader.Java.OpenConnection.ap skipped
C:\Documents and Settings\HP_Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nRT.jar-2e8f809-43121e47.zip ZIP: infected - 1 skipped
C:\Documents and Settings\HP_Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nRT.jar-53fab40d-2d115bd9.zip/HiPointInstallShieldRT.class Infected: Trojan-Downloader.Java.OpenConnection.ap skipped
C:\Documents and Settings\HP_Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nRT.jar-53fab40d-2d115bd9.zip ZIP: infected - 1 skipped
C:\Documents and Settings\HP_Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\History\History.IE5\MSHist012007120120071202\index.dat Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\iMSPQMn.sys Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\_hphtra07.log Object is locked skipped
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\HP_Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\AntiSpam\Log\Spam.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Savrt\0932NAV~.TMP Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Savrt\0937NAV~.TMP Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\chandir.dat Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\chandir.idx Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\chn.dat Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\chn.idx Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\D0000000.FCS Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\inuse.txt Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\L0000011.FCS Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\main.log Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\prs.dat Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\prs.idx Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\prs_die.dat Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\prs_die.idx Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\prs_dnd.dat Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\prs_dnd.idx Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\prs_ext.dat Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\prs_ext.idx Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\prs_rcv.dat Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\prs_rcv.idx Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\storydb.dat Object is locked skipped
C:\Program Files\Updates from HP\9972322\Users\Default\Data\storydb.idx Object is locked skipped
C:\qoobox\Quarantine\C\WINDOWS\main_uninstaller.exe.vir Infected: Trojan-Downloader.Win32.Zlob.cpx skipped
C:\qoobox\Quarantine\C\WINDOWS\msmdev.dll.vir Infected: Trojan-Downloader.Win32.Agent.dag skipped
C:\qoobox\Quarantine\C\WINDOWS\msmhost.dll.vir Infected: not-a-virus:AdWare.Win32.Agent.jw skipped
C:\qoobox\Quarantine\C\WINDOWS\nsduo.dll.vir Infected: not-a-virus:AdWare.Win32.Agent.kc skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{D7BD54B8-C977-4903-8CE7-9415B851EC71}\RP598\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Downloaded Program Files\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{61C37434-EE56-451F-A783-6DB6E9D8D753}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


________________________________________


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:11:48 PM, on 12/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Atari\Axis & Allies\AA.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.87.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/bingame/dsh2/default/D…h2.1.0.0.68.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135130886812
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/bingame/dash/default/D…sh.1.0.0.94.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://www.shockwave.com/content/weddingda…sh.1.0.0.47.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)

–
End of file - 10854 bytes
Looking good. A few deletions and an update and that should do it.

A. Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. A malicious site could render Java content under older, vulnerable versions of Sun's software if the user has not removed them. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 3 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u3…allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Read the License Agreement and then check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel > Add/Remove Programs, double-click on and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.

Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.


B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\Downloaded Program Files\popcaploader.dll

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareBot"=-


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.


C. Please tell me how your system is running. If all seems OK, we will be able to proceed with the final cleanup procedures.


Trevuren
Hey Trevuren,

Overall, my system seems to boot fine and IE goes to my home page in the usual 3 to 4 seconds. The problems I was having yesterday appear to be gone. Thank you very much for your help. Logs follow:

ComboFix 07-12-01.4 - HP_Administrator 2007-12-01 21:47:11.4 - NTFSx86

Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Administrator\Desktop\CFScript.txt

FILE
C:\WINDOWS\Downloaded Program Files\popcaploader.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\Downloaded Program Files\popcaploader.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-02 to 2007-12-02 )))))))))))))))))))))))))))))))
.

2007-12-01 21:40 . 2007-12-01 21:40 d——– C:\Program Files\Sun
2007-12-01 21:40 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2007-12-01 21:37 . 2007-12-01 21:37 d——– C:\Program Files\Common Files\Java
2007-12-01 16:42 . 2007-12-01 16:42 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-12-01 16:42 . 2007-12-01 16:42 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-01 09:13 . 2004-08-10 07:00 185,856 –a—— C:\WINDOWS\system32\framedyn.dll
2007-11-30 18:57 . 2007-11-30 18:57 d——– C:\Program Files\Trend Micro
2007-11-30 13:13 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-30 12:40 . 2007-11-30 12:40 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-30 12:38 . 2007-11-30 12:38 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-11-30 08:06 . 2007-11-30 08:07 125 –a—— C:\ioSpecial.ini
2007-11-28 23:17 . 2007-11-28 23:17 d——– C:\Documents and Settings\HP_Administrator\Application Data\Jane s Hotel

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-02 02:40 ——— d—–w C:\Program Files\Java
2007-12-01 16:51 ——— d—–w C:\Program Files\WildTangent
2007-12-01 13:11 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-30 17:40 ——— d—–w C:\Program Files\Lavasoft
2007-11-30 17:36 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-30 13:06 ——— d—–w C:\Program Files\Wedding Dash
2007-10-25 23:28 ——— d—–w C:\Program Files\Burger Shop
2007-10-18 22:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\NannyMania
2007-10-18 22:18 ——— d—–w C:\Program Files\Shockwave.com
2007-10-10 22:13 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\PlayFirst
2007-07-29 15:02 52,744 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
2006-01-27 19:32 0 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((( snapshot@2007-12-01_ 9.18.36.42 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-01 01:40:31 43,520 —-a-w C:\WINDOWS\system32\CmdLineExt03.dll
+ 2007-12-01 23:01:04 43,520 —-a-w C:\WINDOWS\system32\CmdLineExt03.dll
- 2005-10-10 16:24:38 49,245 —-a-w C:\WINDOWS\system32\java.exe
+ 2007-09-25 03:30:28 135,168 —-a-w C:\WINDOWS\system32\java.exe
- 2005-10-10 16:24:38 49,247 —-a-w C:\WINDOWS\system32\javaw.exe
+ 2007-09-25 03:30:30 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
- 2005-10-10 16:24:38 127,075 —-a-w C:\WINDOWS\system32\javaws.exe
+ 2007-09-25 04:31:42 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
+ 2005-05-24 17:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"Express ClickYes"="C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe" [2005-07-27 03:39]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-20 11:51]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 14:04]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 18:35]
"PCDrProfiler"="" []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-10-05 18:06]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [2005-03-29 12:03]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 17:34]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-10 12:50]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 01:12]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-10-10 11:50]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-12-20 20:53]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 18:05]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 01:23:26]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
Updates from HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2005-10-10 12:10:07]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme


.
Contents of the 'Scheduled Tasks' folder
"2007-11-27 17:31:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-01 02:27:56 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - HP_Administrator.job"
- c:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task:
"2007-12-02 02:06:36 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-01 21:50:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-01 21:52:23 - machine was rebooted
C:\ComboFix2.txt … 2007-12-01 12:30
C:\ComboFix3.txt … 2007-12-01 12:12
.
— E O F —


____________________________________________________________


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:53:18 PM, on 12/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.87.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/bingame/dsh2/default/D…h2.1.0.0.68.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135130886812
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/bingame/dash/default/D…sh.1.0.0.94.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://www.shockwave.com/content/weddingda…sh.1.0.0.47.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)

–
End of file - 10780 bytes
Congratulations, your logs look CLEAN

There are a few things you must do once you system is completely clean:

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK


    • [external image: Posted Image]

  • When shown the disclaimer, Select "2"

The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.


Here are some tips to reduce the potential for spyware infection in the future:

1. Make sure you keep your Windows OS currentby visiting Windows update
regularly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.

2. I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
And also see TonyKlein's good advice
So how did I get infected in the first place?

Regards,

Trevuren
Hey Trevuren,

Thanks for your help. From your last post:

I ran combofix /u. It did not show me the disclaimer so I did not end up selecting "2". However, I did get a message that combofix was uninstalled.

I successfully installed by Spywareblaster and Spywareguard. I have previously installed Ad-Aware. I installed and ran Spybot; however, after it ran I was directed to register for $19.95. I'll gladly pay based upon your recommendation; however, I just wanted to make sure I ended up in the correct place and actually needed to pay.

IE/Spyad seems to have been replaced by ZonedOut. I'm not sure if I got that program (file?) properly installed.

I downloaded the MVPS Hosts file; however, I'm not yet surre if I have that file properly installed.

That said, I did scan Tony Klein's site and it looks like the answers to the above questions will be found there.

Overall, thank you for making my computer clean-up so easy (for me). I've attached one final HJT log.

Good luck to you in the future.

Bill




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:04:11 PM, on 12/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\SpywareBot\SpywareBot.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot (User '?')
O4 - S-1-5-21-1682608480-3281464113-478786595-1008 Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe (User '?')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.87.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/bingame/dsh2/default/D…h2.1.0.0.68.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135130886812
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/bingame/dash/default/D…sh.1.0.0.94.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://www.shockwave.com/content/weddingda…sh.1.0.0.47.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)

–
End of file - 11497 bytes
You have apparently picked up that SpywareBot again.

Please RUN HijackThis.
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:
    O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
    O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot (User '?')
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

  • Using Windows Explorer (Windows Key + E), locate the following folder, and DELETE it (if still present):

    C:\Program Files\SpywareBot<==Folder and all its content.

  • Exit Explorer, and REBOOT your machine

  • Finally, RUN Hijackthis again and produce a new HJT log. Post it in the forum so we can check how everything looks now.

Regards,

Trevuren
Hey Trevuren,

Once again thanks for your help………

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:05:49 PM, on 12/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [Express ClickYes] C:\Program Files\Microsoft Office\Office10\Library\Express ClickYes\ClickYes.exe (User '?')
O4 - HKUS\S-1-5-21-1682608480-3281464113-478786595-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - S-1-5-21-1682608480-3281464113-478786595-1008 Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe (User '?')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.87.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/bingame/dsh2/default/D…h2.1.0.0.68.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135130886812
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/bingame/dash/default/D…sh.1.0.0.94.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://www.shockwave.com/content/weddingda…sh.1.0.0.47.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)

–
End of file - 11060 bytes
1. Ie-Spyad has changed their format unfortunately. I still recommend that you go with the ZonedOut version. 2. If you are looking for full time protection/guard and have a few bucks to spend, I would not use Tea Timer that comes with Spybot but I would choose something as simple as SuperAntisoayware or AVG AS. Good Luck and Safe Surfing. Trevuren

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI