gentleman27us
Topic Starter
Hi,
My system is running very slow..Though I have Pop-up blocker, I still get lot of pop-ups (setthetrend etc..). The typing (on any web application) is really frustating. CPU hits 100% almost all the time. This is becoming a nightmare.
PLEASE HELP.. I am posting HIJACKTHIS, COMBOFIX & INSTALL logs for your kind reference. Please review and suggest a remedy. I appreciate it.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:17:44 PM, on 12/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WZCBDL Service\WZCBDLS.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\JYO\Application Data\Mozilla\Profiles\default\fal84umo.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\JYO\Application Data\Mozilla\Profiles\default\fal84umo.slt\prefs.js)
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1196641397591
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: WZCBDL Service (WZCBDLService) - D-Link - C:\Program Files\WZCBDL Service\WZCBDLS.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
____________________________________________
COMBOFIX
_____________________________________________
ComboFix 07-12-02.6 - Jyo 2007-12-03 21:36:08.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.145 [GMT -6:00]
Running from: C:\Downloads\SJ - ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Program Files\SideFind
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\axpxmqgz.dllbox
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\ixyadqqv.dllbox
C:\WINDOWS\system32\ldcore.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rMa02yy
C:\WINDOWS\system32\zcomegrz.dllbox
C:\WINDOWS\uninst2.htm
C:\WINDOWS\unist1.htm
.
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.
2007-12-03 21:17 . 2007-12-03 21:17 d——– C:\Program Files\Trend Micro
2007-12-03 16:43 . 2007-12-03 16:43 d——– C:\WINDOWS\SYSTEM32\daSgo06
2007-12-03 11:55 . 2007-12-03 11:55 d——– C:\Documents and Settings\Jyo\Application Data\McAfee
2007-12-02 20:23 . 2007-12-02 20:30 d——– C:\Documents and Settings\Jyo\Application Data\AVG7
2007-12-02 20:22 . 2007-12-02 20:22 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-02 20:22 . 2007-12-02 20:22 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-02 20:22 . 2007-12-02 20:25 d——– C:\Documents and Settings\All Users\Application Data\avg7
2007-12-02 13:49 . 2007-12-02 13:52 d–h—– C:\WINDOWS\msdownld.tmp
2007-12-02 12:20 . 2006-11-07 21:01 66,048 –a—— C:\WINDOWS\ieResetIcons.exe
2007-12-02 10:14 . 2007-12-02 10:26 d——– C:\Documents and Settings\Jyo\Application Data\RegClean
2007-12-02 09:44 . 2007-12-02 09:44 d——– C:\Program Files\Windows Installer Clean Up
2007-12-02 09:43 . 2007-12-02 09:43 d——– C:\Program Files\MSECACHE
2007-12-02 09:08 . 2007-12-02 20:26 1,200,226 –ahs—- C:\WINDOWS\SYSTEM32\ybbuoama.ini
2007-12-02 08:39 . 2007-12-02 08:39 d——– C:\WINDOWS\SYSTEM32\daSgo02
2007-12-02 08:39 . 2007-12-02 08:39 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2007-12-02 08:39 . 2007-12-02 08:39 d——– C:\Documents and Settings\Administrator.JYO.000\Application Data\Symantec
2007-12-02 08:39 . 2007-12-02 08:39 d——– C:\Documents and Settings\Administrator.JYO.000\Application Data\Jasc Software Inc
2007-12-01 22:18 . 2004-01-02 04:16 d——– C:\Documents and Settings\Administrator.JYO.000\Application Data\Sonic
2007-12-01 14:19 . 2007-12-02 08:39 d——– C:\Program Files\Spruce
2007-12-01 10:41 . 2007-12-01 10:41 78,400 –a—— C:\WINDOWS\SYSTEM32\kpnyihwv.dll
2007-12-01 10:35 . 2007-12-02 08:44 1,322,574 –ahs—- C:\WINDOWS\SYSTEM32\tgijcsuw.ini
2007-11-30 10:32 . 2007-12-03 21:48 634,264 –ahs—- C:\WINDOWS\SYSTEM32\yxyay.ini2
2007-11-30 10:32 . 2007-12-03 21:49 634,264 –ahs—- C:\WINDOWS\SYSTEM32\yxyay.ini
2007-11-30 10:32 . 2007-11-30 10:32 324,192 –a—— C:\WINDOWS\SYSTEM32\yayxy.dll
2007-11-30 08:06 . 2007-11-30 08:06 d——– C:\temp\bkR11
2007-11-28 23:51 . 2007-12-02 08:39 d——– C:\Program Files\Security Task Manager
2007-11-28 23:51 . 2007-12-02 08:39 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2007-11-27 18:21 . 2007-11-27 18:21 d——– C:\Program Files\Ashampoo
2007-11-27 18:14 . 2007-11-27 18:14 d——– C:\Documents and Settings\Jyo\Application Data\EagleEyeOS
2007-11-27 18:05 . 2007-12-02 22:37 d——– C:\Desktop_Nov 27 07
2007-11-26 22:07 . 2007-11-26 22:08 d——– C:\Documents and Settings\Jyo\Application Data\Move Networks
2007-11-26 18:49 . 2007-11-26 18:51 d——– C:\SAPBW
2007-11-22 14:35 . 2007-11-26 18:55 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-22 14:02 . 2007-12-01 07:58 679,599 –ahs—- C:\WINDOWS\SYSTEM32\uuypnhkc.ini
2007-11-20 05:54 . 2007-11-22 13:59 979,595 –ahs—- C:\WINDOWS\SYSTEM32\cpwlbcpr.ini
2007-11-18 17:42 . 2007-11-18 17:46 4,654 –a—— C:\WINDOWS\SYSTEM32\tmp.reg
2007-11-18 17:09 . 2007-11-20 05:47 694,442 –ahs—- C:\WINDOWS\SYSTEM32\ripcihsh.ini
2007-11-18 17:06 . 2007-11-18 17:09 d——– C:\Nov2007
2007-11-18 16:00 . 2007-11-18 16:00 d——– C:\Ultimate Pkmn Explode
2007-11-18 15:16 . 2004-01-02 04:16 d——– C:\Documents and Settings\Administrator.JYO\Application Data\Sonic
2007-11-18 14:23 . 2007-11-18 14:24 0 –a—— C:\WINDOWS\SYSTEM32\mcrh.tmp
2007-11-18 08:59 . 2007-11-18 09:00 d——– C:\Documents and Settings\Jyo\Application Data\SpywareBot
2007-11-17 12:30 . 2007-11-22 14:03 436,027 –ahs—- C:\WINDOWS\SYSTEM32\ehjjl.ini2
2007-11-17 12:30 . 2007-11-22 14:03 0 –ahs—- C:\WINDOWS\SYSTEM32\ehjjl.ini
2007-11-16 11:20 . 2007-11-16 11:20 208,896 –a—— C:\WINDOWS\io43mvuiw4kj.exe
2007-11-10 08:10 . 2003-02-28 18:26 139,536 –a—— C:\WINDOWS\SYSTEM32\javaee.dll
2007-11-10 07:36 . 2007-11-10 07:36 d——– C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-08 00:24 . 2007-01-08 19:07 991,232 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
2007-11-07 23:03 . 2007-07-09 07:16 582,656 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\rpcrt4.dll
2007-11-07 17:46 . 2007-11-07 17:46 d——– C:\Documents and Settings\Jyo\Application Data\Motive
2007-11-04 12:38 . 2007-01-31 09:58 43,387 –a—— C:\WINDOWS\browser.exe
2007-11-04 12:38 . 2007-01-31 09:58 6,246 –a—— C:\WINDOWS\atty.ico
2007-11-04 12:37 . 2007-11-04 12:37 d——– C:\WINDOWS\Motive
2007-11-04 12:37 . 2007-11-07 17:47 d——– C:\Program Files\Common Files\Motive
2007-11-04 12:37 . 2007-11-04 12:37 d——– C:\Documents and Settings\All Users\Application Data\Motive
2007-11-04 12:37 . 2005-05-10 00:36 81,920 –a—— C:\WINDOWS\SYSTEM32\W32n50.dll
2007-11-04 12:37 . 2005-05-10 00:36 17,162 –a—— C:\WINDOWS\SYSTEM32\Pcandis5.sys
2007-11-04 12:37 . 2005-05-10 00:36 16,848 –a—— C:\WINDOWS\SYSTEM32\Pcandis4.sys
2007-11-04 12:37 . 2005-05-10 00:36 16,073 –a—— C:\WINDOWS\SYSTEM32\Pcandis3.vxd
2007-11-04 12:34 . 2007-11-07 17:47 d——– C:\Program Files\SBC Self Support Tool
2007-11-04 12:30 . 2003-05-19 16:07 86,016 –a—— C:\WINDOWS\SYSTEM32\YPcservice.exe
2007-11-04 12:24 . 2002-01-05 06:18 84,992 –a—— C:\WINDOWS\SYSTEM32\ATL70.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-03 17:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-02 19:49 ——— d—–w C:\Program Files\Google
2007-11-29 05:58 ——— d—–w C:\Documents and Settings\Jyo\Application Data\Apple Computer
2007-11-28 21:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2007-11-28 15:07 ——— d—–w C:\Program Files\Common Files\Adobe
2007-11-18 22:14 ——— d—–w C:\Program Files\Winamp
2007-11-18 22:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-08 01:57 ——— d—–w C:\Program Files\DivX
2007-11-04 19:23 ——— d—–w C:\Program Files\McAfee
2007-11-04 18:29 ——— d–h–r C:\Documents and Settings\Jyo\Application Data\yahoo!
2007-11-04 18:29 ——— d—–w C:\Program Files\Yahoo!
2007-11-04 18:01 155,995 —-a-w C:\WINDOWS\Java\Packages\R1R71NDB.ZIP
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-10-20 00:56 524,288 —-a-w C:\WINDOWS\SYSTEM32\DivXsm.exe
2007-10-20 00:56 43,528 —-a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-10-20 00:56 3,596,288 —-a-w C:\WINDOWS\SYSTEM32\qt-dx331.dll
2007-10-20 00:56 200,704 —-a-w C:\WINDOWS\SYSTEM32\ssldivx.dll
2007-10-20 00:56 129,784 —-a-w C:\WINDOWS\SYSTEM32\pxafs.dll
2007-10-20 00:56 120,056 —-a-w C:\WINDOWS\SYSTEM32\pxcpyi64.exe
2007-10-20 00:56 118,520 —-a-w C:\WINDOWS\SYSTEM32\pxinsi64.exe
2007-10-20 00:56 1,044,480 —-a-w C:\WINDOWS\SYSTEM32\libdivx.dll
2007-10-20 00:54 823,296 —-a-w C:\WINDOWS\SYSTEM32\divx_xx0c.dll
2007-10-20 00:54 823,296 —-a-w C:\WINDOWS\SYSTEM32\divx_xx07.dll
2007-10-20 00:54 81,920 —-a-w C:\WINDOWS\SYSTEM32\dpl100.dll
2007-10-20 00:54 802,816 —-a-w C:\WINDOWS\SYSTEM32\divx_xx11.dll
2007-10-20 00:54 739,840 —-a-w C:\WINDOWS\SYSTEM32\DivX.dll
2007-10-20 00:54 196,608 —-a-w C:\WINDOWS\SYSTEM32\dtu100.dll
2007-10-18 09:06 156,992 —-a-w C:\WINDOWS\SYSTEM32\DivXCodecVersionChecker.exe
2007-10-18 09:03 593,920 —-a-w C:\WINDOWS\SYSTEM32\dpuGUI11.dll
2007-10-18 09:03 57,344 —-a-w C:\WINDOWS\SYSTEM32\dpv11.dll
2007-10-18 09:03 53,248 —-a-w C:\WINDOWS\SYSTEM32\dpuGUI10.dll
2007-10-18 09:03 344,064 —-a-w C:\WINDOWS\SYSTEM32\dpus11.dll
2007-10-18 09:03 294,912 —-a-w C:\WINDOWS\SYSTEM32\dpu11.dll
2007-10-18 09:03 294,912 —-a-w C:\WINDOWS\SYSTEM32\dpu10.dll
2007-10-18 09:02 12,288 —-a-w C:\WINDOWS\SYSTEM32\DivXWMPExtType.dll
2007-10-14 22:30 170 —-a-w C:\Program Files\1bomb.ini
2007-09-12 18:52 53,248 —-a-w C:\WINDOWS\hg173.exe
2007-09-12 18:50 53,248 —-a-w C:\WINDOWS\df87173.exe
2007-07-15 20:06 194,376 —-a-w C:\Documents and Settings\Jyo\Application Data\shb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1e17f4bc-fafe-4b56-a5e3-81c75ef991b1}]
C:\WINDOWS\system32\ehankhov.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3E9E94B1-D85D-42DE-B281-9C1CA3372A42}]
2007-11-30 10:32 324192 –a—— C:\WINDOWS\system32\yayxy.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54DE7259-C729-45B1-BBD8-4BE9B5BD8248}]
2007-11-29 10:28 401408 –a—— C:\Program Files\Spruce\Spruce.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8E3FBDE2-7DBD-4040-85D9-29BBC559C129}]
C:\WINDOWS\system32\nnnnnkl.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-12 18:21]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RegistryMechanic"="" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-02 20:22]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-02 20:22]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{8E3FBDE2-7DBD-4040-85D9-29BBC559C129}"= C:\WINDOWS\system32\nnnnnkl.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnnnkl]
nnnnnkl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= c:\windows\system32\ldcore.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\yayxy.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^D-Link AirPlus Xtreme G Configuration Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\D-Link AirPlus Xtreme G Configuration Utility.lnk
backup=C:\WINDOWS\pss\D-Link AirPlus Xtreme G Configuration Utility.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SBC Self Support Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SBC Self Support Tool.lnk
backup=C:\WINDOWS\pss\SBC Self Support Tool.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
Ati2mdxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2003-05-22 16:15 327680 –a—— C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Live! Cam Manager]
2006-05-31 16:00 143360 ——— C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
C:\Program Files\DellSupport\DSAgnt.exe /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
2003-10-06 10:05 53248 –a—— c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spc_w]
C:\Program Files\NZSearch\nzspc.exe -w
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-09-12 18:21 68856 –a—— C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2004-05-14 08:35 536576 –a—— C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
2004-05-13 18:23 98304 –a—— C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TopSearch]
2005-10-27 15:52 307200 –a—— C:\Program Files\TopSearch\TopSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WG511WLU]
2003-02-21 00:33 188416 –a—— C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WANMiniportService"=2 (0x2)
"SiteAdvisor Service"=2 (0x2)
"ose"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=2 (0x2)
"DSBrokerService"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
"AOL ACS"=2 (0x2)
R2 NIOC;NIOC Service;\??\C:\WINDOWS\System32\NIOC.SYS
R2 WZCBDLService;WZCBDL Service;C:\Program Files\WZCBDL Service\WZCBDLS.exe
S3 AWINDIS5;AWINDIS5 Protocol Driver;\??\C:\WINDOWS\System32\AWINDIS5.SYS
S3 PRISM_ICB;NETGEAR WG511 Wireless LAN Driver;C:\WINDOWS\system32\DRIVERS\WG511ICB.sys
S3 PRISM_USB;D-Link Air DWL-122 Wireless USB Adapter Driver;C:\WINDOWS\system32\DRIVERS\PRISMUSB.sys
S3 V0230Vfx;V0230Vfx;C:\WINDOWS\system32\DRIVERS\V0230Vfx.sys
S3 V0230VID;Live! Cam Video IM Pro;C:\WINDOWS\system32\DRIVERS\V0230VID.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-28 21:12:09 C:\WINDOWS\Tasks\McAfee Cleanup.job"
- C:\DOCUME~1\Jyo\LOCALS~1\Temp\MCPR.tmp\mccleanup.exe
"2006-12-30 19:29:35 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2006-12-30 19:29:35 C:\WINDOWS\Tasks\McQcTask.job"
"2007-12-03 09:30:01 C:\WINDOWS\Tasks\RegClean Scheduled Scan.job"
- C:\Program Files\RegClean\RegClean.exe
"2007-12-03 09:00:01 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job"
- C:\Program Files\SpywareBot\SpywareBot.exe
- C:\Program Files\SpywareBot
"2004-01-11 19:32:23 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-03 21:48:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-03 21:53:32 - machine was rebooted
.
— E O F —
_________________________________________________
INSTALL log
_________________________________________________
AccessDirect
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Download Manager 1.2 (Remove Only)
Adobe Flash Player Plugin
Adobe Photoshop Album 2.0 Starter Edition
Adobe Reader 6.0.1
Advanced Video FX Engine
Air USB Utility
America Online (Choose which version to remove)
AOL Coach Version 1.0(Build:20030807.3)
AT&T Self Support Tool
AT&T Yahoo! Applications
ATI Control Panel
ATI Display Driver
AudibleManager
AutoUpdate
AVG 7.5
Banctec Service Agreement
BCM V.92 56K Modem
Broadcom Advanced Control Suite
BroadJump Client Foundation
Canon CanoScan Toolbox 4.1
CCleaner (remove only)
Creative Live! Cam Center
Creative Live! Cam Manager
Creative Live! Cam Video IM Pro Driver (1.00.07.0725)
Creative Live! Cam Video IM Pro User's Guide (English)
Creative MediaSource 5
Creative MuVo V100
Creative Photo Calendar
Creative Photo Manager
Creative Software AutoUpdate
Creative System Information
Dell Digital Jukebox Driver
Dell Media Experience
Dell Networking Guide
Dell Solution Center
DellSupport
DestroyPokemon Screen Saver
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
D-Link AirPlus Xtreme G Adapter
DS21Patch
DVDSentry
Get Yahoo! Messenger
Google Toolbar for Internet Explorer
Google Updater
Help and Support Customization
HijackThis 2.0.2
Hotfix for Windows XP (KB914440)
Internet Explorer Default Page
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
Learn2 Player (Uninstall Only)
LiveReg (Symantec Corporation)
LiveUpdate 2.0 (Symantec Corporation)
McAfee SecurityCenter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Encarta Encyclopedia Standard 2004
Microsoft Office 97, Professional Edition
Microsoft Office Visio Professional 2003
Modem Helper
Move Networks Media Player for Internet Explorer
Mozilla Firefox (1.5)
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MUSICMATCH® Jukebox
NETGEAR WG511 54 Mbps Wireless PC Card
Netscape (7.1)
Netscape Communicator 4.79
NetZero Internet
NIOC Service
Oracle 8: The Complete Reference
PAL
Pokemon PC 1.8
PowerDVD
PowerLite S1+
QuickSet
QuickTime
RealPlayer
Red Swoosh EDN Client (lol remove only)
Registry Mechanic 7.0
Rm to Mp3 Wav Convertor 2.15
SAP Front End
SAP Interactive Excel
Security Task Manager 1.7e
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB943460)
Shockwave
Sonic DLA
Sonic MyDVD
Sonic RecordNow!
Sonic Update Manager
Sony Picture Utility
Spruce
Spybot - Search & Destroy 1.4
Synaptics Pointing Device Driver
The Ultimate Pokemon Explode
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
VideoLAN VLC media player 0.8.6
Viewpoint Media Player (Remove Only)
WebCyberCoach 3.2 Dell
WebFldrs XP
Winamp (remove only)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Installer Clean Up
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10 Hotfix - KB895316
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinRAR archiver
WordPerfect Office 11
WZCBDL Service
Yahoo! Photos Easy Upload Tool 1v6
Yahoo! Toolbar
My system is running very slow..Though I have Pop-up blocker, I still get lot of pop-ups (setthetrend etc..). The typing (on any web application) is really frustating. CPU hits 100% almost all the time. This is becoming a nightmare.
PLEASE HELP.. I am posting HIJACKTHIS, COMBOFIX & INSTALL logs for your kind reference. Please review and suggest a remedy. I appreciate it.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:17:44 PM, on 12/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WZCBDL Service\WZCBDLS.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\JYO\Application Data\Mozilla\Profiles\default\fal84umo.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\JYO\Application Data\Mozilla\Profiles\default\fal84umo.slt\prefs.js)
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1196641397591
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: WZCBDL Service (WZCBDLService) - D-Link - C:\Program Files\WZCBDL Service\WZCBDLS.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
____________________________________________
COMBOFIX
_____________________________________________
ComboFix 07-12-02.6 - Jyo 2007-12-03 21:36:08.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.145 [GMT -6:00]
Running from: C:\Downloads\SJ - ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Program Files\SideFind
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\axpxmqgz.dllbox
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\ixyadqqv.dllbox
C:\WINDOWS\system32\ldcore.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rMa02yy
C:\WINDOWS\system32\zcomegrz.dllbox
C:\WINDOWS\uninst2.htm
C:\WINDOWS\unist1.htm
.
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.
2007-12-03 21:17 . 2007-12-03 21:17 d——– C:\Program Files\Trend Micro
2007-12-03 16:43 . 2007-12-03 16:43 d——– C:\WINDOWS\SYSTEM32\daSgo06
2007-12-03 11:55 . 2007-12-03 11:55 d——– C:\Documents and Settings\Jyo\Application Data\McAfee
2007-12-02 20:23 . 2007-12-02 20:30 d——– C:\Documents and Settings\Jyo\Application Data\AVG7
2007-12-02 20:22 . 2007-12-02 20:22 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-02 20:22 . 2007-12-02 20:22 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-02 20:22 . 2007-12-02 20:25 d——– C:\Documents and Settings\All Users\Application Data\avg7
2007-12-02 13:49 . 2007-12-02 13:52 d–h—– C:\WINDOWS\msdownld.tmp
2007-12-02 12:20 . 2006-11-07 21:01 66,048 –a—— C:\WINDOWS\ieResetIcons.exe
2007-12-02 10:14 . 2007-12-02 10:26 d——– C:\Documents and Settings\Jyo\Application Data\RegClean
2007-12-02 09:44 . 2007-12-02 09:44 d——– C:\Program Files\Windows Installer Clean Up
2007-12-02 09:43 . 2007-12-02 09:43 d——– C:\Program Files\MSECACHE
2007-12-02 09:08 . 2007-12-02 20:26 1,200,226 –ahs—- C:\WINDOWS\SYSTEM32\ybbuoama.ini
2007-12-02 08:39 . 2007-12-02 08:39 d——– C:\WINDOWS\SYSTEM32\daSgo02
2007-12-02 08:39 . 2007-12-02 08:39 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2007-12-02 08:39 . 2007-12-02 08:39 d——– C:\Documents and Settings\Administrator.JYO.000\Application Data\Symantec
2007-12-02 08:39 . 2007-12-02 08:39 d——– C:\Documents and Settings\Administrator.JYO.000\Application Data\Jasc Software Inc
2007-12-01 22:18 . 2004-01-02 04:16 d——– C:\Documents and Settings\Administrator.JYO.000\Application Data\Sonic
2007-12-01 14:19 . 2007-12-02 08:39 d——– C:\Program Files\Spruce
2007-12-01 10:41 . 2007-12-01 10:41 78,400 –a—— C:\WINDOWS\SYSTEM32\kpnyihwv.dll
2007-12-01 10:35 . 2007-12-02 08:44 1,322,574 –ahs—- C:\WINDOWS\SYSTEM32\tgijcsuw.ini
2007-11-30 10:32 . 2007-12-03 21:48 634,264 –ahs—- C:\WINDOWS\SYSTEM32\yxyay.ini2
2007-11-30 10:32 . 2007-12-03 21:49 634,264 –ahs—- C:\WINDOWS\SYSTEM32\yxyay.ini
2007-11-30 10:32 . 2007-11-30 10:32 324,192 –a—— C:\WINDOWS\SYSTEM32\yayxy.dll
2007-11-30 08:06 . 2007-11-30 08:06 d——– C:\temp\bkR11
2007-11-28 23:51 . 2007-12-02 08:39 d——– C:\Program Files\Security Task Manager
2007-11-28 23:51 . 2007-12-02 08:39 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2007-11-27 18:21 . 2007-11-27 18:21 d——– C:\Program Files\Ashampoo
2007-11-27 18:14 . 2007-11-27 18:14 d——– C:\Documents and Settings\Jyo\Application Data\EagleEyeOS
2007-11-27 18:05 . 2007-12-02 22:37 d——– C:\Desktop_Nov 27 07
2007-11-26 22:07 . 2007-11-26 22:08 d——– C:\Documents and Settings\Jyo\Application Data\Move Networks
2007-11-26 18:49 . 2007-11-26 18:51 d——– C:\SAPBW
2007-11-22 14:35 . 2007-11-26 18:55 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-22 14:02 . 2007-12-01 07:58 679,599 –ahs—- C:\WINDOWS\SYSTEM32\uuypnhkc.ini
2007-11-20 05:54 . 2007-11-22 13:59 979,595 –ahs—- C:\WINDOWS\SYSTEM32\cpwlbcpr.ini
2007-11-18 17:42 . 2007-11-18 17:46 4,654 –a—— C:\WINDOWS\SYSTEM32\tmp.reg
2007-11-18 17:09 . 2007-11-20 05:47 694,442 –ahs—- C:\WINDOWS\SYSTEM32\ripcihsh.ini
2007-11-18 17:06 . 2007-11-18 17:09 d——– C:\Nov2007
2007-11-18 16:00 . 2007-11-18 16:00 d——– C:\Ultimate Pkmn Explode
2007-11-18 15:16 . 2004-01-02 04:16 d——– C:\Documents and Settings\Administrator.JYO\Application Data\Sonic
2007-11-18 14:23 . 2007-11-18 14:24 0 –a—— C:\WINDOWS\SYSTEM32\mcrh.tmp
2007-11-18 08:59 . 2007-11-18 09:00 d——– C:\Documents and Settings\Jyo\Application Data\SpywareBot
2007-11-17 12:30 . 2007-11-22 14:03 436,027 –ahs—- C:\WINDOWS\SYSTEM32\ehjjl.ini2
2007-11-17 12:30 . 2007-11-22 14:03 0 –ahs—- C:\WINDOWS\SYSTEM32\ehjjl.ini
2007-11-16 11:20 . 2007-11-16 11:20 208,896 –a—— C:\WINDOWS\io43mvuiw4kj.exe
2007-11-10 08:10 . 2003-02-28 18:26 139,536 –a—— C:\WINDOWS\SYSTEM32\javaee.dll
2007-11-10 07:36 . 2007-11-10 07:36 d——– C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-08 00:24 . 2007-01-08 19:07 991,232 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
2007-11-07 23:03 . 2007-07-09 07:16 582,656 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\rpcrt4.dll
2007-11-07 17:46 . 2007-11-07 17:46 d——– C:\Documents and Settings\Jyo\Application Data\Motive
2007-11-04 12:38 . 2007-01-31 09:58 43,387 –a—— C:\WINDOWS\browser.exe
2007-11-04 12:38 . 2007-01-31 09:58 6,246 –a—— C:\WINDOWS\atty.ico
2007-11-04 12:37 . 2007-11-04 12:37 d——– C:\WINDOWS\Motive
2007-11-04 12:37 . 2007-11-07 17:47 d——– C:\Program Files\Common Files\Motive
2007-11-04 12:37 . 2007-11-04 12:37 d——– C:\Documents and Settings\All Users\Application Data\Motive
2007-11-04 12:37 . 2005-05-10 00:36 81,920 –a—— C:\WINDOWS\SYSTEM32\W32n50.dll
2007-11-04 12:37 . 2005-05-10 00:36 17,162 –a—— C:\WINDOWS\SYSTEM32\Pcandis5.sys
2007-11-04 12:37 . 2005-05-10 00:36 16,848 –a—— C:\WINDOWS\SYSTEM32\Pcandis4.sys
2007-11-04 12:37 . 2005-05-10 00:36 16,073 –a—— C:\WINDOWS\SYSTEM32\Pcandis3.vxd
2007-11-04 12:34 . 2007-11-07 17:47 d——– C:\Program Files\SBC Self Support Tool
2007-11-04 12:30 . 2003-05-19 16:07 86,016 –a—— C:\WINDOWS\SYSTEM32\YPcservice.exe
2007-11-04 12:24 . 2002-01-05 06:18 84,992 –a—— C:\WINDOWS\SYSTEM32\ATL70.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-03 17:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-02 19:49 ——— d—–w C:\Program Files\Google
2007-11-29 05:58 ——— d—–w C:\Documents and Settings\Jyo\Application Data\Apple Computer
2007-11-28 21:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2007-11-28 15:07 ——— d—–w C:\Program Files\Common Files\Adobe
2007-11-18 22:14 ——— d—–w C:\Program Files\Winamp
2007-11-18 22:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-08 01:57 ——— d—–w C:\Program Files\DivX
2007-11-04 19:23 ——— d—–w C:\Program Files\McAfee
2007-11-04 18:29 ——— d–h–r C:\Documents and Settings\Jyo\Application Data\yahoo!
2007-11-04 18:29 ——— d—–w C:\Program Files\Yahoo!
2007-11-04 18:01 155,995 —-a-w C:\WINDOWS\Java\Packages\R1R71NDB.ZIP
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-10-20 00:56 524,288 —-a-w C:\WINDOWS\SYSTEM32\DivXsm.exe
2007-10-20 00:56 43,528 —-a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-10-20 00:56 3,596,288 —-a-w C:\WINDOWS\SYSTEM32\qt-dx331.dll
2007-10-20 00:56 200,704 —-a-w C:\WINDOWS\SYSTEM32\ssldivx.dll
2007-10-20 00:56 129,784 —-a-w C:\WINDOWS\SYSTEM32\pxafs.dll
2007-10-20 00:56 120,056 —-a-w C:\WINDOWS\SYSTEM32\pxcpyi64.exe
2007-10-20 00:56 118,520 —-a-w C:\WINDOWS\SYSTEM32\pxinsi64.exe
2007-10-20 00:56 1,044,480 —-a-w C:\WINDOWS\SYSTEM32\libdivx.dll
2007-10-20 00:54 823,296 —-a-w C:\WINDOWS\SYSTEM32\divx_xx0c.dll
2007-10-20 00:54 823,296 —-a-w C:\WINDOWS\SYSTEM32\divx_xx07.dll
2007-10-20 00:54 81,920 —-a-w C:\WINDOWS\SYSTEM32\dpl100.dll
2007-10-20 00:54 802,816 —-a-w C:\WINDOWS\SYSTEM32\divx_xx11.dll
2007-10-20 00:54 739,840 —-a-w C:\WINDOWS\SYSTEM32\DivX.dll
2007-10-20 00:54 196,608 —-a-w C:\WINDOWS\SYSTEM32\dtu100.dll
2007-10-18 09:06 156,992 —-a-w C:\WINDOWS\SYSTEM32\DivXCodecVersionChecker.exe
2007-10-18 09:03 593,920 —-a-w C:\WINDOWS\SYSTEM32\dpuGUI11.dll
2007-10-18 09:03 57,344 —-a-w C:\WINDOWS\SYSTEM32\dpv11.dll
2007-10-18 09:03 53,248 —-a-w C:\WINDOWS\SYSTEM32\dpuGUI10.dll
2007-10-18 09:03 344,064 —-a-w C:\WINDOWS\SYSTEM32\dpus11.dll
2007-10-18 09:03 294,912 —-a-w C:\WINDOWS\SYSTEM32\dpu11.dll
2007-10-18 09:03 294,912 —-a-w C:\WINDOWS\SYSTEM32\dpu10.dll
2007-10-18 09:02 12,288 —-a-w C:\WINDOWS\SYSTEM32\DivXWMPExtType.dll
2007-10-14 22:30 170 —-a-w C:\Program Files\1bomb.ini
2007-09-12 18:52 53,248 —-a-w C:\WINDOWS\hg173.exe
2007-09-12 18:50 53,248 —-a-w C:\WINDOWS\df87173.exe
2007-07-15 20:06 194,376 —-a-w C:\Documents and Settings\Jyo\Application Data\shb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1e17f4bc-fafe-4b56-a5e3-81c75ef991b1}]
C:\WINDOWS\system32\ehankhov.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3E9E94B1-D85D-42DE-B281-9C1CA3372A42}]
2007-11-30 10:32 324192 –a—— C:\WINDOWS\system32\yayxy.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54DE7259-C729-45B1-BBD8-4BE9B5BD8248}]
2007-11-29 10:28 401408 –a—— C:\Program Files\Spruce\Spruce.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8E3FBDE2-7DBD-4040-85D9-29BBC559C129}]
C:\WINDOWS\system32\nnnnnkl.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-12 18:21]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RegistryMechanic"="" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-02 20:22]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-02 20:22]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{8E3FBDE2-7DBD-4040-85D9-29BBC559C129}"= C:\WINDOWS\system32\nnnnnkl.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnnnkl]
nnnnnkl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= c:\windows\system32\ldcore.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\yayxy.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^D-Link AirPlus Xtreme G Configuration Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\D-Link AirPlus Xtreme G Configuration Utility.lnk
backup=C:\WINDOWS\pss\D-Link AirPlus Xtreme G Configuration Utility.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SBC Self Support Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SBC Self Support Tool.lnk
backup=C:\WINDOWS\pss\SBC Self Support Tool.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
Ati2mdxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2003-05-22 16:15 327680 –a—— C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Live! Cam Manager]
2006-05-31 16:00 143360 ——— C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
C:\Program Files\DellSupport\DSAgnt.exe /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
2003-10-06 10:05 53248 –a—— c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spc_w]
C:\Program Files\NZSearch\nzspc.exe -w
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-09-12 18:21 68856 –a—— C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2004-05-14 08:35 536576 –a—— C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
2004-05-13 18:23 98304 –a—— C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TopSearch]
2005-10-27 15:52 307200 –a—— C:\Program Files\TopSearch\TopSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WG511WLU]
2003-02-21 00:33 188416 –a—— C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WANMiniportService"=2 (0x2)
"SiteAdvisor Service"=2 (0x2)
"ose"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=2 (0x2)
"DSBrokerService"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
"AOL ACS"=2 (0x2)
R2 NIOC;NIOC Service;\??\C:\WINDOWS\System32\NIOC.SYS
R2 WZCBDLService;WZCBDL Service;C:\Program Files\WZCBDL Service\WZCBDLS.exe
S3 AWINDIS5;AWINDIS5 Protocol Driver;\??\C:\WINDOWS\System32\AWINDIS5.SYS
S3 PRISM_ICB;NETGEAR WG511 Wireless LAN Driver;C:\WINDOWS\system32\DRIVERS\WG511ICB.sys
S3 PRISM_USB;D-Link Air DWL-122 Wireless USB Adapter Driver;C:\WINDOWS\system32\DRIVERS\PRISMUSB.sys
S3 V0230Vfx;V0230Vfx;C:\WINDOWS\system32\DRIVERS\V0230Vfx.sys
S3 V0230VID;Live! Cam Video IM Pro;C:\WINDOWS\system32\DRIVERS\V0230VID.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-28 21:12:09 C:\WINDOWS\Tasks\McAfee Cleanup.job"
- C:\DOCUME~1\Jyo\LOCALS~1\Temp\MCPR.tmp\mccleanup.exe
"2006-12-30 19:29:35 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2006-12-30 19:29:35 C:\WINDOWS\Tasks\McQcTask.job"
"2007-12-03 09:30:01 C:\WINDOWS\Tasks\RegClean Scheduled Scan.job"
- C:\Program Files\RegClean\RegClean.exe
"2007-12-03 09:00:01 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job"
- C:\Program Files\SpywareBot\SpywareBot.exe
- C:\Program Files\SpywareBot
"2004-01-11 19:32:23 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-03 21:48:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-03 21:53:32 - machine was rebooted
.
— E O F —
_________________________________________________
INSTALL log
_________________________________________________
AccessDirect
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Download Manager 1.2 (Remove Only)
Adobe Flash Player Plugin
Adobe Photoshop Album 2.0 Starter Edition
Adobe Reader 6.0.1
Advanced Video FX Engine
Air USB Utility
America Online (Choose which version to remove)
AOL Coach Version 1.0(Build:20030807.3)
AT&T Self Support Tool
AT&T Yahoo! Applications
ATI Control Panel
ATI Display Driver
AudibleManager
AutoUpdate
AVG 7.5
Banctec Service Agreement
BCM V.92 56K Modem
Broadcom Advanced Control Suite
BroadJump Client Foundation
Canon CanoScan Toolbox 4.1
CCleaner (remove only)
Creative Live! Cam Center
Creative Live! Cam Manager
Creative Live! Cam Video IM Pro Driver (1.00.07.0725)
Creative Live! Cam Video IM Pro User's Guide (English)
Creative MediaSource 5
Creative MuVo V100
Creative Photo Calendar
Creative Photo Manager
Creative Software AutoUpdate
Creative System Information
Dell Digital Jukebox Driver
Dell Media Experience
Dell Networking Guide
Dell Solution Center
DellSupport
DestroyPokemon Screen Saver
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
D-Link AirPlus Xtreme G Adapter
DS21Patch
DVDSentry
Get Yahoo! Messenger
Google Toolbar for Internet Explorer
Google Updater
Help and Support Customization
HijackThis 2.0.2
Hotfix for Windows XP (KB914440)
Internet Explorer Default Page
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
Learn2 Player (Uninstall Only)
LiveReg (Symantec Corporation)
LiveUpdate 2.0 (Symantec Corporation)
McAfee SecurityCenter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Encarta Encyclopedia Standard 2004
Microsoft Office 97, Professional Edition
Microsoft Office Visio Professional 2003
Modem Helper
Move Networks Media Player for Internet Explorer
Mozilla Firefox (1.5)
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MUSICMATCH® Jukebox
NETGEAR WG511 54 Mbps Wireless PC Card
Netscape (7.1)
Netscape Communicator 4.79
NetZero Internet
NIOC Service
Oracle 8: The Complete Reference
PAL
Pokemon PC 1.8
PowerDVD
PowerLite S1+
QuickSet
QuickTime
RealPlayer
Red Swoosh EDN Client (lol remove only)
Registry Mechanic 7.0
Rm to Mp3 Wav Convertor 2.15
SAP Front End
SAP Interactive Excel
Security Task Manager 1.7e
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB943460)
Shockwave
Sonic DLA
Sonic MyDVD
Sonic RecordNow!
Sonic Update Manager
Sony Picture Utility
Spruce
Spybot - Search & Destroy 1.4
Synaptics Pointing Device Driver
The Ultimate Pokemon Explode
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
VideoLAN VLC media player 0.8.6
Viewpoint Media Player (Remove Only)
WebCyberCoach 3.2 Dell
WebFldrs XP
Winamp (remove only)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Installer Clean Up
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10 Hotfix - KB895316
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinRAR archiver
WordPerfect Office 11
WZCBDL Service
Yahoo! Photos Easy Upload Tool 1v6
Yahoo! Toolbar