This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] HELP HIJACK THIS LOG

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i have run multiple adware and virus removal tools but this computer just wont heal here is my log


Logfile of HijackThis v1.99.1
Scan saved at 9:25:57 AM, on 1/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [lsass] C:\WINDOWS\lsass .exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [WinService32] C:\WINDOWS\System59\svchost.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1188.exe 61A847B5BBF72813339330466188719AB689201522886B092CBD44BD8689220221DD3257
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim .exe
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Sarah\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Agatha%20Christie%20-%20Peril%20at%20End%20House/Images/stg_drm.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1177792156437
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {7D731A83-6C80-4EA4-9646-5E06A0513274} (Sandlot Loader Control) - http://www.shockwave.com/content/snailmail…gwebinstall.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Wedding%20Dash/Images/armhelper.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/insaniqua…ploader_v10.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Settings Manager ccSetMgrRemoteRegistry (ccSetMgrRemoteRegistry) - Unknown owner - C:\WINDOWS\system32\adsmsextx.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!

  • All hijackthis logs I ask for should be done in normal mode ( not safe mode)
  • These logs should be done last after you have followed my instructions in the previous post.


Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!

_________________________________________________________________
I see signs of 2 anti Virus programs on this machine. Unfortunatley none of them is running. This may be because you did this scan in safe mode ?
Please let me know if this HJT scan was in fact done in safe mode. All other scans when I ask for New HJT logs will be done in normal mode only.

Also having 2 anti virus programs is a bad idea. They will confilct with each other and provide you much less protection.
I advise you to remove 1 of them through add remove programs now. It's up to you which you want to keep. Be sure the one you keep is current and updates are attainable.


________________________________________
Download SDFix and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log



___________________________________________________________________
1. Download Combo fix from one of these locations. ( Please save it to your desktop )
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe


combofix.exe

2.Close all open windows
3. Double click combofix.exe & follow the prompts.
4. When finished, it shall produce a log for you. Post that log in your next reply . (c:\comboFix.txt)

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combo fix in order to be effecient is going to disconect you from the internet. If when it is done and you can't get back on the internet just restart the computer.
_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
  • The report from S&D fix
ComboFix 08-01-03.3 - Teresa 2008-01-04 9:46:33.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.500 [GMT -5:00]
Running from: C:\Downloads\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Teresa\Application Data\FunWebProducts
C:\Documents and Settings\Teresa\Application Data\FunWebProducts\Data\Teresa\avatar.dat
C:\Documents and Settings\Teresa\Application Data\FunWebProducts\Data\Teresa\register.dat
C:\Documents and Settings\Teresa\Application Data\FunWebProducts\Data\Teresa\zbucks.dat
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\3269.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\bivwpwbw
C:\Program Files\bivwpwbw\rmnkxwna.dll
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images\00CEEBCD.urr
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\GRISOFT\AVG7\avgcc.exe
C:\Program Files\GRISOFT\AVG7\avgw.exe
C:\Program Files\Helper
C:\Program Files\Helper\Helper8.dll
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\lsass.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\Outerinfo.exe~
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Save\Save.exe
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe~
C:\Program Files\smss.exe
C:\Program Files\spoolsv.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Temp\bkR11
C:\WINDOWS\Casino.ico
C:\WINDOWS\Free Online Dating.ico
C:\WINDOWS\lsass .exe
C:\WINDOWS\lsass .exe
C:\WINDOWS\lsass.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\WINDOWS\Spyware Remover.ico
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\drvnapr.dll
C:\WINDOWS\system32\fccaxuv.dll
C:\WINDOWS\system32\gebcccd.dll
C:\WINDOWS\system32\gjkkj.ini
C:\WINDOWS\system32\gjkkj.ini2
C:\WINDOWS\system32\jkkjg.dll
C:\WINDOWS\system32\jkkjg.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\njprckha
C:\WINDOWS\system32\njprckha\bg1.gif
C:\WINDOWS\system32\njprckha\bgtop.gif
C:\WINDOWS\system32\njprckha\bottom1.gif
C:\WINDOWS\system32\njprckha\essentials.gif
C:\WINDOWS\system32\njprckha\icon1.ico
C:\WINDOWS\system32\njprckha\install1.gif
C:\WINDOWS\system32\njprckha\left1.gif
C:\WINDOWS\system32\njprckha\li.gif
C:\WINDOWS\system32\njprckha\logo.gif
C:\WINDOWS\system32\njprckha\main.htm
C:\WINDOWS\system32\njprckha\mainframe.htm
C:\WINDOWS\system32\njprckha\njprckha1.exe
C:\WINDOWS\system32\njprckha\njprckha2.exe
C:\WINDOWS\system32\njprckha\njprckha3.exe
C:\WINDOWS\system32\njprckha\reinstall1.gif
C:\WINDOWS\system32\njprckha\right1.gif
C:\WINDOWS\system32\njprckha\s1.htm
C:\WINDOWS\system32\njprckha\s2.htm
C:\WINDOWS\system32\njprckha\s3.htm
C:\WINDOWS\system32\njprckha\SMTop1.gif
C:\WINDOWS\system32\njprckha\SMTop2.gif
C:\WINDOWS\system32\njprckha\SMTop3.gif
C:\WINDOWS\system32\njprckha\SMTop4.gif
C:\WINDOWS\system32\njprckha\soft1_off.gif
C:\WINDOWS\system32\njprckha\soft1_off_ext.gif
C:\WINDOWS\system32\njprckha\soft1_on.gif
C:\WINDOWS\system32\njprckha\soft1_on_ext.gif
C:\WINDOWS\system32\njprckha\soft2_off.gif
C:\WINDOWS\system32\njprckha\soft2_off_ext.gif
C:\WINDOWS\system32\njprckha\soft2_on.gif
C:\WINDOWS\system32\njprckha\soft2_on_ext.gif
C:\WINDOWS\system32\njprckha\soft3_off.gif
C:\WINDOWS\system32\njprckha\soft3_off_ext.gif
C:\WINDOWS\system32\njprckha\soft3_on.gif
C:\WINDOWS\system32\njprckha\soft3_on_ext.gif
C:\WINDOWS\system32\njprckha\softbottom_off.gif
C:\WINDOWS\system32\njprckha\softbottom_on.gif
C:\WINDOWS\system32\njprckha\softleft_off.gif
C:\WINDOWS\system32\njprckha\softleft_on.gif
C:\WINDOWS\system32\njprckha\top1.gif
C:\WINDOWS\system32\njprckha\top2.gif
C:\WINDOWS\system32\njprckha\turnoff1.gif
C:\WINDOWS\system32\njprckha\turnon1.gif
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\RCX11.tmp
C:\WINDOWS\system32\RCX12.tmp
C:\WINDOWS\system32\RCX13.tmp
C:\WINDOWS\system32\RCX1A.tmp
C:\WINDOWS\system32\RCX1B.tmp
C:\WINDOWS\system32\RCX1F.tmp
C:\WINDOWS\system32\RCX21.tmp
C:\WINDOWS\system32\RCX22.tmp
C:\WINDOWS\system32\RCX23.tmp
C:\WINDOWS\system32\RCX25.tmp
C:\WINDOWS\system32\RCX27.tmp
C:\WINDOWS\system32\RCX36.tmp
C:\WINDOWS\system32\RCX39.tmp
C:\WINDOWS\system32\RCX3A.tmp
C:\WINDOWS\system32\RCX4F.tmp
C:\WINDOWS\system32\RCX63.tmp
C:\WINDOWS\system32\RCX6B.tmp
C:\WINDOWS\system32\RCX81.tmp
C:\WINDOWS\system32\RCXE.tmp
C:\WINDOWS\system32\xpdx.sys
C:\WINDOWS\system32\xxywuvu.dll
C:\winlogon.exe
C:\x.dat
C:\z.dat

"C:\Program Files\AIM\aim .exe" replaces infected copy of "C:\Program Files\AIM\aim.exe"
"C:\Program Files\AIM6\aim6 .exe" replaces infected copy of "C:\Program Files\AIM6\aim6.exe"
"C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe" replaces infected copy of "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe"
"C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe" replaces infected copy of "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe"
"C:\Program Files\GRISOFT\AVG7\avgcc .exe" replaces infected copy of "C:\Program Files\GRISOFT\AVG7\avgcc.exe"
"C:\Program Files\GRISOFT\AVG7\avgw .exe" replaces infected copy of "C:\Program Files\GRISOFT\AVG7\avgw.exe"
"C:\Program Files\iTunes\iTunesHelper .exe" replaces infected copy of "C:\Program Files\iTunes\iTunesHelper.exe"
"C:\Program Files\Java\jre1.6.0_01\bin\jusched .exe" replaces infected copy of "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
"C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe" replaces infected copy of "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
"C:\Program Files\Messenger\msmsgs .exe" replaces infected copy of "C:\Program Files\Messenger\msmsgs.exe"
"C:\Program Files\MySpace\IM\MySpaceIM .exe" replaces infected copy of "C:\Program Files\MySpace\IM\MySpaceIM.exe"
"C:\Program Files\Save\Save .exe" replaces infected copy of "C:\Program Files\Save\Save.exe"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger		.exe" replaces infected copy of "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe" replaces infected copy of "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"
"C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig  .exe" replaces infected copy of "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe"
"C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe" replaces infected copy of "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe"
"C:\WINDOWS\system32\ctfmon .exe" replaces infected copy of "C:\WINDOWS\system32\ctfmon.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE
——-\DomainService
——-\xpdx


((((((((((((((((((((((((( Files Created from 2007-12-04 to 2008-01-04 )))))))))))))))))))))))))))))))
.

2008-01-04 09:12 . 2008-01-04 09:12 d——– C:\Documents and Settings\Robert Reese & Ryan\Application Data\AVG7
2008-01-03 16:33 . 2008-01-03 16:33 d——– C:\Documents and Settings\Sarah\Application Data\AVG7
2008-01-03 15:59 . 2008-01-03 16:00 d——– C:\Documents and Settings\Teresa\Application Data\AVG7
2008-01-03 15:59 . 2008-01-03 15:59 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-03 15:59 . 2008-01-03 15:59 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-03 15:57 . 2008-01-03 15:57 1,031,398 –ahs—- C:\WINDOWS\system32\qolueqeq.ini
2008-01-02 15:41 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-02 11:18 . 2008-01-02 11:18 d——– C:\Program Files\V2_Myspace
2008-01-02 11:07 . 2008-01-04 09:58 d——– C:\Program Files\Trillian
2008-01-02 11:07 . 2008-01-02 11:07 d——– C:\Program Files\AskPBar
2008-01-02 10:58 . 2008-01-04 09:40 d——– C:\Documents and Settings\All Users\Application Data\Avg7
2008-01-02 10:09 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-01-02 10:09 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-01-02 10:09 . 2007-12-20 23:11 81,920 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-01-02 10:09 . 2003-06-05 20:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-01-02 10:09 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-01-02 10:09 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-01-02 10:09 . 2008-01-02 10:10 2,860 –a—— C:\WINDOWS\system32\tmp.reg
2008-01-02 09:37 . 2008-01-02 09:37 d——– C:\Documents and Settings\Administrator\Application Data\MySpace
2007-12-31 14:54 . 2007-12-31 14:54 d——– C:\WINDOWS\Snowy Treasure Hunter 3
2007-12-31 14:54 . 2007-12-31 14:54 d——– C:\Program Files\Snowy Treasure Hunter 3
2007-12-31 12:12 . 2007-12-31 12:12 d——– C:\Documents and Settings\Teresa\Application Data\Pogo Games
2007-12-31 12:11 . 2007-12-31 12:12 d——– C:\Program Files\Lottso! de Luxe
2007-12-29 12:10 . 2007-12-29 12:10 d——– C:\Documents and Settings\All Users\Application Data\FireGlow
2007-12-29 10:01 . 2007-12-29 10:01 d——– C:\Documents and Settings\All Users\Application Data\Meridian93
2007-12-29 10:00 . 2007-12-29 10:00 d——– C:\Documents and Settings\Teresa\Application Data\Meridian93
2007-12-28 11:21 . 2007-12-28 11:21 d——– C:\Documents and Settings\Administrator\Application Data\Aim
2007-12-28 11:20 . 2007-12-28 11:20 d——– C:\Documents and Settings\Administrator\Application Data\acccore
2007-12-28 10:53 . 2007-12-28 10:53 d——– C:\Documents and Settings\Teresa\Application Data\acccore
2007-12-28 10:51 . 2007-12-28 10:51 d——– C:\Program Files\Common Files\AOL
2007-12-28 10:51 . 2008-01-04 10:00 d——– C:\Program Files\AIM6
2007-12-28 09:36 . 2007-12-28 09:36 d——– C:\Documents and Settings\All Users\Application Data\HiddenSecretsNightmare
2007-12-27 15:07 . 2007-12-27 15:13 d——– C:\Program Files\Restaurant Empire
2007-12-27 13:05 . 2007-12-27 13:05 d——– C:\WINDOWS\Bigfish Games Miss Management
2007-12-27 13:05 . 2007-12-27 13:05 d——– C:\Program Files\Bigfish Games Miss Management
2007-12-27 12:56 . 2008-01-01 19:22 d——– C:\Program Files\Flowers Story
2007-12-27 12:54 . 2007-12-27 12:54 d——– C:\Program Files\Indianboy 2007 Present Discord Times Precracked Full version
2007-12-27 12:50 . 2007-12-27 12:50 d——– C:\WINDOWS\Cake Mania 2
2007-12-27 12:50 . 2007-12-27 12:50 d——– C:\Program Files\Cake Mania 2
2007-12-27 12:48 . 2007-12-27 12:48 d——– C:\Program Files\Plumeboom - The First Chapter
2007-12-27 12:36 . 2007-12-27 12:36 d——– C:\WINDOWS\Mystery in London
2007-12-27 12:36 . 2007-12-27 12:36 d——– C:\WINDOWS\Little Shop - Big City
2007-12-27 12:36 . 2007-12-27 12:36 d——– C:\WINDOWS\Dream Day - First Home
2007-12-27 12:36 . 2007-12-27 12:36 d——– C:\Program Files\Mystery in London
2007-12-27 12:36 . 2007-12-27 12:37 d——– C:\Program Files\Little Shop - Big City
2007-12-27 12:36 . 2007-12-27 12:37 d——– C:\Program Files\Dream Day - First Home
2007-12-27 12:35 . 2007-12-27 12:35 d——– C:\WINDOWS\Hidden Secrets - The Nightmare
2007-12-27 12:35 . 2007-12-27 12:35 d——– C:\WINDOWS\Christmasville
2007-12-27 12:35 . 2007-12-31 09:25 d——– C:\Program Files\Hidden Secrets - The Nightmare
2007-12-27 12:35 . 2007-12-27 12:35 d——– C:\Program Files\Christmasville
2007-12-27 12:34 . 2007-12-27 12:34 d——– C:\WINDOWS\Santa's Super Friends
2007-12-27 12:34 . 2007-12-31 12:09 d——– C:\Program Files\Santa's Super Friends
2007-12-27 11:31 . 2007-12-27 11:31 d——– C:\WINDOWS\Home Sweet Home
2007-12-27 11:31 . 2007-12-27 11:31 d——– C:\Program Files\Home Sweet Home
2007-12-27 11:17 . 2007-12-27 11:17 2,560 –a—— C:\WINDOWS\system32\bitcometres.dll
2007-12-27 10:24 . 2007-12-28 17:41 d——– C:\Documents and Settings\Teresa\Application Data\ZoomBrowser EX
2007-12-27 10:23 . 2007-12-27 10:23 d——– C:\Documents and Settings\Teresa\Application Data\CANON INC
2007-12-27 10:23 . 2007-12-28 17:41 d——– C:\Documents and Settings\Teresa\Application Data\CameraWindowDC
2007-12-27 10:23 . 2004-08-04 03:56 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-12-27 10:23 . 2004-08-04 01:58 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-12-27 10:23 . 2001-08-17 22:36 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-12-23 15:31 . 2007-12-23 15:31 d——– C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2007-12-23 15:30 . 2007-12-23 15:32 d——– C:\Program Files\Canon
2007-12-23 15:29 . 2007-12-23 15:29 d——– C:\Program Files\Common Files\Canon
2007-12-23 12:05 . 2007-12-23 12:25 d——– C:\Program Files\HollyAChristmasStoryAT
2007-12-21 13:00 . 2007-12-21 13:33 288 –a—— C:\WINDOWS\cncscore.ini
2007-12-21 12:58 . 2007-12-21 12:58 d——– C:\Program Files\Feyruna Fairy Forest
2007-12-21 12:58 . 2007-12-21 12:58 17,408 –a–c— C:\psapi.dll
2007-12-21 12:19 . 2007-12-21 12:19 d——– C:\Program Files\Dcads Games Collection
2007-12-21 12:19 . 2007-12-21 12:19 80,105 –a—— C:\WINDOWS\system32\dcads-remove.exe
2007-12-20 14:43 . 2007-12-20 14:43 d——– C:\WINDOWS\Burger Shop
2007-12-20 14:43 . 2007-12-20 14:43 d——– C:\Program Files\Burger Shop
2007-12-20 14:43 . 2007-12-20 14:43 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2007-12-20 12:25 . 2007-12-20 12:25 d——– C:\Documents and Settings\All Users\Application Data\WinZip
2007-12-20 11:32 . 2007-12-26 21:36 d——– C:\Program Files\Google
2007-12-20 11:31 . 2007-12-31 14:55 d——– C:\Program Files\BitComet
2007-12-20 11:26 . 2007-12-20 11:26 d—-c— C:\GTS Downloads
2007-12-20 11:25 . 2007-12-20 11:25 d—-c— C:\Global Torrent Searcher
2007-12-20 11:21 . 2007-12-20 11:21 173,989 –a–c— C:\Global Torrent Searcher.zip
2007-12-20 10:59 . 2007-01-18 07:00 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-12-20 10:29 . 2007-12-20 10:29 d——– C:\Documents and Settings\Administrator\Application Data\Lavasoft
2007-12-20 10:13 . 2007-12-20 10:13 30,800 –a—— C:\WINDOWS\xpupdate .exe
2007-12-20 10:03 . 2007-12-20 10:03 2 –a–c— C:\1826874728
2007-12-20 10:02 . 2007-12-20 12:39 d——– C:\Program Files\Qgscvrai
2007-12-20 10:02 . 2007-12-20 10:02 1,283,174 –a–c— C:\Install
2007-12-20 10:02 . 2007-12-20 10:06 109 –ahs—- C:\WINDOWS\system32\1826874728.dat
2007-12-20 10:00 . 2007-12-20 10:00 134 –a–c— C:\n.bat
2007-12-20 09:59 . 2007-12-20 09:59 d——– C:\WINDOWS\system32\daSgo05
2007-12-20 09:59 . 2008-01-04 09:56 d—-c— C:\Temp
2007-12-20 09:59 . 2007-12-20 10:20 376,320 –a–c— C:\WINDOWS\mrofinu1188.exe.tmp
2007-12-19 18:51 . 2007-12-26 21:33 d——– C:\Program Files\FabFashion_at
2007-12-19 15:38 . 2008-01-02 04:08 d——– C:\Program Files\Paradise Pet Salon
2007-12-19 10:34 . 2007-12-20 13:12 d——– C:\Program Files\ParadisePetSalon_at
2007-12-19 08:17 . 2007-12-26 21:35 d——– C:\Program Files\GHOSTHunters_at
2007-12-19 07:00 . 2007-12-19 07:00 d——– C:\Documents and Settings\All Users\Application Data\Shockwave
2007-12-18 18:57 . 2007-12-18 18:58 d——– C:\Program Files\BuildALot_at
2007-12-15 20:48 . 2007-12-29 22:13 d——– C:\Documents and Settings\Teresa\Application Data\Home Sweet Home
2007-12-15 18:46 . 2007-12-15 18:46 d——– C:\Documents and Settings\Teresa\Application Data\GameHouse
2007-12-15 18:46 . 2007-12-15 18:46 d——– C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2007-12-14 15:37 . 2007-12-14 15:37 d——– C:\Documents and Settings\All Users\Application Data\PopCap

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-04 15:00 ——— d—–w C:\Program Files\Save
2008-01-04 15:00 ——— d—–w C:\Program Files\AIM
2008-01-04 14:56 ——— d—–w C:\Program Files\QuickTime
2008-01-03 21:33 ——— d—–w C:\Documents and Settings\Sarah\Application Data\IMVU
2007-12-31 19:33 ——— d—–w C:\Documents and Settings\Teresa\Application Data\LimeWire
2007-12-31 14:20 ——— d—–w C:\Program Files\Java
2007-12-28 16:21 ——— d—–w C:\Program Files\AOD
2007-12-28 15:52 ——— d—–w C:\Program Files\Viewpoint
2007-12-28 15:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-28 15:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-28 08:48 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-27 02:45 ——— d—–w C:\Program Files\Shockwave.com
2007-12-27 02:44 ——— d—–w C:\Program Files\Nick Jr. Arcade
2007-12-27 02:44 ——— d—–w C:\Program Files\Nick Arcade
2007-12-27 02:40 ——— d—–w C:\Program Files\THQ
2007-12-27 02:23 ——— d—–w C:\Program Files\iWin.com
2007-12-26 18:18 ——— d–h–r C:\Documents and Settings\Teresa\Application Data\yahoo!
2007-12-20 16:13 ——— d—–w C:\Program Files\LimeWire
2007-12-20 16:07 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-20 16:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-20 16:03 ——— d—–w C:\Program Files\Symantec
2007-12-20 00:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\HipSoft
2007-12-19 10:40 ——— d—–w C:\Documents and Settings\Sarah\Application Data\Big Fish Games
2007-12-16 02:50 ——— d—–w C:\Documents and Settings\Teresa\Application Data\Big Fish Games
2007-12-15 23:46 ——— d—–w C:\Program Files\GameHouse
2007-12-13 20:43 ——— d—–w C:\Documents and Settings\Teresa\Application Data\Wildfire
2007-12-13 20:20 ——— d—–w C:\Program Files\CathysCaribbeanClub_at
2007-12-13 20:16 ——— d—–w C:\Program Files\Mystic Inn
2007-12-13 20:15 ——— d—–w C:\Documents and Settings\Teresa\Application Data\iWin
2007-12-13 20:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\SpinTop Games
2007-12-13 20:14 ——— d—–w C:\Program Files\Mystery Case Files - Prime Suspects
2007-12-13 20:14 ——— d—–w C:\Documents and Settings\Teresa\Application Data\Abra Academy2
2007-12-13 20:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-12-13 20:06 ——— d—–w C:\Program Files\Common Files\AOL(2)
2007-12-13 20:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-12-13 20:05 ——— d—–w C:\Program Files\Mirror Magic Deluxe
2007-12-13 20:05 ——— d—–w C:\Program Files\BitTorrent
2007-12-13 20:04 ——— d—–w C:\Documents and Settings\Teresa\Application Data\BitTorrent
2007-12-13 19:55 ——— d—–w C:\Documents and Settings\Sarah\Application Data\Move Networks
2007-12-12 17:03 ——— d—–w C:\Program Files\Oberon Media
2007-12-05 17:40 ——— d—–w C:\Program Files\Mystery Case Files - Ravenhearst
2007-12-05 17:13 ——— d—–w C:\Program Files\Carrie the Caregiver
2007-12-05 17:09 ——— d—–w C:\Program Files\Fairy Godmother Tycoon
2007-11-26 18:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sandlot Games
2007-11-23 18:45 ——— d—–w C:\Program Files\Plantasia
2007-11-19 00:29 ——— d—–w C:\Documents and Settings\Teresa\Application Data\FrimaStudio
2007-11-17 13:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\Fugazo
2007-11-15 22:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\MumboJumbo
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-11 14:09 ——— d—–w C:\Documents and Settings\Teresa\Application Data\PlayFirst
2007-11-10 00:14 ——— d—–w C:\Program Files\Unity
2007-11-04 14:29 ——— d—–w C:\Documents and Settings\Robert Reese & Ryan\Application Data\Wildfire
2007-11-04 00:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-09-11 13:49 110 —-a-w C:\Documents and Settings\All Users\Application Data\MostFunGameId.bin
2007-05-09 23:17 774,144 —-a-w C:\Program Files\RngInterstitial.dll
.
—-a-w			52,840 2007-12-20 15:43:31  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   450,560 2007-12-24 14:57:06  C:\Program Files\VIAudioi\SBADeck\ADeck .exe
—-a-w		 4,670,968 2007-12-30 02:04:38  C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
—-a-w			30,800 2007-12-20 15:13:59  C:\WINDOWS\xpupdate .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{032233ba-293d-4547-bce8-5f6fcc3f56be}]
2007-05-01 10:57 1362968 –a—— C:\Program Files\V2_Myspace\tbV2_M.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{76F262CF-0308-0FB4-F7A3-043266F3A47C}]
C:\Program Files\Qgscvrai\ytxhaatm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8E015787-B1E3-404a-95DE-3E71E1FA0305}]
C:\WINDOWS\system32\spads.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{F4D76F09-7896-458A-890F-E1F05C46069F}
{032233BA-293D-4547-BCE8-5F6FCC3F56BE}

[HKEY_CLASSES_ROOT\clsid\{032233ba-293d-4547-bce8-5f6fcc3f56be}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{032233BA-293D-4547-BCE8-5F6FCC3F56BE}"= C:\Program Files\V2_Myspace\tbV2_M.dll [2007-05-01 10:57 1362968]

[HKEY_CLASSES_ROOT\clsid\{032233ba-293d-4547-bce8-5f6fcc3f56be}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"WhenUSave"="C:\Program Files\Save\Save.exe" [2008-01-04 09:39 803184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-01-04 09:39 171448]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-01-04 09:39 8720384]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-01-04 09:39 1694208]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTrayp"="VTtrayp.exe" [2007-04-25 14:41 176128 C:\WINDOWS\system32\VTTrayp.exe]
"VTTimer"="VTTimer.exe" [2006-09-14 17:54 53248 C:\WINDOWS\system32\VTTimer.exe]
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [ ]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-04 09:38 517768]
"WinService32"="C:\WINDOWS\System59\svchost.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-01-04 09:39 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [ ]
"6ce3e5c7"="C:\WINDOWS\system32\qeqeuloq.dll" [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-04 09:39 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-01-04 09:39 8720384]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-04 09:47 219136]

C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\
IMVU.lnk - C:\Program Files\IMVU\IMVUClient.exe [2007-08-02 18:02:30]

C:\Documents and Settings\Teresa\Start Menu\Programs\Startup\
MostFun.lnk - C:\Program Files\MostFun\Bin\MostFun.exe [2007-08-28 16:47:20]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 23:05:56]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qomnlml]
qomnlml.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winexy32]
winexy32.dll

S2 ccSetMgrRemoteRegistry;Symantec Settings Manager ccSetMgrRemoteRegistry;C:\WINDOWS\system32\adsmsextx.exe srv []
S3 cur_bus;Curitel USB Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\cur_bus.sys [2005-07-19 18:39]
S3 cur_mdfl;Curitel Packet Service Filter;C:\WINDOWS\system32\DRIVERS\cur_mdfl.sys [2005-07-19 18:40]
S3 cur_mdm;Curitel Packet Service Drivers;C:\WINDOWS\system32\DRIVERS\cur_mdm.sys [2005-07-19 18:40]
S3 cur_serd;Curitel Packet Service Diagnostic Serial Port (WDM);C:\WINDOWS\system32\DRIVERS\cur_serd.sys [2005-07-19 18:42]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-04 10:00:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-04 10:09:09 - machine was rebooted [Teresa]
ComboFix-quarantined-files.txt 2008-01-04 15:09:06
.
2007-12-14 13:04:37 — E O F —



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~END~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~





Logfile of HijackThis v1.99.1
Scan saved at 10:11:08 AM, on 1/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Save\Save.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\MostFun\Bin\MostFun.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: V2_Myspace toolbar - {032233ba-293d-4547-bce8-5f6fcc3f56be} - C:\Program Files\V2_Myspace\tbV2_M.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: V2_Myspace toolbar - {032233ba-293d-4547-bce8-5f6fcc3f56be} - C:\Program Files\V2_Myspace\tbV2_M.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {76F262CF-0308-0FB4-F7A3-043266F3A47C} - C:\Program Files\Qgscvrai\ytxhaatm.dll (file missing)
O2 - BHO: browser optimizer superiorads - {8E015787-B1E3-404a-95DE-3E71E1FA0305} - C:\WINDOWS\system32\spads.dll (file missing)
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: V2_Myspace toolbar - {032233ba-293d-4547-bce8-5f6fcc3f56be} - C:\Program Files\V2_Myspace\tbV2_M.dll
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [WinService32] C:\WINDOWS\System59\svchost.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [6ce3e5c7] rundll32.exe "C:\WINDOWS\system32\qeqeuloq.dll",b
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - Startup: MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim .exe (file missing)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Sarah\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Agatha%20Christie%20-%20Peril%20at%20End%20House/Images/stg_drm.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1177792156437
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {7D731A83-6C80-4EA4-9646-5E06A0513274} (Sandlot Loader Control) - http://www.shockwave.com/content/snailmail…gwebinstall.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Wedding%20Dash/Images/armhelper.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/insaniqua…ploader_v10.cab
O20 - Winlogon Notify: qomnlml - qomnlml.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winexy32 - winexy32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Settings Manager ccSetMgrRemoteRegistry (ccSetMgrRemoteRegistry) - Unknown owner - C:\WINDOWS\system32\adsmsextx.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~END~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~




SDFix: Version 1.122

Run by [removed] on Fri 01/04/2008 at 10:19 AM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\182687~1 - Deleted
C:\WINDOWS\system32\daSgo05\daSgo051080.exe - Deleted
C:\n.bat - Deleted
C:\WINDOWS\mrofinu1188.exe.tmp - Deleted



Folder C:\WINDOWS\system32\daSgo05 - Removed

Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-04 10:26:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Thu 31 May 2007 1,492,560 …H. — "C:\Program Files\Big City Adventure - San Francisco\Big City Adventure - San Francisco.exe"
Fri 4 May 2007 2,498,560 …H. — "C:\Program Files\Cake Mania\Cake Mania.exe"
Thu 31 May 2007 16,082,512 …H. — "C:\Program Files\Mystery Case Files - Prime Suspects\Mystery Case Files - Prime Suspects.exe"
Sat 5 May 2007 15,384,576 …H. — "C:\Program Files\Mystery Case Files - Huntsville\Mystery Case Files - Huntsville.exe"
Fri 4 May 2007 1,572,864 …H. — "C:\Program Files\Virtual Villagers\Virtual Villagers.exe"
Fri 4 May 2007 2,035,712 …H. — "C:\Program Files\Virtual Villagers - The Lost Children\Virtual Villagers - The Lost Children.exe"
Tue 3 Jul 2007 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 30 Apr 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 1 May 2007 7,318 A..H. — "C:\Documents and Settings\Robert Reese & Ryan\Application Data\Microsoft\Office\Shortcut Bar\Off1.tmp"

Finished!
This is quite the mess mommy18723 :blush:

It looks like you have been infected by a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we can't guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found
here

I suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.

If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities.

Should you have any questions, please feel free to ask.

Please let me know what you decide to do in your next post.

Should you decide to clean this machine start by doing the following.

____________________________________________________

I also note that almost every game known to us is on this machine.
Please do not allow anything else to be downloaded on this machine until we are clean. You may download tools I ask you too.

_______________________________________
Download RenV.exe By sUBs to your Desktop.
  • Double click RenV.exe to run it.
  • When finished it will produce a log.
  • Post that log in your next reply please.

_______________________________________

Open HJT

this time click on
Misc tools section

then:
Open uninstall Manager
click on save list.
Post that for me.



_________________________
In your next reply I would like to see:
  • The uninstal list from HJT
  • The report from Renv.exe
3D Groove Playback Engine
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Flash Player ActiveX
Adobe Reader 6.0
Adobe Shockwave Player
AIM 6
AOL Instant Messenger
AVG 7.5
AVG Anti-Rootkit Free
Babysitting Mania
Big City Adventure - San Francisco (remove only)
Big City Adventure San Francisco
Big Fish Games Client
Bigfish Games Miss Management
BitComet 0.97
Build A Lot Free Trial
Build-a-lot
Burger Shop
Cake Mania (remove only)
Cake Mania 2
Canon Camera Access Library
Canon Camera Support Core Library
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC
Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
Canon Utilities EOS Utility
Canon Utilities MyCamera
Canon Utilities MyCamera DC
Canon Utilities PhotoStitch
Canon Utilities RemoteCapture DC
Canon Utilities RemoteCapture Task for ZoomBrowser EX
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
Carrie the Caregiver (remove only)
Charlotte's Web
Christmasville
Clifford Phonics
Curitel Packet Service Software
Diner Dash 2
Dream Day - First Home
Fairy Godmother Tycoon (remove only)
Flower Shop Big City Break
Flowers Story
Hidden Secrets - The Nightmare
Hijackthis 1.99.1
HijackThis 1.99.1
Home Sweet Home
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Indianboy 2007 Present Discord Times Precracked Full version
iWin Games (remove only)
Java™ 6 Update 3
Java™ SE Runtime Environment 6 Update 1
LimeWire PRO 4.12.3
Little Shop - Big City
Lottso! de Luxe
Luxor - Amun Rising
Math Missions Grades K-2
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Premium
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Minigolf Lost Island
Minigolf Wild West
Mirror Magic Deluxe (remove only)
MostFun Game Player
MySpaceIM
Mystery Case Files - Prime Suspects (remove only)
Mystery Case Files - Ravenhearst (remove only)
Mystery Case Files: Huntsville (remove only)
Mystery in London
Nicktoons Basketball
Pacific Heroes
Paradise Pet Salon
Paradise Pet Salon (remove only)
Paradise Pet Salon Free Trial
Pizza Chef
Pizza Frenzy
Plantasia (remove only)
QuickTime
RealArcade
Restaurant Empire (remove only)
Roller Typing
S3 S3Display
S3 S3Gamma2
S3 S3Info2
S3 S3Overlay
S3 S3TrayPlus
Sally's Salon
Santa's Super Friends
Scholastic's I SPY School Days
Scholastic's The Magic School Bus® Lands on Mars
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 8 (KB917734)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB944653)
Shrek 2 Activity Center
Snail Mail Online
SpongeBob SquarePants - The Movie
SpongeBob SquarePants Bubble Rush!
SpongeBob SquarePants Diner Dash
SpongeBob SquarePants Diner Dash 2
SpongeBob SquarePants Employee of the Month
SpongeBob SquarePants Obstacle Odyssey
SpongeBob SquarePants Obstacle Odyssey 2
Stand O`Food (remove only)
Symantec KB-DocID:2003093015493306
The Fairly OddParents - Shadow Showdown (remove only)
Trillian
Tumblebugs
UniChrome Pro IGP Display Driver and Utilities
Unity Web Player
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920342)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB925876)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
V2 Myspace Toolbar
VIA Platform Device Manager
VIA Vinyl Audio Codecs Driver Setup Program
VIA/S3G Display Driver
Viewpoint Media Player
Virtual Villagers - The Lost Children (remove only)
Virtual Villagers (remove only)
Wedding Dash™
Wild Thornberrys 3D Chopper Chase
WinAce Archiver
Windows Communication Foundation
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinZip
Yahoo! Browser Services
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Toolbar

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~END~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



Ran on Thu 01/03/2008 - 14:59:10.53

—-a-w			52,840 2007-12-20 15:43:31  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   450,560 2007-12-24 14:57:06  C:\Program Files\VIAudioi\SBADeck\ADeck .exe
—-a-w		 4,670,968 2007-12-30 02:04:38  C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
—-a-w			30,800 2007-12-20 15:13:59  C:\WINDOWS\xpupdate .exe

 Entries:				4  (4)
 Directories:			0  Files:			 4
 Bytes:		  5,205,168  Blocks:	   10,168
:blush: MESS??? LOL i know between 3 kids on here and all of my games i know im usualy pretty good at this and i dont download anything bad but i dont know what happened this time LOL usually i just reinstall but its such a hassle then i have to reinstall everything i wish i could just reinstall windows reinstall all of my games then create some kind of magic back up that will just bring me right back to it IM IN THE WORLD OF WISHING THO :blush:
Alright here ya go. Hopefully we get it all in 1 go. It was alot !




________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\xpupdate .exe

Renv::
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\Program Files\VIAudioi\SBADeck\ADeck .exe
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE


Folder::
C:\Program Files\Save
C:\Program Files\AskPBar
C:\WINDOWS\System59


Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qomnlml]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winexy32]



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.


________________________________

Go to
Start/control panel/add remove programs ;
And Uninstall


Java™ SE Runtime Environment 6 Update 1 << you have the newest version :thumbup: ,no reason to have this one also.
View Point/ view point manager



______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked



O2 - BHO: (no name) - {76F262CF-0308-0FB4-F7A3-043266F3A47C} - C:\Program Files\Qgscvrai\ytxhaatm.dll (file missing)
O2 - BHO: browser optimizer superiorads - {8E015787-B1E3-404a-95DE-3E71E1FA0305} - C:\WINDOWS\system32\spads.dll (file missing)
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL

O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL

O4 - HKLM\..\Run: [WinService32] C:\WINDOWS\System59\svchost.exe
O4 - HKLM\..\Run: [6ce3e5c7] rundll32.exe "C:\WINDOWS\system32\qeqeuloq.dll",b
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/insaniqua…ploader_v10.cab

O20 - Winlogon Notify: qomnlml - qomnlml.dll (file missing)
O20 - Winlogon Notify: winexy32 - winexy32.dll (file missing)


_____________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


C:\Program Files\V2_Myspace\tbV2_M.dll


Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html



______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.

  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Registry function to clean anything with this program. Having anything auto clean your regisrty is risky).


_________________________________
Please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste that information in your next post.


_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from Renv
  • The report from Jottis/Virus total
  • The report from Kasperskys
just so you know i do have a spy software installed caled 007 i would like to keep it and its installed in c :\program files\system32 and saves data to C:\WINDOWS\System59\
2008-01-04 14:52
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 4/01/2008
Kaspersky Anti-Virus database records: 502545


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 116790
Number of viruses found 22
Number of infected objects 128
Number of suspicious objects 0
Duration of the scan process 01:49:47

Infected Object Name Virus Name Last Action
C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\Documents and Settings\All Users\Application Data\Avg7\Log\emc.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\130d276927b55e302b060f3280bb355b_c8b69e70-eaec-4dbe-b451-be63dbde823a Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Teresa\Application Data\MySpace\IM\Logs\MySpaceIM-20080104-120258.log Object is locked skipped

C:\Documents and Settings\Teresa\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Teresa\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Teresa\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Teresa\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Teresa\Local Settings\History\History.IE5\MSHist012008010420080105\index.dat Object is locked skipped

C:\Documents and Settings\Teresa\Local Settings\Temp\~DF425.tmp Object is locked skipped

C:\Documents and Settings\Teresa\Local Settings\Temp\~DF9B8C.tmp Object is locked skipped

C:\Documents and Settings\Teresa\Local Settings\Temp\~DFD2C4.tmp Object is locked skipped

C:\Documents and Settings\Teresa\Local Settings\Temp\~DFE23E.tmp Object is locked skipped

C:\Documents and Settings\Teresa\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\Teresa\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Teresa\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Teresa\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Teresa\Shared\Build.A.Lot.v1.2.0.0.318-CIY.zip/Build.A.Lot.v1.2.0.0.318-CIY/Build-A-Lot.exe Infected: Trojan-Dropper.Win32.Delf.xo skipped

C:\Documents and Settings\Teresa\Shared\Build.A.Lot.v1.2.0.0.318-CIY.zip/Build.A.Lot.v1.2.0.0.318-CIY/tvrxlgz.exe Infected: Trojan-Dropper.Win32.Delf.xo skipped

C:\Documents and Settings\Teresa\Shared\Build.A.Lot.v1.2.0.0.318-CIY.zip/Build.A.Lot.v1.2.0.0.318-CIY/Uninstall.exe Infected: Trojan-Dropper.Win32.Delf.xo skipped

C:\Documents and Settings\Teresa\Shared\Build.A.Lot.v1.2.0.0.318-CIY.zip RAR: infected - 3 skipped

C:\Documents and Settings\Teresa\Shared\Diego.s.Wolfpup.Rescue.v1.0.0.22.CRACKED-NGEN.zip/Diego.s.Wolfpup.Rescue.v1.0.0.22.CRACKED-NGEN/crack/diego.exe Infected: Trojan-Dropper.Win32.Delf.xo skipped

C:\Documents and Settings\Teresa\Shared\Diego.s.Wolfpup.Rescue.v1.0.0.22.CRACKED-NGEN.zip/Diego.s.Wolfpup.Rescue.v1.0.0.22.CRACKED-NGEN/cracktro.exe Infected: Trojan-Dropper.Win32.Delf.xo skipped

C:\Documents and Settings\Teresa\Shared\Diego.s.Wolfpup.Rescue.v1.0.0.22.CRACKED-NGEN.zip/Diego.s.Wolfpup.Rescue.v1.0.0.22.CRACKED-NGEN/en_diegoswolfscue_nick.exe Infected: Trojan-Dropper.Win32.Delf.xo skipped

C:\Documents and Settings\Teresa\Shared\Diego.s.Wolfpup.Rescue.v1.0.0.22.CRACKED-NGEN.zip ZIP: infected - 3 skipped

C:\Documents and Settings\Teresa\Shared\Dora.s.Star.Catching.Adventure.v1.0.CRACKED-NGEN.zip/Dora.s.Star.Catching.Adventure.v1.0.CRACKED-NGEN/crack/dora_starcatching_31_fps.exe Infected: Trojan-Dropper.Win32.Delf.xo skipped

C:\Documents and Settings\Teresa\Shared\Dora.s.Star.Catching.Adventure.v1.0.CRACKED-NGEN.zip/Dora.s.Star.Catching.Adventure.v1.0.CRACKED-NGEN/en_dorastarcagame_nick.exe Infected: Trojan-Dropper.Win32.Delf.xo skipped

C:\Documents and Settings\Teresa\Shared\Dora.s.Star.Catching.Adventure.v1.0.CRACKED-NGEN.zip ZIP: infected - 2 skipped

C:\Documents and Settings\Teresa\Shared\Dora.s.World.Adventure.v1.0.0.5.CRACKED-NGEN.zip/Dora.s.World.Adventure.v1.0.0.5.CRACKED-NGEN/crack/doraadventure.exe Infected: Trojan-Dropper.Win32.Delf.xo skipped

C:\Documents and Settings\Teresa\Shared\Dora.s.World.Adventure.v1.0.0.5.CRACKED-NGEN.zip/Dora.s.World.Adventure.v1.0.0.5.CRACKED-NGEN/cracktro.exe Infected: Trojan-Dropper.Win32.Delf.xo skipped

C:\Documents and Settings\Teresa\Shared\Dora.s.World.Adventure.v1.0.0.5.CRACKED-NGEN.zip/Dora.s.World.Adventure.v1.0.0.5.CRACKED-NGEN/en_dorasworldture_nick.exe Infected: Trojan-Dropper.Win32.Delf.xo skipped

C:\Documents and Settings\Teresa\Shared\Dora.s.World.Adventure.v1.0.0.5.CRACKED-NGEN.zip ZIP: infected - 3 skipped

C:\Documents and Settings\Teresa\Shared\Eighties classic (dongoto).wma Infected: Trojan-Downloader.WMA.Wimad.l skipped

C:\Documents and Settings\Teresa\Shared\Paradise Pet Salon Keygen.zip/Crack.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\Documents and Settings\Teresa\Shared\Paradise Pet Salon Keygen.zip ZIP: infected - 1 skipped

C:\Documents and Settings\Teresa\Shared\Rare Recording.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped

C:\Documents and Settings\Teresa\Shared\Zoo_Vet-setup.zip/Zoo_Vet-setup.exe Infected: Trojan-Dropper.Win32.Delf.xo skipped

C:\Documents and Settings\Teresa\Shared\Zoo_Vet-setup.zip ZIP: infected - 1 skipped

C:\Downloads\Abra Academy - Returning Cast + Indianboy 2007\Abra Academy - Returning Cast.exe.bc! Object is locked skipped

C:\Downloads\Abra Academy - Returning Cast + Indianboy 2007\Torrent downloaded from Demonoid.com.txt.bc! Object is locked skipped

C:\Downloads\Abra Academy - Returning Cast + Indianboy 2007\Upload By Indianboy 2007.txt.bc! Object is locked skipped

C:\Downloads\Dream Chronicles + Indianboy2007\Dream Chronicles.exe.bc! Object is locked skipped

C:\Downloads\Dream Chronicles + Indianboy2007\Indianboy 2007.txt.bc! Object is locked skipped

C:\Downloads\Dream Chronicles + Indianboy2007\Torrent_downloaded_from_Demonoid.com.txt.bc! Object is locked skipped

C:\Downloads\G.H.O.S.T Hunters The Haunting Of Majesty Manor (CRACKED - 100% Working).zip.bc! Object is locked skipped

C:\Downloads\Ghost_Hunter_Inc\Ghost Hunter Inc.exe.bc! Object is locked skipped

C:\Downloads\Ghost_Hunter_Inc\Torrent downloaded from Demonoid.com.txt.bc! Object is locked skipped

C:\Downloads\Paradise_Pet_Salon_v1.0_CRACKED[TE].zip/Paradise_Pet_Salon_v1.0_CRACKED[TE]/install.exe Infected: not-virus:Hoax.Win32.Agent.p skipped

C:\Downloads\Paradise_Pet_Salon_v1.0_CRACKED[TE].zip 7-Zip: infected - 1 skipped

C:\Downloads\WinZip_Pro_v13beta+Keygen\Setup.exe Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped

C:\Program Files\Hijackthis\backups\backup-20080104-122315-686.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped

C:\Program Files\iWin Games\iWinGamesHookIE.dll Infected: not-a-virus:AdWare.Win32.AdMedia.g skipped

C:\Program Files\System32\svchost.exe Infected: not-a-virus:Monitor.Win32.007SpySoft.342 skipped

C:\Program Files\WinAce\VVSNInst.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped

C:\QooBox\Quarantine\C\Program Files\AIM\aim.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\AIM6\aim6.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\bivwpwbw\rmnkxwna.dll.vir Infected: Trojan-Downloader.Win32.Zlob.fof skipped

C:\QooBox\Quarantine\C\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\GRISOFT\AVG7\avgcc.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\GRISOFT\AVG7\avgw.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\Helper\Helper8.dll.vir Infected: Trojan-Downloader.Win32.Alphabet.ap skipped

C:\QooBox\Quarantine\C\Program Files\iTunes\iTunesHelper.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\Java\jre1.6.0_01\bin\jusched.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\Java\jre1.6.0_03\bin\jusched.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\lsass.exe.vir Infected: Trojan-Downloader.Win32.Alphabet.ap skipped

C:\QooBox\Quarantine\C\Program Files\Messenger\msmsgs.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\MySpace\IM\MySpaceIM.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.gn skipped

C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir NSIS: infected - 1 skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\Save\Save.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\spoolsv.exe.vir Infected: Trojan-Downloader.Win32.Alphabet.gen skipped

C:\QooBox\Quarantine\C\Program Files\Yahoo!\Messenger\YahooMessenger .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\Yahoo!\Messenger\YahooMessenger .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\Yahoo!\Messenger\YahooMessenger .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\Yahoo!\Messenger\YahooMessenger .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\Yahoo!\Messenger\YahooMessenger .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\Program Files\Yahoo!\Messenger\YahooMessenger .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\lsass .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\lsass .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\lsass.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ctfmon.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\fccaxuv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cll skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\jkkjg.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX11.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX12.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX13.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX1A.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX1B.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX1F.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX21.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX22.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX23.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX25.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX27.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX36.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX39.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX3A.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX4F.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX63.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX6B.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCX81.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\RCXE.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\xxywuvu.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cll skipped

C:\QooBox\Quarantine\C\winlogon.exe.vir Infected: not-a-virus:PSWTool.Win32.PassView.p skipped

C:\QooBox\Quarantine\catchme2008-01-04_100025.62.zip/xpdx.sys Infected: Trojan-Clicker.Win32.Costrat.cu skipped

C:\QooBox\Quarantine\catchme2008-01-04_100025.62.zip/jkkjg.dll Infected: Virus.Win32.Trats.c skipped

C:\QooBox\Quarantine\catchme2008-01-04_100025.62.zip ZIP: infected - 2 skipped

C:\SDFix\backups\backups.zip/backups/mrofinu1188.exe.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped

C:\SDFix\backups\backups.zip ZIP: infected - 1 skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0084481.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0084849.exe Infected: Trojan-Proxy.Win32.Agent.kj skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085024.exe Infected: Trojan-Proxy.Win32.Agent.kj skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085025.exe Infected: Trojan-Proxy.Win32.Agent.kj skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085026.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085027.exe Infected: Trojan-Proxy.Win32.Agent.kj skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085028.exe Infected: Trojan-Proxy.Win32.Agent.kj skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085035.exe Infected: Trojan-Proxy.Win32.Agent.kj skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085053.exe Infected: Trojan-Proxy.Win32.Agent.kj skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085054.exe Infected: Trojan-Proxy.Win32.Agent.kj skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085055.exe Infected: Trojan-Proxy.Win32.Agent.kj skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085056.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085067.exe Infected: Trojan-Proxy.Win32.Agent.kj skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085068.exe Infected: Trojan-Proxy.Win32.Agent.kj skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085069.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085070.exe Infected: Trojan-Proxy.Win32.Agent.kj skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP276\A0085079.exe Infected: Trojan-Proxy.Win32.Agent.kj skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP277\A0088663.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP277\A0088665.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP277\A0088667.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0095443.exe Infected: not-a-virus:Monitor.Win32.007SpySoft.342 skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0095448.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096421.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096422.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096429.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096431.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096435.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096436.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096437.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096438.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096439.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096441.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096442.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096443.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096444.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP283\A0096445.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096452.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096459.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096460.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096464.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096470.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096471.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096472.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096473.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096474.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096475.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096476.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096478.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096479.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096480.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096481.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0096482.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0097460.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0097462.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0097463.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0097465.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0097466.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0097467.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0097468.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0097469.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0097470.exe Infected: not-a-virus:FraudTool.Win32.DrAntispy.ag skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0098462.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0098464.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0098465.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0098466.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0098468.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0098470.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0098472.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0098473.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0098474.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0098475.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0098476.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0098477.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0098478.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099459.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099460.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099461.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099467.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099468.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099469.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099471.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099472.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099473.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099474.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099475.dll Infected: not-a-virus:AdWare.Win32.Agent.yr skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099486.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099488.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099490.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099491.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099492.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099493.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099494.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099496.exe Object is locked skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099525.exe/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099525.exe/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099525.exe/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099525.exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099525.exe RarSFX: infected - 4 skipped

C:\System Volume Information\_restore{863B96D7-B2C2-4FEF-A53B-DE96DA8CE094}\RP285\A0099525.exe CryptFF: infected - 4 skipped




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

VIRUSTOTAL
Antivirus Version Last Update Result
AhnLab-V3 2008.1.4.11 2008.01.04 -
AntiVir 7.6.0.46 2008.01.04 -
Authentium 4.93.8 2008.01.04 -
Avast 4.7.1098.0 2008.01.03 -
AVG 7.5.0.516 2008.01.04 -
BitDefender 7.2 2008.01.04 -
CAT-QuickHeal 9.00 2008.01.04 -
ClamAV 0.91.2 2008.01.04 -
DrWeb 4.44.0.09170 2008.01.04 -
eSafe 7.0.15.0 2008.01.03 -
eTrust-Vet 31.3.5430 2008.01.04 -
Ewido 4.0 2008.01.04 -
FileAdvisor 1 2008.01.04 -
Fortinet 3.14.0.0 2008.01.04 -
F-Prot 4.4.2.54 2008.01.04 -
F-Secure 6.70.13030.0 2008.01.04 -
Ikarus T3.1.1.15 2008.01.04 -
Kaspersky 7.0.0.125 2008.01.04 -
McAfee 5200 2008.01.04 -
Microsoft 1.3109 2008.01.04 -
NOD32v2 2765 2008.01.04 -
Norman 5.80.02 2008.01.04 -
Panda 9.0.0.4 2008.01.03 -
Prevx1 V2 2008.01.04 Heuristic: Suspicious Mailer
Rising 20.25.42.00 2008.01.04 -
Sophos 4.24.0 2008.01.04 -
Sunbelt 2.2.907.0 2008.01.04 -
Symantec 10 2008.01.04 -
TheHacker 6.2.9.180 2008.01.04 -
VBA32 3.12.2.5 2008.01.02 -
VirusBuster 4.3.26:9 2008.01.04 -
Webwasher-Gateway 6.6.2 2008.01.04 -
Additional information
File size: 1362968 bytes
MD5: b74e48d913196ab5b2de8f10259638c6
SHA1: 7a7c75b0d4e7ec3469d907ee34d7e9d3696f8725
PEiD: -
Prevx info: http://info.prevx.com/aboutprogramtext.asp…87E580057E19D72





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Ran on 2008-01-04 - 13:00:50.35

—-a-w			52,840 2007-12-20 15:43:31  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   450,560 2007-12-24 14:57:06  C:\Program Files\VIAudioi\SBADeck\ADeck .exe
—-a-w		 4,670,968 2007-12-30 02:04:38  C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
—-a-w			30,800 2007-12-20 15:13:59  C:\WINDOWS\xpupdate .exe

 Entries:				4  (4)
 Directories:			0  Files:			 4
 Bytes:		  5,205,168  Blocks:	   10,168




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 12:59, on 2008-01-04
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\System32\svchost.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: V2_Myspace toolbar - {032233ba-293d-4547-bce8-5f6fcc3f56be} - C:\Program Files\V2_Myspace\tbV2_M.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: V2_Myspace toolbar - {032233ba-293d-4547-bce8-5f6fcc3f56be} - C:\Program Files\V2_Myspace\tbV2_M.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: V2_Myspace toolbar - {032233ba-293d-4547-bce8-5f6fcc3f56be} - C:\Program Files\V2_Myspace\tbV2_M.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [WinService32] C:\Program Files\System32\svchost.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim .exe (file missing)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Sarah\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Agatha%20Christie%20-%20Peril%20at%20End%20House/Images/stg_drm.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1177792156437
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {7D731A83-6C80-4EA4-9646-5E06A0513274} (Sandlot Loader Control) - http://www.shockwave.com/content/snailmail…gwebinstall.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Wedding%20Dash/Images/armhelper.ocx
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Settings Manager ccSetMgrRemoteRegistry (ccSetMgrRemoteRegistry) - Unknown owner - C:\WINDOWS\system32\adsmsextx.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

just so you know i do have a spy software installed caled 007 i would like to keep it and its installed in c :\program files\system32
and saves data to C:\WINDOWS\System59\


Please tell me the exact name of this software. I can't see anything in the unistall list that resembles 2007.
It looks as if you have a lot of cracked software.
Cracked software will infect you almost everytime.


________________________________

Go to
Start/control panel/add remove programs ;
And Uninstall

WinAce Archiver

Symantec KB-DocID:2003093015493306
left over after removing nortons AV.



________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Documents and Settings\Teresa\Shared\Build.A.Lot.v1.2.0.0.318-CIY.zip
C:\Documents and Settings\Teresa\Shared\Diego.s.Wolfpup.Rescue.v1.0.0.22.CRACKED-NGEN.zip
C:\Documents and Settings\Teresa\Shared\Dora.s.Star.Catching.Adventure.v1.0.CRACKED-NGEN.zip
C:\Documents and Settings\Teresa\Shared\Dora.s.World.Adventure.v1.0.0.5.CRACKED-NGEN.zip
C:\Documents and Settings\Teresa\Shared\Eighties classic (dongoto).wma
C:\Documents and Settings\Teresa\Shared\Paradise Pet Salon Keygen.zip
C:\Documents and Settings\Teresa\Shared\Rare Recording.wma
C:\Documents and Settings\Teresa\Shared\Zoo_Vet-setup.zip
C:\Downloads\Paradise_Pet_Salon_v1.0_CRACKED[TE].zip
C:\Downloads\Paradise_Pet_Salon_v1.0_CRACKED[TE].zip 7-Zip:
C:\Downloads\WinZip_Pro_v13beta+Keygen\Setup.exe
C:\Program Files\iWin Games\iWinGamesHookIE.dll



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.



_______________________________________


I see that Viewpoint Media Player is installed.

Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". In 2006, this may change, read Viewpoint to Plunge Into Adware.

I suggest you remove the program now. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present:
  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player
If AOL is present, to prevent it from being recreated every time you run the AOL software:
  • Open AOL
  • Go to Help on the toolbar
  • Select About AOL
  • Hit Ctrl D and a secret panel can be accessed which will allow you to disable all desktop and IM features associated with Viewpoint.
Another way to prevent Viewpoint from being recreated every time you run the AOL software is:
  • Click C:\Program Files\AOL 9.0\Jiti (a hidden folder).
  • Rename viewpoint.exe to viewpoint.old.

___________________________________


I see no evidence of a fire wall. I suggest you get one in place now.

A few words on Microsofts firewall. It only works in one direction. Incoming.
That means if something gets by it you would never know it was trying
to contact the internet.
Example: A bad program installs itself. You would never know it was contacting the internet.
Downloading other nasties and so forth.

If you decide to run one of these you should be certain Microsofts firewall is disabled.
To disable it.

I will list a few free firewalls for you. These are good (free) firewalls:

Never run 2 firwalls together. They will interfere with each other.
So just download and install one!

Comodo Fairly simple to use

Sunbelt Personal Firewall



_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
  • Let me know how things seem to be running.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI