This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] hijacked

121 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

started the CF, got called away from the comp, only about 5mins. when i came back it was rebooting itself.

first thing up was an error window…..At startup windows can not find 'C:\WINDOWS\system32\home:-\Combobatch.bat'
when i pressed ok the screen came up, then another window opened…..just said in the heading……
C:\WINDOWS\system32\kmd.exe


Logfile of HijackThis v1.99.1
Scan saved at 11:40, on 2008-02-08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TomTom HOME\TomTomHOME.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Ian.KERRX4\My Documents\Ian\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Easy SpyRemover] C:\Program Files\Easy SpyRemover\EasySpyRemover.exe /smart
O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\kmd.exe /c C:\ComboFix\Combobatch.bat
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpywareProMFC] C:\Program Files\SpywarePro\SpywarePro.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NetScreen-Remote.lnk = C:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://uk.midas.games.yahoo.net/ctl/kingcomie.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1186233048395
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game03.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SafeNet Monitor Service (IPSECMON) - SafeNet - C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe
O23 - Service: SafeNet IKE Service (IREIKE) - SafeNet - C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

still cant find C:\ComboFix.txt

will run again and stay by the comp this time!

run CF,
completed stage 2 to 43 after that C:\ComboFix\Dir root the process can not access the file because its being used by another…….then it rebooted.
run again………….after stage 43
can not find path specified
re-booted itself

thats it.
A. We are going to try running a completely different version of ComboFix. It even has a slightly different name. First, DELETE your current version of ComboFix on your Desktop, then delete the following folder only C:\ComboFix.

B. Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop. I suggest that you rename it to Combo-Fix.exe (It may provide you with this name as the default name without you having to rename it)

Link 1
Link 2

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results"
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards.
2. Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:ComboFix.txt along with a HijackThis log so we can continue cleaning the system.
Notes:
  • Do not mouseclick combofix's window while it's running. That may cause it to stall
  • CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
before I download CF. i have another folder called ComboFix[1] do i leave it / delete it ? just found a notepad in c:\ not sure what it is, as its called "playground" anything to do with this lot? Tue Aug 07 23:37:35 2007: , version . Tue Aug 07 23:37:36 2007: Started thread and set thread priority (6374960) Tue Aug 07 23:37:36 2007: User data dir: C:\Documents and Settings\All Users.WINDOWS\Application Data\Zylom\ZylomGamesPlayer\zylom\piratepoppers\en-US Tue Aug 07 23:37:36 2007: Common data dir: C:\Documents and Settings\All Users.WINDOWS\Application Data\Zylom\ZylomGamesPlayer\zylom\piratepoppers\en-US Tue Aug 07 23:37:36 2007: WM_SIZE: SIZE_RESTORED Tue Aug 07 23:37:36 2007: WM_WINDOWPOSCHANGING: 0,0,0,0 Tue Aug 07 23:37:36 2007: MUTEX: TDXContextMouseMutex:b951896a:4cf3c9a2:c184eabd:8aea924e Tue Aug 07 23:37:37 2007: SetDisplay: 800x600, 0 Tue Aug 07 23:37:37 2007: WM_WINDOWPOSCHANGING: 0,0,0,0 Tue Aug 07 23:37:37 2007: WM_WINDOWPOSCHANGING: 0,0,0,0 Tue Aug 07 23:37:37 2007: WM_WINDOWPOSCHANGING: 0,0,0,0 Tue Aug 07 23:37:37 2007: WM_WINDOWPOSCHANGING: 0,0,525,394 Tue Aug 07 23:37:37 2007: WM_SIZE: SIZE_RESTORED Tue Aug 07 23:37:37 2007: HandleActivation: 1 Tue Aug 07 23:37:37 2007: SetDisplay:ReleaseAssets Tue Aug 07 23:37:37 2007: TDXContext::Create windowed:800x600, 32bpp Tue Aug 07 23:37:37 2007: Backbuffer info DDSURFACE: (525x394) Format: DDPF_RGB: Bits: 32 (R:00ff0000) (G:0000ff00) (B:000000ff) lPitch: 2112 DDSCAPS_3DDEVICE : This surface can be used for 3-D rendering. Applications can use this flag to ensure that a device that can render only to a certain heap has off-screen surfaces allocated from the correct heap. If this flag is set for a heap, the surface is not allocated from that heap. DDSCAPS_LOCALVIDMEM : This surface exists in true, local video memory, rather than nonlocal video memory. If this flag is specified, DDSCAPS_VIDEOMEMORY must be specified, as well. This flag cannot be used with the DDSCAPS_NONLOCALVIDMEM flag. DDSCAPS_OFFSCREENPLAIN : This surface is any off-screen surface that is not an overlay, texture, z-buffer, front-buffer, back-buffer, or alpha surface. It is used to identify plain surfaces. DDSCAPS_VIDEOMEMORY : This surface exists in display memory. Tue Aug 07 23:37:43 2007: Device identifier: Driver: 'atidrae.dll' Description: 'ATI Technologies, Inc. RAGE XL AGP 2X' Version: 0:0 Vendor ID: 1002 (4098) Device ID: 474d (18253) SubSys: : 81002 (528386) Revision: 65 (101) GUID: d7b71ee2:11cf040d:200873b2:35cdc2ca Tue Aug 07 23:37:43 2007: mDxContext->Create succeeded. Tue Aug 07 23:37:43 2007: Device desc: Surface Caps: D3DDEVCAPS_DRAWPRIMTLVERTEX: Device exports a DrawPrimitive-aware hardware abstraction layer (HAL). This flag was introduced in DirectX 5.0. D3DDEVCAPS_EXECUTESYSTEMMEMORY: Device can use execute buffers from system memory. D3DDEVCAPS_FLOATTLVERTEX: Device accepts floating point for post-transform vertex data. D3DDEVCAPS_HWRASTERIZATION: Device has hardware acceleration for scene rasterization. D3DDEVCAPS_SORTEXACT: Device needs data sorted exactly. D3DDEVCAPS_SORTINCREASINGZ: Device needs data sorted for increasing depth. D3DDEVCAPS_TEXTUREVIDEOMEMORY: Device can retrieve textures from device memory. D3DDEVCAPS_TLVERTEXSYSTEMMEMORY: Device can use buffers from system memory for transformed and lit vertices. D3DDEVCAPS_TEXTURENONLOCALVIDMEM: Device can retrieve textures from nonlocal video (AGP) memory. This flag was introduced in DirectX 5.0. For more information about AGP memory, see Using Non-local Video Memory Surfaces in the DirectDraw documentation. dwDeviceRenderBitDepth: 1280 Device's rendering bit depth. This can be one or more of the following DirectDraw bit-depth constants: DDBD_8, DDBD_16, DDBD_24, or DDBD_32. dwDeviceZBufferBitDepth: 1024 Bit depth of the device's depth-buffer. This can be one of the following DirectDraw bit-depth constants: DDBD_8, DDBD_16, DDBD_24, or DDBD_32. dwMinTextureWidth, dwMaxTextureWidth: 1, 1024 Minimum/Maximum texture width for this device. dwMinTextureHeight, dwMaxTextureHeight: 1, 1024 Minimum/Maximum texture height for this device. dwMaxTextureRepeat: 0 Full range of the integer bits of the post-normalized texture indices. If the D3DPTEXTURECAPS_TEXREPEATNOTSCALEDBYSIZE bit is set, the device defers scaling by the texture size until after the texture address mode is applied. If not set, the device scales the texture indices by the texture size (largest level of detail) prior to interpolation. dwMaxTextureAspectRatio: 0 Maximum texture aspect ratio supported by the hardware; this is typically a power of 2. dwMaxAnisotropy: 0 Maximum valid value for the D3DTSS_MAXANISOTROPY texture-stage state. dvGuardBandLeft, dvGuardBandTop, dvGuardBandRight, and dvGuardBandBottom: 0, 0, 0, 0 The screen-space coordinates of the guard-band clipping region. Coordinates inside this rectangle but outside the viewport rectangle are automatically clipped. dvExtentsAdjust: 0 Number of pixels to adjust the extents rectangle outward to accommodate antialiasing kernels. TriCaps: dwMiscCaps D3DPMISCCAPS_CULLCCW: The driver supports counterclockwise culling through the D3DRENDERSTATE_CULLMODE state. (This applies only to triangle primitives.) This corresponds to the D3DCULL_CCW member of the D3DCULL enumerated type. D3DPMISCCAPS_CULLCW: The driver supports clockwise triangle culling through the D3DRENDERSTATE_CULLMODE state. (This applies only to triangle primitives.) This corresponds to the D3DCULL_CW member of the D3DCULL enumerated type. D3DPMISCCAPS_CULLNONE: The driver does not perform triangle culling. This corresponds to the D3DCULL_NONE member of the D3DCULL enumerated type. D3DPMISCCAPS_MASKPLANES: The device can perform a bitmask of color planes. D3DPMISCCAPS_MASKZ: The device can enable and disable modification of the depth buffer on pixel operations. dwRasterCaps D3DPRASTERCAPS_DITHER: The device can dither to improve color resolution. D3DPRASTERCAPS_FOGVERTEX: The device calculates the fog value during the lighting operation, places the value into the alpha component of the D3DCOLOR value given for the specular member of the D3DTLVERTEX structure and interpolates the fog value during rasterization. D3DPRASTERCAPS_SUBPIXEL: The device performs subpixel placement of z, color, and texture data, rather than working with the nearest integer pixel coordinate. This helps avoid bleed-through due to z imprecision and jitter of color and texture values for pixels. There is no corresponding state that can be enabled and disabled; the device either performs subpixel placement, or it does not. This bit is present only so that the you can better determine what the rendering quality will be. D3DPRASTERCAPS_TRANSLUCENTSORTINDEPENDENT: The device supports translucency that is not dependent on the sort order of the polygons. For more information, see D3DRENDERSTATE_TRANSLUCENTSORTINDEPENDENT. D3DPRASTERCAPS_ZTEST: The device can perform z-test operations. This effectively renders a primitive and indicates whether any z pixels have been rendered. dwShadeCaps D3DPSHADECAPS_ALPHAFLATBLEND D3DPSHADECAPS_COLORFLATRGB D3DPSHADECAPS_COLORGOURAUDRGB D3DPSHADECAPS_FOGFLAT D3DPSHADECAPS_FOGGOURAUD D3DPSHADECAPS_SPECULARFLATRGB D3DPSHADECAPS_SPECULARGOURAUDRGB dwTextureCaps D3DPTEXTURECAPS_ALPHA: Supports RGBA textures in the D3DTBLEND_DECAL and D3DTBLEND_MODULATE texture filtering modes. If this capability is not set, only RGB textures are supported in those modes. Regardless of the setting of this flag, alpha must always be supported in D3DTBLEND_DECALMASK, D3DTBLEND_DECALALPHA, and D3DTBLEND_MODULATEALPHA filtering modes whenever those filtering modes are available. D3DPTEXTURECAPS_PERSPECTIVE: Perspective correction is supported. D3DPTEXTURECAPS_POW2: All nonmipmapped textures must have widths and heights specified as powers of 2. (Mipmapped textures must always have dimensions that are powers of 2.) D3DPTEXTURECAPS_TRANSPARENCY: Texture transparency is supported. (Only those texels that are not the current transparent color are drawn.) LineCaps: dwMiscCaps D3DPMISCCAPS_MASKPLANES: The device can perform a bitmask of color planes. D3DPMISCCAPS_MASKZ: The device can enable and disable modification of the depth buffer on pixel operations. dwRasterCaps D3DPRASTERCAPS_DITHER: The device can dither to improve color resolution. D3DPRASTERCAPS_FOGVERTEX: The device calculates the fog value during the lighting operation, places the value into the alpha component of the D3DCOLOR value given for the specular member of the D3DTLVERTEX structure and interpolates the fog value during rasterization. D3DPRASTERCAPS_SUBPIXEL: The device performs subpixel placement of z, color, and texture data, rather than working with the nearest integer pixel coordinate. This helps avoid bleed-through due to z imprecision and jitter of color and texture values for pixels. There is no corresponding state that can be enabled and disabled; the device either performs subpixel placement, or it does not. This bit is present only so that the you can better determine what the rendering quality will be. D3DPRASTERCAPS_TRANSLUCENTSORTINDEPENDENT: The device supports translucency that is not dependent on the sort order of the polygons. For more information, see D3DRENDERSTATE_TRANSLUCENTSORTINDEPENDENT. D3DPRASTERCAPS_ZTEST: The device can perform z-test operations. This effectively renders a primitive and indicates whether any z pixels have been rendered. dwShadeCaps D3DPSHADECAPS_ALPHAFLATBLEND D3DPSHADECAPS_COLORFLATRGB D3DPSHADECAPS_COLORGOURAUDRGB D3DPSHADECAPS_FOGFLAT D3DPSHADECAPS_FOGGOURAUD dwTextureCaps D3DPTEXTURECAPS_ALPHA: Supports RGBA textures in the D3DTBLEND_DECAL and D3DTBLEND_MODULATE texture filtering modes. If this capability is not set, only RGB textures are supported in those modes. Regardless of the setting of this flag, alpha must always be supported in D3DTBLEND_DECALMASK, D3DTBLEND_DECALALPHA, and D3DTBLEND_MODULATEALPHA filtering modes whenever those filtering modes are available. D3DPTEXTURECAPS_PERSPECTIVE: Perspective correction is supported. D3DPTEXTURECAPS_POW2: All nonmipmapped textures must have widths and heights specified as powers of 2. (Mipmapped textures must always have dimensions that are powers of 2.) D3DPTEXTURECAPS_TRANSPARENCY: Texture transparency is supported. (Only those texels that are not the current transparent color are drawn.) TextureOpCaps: dwTextureOpCaps The D3DTOP_ADD texture blending operation is supported by this device. The D3DTOP_BLENDDIFFUSEALPHA texture blending operation is supported by this device. The D3DTOP_BLENDFACTORALPHA texture blending operation is supported by this device. The D3DTOP_BLENDTEXTUREALPHA texture blending operation is supported by this device. The D3DTOP_DISABLE texture blending operation is supported by this device. The D3DTOP_MODULATE texture blending operation is supported by this device. The D3DTOP_SELECTARG1 texture blending operation is supported by this device. The D3DTOP_SELECTARG2 texture blending operation is supported by this device. Tue Aug 07 23:37:43 2007: TEXT CALLIBRATION pass 0 Tue Aug 07 23:37:43 2007: TDxTextureData::CreateSurface: Requesting 2097152, 3867776 available. Tue Aug 07 23:37:43 2007: TEXT CALLIBRATION pass 1 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -1.000000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -0.750000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -0.500000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -0.250000 y: 0.000000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -1.000000 -0.250000 0.000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.000000 y: 0.000000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -1.000000 0.000000 0.000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.250000 y: 0.000000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -1.000000 0.250000 0.000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.500000 y: 0.000000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -1.000000 0.500000 0.000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.750000 y: 0.000000: 00000000 00ffffff 00ffffff 00000000 00000000 00ffffff 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -1.000000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -0.750000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -0.500000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -0.250000 y: 0.000000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -0.750000 -0.250000 0.000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.000000 y: 0.000000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -0.750000 0.000000 0.000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.250000 y: 0.000000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -0.750000 0.250000 0.000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.500000 y: 0.000000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -0.750000 0.500000 0.000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.750000 y: 0.000000: 00000000 00ffffff 00ffffff 00000000 00000000 00ffffff 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -1.000000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -0.750000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -0.500000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -0.250000 y: 0.000000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -0.500000 -0.250000 0.000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.000000 y: 0.000000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -0.500000 0.000000 0.000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.250000 y: 0.000000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -0.500000 0.250000 0.000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.500000 y: 0.000000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -0.500000 0.500000 0.000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.750000 y: 0.000000: 00000000 00ffffff 00ffffff 00000000 00000000 00ffffff 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -1.000000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -0.750000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -0.500000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -0.250000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.000000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.250000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.500000 y: 0.000000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.750000 y: 0.000000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -1.000000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -0.750000 y: 0.250000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -1.000000 -0.750000 0.250000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -0.500000 y: 0.250000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -1.000000 -0.500000 0.250000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -0.250000 y: 0.250000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -1.000000 -0.250000 0.250000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.000000 y: 0.250000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -1.000000 0.000000 0.250000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.250000 y: 0.250000: 00000000 00ffffff 00ffffff 00000000 00000000 00ffffff 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.500000 y: 0.250000: 00000000 00ffffff 00ffffff 00000000 00000000 00ffffff 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.750000 y: 0.250000: 00000000 00ffffff 00ffffff 00000000 00000000 00ffffff 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -1.000000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -0.750000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -0.500000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -0.250000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.000000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.250000 y: 0.250000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.500000 y: 0.250000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.750000 y: 0.250000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -1.000000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -0.750000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -0.500000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -0.250000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.000000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.250000 y: 0.250000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.500000 y: 0.250000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.750000 y: 0.250000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -1.000000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -0.750000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -0.500000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -0.250000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.000000 y: 0.250000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.250000 y: 0.250000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.500000 y: 0.250000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.750000 y: 0.250000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -1.000000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -0.750000 y: 0.500000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -1.000000 -0.750000 0.500000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -0.500000 y: 0.500000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -1.000000 -0.500000 0.500000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -0.250000 y: 0.500000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -1.000000 -0.250000 0.500000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.000000 y: 0.500000: 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION SUCCESS: -1.000000 0.000000 0.500000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.250000 y: 0.500000: 00000000 00ffffff 00ffffff 00000000 00000000 00ffffff 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.500000 y: 0.500000: 00000000 00ffffff 00ffffff 00000000 00000000 00ffffff 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.750000 y: 0.500000: 00000000 00ffffff 00ffffff 00000000 00000000 00ffffff 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -1.000000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -0.750000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -0.500000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -0.250000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.000000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.250000 y: 0.500000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.500000 y: 0.500000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.750000 y: 0.500000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -1.000000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -0.750000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -0.500000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -0.250000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.000000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.250000 y: 0.500000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.500000 y: 0.500000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.750000 y: 0.500000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -1.000000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -0.750000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -0.500000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -0.250000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.000000 y: 0.500000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.250000 y: 0.500000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.500000 y: 0.500000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.750000 y: 0.500000: 00000000 00000000 00ffffff 00000000 00000000 00000000 00ffffff 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -1.000000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -0.750000 y: 0.750000: 00000000 00000000 00000000 00000000 00ffffff 00000000 00000000 00ffffff Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -0.500000 y: 0.750000: 00000000 00000000 00000000 00000000 00ffffff 00000000 00000000 00ffffff Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: -0.250000 y: 0.750000: 00000000 00000000 00000000 00000000 00ffffff 00000000 00000000 00ffffff Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.000000 y: 0.750000: 00000000 00000000 00000000 00000000 00ffffff 00000000 00000000 00ffffff Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.250000 y: 0.750000: 00000000 00000000 00000000 00000000 00ffffff 00ffffff 00000000 00ffffff Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.500000 y: 0.750000: 00000000 00000000 00000000 00000000 00ffffff 00ffffff 00000000 00ffffff Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -1.000000 x2: 0.750000 y: 0.750000: 00000000 00000000 00000000 00000000 00ffffff 00ffffff 00000000 00ffffff Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -1.000000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -0.750000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -0.500000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: -0.250000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.000000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.250000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.500000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.750000 x2: 0.750000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -1.000000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -0.750000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -0.500000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: -0.250000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.000000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.250000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.500000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.500000 x2: 0.750000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -1.000000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -0.750000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -0.500000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: -0.250000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.000000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.250000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.500000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:44 2007: TEXT CALLIBRATION PIXELS x1: -0.250000 x2: 0.750000 y: 0.750000: 00000000 00000000 00000000 00000000 00000000 00ffffff 00000000 00000000 Tue Aug 07 23:37:46 2007: WM_PAINT 4064c 0 0 Tue Aug 07 23:37:46 2007: FORCING REDRAW Tue Aug 07 23:37:51 2007: WM_PAINT 4064c 0 0 Tue Aug 07 23:37:51 2007: FORCING REDRAW Tue Aug 07 23:38:25 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:25 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:25 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:25 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:25 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:25 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:25 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:25 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:26 2007: TPlatformData::Restore: mDirectDraw NULL. Calling SetDisplay() Tue Aug 07 23:38:26 2007: SetDisplay: 800x600, 0 Tue Aug 07 23:38:26 2007: WM_WINDOWPOSCHANGING: 0,0,0,0 Tue Aug 07 23:38:26 2007: WndProc: WM_KILLFOCUS, 263734, 0 Tue Aug 07 23:38:26 2007: WM_WINDOWPOSCHANGING: 0,0,0,0 Tue Aug 07 23:38:26 2007: WM_WINDOWPOSCHANGING: 0,0,0,0 Tue Aug 07 23:38:26 2007: WM_WINDOWPOSCHANGING: 0,0,525,394 Tue Aug 07 23:38:26 2007: SetDisplay:ReleaseAssets Tue Aug 07 23:38:26 2007: WM_PAINT 4064c 0 0 Tue Aug 07 23:38:26 2007: WM_PAINT 4064c 0 0 Tue Aug 07 23:38:45 2007: TDXContext::Create windowed:800x600, 16bpp Tue Aug 07 23:38:46 2007: Backbuffer info DDSURFACE: (525x394) Format: DDPF_RGB: Bits: 32 (R:00ff0000) (G:0000ff00) (B:000000ff) lPitch: 2112 DDSCAPS_3DDEVICE : This surface can be used for 3-D rendering. Applications can use this flag to ensure that a device that can render only to a certain heap has off-screen surfaces allocated from the correct heap. If this flag is set for a heap, the surface is not allocated from that heap. DDSCAPS_LOCALVIDMEM : This surface exists in true, local video memory, rather than nonlocal video memory. If this flag is specified, DDSCAPS_VIDEOMEMORY must be specified, as well. This flag cannot be used with the DDSCAPS_NONLOCALVIDMEM flag. DDSCAPS_OFFSCREENPLAIN : This surface is any off-screen surface that is not an overlay, texture, z-buffer, front-buffer, back-buffer, or alpha surface. It is used to identify plain surfaces. DDSCAPS_VIDEOMEMORY : This surface exists in display memory. Tue Aug 07 23:38:46 2007: Device identifier: Driver: 'atidrae.dll' Description: 'ATI Technologies, Inc. RAGE XL AGP 2X' Version: 0:0 Vendor ID: 1002 (4098) Device ID: 474d (18253) SubSys: : 81002 (528386) Revision: 65 (101) GUID: d7b71ee2:11cf040d:200873b2:35cdc2ca Tue Aug 07 23:38:46 2007: mDxContext->Create succeeded. Tue Aug 07 23:38:46 2007: Device desc: Surface Caps: D3DDEVCAPS_DRAWPRIMTLVERTEX: Device exports a DrawPrimitive-aware hardware abstraction layer (HAL). This flag was introduced in DirectX 5.0. D3DDEVCAPS_EXECUTESYSTEMMEMORY: Device can use execute buffers from system memory. D3DDEVCAPS_FLOATTLVERTEX: Device accepts floating point for post-transform vertex data. D3DDEVCAPS_HWRASTERIZATION: Device has hardware acceleration for scene rasterization. D3DDEVCAPS_SORTEXACT: Device needs data sorted exactly. D3DDEVCAPS_SORTINCREASINGZ: Device needs data sorted for increasing depth. D3DDEVCAPS_TEXTUREVIDEOMEMORY: Device can retrieve textures from device memory. D3DDEVCAPS_TLVERTEXSYSTEMMEMORY: Device can use buffers from system memory for transformed and lit vertices. D3DDEVCAPS_TEXTURENONLOCALVIDMEM: Device can retrieve textures from nonlocal video (AGP) memory. This flag was introduced in DirectX 5.0. For more information about AGP memory, see Using Non-local Video Memory Surfaces in the DirectDraw documentation. dwDeviceRenderBitDepth: 1280 Device's rendering bit depth. This can be one or more of the following DirectDraw bit-depth constants: DDBD_8, DDBD_16, DDBD_24, or DDBD_32. dwDeviceZBufferBitDepth: 1024 Bit depth of the device's depth-buffer. This can be one of the following DirectDraw bit-depth constants: DDBD_8, DDBD_16, DDBD_24, or DDBD_32. dwMinTextureWidth, dwMaxTextureWidth: 1, 1024 Minimum/Maximum texture width for this device. dwMinTextureHeight, dwMaxTextureHeight: 1, 1024 Minimum/Maximum texture height for this device. dwMaxTextureRepeat: 0 Full range of the integer bits of the post-normalized texture indices. If the D3DPTEXTURECAPS_TEXREPEATNOTSCALEDBYSIZE bit is set, the device defers scaling by the texture size until after the texture address mode is applied. If not set, the device scales the texture indices by the texture size (largest level of detail) prior to interpolation. dwMaxTextureAspectRatio: 0 Maximum texture aspect ratio supported by the hardware; this is typically a power of 2. dwMaxAnisotropy: 0 Maximum valid value for the D3DTSS_MAXANISOTROPY texture-stage state. dvGuardBandLeft, dvGuardBandTop, dvGuardBandRight, and dvGuardBandBottom: 0, 0, 0, 0 The screen-space coordinates of the guard-band clipping region. Coordinates inside this rectangle but outside the viewport rectangle are automatically clipped. dvExtentsAdjust: 0 Number of pixels to adjust the extents rectangle outward to accommodate antialiasing kernels. TriCaps: dwMiscCaps D3DPMISCCAPS_CULLCCW: The driver supports counterclockwise culling through the D3DRENDERSTATE_CULLMODE state. (This applies only to triangle primitives.) This corresponds to the D3DCULL_CCW member of the D3DCULL enumerated type. D3DPMISCCAPS_CULLCW: The driver supports clockwise triangle culling through the D3DRENDERSTATE_CULLMODE state. (This applies only to triangle primitives.) This corresponds to the D3DCULL_CW member of the D3DCULL enumerated type. D3DPMISCCAPS_CULLNONE: The driver does not perform triangle culling. This corresponds to the D3DCULL_NONE member of the D3DCULL enumerated type. D3DPMISCCAPS_MASKPLANES: The device can perform a bitmask of color planes. D3DPMISCCAPS_MASKZ: The device can enable and disable modification of the depth buffer on pixel operations. dwRasterCaps D3DPRASTERCAPS_DITHER: The device can dither to improve color resolution. D3DPRASTERCAPS_FOGVERTEX: The device calculates the fog value during the lighting operation, places the value into the alpha component of the D3DCOLOR value given for the specular member of the D3DTLVERTEX structure and interpolates the fog value during rasterization. D3DPRASTERCAPS_SUBPIXEL: The device performs subpixel placement of z, color, and texture data, rather than working with the nearest integer pixel coordinate. This helps avoid bleed-through due to z imprecision and jitter of color and texture values for pixels. There is no corresponding state that can be enabled and disabled; the device either performs subpixel placement, or it does not. This bit is present only so that the you can better determine what the rendering quality will be. D3DPRASTERCAPS_TRANSLUCENTSORTINDEPENDENT: The device supports translucency that is not dependent on the sort order of the polygons. For more information, see D3DRENDERSTATE_TRANSLUCENTSORTINDEPENDENT. D3DPRASTERCAPS_ZTEST: The device can perform z-test operations. This effectively renders a primitive and indicates whether any z pixels have been rendered. dwShadeCaps D3DPSHADECAPS_ALPHAFLATBLEND D3DPSHADECAPS_COLORFLATRGB D3DPSHADECAPS_COLORGOURAUDRGB D3DPSHADECAPS_FOGFLAT D3DPSHADECAPS_FOGGOURAUD D3DPSHADECAPS_SPECULARFLATRGB D3DPSHADECAPS_SPECULARGOURAUDRGB dwTextureCaps D3DPTEXTURECAPS_ALPHA: Supports RGBA textures in the D3DTBLEND_DECAL and D3DTBLEND_MODULATE texture filtering modes. If this capability is not set, only RGB textures are supported in those modes. Regardless of the setting of this flag, alpha must always be supported in D3DTBLEND_DECALMASK, D3DTBLEND_DECALALPHA, and D3DTBLEND_MODULATEALPHA filtering modes whenever those filtering modes are available. D3DPTEXTURECAPS_PERSPECTIVE: Perspective correction is supported. D3DPTEXTURECAPS_POW2: All nonmipmapped textures must have widths and heights specified as powers of 2. (Mipmapped textures must always have dimensions that are powers of 2.) D3DPTEXTURECAPS_TRANSPARENCY: Texture transparency is supported. (Only those texels that are not the current transparent color are drawn.) LineCaps: dwMiscCaps D3DPMISCCAPS_MASKPLANES: The device can perform a bitmask of color planes. D3DPMISCCAPS_MASKZ: The device can enable and disable modification of the depth buffer on pixel operations. dwRasterCaps D3DPRASTERCAPS_DITHER: The device can dither to improve color resolution. D3DPRASTERCAPS_FOGVERTEX: The device calculates the fog value during the lighting operation, places the value into the alpha component of the D3DCOLOR value given for the specular member of the D3DTLVERTEX structure and interpolates the fog value during rasterization. D3DPRASTERCAPS_SUBPIXEL: The device performs subpixel placement of z, color, and texture data, rather than working with the nearest integer pixel coordinate. This helps avoid bleed-through due to z imprecision and jitter of color and texture values for pixels. There is no corresponding state that can be enabled and disabled; the device either performs subpixel placement, or it does not. This bit is present only so that the you can better determine what the rendering quality will be. D3DPRASTERCAPS_TRANSLUCENTSORTINDEPENDENT: The device supports translucency that is not dependent on the sort order of the polygons. For more information, see D3DRENDERSTATE_TRANSLUCENTSORTINDEPENDENT. D3DPRASTERCAPS_ZTEST: The device can perform z-test operations. This effectively renders a primitive and indicates whether any z pixels have been rendered. dwShadeCaps D3DPSHADECAPS_ALPHAFLATBLEND D3DPSHADECAPS_COLORFLATRGB D3DPSHADECAPS_COLORGOURAUDRGB D3DPSHADECAPS_FOGFLAT D3DPSHADECAPS_FOGGOURAUD dwTextureCaps D3DPTEXTURECAPS_ALPHA: Supports RGBA textures in the D3DTBLEND_DECAL and D3DTBLEND_MODULATE texture filtering modes. If this capability is not set, only RGB textures are supported in those modes. Regardless of the setting of this flag, alpha must always be supported in D3DTBLEND_DECALMASK, D3DTBLEND_DECALALPHA, and D3DTBLEND_MODULATEALPHA filtering modes whenever those filtering modes are available. D3DPTEXTURECAPS_PERSPECTIVE: Perspective correction is supported. D3DPTEXTURECAPS_POW2: All nonmipmapped textures must have widths and heights specified as powers of 2. (Mipmapped textures must always have dimensions that are powers of 2.) D3DPTEXTURECAPS_TRANSPARENCY: Texture transparency is supported. (Only those texels that are not the current transparent color are drawn.) TextureOpCaps: dwTextureOpCaps The D3DTOP_ADD texture blending operation is supported by this device. The D3DTOP_BLENDDIFFUSEALPHA texture blending operation is supported by this device. The D3DTOP_BLENDFACTORALPHA texture blending operation is supported by this device. The D3DTOP_BLENDTEXTUREALPHA texture blending operation is supported by this device. The D3DTOP_DISABLE texture blending operation is supported by this device. The D3DTOP_MODULATE texture blending operation is supported by this device. The D3DTOP_SELECTARG1 texture blending operation is supported by this device. The D3DTOP_SELECTARG2 texture blending operation is supported by this device. Tue Aug 07 23:38:47 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:47 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:47 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:47 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:47 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:47 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:47 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585 Tue Aug 07 23:38:47 2007: DX Error: DirectDraw does not have enough display memory to perform the operation. , File .\dxtexturedata.cpp, Line 1585
I have no idea what all that stuff is. If you do not know what it relates to, just delete it. Also delete the ComboFix[1} folder. Please run the tool. Trevuren
ComboFix 08-02.05.3 - Ian 2008-02-09 12:14:22.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.136 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Program Files\winupdates

.
((((((((((((((((((((((((( Files Created from 2008-01-09 to 2008-02-09 )))))))))))))))))))))))))))))))
.

2008-02-06 23:18 . 2008-02-07 11:22 d——– C:\Program Files\SUPERAntiSpyware
2008-02-06 23:18 . 2008-02-06 23:18 d——– C:\Documents and Settings\Ian.KERRX4\Application Data\SUPERAntiSpyware.com
2008-02-06 23:18 . 2008-02-06 23:18 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-02-06 23:16 . 2008-02-06 23:16 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-05 13:24 . 2008-02-05 13:59 905 –a—— C:\WINDOWS\wininit.ini
2008-02-05 10:23 . 2008-02-05 10:23 d——– C:\Documents and Settings\Administrator.KERRX4\Application Data\Lavasoft
2008-02-05 00:22 . 2008-02-05 00:22 d——– C:\Documents and Settings\Ian.KERRX4\Application Data\Lavasoft
2008-02-05 00:00 . 2008-02-08 00:44 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-05 00:00 . 2008-02-08 00:42 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-02-04 23:47 . 2008-02-05 00:04 d——– C:\Program Files\AdwareAlert
2008-02-04 23:28 . 2008-02-04 23:28 d——– C:\WINDOWS\SpywarePro
2008-02-04 23:15 . 2008-02-04 23:23 d——– C:\Program Files\Easy SpyRemover
2008-02-04 22:36 . 2008-02-04 22:36 d——– C:\Documents and Settings\Ian.KERRX4\Application Data\WinAnonymous
2008-02-04 22:30 . 2008-02-07 10:59 d——– C:\Program Files\Common Files\WinAnonymous
2008-02-04 22:30 . 2008-02-04 22:30 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\WinAnonymous
2008-02-04 22:30 . 2008-02-04 22:30 dr——- C:\Documents and Settings\All Users.WINDOWS\Application Data\SalesMon
2008-01-25 00:24 . 2008-01-25 00:28 d——– C:\Program Files\Yahoo!
2008-01-19 12:27 . 2008-01-19 12:27 30,240 –a—— C:\Documents and Settings\Ian.KERRX4\Application Data\GDIPFONTCACHEV1.DAT
2008-01-15 16:56 . 2005-09-23 07:29 626,688 –a—— C:\WINDOWS\SYSTEM32\msvcr80.dll
2008-01-14 17:25 . 2008-01-14 17:25 d——– C:\Program Files\Learnatrade
2008-01-14 17:25 . 2008-01-14 17:25 159,498 –a—— C:\WINDOWS\Plumbing Level 2 Revision Uninstaller.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-09 12:22 11,818,272 –sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-08 20:36 158,588 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-08 17:09 ——— d—–w C:\Documents and Settings\Shaun.KERRX4\Application Data\LimeWire
2008-02-04 23:10 ——— d—a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-01-27 18:27 2,691,072 —-a-w C:\WINDOWS\Internet Logs\xDB17.tmp
2008-01-07 14:01 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-01-03 13:18 ——— d—–w C:\Documents and Settings\Ian.KERRX4\Application Data\Apple Computer
2007-12-30 14:33 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Kodak
2007-12-30 14:31 ——— d—–w C:\Program Files\Kodak
2007-12-30 14:29 ——— d—–w C:\Program Files\Common Files\Kodak
2007-12-17 20:53 0 —ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-12-17 20:53 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ggsemc_01005.Wdf
2007-12-17 20:46 20,520 —-a-w C:\WINDOWS\system32\drivers\ggsemc.sys
2007-12-17 20:46 13,352 —-a-w C:\WINDOWS\system32\drivers\ggflt.sys
2007-12-17 20:46 1,419,232 —-a-w C:\WINDOWS\SYSTEM32\wdfcoinstaller01005.dll
2007-12-17 20:42 ——— d—–w C:\Program Files\Sony Ericsson
2007-12-02 13:17 512 —-a-w C:\ScanSectorLog.dat
2007-11-14 16:05 75,248 —-a-w C:\WINDOWS\zllsputility.exe
2007-11-14 16:05 1,086,952 —-a-w C:\WINDOWS\SYSTEM32\zpeng24.dll
2007-10-31 14:33 1,163,776 —-a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2007-10-04 20:13 542,720 —-a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2007-09-25 15:35 67,359 —-a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_25_13_38_03_small.dmp.zip
2007-09-25 15:35 17,658,446 —-a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_25_13_37_11_full.dmp.zip
2007-09-25 12:40 110,080 —-a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2007-09-23 21:07 312,832 —-a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2007-09-19 21:58 770,560 —-a-w C:\WINDOWS\Internet Logs\xDB12.tmp
2007-09-09 18:50 79,227 —-a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_12_07_small.dmp.zip
2007-09-09 18:50 75,009 —-a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_10_01_small.dmp.zip
2007-09-09 18:50 72,321 —-a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_31_59_small.dmp.zip
2007-09-09 18:50 66,963 —-a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_31_46_small.dmp.zip
2007-09-09 18:50 5,573,705 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-09-09 18:44 86,528 —-a-w C:\WINDOWS\Internet Logs\xDB10.tmp
2007-09-09 18:44 2,507,776 —-a-w C:\WINDOWS\Internet Logs\xDB11.tmp
2007-09-08 11:05 497,664 —-a-w C:\WINDOWS\Internet Logs\xDB15B.tmp
2007-09-02 10:02 16,949,241 —-a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_09_01_19_05_41_full.dmp.zip
2007-09-01 18:05 836,608 —-a-w C:\WINDOWS\Internet Logs\xDB2B.tmp
2007-08-29 11:04 2,472,960 —-a-w C:\WINDOWS\Internet Logs\xDBF.tmp
2007-08-20 14:13 967,168 —-a-w C:\WINDOWS\Internet Logs\xDBE.tmp
2007-08-09 21:26 338,432 —-a-w C:\WINDOWS\Internet Logs\xDBD.tmp
2007-08-09 16:19 2,365,440 —-a-w C:\WINDOWS\Internet Logs\xDBC.tmp
2007-08-07 15:39 146,944 —-a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2007-08-06 15:29 176,128 —-a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2007-08-05 09:35 80,939 —-a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_08_04_19_48_23_small.dmp.zip
2007-08-05 09:35 74,434 —-a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_08_04_19_47_36_small.dmp.zip
2007-08-04 18:15 427,008 —-a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2007-08-04 14:52 2,338,816 —-a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2007-08-04 14:52 1,583,616 —-a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2007-08-04 09:27 167 —-a-w C:\Documents and Settings\Ian.KERRX4\5278.bat
2007-08-04 09:26 32,768 —-a-w C:\Documents and Settings\Ian.KERRX4\setup9x.exe
2007-08-04 09:26 13,347,383 —-a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_08_03_19_18_15_full.dmp.zip
2007-08-03 18:18 2,310,656 —-a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2007-08-02 16:04 2,310,144 —-a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2007-08-02 16:04 1,723,904 —-a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2007-07-15 01:05 2,718,720 —-a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2007-06-14 13:39 28,904 —-a-w C:\Documents and Settings\Antony\Application Data\GDIPFONTCACHEV1.DAT
2007-06-04 16:27 845,312 —-a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2007-06-04 16:27 1,847,296 —-a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2006-04-05 23:07 29,688 —-a-w C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
2005-05-07 05:00 48,128 —-a-w C:\Documents and Settings\Antony\cnmss Canon SELPHY DS810 (Local).dll
2004-09-03 18:35 266 –sh–w C:\Program Files\desktop.ini
2007-08-04 10:32 6,466 –sha-w C:\WINDOWS\SYSTEM32\gghkj.bak1
2007-08-04 18:14 7,634 –sh–w C:\WINDOWS\SYSTEM32\gghkj.ini2
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24 1694208]
"SpywareProMFC"="C:\Program Files\SpywarePro\SpywarePro.exe" [ ]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" [2007-03-14 15:52 3770024]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 12:20 227328]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"Easy SpyRemover"="C:\Program Files\Easy SpyRemover\EasySpyRemover.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 12:00 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 14:58 1744896]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 04:33:46 282624]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
NetScreen-Remote.lnk - C:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe [2007-08-02 14:24:18 65588]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R2 Crypto;Crypto;C:\WINDOWS\system32\drivers\Crypto.sys [2004-07-30 12:20]
R2 IPSECDRV;SafeNet IPSec Plugin;C:\WINDOWS\system32\Drivers\IPSECDRV.sys [2004-08-11 11:01]
R3 DniVap;SafeNet WAN Miniport (VA);C:\WINDOWS\system32\DRIVERS\vap.sys [2001-12-14 15:26]
S3 ggflt;SEMC USB Flash Driver Filter;C:\WINDOWS\system32\DRIVERS\ggflt.sys [2007-12-17 20:46]
S3 se44bus;Sony Ericsson Device 068 driver (WDM);C:\WINDOWS\system32\DRIVERS\se44bus.sys [2006-11-30 13:58]
S3 se44mdfl;Sony Ericsson Device 068 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\se44mdfl.sys [2006-11-30 13:58]
S3 se44mdm;Sony Ericsson Device 068 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\se44mdm.sys [2006-11-30 13:58]
S3 se44obex;Sony Ericsson Device 068 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\se44obex.sys [2006-07-25 12:54]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fb56f953-fbf3-11db-8e83-00d059f24eab}]
\Shell\AutoRun\command - F:\InstallTomTomHOME.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-30 17:00:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-27 14:21:01 C:\WINDOWS\Tasks\EasyShare Registration Task.job"
- C:\WINDOWS\system32\rundll32.exepC:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Kodak\EasyShareSetup\$REGIS~1\Registration_7.4.20.2.sxt _RegistrationOffer@16
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-09 12:22:17
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

**************************************************************************
.
Completion time: 2008-02-09 12:25:44
ComboFix-quarantined-files.txt 2008-02-09 12:24:44
.
2008-01-11 00:14:47 — E O F —



Logfile of HijackThis v1.99.1
Scan saved at 12:35:22, on 09/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TomTom HOME\TomTomHOME.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Ian.KERRX4\My Documents\Ian\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Easy SpyRemover] C:\Program Files\Easy SpyRemover\EasySpyRemover.exe /smart
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpywareProMFC] C:\Program Files\SpywarePro\SpywarePro.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NetScreen-Remote.lnk = C:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://uk.midas.games.yahoo.net/ctl/kingcomie.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1186233048395
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game03.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SafeNet Monitor Service (IPSECMON) - SafeNet - C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe
O23 - Service: SafeNet IKE Service (IREIKE) - SafeNet - C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
A. You don't appear to be running any anti-virus software

Anti-virus software are programs that detect, clean, and/or erase harmful virus files on a computer. Unchecked, virus files can unintentionally be forwarded to others, and thereby spread infection. Keeping your anti-virus updated is essential.

Please download a free anti-virus software from one these excellent vendors NOW:
It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts.


B. Using the Add/Remove program module in your Control Panel, please UNINSTALL the following "rogue" programs:

WinAnonymous
Easy SpyRemover


C. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\Internet Logs\xDB17.tmp
C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
C:\WINDOWS\system32\drivers\Msft_Kernel_ggsemc_01005.Wdf
C:\WINDOWS\system32\drivers\ggsemc.sys
C:\WINDOWS\system32\drivers\ggflt.sys
C:\WINDOWS\Internet Logs\xDB16.tmp
C:\WINDOWS\Internet Logs\xDB15.tmp
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_25_13_38_03_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_25_13_37_11_full.dmp.zip
C:\WINDOWS\Internet Logs\xDB14.tmp
C:\WINDOWS\Internet Logs\xDB13.tmp
C:\WINDOWS\Internet Logs\xDB12.tmp
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_12_07_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_10_01_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_31_59_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_31_46_small.dmp.zip
C:\WINDOWS\Internet Logs\tvDebug.zip
C:\WINDOWS\Internet Logs\xDB10.tmp
C:\WINDOWS\Internet Logs\xDB11.tmp
C:\WINDOWS\Internet Logs\xDB15B.tmp
C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_09_01_19_05_41_full.dmp.zip
C:\WINDOWS\Internet Logs\xDB2B.tmp
C:\WINDOWS\Internet Logs\xDBF.tmp
C:\WINDOWS\Internet Logs\xDBE.tmp
C:\WINDOWS\Internet Logs\xDBD.tmp
C:\WINDOWS\Internet Logs\xDBC.tmp
C:\WINDOWS\Internet Logs\xDBB.tmp
C:\WINDOWS\Internet Logs\xDBA.tmp
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_08_04_19_48_23_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_08_04_19_47_36_small.dmp.zip
C:\WINDOWS\Internet Logs\xDB9.tmp
C:\WINDOWS\Internet Logs\xDB8.tmp
C:\WINDOWS\Internet Logs\xDB7.tmp
C:\WINDOWS\Internet Logs\xDB9.tmp
C:\WINDOWS\Internet Logs\xDB8.tmp
C:\WINDOWS\Internet Logs\xDB7.tmp
C:\Documents and Settings\Ian.KERRX4\5278.bat
C:\Documents and Settings\Ian.KERRX4\setup9x.exe
C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_08_03_19_18_15_full.dmp.zip
C:\WINDOWS\Internet Logs\xDB6.tmp
C:\WINDOWS\Internet Logs\xDB5.tmp
C:\WINDOWS\Internet Logs\xDB3.tmp
C:\WINDOWS\Internet Logs\xDB4.tmp
C:\WINDOWS\Internet Logs\xDB1.tmp
C:\WINDOWS\Internet Logs\xDB2.tmp
C:\Documents and Settings\Antony\cnmss Canon SELPHY DS810 (Local).dll
C:\WINDOWS\SYSTEM32\gghkj.bak1
F:\InstallTomTomHOME.exe

Folder::
C:\Program Files\Easy SpyRemover
C:\Documents and Settings\Ian.KERRX4\Application Data\WinAnonymous
C:\Program Files\Common Files\WinAnonymous
C:\Documents and Settings\All Users.WINDOWS\Application Data\WinAnonymous
C:\Documents and Settings\All Users.WINDOWS\Application Data\SalesMon
C:\Program Files\SpywarePro

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareProMFC"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Easy SpyRemover"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fb56f953-fbf3-11db-8e83-00d059f24eab}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=-
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="" 
[-HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 08-02.05.3 - Ian 2008-02-09 19:49:51.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.203 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\Ian.KERRX4\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\Documents and Settings\Antony\cnmss Canon SELPHY DS810 (Local).dll
C:\Documents and Settings\Ian.KERRX4\5278.bat
C:\Documents and Settings\Ian.KERRX4\setup9x.exe
C:\WINDOWS\Internet Logs\tvDebug.zip
C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_08_03_19_18_15_full.dmp.zip
C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_09_01_19_05_41_full.dmp.zip
C:\WINDOWS\Internet Logs\xDB1.tmp
C:\WINDOWS\Internet Logs\xDB10.tmp
C:\WINDOWS\Internet Logs\xDB11.tmp
C:\WINDOWS\Internet Logs\xDB12.tmp
C:\WINDOWS\Internet Logs\xDB13.tmp
C:\WINDOWS\Internet Logs\xDB14.tmp
C:\WINDOWS\Internet Logs\xDB15.tmp
C:\WINDOWS\Internet Logs\xDB15B.tmp
C:\WINDOWS\Internet Logs\xDB16.tmp
C:\WINDOWS\Internet Logs\xDB17.tmp
C:\WINDOWS\Internet Logs\xDB2.tmp
C:\WINDOWS\Internet Logs\xDB2B.tmp
C:\WINDOWS\Internet Logs\xDB3.tmp
C:\WINDOWS\Internet Logs\xDB4.tmp
C:\WINDOWS\Internet Logs\xDB5.tmp
C:\WINDOWS\Internet Logs\xDB6.tmp
C:\WINDOWS\Internet Logs\xDB7.tmp
C:\WINDOWS\Internet Logs\xDB8.tmp
C:\WINDOWS\Internet Logs\xDB9.tmp
C:\WINDOWS\Internet Logs\xDBA.tmp
C:\WINDOWS\Internet Logs\xDBB.tmp
C:\WINDOWS\Internet Logs\xDBC.tmp
C:\WINDOWS\Internet Logs\xDBD.tmp
C:\WINDOWS\Internet Logs\xDBE.tmp
C:\WINDOWS\Internet Logs\xDBF.tmp
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_08_04_19_47_36_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_08_04_19_48_23_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_10_01_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_12_07_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_31_46_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_31_59_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_25_13_37_11_full.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_25_13_38_03_small.dmp.zip
C:\WINDOWS\system32\drivers\ggflt.sys
C:\WINDOWS\system32\drivers\ggsemc.sys
C:\WINDOWS\system32\drivers\Msft_Kernel_ggsemc_01005.Wdf
C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
C:\WINDOWS\SYSTEM32\gghkj.bak1
F:\InstallTomTomHOME.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users.WINDOWS\Application Data\SalesMon
C:\Documents and Settings\All Users.WINDOWS\Application Data\WinAnonymous
C:\Documents and Settings\All Users.WINDOWS\Application Data\WinAnonymous\Abbr
C:\Documents and Settings\All Users.WINDOWS\Application Data\WinAnonymous\prod_code
C:\Documents and Settings\Antony\cnmss Canon SELPHY DS810 (Local).dll
C:\Documents and Settings\Ian.KERRX4\5278.bat
C:\Documents and Settings\Ian.KERRX4\Application Data\WinAnonymous
C:\Documents and Settings\Ian.KERRX4\Application Data\WinAnonymous\Logs\update.log
C:\Documents and Settings\Ian.KERRX4\setup9x.exe
C:\Program Files\Common Files\WinAnonymous
C:\Program Files\Easy SpyRemover
C:\Program Files\Easy SpyRemover\Easy SpyRemover.log
C:\Program Files\Easy SpyRemover\settings.ini
C:\WINDOWS\Internet Logs\tvDebug.zip
C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_08_03_19_18_15_full.dmp.zip
C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_09_01_19_05_41_full.dmp.zip
C:\WINDOWS\Internet Logs\xDB1.tmp
C:\WINDOWS\Internet Logs\xDB10.tmp
C:\WINDOWS\Internet Logs\xDB11.tmp
C:\WINDOWS\Internet Logs\xDB12.tmp
C:\WINDOWS\Internet Logs\xDB13.tmp
C:\WINDOWS\Internet Logs\xDB14.tmp
C:\WINDOWS\Internet Logs\xDB15.tmp
C:\WINDOWS\Internet Logs\xDB15B.tmp
C:\WINDOWS\Internet Logs\xDB16.tmp
C:\WINDOWS\Internet Logs\xDB17.tmp
C:\WINDOWS\Internet Logs\xDB2.tmp
C:\WINDOWS\Internet Logs\xDB2B.tmp
C:\WINDOWS\Internet Logs\xDB3.tmp
C:\WINDOWS\Internet Logs\xDB4.tmp
C:\WINDOWS\Internet Logs\xDB5.tmp
C:\WINDOWS\Internet Logs\xDB6.tmp
C:\WINDOWS\Internet Logs\xDB7.tmp
C:\WINDOWS\Internet Logs\xDB8.tmp
C:\WINDOWS\Internet Logs\xDB9.tmp
C:\WINDOWS\Internet Logs\xDBA.tmp
C:\WINDOWS\Internet Logs\xDBB.tmp
C:\WINDOWS\Internet Logs\xDBC.tmp
C:\WINDOWS\Internet Logs\xDBD.tmp
C:\WINDOWS\Internet Logs\xDBE.tmp
C:\WINDOWS\Internet Logs\xDBF.tmp
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_08_04_19_47_36_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_08_04_19_48_23_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_10_01_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_12_07_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_31_46_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_09_11_31_59_small.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_25_13_37_11_full.dmp.zip
C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_25_13_38_03_small.dmp.zip
C:\WINDOWS\system32\drivers\ggflt.sys
C:\WINDOWS\system32\drivers\ggsemc.sys
C:\WINDOWS\system32\drivers\Msft_Kernel_ggsemc_01005.Wdf
C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
C:\WINDOWS\SYSTEM32\gghkj.bak1

.
((((((((((((((((((((((((( Files Created from 2008-01-09 to 2008-02-09 )))))))))))))))))))))))))))))))
.

2008-02-06 23:18 . 2008-02-07 11:22 d——– C:\Program Files\SUPERAntiSpyware
2008-02-06 23:18 . 2008-02-06 23:18 d——– C:\Documents and Settings\Ian.KERRX4\Application Data\SUPERAntiSpyware.com
2008-02-06 23:18 . 2008-02-06 23:18 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-02-06 23:16 . 2008-02-06 23:16 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-05 13:24 . 2008-02-05 13:59 905 –a—— C:\WINDOWS\wininit.ini
2008-02-05 10:23 . 2008-02-05 10:23 d——– C:\Documents and Settings\Administrator.KERRX4\Application Data\Lavasoft
2008-02-05 00:22 . 2008-02-05 00:22 d——– C:\Documents and Settings\Ian.KERRX4\Application Data\Lavasoft
2008-02-05 00:00 . 2008-02-08 00:44 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-05 00:00 . 2008-02-08 00:42 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-02-04 23:47 . 2008-02-05 00:04 d——– C:\Program Files\AdwareAlert
2008-02-04 23:28 . 2008-02-04 23:28 d——– C:\WINDOWS\SpywarePro
2008-01-25 00:24 . 2008-01-25 00:28 d——– C:\Program Files\Yahoo!
2008-01-19 12:27 . 2008-01-19 12:27 30,240 –a—— C:\Documents and Settings\Ian.KERRX4\Application Data\GDIPFONTCACHEV1.DAT
2008-01-15 16:56 . 2005-09-23 07:29 626,688 –a—— C:\WINDOWS\SYSTEM32\msvcr80.dll
2008-01-14 17:25 . 2008-01-14 17:25 d——– C:\Program Files\Learnatrade
2008-01-14 17:25 . 2008-01-14 17:25 159,498 –a—— C:\WINDOWS\Plumbing Level 2 Revision Uninstaller.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-09 20:02 11,889,952 –sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-09 19:58 160,268 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-08 17:09 ——— d—–w C:\Documents and Settings\Shaun.KERRX4\Application Data\LimeWire
2008-02-04 23:10 ——— d—a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-01-07 14:01 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-01-03 13:18 ——— d—–w C:\Documents and Settings\Ian.KERRX4\Application Data\Apple Computer
2007-12-30 14:33 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Kodak
2007-12-30 14:31 ——— d—–w C:\Program Files\Kodak
2007-12-30 14:29 ——— d—–w C:\Program Files\Common Files\Kodak
2007-12-17 20:42 ——— d—–w C:\Program Files\Sony Ericsson
2007-12-02 13:17 512 —-a-w C:\ScanSectorLog.dat
2007-11-14 16:05 75,248 —-a-w C:\WINDOWS\zllsputility.exe
2007-06-14 13:39 28,904 —-a-w C:\Documents and Settings\Antony\Application Data\GDIPFONTCACHEV1.DAT
2006-04-05 23:07 29,688 —-a-w C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
2004-09-03 18:35 266 –sh–w C:\Program Files\desktop.ini
2007-08-04 18:14 7,634 –sh–w C:\WINDOWS\SYSTEM32\gghkj.ini2
.



Logfile of HijackThis v1.99.1
Scan saved at 12:41, on 2008-02-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TomTom HOME\TomTomHOME.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Ian.KERRX4\My Documents\Ian\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NetScreen-Remote.lnk = C:\Program Files\Juniper\NetScreen-Remote\SafeCfg.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://uk.midas.games.yahoo.net/ctl/kingcomie.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1186233048395
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game03.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SafeNet Monitor Service (IPSECMON) - SafeNet - C:\Program Files\Juniper\NetScreen-Remote\IPSecMon.exe
O23 - Service: SafeNet IKE Service (IREIKE) - SafeNet - C:\Program Files\Juniper\NetScreen-Remote\IreIKE.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
A. Things are looking up but we are still getting incomplete ComboFix logs. I have a suspicion that there may be some missing or damaged critical system files in your Operating System. We will check later. Please run through the following procedures, if for some unknown reason, your system balks during one of the steps, note the error message you received and continue with the following step. Remember to post any/all error messages in your reply.

First we need to see "Hidden Files"

To enable the viewing of Hidden files follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the checkbox labeled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
9. Press the Apply button and then the OK button and shutdown My Computer.
10. Now your computer is configured to show all hidden files.

Now we need you to boot into Safe Mode:

How to use the F8 method to Start Your Computer in Safe Mode*Restart the computer.
*as soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
*Use the arrow keys to select the Safe mode menu item
*press Enter.

Finally, using Windows Explorer, (Windows Key +E), locate and DELETE the following file:

C:\WINDOWS\SYSTEM32\gghkj.ini2<==File


B. Now let us see if we need to repair any files:

1. Please go to Start -> Run -> type cmd and press Enter.

2. At the command prompt type sfc /scannow, making sure to put a space between the "c" and the slash, and then press Enter. This will run the System File Checker.

3. Follow the prompts, and insert your Windows installation CD if requested.

4. Then please REBOOT your computer.


C. Lastly, Please download Deckard's System Scanner (DSS) to your desktop.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, a text file will open - Main.txt
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of Main.txt in your thread in the HijackThis Log Help Forum.
  • An additional text file, Extra.txt,will also be available (by default) in the following FOLDER, C:\Deckard\System Scanner.
  • Please go to that FOLDER and also copy the contents of Extra.txt to your post as well.
Note: some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so.

What DSS will do:

  • Create a new System Restore point in Windows XP and Vista.
  • Clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
  • Check some important areas of your system and produce a report for your analyst to review. DSS automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have it installed.

Post Logs:
  • DSS Scan Results: contents of 1) Main.txt and 2) Extra.txt
Finally, using Windows Explorer, (Windows Key +E), locate and DELETE the following file: C:\WINDOWS\SYSTEM32\gghkj.ini2<==File have looked and looked, and searched again and again there is no SYSTEM32 file on here.do i carry on

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI