This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] problems with computer

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 7:58:16 PM, on 2/11/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINNT\SYSTEM32\DWRCS.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\3Com\3Com 11Mbps Wireless LAN PCI Adapter\WLAN_Cfg.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Sprint music manager\MEMonitor.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\user\Desktop\New Folder (2)\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defa…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: IE - {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} - C:\Program Files\WinBudget\bin\matrix.dll
O2 - BHO: (no name) - {0F4D8A86-1233-6DC5-6557-3B71C404C3CC} - C:\WINNT\system32\tfqheac.dll
O2 - BHO: XBTB04084 - {3D1ED03C-73AE-40dd-B952-AC2589DA3C45} - C:\WINNT\DOWNLO~1\CONFLICT.2\XHOLLY~1.DLL (file missing)
O2 - BHO: 0 - {52EB132C-1C84-40BC-F7AA-A9E75A823844} - C:\Program Files\microsoft frontpage\quzatedy629.dll (file missing)
O2 - BHO: Editor plugin - {66CEAA7E-6FBD-4e0f-BDD2-190D5A354C99} - micropr.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {a2d0db8b-cf21-4abf-bc63-2944e904ad4a} - C:\WINNT\system32\niarmhm.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {CD157654-62C0-4CA2-9221-5D6E90ABCB2E} - C:\WINNT\system32\tussp.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,0,8,0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [WLAN_Cfg.exe] C:\Program Files\3Com\3Com 11Mbps Wireless LAN PCI Adapter\WLAN_Cfg.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINNT\system32\avpqdcsl.dll",sitypnow
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [Insider] C:\Program Files\Insider\Insider.exe
O4 - HKCU\..\Run: [SpyDefender Shield] "C:\Program Files\SpyDefender Pro\SpyDefender.exe" –scan2
O4 - Startup: MEMonitor.lnk = C:\Program Files\Sprint music manager\MEMonitor.exe
O4 - Startup: TA_Start.lnk = C:\WINNT\system32\kpdsrngm.exe
O4 - Global Startup: HPAiODevice(hp officejet g series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O8 - Extra context menu item: &iSearch The Web - res://C:\WINNT\system32\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.drivecleaner.com
O15 - Trusted Zone: *.errorprotector.com
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imageservr.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantispyware.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.amaena.com (HKLM)
O15 - Trusted Zone: *.drivecleaner.com (HKLM)
O15 - Trusted Zone: *.errorprotector.com (HKLM)
O15 - Trusted Zone: *.errorsafe.com (HKLM)
O15 - Trusted Zone: *.imageservr.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantispyware.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.winfixer.com (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.birdville.k12.tx.us/CFIDE/classes/CFJava.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - https://livewc01.custhelp.com/7520-b289h-tu…l/java/RntX.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: pmnkkig - pmnkkig.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development - C:\WINNT\SYSTEM32\DWRCS.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
twoo,

Welcome to the Whatthetech forum, You posted twice already, your topic was replied to and you never replied back, we don't have the time and resources to analyze your log, offer suggestions and have you not reply.

You have a real mess going on, this is what you need to do. Run these programs in the order I have posted them

Download VundoFix to your desktop

  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.

Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.






Please download SuperAntiSpyware
Install the program
  • Run SuperAntiSpyware and click: Check for updates
  • Once the update is finished, on the main screen, click: Scan your computer
  • Check: Perform Complete Scan
  • Click Next to start the scan.
Superantispyware scans the computer, and when finished, lists all the infections found.
Make sure everything found has a check next to it, and press: Next <–Don't forget this
Then, click Finish

It is possible that the program asks to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
  • Click: Preferences
  • Click the Statistics/Logs tab
  • Under Scanner Logs, double-click SuperAntiSpyware Scan Log
It opens in your default text editor (such as Notepad)

Please provide the SuperAntiSpyware log in your reply, as well as a new HijackThis log.






Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post the Combofix log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall



Download: DelDomains and save it to the desktop.
  • Close all open windows and your browser
  • Right Click DelDomains.inf and select > Install
  • Reboot your computer
Internet Explorer is needed to run this properly.


I need to see the Vundofix log, the SAS log, the Combofix log and a New HJT log, if they wont fit all in one reply, take as many as you need to post them all
VundoFix V6.7.8

Checking Java version…

Java version is 1.4.2.6
Old versions of java are exploitable and should be removed.

Scan started at 5:59:38 PM 2/14/2008

Listing files found while scanning….

C:\WINNT\system32\avpqdcsl.dll
C:\WINNT\system32\cbjshjdw.exe
C:\WINNT\system32\fyfowruq.exe
C:\WINNT\system32\hgudyeli.exe
C:\WINNT\system32\htremume.exe
C:\WINNT\system32\lscdqpva.ini
C:\WINNT\system32\nohgplwo.exe
C:\WINNT\system32\owsynlcl.exe
C:\WINNT\system32\qcrcxwfn.exe
C:\WINNT\system32\riqppklv.exe
C:\WINNT\system32\tcctltxp.exe
C:\WINNT\system32\ulpesxax.exe
C:\WINNT\system32\xmkanncp.exe
C:\WINNT\system32\xoyuhpyr.exe

Beginning removal…

Attempting to delete C:\WINNT\system32\cbjshjdw.exe
C:\WINNT\system32\cbjshjdw.exe Has been deleted!

Attempting to delete C:\WINNT\system32\fyfowruq.exe
C:\WINNT\system32\fyfowruq.exe Has been deleted!

Attempting to delete C:\WINNT\system32\hgudyeli.exe
C:\WINNT\system32\hgudyeli.exe Has been deleted!

Attempting to delete C:\WINNT\system32\htremume.exe
C:\WINNT\system32\htremume.exe Has been deleted!

Attempting to delete C:\WINNT\system32\lscdqpva.ini
C:\WINNT\system32\lscdqpva.ini Has been deleted!

Attempting to delete C:\WINNT\system32\nohgplwo.exe
C:\WINNT\system32\nohgplwo.exe Has been deleted!

Attempting to delete C:\WINNT\system32\owsynlcl.exe
C:\WINNT\system32\owsynlcl.exe Has been deleted!

Attempting to delete C:\WINNT\system32\qcrcxwfn.exe
C:\WINNT\system32\qcrcxwfn.exe Has been deleted!

Attempting to delete C:\WINNT\system32\riqppklv.exe
C:\WINNT\system32\riqppklv.exe Has been deleted!

Attempting to delete C:\WINNT\system32\tcctltxp.exe
C:\WINNT\system32\tcctltxp.exe Has been deleted!

Attempting to delete C:\WINNT\system32\ulpesxax.exe
C:\WINNT\system32\ulpesxax.exe Has been deleted!

Attempting to delete C:\WINNT\system32\xmkanncp.exe
C:\WINNT\system32\xmkanncp.exe Has been deleted!

Attempting to delete C:\WINNT\system32\xoyuhpyr.exe
C:\WINNT\system32\xoyuhpyr.exe Has been deleted!

Performing Repairs to the registry.
Done!
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/15/2008 at 08:52 PM

Application Version : 3.9.1008

Core Rules Database Version : 3403
Trace Rules Database Version: 1395

Scan type : Complete Scan
Total Scan Time : 01:24:19

Memory items scanned : 312
Memory threats detected : 1
Registry items scanned : 5113
Registry threats detected : 67
File items scanned : 31623
File threats detected : 177

Adware.ClickSpring/Resident
C:\WINNT\SYSTEM32\TFQHEAC.DLL
C:\WINNT\SYSTEM32\TFQHEAC.DLL

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}
HKCR\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}
HKCR\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}
HKCR\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}#AppID
HKCR\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}\InprocServer32
HKCR\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}\InprocServer32#ThreadingModel
HKCR\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}\ProgID
HKCR\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}\Programmable
HKCR\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}\TypeLib
HKCR\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}\VersionIndependentProgID
C:\PROGRAM FILES\WINBUDGET\BIN\MATRIX.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}

Adware.ClickSpring
HKLM\Software\Classes\CLSID\{0F4D8A86-1233-6DC5-6557-3B71C404C3CC}
HKCR\CLSID\{0F4D8A86-1233-6DC5-6557-3B71C404C3CC}
HKCR\CLSID\{0F4D8A86-1233-6DC5-6557-3B71C404C3CC}\InprocServer32
HKCR\CLSID\{0F4D8A86-1233-6DC5-6557-3B71C404C3CC}\InprocServer32#ThreadingModel
HKCR\CLSID\{0F4D8A86-1233-6DC5-6557-3B71C404C3CC}\Programmable
HKCR\CLSID\{0F4D8A86-1233-6DC5-6557-3B71C404C3CC}\TypeLib
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F4D8A86-1233-6DC5-6557-3B71C404C3CC}

Trojan.Unclassified/KBPrty
HKLM\Software\Classes\CLSID\{9C0ADB68-353A-61DD-ED09-1D8003A61111}
HKCR\CLSID\{9C0ADB68-353A-61DD-ED09-1D8003A61111}
HKCR\CLSID\{9C0ADB68-353A-61DD-ED09-1D8003A61111}\InProcServer32
HKCR\CLSID\{9C0ADB68-353A-61DD-ED09-1D8003A61111}\InProcServer32#ThreadingModel
C:\WINNT\SYSTEM32\KB1111P.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{9C0ADB68-353A-61DD-ED09-1D8003A61111}

Spyware.PWS/Check Variant
HKLM\Software\Classes\CLSID\{9C0CFA58-3A6F-51ba-9EFE-5320F4F621BA}
HKCR\CLSID\{9C0CFA58-3A6F-51BA-9EFE-5320F4F621BA}
HKCR\CLSID\{9C0CFA58-3A6F-51BA-9EFE-5320F4F621BA}\InProcServer32
HKCR\CLSID\{9C0CFA58-3A6F-51BA-9EFE-5320F4F621BA}\InProcServer32#ThreadingModel
C:\WINNT\SYSTEM32\BDSCHECA001.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{9C0CFA58-3A6F-51ba-9EFE-5320F4F621BA}
HKCR\CLSID\{9C0CFA58-3A6F-51BA-9EFE-5320F4F621BA}

Browser Hijacker.Internet Explorer Zone Hijack
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\amaena.com
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\amaena.com#*
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsafe.com
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsafe.com#*
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\imagesrvr.com
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\imagesrvr.com#*
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispyware.com
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispyware.com#*
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantivirus.com
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantivirus.com#*
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfixer.com
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfixer.com#*
HKU\S-1-5-21-448539723-839522115-1343024091-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\amaena.com
HKU\S-1-5-21-448539723-839522115-1343024091-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\amaena.com#*
HKU\S-1-5-21-448539723-839522115-1343024091-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsafe.com
HKU\S-1-5-21-448539723-839522115-1343024091-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsafe.com#*
HKU\S-1-5-21-448539723-839522115-1343024091-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\imagesrvr.com
HKU\S-1-5-21-448539723-839522115-1343024091-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\imagesrvr.com#*
HKU\S-1-5-21-448539723-839522115-1343024091-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispyware.com
HKU\S-1-5-21-448539723-839522115-1343024091-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispyware.com#*
HKU\S-1-5-21-448539723-839522115-1343024091-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantivirus.com
HKU\S-1-5-21-448539723-839522115-1343024091-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantivirus.com#*
HKU\S-1-5-21-448539723-839522115-1343024091-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfixer.com
HKU\S-1-5-21-448539723-839522115-1343024091-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfixer.com#*

Adware.Tracking Cookie
C:\Documents and Settings\user\Cookies\user@statcounter[2].txt
C:\Documents and Settings\user\Cookies\user@adultadworld[2].txt
C:\Documents and Settings\user\Cookies\user@yadro[1].txt
C:\Documents and Settings\user\Cookies\user@encyclomedia[1].txt
C:\Documents and Settings\user\Cookies\user@cgi-bin[2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@serving-sys[2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@ig[3].txt
C:\Documents and Settings\user\Cookies\user@adbrite[1].txt
C:\Documents and Settings\user\Cookies\user@webpower[2].txt
C:\Documents and Settings\user\Cookies\user@fastclick[1].txt
C:\Documents and Settings\user\Cookies\user@default[1].txt
C:\Documents and Settings\user\Cookies\user@xiti[1].txt
C:\Documents and Settings\user\Cookies\user@tase[2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@trafficmp[2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@metacafe.122.2o7[1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@spylog[1].txt
C:\Documents and Settings\user\Cookies\user@2o7[1].txt
C:\Documents and Settings\user\Cookies\user@hornymatches[1].txt
C:\Documents and Settings\user\Cookies\user@adrevolver[3].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@adrevolver[2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@www.fpctraffic2[2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@webstat[2].txt
C:\Documents and Settings\user\Cookies\user@apmebf[2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@pornhub[2].txt
C:\Documents and Settings\user\Cookies\user@adinterax[2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@atwola[1].txt
C:\Documents and Settings\user\Cookies\user@enlargepenisguide[2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@clickintext[1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@tribalfusion[1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@revsci[2].txt
C:\Documents and Settings\user\Cookies\user@cgi[2].txt
C:\Documents and Settings\user\Cookies\user@adultfriendfinder[2].txt
C:\Documents and Settings\user\Cookies\user@media6degrees[1].txt
C:\Documents and Settings\user\Cookies\user@burstnet[2].txt
C:\Documents and Settings\user\Cookies\user@questionmarket[1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@casalemedia[2].txt
C:\Documents and Settings\user\Cookies\user@atdmt[2].txt
C:\Documents and Settings\user\Cookies\user@collective-media[2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@sextracker[1].txt
C:\Documents and Settings\user\Cookies\user@realmedia[2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@bluestreak[1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@tacoda[2].txt
C:\Documents and Settings\user\Cookies\user@overture[1].txt
C:\Documents and Settings\user\Cookies\user@dcsi583rp10000oevcqz9y4us_6l6d[1].txt
C:\Documents and Settings\user\Cookies\user@tase[1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@windowsmedia[1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@clickaider[1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed]-sys[1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@zedo[1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@doubleclick[2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@hotlog[1].txt
C:\Documents and Settings\user\Cookies\user@mediaplex[1].txt
C:\Documents and Settings\user\Cookies\user@divx.112.2o7[1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@specificclick[2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@socialmedia[2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@linksynergy[2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@eyewonder[1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@hitbox[2].txt
C:\Documents and Settings\user\Cookies\user@AdRotator[3].txt
C:\Documents and Settings\user\Cookies\user@adlegend[1].txt
C:\Documents and Settings\user\Cookies\user@edge.ru4[1].txt
C:\Documents and Settings\user\Cookies\user@advertising[1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@valueclick[2].txt
C:\Documents and Settings\user\Cookies\user@advancedcleaner[2].txt
C:\Documents and Settings\user\Cookies\user@list[1].txt
C:\Documents and Settings\user\Cookies\user@clicksor[2].txt
C:\Documents and Settings\user\Cookies\user@adserver[1].txt
C:\Documents and Settings\user\Cookies\user@player[1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@usatoday1.112.2o7[1].txt
C:\Documents and Settings\user\Cookies\user@clickbank[1].txt
C:\Documents and Settings\user\Cookies\user@tripod[2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@centralmediaserver[1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@cgi-bin[3].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@directtrack[1].txt
C:\Documents and Settings\user\Cookies\[removed][2].txt
C:\Documents and Settings\user\Cookies\user@ad[1].txt
C:\Documents and Settings\user\Cookies\user@cgi-bin[4].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@interclick[1].txt
C:\Documents and Settings\user\Cookies\user@toplist[1].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt
C:\Documents and Settings\user\Cookies\user@screensavers[2].txt
C:\Documents and Settings\user\Cookies\[removed][1].txt

Adware.ClickSpring/Outer Info Network
C:\Program Files\Outerinfo\Terms.rtf
C:\Program Files\Outerinfo
C:\Documents and Settings\user\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\user\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\user\Start Menu\Programs\Outerinfo

Trojan.VideoCach/Gen
HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}
HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0
HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0\0
HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0\0\win32
HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0\FLAGS
HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0\HELPDIR
HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}
HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid
HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid32
HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\TypeLib
HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\TypeLib#Version

Adware.Web Buying
HKU\S-1-5-21-448539723-839522115-1343024091-1000\Software\WebBuying

Rogue.SpyDefender Pro
HKU\S-1-5-21-448539723-839522115-1343024091-1000\Software\SpyDefender
HKU\S-1-5-21-448539723-839522115-1343024091-1000\Software\SWD123

Trojan.Unknown Origin
C:\PROGRAM FILES\NETMEETING\MEVE22011.EXE
C:\WINNT\B129.EXE
C:\WINNT\SYSTEM32\WAPISVTR.EXE

Adware.eZula
C:\VUNDOFIX BACKUPS\CBJSHJDW.EXE.BAD
C:\VUNDOFIX BACKUPS\FYFOWRUQ.EXE.BAD
C:\VUNDOFIX BACKUPS\HGUDYELI.EXE.BAD
C:\VUNDOFIX BACKUPS\HTREMUME.EXE.BAD
C:\VUNDOFIX BACKUPS\NOHGPLWO.EXE.BAD
C:\VUNDOFIX BACKUPS\OWSYNLCL.EXE.BAD
C:\VUNDOFIX BACKUPS\QCRCXWFN.EXE.BAD
C:\VUNDOFIX BACKUPS\RIQPPKLV.EXE.BAD
C:\VUNDOFIX BACKUPS\TCCTLTXP.EXE.BAD
C:\VUNDOFIX BACKUPS\ULPESXAX.EXE.BAD
C:\VUNDOFIX BACKUPS\XMKANNCP.EXE.BAD
C:\VUNDOFIX BACKUPS\XOYUHPYR.EXE.BAD

Trojan.Downloader-Gen/Installer
C:\WINNT\B103.EXE
C:\WINNT\B104.EXE

Trojan.WinAntiSpyware/WinAntiVirus 2006
C:\WINNT\DOWNLOADED PROGRAM FILES\UWA7P_0001_N99M2908NETINSTALLER.EXE
C:\WINNT\DOWNLOADED PROGRAM FILES\UWAS7_0001_N99M3108NETINSTALLER.EXE

Adware.Vundo Variant/Rel
C:\WINNT\SYSTEM32\MCRH.TMP

Trojan.LSASS(Variant)
C:\WINNT\SYSTEM32\RMTCFG\FILES\HIDDEN32.EXE
C:\WINNT\SYSTEM32\RMTCFG\HIDDEN32.EXE
ComboFix 08-02-18.1 - user 02/17/2008 18:03:35.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\check_LSA7.txt
C:\Documents and Settings\user\Application Data\WinTouch
C:\Documents and Settings\user\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\user\Start Menu\Programs\Startup\ta_start.lnk
C:\install.exe
C:\Program Files\Common Files\download
C:\Program Files\Common Files\windows
C:\Program Files\Common Files\windows\AutoIt3.exe
C:\Program Files\Insider
C:\Program Files\Insider\bak\Insider.exe
C:\Program Files\Insider\Insider.exe
C:\Program Files\Insider\UnInstall.exe
C:\Program Files\WinBudget
C:\Program Files\WinBudget\bin\carp**.1201722707.old
C:\Program Files\WinBudget\bin\matrix.dat
C:\Program Files\WinBudget\bin\matrix.dll.1202000305.old
C:\Program Files\WinBudget\bin\tempzor
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\bass.exe
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\WINNT\cookies.ini
C:\WINNT\Downloaded Program Files\Cache
C:\WINNT\Downloaded Program Files\Cache\297b1becf74fd62bb980296a50551b30.xml
C:\WINNT\Downloaded Program Files\toolbar.bmp
C:\WINNT\mbols~1
C:\WINNT\mbols~1\??mbols\
C:\WINNT\system32\D2
C:\WINNT\system32\f02WtR
C:\WINNT\system32\help.txt
C:\WINNT\system32\ncase.ini
C:\WINNT\Web\default.htt

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\nm


((((((((((((((((((((((((( Files Created from 2008-01-18 to 2008-02-18 )))))))))))))))))))))))))))))))
.

2008-02-15 19:26 . 08-02-15 19:26 d——– C:\Program Files\SUPERAntiSpyware
2008-02-15 19:26 . 08-02-15 19:26 d——– C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com
2008-02-15 19:26 . 08-02-15 19:26 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-15 19:25 . 08-02-15 19:25 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-14 17:59 . 08-02-15 20:58 d——– C:\VundoFix Backups
2008-02-02 21:40 . 08-02-02 21:40 d——– C:\Program Files\Razor
2008-02-02 21:34 . 03-01-07 17:31 172,032 –a—— C:\WINNT\UOUninst.exe
2008-02-02 21:31 . 08-02-02 23:53 d——– C:\Program Files\Ultima Online 2D Client
2008-01-30 14:53 . 08-01-30 14:53 14 –a—— C:\WINNT\7246-3FB6-161F-F868.dat
2008-01-25 00:15 . 08-02-05 22:53 54,156 –ah—– C:\WINNT\QTFont.qfn
2008-01-25 00:15 . 08-01-25 00:15 1,409 –a—— C:\WINNT\QTFont.for
2008-01-24 23:12 . 07-03-04 06:55 1,936,528 –a—— C:\WINNT\system32\ltmm15.dll
2008-01-24 23:12 . 07-03-04 06:55 135,168 –a—— C:\WINNT\system32\DSKernel2.dll
2008-01-24 23:07 . 08-01-24 23:09 d——– C:\Documents and Settings\user\Application Data\GetRightToGo
2008-01-24 22:19 . 08-01-24 22:19 d——– C:\WINNT\Applian FLV Player

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-02 12:04 ——— d—–w C:\Documents and Settings\user\Application Data\AVG7
2008-01-31 05:18 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-01-31 05:17 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-30 21:18 ——— d—a-w C:\Documents and Settings\All Users\Application Data\avg7
2008-01-25 05:10 737,280 —-a-w C:\WINNT\iun6002.exe
2005-10-18 18:24 67,897 —-a-w C:\Documents and Settings\user\plugme.exe
1999-12-07 12:00 32,528 —-a-w C:\WINNT\inf\wbfirdma.sys
1998-12-09 10:53 99,840 —-a-w C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-09 10:53 70,144 —-a-w C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-09 10:53 48,640 —-a-w C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-09 10:53 31,744 —-a-w C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-09 10:53 186,368 —-a-w C:\Program Files\Common Files\IRAREG.DLL
1998-12-09 10:53 17,920 —-a-w C:\Program Files\Common Files\IRASRIAL.DLL
2007-03-09 08:12 27,648 –sha-w C:\WINNT\system32\AVSredirect.dll
2007-09-08 08:52 6,448 –sh–w C:\WINNT\system32\pssut.bak1
2007-09-22 02:02 1,978,799 –sh–w C:\WINNT\system32\pssut.bak2
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3D1ED03C-73AE-40dd-B952-AC2589DA3C45}]
C:\WINNT\DOWNLO~1\CONFLICT.2\XHOLLY~1.DLL

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{52EB132C-1C84-40BC-F7AA-A9E75A823844}]
C:\Program Files\microsoft frontpage\quzatedy629.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66CEAA7E-6FBD-4e0f-BDD2-190D5A354C99}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a2d0db8b-cf21-4abf-bc63-2944e904ad4a}]
C:\WINNT\system32\niarmhm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CD157654-62C0-4CA2-9221-5D6E90ABCB2E}]
C:\WINNT\system32\tussp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpyDefender Shield"="C:\Program Files\SpyDefender Pro\SpyDefender.exe" [ ]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [07-06-21 14:06 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 13:05 111376 C:\WINNT\system32\mobsync.exe]
"NvCplDaemon"="NvQTwk" []
"WLAN_Cfg.exe"="C:\Program Files\3Com\3Com 11Mbps Wireless LAN PCI Adapter\WLAN_Cfg.exe" [08-01-28 19:10 14348]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [08-01-30 14:40 579072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [08-01-28 19:10 14348]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msmsngers"="syscofig32.exe" []
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [08-01-30 14:40 219136]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 13:05 186640]
"msmsngers"="syscofig32.exe" []

C:\Documents and Settings\user\Start Menu\Programs\Startup\
MEMonitor.lnk - C:\Program Files\Sprint music manager\MEMonitor.exe [2007-12-15 23:36:29 983040]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HPAiODevice(hp officejet g series) - 1.lnk - C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe [2002-11-20 16:15:00 151552]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 02:15:54 65588]
Symantec Fax Starter Edition Port.lnk - C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE [1998-12-23 23:51:54 45568]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 0 (0x0)
"Btn_Search"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [06-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 07-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnkkig]
pmnkkig.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=

R1 Avg7RsNT;AVG7 Resident Driver NT;C:\WINNT\system32\Drivers\avg7rsnt.sys [07-02-26 14:56 ]
R3 lne100v5;Linksys LNE100TX(v5) Fast Ethernet Adapter;C:\WINNT\system32\DRIVERS\lne100v5.sys [01-04-02 10:01 ]
R3 PRISM;3Com 3CRDW696 Wireless LAN PCI Adapter LAN Driver;C:\WINNT\system32\DRIVERS\PRISMNDS.sys [02-06-28 19:18 ]
R3 Winacpci;Winacpci;C:\WINNT\system32\DRIVERS\winacpci.sys [99-09-24 17:55 ]
S3 DLKRTS;D-Link DFE-530TX+ PCI Adapter;C:\WINNT\system32\DRIVERS\DLKRTS.SYS [01-10-17 03:03 ]
S3 hpoid407;IEEE-1284.4 Driver hpoid407;C:\WINNT\system32\DRIVERS\hpoid407.sys [05-07-29 12:22 ]
S3 hpoius07;USB to IEEE-1284.4 Translation Driver hpoius07;C:\WINNT\system32\DRIVERS\hpoius07.sys [05-07-29 12:22 ]

.
Contents of the 'Scheduled Tasks' folder
"2007-05-13 07:42:20 C:\WINNT\Tasks\HP DArC Task #Hewlett-Packard#7200#CN38L2B3ZFI5.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe$/#Hewlett-Packard#7200#CN38L2B3ZFI5
"2008-02-16 08:43:00 C:\WINNT\Tasks\HP Usg Daily.job"
- C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\pexpress\hphped05.exe
"2008-02-17 23:51:19 C:\WINNT\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-17 18:15:06
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINNT\SYSTEM32\DWRCS.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2008-02-17 18:26:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-18 00:26:36
.
2008-01-30 21:01:15 — E O F —
Logfile of HijackThis v1.99.1
Scan saved at 10:42:45 PM, on 2/17/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINNT\SYSTEM32\DWRCS.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\3Com\3Com 11Mbps Wireless LAN PCI Adapter\WLAN_Cfg.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Sprint music manager\MEMonitor.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\WINNT\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\user\Desktop\New Folder (2)\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defa…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: XBTB04084 - {3D1ED03C-73AE-40dd-B952-AC2589DA3C45} - C:\WINNT\DOWNLO~1\CONFLICT.2\XHOLLY~1.DLL (file missing)
O2 - BHO: 0 - {52EB132C-1C84-40BC-F7AA-A9E75A823844} - C:\Program Files\microsoft frontpage\quzatedy629.dll (file missing)
O2 - BHO: Editor plugin - {66CEAA7E-6FBD-4e0f-BDD2-190D5A354C99} - micropr.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {a2d0db8b-cf21-4abf-bc63-2944e904ad4a} - C:\WINNT\system32\niarmhm.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {CD157654-62C0-4CA2-9221-5D6E90ABCB2E} - C:\WINNT\system32\tussp.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,0,8,0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [WLAN_Cfg.exe] C:\Program Files\3Com\3Com 11Mbps Wireless LAN PCI Adapter\WLAN_Cfg.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [SpyDefender Shield] "C:\Program Files\SpyDefender Pro\SpyDefender.exe" –scan2
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: MEMonitor.lnk = C:\Program Files\Sprint music manager\MEMonitor.exe
O4 - Global Startup: HPAiODevice(hp officejet g series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O8 - Extra context menu item: &iSearch The Web - res://C:\WINNT\system32\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O15 - Trusted Zone: *.drivecleaner.com
O15 - Trusted Zone: *.errorprotector.com
O15 - Trusted Zone: *.imageservr.com
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.drivecleaner.com (HKLM)
O15 - Trusted Zone: *.errorprotector.com (HKLM)
O15 - Trusted Zone: *.imageservr.com (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.birdville.k12.tx.us/CFIDE/classes/CFJava.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - https://livewc01.custhelp.com/7520-b289h-tu…l/java/RntX.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: pmnkkig - pmnkkig.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development - C:\WINNT\SYSTEM32\DWRCS.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
Hello,

SpyDefender is a Rogue program and not recommended, you can try uninstalling it via the Add Remove Programs in the Control Panel, let me know if it would not uninstall

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
O2 - BHO: XBTB04084 - {3D1ED03C-73AE-40dd-B952-AC2589DA3C45} - C:\WINNT\DOWNLO~1\CONFLICT.2\XHOLLY~1.DLL (file missing)
O2 - BHO: 0 - {52EB132C-1C84-40BC-F7AA-A9E75A823844} - C:\Program Files\microsoft frontpage\quzatedy629.dll (file missing)
O2 - BHO: Editor plugin - {66CEAA7E-6FBD-4e0f-BDD2-190D5A354C99} - micropr.dll (file missing)
O2 - BHO: (no name) - {a2d0db8b-cf21-4abf-bc63-2944e904ad4a} - C:\WINNT\system32\niarmhm.dll (file missing)
O2 - BHO: (no name) - {CD157654-62C0-4CA2-9221-5D6E90ABCB2E} - C:\WINNT\system32\tussp.dll (file missing)

O4 - HKCU\..\Run: [SpyDefender Shield] "C:\Program Files\SpyDefender Pro\SpyDefender.exe" –scan2

O8 - Extra context menu item: &iSearch The Web - res://C:\WINNT\system32\toolbar.dll/SEARCH.HTML

O15 - Trusted Zone: *.drivecleaner.com
O15 - Trusted Zone: *.errorprotector.com
O15 - Trusted Zone: *.imageservr.com
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.drivecleaner.com (HKLM)
O15 - Trusted Zone: *.errorprotector.com (HKLM)
O15 - Trusted Zone: *.imageservr.com (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone

O20 - Winlogon Notify: pmnkkig - pmnkkig.dll (file missing)



You have a downloader trojan called Downloader.Agent.awf or Downloader.Agent.ayy. This trojan replaces legitimate files that are common on most computers with an infected file. It then moves the legitimate file to a "bak" or backup folder. Please follow the directions below to run FindAWF so we can identify the files that have been infected and their backups then restore them.


Please download FindAWF and save it to your desktop

* Double-click FindAWF.exe to start the tool.
* Select option #1 - Scan for bak folders by typing 1 and press 'Enter'
* When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here.

**Do not run any other option unless directed to do so.**


Post the results from AWF and also a new HJT log please
i really appreciate you helping me out. i think its cool that you guys help a lot of people with their computer problems.
thank you.

i couldn't uninstall spydefender because i couldn't find it anywhere. i might have deleted it previously and not uninstalled it.

Find AWF report by noahdfear ©2006
Version 1.40

The current date is: Thu 02/21/2008
The current time is: 0:39:01.46


bak folders found
~~~~~~~~~~~


Directory of C:\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\NORTON~1\BAK

02/27/2002 10:27a 75,384 navapw32.exe
1 File(s) 75,384 bytes

Directory of C:\PROGRA~1\QUICKT~1\BAK

04/22/2005 07:46p 98,304 qttask.exe
1 File(s) 98,304 bytes

Directory of C:\WINNT\SYSTEM32\BAK

08/20/2003 03:15p 483,328 hphmon05.exe
07/09/2001 12:50p 155,648 NeroCheck.exe
2 File(s) 638,976 bytes

Directory of C:\PROGRA~1\2WIRE\GATEWAY\BAK

11/14/2002 12:57a 446,464 2PortalMon.exe
1 File(s) 446,464 bytes

Directory of C:\PROGRA~1\3COM\3COM11~1\BAK

07/02/2002 03:57p 1,020,928 WLAN_Cfg.exe
1 File(s) 1,020,928 bytes

Directory of C:\PROGRA~1\GRISOFT\AVGFRE~1\BAK

02/26/2007 02:56p 411,648 avgcc.exe
1 File(s) 411,648 bytes

Directory of C:\PROGRA~1\HEWLET~1\HPSOFT~1\BAK

09/13/2004 03:49p 49,152 HPWuSchd2.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK

08/20/2003 03:23p 49,152 hphupd05.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\HP\HPCORE~1\BAK

08/20/2003 01:57p 221,184 hpcmpmgr.exe
1 File(s) 221,184 bytes

Directory of C:\PROGRA~1\VIEWPO~1\VIEWPO~2\BAK

11/10/2004 10:15p 111,816 ViewMgr.exe
1 File(s) 111,816 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

08/21/2004 09:31a 180,269 realsched.exe
1 File(s) 180,269 bytes

Directory of C:\PROGRA~1\JAVA\J2RE14~1.2_0\BIN\BAK

09/28/2004 08:26p 32,881 jusched.exe
1 File(s) 32,881 bytes

Directory of C:\PROGRA~1\JAVA\JRE16~1.0_0\BIN\BAK

07/12/2007 04:00a 132,496 jusched.exe
1 File(s) 132,496 bytes

Directory of C:\QOOBOX\QUARAN~1\C\PROGRA~1\INSIDER\BAK

10/26/2007 03:44p 0 Insider.exe.vir
1 File(s) 0 bytes

Directory of C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK

07/25/2003 08:14a 188,416 hpztsb09.exe
1 File(s) 188,416 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

75384 Feb 27 2002 "C:\Program Files\Norton AntiVirus\bak\navapw32.exe"
98304 Apr 22 2005 "C:\Program Files\QuickTime\bak\qttask.exe"
483328 Aug 20 2003 "C:\WINNT\system32\bak\hphmon05.exe"
155648 Jul 9 2001 "C:\WINNT\system32\bak\NeroCheck.exe"
446464 Nov 14 2002 "C:\Program Files\2Wire\Gateway\bak\2PortalMon.exe"
14348 Jan 28 2008 "C:\Program Files\3Com\3Com 11Mbps Wireless LAN PCI Adapter\WLAN_Cfg.exe"
1020928 Jul 2 2002 "C:\Program Files\3Com\3Com 11Mbps Wireless LAN PCI Adapter\bak\WLAN_Cfg.exe"
579072 Jan 30 2008 "C:\Program Files\Grisoft\AVG Free\avgcc.exe"
411648 Feb 26 2007 "C:\Program Files\Grisoft\AVG Free\bak\avgcc.exe"
14348 Jan 28 2008 "C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7upd\backup\avgcc.exe"
49152 Sep 13 2004 "C:\Program Files\Hewlett-Packard\HP Software Update\bak\HPWuSchd2.exe"
49152 Aug 20 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe"
221184 Aug 20 2003 "C:\Program Files\HP\hpcoretech\bak\hpcmpmgr.exe"
111816 Nov 10 2004 "C:\Program Files\Viewpoint\Viewpoint Manager\bak\ViewMgr.exe"
180269 Aug 21 2004 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
14348 Jan 28 2008 "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
32881 Sep 28 2004 "C:\Program Files\Java\j2re1.4.2_06\bin\bak\jusched.exe"
132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"
14348 Jan 28 2008 "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
32881 Sep 28 2004 "C:\Program Files\Java\j2re1.4.2_06\bin\bak\jusched.exe"
132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"
14348 Jan 28 2008 "C:\QooBox\Quarantine\C\Program Files\Insider\Insider.exe.vir"
0 Oct 26 2007 "C:\QooBox\Quarantine\C\Program Files\Insider\bak\Insider.exe.vir"
188416 Jul 25 2003 "C:\WINNT\system32\spool\drivers\w32x86\3\bak\hpztsb09.exe"


end of report


Logfile of HijackThis v1.99.1
Scan saved at 12:59:11 AM, on 2/21/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINNT\SYSTEM32\DWRCS.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\wuauclt.exe
C:\Program Files\3Com\3Com 11Mbps Wireless LAN PCI Adapter\WLAN_Cfg.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Sprint music manager\MEMonitor.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\user\Desktop\New Folder (2)\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defa…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,0,8,0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [WLAN_Cfg.exe] C:\Program Files\3Com\3Com 11Mbps Wireless LAN PCI Adapter\WLAN_Cfg.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: MEMonitor.lnk = C:\Program Files\Sprint music manager\MEMonitor.exe
O4 - Global Startup: HPAiODevice(hp officejet g series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.birdville.k12.tx.us/CFIDE/classes/CFJava.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - https://livewc01.custhelp.com/7520-b289h-tu…l/java/RntX.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development - C:\WINNT\SYSTEM32\DWRCS.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
Good Morning Twoo,

Besides my family and friends, helping nice people like yourself from the slimeballs that write this garbage is another one of my lifes passions. :D

This is what we are going to do, we are going to reinstall the Good files from backups and then delete the bak folders, do it this way.

First go to your Add Remove programs in the Control Panel and uninstall Viewpoint, it installed without your knowledge or consent, uses system resources, is not needed for anything and is in the process of being reclassified as Adware

C:\Program Files\Viewpoint<– Delete both these folders
C:\QooBox


Double-click FindAWF.exe to start the tool.

* Select option #2 - Restore files from bak folders by typing 2 and press 'Enter'
* A text file will open up. Please copy/paste the following bolded text into the text file:

"C:\Program Files\Norton AntiVirus\bak\navapw32.exe"
"C:\Program Files\QuickTime\bak\qttask.exe"
"C:\WINNT\system32\bak\hphmon05.exe"
"C:\WINNT\system32\bak\NeroCheck.exe"
"C:\Program Files\2Wire\Gateway\bak\2PortalMon.exe"
"C:\Program Files\3Com\3Com 11Mbps Wireless LAN PCI Adapter\bak\WLAN_Cfg.exe"
"C:\Program Files\Grisoft\AVG Free\bak\avgcc.exe"
"C:\Program Files\Hewlett-Packard\HP Software Update\bak\HPWuSchd2.exe"
"C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe"
"C:\Program Files\HP\hpcoretech\bak\hpcmpmgr.exe"
"C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
"C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"
"C:\Program Files\Java\j2re1.4.2_06\bin\bak\jusched.exe"
"C:\WINNT\system32\spool\drivers\w32x86\3\bak\hpztsb09.exe"


* Close the .txt file and click 'Yes' to save the changes.
* When the tool has completed, a report will open up in notepad.

Please post the results of the awf.txt here.
Find AWF report by noahdfear ©2006 Version 1.40 Option 2 run successfully The current date is: Mon 02/25/2008 The current time is: 18:29:36.61 bak folders found ~~~~~~~~~~~ Directory of C:\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\NORTON~1\BAK 02/27/2002 10:27a 75,384 navapw32.exe 1 File(s) 75,384 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 04/22/2005 07:46p 98,304 qttask.exe 1 File(s) 98,304 bytes Directory of C:\WINNT\SYSTEM32\BAK 08/20/2003 03:15p 483,328 hphmon05.exe 07/09/2001 12:50p 155,648 NeroCheck.exe 2 File(s) 638,976 bytes Directory of C:\PROGRA~1\2WIRE\GATEWAY\BAK 11/14/2002 12:57a 446,464 2PortalMon.exe 1 File(s) 446,464 bytes Directory of C:\PROGRA~1\3COM\3COM11~1\BAK 07/02/2002 03:57p 1,020,928 WLAN_Cfg.exe 1 File(s) 1,020,928 bytes Directory of C:\PROGRA~1\GRISOFT\AVGFRE~1\BAK 02/26/2007 02:56p 411,648 avgcc.exe 1 File(s) 411,648 bytes Directory of C:\PROGRA~1\HEWLET~1\HPSOFT~1\BAK 09/13/2004 03:49p 49,152 HPWuSchd2.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK 08/20/2003 03:23p 49,152 hphupd05.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\HP\HPCORE~1\BAK 08/20/2003 01:57p 221,184 hpcmpmgr.exe 1 File(s) 221,184 bytes Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 08/21/2004 09:31a 180,269 realsched.exe 1 File(s) 180,269 bytes Directory of C:\PROGRA~1\JAVA\J2RE14~1.2_0\BIN\BAK 09/28/2004 08:26p 32,881 jusched.exe 1 File(s) 32,881 bytes Directory of C:\PROGRA~1\JAVA\JRE16~1.0_0\BIN\BAK 07/12/2007 04:00a 132,496 jusched.exe 1 File(s) 132,496 bytes Directory of C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK 07/25/2003 08:14a 188,416 hpztsb09.exe 1 File(s) 188,416 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 75384 Feb 27 2002 "C:\Program Files\Norton AntiVirus\navapw32.exe" 75384 Feb 27 2002 "C:\Program Files\Norton AntiVirus\bak\navapw32.exe" 98304 Apr 22 2005 "C:\Program Files\QuickTime\qttask.exe" 98304 Apr 22 2005 "C:\Program Files\QuickTime\bak\qttask.exe" 483328 Aug 20 2003 "C:\WINNT\system32\hphmon05.exe" 483328 Aug 20 2003 "C:\WINNT\system32\bak\hphmon05.exe" 155648 Jul 9 2001 "C:\WINNT\system32\NeroCheck.exe" 155648 Jul 9 2001 "C:\WINNT\system32\bak\NeroCheck.exe" 446464 Nov 14 2002 "C:\Program Files\2Wire\Gateway\2PortalMon.exe" 446464 Nov 14 2002 "C:\Program Files\2Wire\Gateway\bak\2PortalMon.exe" 1020928 Jul 2 2002 "C:\Program Files\3Com\3Com 11Mbps Wireless LAN PCI Adapter\WLAN_Cfg.exe" 1020928 Jul 2 2002 "C:\Program Files\3Com\3Com 11Mbps Wireless LAN PCI Adapter\bak\WLAN_Cfg.exe" 411648 Feb 26 2007 "C:\Program Files\Grisoft\AVG Free\avgcc.exe" 411648 Feb 26 2007 "C:\Program Files\Grisoft\AVG Free\bak\avgcc.exe" 14348 Jan 28 2008 "C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7upd\backup\avgcc.exe" 49152 Sep 13 2004 "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" 49152 Sep 13 2004 "C:\Program Files\Hewlett-Packard\HP Software Update\bak\HPWuSchd2.exe" 49152 Aug 20 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" 49152 Aug 20 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe" 221184 Aug 20 2003 "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" 221184 Aug 20 2003 "C:\Program Files\HP\hpcoretech\bak\hpcmpmgr.exe" 180269 Aug 21 2004 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" 180269 Aug 21 2004 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 32881 Sep 28 2004 "C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe" 132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" 32881 Sep 28 2004 "C:\Program Files\Java\j2re1.4.2_06\bin\bak\jusched.exe" 132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe" 32881 Sep 28 2004 "C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe" 132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" 32881 Sep 28 2004 "C:\Program Files\Java\j2re1.4.2_06\bin\bak\jusched.exe" 132496 Jul 12 2007 "C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe" 188416 Jul 25 2003 "C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb09.exe" 188416 Jul 25 2003 "C:\WINNT\system32\spool\drivers\w32x86\3\bak\hpztsb09.exe" end of report
Hello,

First go to your Add Remove Programs in the Control Panel and uninstall every entry related to JAVA except jre1.6.0_02


Double-click FindAWF.exe to start the tool.

  • Select option #3 - Remove bak folders by typing 3 and press 'Enter'
  • A text file will open up. Please copy/paste the following bolded text into the text file:

C:\Program Files\Norton AntiVirus\bak
C:\Program Files\QuickTime\bak
C:\WINNT\system32\bak
C:\WINNT\system32\bak
C:\Program Files\2Wire\Gateway\bak
C:\Program Files\3Com\3Com 11Mbps Wireless LAN PCI Adapter\bak
C:\Program Files\Grisoft\AVG Free\bak
C:\Program Files\Hewlett-Packard\HP Software Update\bak
C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak
C:\Program Files\HP\hpcoretech\bak
C:\Program Files\Common Files\Real\Update_OB\bak
C:\Program Files\Java\jre1.6.0_02\bin\bak
C:\Program Files\Java\j2re1.4.2_06\bin\bak
C:\WINNT\system32\spool\drivers\w32x86\3\bak


* Close the .txt file and click 'Yes' to save the changes.
* When the tool has completed, a report will open up in notepad.

Please post the results of the awf.txt here.
there are only 2 java files in the add remove list.
Java 2 Runtime Environment, SE v1.4.2_06
Java™ 6 Update 2
there was no java jre1.6.0_02
so i didn't uninstal the 2 that are on there

Find AWF report by noahdfear ©2006
Version 1.40
Option 3 run successfully

The current date is: Wed 02/27/2008
The current time is: 18:48:16.50


bak folders found
~~~~~~~~~~~


Directory of C:\BAK

0 File(s) 0 bytes

Directory of C:\WINNT\SYSTEM32\BAK

08/20/2003 03:15p 483,328 hphmon05.exe
1 File(s) 483,328 bytes

Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK

08/20/2003 03:23p 49,152 hphupd05.exe
1 File(s) 49,152 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

483328 Aug 20 2003 "C:\WINNT\system32\hphmon05.exe"
483328 Aug 20 2003 "C:\WINNT\system32\bak\hphmon05.exe"
49152 Aug 20 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"
49152 Aug 20 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe"


end of report
twoo.

SE v1.4.2_06 <–Uninstall this one only

We need to make another run with AWF as the one for your printer did not take. Turn you printer off. If these do not clean up this time, your going to have to uninstall your printer software, but lets worry about that in a bit.

Double-click FindAWF.exe to start the tool.
* Select option #2 - Restore files from bak folders by typing 2 and press 'Enter'
* A text file will open up. Please copy/paste the following bolded text into the text file:

"C:\WINNT\system32\bak\hphmon05.exe"
"C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe"
"C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe"


* Close the .txt file and click 'Yes' to save the changes.
* When the tool has completed, a report will open up in notepad.

Please post the results of the awf.txt here.
Find AWF report by noahdfear ©2006 Version 1.40 Option 2 run successfully The current date is: Mon 03/03/2008 The current time is: 19:16:24.61 bak folders found ~~~~~~~~~~~ Directory of C:\BAK 0 File(s) 0 bytes Directory of C:\WINNT\SYSTEM32\BAK 08/20/2003 03:15p 483,328 hphmon05.exe 1 File(s) 483,328 bytes Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK 08/20/2003 03:23p 49,152 hphupd05.exe 1 File(s) 49,152 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 483328 Aug 20 2003 "C:\WINNT\system32\hphmon05.exe" 483328 Aug 20 2003 "C:\WINNT\system32\bak\hphmon05.exe" 49152 Aug 20 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" 49152 Aug 20 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe" end of report
Hello,

Double-click FindAWF.exe to start the tool.

  • Select option #3 - Remove bak folders by typing 3 and press 'Enter'
  • A text file will open up. Please copy/paste the following bolded text into the text file:
C:\WINNT\system32\bak
C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak


* Close the .txt file and click 'Yes' to save the changes.
* When the tool has completed, a report will open up in notepad.

Please post the results of the awf.txt here.



Then do this.

Double-click the FindAWF icon once again.
Use the following option: Press 4 then Enter to reset domain zones.

When the program returns to the main menu, use the following option:
Press E then Enter to EXIT.
Find AWF report by noahdfear ©2006 Version 1.40 Option 3 run successfully The current date is: Sat 03/08/2008 The current time is: 14:06:24.60 bak folders found ~~~~~~~~~~~ Directory of C:\BAK 0 File(s) 0 bytes Directory of C:\WINNT\SYSTEM32\BAK 08/20/2003 03:15p 483,328 hphmon05.exe 1 File(s) 483,328 bytes Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK 08/20/2003 03:23p 49,152 hphupd05.exe 1 File(s) 49,152 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 483328 Aug 20 2003 "C:\WINNT\system32\hphmon05.exe" 483328 Aug 20 2003 "C:\WINNT\system32\bak\hphmon05.exe" 49152 Aug 20 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" 49152 Aug 20 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe" end of report
Hello,

These will not go so your going to have to uninstall all your HP Printer software via the Add Remove Programs in the Control Panel.

Then delete the folder as the bad files may still be present in that folder
C:\Program Files\Hewlett-Packard

Make sure these are gone also
C:\WINNT\system32\hphmon05.exe
C:\WINNT\system32\bak

Then reinstall the software for your printer and you should be ok


Run option 1 for FindAWF and post the report

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI