This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Pop-up Warning: possible spyware.. Click here" an

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been receiving pop-ups in IE7 that say "Warning: possible spyware or adware infection! Click here to scan your computer for spyware and adware…". I have run many scans (Trend Micro online, Avast!, Spybot SD, Adware) and although they find and change things (such as the removal of AdRemover2008), the pop-up still occurs. I am moderately techno savvy, so the thought of which reg. and .dll to clean is a little beyond me, but I'll be able to follow if you can guide me through it. Also, I noticed that after a few days of these pop-ups, my desktop will be replaced by a red screen with biohazard symbols, stating "Your privacy is in Danger!". I have managed to goto a last restore point which gets rid of the red screen, but I cannot go far enough back to get tid of the pop-ups. Therefore, in another couple of days of pop-ups, I get the red screen and have to restore again. I have just downloaded the Trend Micro HijackThis, as I have seen others do with this problem, but I do not want to install it, yet, for fear of running too many anti-virus programs at the same time. Besides I wouldn't know what to do with the outcome, anyway. As a final note, I believe that this problem began after downloading Adobe and WinZip from the Google add-on site. Please, help! Any advice would be great!
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

As I am still training, my posts to you will be checked by an Expert member. This will ensure that all advice and instructions I give you are accurate and safe. This may mean that my replies may take a little longer.

jpshortstuff
Hi

Please install and run HijackThis to produce a log. It is not an Anti-Virus program, it will not slow your computer down unless it is running, which only takes 10-20 seconds anyway.


I need to see another log from HijackThis.
  • Run Hijackthis.
  • Click on Open the Misc Tools section.
  • Next click on Open uninstall manager.
  • Press the Save list button.
  • Save the file to your desktop, with the default name of uninstall_list
  • Copy & Paste the entire contents of that file in your in your next post.
Thanks.
Thanks for your quick response!

I have the two log files for you below…

uninstall_list.txt

Accurate Outlook Express Mail Expert 3.2
Adobe Flash Player ActiveX
Adobe Reader 7.0.5
avast! Antivirus
BitTorrent 4.4.1
C-Media WDM Audio Driver
DivX
DivX Player
GameSpy Arcade
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
HP PSC & OfficeJet 5.3.B
Java™ 6 Update 3
Medal of Honor Allied Assault Multiplayer Demo
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
MSXML 6.0 Parser (KB933579)
NVIDIA Drivers
Quake 3 Arena Demo
RealPlayer
Realtek AC'97 Audio
Renegade Multiplayer Demo
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
SpywareBlaster 4.0
Sveerz
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920342)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925876)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
VIA Platform Device Manager
VIA Rhine-Family Fast Ethernet Adapter
VideoLAN VLC media player 0.8.5
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859



The HijackThis Log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:17:15 AM, on 3/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft

Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Silicon Prairie

Software\MemTurbo\memturbo.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start

Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search

Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start

Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection -

{53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class -

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: SXG Advisor -

{E48B3E0C-2D23-4249-BE65-23A8719284E3} -

C:\WINDOWS\dmdqdrxgxq.dll
O3 - Toolbar: emotrlq -

{7B1E78A2-2FC8-4947-A9D1-5177D10B38E6} -

C:\WINDOWS\emotrlq.dll (file missing)
O4 - HKLM\..\Run: [Cmaudio] RunDll32

cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!]

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common

Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SBI] C:\Documents and

Settings\Riley.CURIOUS_GEORGE\Local Settings\Temporary

Internet Files\Content.IE5\0Y1FNGAE\install_sbd_en[1].exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program

Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program

Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program

Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: BitTorrent.lnk = C:\Program

Files\BitTorrent\bittorrent.exe
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon

Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk =

C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program

Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program

Files\VIA\RAID\raid_tool.exe
O6 - HKCU\Software\Policies\Microsoft\Internet

Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) -

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy

Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP

Download Manager) -

https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java

Runtime Environment 1.6.0) -

http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-window

s-i586-jc.cab
O21 - SSODL: bdmnopx -

{9D532653-1EE3-4AB8-84CE-78EAED97B22B} -

C:\WINDOWS\bdmnopx.dll (file missing)
O21 - SSODL: admggxp -

{49D83D7A-E972-4575-BF88-2241EAD666A3} -

C:\WINDOWS\admggxp.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) -

ALWIL Software - C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software -

C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software -

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software -

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) -

NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP -

C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 5919 bytes


I've also Spyware Blaster and IE-SPYAD for ZonedOut, before I noticed your reply.
I hope this does not interfere.

I will not do anything else before I hear from you again.


***Divna
Sorry, but it very hard to read your log in its current format. Please click Start >> Run and then type notepad and hit enter. Click Format and then make sure Word Wrap is unchecked.

Please scan again with HijackThis and post the new log.
Sorry about that.
Here is the new scan:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:53:14 AM, on 3/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\notepad.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: SXG Advisor - {E48B3E0C-2D23-4249-BE65-23A8719284E3} - C:\WINDOWS\dmdqdrxgxq.dll
O3 - Toolbar: emotrlq - {7B1E78A2-2FC8-4947-A9D1-5177D10B38E6} - C:\WINDOWS\emotrlq.dll (file missing)
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SBI] C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temporary Internet Files\Content.IE5\0Y1FNGAE\install_sbd_en[1].exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O21 - SSODL: bdmnopx - {9D532653-1EE3-4AB8-84CE-78EAED97B22B} - C:\WINDOWS\bdmnopx.dll (file missing)
O21 - SSODL: admggxp - {49D83D7A-E972-4575-BF88-2241EAD666A3} - C:\WINDOWS\admggxp.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 5952 bytes
Hi, thanks for the log, looking at it now. Please bear in mind that my posts to you must be checked by an expert first, so my replies may take a little longer. The expert working with me on this topic will be offline for a few hours, so I'd check back again in a bit (just letting you know in case you are hanging around for a reply :)).
Hi "JP", Just an update to let you knowthe my desktop has again reverted to the Red Biohazard screen. I have a screen shot for you here in the attachment. Generally, now is when I restore to a prior 'good' point, but I wanted to ask you 1st if you need to capture some information about this 1st. Please, keep in mind that I do not want to wait too long before restoring, as I think I recall that waiting with the Red Screen, meant my cmpt slowing down. I'll check back in about 15 min. to see if you have had a chance to respond to this. Thanks again, and I do understand that you may not get a response from your advisor soon. ***Divna

Attachments:

  • [attachment removed: Your_Privacy_is_in_Danger.gif]
Well my instructor said he'd be offline for a few hours, a bit over 2 hours ago. Of course, its entirely up to you whether or not you perform the system restore. If you can bear to refrain from restoring, that would be nice, as the fixes that I am posting are based on your system's current status, and if you change that then my fixes may become obsolete or un-helpful. Let me know what you're doing, thanks.
Ok, hi again "JP",

I was bombarded with pop-up screens and my cmpt slowed to a stop.
I did have to restore just to get back online with you, sorry.
However, I just went back to the point that I retored to this moring, so I think ( in my limited logic) that my cmpt is at the same stage as when I first wrote to you.

However, here are the 2 log files, as I just re-ran HijackThis, again.
I hope this helps, because I truely am greatful to your efforts.

I hope to be able to stay online now.


hijackthis_at 310pm.log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:10:12 PM, on 3/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Exe Program Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: SXG Advisor - {E48B3E0C-2D23-4249-BE65-23A8719284E3} - C:\WINDOWS\dmdqdrxgxq.dll
O3 - Toolbar: emotrlq - {7B1E78A2-2FC8-4947-A9D1-5177D10B38E6} - C:\WINDOWS\emotrlq.dll (file missing)
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SBI] C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temporary Internet Files\Content.IE5\0Y1FNGAE\install_sbd_en[1].exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O21 - SSODL: bdmnopx - {9D532653-1EE3-4AB8-84CE-78EAED97B22B} - C:\WINDOWS\bdmnopx.dll (file missing)
O21 - SSODL: admggxp - {49D83D7A-E972-4575-BF88-2241EAD666A3} - C:\WINDOWS\admggxp.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 5782 bytes







uninstall_list2.txt





Accurate Outlook Express Mail Expert 3.2
Adobe Flash Player ActiveX
Adobe Reader 7.0.5
avast! Antivirus
BitTorrent 4.4.1
C-Media WDM Audio Driver
DivX
DivX Player
GameSpy Arcade
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
HP PSC & OfficeJet 5.3.B
Java™ 6 Update 3
Medal of Honor Allied Assault Multiplayer Demo
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
MSXML 6.0 Parser (KB933579)
NVIDIA Drivers
Quake 3 Arena Demo
RealPlayer
Realtek AC'97 Audio
Renegade Multiplayer Demo
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
Sveerz
TaxTron 2007
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920342)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925876)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
VIA Platform Device Manager
VIA Rhine-Family Fast Ethernet Adapter
VideoLAN VLC media player 0.8.5
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Hi

You need to disable TeaTimer, so that it doesn't interfere with our fix.

This is a two step process.
First step:
  • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
  • If you have the new version 1.5, click once on Resident Protection, then right-click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
  • If you have Version 1.4, Click on Exit Spybot S&D Resident
Second step, For both versions :
  • Open Spybot S&D
  • Click Mode, choose Advanced Mode
  • Go to the bottom of the vertical panel on the left, click Tools
  • Then, also in left panel, click Resident shows a red/white shield.
  • If your firewall raises a question, say OK
  • In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
  • OK any prompts.
  • Use File, Exit to terminate Spybot
  • Reboot your machine for the changes to take effect.


Download SDFix and save it to your desktop.

It would be a good idea if you print out these instructions or write them down, as you wont have access to the internet.

We need to boot into Safe Mode:
  • Restart the computer.
  • as soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
  • Use the arrow keys to select the Safe mode menu item
  • Press Enter.
  • Choose your usual account.
Once in Safe Mode:
  • Right click the SDFix.zip folder on your Desktop and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log


Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt in your reply.

Thanks.
Hello again "JP",

Thanks for the walk-through.
It was easy to follow.
Here are the results…


report.txt


SDFix: Version 1.150

Run by [removed] on Sun 03/02/2008 at 07:36 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\Leilani\Desktop\SDFix\SDFix

Checking Services :


Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default HomePage Value
Restoring Default Desktop Components Value

Rebooting


Checking Files :

Trojan Files Found:

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat - Contains Links to Malware Sites! - Deleted
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat - Contains Links to Malware Sites! - Deleted
C:\WINDOWS\dmdqdrxgxq.dll - Deleted
C:\DOCUME~1\Leilani\LOCALS~1\Temp\ac8zt2.dat - Deleted
C:\WINDOWS\admggxp.dll - Deleted
C:\WINDOWS\dat.txt - Deleted
C:\WINDOWS\fsxloqf.exe - Deleted
C:\WINDOWS\rs.txt - Deleted
C:\WINDOWS\search_res.txt - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-02 19:48:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:0000008c

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"E:\\Q3Ademo\\quake3.exe"="E:\\Q3Ademo\\quake3.exe:*:Enabled:quake3"
"E:\\RenegadeMPDemo\\RenegadeDemo.exe"="E:\\RenegadeMPDemo\\RenegadeDemo.exe:*:Enabled:Renegade"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files :


File Backups: - C:\DOCUME~1\Leilani\Desktop\SDFix\SDFix\backups\backups.zip

Files with Hidden Attributes :

Mon 12 Nov 2007 24,576 A..H. — "C:\Documents and Settings\Desktop\~WRL0003.tmp"
Mon 12 Nov 2007 31,232 A..H. — "C:\Documents and Settings\Desktop\~WRL2175.tmp"
Mon 12 Nov 2007 34,304 A..H. — "C:\Documents and Settings\Desktop\~WRL2407.tmp"
Mon 12 Nov 2007 59,904 A..H. — "C:\Documents and Settings\Desktop\~WRL3493.tmp"
Mon 12 Nov 2007 63,488 A..H. — "C:\Documents and Settings\Desktop\~WRL3573.tmp"
Mon 28 Jan 2008 1,404,240 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR — "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Mon 12 Nov 2007 24,576 A..H. — "C:\Documents and Settings\Leilani\Desktop\~WRL0003.tmp"
Mon 12 Nov 2007 31,232 A..H. — "C:\Documents and Settings\Leilani\Desktop\~WRL2175.tmp"
Mon 12 Nov 2007 34,304 A..H. — "C:\Documents and Settings\Leilani\Desktop\~WRL2407.tmp"
Tue 28 Sep 2004 3,529 A..HR — "C:\MINE\Leilani\Cover Letter\~WRL0005.tmp"
Sun 21 Jul 2002 418,816 …HR — "C:\WINDOWS\system32\Tools\All.exe"
Thu 18 Jul 2002 390,144 …HR — "C:\WINDOWS\system32\Tools\Change.exe"
Thu 18 Jul 2002 574,464 …HR — "C:\WINDOWS\system32\Tools\CheckPath.exe"
Mon 19 Aug 2002 430,592 …HR — "C:\WINDOWS\system32\Tools\Counter.exe"
Mon 22 Jul 2002 390,656 …HR — "C:\WINDOWS\system32\Tools\DelFolders.exe"
Fri 22 Nov 2002 399,872 …HR — "C:\WINDOWS\system32\Tools\DirectSetup.exe"
Fri 19 Jul 2002 388,096 …HR — "C:\WINDOWS\system32\Tools\RegClean.exe"
Fri 19 Jul 2002 388,608 …HR — "C:\WINDOWS\system32\Tools\Regexe.exe"
Sun 1 Dec 2002 431,616 …HR — "C:\WINDOWS\system32\Tools\Restart.exe"
Fri 19 Jul 2002 388,096 …HR — "C:\WINDOWS\system32\Tools\RunRegexe.exe"
Sun 3 Feb 2008 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT1.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT10.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT11.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT12.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT13.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT14.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT15.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT16.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT17.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT18.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT19.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT1A.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT1B.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT1C.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT1D.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT1F.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT2.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT20.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT21.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT22.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT23.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT24.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT25.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT26.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT27.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT28.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT2B.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT2C.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT2D.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT2E.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT2F.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT3.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT30.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT31.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT32.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT33.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT34.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT35.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT36.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT37.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT38.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT39.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT3A.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT3B.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT3C.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT3D.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT3E.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT3F.tmp"
Sat 5 Jan 2008 85,946 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT3F7.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT4.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT40.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT41.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT42.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT43.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT44.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT45.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT46.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT47.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT48.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT49.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT4A.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT4B.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT4C.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT4D.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT4E.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT4F.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT5.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT50.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT51.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT52.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT53.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT54.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT55.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT56.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT57.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT58.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT59.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT5A.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT5B.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT5C.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT5D.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT5E.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT5F.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT6.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT60.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT61.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT62.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT63.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT64.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT65.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT66.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT67.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT68.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT69.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT6A.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT6B.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT6C.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT6D.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT6E.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT6F.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT7.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT70.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT71.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT72.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT73.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT74.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT75.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT76.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT77.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT78.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT79.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT7A.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT7B.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT7C.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT7D.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT7E.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT7F.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT8.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT80.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT81.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT82.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT83.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT84.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT85.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT86.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT87.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT88.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT89.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT8A.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT8B.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT8C.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT8D.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT8E.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT8F.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT9.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT90.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT91.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT92.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT93.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT94.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT95.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT96.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT97.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT98.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT99.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT9A.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT9B.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT9C.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT9D.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT9E.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT9F.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITA.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITA0.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITA1.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITA2.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITA3.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITA4.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITA5.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITA6.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITA7.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITA8.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITA9.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITAA.tmp"
Tue 12 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITAB.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITAC.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITAE.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITAF.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITB.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITB1.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITB2.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITB4.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITB5.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITB6.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITB8.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITBA.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITBB.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITBD.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITBE.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITC.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITC0.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITC2.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITC3.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITC4.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITC6.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITC7.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITC8.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITC9.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITCA.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITCB.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITCC.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITCD.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITCE.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITCF.tmp"
Sat 9 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITD.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITD0.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITD2.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITD3.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITD4.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITD5.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITD6.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITD7.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITD8.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITD9.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITDA.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITDB.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITDC.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITDD.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITDE.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITDF.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITE.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITE0.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITE1.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITE2.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITE3.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITE4.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITE5.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITE6.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITE7.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITE8.tmp"
Thu 14 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITE9.tmp"
Sun 10 Feb 2008 0 A..H. — "C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BITF.tmp"
Tue 28 Sep 2004 3,529 A..HR — "C:\MINE\Leilani\Cover Letter\Cover Letter 04\~WRL0005.tmp"
Tue 1 Jun 2004 24,064 A..HR — "C:\MINE\W O R K\Resumes etc 3005\2003 cover letters\~WRL0941.tmp"
Tue 1 Jun 2004 23,040 A..HR — "C:\MINE\W O R K\Resumes etc 3005\2003 cover letters\~WRL3099.tmp"
Tue 1 Jun 2004 24,064 A..HR — "C:\MINE\W O R K\Resumes etc 3005\2003 cover letters\~WRL3495.tmp"
Sun 3 Feb 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\3a4b17774256790710b116f48cad024c\BITB.tmp"
Mon 12 Nov 2007 59,904 A..H. — "C:\Documents and Settings\Leilani\Application Data\Microsoft\Internet Explorer\~WRL3493.tmp"
Mon 12 Nov 2007 63,488 A..H. — "C:\Documents and Settings\Leilani\Application Data\Microsoft\Internet Explorer\~WRL3573.tmp"
Thu 30 Dec 2004 23,552 A..H. — "C:\Documents and Settings\Leilani\My Documents\Leilani May\3005 rez-cvrlts\~WRL1379.tmp"
Sat 18 Dec 2004 51,200 A..H. — "C:\Documents and Settings\Leilani\My Documents\Leilani May\3005 rez-cvrlts\~WRL2232.tmp"
Thu 30 Dec 2004 23,552 A..H. — "C:\Documents and Settings\Leilani\My Documents\Leilani May\3005 rez-cvrlts\~WRL3678.tmp"
Wed 14 Sep 2005 19,968 A..H. — "C:\Documents and Settings\Leilani\My Documents\Leilani May\TALK\~WRL0004.tmp"

Finished!


hijackthis_afterSDFix.log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:55:14 PM, on 3/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
C:\Exe Program Downloads\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 5096 bytes


main.txt

Deckard's System Scanner v20071014.68
Run by [removed] on 2008-03-02 19:58:18
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
56: 2008-03-03 03:58:24 UTC - RP57 - Deckard's System Scanner Restore Point
55: 2008-03-02 22:15:14 UTC - RP56 - Installed TaxTron 2007
54: 2008-03-02 22:04:27 UTC - RP55 - Installed Microsoft .NET Framework 1.1
53: 2008-03-02 22:02:51 UTC - RP54 - Installed Microsoft .NET Framework 1.1
52: 2008-03-02 21:52:27 UTC - RP53 - Software Distribution Service 3.0


– First Restore Point –
1: 2008-02-04 00:04:30 UTC - RP2 - Installed Platform


Backed up registry hives.
Performed disk cleanup.



– HijackThis (run as Leilani.exe) ———————————————

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:59:09 PM, on 3/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Leilani\Desktop\dss.exe
C:\EXEPRO~1\Leilani.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 4797 bytes

– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R3 catchme - c:\docume~1\leilani\locals~1\temp\catchme.sys (file missing)


– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ——————–

All services whitelisted.


– Device Manager: Disabled —————————————————-

No disabled devices found.


– Scheduled Tasks ————————————————————-

2008-03-01 09:59:00 284 –a—— C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


– Files created between 2008-02-02 and 2008-03-02 —————————–

2008-03-02 19:31:57 0 d——– C:\WINDOWS\ERUNT
2008-03-02 14:15:15 0 d——– C:\Program Files\TaxTron 2007
2008-03-02 14:00:08 0 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-03-02 12:45:31 0 d——– C:\WINDOWS\privacy_danger(3)
2008-03-02 09:56:22 0 d——– C:\ie-spyad_zo
2008-03-02 09:24:05 0 d——– C:\Program Files\SpywareBlaster
2008-03-02 08:13:23 0 d——– C:\WINDOWS\privacy_danger(2)
2008-03-01 09:49:19 0 d——– C:\Documents and Settings\Leilani\Application Data\Talkback
2008-03-01 09:48:58 0 –a—— C:\WINDOWS\nsreg.dat
2008-03-01 09:48:54 0 d——– C:\Documents and Settings\Leilani\Application Data\Mozilla
2008-03-01 09:48:44 0 d——– C:\Program Files\Mozilla Firefox(2)
2008-02-24 16:12:17 4718592 –a—— C:\Documents and Settings\Leilani\ntuser.dat
2008-02-24 13:19:48 0 d——– C:\Documents and Settings\Leilani\.housecall6.6
2008-02-24 12:27:41 691545 –a—— C:\WINDOWS\unins000.exe
2008-02-24 12:27:41 2551 –a—— C:\WINDOWS\unins000.dat
2008-02-24 12:04:56 0 d——– C:\WINDOWS\CD95F661A5C444F5A6AAECDD91C240B5.TMP
2008-02-24 12:03:54 0 d——– C:\Skunk Studios
2008-02-24 12:03:48 0 d——– C:\Program Files\Flt
2008-02-21 18:45:12 0 d——– C:\Program Files\Spyware Doctor(2)
2008-02-21 17:57:57 0 d——– C:\Program Files\Enigma Software Group
2008-02-16 12:47:22 0 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-16 12:36:40 0 d——– C:\Program Files\Lavasoft
2008-02-10 23:01:51 0 d——– C:\Documents and Settings\All Users\Application Data\WinZip
2008-02-10 22:17:58 0 d——– C:\Temp
2008-02-09 14:11:34 0 d——– C:\WINDOWS\Extras
2008-02-08 19:27:40 90112 –a—— C:\WINDOWS\unvise32.exe
Hi

First of all, your Anti-Virus software (Avast!) seems to be disabled, is this something that you or another user have done yourself?

Your logs are looking better :thumbup:


Open HijackThis. Hit Do A System Scan Only. Place a check next to the following items (if present):
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

Close all browsers and windows except for HijackThis and click Fix Checked.



1. Go to Start->Run and type in notepad and hit OK.

2. Then copy and paste the content of the following codebox into Notepad:

@Echo off
FOR %%G IN (
"C:\Documents and Settings\Desktop\~WRL*.tmp"
"C:\Documents and Settings\Leilani\Desktop\~WRL*.tmp"
"C:\MINE\Leilani\Cover Letter\~WRL*.tmp"
"C:\Documents and Settings\Riley.CURIOUS_GEORGE\Local Settings\Temp\BIT*.tmp"
"C:\MINE\Leilani\Cover Letter\Cover Letter 04\~WRL*.tmp"
"C:\MINE\W O R K\Resumes etc 3005\2003 cover letters\~WRL*.tmp"
"C:\WINDOWS\SoftwareDistribution\Download\3a4b17774256790710b116f48cad024c\BIT*.tmp"
"C:\Documents and Settings\Leilani\Application Data\Microsoft\Internet Explorer\~WRL3493.tmp"
"C:\Documents and Settings\Leilani\Application Data\Microsoft\Internet Explorer\~WRL3573.tmp"
"C:\Documents and Settings\Leilani\My Documents\Leilani May\3005 rez-cvrlts\~WRL*.tmp"
"C:\Documents and Settings\Leilani\My Documents\Leilani May\TALK\~WRL*.tmp"

) DO (
attrib -r -h -s %%G
del /q /f %%G
)
del delete.bat

3. Save the file to your DESKTOP as "delete.bat". Make sure to save it with the quotes. Once saved, the icon to click should look like this on your desktop: [external image: Posted Image]

4. Double click delete.bat.



Download ComboFix by sUBs from here or here

**Save it to your desktop**

Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall




Please do an online scan with Kaspersky WebScanner

Follow this link in Internet Explorer (Note: You must use Internet explorer to use Kaspersky): Kaspersky WebScanner

You will be prompted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    o Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)

    o Scan Options:
    Scan Archives Scan Mail Bases

  • Click OK
  • Now under select a target to scan:
    Select My Computer
  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    o Now click on the Save as Text button:
  • Save the file to your desktop.
Please post the results of the Kaspersky scan in your next reply.

Also, please give a detailed description of how your computer is running and behaving at the moment, listing any remaining problems.

Thanks.
Gooe Evening,

I have done all that you had suggested and here are the results:


ComboFix_Log


ComboFix 08-03-04.1 - Leilani 2008-03-03 18:13:15.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.631 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\MyWay
C:\WINDOWS\system32\uninstall.exe

.
((((((((((((((((((((((((( Files Created from 2008-02-04 to 2008-03-04 )))))))))))))))))))))))))))))))
.

2008-03-02 20:24 . 2008-03-02 20:47 d——– C:\Program Files\SpywareBlaster
2008-03-02 20:24 . 2008-03-02 20:47 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-02 19:57 . 2008-03-02 19:57 d——– C:\Deckard
2008-03-02 19:31 . 2008-03-02 19:32 d——– C:\WINDOWS\ERUNT
2008-03-02 14:15 . 2008-03-02 14:15 d——– C:\Program Files\TaxTron 2007
2008-03-02 14:00 . 2008-03-02 14:00 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-03-02 12:45 . 2008-03-02 13:47 d——– C:\WINDOWS\privacy_danger(3)
2008-03-02 09:56 . 2008-03-02 20:25 d——– C:\ie-spyad_zo
2008-03-02 08:13 . 2008-03-02 13:48 d——– C:\WINDOWS\privacy_danger(2)
2008-03-01 09:49 . 2008-03-01 09:49 d——– C:\Documents and Settings\Leilani\Application Data\Talkback
2008-03-01 09:48 . 2008-03-02 13:49 d——– C:\Program Files\Mozilla Firefox(2)
2008-03-01 09:48 . 2008-03-01 09:48 0 –a—— C:\WINDOWS\nsreg.dat
2008-02-24 13:22 . 2008-02-24 13:20 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-24 13:19 . 2008-02-24 13:22 d——– C:\Documents and Settings\Leilani\.housecall6.6
2008-02-24 13:05 . 2008-02-24 13:06 163 –a—— C:\WINDOWS\wininit.ini
2008-02-24 12:27 . 2008-02-24 12:26 691,545 –a—— C:\WINDOWS\unins000.exe
2008-02-24 12:27 . 2008-02-24 12:27 2,551 –a—— C:\WINDOWS\unins000.dat
2008-02-24 12:04 . 2008-02-24 12:04 d——– C:\WINDOWS\CD95F661A5C444F5A6AAECDD91C240B5.TMP
2008-02-24 12:03 . 2008-02-24 12:03 d——– C:\Skunk Studios
2008-02-24 12:03 . 2008-02-24 12:03 d——– C:\Program Files\Flt
2008-02-21 18:45 . 2008-02-24 12:03 d——– C:\Program Files\Spyware Doctor(2)
2008-02-21 17:57 . 2008-02-21 18:37 d——– C:\Program Files\Enigma Software Group
2008-02-16 12:47 . 2008-02-24 12:04 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-16 12:36 . 2008-02-24 12:04 d——– C:\Program Files\Lavasoft
2008-02-10 23:01 . 2008-02-10 23:02 d——– C:\Documents and Settings\All Users\Application Data\WinZip
2008-02-10 22:29 . 2004-08-03 22:58 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-02-10 22:29 . 2004-08-03 22:58 15,104 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-02-10 22:27 . 2004-08-03 23:01 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-10 22:27 . 2004-08-03 23:01 25,856 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2008-02-10 22:26 . 2004-08-03 23:08 31,616 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2008-02-10 22:26 . 2004-08-03 23:08 31,616 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-02-10 22:17 . 2008-02-10 22:25 d——– C:\Temp\HP_WebRelease
2008-02-10 22:17 . 2008-02-10 22:17 d——– C:\Temp
2008-02-10 12:15 . 2008-02-10 12:15 15,360 –ahs—- C:\WINDOWS\Thumbs.db
2008-02-10 12:15 . 2008-02-10 12:15 5,120 –ahs—- C:\WINDOWS\system32\Thumbs.db
2008-02-09 14:11 . 2008-02-09 14:11 d——– C:\WINDOWS\Extras
2008-02-08 19:27 . 2004-03-29 16:23 90,112 –a—— C:\WINDOWS\unvise32.exe
2008-02-05 18:39 . 2008-02-05 18:40 d——– C:\Program Files\BitTorrent
2008-02-05 18:29 . 2008-02-24 12:03 d——– C:\Program Files\Google
2008-02-05 15:40 . 2008-02-05 16:41 d——– C:\test
2008-02-05 12:02 . 2008-02-05 12:02 d——– C:\Documents and Settings\.housecall6.6\report
2008-02-05 12:02 . 2008-02-05 12:02 d——– C:\Documents and Settings\.housecall6.6\debug
2008-02-05 12:02 . 2008-02-05 12:02 11 –a—— C:\AuResult.ini
2008-02-05 11:14 . 2008-02-05 11:14 d——– C:\Documents and Settings\Leilani\Application Data\Autodesk
2008-02-05 11:14 . 2008-02-05 11:14 d——– C:\Documents and Settings\Leilani\Application Data\Apple Computer
2008-02-05 11:14 . 2008-02-05 11:14 d——– C:\Documents and Settings\Leilani\Application Data\Ahead
2008-02-05 11:14 . 2008-02-05 11:14 d——– C:\Documents and Settings\Leilani\Application Data\AdobeUM
2008-02-05 11:14 . 2008-02-05 11:14 d——– C:\Documents and Settings\Leilani\Application Data\AdobeAUM
2008-02-05 11:14 . 2008-02-05 11:14 d——– C:\Documents and Settings\Leilani\Application Data\.bittorrent
2008-02-05 11:11 . 2008-02-05 11:11 d——– C:\Documents and Settings\Leilani\Application Data\Microsoft Games
2008-02-05 11:11 . 2008-02-05 11:11 d——– C:\Documents and Settings\Leilani\Application Data\Leadertech
2008-02-05 11:11 . 2008-02-05 11:11 d——– C:\Documents and Settings\Leilani\Application Data\Image Zone Express
2008-02-05 11:11 . 2008-02-05 11:11 d——– C:\Documents and Settings\Leilani\Application Data\HP
2008-02-05 11:11 . 2008-02-05 11:11 d——– C:\Documents and Settings\Leilani\Application Data\ESRI
2008-02-05 11:11 . 2008-02-05 11:11 d——– C:\Documents and Settings\Leilani\Application Data\BitTorrent
2008-02-05 11:10 . 2008-02-05 11:10 d——– C:\Documents and Settings\Leilani\Application Data\uTorrent
2008-02-05 11:10 . 2008-02-05 11:10 d——– C:\Documents and Settings\Leilani\Application Data\Red Chair Software
2008-02-05 10:57 . 2008-02-05 10:58 d——– C:\WINDOWS\nview
2008-02-05 10:57 . 2005-07-20 20:07 176,128 –a—— C:\WINDOWS\system32\nvudisp.exe
2008-02-05 10:57 . 2008-03-03 17:56 29,204 –a—— C:\WINDOWS\system32\nvapps.xml
2008-02-05 10:57 . 2005-07-20 20:07 14,757 –a—— C:\WINDOWS\system32\nvdisp.nvu
2008-02-04 17:52 . 2008-02-04 17:52 d——– C:\Program Files\Accurate Outlook Express Mail Expert
2008-02-04 16:18 . 2008-02-04 16:18 d——– C:\Documents and Settings\Leilani\Application Data\vlc
2008-02-04 15:58 . 2001-08-17 14:02 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-02-04 15:58 . 2001-08-17 14:02 9,600 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys
2008-02-04 14:49 . 2008-02-04 14:49 d——– C:\Program Files\VIA Technologies, Inc
2008-02-04 14:49 . 2002-12-18 11:57 45,056 –a—— C:\WINDOWS\system32\vusetup.dll
2008-02-04 14:49 . 2002-11-13 01:34 10,496 –a—— C:\WINDOWS\system32\drivers\vulfntr.sys
2008-02-04 14:49 . 2002-10-24 00:07 6,912 –a—— C:\WINDOWS\system32\drivers\vulfnth.sys
2008-02-04 14:33 . 2008-02-04 14:33 91 –a—— C:\BIOSVIEW.INI
2008-02-04 14:33 . 2008-02-04 14:33 34 –a—— C:\BIOSINFO.INI
2008-02-04 11:24 . 2008-02-04 11:24 d–h—– C:\WINDOWS\PIF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-02 18:15 ——— d—–w C:\Program Files\Trend Micro
2008-03-02 17:21 96,160 —-a-w C:\Documents and Settings\Leilani\Application Data\GDIPFONTCACHEV1.DAT
2008-02-24 21:17 ——— d—–w C:\Program Files\Java
2008-02-24 20:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-24 20:29 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-10 19:57 ——— d—–w C:\Program Files\GameSpy Arcade
2008-02-10 05:19 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-05 19:19 ——— d—–w C:\Documents and Settings\Leilani\Application Data\Skype
2008-02-05 19:14 ——— d—–w C:\Documents and Settings\Leilani\Application Data\.bittorrent
2008-02-05 19:10 ——— d—–w C:\Documents and Settings\Leilani\Application Data\Symantec
2008-02-05 00:12 ——— d—–w C:\Program Files\Windows Media Connect 2
2008-02-04 22:50 ——— d—–w C:\Program Files\AvRack
2008-02-04 05:24 ——— d—–w C:\Program Files\MSXML 6.0
2008-02-04 00:49 ——— d—–w C:\Program Files\Common Files\L&H;
2008-02-03 23:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-03 23:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-02-03 09:03 ——— d—–w C:\Documents and Settings\Leilani\Application Data\Microsoft Web Folders
2008-02-03 05:42 ——— d—–w C:\Documents and Settings\Riley\Application Data\HP
2008-02-03 05:42 ——— d—–w C:\Documents and Settings\Riley\Application Data\Apple Computer
2008-02-03 05:42 ——— d—–w C:\Documents and Settings\Riley\Application Data\.bittorrent
2008-02-03 05:41 ——— d—–w C:\Documents and Settings\Riley\Application Data\Skype
2008-02-03 05:41 ——— d—–w C:\Documents and Settings\Riley\Application Data\Microsoft Games
2008-02-03 05:10 ——— d—–w C:\Program Files\Nero
2008-02-03 05:10 ——— d—–w C:\Program Files\MSXML 4.0
2008-02-03 05:09 ——— d—–w C:\Program Files\MSN Messenger
2008-02-03 05:05 ——— d—a-w C:\Program Files\Maxis
2008-02-03 05:05 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-02-03 05:04 ——— d—–w C:\Program Files\Macromedia
2008-02-03 05:04 ——— d—–w C:\Program Files\Luxor
2008-02-03 05:03 ——— d—–w C:\Program Files\Logitech
2008-02-03 04:59 ——— d—–w C:\Program Files\Kodak
2008-02-03 04:57 ——— d—–w C:\Program Files\iTunes
2008-02-03 04:57 ——— d—–w C:\Program Files\iPod
2008-02-03 04:57 ——— d—–w C:\Program Files\iPhoto Plus 4
2008-02-03 04:52 ——— d—–w C:\Program Files\HP
2008-02-03 04:52 ——— d—–w C:\Program Files\Hewlett-Packard
2008-02-03 04:52 ——— d—–w C:\Program Files\FutureTax 2006
2008-02-03 04:52 ——— d—–w C:\Program Files\FlexVoice
2008-02-03 04:51 ——— d—–w C:\Program Files\FileMaker
2008-02-03 04:51 ——— d—–w C:\Program Files\ESRI
2008-02-03 04:40 ——— d—–w C:\Program Files\EA GAMES
2008-02-03 04:40 ——— d—–w C:\Program Files\DivX
2008-02-03 04:40 ——— d—–w C:\Program Files\DIFX
2008-02-03 04:40 ——— d—–w C:\Program Files\Creative
2008-02-03 04:39 ——— d—a-w C:\Program Files\Common Files\Ahead
2008-02-03 04:39 ——— d—–w C:\Program Files\Common Files\Autodesk Shared
2008-02-03 04:39 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-03 04:38 ——— d—–w C:\Program Files\Common Files\HP
2008-02-03 04:38 ——— d—–w C:\Program Files\Common Files\Hewlett-Packard
2008-02-03 04:38 ——— d—–w C:\Program Files\Common Files\ESRI
2008-02-03 04:38 ——— d—–w C:\Program Files\Common Files\DirectX
2008-02-03 04:38 ——— d—–w C:\Program Files\Common Files\DEVConcept Shared
2008-02-03 04:38 ——— d—–w C:\Program Files\Common Files\Bentley Shared
2008-02-03 04:37 ——— d—–w C:\Program Files\Common Files\Kodak
2008-02-03 04:37 ——— d—–w C:\Program Files\Common Files\Java
2008-02-03 04:37 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-02-03 04:36 ——— d—–w C:\Program Files\Common Files\LogiShrd
2008-02-03 04:36 ——— d—–w C:\Program Files\Common Files\L&H; Shared
2008-02-03 04:35 ——— d—–w C:\Program Files\Common Files\Macrovision Shared
2008-02-03 04:35 ——— d—–w C:\Program Files\Common Files\Logitech
2008-02-03 04:33 ——— d—a-w C:\Program Files\Common Files\Symantec Shared
2008-02-03 04:33 ——— d—a-w C:\Program Files\Common Files\Panda Software
2008-02-03 04:33 ——— d—–w C:\Program Files\Common Files\Sonic Shared
2008-02-03 04:33 ——— d—–w C:\Program Files\Common Files\Skype
2008-02-03 04:33 ——— d—–w C:\Program Files\Common Files\Real
2008-02-03 04:33 ——— d—–w C:\Program Files\Common Files\Pure Networks Shared
2008-02-03 04:33 ——— d—–w C:\Program Files\Common Files\Mindmaker
2008-02-03 04:32 ——— d—–w C:\Program Files\Common Files\xing shared
2008-02-03 04:31 ——— d—–w C:\Program Files\Chuzzle Deluxe
2008-02-03 04:31 ——— d—–w C:\Program Files\CCleaner
2008-02-03 04:31 ——— d—–w C:\Program Files\Canon
2008-02-03 04:31 ——— d—–w C:\Program Files\Byteswarm
2008-02-03 04:31 ——— d—–w C:\Program Files\Bentley
2008-02-03 04:28 ——— d—–w C:\Program Files\Autodesk
2008-02-03 04:28 ——— d—–w C:\Program Files\AutoCAD 2004
2008-02-03 04:25 ——— d—–w C:\Program Files\ArcGIS
2008-02-03 04:15 ——— d—–w C:\Program Files\Apple Software Update
2008-02-03 04:15 ——— d—–w C:\Program Files\AnswerWorks 4.0
2008-02-03 04:14 ——— d—–w C:\Program Files\Alwil Software
2008-02-03 04:14 ——— d—–w C:\Program Files\Ahead
2008-02-03 04:13 ——— d—a-w C:\Program Files\Accessories
2008-02-03 04:13 ——— d—–w C:\Program Files\Yahoo!
2008-02-03 04:12 ——— d—–w C:\Program Files\WildTangent Games
2008-02-03 04:12 ——— d—–w C:\Program Files\WiFiConnector
2008-02-03 04:12 ——— d—–w C:\Program Files\War Chess
2008-02-03 04:12 ——— d—–w C:\Program Files\VideoLAN
2008-02-03 04:12 ——— d—–w C:\Program Files\VIAudioi
2008-02-03 04:11 ——— d—–w C:\Program Files\Universal Document Converter
2008-02-03 04:11 ——— d—–w C:\Program Files\Unitype
2008-02-03 04:11 ——— d—–w C:\Program Files\UltraVNC
2008-02-03 04:11 ——— d—–w C:\Program Files\Trymedia
2008-02-03 04:10 ——— d—–w C:\Program Files\TLI
2008-02-03 04:10 ——— d—–w C:\Program Files\TextBridge Classic
2008-02-03 04:09 ——— d—a-w C:\Program Files\Symantec
2008-02-03 04:09 ——— d—–w C:\Program Files\Skype
2008-02-03 04:08 ——— d—a-w C:\Program Files\Silicon Prairie Software
2008-02-03 04:08 ——— d—–w C:\Program Files\ReflexiveArcade
2008-02-03 04:08 ——— d—–w C:\Program Files\Red Chair Software
2008-02-03 04:07 ——— d—–w C:\Program Files\Real
2008-02-03 04:07 ——— d—–w C:\Program Files\ReadPlease 2003
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24 1694208]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 04:39 69632 C:\WINDOWS\soundman.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-07-20 20:07 7110656]
"nwiz"="nwiz.exe" [2005-07-20 20:07 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-07-20 20:07 86016]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-05 18:31 185632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]

C:\Documents and Settings\Leilani\Start Menu\Programs\Startup\
BitTorrent.lnk - C:\Program Files\BitTorrent\bittorrent.exe [2006-02-02 23:42:04 153088]
MemTurbo.lnk - C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe [2005-10-02 11:05:15 221696]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]
VIA RAID TOOL.lnk - C:\Program Files\VIA\RAID\raid_tool.exe [2005-10-02 10:41:54 565248]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

S3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2004-12-16 13:36]

.
Contents of the 'Scheduled Tasks' folder
"2008-03-01 17:59:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-03 18:15:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-03 18:15:58
ComboFix-quarantined-files.txt 2008-03-04 02:15:44
.
2008-03-02 21:55:27 — E O F —




hijackthis_Mar3




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:21:21 PM, on 3/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Exe Program Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 5066 bytes





KasperskyScanResults


——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, March 03, 2008 9:15:42 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 4/03/2008
Kaspersky Anti-Virus database records: 594923
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 95809
Number of viruses found: 9
Number of infected objects: 21
Number of suspicious objects: 0
Duration of the scan process: 02:02:12

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Leilani\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Leilani\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Leilani\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Leilani\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Leilani\Local Settings\History\History.IE5\MSHist012008022520080303\index.dat Object is locked skipped
C:\Documents and Settings\Leilani\Local Settings\History\History.IE5\MSHist012008030320080304\index.dat Object is locked skipped
C:\Documents and Settings\Leilani\Local Settings\Temp\Perflib_Perfdata_854.dat Object is locked skipped
C:\Documents and Settings\Leilani\Local Settings\Temp\~DF20FF.tmp Object is locked skipped
C:\Documents and Settings\Leilani\Local Settings\Temp\~DF210B.tmp Object is locked skipped
C:\Documents and Settings\Leilani\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Leilani\My Documents\Adware Help\SDFix\SDFix\backups\backups.zip/backups/admggxp.dll Infected: not-a-virus:AdWare.Win32.Vapsup.bay skipped
C:\Documents and Settings\Leilani\My Documents\Adware Help\SDFix\SDFix\backups\backups.zip/backups/dmdqdrxgxq.dll Infected: not-a-virus:AdWare.Win32.Vapsup.bax skipped
C:\Documents and Settings\Leilani\My Documents\Adware Help\SDFix\SDFix\backups\backups.zip/backups/fsxloqf.exe Infected: not-a-virus:AdWare.Win32.Vapsup.baz skipped
C:\Documents and Settings\Leilani\My Documents\Adware Help\SDFix\SDFix\backups\backups.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Leilani\ntuser.dat Object is locked skipped
C:\Documents and Settings\Leilani\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\UltraVNC\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\Program Files\UltraVNC\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 skipped
C:\Program Files\UltraVNC\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP2\A0000233.exe Infected: not-a-virus:RiskTool.Win32.Reboot.e skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP20\A0026230.exe Infected: not-a-virus:RiskTool.Win32.Reboot.e skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP26\A0042569.dll Infected: not-a-virus:AdWare.Win32.Vapsup.azi skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP34\A0042755.exe Infected: not-a-virus:FraudTool.Win32.BraveSentry.h skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP34\A0042760.exe Infected: not-virus:Hoax.Win32.Renos.avb skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP45\A0046158.exe Infected: not-a-virus:FraudTool.Win32.BraveSentry.h skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP45\A0046163.dll Infected: not-a-virus:AdWare.Win32.Vapsup.azi skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP45\A0046164.exe Infected: not-virus:Hoax.Win32.Renos.avb skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP56\A0048557.dll Infected: not-a-virus:AdWare.Win32.Vapsup.bax skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP56\A0048558.dll Infected: not-a-virus:AdWare.Win32.Vapsup.bay skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP56\A0048559.exe Infected: not-a-virus:AdWare.Win32.Vapsup.baz skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP56\A0048565.dll Infected: not-a-virus:AdWare.Win32.Vapsup.bay skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP56\A0048566.dll Infected: not-a-virus:AdWare.Win32.Vapsup.bax skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP56\A0048568.exe Infected: not-a-virus:AdWare.Win32.Vapsup.baz skipped
C:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP58\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_574.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{57F5DD97-AD14-41CD-A50D-92CC59CAE65C}\RP58\change.log Object is locked skipped

Scan process completed.







My cmpt has not had any pop ups nor the Red Screen since running the process that you had suggested, yesterday.
Thank-you sooooooooo much!

As the KasperskyScan took over 2 hrs to complete, I must sign off forthe evening.
I'll check back tomorrow evening for any further instructions.

Again, thank-you for ALL of this :)


***Divna

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI