This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HELP! frustrating spyware and slow browser

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Help me please i have this weird spyware that changes regular website ads into some antivirus ad and also firefox is running slow on certain web sites and just continously loads a page with a blank page.


Logfile of HijackThis v1.99.1
Scan saved at 12:32:25 AM, on 3/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Azureus\Azureus.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Anubis\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: {7e330310-8b49-4449-7b64-87b791eb5598} - {8955be19-7b78-46b7-9444-94b8013033e7} - C:\WINDOWS\system32\ipjoitxm.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BM07924ba6] Rundll32.exe "C:\WINDOWS\system32\sdxojgfj.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Add To Compaq Organize… - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!

  • Saveand quit any work your doing before beginning the fix.
  • All hijackthis logs I ask for should be done in normal mode ( not safe mode)
  • These logs should be done last after you have followed my instructions in the previous post.


Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!




I see that Viewpoint is installed.

Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". In 2006, this may change, read Viewpoint to Plunge Into Adware.

I suggest you remove the program now. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present:
  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player
If AOL is present, to prevent it from being recreated every time you run the AOL software:
  • Open AOL
  • Go to Help on the toolbar
  • Select About AOL
  • Hit Ctrl D and a secret panel can be accessed which will allow you to disable all desktop and IM features associated with Viewpoint.
Another way to prevent Viewpoint from being recreated every time you run the AOL software is:
  • Click C:\Program Files\AOL 9.0\Jiti (a hidden folder).
  • Rename viewpoint.exe to viewpoint.old.
This is the item to fix in HijackThis.

O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe


_________________________________________

WeatherBug is a system tray icon that offers weather information and includes built-in ads. WeatherBug is controlled by AWS Convergence Technologies (weatherbugmedia.com). There is some controversy over whether WeatherBug should be targeted by anti-parasite software. AWS strongly deny their software is ‘spyware’, and by the definition used here, it is not, as it does not leak information back to its controlling servers. However, WeatherBug has in the past been silently installed by the FavoriteMan parasite and Freeze.com screensavers, and more recently has been bundled by software such as AIM and Blubster. This makes it ‘unsolicited’, and since it is installed to raise money for its creators through the built-in ads it is certainly ‘commercial’. So it does meet the definition for ‘parasite’: unsolicited commercial software. It is nonetheless listed as a borderline case because it is not overtly harmful and many people do install it deliberately. WeatherBug bundles the MySearch parasite in its standalone distribution and has in the past, installed Gator and SVAPlayer.

I recommend that you uninstall WeatherBugand choose one of these alternatives:
Weather Pulse
Weather Watcher
or
Get mozilla Firefox and then get FORECASTFOX!!!
or check the weather at these websites:
Weather Street: US Weather
Intellicast
To uninstall WeatherBug:
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight WeatherBug, click Remove.
  • Close the Add or Remove Programs and the Control Panel windows.
This is the item to fix in HijackThis:

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} -C:\Program
Files\AWS\WeatherBug\Weather.exe (file missing)


O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} - http://download.weatherbug.com/minibug/tri…Transporter.cab?


_______________________________________________






1. Download Combo fix from one of these locations.
* IMPORTANT !!! Place combofix.exe on your Desktop

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

2. Click start/run and copy and Paste this in exactly using the picture below for reference:

"%userprofile%\desktop\combofix.exe" /killall


[external image: Posted Image]

3. Combo will begin to run DO NOTHING while this is happeneing.
  • It will kill a few processes and disconnect you from the internet.
  • If by chance it stops prematurly you can re-establish your internet connection by restarting your computer.
  • This needs to be done so the program can work most efficiently for you.
Do not attempt to use the internet or anything else while it's doing its job for you.

If when it's completed you can not get on the internet just reboot the computer

Post the log from comboFix for me located in
c:\comboFix.txt





_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
The new HJT report:
Logfile of HijackThis v1.99.1
Scan saved at 11:23:54 PM, on 3/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Anubis\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Add To Compaq Organize… - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

ComboFix report:

ComboFix 08-03-10.1 - Anubis 2008-03-12 23:07:23.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.934 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Anubis\Application Data\macromedia\Flash Player\#SharedObjects\P7GVALZP\www.broadcaster.com
C:\Documents and Settings\Anubis\Application Data\macromedia\Flash Player\#SharedObjects\P7GVALZP\www.broadcaster.com\played_list.sol
C:\Documents and Settings\Anubis\Application Data\macromedia\Flash Player\#SharedObjects\P7GVALZP\www.broadcaster.com\video_queue.sol
C:\Documents and Settings\Anubis\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Anubis\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\Anubis\Application Data\searchtoolbarcorp
C:\Documents and Settings\Anubis\Application Data\searchtoolbarcorp\Toolbar Vision\PageHistory.txt
C:\Documents and Settings\Anubis\Application Data\searchtoolbarcorp\Toolbar Vision\WebHistory.txt
C:\Temp\bkR11
C:\WINDOWS\BM07924ba6.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aabalpwd.dll
C:\WINDOWS\system32\awxqigpo.dll
C:\WINDOWS\system32\bkkmtphc.ini
C:\WINDOWS\system32\bqoxcgey.ini
C:\WINDOWS\system32\cimmfwfi.dll
C:\WINDOWS\system32\cvtguunt.ini
C:\WINDOWS\system32\daSgo02
C:\WINDOWS\system32\dmcgkrlt.dll
C:\WINDOWS\system32\fexgtiik.dll
C:\WINDOWS\system32\fvpyvvfo.ini
C:\WINDOWS\system32\geuvpbky.dll
C:\WINDOWS\system32\gwevrvnr.dll
C:\WINDOWS\system32\hjtxrxgk.ini
C:\WINDOWS\system32\hmcdtfly.ini
C:\WINDOWS\system32\ikutnvvf.dll
C:\WINDOWS\system32\ipjoitxm.dll
C:\WINDOWS\system32\iwsdvijd.dll
C:\WINDOWS\system32\ktcwbkss.ini
C:\WINDOWS\system32\kuqqhtfi.ini
C:\WINDOWS\system32\kvfivynu.dll
C:\WINDOWS\system32\kxacxxsn.ini
C:\WINDOWS\system32\lxpulnmo.dll
C:\WINDOWS\system32\mchynumc.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mcrshphp.dll
C:\WINDOWS\system32\mfkneixp.dll
C:\WINDOWS\system32\mqitrlki.ini
C:\WINDOWS\system32\napxeiyj.ini
C:\WINDOWS\system32\npsovohs.dll
C:\WINDOWS\system32\olgbfjph.dll
C:\WINDOWS\system32\osmnukjc.ini
C:\WINDOWS\system32\otvhdgcc.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\qhmjbtyq.dll
C:\WINDOWS\system32\qlovxmuv.ini
C:\WINDOWS\system32\rotukqse.dll
C:\WINDOWS\system32\rrutv.ini
C:\WINDOWS\system32\rrutv.ini2
C:\WINDOWS\system32\rtvwa.ini
C:\WINDOWS\system32\rtvwa.ini2
C:\WINDOWS\system32\sbpoevpd.tmp
C:\WINDOWS\system32\sbpoevpd.tmp2
C:\WINDOWS\system32\sdxojgfj.dll
C:\WINDOWS\system32\serlaiqb.dll
C:\WINDOWS\system32\tbxmgdob.dll
C:\WINDOWS\system32\tnvlnqwn.dll
C:\WINDOWS\system32\tnvtkfhb.ini
C:\WINDOWS\system32\tsypfqma.dll
C:\WINDOWS\system32\tyujbpfb.dll
C:\WINDOWS\system32\ugvdyshi.ini
C:\WINDOWS\system32\uimckmpf.ini
C:\WINDOWS\system32\utstv.ini
C:\WINDOWS\system32\utstv.ini2
C:\WINDOWS\system32\uylkiban.dll
C:\WINDOWS\system32\vmbsqqqw.dll
C:\WINDOWS\system32\wfbdbydp.dll
C:\WINDOWS\system32\wfnsvtxw.ini
C:\WINDOWS\system32\wjitgumn.dll
C:\WINDOWS\system32\ybwlvlgj.ini
C:\WINDOWS\system32\ydjkprhx.dll
C:\WINDOWS\system32\yvdqxjwf.dll
D:\Autorun.inf
L:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-02-13 to 2008-03-13 )))))))))))))))))))))))))))))))
.

2008-03-12 22:50 . 2008-03-12 22:52 d——– C:\Program Files\Windows Live
2008-03-10 10:44 . 2008-03-10 10:44 16,384 –a—— C:\WINDOWS\~DFF829.tmp
2008-03-07 12:09 . 2008-03-07 12:16 d——– C:\Program Files\CA Yahoo! Anti-Spy
2008-02-28 00:41 . 2008-02-28 00:41 d——– C:\Documents and Settings\Anubis\Application Data\Malwarebytes
2008-02-28 00:40 . 2008-03-09 20:57 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-28 00:40 . 2008-02-28 00:40 d——– C:\Program Files\Common Files\Download Manager
2008-02-28 00:40 . 2008-02-28 00:40 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-28 00:00 . 2004-08-04 00:10 10,880 –a—— C:\WINDOWS\system32\drivers\NdisIP.sys
2008-02-28 00:00 . 2004-08-04 00:10 10,880 –a–c— C:\WINDOWS\system32\dllcache\ndisip.sys
2008-02-28 00:00 . 2004-08-03 23:58 5,504 –a—— C:\WINDOWS\system32\drivers\MSTEE.sys
2008-02-28 00:00 . 2004-08-03 23:58 5,504 –a–c— C:\WINDOWS\system32\dllcache\mstee.sys
2008-02-27 23:57 . 2004-08-04 01:56 90,624 –a—— C:\WINDOWS\system32\kswdmcap.ax
2008-02-27 23:57 . 2004-08-04 01:56 90,624 –a–c— C:\WINDOWS\system32\dllcache\kswdmcap.ax
2008-02-27 23:57 . 2004-08-04 01:56 61,952 –a—— C:\WINDOWS\system32\kstvtune.ax
2008-02-27 23:57 . 2004-08-04 01:56 61,952 –a–c— C:\WINDOWS\system32\dllcache\kstvtune.ax
2008-02-27 23:57 . 2004-08-04 01:56 53,760 –a—— C:\WINDOWS\system32\vfwwdm32.dll
2008-02-27 23:57 . 2004-08-04 01:56 53,760 –a–c— C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-02-27 23:57 . 2004-08-04 01:56 43,008 –a—— C:\WINDOWS\system32\ksxbar.ax
2008-02-27 23:57 . 2004-08-04 01:56 43,008 –a–c— C:\WINDOWS\system32\dllcache\ksxbar.ax
2008-02-27 23:57 . 2004-08-04 01:56 28,672 –a—— C:\WINDOWS\system32\vidcap.ax
2008-02-27 23:57 . 2004-08-04 01:56 28,672 –a–c— C:\WINDOWS\system32\dllcache\vidcap.ax
2008-02-27 23:49 . 2008-02-27 23:49 d——– C:\Program Files\PC Camer@
2008-02-27 23:49 . 2006-11-03 10:59 48,128 –a—— C:\WINDOWS\system32\Remove.exe
2008-02-27 23:49 . 2007-02-12 01:06 408 –a—— C:\WINDOWS\system32\Remover.ini
2008-02-27 13:20 . 2008-02-27 13:20 d—s—- C:\Documents and Settings\Guest.ANUBISZRO\UserData
2008-02-27 09:08 . 2008-03-12 22:59 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-27 09:08 . 2008-02-27 09:08 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-26 23:38 . 2008-02-26 23:38 d——– C:\Documents and Settings\Anubis\Application Data\ATI MMC
2008-02-24 15:14 . 2008-01-12 19:32 23,904 –a—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-02-24 15:14 . 2008-01-15 10:54 10,537 –a—— C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-02-24 15:14 . 2008-01-15 06:28 706 –a—— C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-02-24 15:04 . 2008-02-24 15:04 16 –a—— C:\WINDOWS\system32\coh.cache
2008-02-24 14:46 . 2008-02-24 15:02 123,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-24 14:46 . 2008-02-24 15:02 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-24 14:46 . 2008-02-24 15:02 10,740 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-24 14:46 . 2008-02-24 15:02 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-24 14:35 . 2008-02-24 14:35 d——– C:\WINDOWS\E80F62FF5D3C4A1984099721F2928206.TMP
2008-02-22 22:03 . 2008-02-23 21:28 1,674 —hs—- C:\WINDOWS\system32\ovwkcwvl.ini
2008-02-21 22:03 . 2008-02-22 22:02 1,434 —hs—- C:\WINDOWS\system32\qsbyoyaa.ini
2008-02-20 19:43 . 2008-02-21 22:03 1,194 —hs—- C:\WINDOWS\system32\cdgrymnb.ini
2008-02-19 10:46 . 2008-02-20 19:43 1,014 —hs—- C:\WINDOWS\system32\eijbwxmk.ini
2008-02-19 10:44 . 2008-02-19 10:46 894 —hs—- C:\WINDOWS\system32\iaguxmph.ini
2008-02-18 23:33 . 2004-08-03 23:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-02-18 23:33 . 2004-08-03 23:58 14,848 –a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-02-18 10:42 . 2008-02-19 10:41 834 —hs—- C:\WINDOWS\system32\tnpanycr.ini
2008-02-17 02:17 . 2008-02-18 10:40 534 —hs—- C:\WINDOWS\system32\wghmnstb.ini
2008-02-16 13:09 . 2008-02-16 13:09 230 –a—— C:\WINDOWS\system32\spupdsvc.inf
2008-02-16 11:37 . 2008-02-16 11:37 294 —hs—- C:\WINDOWS\system32\draopbdk.ini
2008-02-15 00:18 . 2008-02-15 22:11 414 —hs—- C:\WINDOWS\system32\clthuuit.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-13 02:53 ——— d—–w C:\Program Files\MSN Messenger
2008-03-13 02:50 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-13 02:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-13 01:47 ——— d—–w C:\Program Files\Viewpoint
2008-03-13 01:47 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Viewpoint
2008-03-13 01:47 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-13 00:34 ——— d—–w C:\Documents and Settings\Anubis\Application Data\U3
2008-03-12 23:51 ——— d—–w C:\Documents and Settings\Anubis\Application Data\WeatherBug
2008-03-11 06:08 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Azureus
2008-03-10 14:44 16,384 —-a-w C:\WINDOWS\~DFF829.tmp
2008-03-10 00:21 ——— d—–w C:\Program Files\Java
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Vso
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\vlc
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Symantec
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Sonic
2008-03-09 06:20 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Intervideo
2008-03-09 06:20 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Apple Computer
2008-03-07 03:22 ——— d—–w C:\Program Files\Azureus
2008-02-28 22:14 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\Symantec
2008-02-28 05:19 ——— d—–w C:\Program Files\Yahoo!
2008-02-28 05:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-02-28 03:49 ——— d—–w C:\Program Files\Common Files\PAC207
2008-02-27 17:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-27 17:16 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\Yahoo!
2008-02-27 13:07 ——— d—–w C:\Program Files\iTunes
2008-02-27 13:07 ——— d—–w C:\Program Files\iPod
2008-02-27 13:04 ——— d—–w C:\Program Files\QuickTime
2008-02-27 03:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\ATI MMC
2008-02-24 19:02 ——— d—–w C:\Program Files\Symantec
2008-02-24 18:53 ——— d—–w C:\Program Files\Norton 360
2008-02-13 06:31 ——— d—–w C:\Program Files\AIM6
2008-02-13 06:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-13 06:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-02-12 18:47 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-12 16:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-12 04:47 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-12 04:10 ——— d—–w C:\Program Files\YourWare Solutions
2008-02-08 17:03 ——— d—–w C:\Documents and Settings\Anubis\Application Data\LimeWire
2008-01-30 03:55 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\MySpace
2008-01-30 03:55 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\Logitech
2008-01-30 03:55 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\ATI
2008-01-14 02:11 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Yahoo!
2007-12-16 06:13 87,608 —-a-w C:\Documents and Settings\Anubis\Application Data\inst.exe
2007-12-16 06:13 47,360 —-a-w C:\Documents and Settings\Anubis\Application Data\pcouffin.sys
2006-11-12 00:31 1,430,151 –sha-w C:\WINDOWS\Fonts\apun.tmp
2007-02-03 17:52 1,001,091 –sha-w C:\WINDOWS\repair\blips.bak1
2007-02-03 17:51 1,000,836 –sha-w C:\WINDOWS\repair\blips.bak2
2007-02-04 05:03 999,985 –sha-w C:\WINDOWS\repair\blips.ini2
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 17:00 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 12:15 50528]
"ATI Launchpad"="" []
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 18:43 4670704]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 03:33 8720384]
"FreeRAM XP"="C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 01:13 1591808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04 52736]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 23:02 61440]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 11:01 110592]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-22 01:31 180269]
"Home Theater SchSvr"="C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2004-09-23 13:22 106496]
"WINREMOTE"="C:\Program Files\InterVideo\Common\Bin\WinRemote.exe" [2004-10-01 03:18 192512]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 23:43 233472]
"VTTimer"="VTTimer.exe" []
"SoundMan"="SOUNDMAN.EXE" [2004-07-29 03:40 77824 C:\WINDOWS\SOUNDMAN.EXE]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 23:13 98304]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-29 04:34 2551808 C:\WINDOWS\ALCWZRD.EXE]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 00:54 253952]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-10 22:10 339968]
"ATI DeviceDetect"="C:\Program Files\ATI Multimedia\main\ATIDtct.EXE" [2004-06-15 23:17 69705]
"HydraVisionDesktopManager"="C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe" [2003-09-15 22:00 270336]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 19:30 517768]
"LWBKEYBOARD"="C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe" [2004-05-26 22:37 392704]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [ ]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 16:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-07-13 16:01 169264]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41 45056]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 01:59 115816]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 03:33 8720384]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-11-30 14:54:09 692224]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 iteraid;ITERAID_Service_Install;C:\WINDOWS\system32\DRIVERS\iteraid.sys [2004-06-01 14:19]
R2 Maxtor Sync Service;Maxtor Service;"C:\Program Files\Maxtor\Sync\SyncServices.exe" [2007-07-13 16:02]
R3 PAC207;PC Camer@;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-06-12 12:39]
S3 cpqdiag;Compaq Diagnostics;C:\WINDOWS\system32\drivers\cpqdiag.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c1bcc9a4-a4dd-11dc-aeec-0011d825a186}]
\Shell\AutoRun\command - N:\LaunchU3.exe -a

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-27 12:51:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-26 19:04:01 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-12 23:14:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\Ati2evxx.exe
.
**************************************************************************
.
Completion time: 2008-03-12 23:18:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-13 03:18:25
.
2008-02-18 14:53:19 — E O F —
_____________________________
Submit 2 files to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


C:\Documents and Settings\Anubis\Application Data\inst.exe

C:\WINDOWS\Fonts\apun.tmp



Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html





________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File:: 
C:\WINDOWS\system32\ovwkcwvl.ini
C:\WINDOWS\system32\qsbyoyaa.ini
C:\WINDOWS\system32\cdgrymnb.ini
C:\WINDOWS\system32\eijbwxmk.ini
C:\WINDOWS\system32\iaguxmph.ini
C:\WINDOWS\system32\tnpanycr.ini
C:\WINDOWS\system32\wghmnstb.ini
C:\WINDOWS\system32\draopbdk.ini
C:\WINDOWS\system32\clthuuit.ini
C:\WINDOWS\Fonts\apun.tmp
C:\WINDOWS\repair\blips.bak1
C:\WINDOWS\repair\blips.bak2
C:\WINDOWS\repair\blips.ini2


NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.




__________________________________

The following program has been damaged by the infection and needs to be uninstalled and reinstalled if you want to use it.
Usinsing add remove programs uninstall this Program

Yahoo! Tool bar \Search Protection

__________________________________




Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.

  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Registry function to clean anything with this program. Having anything auto clean your regisrty is risky).


_________________________________

Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
        • Scan Options:
          • Scan Archives
          • Scan Mail Bases

          • Click OK & have it scan My Computer
          • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

          Click save report as

          [external image: Posted Image]

        • Click the Save as Text button to save the file to your desktop and post it in your next reply
        • [external image: Posted Image]



          Turn off the real time scanner of any existing antivirus program while performing the online scan



          _________________________
          In your next reply I would like to see:
          • A new HJT log
          • The report from Combo Fix
          • The report from Kaspersky
Thank u for the help so far my computer is starting to work much better now :)

heres the reports u requested

New HJT Log::

Logfile of HijackThis v1.99.1
Scan saved at 9:57:23 PM, on 3/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\svchost.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Anubis\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Add To Compaq Organize… - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

new combo fix log::

ComboFix 08-03-10.1 - Anubis 2008-03-13 18:08:00.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Anubis\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\Fonts\apun.tmp
C:\WINDOWS\repair\blips.bak1
C:\WINDOWS\repair\blips.bak2
C:\WINDOWS\repair\blips.ini2
C:\WINDOWS\system32\cdgrymnb.ini
C:\WINDOWS\system32\clthuuit.ini
C:\WINDOWS\system32\draopbdk.ini
C:\WINDOWS\system32\eijbwxmk.ini
C:\WINDOWS\system32\iaguxmph.ini
C:\WINDOWS\system32\ovwkcwvl.ini
C:\WINDOWS\system32\qsbyoyaa.ini
C:\WINDOWS\system32\tnpanycr.ini
C:\WINDOWS\system32\wghmnstb.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Anubis\Application Data\inst.exe
C:\WINDOWS\Fonts\apun.tmp
C:\WINDOWS\repair\blips.bak1
C:\WINDOWS\repair\blips.bak2
C:\WINDOWS\repair\blips.ini2
C:\WINDOWS\system32\cdgrymnb.ini
C:\WINDOWS\system32\clthuuit.ini
C:\WINDOWS\system32\draopbdk.ini
C:\WINDOWS\system32\eijbwxmk.ini
C:\WINDOWS\system32\iaguxmph.ini
C:\WINDOWS\system32\ovwkcwvl.ini
C:\WINDOWS\system32\qsbyoyaa.ini
C:\WINDOWS\system32\tnpanycr.ini
C:\WINDOWS\system32\wghmnstb.ini
L:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-02-13 to 2008-03-13 )))))))))))))))))))))))))))))))
.

2008-03-12 22:50 . 2008-03-12 22:52 d——– C:\Program Files\Windows Live
2008-03-10 10:44 . 2008-03-10 10:44 16,384 –a—— C:\WINDOWS\~DFF829.tmp
2008-03-07 12:09 . 2008-03-07 12:16 d——– C:\Program Files\CA Yahoo! Anti-Spy
2008-02-28 00:41 . 2008-02-28 00:41 d——– C:\Documents and Settings\Anubis\Application Data\Malwarebytes
2008-02-28 00:40 . 2008-03-09 20:57 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-28 00:40 . 2008-02-28 00:40 d——– C:\Program Files\Common Files\Download Manager
2008-02-28 00:40 . 2008-02-28 00:40 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-28 00:00 . 2004-08-04 00:10 10,880 –a—— C:\WINDOWS\system32\drivers\NdisIP.sys
2008-02-28 00:00 . 2004-08-04 00:10 10,880 –a–c— C:\WINDOWS\system32\dllcache\ndisip.sys
2008-02-28 00:00 . 2004-08-03 23:58 5,504 –a—— C:\WINDOWS\system32\drivers\MSTEE.sys
2008-02-28 00:00 . 2004-08-03 23:58 5,504 –a–c— C:\WINDOWS\system32\dllcache\mstee.sys
2008-02-27 23:57 . 2004-08-04 01:56 90,624 –a—— C:\WINDOWS\system32\kswdmcap.ax
2008-02-27 23:57 . 2004-08-04 01:56 90,624 –a–c— C:\WINDOWS\system32\dllcache\kswdmcap.ax
2008-02-27 23:57 . 2004-08-04 01:56 61,952 –a—— C:\WINDOWS\system32\kstvtune.ax
2008-02-27 23:57 . 2004-08-04 01:56 61,952 –a–c— C:\WINDOWS\system32\dllcache\kstvtune.ax
2008-02-27 23:57 . 2004-08-04 01:56 53,760 –a—— C:\WINDOWS\system32\vfwwdm32.dll
2008-02-27 23:57 . 2004-08-04 01:56 53,760 –a–c— C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-02-27 23:57 . 2004-08-04 01:56 43,008 –a—— C:\WINDOWS\system32\ksxbar.ax
2008-02-27 23:57 . 2004-08-04 01:56 43,008 –a–c— C:\WINDOWS\system32\dllcache\ksxbar.ax
2008-02-27 23:57 . 2004-08-04 01:56 28,672 –a—— C:\WINDOWS\system32\vidcap.ax
2008-02-27 23:57 . 2004-08-04 01:56 28,672 –a–c— C:\WINDOWS\system32\dllcache\vidcap.ax
2008-02-27 23:49 . 2008-02-27 23:49 d——– C:\Program Files\PC Camer@
2008-02-27 23:49 . 2006-11-03 10:59 48,128 –a—— C:\WINDOWS\system32\Remove.exe
2008-02-27 23:49 . 2007-02-12 01:06 408 –a—— C:\WINDOWS\system32\Remover.ini
2008-02-27 13:20 . 2008-02-27 13:20 d—s—- C:\Documents and Settings\Guest.ANUBISZRO\UserData
2008-02-27 09:08 . 2008-03-13 15:07 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-27 09:08 . 2008-02-27 09:08 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-26 23:38 . 2008-02-26 23:38 d——– C:\Documents and Settings\Anubis\Application Data\ATI MMC
2008-02-24 15:14 . 2008-01-12 19:32 23,904 –a—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-02-24 15:14 . 2008-01-15 10:54 10,537 –a—— C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-02-24 15:14 . 2008-01-15 06:28 706 –a—— C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-02-24 15:04 . 2008-02-24 15:04 16 –a—— C:\WINDOWS\system32\coh.cache
2008-02-24 14:46 . 2008-02-24 15:02 123,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-24 14:46 . 2008-02-24 15:02 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-24 14:46 . 2008-02-24 15:02 10,740 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-24 14:46 . 2008-02-24 15:02 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-24 14:35 . 2008-02-24 14:35 d——– C:\WINDOWS\E80F62FF5D3C4A1984099721F2928206.TMP
2008-02-18 23:33 . 2004-08-03 23:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-02-18 23:33 . 2004-08-03 23:58 14,848 –a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-02-16 13:09 . 2008-02-16 13:09 230 –a—— C:\WINDOWS\system32\spupdsvc.inf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-13 22:12 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Azureus
2008-03-13 02:53 ——— d—–w C:\Program Files\MSN Messenger
2008-03-13 02:50 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-13 02:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-13 01:47 ——— d—–w C:\Program Files\Viewpoint
2008-03-13 01:47 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Viewpoint
2008-03-13 01:47 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-13 00:34 ——— d—–w C:\Documents and Settings\Anubis\Application Data\U3
2008-03-12 23:51 ——— d—–w C:\Documents and Settings\Anubis\Application Data\WeatherBug
2008-03-10 14:44 16,384 —-a-w C:\WINDOWS\~DFF829.tmp
2008-03-10 00:21 ——— d—–w C:\Program Files\Java
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Vso
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\vlc
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Symantec
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Sonic
2008-03-09 06:20 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Intervideo
2008-03-09 06:20 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Apple Computer
2008-03-07 03:22 ——— d—–w C:\Program Files\Azureus
2008-02-28 22:14 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\Symantec
2008-02-28 05:19 ——— d—–w C:\Program Files\Yahoo!
2008-02-28 05:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-02-28 03:49 ——— d—–w C:\Program Files\Common Files\PAC207
2008-02-27 17:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-27 17:16 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\Yahoo!
2008-02-27 13:07 ——— d—–w C:\Program Files\iTunes
2008-02-27 13:07 ——— d—–w C:\Program Files\iPod
2008-02-27 13:04 ——— d—–w C:\Program Files\QuickTime
2008-02-27 03:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\ATI MMC
2008-02-24 19:02 ——— d—–w C:\Program Files\Symantec
2008-02-24 18:53 ——— d—–w C:\Program Files\Norton 360
2008-02-13 06:31 ——— d—–w C:\Program Files\AIM6
2008-02-13 06:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-13 06:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-02-12 18:47 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-12 16:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-12 04:47 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-12 04:10 ——— d—–w C:\Program Files\YourWare Solutions
2008-02-09 01:55 68,160 —-a-w C:\WINDOWS\system32\keihglax.dll
2008-02-08 17:03 ——— d—–w C:\Documents and Settings\Anubis\Application Data\LimeWire
2008-02-05 03:12 68,672 —-a-w C:\WINDOWS\system32\fypduxfc.dll
2008-01-30 03:55 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\MySpace
2008-01-30 03:55 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\Logitech
2008-01-30 03:55 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\ATI
2008-01-27 22:16 8,587 —-a-w C:\WINDOWS\system32\hvmoelbd.dll
2008-01-26 22:09 68,160 —-a-w C:\WINDOWS\system32\ncnttkey.dll
2008-01-24 21:47 8,587 —-a-w C:\WINDOWS\system32\tmhvwkif.dll
2008-01-23 21:41 68,672 —-a-w C:\WINDOWS\system32\qrfpulxo.dll
2008-01-20 02:32 69,696 —-a-w C:\WINDOWS\system32\frtvqggc.dll
2008-01-19 02:19 69,696 —-a-w C:\WINDOWS\system32\jjuixibv.dll
2008-01-19 02:16 43,435 —-a-w C:\WINDOWS\system32\ewhicggk.dll
2008-01-16 16:31 8,587 —-a-w C:\WINDOWS\system32\bgcrwdwj.dll
2008-01-14 02:11 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Yahoo!
2008-01-11 03:58 65,215 —-a-w C:\WINDOWS\system32\ilehnjit.dll
2007-12-28 21:40 1,031,259 –sha-w C:\WINDOWS\system32\sskdwgxk.tmp
2007-12-16 06:13 47,360 —-a-w C:\Documents and Settings\Anubis\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((( snapshot@2008-03-12_23.18.09.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-02-14 14:19:45 12,288 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-03-13 15:16:11 12,288 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-02-14 14:19:45 135,168 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-03-13 15:16:11 135,168 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-02-14 14:19:45 11,264 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-03-13 15:16:11 11,264 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-02-14 14:19:45 27,136 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-03-13 15:16:11 27,136 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-02-14 14:19:45 4,096 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-03-13 15:16:11 4,096 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-02-14 14:19:45 794,624 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-03-13 15:16:11 794,624 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-02-14 14:19:45 249,856 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-03-13 15:16:11 249,856 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-02-14 14:19:46 23,040 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-03-13 15:16:11 23,040 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-02-14 14:19:45 286,720 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-03-13 15:16:11 286,720 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-02-14 14:19:45 409,600 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-03-13 15:16:10 409,600 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2008-02-04 23:09:46 18,214,008 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2008-03-05 16:30:54 19,148,408 —-a-w C:\WINDOWS\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 17:00 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 12:15 50528]
"ATI Launchpad"="" []
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 18:43 4670704]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 03:33 8720384]
"FreeRAM XP"="C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 01:13 1591808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04 52736]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 23:02 61440]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 11:01 110592]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-22 01:31 180269]
"Home Theater SchSvr"="C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2004-09-23 13:22 106496]
"WINREMOTE"="C:\Program Files\InterVideo\Common\Bin\WinRemote.exe" [2004-10-01 03:18 192512]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 23:43 233472]
"VTTimer"="VTTimer.exe" []
"SoundMan"="SOUNDMAN.EXE" [2004-07-29 03:40 77824 C:\WINDOWS\SOUNDMAN.EXE]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 23:13 98304]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-29 04:34 2551808 C:\WINDOWS\ALCWZRD.EXE]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 00:54 253952]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-10 22:10 339968]
"ATI DeviceDetect"="C:\Program Files\ATI Multimedia\main\ATIDtct.EXE" [2004-06-15 23:17 69705]
"HydraVisionDesktopManager"="C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe" [2003-09-15 22:00 270336]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 19:30 517768]
"LWBKEYBOARD"="C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe" [2004-05-26 22:37 392704]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [ ]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 16:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-07-13 16:01 169264]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41 45056]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 01:59 115816]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 03:33 8720384]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-11-30 14:54:09 692224]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

R0 iteraid;ITERAID_Service_Install;C:\WINDOWS\system32\DRIVERS\iteraid.sys [2004-06-01 14:19]
R2 Maxtor Sync Service;Maxtor Service;"C:\Program Files\Maxtor\Sync\SyncServices.exe" [2007-07-13 16:02]
R3 PAC207;PC Camer@;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-06-12 12:39]
S3 cpqdiag;Compaq Diagnostics;C:\WINDOWS\system32\drivers\cpqdiag.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c1bcc9a4-a4dd-11dc-aeec-0011d825a186}]
\Shell\AutoRun\command - N:\LaunchU3.exe -a

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-27 12:51:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-26 19:04:01 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-13 18:12:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-13 18:13:34
ComboFix-quarantined-files.txt 2008-03-13 22:13:30
ComboFix2.txt 2008-03-13 03:18:30
.
2008-03-13 15:17:29 — E O F —


Kaspersky report::

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Thursday, March 13, 2008 9:53:41 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 13/03/2008
Kaspersky Anti-Virus database records: 628423
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
L:\

Scan Statistics:
Total number of scanned objects: 133183
Number of viruses found: 14
Number of infected objects: 175
Number of suspicious objects: 0
Duration of the scan process: 02:27:57

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b4e8e379a5fd6f8a3d49cac609cd7c6_de17b053-1a2f-4196-af5d-40229baf0926 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\index.qbs Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\56CB47A6.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\ABB24084.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\acccore\nss\cert8.db Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\acccore\nss\key3.db Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\MySpace\IM\Logs\MySpaceIM-20080313-183926.log Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\MySpace\IM\SkypeCache\myspace#3afallengodres\contactgroup256.dbb Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\MySpace\IM\SkypeCache\myspace#3afallengodres\index2.dat Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\MySpace\IM\SkypeCache\myspace#3afallengodres\profile256.dbb Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\MySpace\IM\SkypeCache\myspace#3afallengodres\user1024.dbb Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\MySpace\IM\SkypeCache\myspace#3afallengodres\user256.dbb Object is locked skipped
C:\Documents and Settings\Anubis\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\AOL OCP\AIM\Storage\data\anubitron\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\AOL OCP\AIM\Storage\data\fallengodres\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\AOL OCP\AIM\Storage\data\purgatoryzro\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\AOL OCP\AIM\Storage\data\tronicx3\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\ApplicationHistory\cli.exe.c88dbd71.ini.inuse Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_4204_A181_4A1_7895\dfsr.db Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_4204_A181_4A1_7895\fsr.log Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_4204_A181_4A1_7895\fsrtmp.log Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_4204_A181_4A1_7895\tmp.edb Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\real\members.stg Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\shadow\members.stg Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Mozilla\Firefox\Profiles\k33kcsh3.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Mozilla\Firefox\Profiles\k33kcsh3.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Mozilla\Firefox\Profiles\k33kcsh3.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Mozilla\Firefox\Profiles\k33kcsh3.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\History\History.IE5\MSHist012008031320080314\index.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\Perflib_Perfdata_8c8.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\Perflib_Perfdata_d2c.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\Perflib_Perfdata_e90.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\Perflib_Perfdata_e98.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\~DF4C11.tmp Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\~DF4C2C.tmp Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\~DF694C.tmp Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\~DF6985.tmp Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\~DFE6D3.tmp Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Anubis\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Anubis\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\97TFVK94\index[1].htm Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAD.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWADMT.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.ldb Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\InstallShield Installation Information\{639858DD-4966-40F3-A706-7C838BCF3A2B}\setup.ilg Object is locked skipped
C:\Program Files\Norton 360\Log\AutoProtect.log Object is locked skipped
C:\Program Files\Norton 360\Log\AVContext.log Object is locked skipped
C:\Program Files\Norton 360\Log\AVManual.log Object is locked skipped
C:\Program Files\Norton 360\Log\Backup.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetPageViewHistory.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetSearchHistory.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetTempFiles.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUWindowsTempFiles.log Object is locked skipped
C:\Program Files\Norton 360\Log\EmailScan.log Object is locked skipped
C:\Program Files\Norton 360\Log\InternetSecurity.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISIntrusionPrevented.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISIOTraffic.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISNewNetwork.log Object is locked skipped
C:\Program Files\Norton 360\Log\LiveUpdate.log Object is locked skipped
C:\Program Files\Norton 360\Log\NCO.log Object is locked skipped
C:\Program Files\Norton 360\Log\VABrowserSettings.log Object is locked skipped
C:\Program Files\Norton 360\Log\VAIPAddresses.log Object is locked skipped
C:\Program Files\Norton 360\Log\VAWeakPasswords.log Object is locked skipped
C:\Program Files\Norton 360\Log\WDFScanner.log Object is locked skipped
C:\Program Files\pspvideo9\settings.xml Object is locked skipped
C:\Program Files\VideoraiPodConverter\settings.xml Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\20060419005503.zip Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\.NetworkShare\LimeWirePackedJars4.10.0.7z Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\.NetworkShare\LimeWireWin4.10.0.exe Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\clink.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\commons-httpclient.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\commons-logging.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\commons-net.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\COPYING Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\daap.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\data.ser Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\donotremove.htm Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\GenericWindowsUtils.dll Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\hashes Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\i18n.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\icu4j.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\id3v2.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\install.log Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\jcraft.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\jl011.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\jmdns.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\language.prop Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\LimeWire On Startup.lnk Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\LimeWire.exe Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\LimeWire.ico Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\LimeWire.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\LimeWire20.dll Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\log.txt Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\log4j.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\log4j.properties Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\logicrypto.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\looks.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\MessagesBundle.properties Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\MessagesBundles.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\mp3sp14.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\pmf.ico Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\ProgressTabs.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\root\magnet10\badge.img Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\root\magnet10\canHandle.img Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\root\magnet10\limewire.gif Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\root\magnet10\options.js Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\root\magnet10\silentdetect.js Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\SOURCE Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\spacer.gif Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\themes.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\tritonus.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\uninstall.exe Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\unpack.log Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\update.ver Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\vorbis.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\WindowsV5PlusUtils.dll Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\xerces.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\xml-apis.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\xml.war Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq53.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq55.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq57.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq58.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq59.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5A.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5B.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5C.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5D.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5E.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5F.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq60.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq61.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq62.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq63.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq64.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq65.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq66.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq67.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq68.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq69.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6A.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6B.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6C.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6D.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6E.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6F.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq70.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq71.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq72.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq73.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq74.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq75.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq76.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq77.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq78.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq79.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7A.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7B.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7C.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7D.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7E.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7F.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq80.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq81.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq82.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq83.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq84.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq85.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq86.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq87.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq88.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq89.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8A.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8B.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8C.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8D.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8E.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8F.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq90.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq91.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq92.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq93.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq94.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq95.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq96.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq97.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq98.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq99.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9A.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9B.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9C.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9D.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9E.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9F.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA0.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA1.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA2.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA3.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA4.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA5.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA6.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA7.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA8.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA9.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqAA.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqAB.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqdb.dat Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqsdb.dat Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\aabalpwd.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\awxqigpo.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\cimmfwfi.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\dmcgkrlt.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\fexgtiik.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\geuvpbky.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\gwevrvnr.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ikutnvvf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ipjoitxm.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\iwsdvijd.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\kvfivynu.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\lxpulnmo.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mchynumc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mcrshphp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mfkneixp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\npsovohs.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\olgbfjph.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\otvhdgcc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\qhmjbtyq.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\rotukqse.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\sdxojgfj.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\serlaiqb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ixf skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\tbxmgdob.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\tnvlnqwn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\tsypfqma.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\tyujbpfb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\uylkiban.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\vmbsqqqw.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\wfbdbydp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\wjitgumn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ydjkprhx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\yvdqxjwf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc1.mp3 Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc10.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc11.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc12.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc13.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc14.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc15.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc16.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc17.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc18.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc19.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc2.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc20.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc21.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc22.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc23.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc24.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc25.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc26.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc27.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc28.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc29.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc3.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc30.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc31.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc32.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc33.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc34.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc35.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc36.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc37.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc38.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc39.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\001.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\002.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\003.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\004.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\005.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\006.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\007.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\008.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\009.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\010.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\011.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\012.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\013.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\014.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\015.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\016.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\Thumbs.db Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc40.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc41.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc42.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc43.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc44.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc45.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc46.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\13825097_22509.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\2-2125134-5j.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\44928432_41487.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\45831737_39423.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\47579723_50591.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\50931872_95152.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\piclist Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\2-2125134-2j.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\001.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\004.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\008.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\009.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\011.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\button_search_now_150_english.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\header.css Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\logo_195x40.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\counter.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\head.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\help.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\logo.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\main.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\spacer.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\spacer_002.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\spacer_003.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\style.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\trans.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\__utm.js Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc48.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc49.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Happy Birthday Mangahelpers!.png Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Kylara is in need!.png Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_01.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_02.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_03.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_04.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_05.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_06.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_07.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_08.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_09.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_10.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_11.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_12.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_13.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_14.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_15.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_16.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_17.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Thumbs.db Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc50.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc51.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc52.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc53.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc54.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc55.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc6.exe Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc7.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc8.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc9.rar Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP49\A0019637.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP49\A0019679.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP49\A0019681.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP50\A0019709.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020294.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020296.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020297.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020300.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020301.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020302.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020303.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020304.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.is skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020305.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020306.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020307.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020308.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020312.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP56\A0020542.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP58\A0020724.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP58\A0020925.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP58\A0021972.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP59\A0022041.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP59\A0022076.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP59\A0022204.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP60\A0022348.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.eby skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP60\A0022401.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP61\A0022521.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP62\A0022585.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.edw skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP63\A0022646.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP63\A0022701.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP63\A0022747.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP63\A0022749.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP64\A0022776.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP64\A0022777.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP64\A0022826.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022844.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022871.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.byl skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022873.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022874.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022875.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022876.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022877.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022878.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0023848.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.byl skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0023853.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.byl skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP66\A0023904.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP67\A0024988.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP67\A0025015.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP67\A0025016.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP67\A0025017.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP67\A0025019.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP67\A0025102.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP68\A0025175.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP68\A0025178.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP68\A0025185.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP68\A0025259.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP69\A0025367.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP70\A0025502.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026585.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026586.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026587.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026588.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026589.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026590.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026595.DLL Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026596.EXE Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026597.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ao skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027556.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027598.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027599.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027600.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027601.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027602.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027603.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027604.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027664.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027664.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027667.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027668.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP73\A0028152.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP73\A0028170.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP73\A0028173.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP74\A0028437.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP75\A0028670.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP76\A0029726.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP76\A0029727.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP76\A0029759.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP77\A0029812.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP78\A0029881.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP79\A0029943.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ixe skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP79\A0030544.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.bce skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP81\A0030595.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP81\A0030632.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP82\A0031032.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP85\A0032414.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP94\A0032952.exe Infected: not-a-virus:Downloader.Win32.Keylogger.a skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP94\A0032980.EXE/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP94\A0032980.EXE WiseSFX: infected - 1 skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP94\A0032980.EXE WiseSFXDropper: infected - 1 skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033074.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033075.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033076.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033077.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033078.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033079.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033080.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033081.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033082.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033083.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033084.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033085.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033086.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033087.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033088.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033089.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033090.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033091.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033092.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033093.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033094.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033095.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ixf skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033096.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033097.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033098.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033099.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033100.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033101.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033102.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033103.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033104.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033105.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP99\change.log Object is locked skipped
C:\USERDATA\Application Data\Symantec\Cleanup\cuUser.cfg Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{9850296E-CA74-4AC1-B6C4-BFC5C97BA9C8}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\bgcrwdwj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\ewhicggk.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\frtvqggc.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\fypduxfc.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\hvmoelbd.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.kp skipped
C:\WINDOWS\system32\ilehnjit.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\jjuixibv.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\keihglax.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\ncnttkey.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\qrfpulxo.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\tmhvwkif.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\cc1A.tmp Object is locked skipped
C:\WINDOWS\TEMP\cc1B.tmp Object is locked skipped
C:\WINDOWS\TEMP\cc1C.tmp Object is locked skipped
C:\WINDOWS\TEMP\cc1D.tmp Object is locked skipped
C:\WINDOWS\TEMP\cc1E.tmp Object is locked skipped
C:\WINDOWS\TEMP\cc1F.tmp Object is locked skipped
C:\WINDOWS\TEMP\cc20.tmp Object is locked skipped
C:\WINDOWS\TEMP\JET713F.tmp Object is locked skipped
C:\WINDOWS\TEMP\JET721A.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP99\change.log Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP99\change.log Object is locked skipped
L:\0\0\Lost Files\Recovered_JPEG_327.jpg Infected: Trojan-Downloader.Win32.Agent.gwe skipped
L:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
L:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP99\change.log Object is locked skipped

Scan process completed.


scan reults for the 2 files::

C:\Documents and Settings\Anubis\Application Data\inst.exe

Scanner results
Scan taken on 13 Mar 2008 21:42:58 (GMT)
A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing


C:\WINDOWS\Fonts\apun.tmp

Scanner results
Scan taken on 13 Mar 2008 21:56:28 (GMT)
A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing
Just run this one last time for me and assure me everything is still OK.

________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File:: 
C:\WINDOWS\system32\keihglax.dll
C:\WINDOWS\system32\fypduxfc.dll
C:\WINDOWS\system32\hvmoelbd.dll
C:\WINDOWS\system32\ncnttkey.dll
C:\WINDOWS\system32\tmhvwkif.dll
C:\WINDOWS\system32\qrfpulxo.dll
C:\WINDOWS\system32\frtvqggc.dll
C:\WINDOWS\system32\jjuixibv.dll
C:\WINDOWS\system32\ewhicggk.dll
C:\WINDOWS\system32\bgcrwdwj.dll
C:\WINDOWS\system32\ilehnjit.dll
C:\WINDOWS\system32\sskdwgxk.tmp
L:\0\0\Lost Files\Recovered_JPEG_327.jpg


NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.



_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
Yes thank u again everything working ok now and u got rid of the last bit of adware that was bugging me :)


HJT Log::

Logfile of HijackThis v1.99.1
Scan saved at 10:42:17 AM, on 3/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Anubis\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Add To Compaq Organize… - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)




ComboFix Report::

ComboFix 08-03-10.1 - Anubis 2008-03-14 10:33:17.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1041 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Anubis\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\system32\bgcrwdwj.dll
C:\WINDOWS\system32\ewhicggk.dll
C:\WINDOWS\system32\frtvqggc.dll
C:\WINDOWS\system32\fypduxfc.dll
C:\WINDOWS\system32\hvmoelbd.dll
C:\WINDOWS\system32\ilehnjit.dll
C:\WINDOWS\system32\jjuixibv.dll
C:\WINDOWS\system32\keihglax.dll
C:\WINDOWS\system32\ncnttkey.dll
C:\WINDOWS\system32\qrfpulxo.dll
C:\WINDOWS\system32\sskdwgxk.tmp
C:\WINDOWS\system32\tmhvwkif.dll
L:\0\0\Lost Files\Recovered_JPEG_327.jpg
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\bgcrwdwj.dll
C:\WINDOWS\system32\ewhicggk.dll
C:\WINDOWS\system32\frtvqggc.dll
C:\WINDOWS\system32\fypduxfc.dll
C:\WINDOWS\system32\hvmoelbd.dll
C:\WINDOWS\system32\ilehnjit.dll
C:\WINDOWS\system32\jjuixibv.dll
C:\WINDOWS\system32\keihglax.dll
C:\WINDOWS\system32\ncnttkey.dll
C:\WINDOWS\system32\qrfpulxo.dll
C:\WINDOWS\system32\sskdwgxk.tmp
C:\WINDOWS\system32\tmhvwkif.dll
L:\0\0\Lost Files\Recovered_JPEG_327.jpg
L:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-02-14 to 2008-03-14 )))))))))))))))))))))))))))))))
.

2008-03-13 18:59 . 2008-03-13 18:59 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-03-13 18:59 . 2008-03-13 18:59 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-13 18:45 . 2008-03-13 18:45 d——– C:\Program Files\CCleaner
2008-03-12 22:50 . 2008-03-12 22:52 d——– C:\Program Files\Windows Live
2008-03-10 10:44 . 2008-03-10 10:44 16,384 –a—— C:\WINDOWS\~DFF829.tmp
2008-02-28 00:41 . 2008-02-28 00:41 d——– C:\Documents and Settings\Anubis\Application Data\Malwarebytes
2008-02-28 00:40 . 2008-03-09 20:57 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-28 00:40 . 2008-02-28 00:40 d——– C:\Program Files\Common Files\Download Manager
2008-02-28 00:40 . 2008-02-28 00:40 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-28 00:00 . 2004-08-04 00:10 10,880 –a—— C:\WINDOWS\system32\drivers\NdisIP.sys
2008-02-28 00:00 . 2004-08-04 00:10 10,880 –a–c— C:\WINDOWS\system32\dllcache\ndisip.sys
2008-02-28 00:00 . 2004-08-03 23:58 5,504 –a—— C:\WINDOWS\system32\drivers\MSTEE.sys
2008-02-28 00:00 . 2004-08-03 23:58 5,504 –a–c— C:\WINDOWS\system32\dllcache\mstee.sys
2008-02-27 23:57 . 2004-08-04 01:56 90,624 –a—— C:\WINDOWS\system32\kswdmcap.ax
2008-02-27 23:57 . 2004-08-04 01:56 90,624 –a–c— C:\WINDOWS\system32\dllcache\kswdmcap.ax
2008-02-27 23:57 . 2004-08-04 01:56 61,952 –a—— C:\WINDOWS\system32\kstvtune.ax
2008-02-27 23:57 . 2004-08-04 01:56 61,952 –a–c— C:\WINDOWS\system32\dllcache\kstvtune.ax
2008-02-27 23:57 . 2004-08-04 01:56 53,760 –a—— C:\WINDOWS\system32\vfwwdm32.dll
2008-02-27 23:57 . 2004-08-04 01:56 53,760 –a–c— C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-02-27 23:57 . 2004-08-04 01:56 43,008 –a—— C:\WINDOWS\system32\ksxbar.ax
2008-02-27 23:57 . 2004-08-04 01:56 43,008 –a–c— C:\WINDOWS\system32\dllcache\ksxbar.ax
2008-02-27 23:57 . 2004-08-04 01:56 28,672 –a—— C:\WINDOWS\system32\vidcap.ax
2008-02-27 23:57 . 2004-08-04 01:56 28,672 –a–c— C:\WINDOWS\system32\dllcache\vidcap.ax
2008-02-27 23:49 . 2008-02-27 23:49 d——– C:\Program Files\PC Camer@
2008-02-27 23:49 . 2006-11-03 10:59 48,128 –a—— C:\WINDOWS\system32\Remove.exe
2008-02-27 23:49 . 2007-02-12 01:06 408 –a—— C:\WINDOWS\system32\Remover.ini
2008-02-27 13:20 . 2008-02-27 13:20 d—s—- C:\Documents and Settings\Guest.ANUBISZRO\UserData
2008-02-27 09:08 . 2008-03-14 10:19 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-27 09:08 . 2008-02-27 09:08 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-26 23:38 . 2008-02-26 23:38 d——– C:\Documents and Settings\Anubis\Application Data\ATI MMC
2008-02-24 15:14 . 2008-01-12 19:32 23,904 –a—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-02-24 15:14 . 2008-01-15 10:54 10,537 –a—— C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-02-24 15:14 . 2008-01-15 06:28 706 –a—— C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-02-24 15:04 . 2008-02-24 15:04 16 –a—— C:\WINDOWS\system32\coh.cache
2008-02-24 14:46 . 2008-02-24 15:02 123,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-24 14:46 . 2008-02-24 15:02 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-24 14:46 . 2008-02-24 15:02 10,740 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-24 14:46 . 2008-02-24 15:02 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-24 14:35 . 2008-02-24 14:35 d——– C:\WINDOWS\E80F62FF5D3C4A1984099721F2928206.TMP
2008-02-18 23:33 . 2004-08-03 23:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-02-18 23:33 . 2004-08-03 23:58 14,848 –a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-02-16 13:09 . 2008-02-16 13:09 230 –a—— C:\WINDOWS\system32\spupdsvc.inf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-14 04:05 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Azureus
2008-03-13 22:34 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Yahoo!
2008-03-13 22:34 ——— d—–w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-03-13 22:28 ——— d—–w C:\Program Files\Yahoo!
2008-03-13 22:28 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-13 02:53 ——— d—–w C:\Program Files\MSN Messenger
2008-03-13 02:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-13 01:47 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Viewpoint
2008-03-13 01:47 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-13 00:34 ——— d—–w C:\Documents and Settings\Anubis\Application Data\U3
2008-03-12 23:51 ——— d—–w C:\Documents and Settings\Anubis\Application Data\WeatherBug
2008-03-10 14:44 16,384 —-a-w C:\WINDOWS\~DFF829.tmp
2008-03-10 00:21 ——— d—–w C:\Program Files\Java
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Vso
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\vlc
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Symantec
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Sonic
2008-03-09 06:20 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Intervideo
2008-03-09 06:20 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Apple Computer
2008-03-07 03:22 ——— d—–w C:\Program Files\Azureus
2008-02-28 22:14 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\Symantec
2008-02-28 03:49 ——— d—–w C:\Program Files\Common Files\PAC207
2008-02-27 17:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-27 17:16 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\Yahoo!
2008-02-27 13:07 ——— d—–w C:\Program Files\iTunes
2008-02-27 13:07 ——— d—–w C:\Program Files\iPod
2008-02-27 13:04 ——— d—–w C:\Program Files\QuickTime
2008-02-27 03:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\ATI MMC
2008-02-24 19:02 ——— d—–w C:\Program Files\Symantec
2008-02-24 18:53 ——— d—–w C:\Program Files\Norton 360
2008-02-13 06:31 ——— d—–w C:\Program Files\AIM6
2008-02-13 06:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-13 06:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-02-12 18:47 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-12 16:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-12 04:47 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-12 04:10 ——— d—–w C:\Program Files\YourWare Solutions
2008-02-08 17:03 ——— d—–w C:\Documents and Settings\Anubis\Application Data\LimeWire
2008-01-30 03:55 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\MySpace
2008-01-30 03:55 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\Logitech
2008-01-30 03:55 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\ATI
2007-12-16 06:13 47,360 —-a-w C:\Documents and Settings\Anubis\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((( snapshot@2008-03-12_23.18.09.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-02-14 14:19:45 12,288 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-03-13 15:16:11 12,288 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-02-14 14:19:45 135,168 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-03-13 15:16:11 135,168 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-02-14 14:19:45 11,264 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-03-13 15:16:11 11,264 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-02-14 14:19:45 27,136 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-03-13 15:16:11 27,136 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-02-14 14:19:45 4,096 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-03-13 15:16:11 4,096 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-02-14 14:19:45 794,624 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-03-13 15:16:11 794,624 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-02-14 14:19:45 249,856 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-03-13 15:16:11 249,856 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-02-14 14:19:46 23,040 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-03-13 15:16:11 23,040 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-02-14 14:19:45 286,720 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-03-13 15:16:11 286,720 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-02-14 14:19:45 409,600 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-03-13 15:16:10 409,600 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2005-05-24 16:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-02-04 23:09:46 18,214,008 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2008-03-05 16:30:54 19,148,408 —-a-w C:\WINDOWS\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 17:00 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 12:15 50528]
"ATI Launchpad"="" []
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 18:43 4670704]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 03:33 8720384]
"FreeRAM XP"="C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 01:13 1591808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04 52736]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 23:02 61440]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 11:01 110592]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-22 01:31 180269]
"Home Theater SchSvr"="C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2004-09-23 13:22 106496]
"WINREMOTE"="C:\Program Files\InterVideo\Common\Bin\WinRemote.exe" [2004-10-01 03:18 192512]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 23:43 233472]
"VTTimer"="VTTimer.exe" []
"SoundMan"="SOUNDMAN.EXE" [2004-07-29 03:40 77824 C:\WINDOWS\SOUNDMAN.EXE]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 23:13 98304]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-29 04:34 2551808 C:\WINDOWS\ALCWZRD.EXE]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 00:54 253952]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-10 22:10 339968]
"ATI DeviceDetect"="C:\Program Files\ATI Multimedia\main\ATIDtct.EXE" [2004-06-15 23:17 69705]
"HydraVisionDesktopManager"="C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe" [2003-09-15 22:00 270336]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 19:30 517768]
"LWBKEYBOARD"="C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe" [2004-05-26 22:37 392704]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 16:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-07-13 16:01 169264]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41 45056]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 01:59 115816]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 03:33 8720384]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-11-30 14:54:09 692224]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

R0 iteraid;ITERAID_Service_Install;C:\WINDOWS\system32\DRIVERS\iteraid.sys [2004-06-01 14:19]
R2 Maxtor Sync Service;Maxtor Service;"C:\Program Files\Maxtor\Sync\SyncServices.exe" [2007-07-13 16:02]
R3 PAC207;PC Camer@;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-06-12 12:39]
S3 cpqdiag;Compaq Diagnostics;C:\WINDOWS\system32\drivers\cpqdiag.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c1bcc9a4-a4dd-11dc-aeec-0011d825a186}]
\Shell\AutoRun\command - N:\LaunchU3.exe -a

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-27 12:51:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-26 19:04:01 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-14 10:36:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-14 10:37:12
ComboFix-quarantined-files.txt 2008-03-14 14:37:03
ComboFix2.txt 2008-03-13 22:20:59
ComboFix3.txt 2008-03-13 03:18:30
.
2008-03-13 15:17:29 — E O F —
Great news ! [external image: Posted Image]

Your log now appears to be clean.

Lets do a few things to tidy up.
Please do these in the order I suggest!


Go to start > run and copy and paste this in the field:

ComboFix /u

Make sure there's a space between Combofix and /
Then hit enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the
system/hidden files and resets System Restore again.

______________________________


A few things to help with possible threats

These are optional . But will help protect you further.
___________________________________

SpywareBlaster

Install SpywareBlaster

SpywareBlaster will add a large list of programs and sites to your Internet Explorer settings that will protect you from accidentally running or downloading known malicious programs.
After the installation, click Download Latest Protection Updates. When it finishes, click Enable All Protection.


______________________________
SiteHound

http://www.firetrust.com/firetrustsitehound.html

This tool bar will help protect you from.

Over 4,000 fake bank and credit sites.
Tens of thousands of pornographic
and adult sites.
The never ending fake phishing sites.
Malicious sites, which can infect you
with spyware and adware if you visit
them.
Sites to download software which
may infect your computer with
spyware, a virus or adware


___________________________________
Download and Install a HOSTS File
A Hosts file is a plain text file which prevents your computer from connecting to malware and spyware sites by redirecting the connection request to 127.0.0.1, which is your local address. If you use a proxy server, or if you are on AOL, be sure to read the special instructions.
You can download the MVPS Hosts File and see a HOSTS file tutorial here :
This website also contains useful tips, and links to other resources and utilities.


___________________________________
Make your Internet Explorer more secure
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click on the Security tab
3. Click the Internet icon so it becomes highlighted.
4. Click on Default Level and click Ok
5. Click on the Custom Level button.

Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.

6. Next press the Apply button and then the OK to exit the Internet Properties page.


Here's a site with great advise on how to AVOID malware. Much easier to do than removing it.





Safe and Happy Surfing. :)
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI