This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Better to be safe than sorry

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First off, allow me to thank you all in advance for the help. The issue at hand is about 2 weeks ago my final fantasy character was logged in from elsewhere, the account password was changed, and before I recover it I would like to make sure my computer is clean. I have run a battery of virus/malware scanners, updated poor IE to firefox with noscript + adlock, installed comodo firewall and like to think that I am now secure. However, as I mentioned before I would like to *know* my computer is currently clean of malware before once again logging into my "fixed" account. I know some issues have come across your boards that dealt with smart.dll and the loss of accounts this way. At no point have I had smart.dll on my pc, so obviously I have also not cleared it off already. What is bothering me the most is somehow almost every morning when avast scans it finds a rootkit in C:\Users\Greg\AppData\Local\Temp so today I attempted to clear the entire Temp folder. As requested by your stickies I rebooted my PC with only 1 anti-virus (avast) and 1 firewall running (comodo), the only thing I opened before running hijackthis for a log was POL (final fantasy) incase there is malware that is only active once that exe is run. If you would like me to re-run hijackthis and repost without POL.exe open I will be glad to. My windows updates and flash are completely updated. Here are my hijackthis results:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:07:07 PM, on 5/28/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-21-2558772488-3530516235-307242920-1000\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl (User '?')
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O13 - Gopher Prefix:
O15 - Trusted Zone: http://asia.msi.com.tw
O15 - Trusted Zone: http://global.msi.com.tw
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\Windows\system32\guard32.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

–
End of file - 6745 bytes
Hi Greg911,

Is Avast still finding a rootkit as you mentioned? If so, please post details from the Avast log or event history with the file and path of the detection (e.g. C:\Users\Greg\AppData\Local\Temp\rootkit.exe)

I know you have already run a lot of scans, but I have to ask you to run a few more so you can be as safe as possible. I would however point out that it's not possible for us to give you a 100% guarantee that the machine is clean, if a guarantee is what you require then a reformat is the only way to do this.

Download Dr.WEB CureIt to your desktop from here:
ftp://ftp.drweb.com/pub/drweb/cureit/cureit.exe
  • Right-click cureit.exe and choose Run as administrator to start the program.
  • Press Start and then OK to start the Express scan
  • The Express scan takes just a few moments to finish, if something is found, click Yes to cure it
  • Once the short scan has finished, Click Options->Change settings
  • Choose the Scan tab and UN-CHECK Heuristic analysis
  • Choose the Actions tab and make these changes:
    • Next to Infected objects select Report
    • Next to Incurable objects select Report
    • Next to Infected containers select Report
  • At the bottom-left, UN-CHECK Prompt on action, then press OK to close the settings box.
  • Note: These settings changes are IMPORTANT, please ensure you have made them before scanning
  • Then select Complete scan and press the green arrow to start the scan
  • When the scan is complete, click File-> Save report list, save the report to your desktop and close Dr Web CureIt


Next, please download F-Secure Blacklight to your Desktop (right-click the link, select Save Target As…, select your Desktop and press Save)
  • Double click fsbl.exe to run it, choose I accept the agreement then press Scan
  • It will create the fsbl-xxxxxxx.log on your desktop containing a list of all items found.
  • Do not choose to rename any because legitimate items can also be present.
  • Exit Blacklight and post the contents of the log in your next reply.

Download Deckard's System Scanner (DSS) to your Desktop (right-click the link, select Save Target As…, select your Desktop and press Save)
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Make sure Format->Word Wrap is unchecked
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your reply

Once complete, please post the Dr Web report, the Blacklight report and both DSS logs, you won't need to produce a new HijackThis log as DSS produces one for you.
Silver,

Thanks for your reply, I do realize theres no way to 100% say I'm safe or clean, I'm just doing my best to be 99% sure. As for the rootkit nothing has been found in over a week, I am wondering if maybe when I updated my Flash player that issue was resolved. When something was found previously it was located here:
TrojWare.Java.ClassLoader.B(ID = 0x33eb2) D:\Documents and Settings\Greg\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-393d648-7de7a6e3.class However, as I mentioned nothing has been found in the past 5-7 days. In the DSS reports, I disabled my firewall/anti-virus as recommended.

Dr. Web
Dr web found nothing and therefore I was unable to save a log, to verify this I took a SS of nothing being found and showing that the save report is is not available
[external image: Posted Image]

F-Secure Backlight
06/08/08 18:49:21 [Info]: BlackLight Engine 1.0.70 initialized
06/08/08 18:49:21 [Info]: OS: 6.0 build 6000 ()
06/08/08 18:49:21 [Note]: 7019 4
06/08/08 18:49:21 [Note]: 7005 0
06/08/08 18:49:39 [Note]: 7006 0
06/08/08 18:49:39 [Note]: 7027 0
06/08/08 18:49:40 [Note]: 7035 0
06/08/08 18:49:40 [Note]: 7026 0
06/08/08 18:49:40 [Note]: 7026 0
06/08/08 18:49:46 [Note]: FSRAW library version 1.7.1024
06/08/08 18:55:30 [Note]: 7007 0

DSS
Main:
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-06-08 18:57:53
Computer is in Normal Mode.
——————————————————————————–

Backed up registry hives.
Performed disk cleanup.



– HijackThis (run as Greg.exe) ————————————————

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:00:12 PM, on 6/8/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Greg\Desktop\dss.exe
C:\Windows\system32\SearchFilterHost.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Greg.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-21-2558772488-3530516235-307242920-1000\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl (User '?')
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O13 - Gopher Prefix:
O15 - Trusted Zone: http://asia.msi.com.tw
O15 - Trusted Zone: http://global.msi.com.tw
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,C:\Windows\system32\guard32.dll,avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

–
End of file - 7135 bytes

– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

All drivers whitelisted.


– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ——————–

All services whitelisted.


– Device Manager: Disabled —————————————————-

No disabled devices found.


– Files created between 2008-05-08 and 2008-06-08 —————————–

2008-06-08 12:29:13 0 d——– C:\Users\Greg\DoctorWeb
2008-05-31 14:38:11 0 d–h—– C:\$AVG8.VAULT$
2008-05-31 12:47:15 0 d——– C:\Windows\system32\drivers\Avg
2008-05-31 12:46:47 0 d——– C:\Program Files\AVG
2008-05-31 12:46:46 0 d——– C:\Users\All Users\avg8
2008-05-28 23:15:47 0 d——– C:\Users\All Users\TEMP
2008-05-28 23:15:32 0 d——– C:\Program Files\SpywareBlaster
2008-05-28 18:41:29 0 d——– C:\Program Files\Trend Micro
2008-05-20 21:26:25 0 d——– C:\Users\All Users\comodo
2008-05-20 21:26:22 0 d——– C:\Program Files\COMODO
2008-05-20 21:18:38 0 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-05-20 21:12:51 1160 –a—— C:\Windows\mozver.dat
2008-05-20 10:51:07 0 –a—— C:\Windows\nsreg.dat
2008-05-19 23:45:50 0 d——– C:\Program Files\Alwil Software
2008-05-13 09:41:13 0 d——– C:\Program Files\Opera


– Find3M Report —————————————————————

2008-05-30 19:49:48 0 d——– C:\Users\Greg\AppData\Roaming\LimeWire
2008-05-20 21:26:26 0 d——– C:\Users\Greg\AppData\Roaming\Comodo
2008-05-20 10:51:04 0 d——– C:\Users\Greg\AppData\Roaming\Mozilla
2008-05-19 23:40:51 0 d——– C:\Program Files\Windows Mail
2008-05-19 23:40:48 0 d——– C:\Program Files\Microsoft Silverlight
2008-05-13 09:47:05 0 d——– C:\Program Files\PlayOnline
2008-05-13 09:41:36 0 d——– C:\Users\Greg\AppData\Roaming\Opera
2008-05-11 15:50:54 0 d——– C:\Users\Greg\AppData\Roaming\BitTorrent
2008-05-05 19:46:22 0 d——– C:\Users\Greg\AppData\Roaming\Winamp
2008-05-02 18:06:36 0 d——– C:\Program Files\Realtek AC97
2008-04-28 09:59:59 0 d——– C:\Program Files\Xvid
2008-04-22 18:01:51 0 d——– C:\Program Files\BitTorrent
2008-04-21 14:22:19 0 d——– C:\Program Files\Paint.NET
2008-04-18 13:00:58 0 d——– C:\Program Files\Common Files
2008-04-18 13:00:58 0 d——– C:\Program Files\Common Files\Logitech
2008-04-18 13:00:57 0 d——– C:\Program Files\Logitech
2008-03-20 12:27:37 0 –a—— C:\Windows\ativpsrm.bin
2008-03-18 21:45:19 4096 –a—— C:\Windows\d3dx.dat
2008-03-13 08:27:04 174 –ahs—- C:\Program Files\desktop.ini


– Registry Dump —————————————————————

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [03/13/2008 08:10 AM]
"SoundMan"="SOUNDMAN.EXE" [03/09/2007 04:28 PM C:\Windows\SOUNDMAN.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [03/18/2008 06:45 PM]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [11/10/2006 12:35 PM]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [01/15/2008 06:54 PM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [01/31/2008 11:13 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/19/2008 01:10 PM]
"@"="" []
"Launch LGDCore"="C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" [04/26/2007 05:22 PM]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [05/15/2008 07:19 PM]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [06/03/2008 09:16 PM]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [05/31/2008 12:47 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\Program Files\AIM\aim.exe" [08/01/2006 03:35 PM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [03/20/2008 05:45 PM]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [10/18/2007 11:34 AM]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [3/20/2008 5:45:41 PM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 1:01:04 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"EnableLUA"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,C:\Windows\system32\guard32.dll,avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



– Hosts ———————————————————————–

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

8382 more entries in hosts file.


– End of Deckard's System Scanner: finished at 2008-06-08 19:03:26 ————


Extra:
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
——————————————————————————–

– System Information ———————————————————-

Architecture: X86; Language: English

Percentage of Memory in Use: 42%
Physical Memory (total/avail): 2046.81 MiB / 1175.37 MiB
Pagefile Memory (total/avail): 4313.21 MiB / 3378.44 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1930.93 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 298.09 GiB total, 212.45 GiB free.
D: is Fixed (NTFS) - 227.87 GiB total, 142.5 GiB free.
E: is CDROM (No Media)



– Security Center ————————————————————-

AUOptions is set to notify before download.
Windows Internal Firewall is enabled.

FW: COMODO Firewall Pro v3.0 (COMODO)
AV: AVG Anti-Virus Free v8.0 (AVG Technologies) Outdated
AV: avast! antivirus 4.8.1201 [VPS 080608-0] v4.8.1201 (ALWIL Software) Disabled
AS: AVG Anti-Virus Free v8.0 (AVG Technologies) Disabled Outdated
AS: Windows Defender v1.1.1505.0 (Microsoft Corporation)
AS: avast! antivirus 4.8.1201 [VPS 080608-0] v4.8.1201 (ALWIL Software) Disabled

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"


– Environment Variables ——————————————————-

ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\Greg\AppData\Roaming
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=GREG-PC
ComSpec=C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\Greg
LOCALAPPDATA=C:\Users\Greg\AppData\Local
LOGONSERVER=\\GREG-PC
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 75 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=4b02
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
PROMPT=$P$G
PUBLIC=C:\Users\Public
QTJAVA=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\Greg\AppData\Local\Temp
TMP=C:\Users\Greg\AppData\Local\Temp
USERDOMAIN=Greg-PC
USERNAME=Greg
USERPROFILE=C:\Users\Greg
windir=C:\Windows


– User Profiles —————————————————————

Greg (admin)


– Add/Remove Programs ———————————————————

Adobe Flash Player ActiveX –> C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin –> C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
AOL Instant Messenger –> C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=
Apple Mobile Device Support –> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update –> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
ATI AVIVO Codecs –> MsiExec.exe /I{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}
avast! Antivirus –> C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
AVG Free 8.0 –> C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
BitTorrent –> C:\Program Files\BitTorrent\uninst.exe
Bonjour –> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
COMODO Firewall Pro –> C:\Program Files\COMODO\Firewall\cfpconfg.exe -u
FINAL FANTASY XI –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{678F6475-D227-432A-94FF-806178A34520}
FINAL FANTASY XI: Chains of Promathia –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{3C0619B4-4A2C-4244-8077-488E420DF907}
FINAL FANTASY XI: Rise of the Zilart –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{6FC76C41-8C1D-4B43-85E7-0BAA2002F1BE}
FINAL FANTASY XI: Treasures of Aht Urhgan –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A606C6FF-12E7-40BE-B777-D8F360FF00CD}
FINAL FANTASY XI: Wings of the Goddess –> C:\Program Files\InstallShield Installation Information\{5B037ED7-0755-48D4-9554-808E5AF50F17}\setup.exe -runfromtemp -l0x0409
Foxit Reader –> C:\Program Files\Foxit Software\Foxit Reader\Uninstall.exe
Google Desktop –> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Toolbar for Internet Explorer –> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer –> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Google Updater –> "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
HijackThis 2.0.2 –> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
iTunes –> MsiExec.exe /I{80FD852F-5AAC-4129-B931-06AAFFA43138}
Java™ 6 Update 3 –> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5 –> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
LimeWire 4.16.6 –> "C:\Program Files\LimeWire\uninstall.exe"
Logitech G11 Keyboard Software 1.04 –> MsiExec.exe /X{EC392EE1-9459-46C0-BE09-A20325100E0C}
Microsoft Office XP Professional with FrontPage –> MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
Microsoft Silverlight –> MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 Redistributable –> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (2.0.0.14) –> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
OpenOffice.org 2.3 –> MsiExec.exe /I{2F29D6D2-824E-4FEF-8AED-7013F39F642A}
Paint.NET v3.30 –> MsiExec.exe /X{FF09A6A1-4DE5-467D-AA26-EF18C0EA4DAB}
PlayOnline Viewer & Tetra Master –> C:\Program Files\InstallShield Installation Information\{47004155-7376-403E-89E9-4C9F44AAF0D0}\setup.exe -runfromtemp -l0x0409
QuickTime –> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
Realtek AC'97 Audio –> Alcrmv.exe -r -m
SpywareBlaster 4.0 –> "C:\Program Files\SpywareBlaster\unins000.exe"
Viewpoint Media Player –> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Winamp –> "C:\Program Files\Winamp\UninstWA.exe"
Windows Live installer –> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger –> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant –> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Player Firefox Plugin –> MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinRAR archiver –> C:\Program Files\WinRAR\uninstall.exe
Xvid 1.1.3 final uninstall –> "C:\Program Files\Xvid\unins000.exe"


– Application Event Log ——————————————————-

Event Record #/Type4355 / Error
Event Submitted/Written: 06/08/2008 00:59:01 PM
Event ID/Source: 3 / SecurityCenter
Event Description:
The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.

Event Record #/Type4352 / Success
Event Submitted/Written: 06/08/2008 00:57:29 PM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.

Event Record #/Type4349 / Success
Event Submitted/Written: 06/08/2008 00:56:52 PM
Event ID/Source: 5617 / WinMgmt
Event Description:


Event Record #/Type4348 / Success
Event Submitted/Written: 06/08/2008 00:56:50 PM
Event ID/Source: 5615 / WinMgmt
Event Description:


Event Record #/Type4343 / Success
Event Submitted/Written: 06/08/2008 00:56:10 PM
Event ID/Source: 902 / Software Licensing Service
Event Description:
The Software Licensing service has started.



– Security Event Log ———————————————————-

No Errors/Warnings found.


– System Event Log ————————————————————

Event Record #/Type23330 / Warning
Event Submitted/Written: 06/08/2008 07:00:18 PM
Event ID/Source: 3004 / WinDefend
Event Description:
%Greg-PC27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %Greg-PC27 can't undo changes that you allow.

For more information please see the following:
%Greg-PC275

Scan ID: {588D6C9E-CE93-4BD0-91B0-6CD2DD32F103}

User: Greg-PC\Greg

Name: %Greg-PC271

ID: %Greg-PC272

Severity ID: %Greg-PC273

Category ID: %Greg-PC274

Path Found: %Greg-PC276

Alert Type: %Greg-PC278

Detection Type: 1.1.1505.02

Event Record #/Type23329 / Warning
Event Submitted/Written: 06/08/2008 07:00:18 PM
Event ID/Source: 3004 / WinDefend
Event Description:
%Greg-PC27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %Greg-PC27 can't undo changes that you allow.

For more information please see the following:
%Greg-PC275

Scan ID: {CD601761-6F0F-4DF3-9E85-32306E49D5C3}

User: Greg-PC\Greg

Name: %Greg-PC271

ID: %Greg-PC272

Severity ID: %Greg-PC273

Category ID: %Greg-PC274

Path Found: %Greg-PC276

Alert Type: %Greg-PC278

Detection Type: 1.1.1505.02

Event Record #/Type23328 / Warning
Event Submitted/Written: 06/08/2008 07:00:18 PM
Event ID/Source: 3004 / WinDefend
Event Description:
%Greg-PC27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %Greg-PC27 can't undo changes that you allow.

For more information please see the following:
%Greg-PC275

Scan ID: {352FEC5C-7890-4DFE-AD68-DD1B177AC0C0}

User: Greg-PC\Greg

Name: %Greg-PC271

ID: %Greg-PC272

Severity ID: %Greg-PC273

Category ID: %Greg-PC274

Path Found: %Greg-PC276

Alert Type: %Greg-PC278

Detection Type: 1.1.1505.02

Event Record #/Type23327 / Warning
Event Submitted/Written: 06/08/2008 07:00:16 PM
Event ID/Source: 3004 / WinDefend
Event Description:
%Greg-PC27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %Greg-PC27 can't undo changes that you allow.

For more information please see the following:
%Greg-PC275

Scan ID: {9339D3C2-A651-4654-A024-AAD981D93925}

User: Greg-PC\Greg

Name: %Greg-PC271

ID: %Greg-PC272

Severity ID: %Greg-PC273

Category ID: %Greg-PC274

Path Found: %Greg-PC276

Alert Type: %Greg-PC278

Detection Type: 1.1.1505.02

Event Record #/Type23326 / Warning
Event Submitted/Written: 06/08/2008 07:00:16 PM
Event ID/Source: 3004 / WinDefend
Event Description:
%Greg-PC27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %Greg-PC27 can't undo changes that you allow.

For more information please see the following:
%Greg-PC275

Scan ID: {824F30B2-AB8C-4FA3-A263-07CAFC3AA397}

User: Greg-PC\Greg

Name: %Greg-PC271

ID: %Greg-PC272

Severity ID: %Greg-PC273

Category ID: %Greg-PC274

Path Found: %Greg-PC276

Alert Type: %Greg-PC278

Detection Type: 1.1.1505.02



– End of Deckard's System Scanner: finished at 2008-06-08 19:03:26 ————


Lastly,
Today while looking through the logs I noticed an odd .bin file on my desktop. I tried to open it in notepad and it seemed appear like japanese ascii. None of the scans flagged it as dangerous. Here is a SS of its properties:
[external image: Posted Image]
Hi Greg911,

In this post we'll clean the Java cache to make sure whatever was in there has now gone, and the u7iavi14764j.bin file looks to be an AVG update file, if you found it on your Desktop you should be able to safely remove it.

————————————————————————

Do you have System Restore running? This is a vital safety net so if it is off please turn it back on immediately as follows:

Turn on System Restore and make a new Restore Point:
Open the Start Menu, right-click Computer and select Properties
Click the System Protection link on the left side
Under Automatic Restore Points place a checkmark next to all drive letters, then press Apply
Next press Create… to create a new Restore Point, type a name such as "before cleaning" and press Create
You should be prompted that a System Restore point has been created, OK the prompt and press OK to close the System Protection settings dialog box.

————————————————————————

It appears that you have two antivirus programs running - AVG and Avast. Running one antivirus program is essential, but having two can cause conflicts, slow your system down and even cause stability problems without improving your security. You should use just one antivirus program and if you want an "2nd opinion", use an online scanner like Kaspersky's.

If you have two antivirus programs installed, then before proceeding, please remove one of them.
Please make sure you choose one currently capable of receiving updates, because an antivirus program without updates cannot protect your system effectively. If you have any problems, please stop and let me know.

————————————————————————

Please press Start->Control Panel->Java to open the Java control panel applet
On the General tab click Settings…, click Delete files…, make sure both boxes are checked and press OK
Press OK and OK again to close the Java control panel applet

————————————————————————

Please open Start->Control Panel->Uninstall a program/Programs and Features, and remove the following:

JavaT 6 Update 3
JavaT 6 Update 5

These are out of date and now a security risk, you can get the latest update (Java Runtime Environment (JRE) 6 Update 6) from here.

You have Viewpoint Media Player installed on your system. This program is not malware but it is foistware in that it is usually installed without the user's knowledge or approval, and for this reason I recommend you remove it. If you actually use this program, I recommend you try using safe and free alternatives such as VLC Media Player.
Viewpoint Media Player can be removed via Programs and Features

You have BitTorrent and Limewire, P2P file sharing programs installed on your computer. These programs do not come bundled with malware as some similar programs do, but peer-to-peer file sharing networks are one of the biggest sources of malware we see. Anything downloaded from them cannot be trusted to be clean, because even if the file appears to be what it claims to be, it can have malware embedded in it.
I strongly recommend you remove these via Programs and Features.

————————————————————————

Right-click the HijackThis program or shortcut, and choose Run as administrator to start the program
Choose Do a system scan only and place a checkmark next to the following line:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

You have websites in your Trusted Zone. Any sites in the Trusted Zone are a security risk, so unless you need them to be there in order for the sites to work then please remove them by checking these lines:

O15 - Trusted Zone: http://asia.msi.com.tw
O15 - Trusted Zone: http://global.msi.com.tw
O15 - Trusted Zone: http://www.msi.com.tw

Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

————————————————————————

Then please do an online scan with Kaspersky:
Open Kaspersky Online Scanner in Internet Explorer

When prompted, allow the installation of ActiveX components from Kaspersky
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT and then Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • The program will start to scan your system.
  • Once the scan is complete, click on the Save Report As… button, change Save as type: to Text file and save the file to your desktop as Kaspersky.txt
  • If Internet Explorer responds saying the report has been saved to the Temporary Internet Files folder, say Yes to open the folder, then navigate to C -> Users -> (Your username) -> Desktop to locate the report
Note: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

————————————————————————

Once complete, please post the Kaspersky report along with a new HijackThis log.
Hi Silver,

Here is an update from your recommended tips:

I deleted the .bin file on my desktop and then activated system restore using the method you listed.

_______________________________

I have un-installed avast and set AVG to automatically update, and also scan once a day.

_______________________________

I have deleted my Java files via control panel>Java, uninstalled Update 3 & 5 and installed Update 6 from their website.

_______________________________

As for Viewpoint: When I double click on it to uninstall it, it pops up a box named Viewpoint and has the message Please log in as administrator to install the Viewpoint Media Player with only the option OK.

_______________________________

I have removed O2 - BHO and the three O15 - Trusted Zones using HijackThis

_______________________________

I installed/setup Kaspersky as you recommended and ran the scan, here is the log:
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, June 09, 2008 7:09:14 PM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 9/06/2008
Kaspersky Anti-Virus database records: 841768
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 242122
Number of viruses found: 5
Number of infected objects: 6
Number of suspicious objects: 0
Duration of the scan process: 03:12:07

Infected Object Name / Virus Name / Last Action
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\ProgramData\avg8\Log\avgcfg.log Object is locked skipped
C:\ProgramData\avg8\Log\avgcore.log Object is locked skipped
C:\ProgramData\avg8\Log\avgcore.log.1 Object is locked skipped
C:\ProgramData\avg8\Log\avgcore.log.2 Object is locked skipped
C:\ProgramData\avg8\Log\avgrs.log Object is locked skipped
C:\ProgramData\avg8\Log\avgscan.log Object is locked skipped
C:\ProgramData\avg8\Log\avgsched.log Object is locked skipped
C:\ProgramData\avg8\Log\avgsrm.log Object is locked skipped
C:\ProgramData\avg8\Log\avgui.log Object is locked skipped
C:\ProgramData\avg8\Log\avgwd.log Object is locked skipped
C:\ProgramData\avg8\scanlogs\I_00000014.log Object is locked skipped
C:\ProgramData\comodo\common\db\sigsdb.db Object is locked skipped
C:\ProgramData\comodo\Firewall Pro\cfplogdb.sdb Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.70.Crwl Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.70.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010012.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010014.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010016.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010019.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001A.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010020.ci Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010020.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010020.wsb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010022.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy61.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf317B.tmp Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf317C.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-11022006-050241.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\dbc2e.ht1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\dbdam Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\dbdao Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\dbeam Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\dbeao Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\dbm Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\dbu2d.ht1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\dbvm.cf1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\dbvmh.ht1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\fii.cf1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\fiih.ht1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\hp Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\hpt2i.ht1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\rpm.cf1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\rpm1m.cf1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\rpm1mh.ht1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\rpmh.ht1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\safeweb\goog-black-enchashm.cf1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\safeweb\goog-black-enchashmh.ht1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\safeweb\goog-black-urlm.cf1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\safeweb\goog-black-urlmh.ht1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\safeweb\goog-malware-domainm.cf1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\safeweb\goog-malware-domainmh.ht1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\safeweb\goog-white-domainm.cf1 Object is locked skipped
C:\Users\Greg\AppData\Local\Google\Google Desktop\1bfe5164bd1a\safeweb\goog-white-domainmh.ht1 Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Messenger\[removed]\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Messenger\[removed]\SharingMetadata\pending.dat Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_C654_5628_5456_1B8D\dfsr.db Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_C654_5628_5456_1B8D\fsr.log Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_C654_5628_5456_1B8D\fsrtmp.log Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_C654_5628_5456_1B8D\tmp.edb Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Windows\UsrClass.dat{909b6dda-f10a-11dc-ab0c-001617f12bc2}.TM.blf Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Windows\UsrClass.dat{909b6dda-f10a-11dc-ab0c-001617f12bc2}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Windows\UsrClass.dat{909b6dda-f10a-11dc-ab0c-001617f12bc2}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Windows Defender\FileTracker\{DFEE4857-7EA2-4693-A703-B3E2F5A7B1C0} Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Windows Live Contacts\[removed]\real\members.stg Object is locked skipped
C:\Users\Greg\AppData\Local\Microsoft\Windows Live Contacts\[removed]\shadow\members.stg Object is locked skipped
C:\Users\Greg\AppData\Local\Mozilla\Firefox\Profiles\0otbh4p5.default\Cache\_CACHE_001_ Object is locked skipped
C:\Users\Greg\AppData\Local\Mozilla\Firefox\Profiles\0otbh4p5.default\Cache\_CACHE_002_ Object is locked skipped
C:\Users\Greg\AppData\Local\Mozilla\Firefox\Profiles\0otbh4p5.default\Cache\_CACHE_003_ Object is locked skipped
C:\Users\Greg\AppData\Local\Mozilla\Firefox\Profiles\0otbh4p5.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Users\Greg\AppData\Local\Mozilla\Firefox\Profiles\0otbh4p5.default\XUL.mfl Object is locked skipped
C:\Users\Greg\AppData\Local\Temp\~DF436D.tmp Object is locked skipped
C:\Users\Greg\AppData\Local\Temp\~DFAB15.tmp Object is locked skipped
C:\Users\Greg\AppData\Local\Temp\~DFC0AA.tmp Object is locked skipped
C:\Users\Greg\AppData\Local\Temp\~DFC0C1.tmp Object is locked skipped
C:\Users\Greg\AppData\Local\Temp\~DFC725.tmp Object is locked skipped
C:\Users\Greg\AppData\Roaming\Aim\bdagbefw\crazydancingreg\cert8.db Object is locked skipped
C:\Users\Greg\AppData\Roaming\Aim\bdagbefw\crazydancingreg\key3.db Object is locked skipped
C:\Users\Greg\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\Greg\AppData\Roaming\Mozilla\Firefox\Profiles\0otbh4p5.default\cert8.db Object is locked skipped
C:\Users\Greg\AppData\Roaming\Mozilla\Firefox\Profiles\0otbh4p5.default\formhistory.dat Object is locked skipped
C:\Users\Greg\AppData\Roaming\Mozilla\Firefox\Profiles\0otbh4p5.default\history.dat Object is locked skipped
C:\Users\Greg\AppData\Roaming\Mozilla\Firefox\Profiles\0otbh4p5.default\key3.db Object is locked skipped
C:\Users\Greg\AppData\Roaming\Mozilla\Firefox\Profiles\0otbh4p5.default\parent.lock Object is locked skipped
C:\Users\Greg\AppData\Roaming\Mozilla\Firefox\Profiles\0otbh4p5.default\search.sqlite Object is locked skipped
C:\Users\Greg\AppData\Roaming\Mozilla\Firefox\Profiles\0otbh4p5.default\urlclassifier2.sqlite Object is locked skipped
C:\Users\Greg\ntuser.dat Object is locked skipped
C:\Users\Greg\ntuser.dat.LOG1 Object is locked skipped
C:\Users\Greg\ntuser.dat.LOG2 Object is locked skipped
C:\Users\Greg\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Users\Greg\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Greg\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\SoftwareDistribution\EventCache\{970C439D-8951-4BFC-A55C-7187DE0047BA}.bin Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped
C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped
C:\Windows\System32\config\RegBack\SAM Object is locked skipped
C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped
C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped
C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{1341d01f-1a72-11dd-a5c4-001617f12bc2}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{1341d01f-1a72-11dd-a5c4-001617f12bc2}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{1341d01f-1a72-11dd-a5c4-001617f12bc2}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{1341d01f-1a72-11dd-a5c4-001617f12bc2}.TxR.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTm.blf Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000001 Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000002 Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.001 Object is locked skipped
C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped
C:\Windows\System32\winevt\Logs\ACEEventLog.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\WindowsUpdate.log Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0dbd18113b1fa6279559eada7d4ca78b_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0eca6479047b1be908e54e87170bd2ad_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1065f4ac1603172028bd31b7bba0cd3c_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\182e69905fdef54c211afc2529c2e448_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1ae2f1193b8471f5207553bec3ab2f1c_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1cc8443b88ab106684e1ee016b465b5f_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1e3b657227b57a4d28c93b4ece779c5a_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\25053cac1c6ce14a0282ce692441342b_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2d8bcfaed2ec2774cbdb16d3f5df9582_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3278f4ac313d0c1fdadbc53c67c5a2bd_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\39a28770d2377d5d989b4e8b771965b3_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\408a2e6b7f59b5daac4febc09c5980d7_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\40eac94305c87cd008e726fa59c451df_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4d43c7f3cbd635aed2193f8c3c708145_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4fa107643ebd33cb52ac037588baaf93_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57bfdb794dd59d8195d24b9480169019_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\60e6e1afd4609d7f1aecce2a5103e3ee_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\62951c94662ba4fbfb98d11f5b2ad5db_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6495fbe5c2b89fb4e18beb6c6b664c11_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\67648f32268f047bec2c70014bd51e22_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\67db702ac928aef2b793703b86aed522_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\71a13bb3b76571ecb9420fc0e914e835_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7324b7b617d9760b914440ef2c9b9115_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\83f2b5875130bfc70668d5fb54910c5e_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\852efc61b141f908cb81e477db5fe742_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\864fcfb5b9be3f3c8306680d3e7138cf_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89736d9e956215fc3b7c61df3ab42978_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\95afd602494111f0b1d658e540e13397_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9d1d3d2935012ff1bbcd0ac11424fc1e_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a5a65e1e4617489656c8b61481bd5211_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b08f8dd64cfbd5edc825d4d24b38669c_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b62ab6d96120eb87696c7a59aa4f495f_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd9318b0c6160238e06a921d31e21bc8_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\be1ab5d32c1344965c0d33c84239d395_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bfcc19ae340f091f222bf43868dc6fc5_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c0828f699c1ee468f931f04503ca0ff3_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c5687702e146ce185260e71b82811a7c_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c82cfdda729069a05a6c56a6d1fb0ee2_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c9b3ef2559a69c85cc24f6d874fc6be3_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc05889f2eb70a58cd04001f2a20fe66_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d8a89338abb57d392ea07f80844ed09e_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d8cea8044fbf07accebc1d11baa2986b_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dce1b4c7f6083e58ecf1f2152f75a47a_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dfae043a65c31077ed88f0610502d495_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eac57e938842dd6c98241928574753f7_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\efa4c982f5e0dfcbcbc7e6f83c7c313e_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f45a6c788aa51627b08e08567db28276_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f57f3614fb7c587680a05950c01455cd_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f6f507e2febb6e0cd52834827aa3e1ca_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f7e4aad27da1329b330d8d4097ff69c7_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\faa706e2c3bbb451148a8d55d073dab0_581c64ca-4de6-4df3-beb4-c16b6941440e Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0AF40000.VBN Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
D:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0AF40001.VBN Infected: Trojan.Java.ClassLoader.h skipped
D:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0AF40002.VBN Infected: Trojan.Java.ClassLoader.d skipped
D:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0AF80000.VBN Infected: Exploit.Java.ByteVerify skipped
D:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0B000000.VBN Infected: Trojan-Downloader.Java.OpenStream.c skipped
D:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0B0C0000.VBN Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.

__________________________________________

Lastly, here is the new Hijackthis log you've requested:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:24:23 PM, on 6/9/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-21-2558772488-3530516235-307242920-1000\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl (User '?')
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,C:\Windows\system32\guard32.dll,avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

–
End of file - 6732 bytes
Hi Greg911,

That's an unusual problem to have with Viewpoint, please try the following method to uninstall it:
Highlight and copy (CTRL-C) the following:

"C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe" /u

Then right-click your Desktop and choose New->Shortcut
Click in the box marked Type the location of the item:, press CTRL-V to paste in the text and press Next
Then type the name Viewpoint in the box and press Finish
Now, right-click the new shortcut and choose Run as administrator
This should hopefully begin the process of uninstalling Viewpoint, let me know how you get on.

Make hidden/system files and folders visible:
Click Start -> Computer, press Alt once, then from the top menu select Tools, Click Folder Options and select the View tab
Under the Hidden files and folders heading SELECT Show hidden files and folders
UNCHECK the Hide extensions for known file types option
UNCHECK the Hide protected operating system files (recommended) option
Click Yes to confirm and press OK

Use Windows Explorer (right-click Start, select Explore) to open the following folder:

D:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine

Please delete everything inside this folder

Once complete, please tell me if you had any difficulties with the instructions and post a new HijackThis log.
Hey again Silver,

Viewpoint:
As you instructed I created the shortcut file on my desktop and ran as administrator. I once again received the popup from Viewpoint saying Please log in as an administrator to install the Viewpoint Media Player. I then went directly to the folder and attempted to run the file as administrator and once again received the same error. If you would like I can take a screenshot of the error.


Symantec Quarantine:
I followed your directions, deleted the files inside the folder, and emptied my recycling bin. This made me realize one thing and brought a new question to light. My D:\ is actually a salvaged HD from a previous PC I owned. It was an all in one Sony VAIO unit and the display went so we put the unaffected HD into a new tower primarily to be used as an additional HD but without formatting it or removing the previous Windows components. Many programs I have on the D:\ are incredibly outdated. Do these pose a security risk? By no means do I expect you will walk me through reformatting the D:\ if it is, but what do you recommend I do with this drive? If it is not a security risk I will just leave it be, but if it does pose a security risk I will be glad to take action.

Here is a new Hijackthis log after removing the quarantined files:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:36:16 PM, on 6/9/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-21-2558772488-3530516235-307242920-1000\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl (User '?')
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,C:\Windows\system32\guard32.dll,avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

–
End of file - 6691 bytes


edit: I also had to use IE today when scanning with Kapernsky, I blocked an attempt from C:\Program FIles\Internet Explorer\iexplore.exe Direct Keyboard Access to no target. I'm not sure if this is anything to be worried about.
Hi Greg911,

I don't know what the cause of the Viewpoint problem is, but the program is not operating normally. We can remove it manually as follows:
Use Windows Explorer (right-click Start, select Explore) to find and delete the following folder:

C:\Program Files\Viewpoint

Now right-click the HijackThis shortcut and select Run as administrator
Select Open the Misc Tools section
Press the Open Uninstall Manager… button
Scroll down the list and find this entry:

Viewpoint Media Player

Click it to highlight it, then press Delete this entry
Then close HijackThis

You may also need to delete the Viewpoint Start menu folder or shortcut if one is present.

The old programs on your D: drive are not a security risk unless you actually use them. We've scanned the drive with Kaspersky and it doesn't look like there is any further malware there, so you can leave it be if you wish.

I also had to use IE today when scanning with Kapernsky, I blocked an attempt from C:\Program FIles\Internet Explorer\iexplore.exe Direct Keyboard Access to no target. I'm not sure if this is anything to be worried about.

Which program gave you this warning? Is that all the information the program gave?
Silver,

Thanks for the quick reply. I removed Viewpoint by deleting the folder and also uninstalling it through HijackThis. There was no start menu folder to be deleted.

____________________________________

Comodo firewall gave me that warning. As I mentioned I was using IE by accident since I was scanning with Kaspersky and the warning popped up. I should have taken note as to what website I was on at the time but I'm pretty sure it was a forum where my password is stored automatically. Here is an image of the Defense+ log. Also for the record I have in the past really raised the security in IE.

[external image: Posted Image]
Hi Greg911,

Glad to hear the Viewpoint removal went smoothly. I don't think that message from Comodo is anything to worry about because if the security settings are cranked up then you'll get that message simply by visiting the Kaspersky online scanner page. When you see messages like that it depends on what site you are visiting as to whether you should allow it or not.

Some important final steps:

Please delete fsbl.exe and dss.exe from your Desktop, also delete this folder:

C:\Deckard


Create a new, clean System Restore point which you can use in case of future system problems:
  • Press Start, then right-click Computer, select Properties then click System Protection
  • Next to You can create a Restore Point right now… click Create…
  • Type a name for the Restore Point like All Clean and press OK
  • Once the Restore Point has been created, press OK, OK and close the System dialog box.

Now remove old, infected System Restore points:
  • Next click Start, type cleanmgr in the search box and press Enter
  • Select Files from all users on this computer
  • Ensure the boxes for Recycle Bin, Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
  • Select the More Options tab, under System Restore press Clean up… and confirm by pressing Delete
  • Then press OK and Delete Files to confirm

Re-hide hidden/system files and folders:
Click Start -> Computer, press Alt once, then from the top menu select Tools,
Click Folder Options and select the View tab
Under the Hidden files and folders heading SELECT Do not show hidden files and folders
CHECK the Hide extensions for known file types option
CHECK the Hide protected operating system files (recommended) option
Press OK

————————————————————————

If the above went well I think your machine is clean of malware :) here are some tips to help you keep it that way:

You have good protection software installed however please ensure it is kept up to date. Check that your antivirus and antispyware programs are set to automatically update themselves daily, and that your firewall is the latest version.

I recommend you install a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
Also: subscribe to the mailing list to get update notifications.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware - this includes allowing websites to install browser plug-ins or ActiveX controls. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

Find out more about how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know that you have read this, and if there are any further issues.
Silver, Thanks again for all the help. I removed fsbl.exe, dss.exe, and C:\Deckard. After that I created a new restore point and cleaned up the files and removed all but my most recent restore point. Files have also been hidden as you instructed. I will definitely look into WVPS Hosts, is it similar to what Adblock Plus does since I've added previously recommended subscriptions to that. Is it OK to run both? I will also look in to your other recommendations tonight after work and install/setup WinPatrol. Also is it acceptable to have some other scanners DL'd but not constantly running such as ad-aware and search and destroy? Or should I just stick with AVG + Firewall + The recommendations you made in the previous post. Thanks again your service was invaluable! I'll definitely be making a donation.
You're most welcome and thank you for your generosity :)

MVPs hosts is like Adblock Plus but better, it effectively blocks access to a list of known bad domains and because it uses the hosts file, there is no program running in the background so it doesn't slow down your computer. Be sure to disable the DNS Client service before installing it, here's how:

Stop and Disable the DNS Client Service
Go to Start and type Services.msc in the Search box and press Enter
Under the Extended Tab, Scroll down and find this service:

DNS Client

Right-Click on the DNS Client Service. Choose Properties
Click the Arrow-down tab on the right-hand side at the Start-up Type box.
From the drop-down menu, select Disabled
Then click on the Stop button, wait for the service to stop and press OK
Close the Services console

Having other scanners on-board like Ad-Aware and Spybot is just fine, but make sure you don't have too much active protection at the same time otherwise you can have performance problems. For example, if you choose to use WinPatrol, make sure that Spybot's Tea Timer is not active otherwise you will have two programs covering the same territory. Do not however install more than one antivirus or firewall program - these will conflict and cause problems.

If you have any further questions please let me know.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI