Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

trojan.w32.looksky came back or never left [RESOLVED]


  • This topic is locked This topic is locked

#16
patrickg26

patrickg26

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
My DSS log...

Deckard's System Scanner v20070826.66
Run by Compaq_Owner on 2007-08-29 15:24:30
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Compaq_Owner.exe) ----------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 3:24:42 PM, on 8/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\EPSON\ESM2\eEBSVC.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\AOL\1127691177\ee\AOLSoftware.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Common Files\AOL\1127691177\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Lexmark 8300 Series\lxcjmon.exe
C:\Program Files\Lexmark 8300 Series\ezprint.exe
C:\Program Files\Napster\napster.exe
C:\WINDOWS\system32\lxcjcoms.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.EXE
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\Program Files\EPSON\ESM2\STMS.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Creative Home\Hallmark Card Studio Express\Planner\PLNRnote.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\AOL\1127691177\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\1127691177\ee\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Compaq_Owner\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\COMPAQ~1.EXE
C:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MSVPS System - {208D7BCC-9857-4C9E-823B-D04E72490A67} - C:\WINDOWS\mxduo.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1127691177\ee\SSCRun.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127691177\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1127691177\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [LXCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcjmon.exe] "C:\Program Files\Lexmark 8300 Series\lxcjmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 8300 Series\ezprint.exe"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Global Startup: 2Wire Wireless Client.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\EPSON\ESM2\STMS.exe
O4 - Global Startup: ExpressPLNRnote.lnk = C:\Program Files\Creative Home\Hallmark Card Studio Express\Planner\PLNRnote.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://www01.webpcf...trix/wficat.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp...ads/sysinfo.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://onlinedesigne...p/view22rte.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo....plorer1_9us.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: wmphost - {C47CA3B4-F355-41A2-8FB3-C33467D477B0} - C:\WINDOWS\wmphost.dll
O21 - SSODL: wmpdev - {15B22275-D877-418C-99ED-F166E58B7CEF} - C:\WINDOWS\wmpdev.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\EPSON\ESM2\eEBSVC.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: LXCJCustomerConnect - Unknown owner - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\LXCJserv.exe
O23 - Service: lxcj_device - - C:\WINDOWS\system32\lxcjcoms.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE


-- Files created between 2007-07-29 and 2007-08-29 -----------------------------

2007-08-29 13:30:30 0 d-------- C:\Documents and Settings\Compaq_Owner\DoctorWeb
2007-08-29 13:28:45 200704 --a------ C:\WINDOWS\wmphost.dll <Not Verified; ; IEXPLORE>
2007-08-29 13:28:45 307200 --a------ C:\WINDOWS\wmpdev.dll
2007-08-29 13:26:45 217088 --a------ C:\WINDOWS\mxduo.dll <Not Verified; ; BhoNew Module>
2007-08-29 13:14:50 50688 --a------ C:\WINDOWS\main_uninstaller.exe
2007-08-28 16:03:55 0 d-------- C:\WINDOWS\ERUNT
2007-08-25 15:16:05 0 dr-h----- C:\$VAULT$.AVG
2007-08-25 02:08:39 6370 --a------ C:\WINDOWS\system32\tmp.reg
2007-08-25 02:06:49 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2007-08-25 02:06:49 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-08-25 02:06:47 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2007-08-02 01:50:07 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Roxio
2007-08-02 01:31:56 0 d-------- C:\Program Files\Common Files\Napster Shared
2007-08-02 01:31:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Napster
2007-08-02 01:31:19 0 d-------- C:\Program Files\Napster


-- Find3M Report ---------------------------------------------------------------

2007-08-25 15:20:34 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\AVG7
2007-08-25 15:15:32 0 d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-25 02:03:44 0 d-------- C:\Program Files\Lx_cats
2007-08-24 21:01:39 0 d-------- C:\Program Files\America Online 9.0b
2007-08-08 13:59:31 14654 --a------ C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
2007-08-02 01:31:56 0 d-------- C:\Program Files\Common Files
2007-08-02 01:31:26 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-07-22 13:45:54 0 d-------- C:\Program Files\View22
2007-07-21 21:09:39 0 d-------- C:\Program Files\SmartDraw 2007
2007-07-14 15:59:05 0 d-------- C:\Program Files\Lexmark 8300 Series
2007-07-13 17:24:54 0 d-------- C:\Program Files\SierraHome
2007-07-13 16:58:29 0 d-------- C:\Program Files\Common Files\Nova Development
2007-07-13 16:56:42 0 d-------- C:\Program Files\Creative Home
2007-07-07 17:41:13 1156 --a------ C:\WINDOWS\mozver.dat
2007-07-07 17:12:25 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla
2007-07-05 15:18:32 0 d-------- C:\Program Files\Microsoft ActiveSync
2007-07-05 08:23:29 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Apple Computer
2007-07-04 09:31:03 2528 --a------ C:\Documents and Settings\Compaq_Owner\Application Data\$_hpcst$.hpc
2007-07-03 16:44:50 0 d-------- C:\Program Files\Microsoft IntelliPoint
2007-07-03 16:44:17 0 d-------- C:\Program Files\Microsoft IntelliType Pro
2007-07-01 02:12:25 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\MP3Rocket
2007-07-01 02:08:52 0 d-------- C:\Program Files\MP3 Rocket
2007-07-01 01:15:41 0 d-------- C:\Program Files\iTunes
2007-07-01 01:15:28 0 d-------- C:\Program Files\iPod
2007-07-01 01:11:56 0 d-------- C:\Program Files\QuickTime
2007-07-01 01:08:17 0 d-------- C:\Program Files\Apple Software Update
2007-07-01 01:07:33 0 d-------- C:\Program Files\Common Files\Apple
2007-07-01 00:11:27 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\SBC Yahoo! Messenger


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{208D7BCC-9857-4C9E-823B-D04E72490A67}]
08/29/2007 08:43 AM 217088 --a------ C:\WINDOWS\mxduo.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [09/13/2004 04:49 PM]
"YBrowser"="C:\Program Files\Yahoo!\browser\ybrwicon.exe" [07/11/2003 01:51 PM]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [08/30/2004 07:29 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [01/28/2005 09:44 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [03/14/2007 03:43 AM]
"sscRun"="C:\Program Files\Common Files\AOL\1127691177\ee\SSCRun.exe" [11/20/2006 01:42 PM]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [07/03/2001 09:11 AM]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [04/14/2004 01:43 PM]
"Pure Networks Port Magic"="C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" [08/24/2004 03:09 PM]
"PS2"="C:\WINDOWS\system32\ps2.exe" [09/12/2003 12:13 PM]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [04/13/2004 07:45 PM]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [11/07/2006 03:41 PM]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [11/07/2006 03:41 PM]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [10/14/2004 02:54 PM]
"KBD"="C:\HP\KBD\KBD.EXE" [02/11/2003 12:02 PM]
"IPInSightMonitor 01"="C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe" [07/14/2003 12:30 PM]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [05/07/1998 09:04 AM]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [11/02/2004 08:59 AM]
"HostManager"="C:\Program Files\Common Files\AOL\1127691177\ee\AOLSoftware.exe" [09/25/2006 05:52 PM]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [08/27/2004 04:22 PM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [08/24/2007 09:11 PM]
"AOLSPScheduler"="C:\Program Files\Common Files\AOL\1127691177\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe" [11/20/2006 01:42 PM]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [10/23/2006 05:50 AM]
"AGRSMMSG"="AGRSMMSG.exe" [03/04/2005 12:01 PM C:\WINDOWS\AGRSMMSG.exe]
"2wSysTray"="C:\Program Files\2Wire\2PortalMon.exe" [09/15/2004 01:52 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/27/2007 09:41 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [06/28/2007 09:14 AM]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [12/04/2005 05:38 PM]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [12/04/2005 05:39 PM]
"LXCJCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll" [02/24/2006 05:07 PM]
"lxcjmon.exe"="C:\Program Files\Lexmark 8300 Series\lxcjmon.exe" [09/30/2005 10:49 AM]
"EzPrint"="C:\Program Files\Lexmark 8300 Series\ezprint.exe" [04/19/2006 09:57 AM]
"NapsterShell"="C:\Program Files\Napster\napster.exe" [01/12/2007 07:36 PM]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [08/10/2004 12:42 PM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 09:24 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/27/2007 10:05 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 04:00 AM]
"Aim6"="" []
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [11/13/2006 01:39 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
2Wire Wireless Client.lnk - C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.EXE [5/6/2005 9:55:38 PM]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 11:05:26 PM]
Compaq Connections.lnk - C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe [1/28/2005 9:57:46 PM]
EPSON Background Monitor.lnk - C:\Program Files\EPSON\ESM2\STMS.exe [6/7/1999 11:11:18 AM]
ExpressPLNRnote.lnk - C:\Program Files\Creative Home\Hallmark Card Studio Express\Planner\PLNRnote.exe [1/16/2006 3:28:06 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [11/4/2004 8:28:24 PM]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [11/4/2004 8:50:52 PM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"wmphost"= {C47CA3B4-F355-41A2-8FB3-C33467D477B0} - C:\WINDOWS\wmphost.dll [08/29/2007 08:43 AM 200704]
"wmpdev"= {15B22275-D877-418C-99ED-F166E58B7CEF} - C:\WINDOWS\wmpdev.dll [08/29/2007 08:43 AM 307200]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4af3d79a-beb0-11d9-a5a6-806d6172696f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{946850c5-1e27-11d9-baf0-806d6172696f}]
AutoRun\command- D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c7eaf834-7138-11d9-a02f-806d6172696f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480




-- End of Deckard's System Scanner: finished at 2007-08-29 15:25:11 ------------
  • 0

Advertisements


#17
patrickg26

patrickg26

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Everything seems good so far. Desktop is back to normal, taskbar is stable, and I haven't received any pop ups.
  • 0

#18
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello Patrick

You seem to be using two anti-virus programs, Norton AntiVirus and AVG anti-virus. You need to uninstall one of these programs as it can cause a lot of problems. I recommend keeping Norton, so please go to Start > Control Panel > Add or Remove Programs > Remove Norton Internet Security or AVG


We need to run these tools again as the infection seems to have returned.


Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Please download SmitfraudFix (by S!Ri) to your Desktop.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.



1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: MSVPS System - {208D7BCC-9857-4C9E-823B-D04E72490A67} - C:\WINDOWS\mxduo.dll
O21 - SSODL: wmphost - {C47CA3B4-F355-41A2-8FB3-C33467D477B0} - C:\WINDOWS\wmphost.dll
O21 - SSODL: wmpdev - {15B22275-D877-418C-99ED-F166E58B7CEF} - C:\WINDOWS\wmpdev.dll


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



Please run OTMoveIt by OldTimer again.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\mxduo.dll
    C:\WINDOWS\wmphost.dll
    C:\WINDOWS\wmpdev.dll


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please "Copy" the results from the "Results" window (to the right) and then "Paste" them into your next reply on the forum.

Note : If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")

Click "Exit" to close OTMoveIt.


So in your next reply I need to see the following : the SmitfraudFix report, the OTMoveIt results, a new DSS log and tell me how your PC is running now.
  • 0

#19
patrickg26

patrickg26

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Once again, thank you for the continued help.


I deleted the AVG anti-virus and performed the Smitfraudfix and HJT scan/fix



Here is the Smitfraudfix report


SmitFraudFix v2.216

Scan done at 18:07:11.09, Wed 08/29/2007
Run from C:\Documents and Settings\Compaq_Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\main_uninstaller.exe Deleted

»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{03C2314C-C788-48C6-8154-2DFCAD3D5D11}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS1\Services\Tcpip\..\{03C2314C-C788-48C6-8154-2DFCAD3D5D11}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS3\Services\Tcpip\..\{03C2314C-C788-48C6-8154-2DFCAD3D5D11}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS3\Services\Tcpip\..\{5113244C-BF81-493A-9D81-510552FA6BF5}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End













Here are the OTMoveIt results...

C:\WINDOWS\mxduo.dll unregistered successfully.
C:\WINDOWS\mxduo.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\wmphost.dll
C:\WINDOWS\wmphost.dll NOT unregistered.
C:\WINDOWS\wmphost.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\wmpdev.dll
C:\WINDOWS\wmpdev.dll NOT unregistered.
C:\WINDOWS\wmpdev.dll moved successfully.

Created on 08/29/2007 18:25:19
  • 0

#20
patrickg26

patrickg26

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Comp seems to be running well still.


And here is my DSS log...


Deckard's System Scanner v20070826.66
Run by Compaq_Owner on 2007-08-29 18:29:31
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Compaq_Owner.exe) ----------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 6:29:34 PM, on 8/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\EPSON\ESM2\eEBSVC.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\AOL\1127691177\ee\AOLSoftware.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\AOL\1127691177\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Lexmark 8300 Series\lxcjmon.exe
C:\Program Files\Lexmark 8300 Series\ezprint.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Common Files\AOL\1127691177\ee\aolsoftware.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\lxcjcoms.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\Program Files\EPSON\ESM2\STMS.exe
C:\Program Files\Creative Home\Hallmark Card Studio Express\Planner\PLNRnote.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\AOL\1127691177\ee\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Compaq_Owner\Desktop\dss.exe
C:\WINDOWS\system32\imapi.exe
C:\PROGRA~1\HIJACK~1\COMPAQ~1.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MSVPS System - {208D7BCC-9857-4C9E-823B-D04E72490A67} - C:\WINDOWS\mxduo.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1127691177\ee\SSCRun.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127691177\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1127691177\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [LXCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcjmon.exe] "C:\Program Files\Lexmark 8300 Series\lxcjmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 8300 Series\ezprint.exe"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Global Startup: 2Wire Wireless Client.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\EPSON\ESM2\STMS.exe
O4 - Global Startup: ExpressPLNRnote.lnk = C:\Program Files\Creative Home\Hallmark Card Studio Express\Planner\PLNRnote.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://www01.webpcf...trix/wficat.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp...ads/sysinfo.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://onlinedesigne...p/view22rte.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo....plorer1_9us.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: wmphost - {9AAFB4CC-B0EA-4CC7-9547-23B80B709833} - C:\WINDOWS\wmphost.dll
O21 - SSODL: wmpdev - {B926CC7D-8AE8-41F3-A040-57DD7A60A5D4} - C:\WINDOWS\wmpdev.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\EPSON\ESM2\eEBSVC.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: LXCJCustomerConnect - Unknown owner - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\LXCJserv.exe
O23 - Service: lxcj_device - - C:\WINDOWS\system32\lxcjcoms.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE


-- Files created between 2007-07-29 and 2007-08-29 -----------------------------

2007-08-29 18:29:21 200704 --a------ C:\WINDOWS\wmphost.dll <Not Verified; ; IEXPLORE>
2007-08-29 18:29:21 307200 --a------ C:\WINDOWS\wmpdev.dll
2007-08-29 18:29:21 217088 --a------ C:\WINDOWS\mxduo.dll <Not Verified; ; BhoNew Module>
2007-08-29 18:22:17 50688 --a------ C:\WINDOWS\main_uninstaller.exe
2007-08-29 17:51:13 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2007-08-29 13:30:30 0 d-------- C:\Documents and Settings\Compaq_Owner\DoctorWeb
2007-08-28 16:03:55 0 d-------- C:\WINDOWS\ERUNT
2007-08-25 02:08:39 6188 --a------ C:\WINDOWS\system32\tmp.reg
2007-08-25 02:06:49 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2007-08-25 02:06:49 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-08-25 02:06:47 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2007-08-02 01:50:07 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Roxio
2007-08-02 01:31:56 0 d-------- C:\Program Files\Common Files\Napster Shared
2007-08-02 01:31:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Napster
2007-08-02 01:31:19 0 d-------- C:\Program Files\Napster


-- Find3M Report ---------------------------------------------------------------

2007-08-29 18:00:00 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\MP3Rocket
2007-08-29 17:59:48 0 d-------- C:\Program Files\LimeWire
2007-08-25 15:15:32 0 d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-25 02:03:44 0 d-------- C:\Program Files\Lx_cats
2007-08-24 21:01:39 0 d-------- C:\Program Files\America Online 9.0b
2007-08-08 13:59:31 14654 --a------ C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
2007-08-02 01:31:56 0 d-------- C:\Program Files\Common Files
2007-08-02 01:31:26 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-07-22 13:45:54 0 d-------- C:\Program Files\View22
2007-07-21 21:09:39 0 d-------- C:\Program Files\SmartDraw 2007
2007-07-14 15:59:05 0 d-------- C:\Program Files\Lexmark 8300 Series
2007-07-13 17:24:54 0 d-------- C:\Program Files\SierraHome
2007-07-13 16:58:29 0 d-------- C:\Program Files\Common Files\Nova Development
2007-07-13 16:56:42 0 d-------- C:\Program Files\Creative Home
2007-07-07 17:41:13 1156 --a------ C:\WINDOWS\mozver.dat
2007-07-07 17:12:25 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla
2007-07-05 15:18:32 0 d-------- C:\Program Files\Microsoft ActiveSync
2007-07-05 08:23:29 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Apple Computer
2007-07-04 09:31:03 2528 --a------ C:\Documents and Settings\Compaq_Owner\Application Data\$_hpcst$.hpc
2007-07-03 16:44:50 0 d-------- C:\Program Files\Microsoft IntelliPoint
2007-07-03 16:44:17 0 d-------- C:\Program Files\Microsoft IntelliType Pro
2007-07-01 01:15:41 0 d-------- C:\Program Files\iTunes
2007-07-01 01:15:28 0 d-------- C:\Program Files\iPod
2007-07-01 01:11:56 0 d-------- C:\Program Files\QuickTime
2007-07-01 01:08:17 0 d-------- C:\Program Files\Apple Software Update
2007-07-01 01:07:33 0 d-------- C:\Program Files\Common Files\Apple
2007-07-01 00:11:27 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\SBC Yahoo! Messenger


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{208D7BCC-9857-4C9E-823B-D04E72490A67}]
08/29/2007 08:43 AM 217088 --a------ C:\WINDOWS\mxduo.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [09/13/2004 04:49 PM]
"YBrowser"="C:\Program Files\Yahoo!\browser\ybrwicon.exe" [07/11/2003 01:51 PM]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [08/30/2004 07:29 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [01/28/2005 09:44 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [03/14/2007 03:43 AM]
"sscRun"="C:\Program Files\Common Files\AOL\1127691177\ee\SSCRun.exe" [11/20/2006 01:42 PM]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [07/03/2001 09:11 AM]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [04/14/2004 01:43 PM]
"Pure Networks Port Magic"="C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" [08/24/2004 03:09 PM]
"PS2"="C:\WINDOWS\system32\ps2.exe" [09/12/2003 12:13 PM]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [04/13/2004 07:45 PM]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [11/07/2006 03:41 PM]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [11/07/2006 03:41 PM]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [10/14/2004 02:54 PM]
"KBD"="C:\HP\KBD\KBD.EXE" [02/11/2003 12:02 PM]
"IPInSightMonitor 01"="C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe" [07/14/2003 12:30 PM]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [05/07/1998 09:04 AM]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [11/02/2004 08:59 AM]
"HostManager"="C:\Program Files\Common Files\AOL\1127691177\ee\AOLSoftware.exe" [09/25/2006 05:52 PM]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [08/27/2004 04:22 PM]
"AOLSPScheduler"="C:\Program Files\Common Files\AOL\1127691177\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe" [11/20/2006 01:42 PM]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [10/23/2006 05:50 AM]
"AGRSMMSG"="AGRSMMSG.exe" [03/04/2005 12:01 PM C:\WINDOWS\AGRSMMSG.exe]
"2wSysTray"="C:\Program Files\2Wire\2PortalMon.exe" [09/15/2004 01:52 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/27/2007 09:41 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [06/28/2007 09:14 AM]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [12/04/2005 05:38 PM]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [12/04/2005 05:39 PM]
"LXCJCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll" [02/24/2006 05:07 PM]
"lxcjmon.exe"="C:\Program Files\Lexmark 8300 Series\lxcjmon.exe" [09/30/2005 10:49 AM]
"EzPrint"="C:\Program Files\Lexmark 8300 Series\ezprint.exe" [04/19/2006 09:57 AM]
"NapsterShell"="C:\Program Files\Napster\napster.exe" [01/12/2007 07:36 PM]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [08/10/2004 12:42 PM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 09:24 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/27/2007 10:05 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 04:00 AM]
"Aim6"="" []
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [11/13/2006 01:39 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
2Wire Wireless Client.lnk - C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.EXE [5/6/2005 9:55:38 PM]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 11:05:26 PM]
Compaq Connections.lnk - C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe [1/28/2005 9:57:46 PM]
EPSON Background Monitor.lnk - C:\Program Files\EPSON\ESM2\STMS.exe [6/7/1999 11:11:18 AM]
ExpressPLNRnote.lnk - C:\Program Files\Creative Home\Hallmark Card Studio Express\Planner\PLNRnote.exe [1/16/2006 3:28:06 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [11/4/2004 8:28:24 PM]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [11/4/2004 8:50:52 PM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"wmphost"= {9AAFB4CC-B0EA-4CC7-9547-23B80B709833} - C:\WINDOWS\wmphost.dll [08/29/2007 08:43 AM 200704]
"wmpdev"= {B926CC7D-8AE8-41F3-A040-57DD7A60A5D4} - C:\WINDOWS\wmpdev.dll [08/29/2007 08:43 AM 307200]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{946850c5-1e27-11d9-baf0-806d6172696f}]
AutoRun\command- D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c7eaf834-7138-11d9-a02f-806d6172696f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480




-- End of Deckard's System Scanner: finished at 2007-08-29 18:30:00 ------------
  • 0

#21
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello Patrick, it seems this malware is putting up a fight. Let's try out a few things before we bring in the big guns.


Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Reboot into Safe Mode by continuously tapping the F8 key as soon as the computer begins to boot. A menu should come up where you will be given the option to enter Safe Mode.


1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: MSVPS System - {208D7BCC-9857-4C9E-823B-D04E72490A67} - C:\WINDOWS\mxduo.dll
O21 - SSODL: wmphost - {C47CA3B4-F355-41A2-8FB3-C33467D477B0} - C:\WINDOWS\wmphost.dll
O21 - SSODL: wmpdev - {15B22275-D877-418C-99ED-F166E58B7CEF} - C:\WINDOWS\wmpdev.dll


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



Please run OTMoveIt by OldTimer again.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\mxduo.dll
    C:\WINDOWS\wmphost.dll
    C:\WINDOWS\wmpdev.dll
    C:\WINDOWS\main_uninstaller.exe


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please "Copy" the results from the "Results" window (to the right) and then "Paste" them into your next reply on the forum.

Note : If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")

Click "Exit" to close OTMoveIt.



While still in Safe Mode do the following :

Double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.



Reboot your PC and do the following :

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


So in your next reply please post the following : the SmitfraudFix report, a new DSS log, the OTMoveIt results, and the ComboFix log.
  • 0

#22
patrickg26

patrickg26

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Here goes the SmitfraudFix report...


SmitFraudFix v2.216

Scan done at 19:05:25.53, Wed 08/29/2007
Run from C:\Documents and Settings\Compaq_Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{03C2314C-C788-48C6-8154-2DFCAD3D5D11}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CCS\Services\Tcpip\..\{5113244C-BF81-493A-9D81-510552FA6BF5}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS1\Services\Tcpip\..\{03C2314C-C788-48C6-8154-2DFCAD3D5D11}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS1\Services\Tcpip\..\{5113244C-BF81-493A-9D81-510552FA6BF5}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS3\Services\Tcpip\..\{03C2314C-C788-48C6-8154-2DFCAD3D5D11}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS3\Services\Tcpip\..\{5113244C-BF81-493A-9D81-510552FA6BF5}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End







OTMoveIT results....

File/Folder C:\WINDOWS\mxduo.dll not found.
DllUnregisterServer procedure not found in C:\WINDOWS\wmphost.dll
C:\WINDOWS\wmphost.dll NOT unregistered.
C:\WINDOWS\wmphost.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\wmpdev.dll
C:\WINDOWS\wmpdev.dll NOT unregistered.
C:\WINDOWS\wmpdev.dll moved successfully.
C:\WINDOWS\main_uninstaller.exe moved successfully.

Created on 08/29/2007 19:04:27
  • 0

#23
patrickg26

patrickg26

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
ComboFix Log...

ComboFix 07-08-30.2 - "Compaq_Owner" 2007-08-29 19:18:56.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.758 [GMT -7:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\FindIt.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\FindItHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\findithotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\finditxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\Highlight.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\HighlightHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\highlighthotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\highlightxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\logo.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\logoxp.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\Reference.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\ReferenceHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\referencehotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\referencexp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\screensaver.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\Screensavers0.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\Weather.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\weatherhotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\weatherxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\contexts\error.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\contexts\related.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\contexts\travel.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\Games\images\active\Games0.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\images\walertXP.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\Movies\images\active\Movies0.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\ScreensaversMarketingSitePager\images\active\ScreensaversMarketingSitePager0.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\SimpleUpdate\ProductMessagingConfig.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\SimpleUpdate\ProductMessagingConfig.xml.backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\SimpleUpdate\SimpleUpdateConfig.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\SimpleUpdate\SimpleUpdateConfig.xml.backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\SimpleUpdate\TimerManagerConfig.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\SimpleUpdate\TimerManagerConfig.xml.backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316
C:\DOCUME~1\COMPAQ~1\APPLIC~1\Starware316
C:\Program Files\Starware316
C:\Program Files\Starware316\brand.bmp
C:\Program Files\Starware316\Starware316Config.xml
C:\WINDOWS\dat.txt
D:\Autorun.inf


((((((((((((((((((((((((( Files Created from 2007-07-28 to 2007-08-30 )))))))))))))))))))))))))))))))


2007-08-29 19:17 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-29 13:30 <DIR> d-------- C:\DOCUME~1\COMPAQ~1\DoctorWeb
2007-08-28 16:03 <DIR> d-------- C:\WINDOWS\ERUNT
2007-08-25 02:15 <DIR> d-------- C:\Deckard
2007-08-25 02:08 6,188 --a------ C:\WINDOWS\system32\tmp.reg
2007-08-25 02:06 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-08-25 02:06 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-08-25 02:06 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-08-02 01:50 <DIR> d-------- C:\DOCUME~1\COMPAQ~1\APPLIC~1\Roxio
2007-08-02 01:31 <DIR> d-------- C:\Program Files\Napster
2007-08-02 01:31 <DIR> d-------- C:\Program Files\Common Files\Napster Shared
2007-08-02 01:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Napster


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-29 18:00 --------- d-------- C:\DOCUME~1\COMPAQ~1\APPLIC~1\MP3Rocket
2007-08-29 17:59 --------- d-------- C:\Program Files\LimeWire
2007-08-25 15:15 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-25 02:03 --------- d-------- C:\Program Files\Lx_cats
2007-08-24 21:01 --------- d-------- C:\Program Files\America Online 9.0b
2007-08-02 01:31 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\dllcache\wups.dll
2007-07-22 13:45 --------- d-------- C:\Program Files\View22
2007-07-21 21:09 --------- d-------- C:\Program Files\SmartDraw 2007
2007-07-18 23:59 3583488 --a------ C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-14 15:59 --------- d-------- C:\Program Files\Lexmark 8300 Series
2007-07-13 17:29 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SierraHome
2007-07-13 17:24 --------- d-------- C:\Program Files\SierraHome
2007-07-13 16:58 --------- d-------- C:\Program Files\Common Files\Nova Development
2007-07-13 16:56 --------- d-------- C:\Program Files\Creative Home
2007-07-13 16:56 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative Home
2007-07-12 16:31 765952 --a------ C:\WINDOWS\system32\dllcache\vgx.dll
2007-07-05 16:41 --------- d-------- C:\DOCUME~1\Guest\APPLIC~1\Viewpoint
2007-07-05 15:32 --------- d-------- C:\DOCUME~1\Guest\APPLIC~1\Google
2007-07-05 15:18 --------- d-------- C:\Program Files\Microsoft ActiveSync
2007-07-05 08:23 --------- d-------- C:\DOCUME~1\COMPAQ~1\APPLIC~1\Apple Computer
2007-07-03 16:44 --------- d-------- C:\Program Files\Microsoft IntelliType Pro
2007-07-03 16:44 --------- d-------- C:\Program Files\Microsoft IntelliPoint
2007-07-01 01:15 --------- d-------- C:\Program Files\iTunes
2007-07-01 01:15 --------- d-------- C:\Program Files\iPod
2007-07-01 01:11 --------- d-------- C:\Program Files\QuickTime
2007-07-01 01:11 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-07-01 01:08 --------- d-------- C:\Program Files\Apple Software Update
2007-07-01 01:07 --------- d-------- C:\Program Files\Common Files\Apple
2007-07-01 01:07 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-01 00:11 --------- d-------- C:\DOCUME~1\COMPAQ~1\APPLIC~1\SBC Yahoo! Messenger
2007-06-27 07:34 823808 --a------ C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 07:34 671232 --a------ C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 07:34 6058496 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 07:34 52224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 07:34 477696 --a------ C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 07:34 459264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 07:34 44544 --a------ C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 07:34 384512 --a------ C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 07:34 383488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 07:34 27648 --a------ C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 07:34 267776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 07:34 232960 --a------ C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 07:34 230400 --a------ C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 07:34 193024 --a------ C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 07:34 153088 --a------ C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 07:34 132608 --a------ C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 07:34 124928 --a------ C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 07:34 1152000 --a------ C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 07:34 105984 --a------ C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 07:34 102400 --a------ C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 01:27 63488 --a------ C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 01:27 625152 --a------ C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 01:27 13824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 00:00 161792 --a------ C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-25 23:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-25 23:08 1104896 --a------ C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 06:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-19 06:31 282112 --a------ C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-13 03:23 1033216 --a------ C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 03:23 1033216 --a------ C:\WINDOWS\explorer.exe
2004-08-04 11:00:00 94,784 --sh--w C:\WINDOWS\twain.dll
2004-08-04 11:00:00 50,688 --sh--w C:\WINDOWS\twain_32.dll
2004-08-04 11:00:00 1,028,096 --sh--w C:\WINDOWS\system32\mfc42.dll
2004-08-04 11:00:00 54,784 --sh--w C:\WINDOWS\system32\msvcirt.dll
2004-08-04 11:00:00 413,696 --sh--w C:\WINDOWS\system32\msvcp60.dll
2004-08-04 11:00:00 343,040 --sh--w C:\WINDOWS\system32\msvcrt.dll
2007-05-17 11:28:05 549,376 --sh--w C:\WINDOWS\system32\oleaut32.dll
2004-08-04 11:00:00 83,456 --sh--w C:\WINDOWS\system32\olepro32.dll
2004-08-04 11:00:00 11,776 --sh--w C:\WINDOWS\system32\regsvr32.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 16:49]
"YBrowser"="C:\Program Files\Yahoo!\browser\ybrwicon.exe" [2003-07-11 13:51]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [2004-08-30 19:29]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-01-28 21:44]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"sscRun"="C:\Program Files\Common Files\AOL\1127691177\ee\SSCRun.exe" [2006-11-20 13:42]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 09:11]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 13:43]
"Pure Networks Port Magic"="C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" [2004-08-24 15:09]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 12:13]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [2004-04-13 19:45]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-11-07 15:41]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-11-07 15:41]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 14:54]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 12:02]
"IPInSightMonitor 01"="C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe" [2003-07-14 12:30]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 09:04]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-02 08:59]
"HostManager"="C:\Program Files\Common Files\AOL\1127691177\ee\AOLSoftware.exe" [2006-09-25 17:52]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-08-27 16:22]
"AOLSPScheduler"="C:\Program Files\Common Files\AOL\1127691177\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe" [2006-11-20 13:42]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 05:50]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 12:01 C:\WINDOWS\AGRSMMSG.exe]
"2wSysTray"="C:\Program Files\2Wire\2PortalMon.exe" [2004-09-15 01:52]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2005-12-04 17:38]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2005-12-04 17:39]
"LXCJCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll" [2006-02-24 17:07]
"lxcjmon.exe"="C:\Program Files\Lexmark 8300 Series\lxcjmon.exe" [2005-09-30 10:49]
"EzPrint"="C:\Program Files\Lexmark 8300 Series\ezprint.exe" [2006-04-19 09:57]
"NapsterShell"="C:\Program Files\Napster\napster.exe" [2007-01-12 19:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2004-08-10 12:42]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 10:05]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00]
"Aim6"="" []
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39]

R2 LXCJCustomerConnect;LXCJCustomerConnect;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\LXCJserv.exe
R3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
R3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys
R3 WlanUIG;2Wire 802.11g USB Driver;C:\WINDOWS\system32\DRIVERS\WlanUIG.sys
S3 z520bus;Sony Ericsson 520 driver (WDM);C:\WINDOWS\system32\DRIVERS\z520bus.sys
S3 z520mdfl;Sony Ericsson 520 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\z520mdfl.sys
S3 z520mdm;Sony Ericsson 520 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\z520mdm.sys
S3 z520mgmt;Sony Ericsson 520 USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\z520mgmt.sys
S3 z520obex;Sony Ericsson 520 USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\z520obex.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{946850c5-1e27-11d9-baf0-806d6172696f}]
AutoRun\command- D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c7eaf834-7138-11d9-a02f-806d6172696f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

*Newly Created Service* - CATCHME

Contents of the 'Scheduled Tasks' folder
2007-07-14 18:35:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2005-05-07 23:51:42 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-29 19:22:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCJCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-29 19:22:51
C:\ComboFix-quarantined-files.txt ... 2007-08-29 19:22

--- E O F ---
  • 0

#24
patrickg26

patrickg26

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
And my DSS log...


Deckard's System Scanner v20070826.66
Run by Compaq_Owner on 2007-08-29 19:30:48
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Compaq_Owner.exe) ----------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 7:30:56 PM, on 8/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\EPSON\ESM2\eEBSVC.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\AOL\1127691177\ee\AOLSoftware.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\AOL\1127691177\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Lexmark 8300 Series\lxcjmon.exe
C:\Program Files\Lexmark 8300 Series\ezprint.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\AOL\1127691177\ee\aolsoftware.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\lxcjcoms.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.EXE
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\Program Files\EPSON\ESM2\STMS.exe
C:\Program Files\Creative Home\Hallmark Card Studio Express\Planner\PLNRnote.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\AOL\1127691177\ee\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Compaq_Owner\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\COMPAQ~1.EXE
C:\WINDOWS\system32\NOTEPAD.EXE

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1127691177\ee\SSCRun.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127691177\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1127691177\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [LXCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcjmon.exe] "C:\Program Files\Lexmark 8300 Series\lxcjmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 8300 Series\ezprint.exe"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Global Startup: 2Wire Wireless Client.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\EPSON\ESM2\STMS.exe
O4 - Global Startup: ExpressPLNRnote.lnk = C:\Program Files\Creative Home\Hallmark Card Studio Express\Planner\PLNRnote.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://www01.webpcf...trix/wficat.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp...ads/sysinfo.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://onlinedesigne...p/view22rte.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo....plorer1_9us.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\EPSON\ESM2\eEBSVC.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: LXCJCustomerConnect - Unknown owner - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\LXCJserv.exe
O23 - Service: lxcj_device - - C:\WINDOWS\system32\lxcjcoms.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE


-- Files created between 2007-07-29 and 2007-08-29 -----------------------------

2007-08-29 17:51:13 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2007-08-29 13:30:30 0 d-------- C:\Documents and Settings\Compaq_Owner\DoctorWeb
2007-08-28 16:03:55 0 d-------- C:\WINDOWS\ERUNT
2007-08-25 02:08:39 6188 --a------ C:\WINDOWS\system32\tmp.reg
2007-08-25 02:06:49 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2007-08-25 02:06:49 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-08-25 02:06:47 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2007-08-02 01:50:07 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Roxio
2007-08-02 01:31:56 0 d-------- C:\Program Files\Common Files\Napster Shared
2007-08-02 01:31:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Napster
2007-08-02 01:31:19 0 d-------- C:\Program Files\Napster


-- Find3M Report ---------------------------------------------------------------

2007-08-29 18:00:00 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\MP3Rocket
2007-08-29 17:59:48 0 d-------- C:\Program Files\LimeWire
2007-08-25 15:15:32 0 d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-25 02:03:44 0 d-------- C:\Program Files\Lx_cats
2007-08-24 21:01:39 0 d-------- C:\Program Files\America Online 9.0b
2007-08-08 13:59:31 14654 --a------ C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
2007-08-02 01:31:56 0 d-------- C:\Program Files\Common Files
2007-08-02 01:31:26 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-07-22 13:45:54 0 d-------- C:\Program Files\View22
2007-07-21 21:09:39 0 d-------- C:\Program Files\SmartDraw 2007
2007-07-14 15:59:05 0 d-------- C:\Program Files\Lexmark 8300 Series
2007-07-13 17:24:54 0 d-------- C:\Program Files\SierraHome
2007-07-13 16:58:29 0 d-------- C:\Program Files\Common Files\Nova Development
2007-07-13 16:56:42 0 d-------- C:\Program Files\Creative Home
2007-07-07 17:41:13 1156 --a------ C:\WINDOWS\mozver.dat
2007-07-07 17:12:25 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla
2007-07-05 15:18:32 0 d-------- C:\Program Files\Microsoft ActiveSync
2007-07-05 08:23:29 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Apple Computer
2007-07-04 09:31:03 2528 --a------ C:\Documents and Settings\Compaq_Owner\Application Data\$_hpcst$.hpc
2007-07-03 16:44:50 0 d-------- C:\Program Files\Microsoft IntelliPoint
2007-07-03 16:44:17 0 d-------- C:\Program Files\Microsoft IntelliType Pro
2007-07-01 01:15:41 0 d-------- C:\Program Files\iTunes
2007-07-01 01:15:28 0 d-------- C:\Program Files\iPod
2007-07-01 01:11:56 0 d-------- C:\Program Files\QuickTime
2007-07-01 01:08:17 0 d-------- C:\Program Files\Apple Software Update
2007-07-01 01:07:33 0 d-------- C:\Program Files\Common Files\Apple
2007-07-01 00:11:27 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\SBC Yahoo! Messenger


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [09/13/2004 04:49 PM]
"YBrowser"="C:\Program Files\Yahoo!\browser\ybrwicon.exe" [07/11/2003 01:51 PM]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [08/30/2004 07:29 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [01/28/2005 09:44 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [03/14/2007 03:43 AM]
"sscRun"="C:\Program Files\Common Files\AOL\1127691177\ee\SSCRun.exe" [11/20/2006 01:42 PM]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [07/03/2001 09:11 AM]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [04/14/2004 01:43 PM]
"Pure Networks Port Magic"="C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" [08/24/2004 03:09 PM]
"PS2"="C:\WINDOWS\system32\ps2.exe" [09/12/2003 12:13 PM]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [04/13/2004 07:45 PM]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [11/07/2006 03:41 PM]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [11/07/2006 03:41 PM]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [10/14/2004 02:54 PM]
"KBD"="C:\HP\KBD\KBD.EXE" [02/11/2003 12:02 PM]
"IPInSightMonitor 01"="C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe" [07/14/2003 12:30 PM]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [05/07/1998 09:04 AM]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [11/02/2004 08:59 AM]
"HostManager"="C:\Program Files\Common Files\AOL\1127691177\ee\AOLSoftware.exe" [09/25/2006 05:52 PM]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [08/27/2004 04:22 PM]
"AOLSPScheduler"="C:\Program Files\Common Files\AOL\1127691177\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe" [11/20/2006 01:42 PM]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [10/23/2006 05:50 AM]
"AGRSMMSG"="AGRSMMSG.exe" [03/04/2005 12:01 PM C:\WINDOWS\AGRSMMSG.exe]
"2wSysTray"="C:\Program Files\2Wire\2PortalMon.exe" [09/15/2004 01:52 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/27/2007 09:41 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [06/28/2007 09:14 AM]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [12/04/2005 05:38 PM]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [12/04/2005 05:39 PM]
"LXCJCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll" [02/24/2006 05:07 PM]
"lxcjmon.exe"="C:\Program Files\Lexmark 8300 Series\lxcjmon.exe" [09/30/2005 10:49 AM]
"EzPrint"="C:\Program Files\Lexmark 8300 Series\ezprint.exe" [04/19/2006 09:57 AM]
"NapsterShell"="C:\Program Files\Napster\napster.exe" [01/12/2007 07:36 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [08/10/2004 12:42 PM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 09:24 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/27/2007 10:05 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 04:00 AM]
"Aim6"="" []
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [11/13/2006 01:39 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
2Wire Wireless Client.lnk - C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.EXE [5/6/2005 9:55:38 PM]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 11:05:26 PM]
Compaq Connections.lnk - C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe [1/28/2005 9:57:46 PM]
EPSON Background Monitor.lnk - C:\Program Files\EPSON\ESM2\STMS.exe [6/7/1999 11:11:18 AM]
ExpressPLNRnote.lnk - C:\Program Files\Creative Home\Hallmark Card Studio Express\Planner\PLNRnote.exe [1/16/2006 3:28:06 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [11/4/2004 8:28:24 PM]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [11/4/2004 8:50:52 PM]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{946850c5-1e27-11d9-baf0-806d6172696f}]
AutoRun\command- D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c7eaf834-7138-11d9-a02f-806d6172696f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

*Newly Created Service* - CATCHME



-- End of Deckard's System Scanner: finished at 2007-08-29 19:31:21 ------------
  • 0

#25
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
That seems to have done the trick :whistling:

I just want to run two scans to make sure everything is good, as those infections were being a real pain.


Please download RUNSCANNER and install
When the first page comes up select Beginner Mode
On the next page select Save a binary .Run file (optional)
Then click Start full computer scan at the bottom
At this time Runscanner.exe may request access to the Internet through your firewall please allow it to do so
It will then run for 2 or 3 minutes
On completion it will ask for a location to save the file and a name
It will do this for both the .run file and the log
Call the file Select a file name here and save to your desktop
You will see the .run file on your desktop. Please zip that file by right clicking and selecting send to Zip file

Then upload that as an attachment to your next post.
Along with the Log file produced



Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

I see you have Viewpoint Manager installed on your PC

Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight >>Viewpoint component<< , click Remove.
  • Do the same for each Viewpoint component.


So in your next reply please post the following : the .run file from runscanner(you will need to attach this file), the Kaspersky Webscanner report, and tell me if your PC is having any trouble.
  • 0

Advertisements


#26
patrickg26

patrickg26

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Hello


Deleted the Viewpoint components and performed the scans. Comp seems to be running pretty well.



I've attached the RUNSCANNER.run file





Here is the RUNSCANNER log


Runscanner logfile http://www.runscanner.net

* = authenticode signed file
- = file not found

000 General info
----------------
Computer name : PATRICIA
Creation time : 8/30/2007 1:33:16 PM
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 7.0.5730.11
OS : Microsoft Windows XP
OS Build : 2600
OS SP : Service Pack 2
RunScanner Version : 1.0.3.0
Type of scan : Full scan
User Language : English (United States)
User rights : Administrator
Windows folder : C:\WINDOWS

001 Running processes
---------------------
c:\program files\hp\digital imaging\bin\hpqgalry.exe (Hewlett-Packard Co.)
* c:\program files\common files\aol\1127691177\ee\aolsoftware.exe (America Online, Inc.)
* c:\program files\common files\aol\1127691177\ee\aolsoftware.exe (America Online, Inc.)
* c:\program files\common files\aol\1127691177\ee\aolsoftware.exe (America Online, Inc.)
* c:\progra~1\common~1\aol\acs\aolacsd.exe (AOL LLC)
c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe (Apple, Inc.)
c:\program files\epson\esm2\stms.exe (SEIKO EPSON CORPORATION)
c:\program files\compaq connections\6750491\program\compaq connections.exe (Hewlett-Packard)
c:\program files\epson\esm2\eebsvc.exe
* c:\program files\ca\pprt\bin\itmrtsvc.exe (CA, Inc.)
* c:\program files\creative home\hallmark card studio express\planner\plnrnote.exe (Creative Home)
c:\program files\ewido anti-malware\ewidoctrl.exe (ewido networks)
* c:\program files\mozilla firefox\firefox.exe (Mozilla Corporation)
* c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe (Google Inc.)
* c:\windows\system32\hkcmd.exe (Intel Corporation)
c:\program files\2wire\2portalmon.exe (2Wire, Inc.)
c:\program files\hp\digital imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe (Hewlett-Packard)
c:\progra~1\hewlet~1\hpshar~1\hpgs2wnf.exe
c:\windows\system\hpsysdrv.exe (Hewlett-Packard Company)
c:\program files\hp\hp software update\hpwuschd2.exe (Hewlett-Packard Company)
* c:\program files\ipod\bin\ipodservice.exe (Apple Inc.)
* c:\program files\norton internet security\issvc.exe (Symantec Corporation)
* c:\program files\itunes\ituneshelper.exe (Apple Inc.)
* c:\program files\java\jre1.6.0_01\bin\jusched.exe (Sun Microsystems, Inc.)
c:\hp\kbd\kbd.exe (Hewlett-Packard Company)
c:\program files\lexmark 8300 series\lxcjmon.exe (Lexmark International, Inc.)
c:\program files\lexmark 8300 series\ezprint.exe (Lexmark International Inc.)
c:\program files\musicmatch\musicmatch jukebox\mmdiag.exe (Musicmatch, Inc.)
c:\program files\musicmatch\musicmatch jukebox\mim.exe (Musicmatch, Inc.)
c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe (Musicmatch, Inc.)
* c:\program files\napster\napster.exe (Napster)
* c:\program files\common files\symantec shared\sndsrvc.exe (Symantec Corporation)
* c:\program files\norton internet security\norton antivirus\navapsvc.exe (Symantec Corporation)
* c:\program files\common files\symantec shared\security center\symwsc.exe (Symantec Corporation)
* c:\windows\system32\lxcjcoms.exe
c:\windows\system32\prismsvr.exe (Conexant Systems, Inc.)
c:\program files\quicktime\qttask.exe (Apple Inc.)
c:\program files\common files\real\update_ob\realsched.exe (RealNetworks, Inc.)
* c:\docume~1\compaq~1\locals~1\temp\temporary directory 1 for runscanner.zip\runscanner.exe (Runscanner.net)
* c:\windows\system32\spool\drivers\w32x86\3\lxcjserv.exe
* c:\windows\agrsmmsg.exe (Agere Systems)
* c:\program files\common files\symantec shared\spbbc\spbbcsvc.exe (Symantec Corporation)
* c:\program files\common files\aol\1127691177\ee\services\safetycore\ver210_5_2_1\aolsp scheduler.exe (AOL LLC)
* c:\program files\common files\symantec shared\ccevtmgr.exe (Symantec Corporation)
* c:\program files\common files\symantec shared\ccproxy.exe (Symantec Corporation)
* c:\program files\common files\symantec shared\ccsetmgr.exe (Symantec Corporation)
* c:\program files\common files\symantec shared\ccapp.exe (Symantec Corporation)
* c:\program files\viewpoint\viewpoint manager\viewmgr.exe (Viewpoint Corporation)
c:\program files\viewpoint\common\viewpointservice.exe (Viewpoint Corporation)
c:\windows\wanmpsvc.exe (America Online, Inc.)
c:\program files\2wire 802.11g wireless\prismcfg.exe (2Wire Inc.)
c:\program files\yahoo!\browser\ybrwicon.exe (Yahoo!, Inc.)
c:\progra~1\yahoo!\browser\ycommon.exe (Yahoo!, Inc.)
c:\program files\yahoo!\messenger\ymsgr_tray.exe

002 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (+subkeys)
-----------------------------------------------------------------
c:\program files\2wire\2portalmon.exe (2Wire, Inc.)
* C:\WINDOWS\agrsmmsg.exe (Agere Systems)
* c:\program files\common files\aol\acs\aoldial.exe (AOL LLC)
* c:\program files\common files\aol\1127691177\ee\services\safetycore\ver210_5_2_1\aolsp scheduler.exe (AOL LLC)
* c:\program files\common files\symantec shared\ccapp.exe (Symantec Corporation)
c:\program files\lexmark 8300 series\ezprint.exe (Lexmark International Inc.)
* c:\program files\common files\aol\1127691177\ee\aolsoftware.exe (America Online, Inc.)
* c:\windows\system32\hkcmd.exe (Intel Corporation)
c:\program files\hp\hp software update\hpwuschd2.exe (Hewlett-Packard Company)
c:\windows\system\hpsysdrv.exe (Hewlett-Packard Company)
c:\program files\sbc yahoo!\connection manager\ip insight\ipmon32.exe (Visual Networks)
* c:\program files\itunes\ituneshelper.exe (Apple Inc.)
c:\hp\kbd\kbd.exe (Hewlett-Packard Company)
c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe (Hewlett-Packard Company)
* c:\windows\system32\spool\drivers\w32x86\3\lxcjtime.dll
c:\program files\lexmark 8300 series\lxcjmon.exe (Lexmark International, Inc.)
c:\progra~1\musicm~1\musicm~1\mimboot.exe (Musicmatch, Inc.)
c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe (Musicmatch, Inc.)
* c:\program files\napster\napster.exe (Napster)
c:\windows\system32\prismsvr.exe (Conexant Systems, Inc.)
* c:\windows\system32\ps2.exe (Hewlett-Packard Company)
* c:\progra~1\purene~1\portma~1\portaol.exe (Pure Networks, Inc.)
c:\program files\quicktime\qttask.exe (Apple Inc.)
c:\windows\sminst\recguard.exe
c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe (Hewlett-Packard)
* c:\program files\common files\aol\1127691177\ee\sscrun.exe (AOL LLC)
* c:\program files\java\jre1.6.0_01\bin\jusched.exe (Sun Microsystems, Inc.)
c:\program files\common files\real\update_ob\realsched.exe (RealNetworks, Inc.)
* c:\program files\norton internet security\urllstck.exe (Symantec Corporation)
c:\program files\yahoo!\browser\ybrwicon.exe (Yahoo!, Inc.)

003 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (+subkeys)
-----------------------------------------------------------------
* c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe (Google Inc.)
c:\program files\yahoo!\messenger\ypager.exe (Yahoo! Inc.)

005 C:\Documents and Settings\All Users\Start Menu\Programs\Startup
-------------------------------------------------------------------
c:\progra~1\adobe\acroba~3.0\reader\reader~1.exe (Adobe Systems Incorporated)
c:\progra~1\epson\esm2\stms.exe (SEIKO EPSON CORPORATION)
c:\progra~1\compaq~1\6750491\program\compaq~1.exe (Hewlett-Packard)
* c:\progra~1\creati~1\hallma~1\planner\plnrnote.exe (Creative Home)
c:\progra~1\hp\digita~1\bin\hpqtra08.exe (Hewlett-Packard Co.)
c:\progra~1\hp\digita~1\bin\hpqthb08.exe (Hewlett-Packard Co.)
c:\progra~1\2wire8~1.11g\prismcfg.exe (2Wire Inc.)

010 HKLM\SYSTEM\CurrentControlSet\Services (Services)
-----------------------------------------------------
* c:\progra~1\common~1\aol\acs\aolacsd.exe (AOL Connectivity Service)
c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe (Apple Mobile Device)
* c:\program files\ca\pprt\bin\itmrtsvc.exe (CA Pest Patrol Realtime Protection Service)
c:\program files\epson\esm2\eebsvc.exe (EpsonBidirectionalService)
c:\program files\ewido anti-malware\ewidoctrl.exe (ewido security suite control)
* c:\program files\google\common\google updater\googleupdaterservice.exe (Google Updater Service)
c:\program files\common files\installshield\driver\1050\intel 32\idrivert.exe (InstallDriver Table Manager)
* c:\program files\ipod\bin\ipodservice.exe (iPod Service)
* c:\program files\norton internet security\issvc.exe (ISSvc)
* c:\windows\system32\lxcjcoms.exe (lxcj_device)
* c:\windows\system32\spool\drivers\w32x86\3\\lxcjserv.exe (LXCJCustomerConnect)
* c:\program files\norton internet security\norton antivirus\navapsvc.exe (Norton AntiVirus Auto-Protect Service)
c:\windows\system32\hpzipm12.exe (Pml Driver HPZ12)
* c:\program files\norton internet security\norton antivirus\savscan.exe (SAVScan)
* c:\program files\common files\symantec shared\ccevtmgr.exe (Symantec Event Manager)
* c:\program files\common files\symantec shared\sndsrvc.exe (Symantec Network Drivers Service)
* c:\program files\common files\symantec shared\ccproxy.exe (Symantec Network Proxy)
* c:\program files\common files\symantec shared\ccpwdsvc.exe (Symantec Password Validation)
* c:\program files\common files\symantec shared\ccsetmgr.exe (Symantec Settings Manager)
* c:\program files\common files\symantec shared\spbbc\spbbcsvc.exe (Symantec SPBBCSvc)
* c:\program files\common files\symantec shared\security center\symwsc.exe (SymWMI Service)
c:\program files\viewpoint\common\viewpointservice.exe (Viewpoint Manager Service)
c:\windows\wanmpsvc.exe (WAN Miniport (ATW) Service)
c:\program files\windows media connect 2\wmccds.exe (Windows Media Connect Service)
c:\windows\system32\ypcser~1.exe (YPCService)

011 HKLM\SYSTEM\CurrentControlSet\Services (drivers)
----------------------------------------------------
* C:\WINDOWS\system32\drivers\wlanuig.sys (2Wire 802.11g USB Driver)
C:\WINDOWS\system32\drivers\mdc8021x.sys (AEGIS Protocol (IEEE 802.1x) v2.3.1.9)
* C:\WINDOWS\system32\drivers\agrsm.sys (Agere Systems Soft Modem)
- c:\docume~1\compaq~1\locals~1\temp\catchme.sys (Base)
* C:\WINDOWS\system32\drivers\ptilink.sys (Direct Parallel Link Driver)
* c:\windows\system32\drivers\symdns.sys (DNS Filter Driver)
* c:\windows\system32\drivers\symfw.sys (Firewall Filter Driver)
* C:\WINDOWS\system32\drivers\gearaspiwdm.sys (GEAR CDRom Filter)
- c:\windows\system32\drivers\hsf_cnxt.sys (hsf_cnxt.sys)
- c:\windows\system32\drivers\hsf_dp.sys (hsf_dp.sys)
- c:\windows\system32\drivers\hsfhwbs2.sys (hsfhwbs2.sys)
* c:\progra~1\common~1\symant~1\symcdata\idsdefs\20050303.027\symidsco.sys (IDS Core Driver)
* c:\windows\system32\drivers\symids.sys (IDS Filter Driver)
* C:\WINDOWS\system32\drivers\hpzid412.sys (IEEE-1284.4 Driver HPZid412)
* c:\progra~1\common~1\symant~1\virusd~1\20041117.006\naveng.sys (NAVENG)
* c:\progra~1\common~1\symant~1\virusd~1\20041117.006\navex15.sys (NAVEX15)
* c:\windows\system32\drivers\symndis.sys (NDIS Filter Driver)
* C:\WINDOWS\system32\drivers\hpzipr12.sys (Print Class Driver for IEEE-1284.4 HPZipr12)
* C:\WINDOWS\system32\drivers\ps2.sys (PS2)
C:\WINDOWS\system32\drivers\pxhelp20.sys (PxHelp20)
* C:\WINDOWS\system32\drivers\r8139n51.sys (Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver)
* c:\windows\system32\drivers\symredrv.sys (Redirector Filter Driver)
* c:\program files\norton internet security\norton antivirus\savrt.sys (SAVRT)
* c:\program files\norton internet security\norton antivirus\savrtpel.sys (SAVRTPEL)
* C:\WINDOWS\system32\drivers\secdrv.sys (Secdrv)
* C:\WINDOWS\system32\drivers\alcxwdm.sys (Service for Realtek AC97 Audio (WDM))
* C:\WINDOWS\system32\drivers\sisnic.sys (SiS PCI Fast Ethernet Adapter Driver)
- c:\windows\system32\drivers\smserial.sys (smserial.sys)
* C:\WINDOWS\system32\drivers\z520bus.sys (Sony Ericsson 520 driver (WDM))
* C:\WINDOWS\system32\drivers\z520mgmt.sys (Sony Ericsson 520 USB WMC Device Management Drivers)
* C:\WINDOWS\system32\drivers\z520mdm.sys (Sony Ericsson 520 USB WMC Modem Drivers)
* C:\WINDOWS\system32\drivers\z520mdfl.sys (Sony Ericsson 520 USB WMC Modem Filter)
* C:\WINDOWS\system32\drivers\z520obex.sys (Sony Ericsson 520 USB WMC OBEX Interface Drivers)
* c:\program files\common files\symantec shared\spbbc\spbbcdrv.sys (SPBBCDrv)
* c:\program files\symantec\symevent.sys (Symantec Event Library)
* c:\windows\system32\drivers\symtdi.sys (SYMTDI)
* C:\WINDOWS\system32\drivers\hpzius12.sys (USB to IEEE-1284.4 Translation Driver HPZius12)
* C:\WINDOWS\system32\drivers\ialmnt5.sys (Video)
* C:\WINDOWS\system32\drivers\wanatw4.sys (WAN Miniport (ATW))

030 HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
------------------------------------------
C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) {1E66F26B-79EE-11D2-8710-00C04F79ED0D}

031 HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
-------------------------------------------
c:\program files\common files\microsoft shared\information retrieval\msitss.dll (Microsoft Corporation) {0A9007C0-4076-11D3-8789-0000F8105754}

035 HKLM-HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components
------------------------------------------------------------------
c:\windows\system32\mscories.dll (Microsoft Corporation) {89B4C1CD-B018-4511-B0A1-5476DBF70820}

040 HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
------------------------------------------------------------
* c:\program files\yahoo!\companion\installs\cpn1\yt.dll (Yahoo! Inc.) {EF99BD32-C1FB-11D2-892F-0090271D4F88}

041 HKLM-HKCU\Software\Microsoft\Internet Explorer\Toolbar
----------------------------------------------------------
* c:\program files\google\googletoolbar2.dll (Google Inc.) {2318C2B1-4965-11d4-9B18-009027A5CD4F}
* c:\program files\norton internet security\norton antivirus\navshext.dll (Symantec Corporation) {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}
* c:\program files\yahoo!\companion\installs\cpn1\yt.dll (Yahoo! Inc.) {EF99BD32-C1FB-11D2-892F-0090271D4F88}

042 HKLM\Software\Microsoft\Internet Explorer\Extensions
--------------------------------------------------------
GUID / CLSID not found {4982D40A-C53B-4615-B15B-B5B5E98D167C}

045 HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
----------------------------------------------------------------
* c:\program files\google\googletoolbar2.dll (Google Inc.) {2318C2B1-4965-11D4-9B18-009027A5CD4F}
* c:\program files\norton internet security\norton antivirus\navshext.dll (Symantec Corporation) {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}
* c:\program files\yahoo!\companion\installs\cpn1\yt.dll (Yahoo! Inc.) {EF99BD32-C1FB-11D2-892F-0090271D4F88}

047 Trusted zones
-----------------
Zone: objects.aol.com : *.objects.aol.com
Zone: online.musicmatch.com : https://online.musicmatch.com

050 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
-----------------------------------------------------------------------------
c:\program files\ewido anti-malware\shellhook.dll {54D9498B-CF93-414F-8984-8CE7FDE0D391}

052 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
----------------------------------------------------------------------------------
* c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll (Adobe Systems Incorporated) {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
* c:\program files\google\googletoolbar2.dll (Google Inc.) {AA58ED58-01DD-4d91-8333-CF10577473F7}
* c:\program files\google\googletoolbarnotifier\2.0.301.7164\swg.dll (Google Inc.) {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
* c:\program files\java\jre1.6.0_01\bin\ssv.dll (Sun Microsystems, Inc.) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
* c:\program files\norton internet security\norton antivirus\navshext.dll (Symantec Corporation) {BDF3E430-B101-42AD-A544-FADC6B084872}
* c:\program files\yahoo!\companion\installs\cpn1\yt.dll (Yahoo! Inc.) {02478D38-C3F9-4EFB-9B51-7695ECA05670}

061 HKLM-HCKU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
---------------------------------------------------------------------------------
- deskpan.dll {42071714-76d4-11d1-8b24-00a0c9068ff3}
c:\windows\system32\mscoree.dll (Microsoft Corporation) {1D2680C9-0E2A-469d-B787-065558BC7D43}
* c:\windows\system32\hticons.dll (Hilgraeve, Inc.) {88895560-9AA2-1069-930E-00AA0030EBC8}
* c:\program files\itunes\itunesminiplayer.dll (Apple Inc.) {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}
c:\program files\sonic recordnow!\shlext.dll {DEE12703-6333-4D4E-8F34-738C4DCC2E04}
c:\windows\system32\shellvrtf.dll (XSS) {7F67036B-66F1-411A-AD85-759FB9C5B0DB}
c:\program files\hewlett-packard\hp share-to-web\hpgs2wns.dll (Hewlett-Packard) {A4DF5659-0801-4A60-9607-1C48695EFDA9}
c:\program files\real\realplayer\rpshell.dll (RealNetworks, Inc.) {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}
c:\windows\system32\dfshim.dll (Microsoft Corporation) {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}
c:\windows\system32\dfshim.dll (Microsoft Corporation) {e82a2d71-5b2f-43a0-97b8-81be15854de8}
c:\program files\sony ericsson\mobile\file manager\fmgrgui.dll (Sony Ericsson Mobile Communications AB) {A5110426-177D-4e08-AB3F-785F10B4439C}
* c:\program files\yahoo!\common\ymmapi.dll (Yahoo! Inc.) {5464D816-CF16-4784-B9F3-75C0DB52B499}

062 HKLM-HKCU\Software\Classes\Folder\Shellex\ColumnHandlers
------------------------------------------------------------
c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll (Adobe Systems, Inc.) {F9DB5320-233E-11D1-9F84-707F02C10627}

067 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
---------------------------------------------------------------------
* C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)

069 HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
--------------------------------------------------------
* C:\WINDOWS\system32\lxcjlmpm.dll
C:\WINDOWS\system32\ebpmon2.dll (SEIKO EPSON CORPORATION)
C:\WINDOWS\system32\ebpmon2.dll (SEIKO EPSON CORPORATION)
* C:\WINDOWS\system32\hpzsnt12.dll (HP)
C:\WINDOWS\system32\mdimon.dll (Microsoft Corporation)

073 %windir%\Tasks
------------------
AppleSoftwareUpdate.job : c:\program files\apple software update\softwareupdate.exe (Apple Inc.)
Symantec NetDetect.job : c:\program files\symantec\liveupdate\ndetect.exe (Symantec Corporation)

100 Internet Explorer settings
------------------------------
CustomizeSearch HKLM : http://ie.search.msn...st/srchcust.htm
Default_Page_URL HKLM : http://www.microsoft...p...&ar=msnhome
Default_Search_URL HKCU : http://www.microsoft...amp;ar=iesearch
Default_Search_URL HKLM : http://www.microsoft...amp;ar=iesearch
Search Page HKCU : http://www.microsoft...amp;ar=iesearch
Search Page HKLM : http://www.microsoft...amp;ar=iesearch
SearchAssistant HKLM : http://ie.search.msn...st/srchasst.htm
SearchUrl HKCU : http://home.microsof...search.asp?p=%s
Start Page HKCU : http://www.microsoft...p...&ar=msnhome
Start Page HKLM : http://www.microsoft...p...ER}&ar=home

102 HKLM - HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars
------------------------------------------------------------------
c:\program files\yahoo!\messenger\yhexbmes.dll (Yahoo! Inc.) {4528BBE0-4E08-11D5-AD55-00010333D0AD}
c:\program files\yahoo!\messenger\yhexbmes.dll (Yahoo! Inc.) {4528BBE0-4E08-11D5-AD55-00010333D0AD}

104 HKLM\Software\Microsoft\Code Store Database\Distribution Units
------------------------------------------------------------------
* c:\program files\quicktime\qtplugin.ocx (Apple Inc.) {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
c:\progra~1\citrix\icaweb32\wfica.ocx (Citrix Systems, Inc.) {238F6F83-B8B4-11CF-8771-00A024541EE3}
* c:\program files\yahoo!\common\yinsthelper.dll (Yahoo! Inc.) {30528230-99f7-4bb4-88d8-fa1d4f56a2ab}
- c:\windows\downlo~1\sysinfo.dll {49232000-16E4-426C-A231-62846947304B}
- c:\windows\downloaded program files\rufsi.dll {644E432F-49D3-41A1-8DD5-E099162EEEC5}
* c:\program files\java\jre1.6.0_01\bin\npjpi160_01.dll (Sun Microsystems, Inc.) {8AD9C840-044E-11D1-B3E9-00805F499D93}
* c:\windows\system32\macromed\download\download.dll (Adobe Systems, Inc.) {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
* c:\program files\yahoo!\common\ymmapi.dll (Yahoo! Inc.) {A17E30C4-A9BA-11D4-8673-60DB54C10000}
c:\program files\yahoo!\common\yaddbook.dll (Yahoo! Inc.) {B9191F79-5613-4C76-AA2A-398534BB8999}
- c:\windows\downloaded program files\view22rte.dll {BCBC9371-595D-11D4-A96D-00105A1CEF6C}
c:\program files\java\j2re1.4.2_03\bin\npjpi142_03.dll (JavaSoft / Sun Microsystems, Inc.) {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
c:\program files\java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.) {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
* c:\program files\java\jre1.6.0_01\bin\npjpi160_01.dll (Sun Microsystems, Inc.) {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
* c:\program files\java\jre1.6.0_01\bin\npjpi160_01.dll (Sun Microsystems, Inc.) {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
* c:\program files\yahoo!\common\yphotos.dll (Yahoo! Inc.) {D18F962A-3722-4B59-B08D-28BB9EB2281E}
* c:\windows\system32\macromed\flash\flash9c.ocx (Adobe Systems, Inc.) {D27CDB6E-AE6D-11CF-96B8-444553540000}

105 HKCU\Software\Microsoft\Internet Explorer\MenuExt
-----------------------------------------------------
Add To Compaq Organize... : C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
E&xport to Microsoft Excel : res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000

161 HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System
------------------------------------------------------------------
dontdisplaylastusername : 0
shutdownwithoutlogon : 1
undockwithoutlogon : 1

170 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
------------------------------------------------------------------------
{946850c5-1e27-11d9-baf0-806d6172696f} : D:\setup.exe
{c7eaf834-7138-11d9-a02f-806d6172696f} : C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
D : C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

173 HKCR\*\shellex\ContextMenuHandlers
--------------------------------------
GUID / CLSID not found
* c:\program files\norton internet security\norton antivirus\navshext.dll (Symantec Corporation) {5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}
* c:\program files\yahoo!\common\ymmapi.dll (Yahoo! Inc.) {5464D816-CF16-4784-B9F3-75C0DB52B499}

Attached Files


  • 0

#27
patrickg26

patrickg26

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
And here is the Kaspersky Online Scanner report...


-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, August 30, 2007 6:24:20 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 31/08/2007
Kaspersky Anti-Virus database records: 400484
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan Statistics:
Total number of scanned objects: 101596
Number of viruses found: 12
Number of infected objects: 240
Number of suspicious objects: 0
Duration of the scan process: 01:47:40

Infected Object Name / Virus Name / Last Action
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT102.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT102.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT127.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT127.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT1A6.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT1A6.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT1D9.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT1D9.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT1E3.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT1E3.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT1ED.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT1ED.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT1FA.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT1FA.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT201.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT201.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT208.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT208.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT218.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT218.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT222.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT222.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT22C.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT22C.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT233.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT233.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT23D.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT23D.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3A4.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3A4.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3AC.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3AC.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3B9.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3B9.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3CE.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3CE.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3D8.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3D8.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3DD.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3DD.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3E2.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3E2.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3EF.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3EF.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3F4.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3F4.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3F9.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3F9.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3FE.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT3FE.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT403.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT403.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT408.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT408.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT40D.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT40D.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT412.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT412.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT417.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT417.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT41C.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT41C.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT421.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT421.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT426.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT426.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT435.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT435.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT443.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT443.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT448.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT448.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT45D.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT45D.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT467.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT467.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT490.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT490.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT4A3.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT4A3.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT607.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT607.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT62E.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT62E.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT655.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT655.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT661.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT661.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT67C.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT67C.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT697.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT697.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT6B8.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT6B8.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT6C4.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT6C4.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT6C7.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT6C7.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT6F5.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT6F5.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT705.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT705.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT71A.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT71A.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT726.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT726.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT729.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT729.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT738.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT738.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT73B.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT73B.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT73E.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT73E.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT741.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT741.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT762.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT762.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT765.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT765.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT768.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT768.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT778.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT778.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT78E.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT78E.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7AE.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7AE.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7B1.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7B1.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7B4.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7B4.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7B7.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7B7.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7BD.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7BD.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7EE.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7EE.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7F1.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT7F1.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT841.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT841.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT84C.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT84C.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT856.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT856.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT879.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT879.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT8B7.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT8B7.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT8F3.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT8F3.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT924.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT924.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT92A.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT92A.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT92D.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT92D.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT93.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT93.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT930.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT930.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT933.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT933.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT964.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT964.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT974.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT974.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT97E.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT97E.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT990.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT990.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT993.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT993.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT9A.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT9A.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT9B4.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT9B4.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT9C2.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT9C2.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT9C5.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT9C5.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT9DF.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT9DF.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT9E8.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BIT9E8.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITA1.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITA1.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITA19.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITA19.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITA2B.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITA2B.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITA35.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITA35.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITA3F.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITA3F.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITAB5.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITAB5.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITB3.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITB3.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITBB.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITBB.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITBE.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITBE.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITD8.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITD8.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITE9.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITE9.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITFA.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070826124101\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITFA.tmp ZIP: infected - 1 skipped
C:\Deckard\System Scanner\20070828162018\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITAC0.tmp/ac8zt2/edi.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\Deckard\System Scanner\20070828162018\backup\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\BITAC0.tmp ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Prism\34dec74a Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\nowcq19n.default\cert8.db Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\nowcq19n.default\history.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\nowcq19n.default\key3.db Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\nowcq19n.default\parent.lock Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\nowcq19n.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\nowcq19n.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Compaq_Owner\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Compaq_Owner\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Compaq_Owner\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Documents.dfd Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Documents.did Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Documents.dsd Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.kdb Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.kdl Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.kib Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.kpf Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.ksb Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\ApplicationHistory\hpqgalry.exe.cf8dd223.ini.inuse Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\nowcq19n.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\nowcq19n.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\nowcq19n.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\nowcq19n.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Musicmatch\Jukebox\mmjbaltlog.txt Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Musicmatch\Jukebox\mmjblog.txt Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Musicmatch\Jukebox\Portables.log Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Musicmatch\MIM\Database\Default.ldb Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Musicmatch\MIM\Database\Default.mdb Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\B.tmp Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\JET672C.tmp Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\WCESLog.log Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\~DF789C.tmp Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\~DF8151.tmp Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\~DF9169.tmp Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Compaq_Owner\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\hp\bin\KillWind.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped
C:\Program Files\CA\PPRT\logs\2007-08-29.csv Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\AntiSpam\Log\Spam.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPStop.log Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\chandir.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\chandir.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\chn.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\chn.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\D0000000.FCS Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\inuse.txt Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\L0000001.FCS Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\main.log Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_die.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_die.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_dnd.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_dnd.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_ext.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_ext.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_rcv.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_rcv.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\storydb.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\storydb.idx Object is locked skipped
C:\Program Files\Hijackthis\backups\backup-20070829-132248-579.dll Infected: not-a-virus:AdWare.Win32.Agent.fh skipped
C:\Program Files\Hijackthis\backups\backup-20070829-181749-157.dll Infected: not-a-virus:AdWare.Win32.Agent.fh skipped
C:\Program Files\Hijackthis\backups\backup-20070829-190251-907.dll Infected: not-a-virus:AdWare.Win32.Agent.fh skipped
C:\Program Files\Mozilla Firefox\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP633\A0090103.dll Infected: not-a-virus:AdWare.Win32.Agent.el skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP634\A0090109.dll Infected: not-a-virus:AdWare.Win32.Agent.el skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP634\A0090153.dll Infected: not-a-virus:AdWare.Win32.Agent.el skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP635\A0090170.dll Infected: not-a-virus:AdWare.Win32.BHO.du skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP635\A0090261.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP635\A0090265.exe Infected: Trojan-Downloader.Win32.Zlob.cdd skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP636\A0090303.exe Infected: Trojan-Downloader.Win32.Zlob.cee skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP636\A0090313.dll Infected: not-a-virus:AdWare.Win32.Agent.em skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP636\A0090340.dll Infected: not-a-virus:AdWare.Win32.Agent.ff skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP636\A0090353.dll Infected: not-a-virus:AdWare.Win32.Agent.fh skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP639\A0090510.dll Infected: not-a-virus:AdWare.Win32.Agent.fh skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP639\A0090512.dll Infected: not-a-virus:AdWare.Win32.Agent.fj skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP639\A0090513.dll Infected: not-a-virus:AdWare.Win32.Agent.en skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP639\A0090522.dll Infected: not-a-virus:AdWare.Win32.Agent.fh skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP639\A0090523.dll Infected: not-a-virus:AdWare.Win32.Agent.fj skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP639\A0090524.dll Infected: not-a-virus:AdWare.Win32.Agent.fi skipped
C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP641\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\
  • 0

#28
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello Patrick, your logs are looking good! We need to do a few little things.

Download the zipped attachment at the end of this post(this will be your runscanner as fixed by me)
  • Unzip it to your desktop then double click the runscanner icon this will run the program.
  • You will notice several entries in ORANGE with a tick, right click them individually and select delete.
  • Accept the warning then repeat until they are all gone.
You now need to update your Java and remove your older versions.

Please follow these steps to remove older version Java components.

* Click Start > Control Panel.
* Click Add/Remove Programs.
* Check any item with Java Runtime Environment (JRE) in the name.
* Click the Remove or Change/Remove button.

Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
here


Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :
http://www.adobe.com.../readstep2.html


Now we need to create a new System Restore point.

Click Start Menu > Run > type (or copy and paste)

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it and click Create, when the confirmation screen shows the restore point has been created click Close.

Next goto Start Menu > Run > type

cleanmgr

Click OK, Disk Cleanup will open and start calculating the amount of space that can be freed, Once thats finished it will open the Disk Cleanup options screen, click the More Options tab then click Clean up on the system restore area and choose Yes at the confirmation window which will remove all the restore points except the one we just created.

To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.


Some clean up :

Please double-click OTMoveIt.exe to run it.
Click the Clean up button
Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
Click Yes to the reboot. Then you can delete OTMoveIt.exe and the folder C:\_OTMoveIt


Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
SpywareBlaster protects against bad ActiveX
IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all

* SpywareGuard offers realtime protection from spyware installation attempts.

* I recommend the following anti-spyware programs to protect yourself against spyware, make sure you only use one real-time anti-spyware protection program though :
AVG anti-spyware
SUPERAntiSpyware
Spybot - Search and Destroy
Ad-Aware 2007 Free

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here

Thank you for your patience, and performing all of the procedures requested.

Edited by Rorschach112, 30 August 2007 - 08:03 PM.

  • 0

#29
patrickg26

patrickg26

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
I have performed all the tasks in your last post. Comp seems to be running fine now.

Thank you so much for your time and help. You were very helpful and responded quickly. THANKS!!
  • 0

#30
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Glad I could be of help :whistling:

Good luck and enjoy your weekend !
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP