Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijack This Log


  • Please log in to reply
11 replies to this topic

#1 waynechr

waynechr

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 16 December 2007 - 02:04 PM

it is called "uptown search engine", I have followed all the above steps, my log is attached.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:53:23 AM, on 12/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\lxdccoms.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WUSB54GSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\SYSTEM32\TwcToolbarBho.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\SYSTEM32\TwcToolbarIe7.dll
O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe"
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://mypoints.worldwinner.com/games/v47/...GamesLoader.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://renowayne.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - http://www.worldwinner.com/games/v45/royal/royal.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,23/mcgdmgr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} (RockYou Image Uploader Control) - http://www.rockyou.com/RockYouImageUploader.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by106fd.bay106.hotmail.msn.com/activex/HMAtchmt.ocx
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: WUSB54GSCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

--
End of file - 10284 bytes

BC AdBot (Login to Remove)

 


#2 lusitano

lusitano

    Portuguese Malware Fighter


  • Members
  • 1,443 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Portugal

Posted 17 December 2007 - 09:15 AM

Hi, Wellcome to Bleeping Computer Forums!

You might want to save this page on your favorites, so you can find it again when you return.


Please take note of the following:
  • I will be handling your log and helping you, please do not make any system changes yet.
  • The process is not instant. Please continue to review my answers until I tell you that your computer is clean. Be patience.
  • The fixes are specific to your problem and should only be used for this issue on this machine
  • If there's anything that you don't understand, please ask your question(s) before proceeding with the fixes.
  • Please reply to this thread. Do not start a new topic.
Please give me some time to look over your log and I will get back to you as soon as possible.

:thumbsup:
Posted Image
Please do not PM me asking for support.
Please be courteous, polite, and say thank you.
Please post the final results, good or bad. We like to know!

#3 lusitano

lusitano

    Portuguese Malware Fighter


  • Members
  • 1,443 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Portugal

Posted 17 December 2007 - 11:19 AM

Hello,

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below,"if still present":

R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab

Click on Posted Image button. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



2. Please uninstall any of the following program(s) using Add/Remove Programs if they are present. To do this, go to Start > Settings > Control Panel and double-click on Add/Remove Programs. From within Add/Remove Programs highlight each one and select Remove.

SpySpotter3
Its a software of dubious repute, read more here



3. Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.



4. Please do an online scan with Kaspersky WebScanner

Click on Posted Image

You will be prompted to install an ActiveX component from Kaspersky, Click Posted Image
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on Posted Image
  • Now click on Posted Image
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click Posted Image
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post, along whit a new HijackThis log. Also let me know how i your computer its running.

Posted Image
Please do not PM me asking for support.
Please be courteous, polite, and say thank you.
Please post the final results, good or bad. We like to know!

#4 waynechr

waynechr
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 17 December 2007 - 02:32 PM

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, December 17, 2007 11:30:41 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/12/2007
Kaspersky Anti-Virus database records: 485329
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 57247
Number of viruses found: 17
Number of infected objects: 46
Number of suspicious objects: 0
Duration of the scan process: 00:40:16

Infected Object Name / Virus Name / Last Action
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\CGF1HTHS.dll Infected: Trojan-Spy.Win32.Agent.aan skipped
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\MirarDownloader_876260.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\Mirar_VC_Setup_876260_V58IE7.exe Infected: not-a-virus:AdWare.Win32.Mirar.g skipped
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\mit8.tmp/Mirar_VC_Setup_876260_V58IE7.exe Infected: not-a-virus:AdWare.Win32.Mirar.g skipped
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\mit8.tmp CAB: infected - 1 skipped
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\mit8.tmp.cab/Mirar_VC_Setup_876260_V58IE7.exe Infected: not-a-virus:AdWare.Win32.Mirar.g skipped
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\mit8.tmp.cab CAB: infected - 1 skipped
C:\Deckard\System Scanner\backup\WINDOWS\temp\fffgtt.exe/c4nn0t.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.603 skipped
C:\Deckard\System Scanner\backup\WINDOWS\temp\fffgtt.exe/mirc.ini Infected: Backdoor.IRC.Sliv.a skipped
C:\Deckard\System Scanner\backup\WINDOWS\temp\fffgtt.exe/v1r1 Infected: Backdoor.IRC.Zapchast skipped
C:\Deckard\System Scanner\backup\WINDOWS\temp\fffgtt.exe/v1r10 Infected: Backdoor.IRC.Sliv.a skipped
C:\Deckard\System Scanner\backup\WINDOWS\temp\fffgtt.exe/v1r3 Infected: Net-Worm.Win32.Randon.ar skipped
C:\Deckard\System Scanner\backup\WINDOWS\temp\fffgtt.exe/v1r5 Infected: Backdoor.IRC.Zapchast skipped
C:\Deckard\System Scanner\backup\WINDOWS\temp\fffgtt.exe/v1r6 Infected: Backdoor.IRC.Sliv.a skipped
C:\Deckard\System Scanner\backup\WINDOWS\temp\fffgtt.exe/v1r8 Infected: Backdoor.IRC.Sliv.a skipped
C:\Deckard\System Scanner\backup\WINDOWS\temp\fffgtt.exe/x Infected: Backdoor.IRC.Sliv.a skipped
C:\Deckard\System Scanner\backup\WINDOWS\temp\fffgtt.exe/island.exe Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
C:\Deckard\System Scanner\backup\WINDOWS\temp\fffgtt.exe Instyler: infected - 10 skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Prism\9c93d2a1 Object is locked skipped
C:\Documents and Settings\All Users\Documents\DESKTOP.INI Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Desktop.ini Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\PS2Trial.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Music\DESKTOP.INI Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Pictures\Desktop.ini Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\DESKTOP.INI Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Robin\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Robin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Robin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Robin\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Robin\Local Settings\History\History.IE5\MSHist012007121720071218\index.dat Object is locked skipped
C:\Documents and Settings\Robin\Local Settings\Temp\~DF95B3.tmp Object is locked skipped
C:\Documents and Settings\Robin\Local Settings\Temp\~DF9680.tmp Object is locked skipped
C:\Documents and Settings\Robin\Local Settings\Temp\~DFEDB9.tmp Object is locked skipped
C:\Documents and Settings\Robin\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Robin\My Documents\PLAY.EXE Infected: Trojan-Downloader.Win32.Agent.dzm skipped
C:\Documents and Settings\Robin\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Robin\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Robin\Shared\06 Track 6.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
C:\Documents and Settings\Robin\Shared\Eighties classic.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
C:\Documents and Settings\Robin\Shared\she is more than a memory.wm Infected: Trojan-Downloader.WMA.Wimad.m skipped
C:\found.000\dir0000.chk\aol[2].htm Object is locked skipped
C:\found.000\dir0000.chk\optn=1[1].gif Object is locked skipped
C:\found.000\dir0000.chk\spacer[1].gif Object is locked skipped
C:\Program Files\InstallShield Installation Information\{3D047C15-C859-45F7-81CE-F2681778069B}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{67BB93E2-60DD-49F5-97CB-3187BAE9D4E6}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{74FCFEA6-7447-4BDB-BFEC-FF195AA62A13}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{7B5CE976-C7A9-4E38-A7F3-6C8EF025DD8E}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{A3BC5D37-30F9-4CF7-BD5C-0DFF063E4B6D}\setup.ilg Object is locked skipped
C:\RECYCLER\S-1-5-21-3956317214-1420226831-1137632509-501\Dc1.exe Infected: Trojan.Win32.EliteBar.e skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP746\A0080561.dll Infected: not-a-virus:AdWare.Win32.Comet.bb skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP766\A0081887.dll Infected: not-a-virus:AdWare.Win32.Coupons skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP767\A0081914.dll Infected: not-a-virus:AdWare.Win32.Mirar.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP768\A0081972.dll Infected: not-a-virus:AdWare.Win32.Beginto.f skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP768\A0081973.dll Infected: not-a-virus:AdWare.Win32.Beginto.f skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0082214.exe/c4nn0t.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.603 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0082214.exe/mirc.ini Infected: Backdoor.IRC.Sliv.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0082214.exe/v1r1 Infected: Backdoor.IRC.Zapchast skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0082214.exe/v1r10 Infected: Backdoor.IRC.Sliv.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0082214.exe/v1r3 Infected: Net-Worm.Win32.Randon.ar skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0082214.exe/v1r5 Infected: Backdoor.IRC.Zapchast skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0082214.exe/v1r6 Infected: Backdoor.IRC.Sliv.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0082214.exe/v1r8 Infected: Backdoor.IRC.Sliv.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0082214.exe/x Infected: Backdoor.IRC.Sliv.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0082214.exe/island.exe Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\A0082214.exe Instyler: infected - 10 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP775\change.log Object is locked skipped
C:\WINDOWS\1-fe5e180d56ed9c233080898276c260cc.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.Beginto.f skipped
C:\WINDOWS\1-fe5e180d56ed9c233080898276c260cc.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.Beginto.f skipped
C:\WINDOWS\1-fe5e180d56ed9c233080898276c260cc.exe/stream Infected: not-a-virus:AdWare.Win32.Beginto.f skipped
C:\WINDOWS\1-fe5e180d56ed9c233080898276c260cc.exe NSIS: infected - 3 skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\distro_SelectRebatesSetup_um1001.exe Infected: Trojan-Spy.Win32.Agent.aan skipped
C:\WINDOWS\MirarDownloader_876260.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{FFF3CD0F-7631-4EC0-A840-CA40C1D9419B}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_ed8.dat Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\xz.bat Infected: Trojan.BAT.KillProc.a skipped

Scan process completed.

#5 waynechr

waynechr
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 17 December 2007 - 02:33 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:33:08 AM, on 12/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\lxdccoms.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WUSB54GSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\SYSTEM32\TwcToolbarBho.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\SYSTEM32\TwcToolbarIe7.dll
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe"
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://mypoints.worldwinner.com/games/v47/...GamesLoader.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://renowayne.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - http://www.worldwinner.com/games/v45/royal/royal.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,23/mcgdmgr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} (RockYou Image Uploader Control) - http://www.rockyou.com/RockYouImageUploader.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by106fd.bay106.hotmail.msn.com/activex/HMAtchmt.ocx
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: WUSB54GSCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

--
End of file - 10066 bytes

#6 waynechr

waynechr
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 17 December 2007 - 02:37 PM

[topic="HIJACK THIS"]HIJACK THIS LOG REPLY[/topic]
Okay I have done as instructd awaiting your reply, will check back tomorrow morning...Thanks for the help!
Wayne

#7 lusitano

lusitano

    Portuguese Malware Fighter


  • Members
  • 1,443 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Portugal

Posted 18 December 2007 - 12:51 PM

Hello,

Please empty your recicle, then download the OTMoveIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Deckard\System Scanner\backup
    C:\Documents and Settings\Robin\My Documents\PLAY.EXE
    C:\Documents and Settings\Robin\Shared\06 Track 6.wma
    C:\Documents and Settings\Robin\Shared\Eighties classic.wma
    C:\Documents and Settings\Robin\Shared\she is more than a memory.wm
    C:\WINDOWS\1-fe5e180d56ed9c233080898276c260cc.exe
    C:\WINDOWS\distro_SelectRebatesSetup_um1001.exe
    C:\WINDOWS\MirarDownloader_876260.exe
    C:\xz.bat


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply, along with a new HijackThis log.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Regards
Posted Image
Please do not PM me asking for support.
Please be courteous, polite, and say thank you.
Please post the final results, good or bad. We like to know!

#8 waynechr

waynechr
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 18 December 2007 - 12:51 PM

still waiting for help, thanks
Wayne, Reno, Nv

#9 waynechr

waynechr
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 18 December 2007 - 01:50 PM

OKAY HERE IS MY MOVE IT

C:\Deckard\System Scanner\backup\WINDOWS\temp\BullGuard moved successfully.
C:\Deckard\System Scanner\backup\WINDOWS\temp\brwsrlogs moved successfully.
C:\Deckard\System Scanner\backup\WINDOWS\temp\2wswlog moved successfully.
C:\Deckard\System Scanner\backup\WINDOWS\temp moved successfully.
C:\Deckard\System Scanner\backup\WINDOWS\Downloaded Program Files moved successfully.
C:\Deckard\System Scanner\backup\WINDOWS moved successfully.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~fbebc55d98d1c4e067229a3000?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~fbebc55d98d1c4e067229a3000?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~fad5e939439b1c510aeb2cc1400?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~fad5e939439b1c510aeb2cc1400?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~facc24cf8dc2761c64ac956190500?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~facc24cf8dc2761c64ac956190500?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~fa9e8257e6a9361c806a9ac54800?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~fa9e8257e6a9361c806a9ac54800?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~fa7d4cbbd1d51c56e91e159d000?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~fa7d4cbbd1d51c56e91e159d000?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~fa428014cfa1c631defa640f00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~fa428014cfa1c631defa640f00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~f9d6eec6129021c513c1d69a9d00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~f9d6eec6129021c513c1d69a9d00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~f980eb874e5641c420318cbe8900?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~f980eb874e5641c420318cbe8900?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~f580eb864690f1c420318defb600?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~f580eb864690f1c420318defb600?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~f2c3d38b12571c4eafd4779b300?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~f2c3d38b12571c4eafd4779b300?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~f0e399c9f0501c4e4bca49db500?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~f0e399c9f0501c4e4bca49db500?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~eef400171735f1c5e43ac8eae300?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~eef400171735f1c5e43ac8eae300?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~eee82387d891c7e05de01e2200?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~eee82387d891c7e05de01e2200?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~ed6b3e92da9a1c7e05e17f0e00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~ed6b3e92da9a1c7e05e17f0e00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e9413192c5c461c527326736100?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e9413192c5c461c527326736100?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e935ca92611f1c5777b2c6dc000?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e935ca92611f1c5777b2c6dc000?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e6d5e9393ff71c510aeb2cc1400?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e6d5e9393ff71c510aeb2cc1400?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e6337c8236af1c5bd773fdaf800?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e6337c8236af1c5bd773fdaf800?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e4e561e2199d91c7dc5571a02500?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e4e561e2199d91c7dc5571a02500?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e4e561cc1bd6b1c7dc5572d15200?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e4e561cc1bd6b1c7dc5572d15200?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e36b3e929f91c7e05df6c47900?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e36b3e929f91c7e05df6c47900?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e11506d7d5d3f1c4eb85396f7500?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e11506d7d5d3f1c4eb85396f7500?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e07f3e8e6da41c5589c5ee2ee00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~e07f3e8e6da41c5589c5ee2ee00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~df44cce47461c54eca700a2300?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~df44cce47461c54eca700a2300?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~da0220bc17cab1c4e4bc55f01b00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~da0220bc17cab1c4e4bc55f01b00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~d87a097a2b7f1c5d151ac1c0200?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~d87a097a2b7f1c5d151ac1c0200?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~d65689ab15f981c4e4bcbb440c00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~d65689ab15f981c4e4bcbb440c00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~d3c444dcaa81c63b19163dae00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~d3c444dcaa81c63b19163dae00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~d0d5530f51f481c7e05e6b97b300?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~d0d5530f51f481c7e05e6b97b300?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~cf80eb86b0a9e1c420318defb600?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~cf80eb86b0a9e1c420318defb600?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~cd9f36538dc2761c635eec3329b00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~cd9f36538dc2761c635eec3329b00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~c6f2be929b27b1c822161d85ec00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~c6f2be929b27b1c822161d85ec00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~c4d556d48be21c80256cd9b2900?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~c4d556d48be21c80256cd9b2900?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~c1d533bf11b361c7fc65a1cfe000?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~c1d533bf11b361c7fc65a1cfe000?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~c15610b646801c5a34a66f27400?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~c15610b646801c5a34a66f27400?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~c0e291e16a7e1c5672e8ce68000?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~c0e291e16a7e1c5672e8ce68000?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~c06780f0155a1c631df136cc000?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~c06780f0155a1c631df136cc000?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~ba7d4cb4a8641c56e91e28afd00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~ba7d4cb4a8641c56e91e28afd00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~b56b3e9274901c7e05df926d300?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~b56b3e9274901c7e05df926d300?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~b46005c6f591c63b19163dae00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~b46005c6f591c63b19163dae00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~b43a1dc367851c7ecfe4366b000?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~b43a1dc367851c7ecfe4366b000?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~b3ac2cbcf0071c5589c7dd1900?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~b3ac2cbcf0071c5589c7dd1900?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~b01b0918170d91c5632e23313500?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~b01b0918170d91c5632e23313500?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~ae6418b281071c80256ab091000?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~ae6418b281071c80256ab091000?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~abf50138ae241c5589c5ee2ee00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~abf50138ae241c5589c5ee2ee00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~ab07913dfef1c80c3889396100?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~ab07913dfef1c80c3889396100?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~aafda0f1b43c1c7dab82ef51600?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~aafda0f1b43c1c7dab82ef51600?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~a9f1a399d561c80c388b9bbb00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~a9f1a399d561c80c388b9bbb00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~a983f8b795311c5589ca4072000?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~a983f8b795311c5589ca4072000?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~a380eb87704d61c420318defb600?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~a380eb87704d61c420318defb600?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~9ecd83f1815c1c512462f452b00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~9ecd83f1815c1c512462f452b00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~9ce9380112401c580eb2072ee00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~9ce9380112401c580eb2072ee00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~9c8e4a08133311c63e96aae83900?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~9c8e4a08133311c63e96aae83900?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~9ba97c887a91c52731ce6c1e00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~9ba97c887a91c52731ce6c1e00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~95d2a4891416a1c4e4bc4a045900?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~95d2a4891416a1c4e4bc4a045900?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~94b078e62d5d61c510af8bc21200?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~94b078e62d5d61c510af8bc21200?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~90fa9d1715f9361c7f73cafa0d500?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~90fa9d1715f9361c7f73cafa0d500?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~8e0ea8c09877e1c806a8aefabf00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~8e0ea8c09877e1c806a8aefabf00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~8a1b098b15d4e1c5632dc766ac00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~8a1b098b15d4e1c5632dc766ac00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~88cd83de56f41c5124fd8dcea00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~88cd83de56f41c5124fd8dcea00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~8380eb8758e3f1c420318defb600?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~8380eb8758e3f1c420318defb600?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~812e299d30691c5c3d7bf03a800?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~812e299d30691c5c3d7bf03a800?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~7ecdf6a773041c51246f063a500?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~7ecdf6a773041c51246f063a500?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~76fc9a1843811c8025770ec3e00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~76fc9a1843811c8025770ec3e00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~72d57a081c2e1c510bc9931c900?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~72d57a081c2e1c510bc9931c900?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~727baf54101ac11c53e5a53924200?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~727baf54101ac11c53e5a53924200?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~6d5fd14187d1c5d36e5ec8ac00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~6d5fd14187d1c5d36e5ec8ac00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~6d5fbc410531c580e675f8cc00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~6d5fbc410531c580e675f8cc00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~6c641bc597131c5589bf98efd00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~6c641bc597131c5589bf98efd00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~6b7e72c012b8f1c5589c32c76d00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~6b7e72c012b8f1c5589c32c76d00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~6b4f15f1a7531c5589c74581800?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~6b4f15f1a7531c5589c74581800?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~68636670d901c80c3889396100?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~68636670d901c80c3889396100?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~67c4278535d1c5c2f8cf912100?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~67c4278535d1c5c2f8cf912100?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~64e561e21d4eb1c7dc5571a02500?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~64e561e21d4eb1c7dc5571a02500?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~64bc523edc0361c81d6afc7f5000?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~64bc523edc0361c81d6afc7f5000?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~5fdf865e71441c5130a464d5100?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~5fdf865e71441c5130a464d5100?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~5e719de31fe3e1c5aa5c461dd300?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~5e719de31fe3e1c5aa5c461dd300?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~580105fd6a6f1c7ebe950de4600?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~580105fd6a6f1c7ebe950de4600?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~53cc1d38f811c63b1926ee2400?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~53cc1d38f811c63b1926ee2400?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~5380eb86a512b1c420318defb600?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~5380eb86a512b1c420318defb600?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~531506ca11ee2e1c4eb852197f100?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~531506ca11ee2e1c4eb852197f100?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~4d3192feb76e1c7e05e3be8ab00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~4d3192feb76e1c7e05e3be8ab00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~4c0eb714feb1c631df3ac38d00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~4c0eb714feb1c631df3ac38d00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~4ad5e933474f1c510aeb19ae700?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~4ad5e933474f1c510aeb19ae700?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~4ab10a82a2ac01c7fc751c542c00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~4ab10a82a2ac01c7fc751c542c00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~48dab4cf143651c4e4bc93ed3f00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~48dab4cf143651c4e4bc93ed3f00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~3cee23281f0181c4e4bc78823400?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~3cee23281f0181c4e4bc78823400?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~381b2963934761c801e5f20aed00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~381b2963934761c801e5f20aed00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~35dab2fc55441c5589c20e5ca00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~35dab2fc55441c5589c20e5ca00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~30afce133ba61c5a34aaae57900?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~30afce133ba61c5a34aaae57900?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~2f79105211ee3e1c4ef082c95ad00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~2f79105211ee3e1c4ef082c95ad00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~2da8657b398bc1c4eb8960c84100?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~2da8657b398bc1c4eb8960c84100?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~29bf00f7c7d811c7fc75460d5300?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~29bf00f7c7d811c7fc75460d5300?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~2986d0a7ef71c803ce59839100?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~2986d0a7ef71c803ce59839100?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~22cd457912de1c7f1711dfbfb00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~22cd457912de1c7f1711dfbfb00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~220a7e1dc6dc1c56e91e159d000?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~220a7e1dc6dc1c56e91e159d000?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~1e428014ccc1c631defa640f00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~1e428014ccc1c631defa640f00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~1d9251bde26b1c7e05dcd0b5200?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~1d9251bde26b1c7e05dcd0b5200?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~18bf36701139121c7fc76c1233900?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~18bf36701139121c7fc76c1233900?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~16f21a19b4b41c7e05de7453000?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~16f21a19b4b41c7e05de7453000?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~138b6c52946e1c8069c355cd400?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~138b6c52946e1c8069c355cd400?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~13192eb52eb01c7e05e620e4b00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~13192eb52eb01c7e05e620e4b00?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~113192e593181c7e05e2b383500?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~113192e593181c7e05e2b383500?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~10d45712d5b21c80c24892f6600?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~10d45712d5b21c80c24892f6600?d scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~107913ce9e1c80c388a6a8e00?g scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\~107913ce9e1c80c388a6a8e00?d scheduled to be moved on reboot.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\{a3bc5d37-30f9-4cf7-bd5c-0dff063e4b6d} moved successfully.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\ymsgr5 scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\ymsgr4 scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\ymsgr3 scheduled to be moved on reboot.
Folder move failed. C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\ymsgr2 scheduled to be moved on reboot.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\Yahoo!\install moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\Yahoo! moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\WPDNSE moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\w3c-cache moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\VBE moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\TileCache\Raster\Process moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\TileCache\Raster moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\TileCache moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\services\preferences\ver1_2_0_0 moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\services\preferences moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\services\notification\ver3_5_0_0 moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\services\notification moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\services\miniXML\ver1_1_1_0 moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\services\miniXML moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\services\localStorage\ver3_0_0_0 moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\services\localStorage moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\services\htmlRenderer\ver0_9_13 moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\services\htmlRenderer moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\services\compression\ver1_1_3_0 moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\services\compression moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\services moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\ppsdown moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\msoclip1\01 moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\msoclip1 moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\McDMTemp007 moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\LxThumbs\C\Documents and Settings\Robin\My Documents\My Pictures moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\LxThumbs\C\Documents and Settings\Robin\My Documents moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\LxThumbs\C\Documents and Settings\Robin moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\LxThumbs\C\Documents and Settings moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\LxThumbs\C moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\LxThumbs moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\ImageUploader_Temp moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\hsperfdata_Robin moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\Google Toolbar moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\FrontPageTempDir moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\Adobe Reader 8 moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\Adobe\Online Services moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\Adobe\Acrobat moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp\Adobe moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1\Temp moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin\LOCALS~1 moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1\Robin moved successfully.
C:\Deckard\System Scanner\backup\DOCUME~1 moved successfully.
C:\Deckard\System Scanner\backup moved successfully.
C:\Documents and Settings\Robin\My Documents\PLAY.EXE moved successfully.
C:\Documents and Settings\Robin\Shared\06 Track 6.wma moved successfully.
C:\Documents and Settings\Robin\Shared\Eighties classic.wma moved successfully.
C:\Documents and Settings\Robin\Shared\she is more than a memory.wm moved successfully.
C:\WINDOWS\1-fe5e180d56ed9c233080898276c260cc.exe moved successfully.
C:\WINDOWS\distro_SelectRebatesSetup_um1001.exe moved successfully.
C:\WINDOWS\MirarDownloader_876260.exe moved successfully.
C:\xz.bat moved successfully.

Created on 12/18/2007 10:47:42


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:49:38 AM, on 12/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\lxdccoms.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WUSB54GSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\SYSTEM32\TwcToolbarBho.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\SYSTEM32\TwcToolbarIe7.dll
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe"
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://mypoints.worldwinner.com/games/v47/...GamesLoader.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://renowayne.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - http://www.worldwinner.com/games/v45/royal/royal.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,23/mcgdmgr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} (RockYou Image Uploader Control) - http://www.rockyou.com/RockYouImageUploader.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by106fd.bay106.hotmail.msn.com/activex/HMAtchmt.ocx
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: WUSB54GSCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

--
End of file - 10066 bytes

#10 lusitano

lusitano

    Portuguese Malware Fighter


  • Members
  • 1,443 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Portugal

Posted 19 December 2007 - 05:37 AM

Hello,
  • Double click OTMoveIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If you receive a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet, please allow it to do so.

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE)6 Update 3...allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Read the License Agreement and then check the box that says: "Accept License Agreement". The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.
Please post a new HijackThis log and let me know how your computer its running now.
Posted Image
Please do not PM me asking for support.
Please be courteous, polite, and say thank you.
Please post the final results, good or bad. We like to know!

#11 waynechr

waynechr
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 19 December 2007 - 12:06 PM

Ok here is my HJT Thanks, and by the way that uptown search engine no longer popping up every ten minutes, thanks again, system running great...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:04:49 AM, on 12/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\lxdccoms.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WUSB54GSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\SYSTEM32\TwcToolbarBho.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\SYSTEM32\TwcToolbarIe7.dll
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe"
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://mypoints.worldwinner.com/games/v47/...GamesLoader.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://renowayne.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - http://www.worldwinner.com/games/v45/royal/royal.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,23/mcgdmgr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} (RockYou Image Uploader Control) - http://www.rockyou.com/RockYouImageUploader.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by106fd.bay106.hotmail.msn.com/activex/HMAtchmt.ocx
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: WUSB54GSCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

--
End of file - 10443 bytes

#12 lusitano

lusitano

    Portuguese Malware Fighter


  • Members
  • 1,443 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Portugal

Posted 27 December 2007 - 04:51 AM

Hi,

Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below,"if still present":

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com

Click on Posted Image button. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.




Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply, along with a new HijackThis log.
  • Click Close to exit the program.

Posted Image
Please do not PM me asking for support.
Please be courteous, polite, and say thank you.
Please post the final results, good or bad. We like to know!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users