Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan Found - Lose Desktop Background - Internet Explorer Crashes


  • This topic is locked This topic is locked
16 replies to this topic

#1 gramsay

gramsay

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:11:50 PM

Posted 12 August 2007 - 09:16 AM

Hello All,

My name is Gary and am new to this forum but I am computer savvy.

However I am stumped with these trojans and malware of late.

It all started when I was searching for a crack/serial for a program.

All these pop-ups occured about anti-spyware, etc.

However I cancelled these pop-ups and did not download the software.

Here are my symptoms:

1) PC is slow to boot after Windows XP Home Edition splash screen
2) Norton antivirus detects and removes trojans
3) Adware detects trojans
4) Spybot detects trojans
5) Internet explorer keeps crashing

I have removed these trojans in both safe mode and real mode and
the problem keeps coming back.

Im starting to think that the problem is an infected Internet Explorer,
but then again I could be wrong.

Thanks in advance,
Gary :thumbsup:

========================================================================

Posted Image

Posted Image

Posted Image


========================================================================
Logfile of HijackThis v1.99.1
Scan saved at 10:15:08 AM, on 8/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Dell AIO Printer A960\dlbfbmgr.exe
C:\Program Files\Dell AIO Printer A960\dlbfbmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
C:\Program Files\BearShare\BearShare.exe
C:\Program Files\Opera\Opera.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://login.passport.net/uilogin.srf?id=2
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: (no name) - {6D55F78D-57E0-7A56-9975-02E12506D1B4} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: XBTP01621 - {F6104497-54FD-4688-9162-5115CC8AB0FB} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file)
O4 - HKLM\..\Run: [Dell AIO Printer A960] "C:\Program Files\Dell AIO Printer A960\dlbfbmgr.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mp4: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.dotphoto.com/ImageUploader4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\iwhlpapi.dll (file missing)
O20 - Winlogon Notify: eeadadade - C:\WINDOWS\system32\eeadadade.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: ShellCompatibility - C:\WINDOWS\system32\mutext40.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winrnt32 - C:\WINDOWS\SYSTEM32\winrnt32.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\qiijdghv.exe (file missing)
O23 - Service: IAA Event Monitor (IAANTMon) - Intel - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NPDOR File Monitor Service (NFMService) - Unknown owner - C:\WINDOWS\System32\NPDORNT.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

BC AdBot (Login to Remove)

 


#2 gramsay

gramsay
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:11:50 PM

Posted 13 August 2007 - 02:55 AM

Hello all,

Things may have improved since IE has not crashed for a full day now.

Im not sure if I fixed the spyware/malware problems.

Thanks,
GR

#3 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:05:50 AM

Posted 13 August 2007 - 03:57 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum gramsay :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".
This will change from what we know in 2006 read this article:
http://www.clickz.com/news/article.php/3561546

You are well advised to remove the program now.
Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present:

Viewpoint
Viewpoint Manager
Viewpoint Media Player


Then restart your pc.
---------------------------------------------------

Download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#4 gramsay

gramsay
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:11:50 PM

Posted 15 August 2007 - 07:28 PM

Hello RichieUK,

You have been very helpful.

I got rid of Viewpoint program.

I installed and ran ComboFix program.

Here are the logs:

================================================================

ComboFix 07-08-15.3 - "GARY" 2007-08-15 19:33:12.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.427 [GMT -4:00]


(((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))


Granting SeDebugPrivilege to Administrators ... successful


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\GARY\APPLIC~1.\macromedia\Flash Player\#SharedObjects\3G96EKZH\www.broadcaster.com
C:\DOCUME~1\GARY\APPLIC~1.\macromedia\Flash Player\#SharedObjects\3G96EKZH\www.broadcaster.com\played_list.sol
C:\DOCUME~1\GARY\APPLIC~1.\macromedia\Flash Player\#SharedObjects\3G96EKZH\www.broadcaster.com\video_queue.sol
C:\DOCUME~1\GARY\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\DOCUME~1\GARY\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\DOCUME~1\GARY\MYDOCU~1.\racle~1
C:\DOCUME~1\GARY\MYDOCU~1.\racle~1\?racle\
C:\DOCUME~1\GARY\MYDOCU~1.\racle~1\rundll.exe
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\SpamBlockerUtility.log
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1.sdf
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1951543.sdf
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2208948.sdf
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\890068.sdf
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\ASPL1.dat
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\domains.txt
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\hstat\3533.dat
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\2021
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25469
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\26656
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\35047
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43377
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\4382
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44882
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44883
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44885
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\45654
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\54189
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\614571
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64517
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\72123
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\73670
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\90358
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\93899
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\94407
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\99795
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\ustat\3533.dat
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\ads.cdf
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\btntrans.idx
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\btntrans1.dat
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\business_promo.htm
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\buttondir.txt
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\components.cdf
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_1000.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_2000.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_3000.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_bar.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_bbar1.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_logos.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_other.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_weather.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\default.cdf
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz1.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz10.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz11.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz12.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz13.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz14.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz15.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz16.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz17.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz18.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz19.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz2.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz20.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz3.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz4.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz5.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz6.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz7.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz8.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz9.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_categorize.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_comparison.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_em_PROFL_CA_flow_b_IEB.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_explorer-Mails.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_explorer-people.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_fastutilities.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_favorites.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_Games.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_Hide.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_hotbarcom.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_Hotmail.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_hsskin.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_jemster.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_jemsterie.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_jemsteruk.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_jobsearch.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_Mails.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_new.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_premium.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_reun.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_ringtones.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_SearchBoxTrapper.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_searchfor.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_searchgo.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_weather.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_yellowpages.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\email-def-511724-9595.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\email-t1-bg.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\hotbar-premium-hotbar-premium.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\hotbar-premium.cdf
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\hotbar_promo.htm
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\icons2.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\keywords.idx
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\keywords1.dat
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\layout.cdf
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\linkpathlegal.txt
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\progress.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\s_icons_buttons.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\sales_buttons.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\t2_bg.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\theweb.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\top7.cdf
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Top7_theweb.mnu
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\tsd_bg.res
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\ads.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\BtnTrans.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\BtnTrans1.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\business_promo.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\buttondir.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_1000.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_2000.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_3000.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_bar.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_bbar1.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_logos.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_other.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_weather.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\default.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\email-t1-bg.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\hotbar-premium.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\hotbar_promo.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\icons2.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\keywords.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\keywords1.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\layout.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\linkpathlegal.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\progress.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\s_icons_buttons.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\sales_buttons.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\samplegroups2.txt
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\samplegroups2.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\t2_bg.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\top7.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\tsd_bg.xip
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility_Icons
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility_Icons\Registryrepair.ico
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility_Icons\Software_Online_8.ico
C:\DOCUME~1\IVY\APPLIC~1\SpamBlockerUtility_Icons\wallpapere1.ico
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlocker
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\SpamBlockerUtility.log
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1049983.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1055597.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1055998.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1056061.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1059014.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1390343.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\165295.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2415670.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2884323.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\315066.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3423589.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3757882.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3859864.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\396933.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\413102.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\543827.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\625696.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\662116.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\819382.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\880604.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\890068.sdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\ASPL1.dat
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\domains.txt
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\hstat\3533.dat
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\11091
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\117970
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\11891
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\13546
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\13624
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\13914
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\146936
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15040
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\17025
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\17040
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\19650
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\2021
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20570
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\21668
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\21669
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\22353
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\22657
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\23111
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\23147
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25469
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25708
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\26185
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\26664
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\27505
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\29115
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32242
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\33137
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\33697
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\34140
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\34237
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\35000
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\35047
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\36598
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\38742
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\39947
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\39972
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\40256
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41526
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41928
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41940
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41999
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43638
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\4382
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43907
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44228
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44293
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44458
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44484
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44557
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44878
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\45833
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\47914
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\48964
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\50905
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\51988
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\52253
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\541369
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\54189
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\54469
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\54473
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\565392
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\59987
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\60739
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\61627
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64404
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64424
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64484
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64517
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\66836
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\67491
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\68019
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\68021
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6873
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\727607
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744753
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745340
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\751223
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\7521
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\753009
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\78592
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\7887
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\79257
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\7946
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\81830
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\82292
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\83216
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\83706
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\83732
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\8443
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\85064
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\85083
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\85547
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\86146
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\86379
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87215
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87555
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\88104
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\90358
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\9313
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\93682
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\93899
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\93911
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\94407
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95610
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95615
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95704
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\97734
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\98060
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\98395
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\ustat\3533.dat
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\ads.cdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\btntrans.idx
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\btntrans1.dat
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\business_promo.htm
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\buttondir.txt
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\components.cdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_1000.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_2000.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_3000.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_bar.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_bbar1.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_logos.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_other.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_weather.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\default.cdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz1.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz10.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz11.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz12.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz13.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz14.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz15.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz16.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz17.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz18.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz19.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz2.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz20.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz3.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz4.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz5.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz6.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz7.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz8.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz9.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_categorize.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_comparison.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_em_PROFL_CA_flow_b_IEB.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_explorer-Mails.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_explorer-people.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_fastutilities.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_favorites.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_Games.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_Hide.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_hotbarcom.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_Hotmail.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_hsskin.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_jemster.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_jemsterie.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_jemsteruk.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_jobsearch.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_Mails.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_new.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_premium.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_reun.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_ringtones.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_SearchBoxTrapper.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_searchfor.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_searchgo.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_weather.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_yellowpages.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\email-def-511724-9595.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\email-t1-bg.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\hotbar-premium-hotbar-premium.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\hotbar-premium.cdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\hotbar_promo.htm
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\icons2.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\keywords.idx
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\keywords1.dat
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\layout.cdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\linkpathlegal.txt
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\progress.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\s_icons_buttons.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\sales_buttons.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\t2_bg.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\theweb.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\top7.cdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Top7_theweb.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\tsd_bg.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\ads.cdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\btntrans.idx
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\btntrans1.dat
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\business_promo.htm
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\buttondir.txt
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\components.cdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_1000.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_2000.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_3000.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_bar.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_bbar1.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_logos.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_other.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_weather.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\default.cdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz1.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz10.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz11.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz12.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz13.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz14.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz15.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz16.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz17.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz18.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz19.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz2.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz20.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz3.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz4.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz5.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz6.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz7.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz8.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz9.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_categorize.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_comparison.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_em_PROFL_CA_flow_b_IEB.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_explorer-Mails.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_explorer-people.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_fastutilities.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_favorites.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_Games.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_Hide.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_hotbarcom.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_Hotmail.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_hsskin.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_jemster.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_jemsterie.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_jemsteruk.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_jobsearch.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_Mails.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_new.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_premium.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_reun.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_ringtones.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_SearchBoxTrapper.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_searchfor.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_searchgo.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_weather.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_yellowpages.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\email-def-511724-9595.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\email-t1-bg.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\hotbar-premium-hotbar-premium.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\hotbar-premium.cdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\hotbar_promo.htm
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\icons2.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\keywords.idx
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\keywords1.dat
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\layout.cdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\linkpathlegal.txt
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\progress.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\s_icons_buttons.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\sales_buttons.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\t2_bg.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\theweb.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\top7.cdf
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Top7_theweb.mnu
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\tsd_bg.res
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\ads.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\BtnTrans.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\BtnTrans1.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\business_promo.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\buttondir.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_1000.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_2000.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_3000.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_bar.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_bbar1.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_logos.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_other.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_weather.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\default.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\email-t1-bg.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\hotbar-premium.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\hotbar_promo.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\icons2.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\keywords.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\keywords1.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\layout.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\linkpathlegal.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\progress.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\s_icons_buttons.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\sales_buttons.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\samplegroups2.txt
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\samplegroups2.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\t2_bg.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\top7.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\tsd_bg.xip
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility_Icons
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility_Icons\Registryrepair.ico
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility_Icons\Software_Online_8.ico
C:\DOCUME~1\ROYES_~1\APPLIC~1\SpamBlockerUtility_Icons\wallpapere1.ico
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\Program Files\ini.ini\
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe
C:\Program Files\winupdates
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\WINDOWS\Casino.ico
C:\WINDOWS\Free Online Dating.ico
C:\WINDOWS\hosts
C:\WINDOWS\system32\A1
C:\WINDOWS\SYSTEM32\acbeg.bak1
C:\WINDOWS\SYSTEM32\acbeg.bak2
C:\WINDOWS\SYSTEM32\acbeg.ini
C:\WINDOWS\SYSTEM32\acbeg.ini2
C:\WINDOWS\SYSTEM32\acbeg.tmp
C:\WINDOWS\system32\B1
C:\WINDOWS\system32\configs
C:\WINDOWS\system32\configs\y909.exe
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f10WtR
C:\WINDOWS\SYSTEM32\jlnmp.bak1
C:\WINDOWS\SYSTEM32\jlnmp.ini
C:\WINDOWS\system32\pmnlj.dll
C:\WINDOWS\system32\pppatc~1
C:\WINDOWS\system32\pppatc~1\w?auclt.exe
C:\WINDOWS\system32\win
C:\WINDOWS\system32\winrnt32.dll
C:\WINDOWS\system32\wnsinti.exe
C:\WINDOWS\system32\wnsintsv.exe
C:\WINDOWS\system32\X2


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_DOMAINSERVICE
-------\LEGACY_IPRIP
-------\Iprip


((((((((((((((((((((((((( Files Created from 2007-07-15 to 2007-08-15 )))))))))))))))))))))))))))))))


2007-08-15 19:31 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-15 14:08 153,088 --a------ C:\WINDOWS\SYSTEM32\gln.exe
2007-08-15 13:13 43,542 --a------ C:\WINDOWS\SYSTEM32\urqrppo.dll
2007-08-15 11:10 43,542 --a------ C:\WINDOWS\SYSTEM32\khfddef.dll
2007-08-15 09:58 <DIR> d-------- C:\211c7dd7aaf1e4f755d9
2007-08-15 01:16 0 --a------ C:\WINDOWS\SYSTEM32\tuvwxus.dll
2007-08-14 14:28 141,312 --------- C:\WINDOWS\SYSTEM32\gln.dll
2007-08-14 13:30 <DIR> d-------- C:\DECCHECK
2007-08-14 11:47 <DIR> d-------- C:\Program Files\AviSynth 2.5
2007-08-14 10:52 <DIR> d-------- C:\divx
2007-08-14 10:09 <DIR> d-------- C:\Program Files\AC3Filter
2007-08-14 09:46 <DIR> d-------- C:\Program Files\DVD Decrypter
2007-08-14 09:31 <DIR> d-------- C:\CHINCONN
2007-08-14 09:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-08-14 09:26 <DIR> d-------- C:\Program Files\DVD Shrink
2007-08-14 09:08 <DIR> d-------- C:\Program Files\Google
2007-08-12 16:29 <DIR> d-------- C:\DOCUME~1\GARY\APPLIC~1\DivX
2007-08-12 16:27 9,464 --------- C:\WINDOWS\SYSTEM32\DRIVERS\cdralw2k.sys
2007-08-12 16:27 9,336 --------- C:\WINDOWS\SYSTEM32\DRIVERS\cdr4_xp.sys
2007-08-12 16:27 129,784 --------- C:\WINDOWS\SYSTEM32\pxafs.dll
2007-08-12 15:53 <DIR> d-------- C:\DOCUME~1\ROYES_~1\APPLIC~1\Intuit
2007-08-12 15:44 82,501 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bckg.dll
2007-08-12 15:44 780,885 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\chkrres.dll
2007-08-12 15:44 753,236 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\rvseres.dll
2007-08-12 15:44 66,113 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\shvl.dll
2007-08-12 15:44 57,409 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hrtz.dll
2007-08-12 15:44 48,706 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\rvse.dll
2007-08-12 15:44 42,577 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bckgzm.exe
2007-08-12 15:44 42,575 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\chkrzm.exe
2007-08-12 15:44 42,574 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\rvsezm.exe
2007-08-12 15:44 42,573 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\shvlzm.exe
2007-08-12 15:44 42,573 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hrtzzm.exe
2007-08-12 15:44 41,029 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zcorem.dll
2007-08-12 15:44 40,515 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\chkr.dll
2007-08-12 15:44 4,677 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zeeverm.dll
2007-08-12 15:44 36,937 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zclientm.exe
2007-08-12 15:44 32,339 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\uniansi.dll
2007-08-12 15:44 29,760 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\znetm.dll
2007-08-12 15:44 217,160 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cmnclim.dll
2007-08-12 15:44 2,178,131 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\shvlres.dll
2007-08-12 15:44 18,944 --a------ C:\WINDOWS\SYSTEM32\simptcp.dll
2007-08-12 15:44 18,944 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\simptcp.dll
2007-08-12 15:44 13,894 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zonelibm.dll
2007-08-12 15:44 13,312 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\htrn_jis.dll
2007-08-12 15:44 113,222 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zoneclim.dll
2007-08-12 15:44 1,817,687 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bckgres.dll
2007-08-12 15:44 1,175,635 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hrtzres.dll
2007-08-12 15:44 1,039,955 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cmnresm.dll
2007-08-12 15:28 138,752 --a------ C:\WINDOWS\SYSTEM32\sndvol32.exe
2007-08-12 15:28 138,752 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\sndvol32.exe
2007-08-12 14:53 <DIR> d-------- C:\Program Files\Jasc Software Inc
2007-08-12 14:29 446,464 -ra------ C:\WINDOWS\SYSTEM32\hhactivex.dll
2007-08-12 14:29 176,128 --a------ C:\WINDOWS\SYSTEM32\RcdScan.dll
2007-08-12 12:33 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Citrix
2007-08-12 11:20 <DIR> d-------- C:\Program Files\a-squared Anti-Malware
2007-08-12 08:26 <DIR> d-------- C:\Program Files\BearShare
2007-08-12 08:07 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-08-12 08:07 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-08-12 07:15 <DIR> d-------- C:\VundoFix Backups
2007-08-11 20:44 1,242 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-08-11 20:09 6,760 ---hs---- C:\WINDOWS\SYSTEM32\qpqss.ini2
2007-08-11 20:04 <DIR> d-------- C:\Program Files\RogueRemover FREE
2007-08-11 19:59 6,421 ---hs---- C:\WINDOWS\SYSTEM32\qpqss.bak1
2007-08-11 19:59 231,520 --a------ C:\WINDOWS\SYSTEM32\ssqpq.dll.vir
2007-08-11 19:53 31,254 --a------ C:\WINDOWS\SYSTEM32\byxxxxx.dll.vir
2007-08-11 19:09 92,062,544 --a------ C:\xps08112007.reg
2007-08-11 18:08 <DIR> d-------- C:\HijackThis
2007-08-11 17:18 <DIR> d-------- C:\Program Files\msn gaming zone
2007-08-11 15:30 552 --a------ C:\WINDOWS\SYSTEM32\d3d8caps.dat
2007-08-11 13:06 118,288 --------- C:\WINDOWS\SYSTEM32\eeadadade.dll
2007-08-11 06:47 93,952 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwcwdm.sys
2007-08-11 06:47 72,832 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwbwdm.sys
2007-08-11 06:47 50,176 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyyport.sys
2007-08-11 06:47 49,792 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyzport.sys
2007-08-11 06:47 48,640 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwrwdm.sys
2007-08-11 06:47 3,584 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwcosnt5.sys
2007-08-11 06:47 3,072 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwbmidi.sys
2007-08-11 06:47 3,072 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwbase.sys
2007-08-11 06:47 28,672 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyycoins.dll
2007-08-11 06:47 27,648 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyzports.dll
2007-08-11 06:47 27,648 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyyports.dll
2007-08-11 06:47 27,136 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyzcoins.dll
2007-08-11 06:47 17,152 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyclad-z.sys
2007-08-11 06:47 14,848 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyclom-y.sys
2007-08-11 06:47 117,760 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\d100ib5.sys
2007-08-11 06:47 111,872 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwcspud.sys
2007-08-11 06:46 96,256 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctlsb16.sys
2007-08-11 06:46 60,970 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cpqtrnd5.sys
2007-08-11 06:46 6,912 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctlfacem.sys
2007-08-11 06:46 57,399 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cplexe.exe
2007-08-11 06:46 42,112 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\crtaud.sys
2007-08-11 06:46 4,096 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctwdm32.dll
2007-08-11 06:46 3,712 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctljystk.sys
2007-08-11 06:46 249,856 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctmasetp.dll
2007-08-11 06:46 216,064 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cpscan.dll
2007-08-11 06:46 21,533 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cpqndis5.sys
2007-08-11 06:46 18,944 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cprofile.exe
2007-08-11 06:46 175,104 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\csamsp.dll
2007-08-11 06:45 9,344 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\compbatt.sys
2007-08-11 06:45 44,032 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cnusd.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-15 19:59 --------- d-------- C:\Program Files\Symantec AntiVirus
2007-08-14 09:08 --------- d-------- C:\Program Files\DivX
2007-08-13 07:43 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-12 15:44 --------- d-------- C:\Program Files\Windows NT
2007-08-12 14:59 --------- d-------- C:\Program Files\Creative
2007-08-12 14:53 --------- d-------- C:\Program Files\Dell Computer
2007-08-12 11:29 --------- d-------- C:\Program Files\Zinio
2007-08-12 11:29 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\ContentGuard
2007-08-12 11:28 --------- d-------- C:\Program Files\Viewpoint
2007-08-12 09:46 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\gtk-2.0
2007-08-12 08:25 --------- d-------- C:\Program Files\Lavasoft
2007-08-12 08:18 9344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-08-12 08:18 8320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-12 02:11 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\Creative
2007-08-11 19:21 --------- d-------- C:\Program Files\RegScrubXP
2007-08-10 04:07 149 --a------ C:\Program Files\ini.ini
2007-08-04 09:06 1972 --a------ C:\Program Files\installer.js
2007-08-03 18:47 --------- d-------- C:\Program Files\eFax Messenger Plus 3.3
2007-08-01 16:19 --------- d-------- C:\Program Files\America Online 9.0
2007-07-25 22:53 43528 --------- C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-07-25 22:53 120056 -----c--- C:\WINDOWS\system32\pxcpyi64.exe
2007-07-25 22:53 118520 -----c--- C:\WINDOWS\system32\pxinsi64.exe
2007-07-14 18:45 --------- d-------- C:\Program Files\MSN Messenger
2007-07-14 18:04 --------- d-------- C:\Program Files\AIM
2007-07-03 17:18 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\MSN6
2007-06-29 22:53 --------- d-------- C:\Program Files\Opera
2007-06-28 23:15 --------- d-------- C:\Program Files\CARCare
2007-06-28 23:15 --------- d-------- C:\Program Files\Automotive Wolf
2007-06-28 23:10 --------- d-------- C:\Program Files\CramMaster
2007-06-28 22:44 --------- d-------- C:\Program Files\Seagate Software
2007-06-28 21:57 --------- d-------- C:\Program Files\Market Research Wizard
2007-06-26 11:13 851968 --a------ C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 10:35 665600 --a------ C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-26 02:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-26 02:08 1104896 --a------ C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 09:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-19 09:31 282112 --a------ C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-18 18:44 --------- d-------- C:\Program Files\GIMP-2.0
2007-06-18 18:43 --------- d-------- C:\Program Files\Common Files\GTK
2007-06-15 04:12 96256 --a------ C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-15 04:12 616960 --a------ C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-15 04:12 55808 --a------ C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-15 04:12 532480 --a------ C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-15 04:12 474112 --a------ C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-15 04:12 449024 --a------ C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-15 04:12 39424 --a------ C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-15 04:12 357888 --a------ C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-15 04:12 3064320 --a------ C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-15 04:12 251904 --a------ C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-15 04:12 205824 --a------ C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-15 04:12 16384 --a------ C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-15 04:12 151040 --a------ C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-15 04:12 1498112 --a------ C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-15 04:12 146432 --a------ C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-15 04:12 1054208 --a------ C:\WINDOWS\system32\dllcache\danim.dll
2007-06-15 04:12 1022976 --a------ C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 06:32 18432 --a------ C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 06:23 1033216 --a------ C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 06:23 1033216 --a------ C:\WINDOWS\explorer.exe
2007-05-17 07:28 549376 --a------ C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-05-17 07:28 549376 --------- C:\WINDOWS\system32\oleaut32.dll
2007-05-16 11:12 86528 --a------ C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 --a------ C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 --a------ C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 --a------ C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 --a------ C:\WINDOWS\system32\dllcache\msoe.dll
2005-09-10 22:34 774144 --a--c--- C:\Program Files\RngInterstitial.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{57D6708C-88E2-4CAB-9FA4-78BB8CA3A3C4}]
2007-08-15 11:10 43542 --a------ C:\WINDOWS\system32\khfddef.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6674BE31-150F-435E-B54C-D1975AD8B382}]
C:\WINDOWS\system32\awvtu.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D55F78D-57E0-7A56-9975-02E12506D1B4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4E7CAAB-6535-4243-99BD-F12350B584A2}]
2007-08-14 14:28 141312 --------- C:\WINDOWS\system32\gln.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 22:49]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CamTray.exe" [2005-03-29 02:13]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

C:\Documents and Settings\ROYES_RAMSAY\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57D6708C-88E2-4CAB-9FA4-78BB8CA3A3C4}"= C:\WINDOWS\system32\khfddef.dll [2007-08-15 11:10 43542]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\eeadadade]
C:\WINDOWS\system32\eeadadade.dll 2007-08-11 13:06 118288 C:\WINDOWS\SYSTEM32\eeadadade.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khfddef]
khfddef.dll 2007-08-15 11:10 43542 C:\WINDOWS\SYSTEM32\khfddef.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Live Menu 3.3.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Tray Menu 3.3.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^GARY^Start Menu^Programs^Startup^Morpheus.lnk]
path=C:\Documents and Settings\GARY\Start Menu\Programs\Startup\Morpheus.lnk
backup=C:\WINDOWS\pss\Morpheus.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^GARY^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^GARY^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\GARY\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^GARY^Start Menu^Programs^Startup^TickerBar.lnk]
backup=C:\WINDOWS\pss\TickerBar.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aida]
"C:\DOCUME~1\GARY\MYDOCU~1\RACLE~1\rundll.exe" -vt yazb

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
"C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearFlix]
"C:\Program Files\BearFlix\BearFlix.exe" /pause

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
"C:\Program Files\BearShare\BearShare.exe" /pause

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Consumer Input]
C:\Program Files\Consumer Input\ConsumerInput.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Consumer Input Update]
C:\Program Files\Consumer Input\ConsumerInputUa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ejqlkj]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\elodaf]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\erurwdyj]
rundll32.exe "C:\Program Files\uduzytax\adalyvst.dll",Init

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FineReader7NewsReaderPro]
"C:\Program Files\ABBYY FineReader 7.0 Professional Edition\ABBYYNewsReader.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GreenHorseTickerBar]
C:\Documents and Settings\GARY\TickerBar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hti]
C:\npdor\npdor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Magicantispy]
C:\Program Files\Magicantispy\Magicantispy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetMeter]
C:\PROGRA~1\NETRAT~1\NetMeter\NetMeter.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PD0630 STISvc]
RunDLL32.exe P0630Pin.dll,RunDLL32EP 513

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
"C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SB Audigy 2 Startup Menu]
/L:ENG

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SC2]
C:\Program Files\SecCenter\scprot4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyKiller]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
"C:\Program Files\Spy Sweeper\SpySweeper.exe" /startintray

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe "C:\WINDOWS\system32\uyukgjey.dll",forkonce

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WD Button Manager]
WDBtnMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebBuying]
C:\Program Files\Web Buying\v1.8.1\webbuying.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]
C:\Windows\xpupdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zinio DLM]
C:\PROGRA~1\Zinio\ZDLM.exe /hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zzz_ImInstaller_IncrediMail]

C:\DOCUME~1\GARY\LOCALS~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{DB-B1-14-44-ZN}]
c:\windows\system32\lkdsrngm.exe CHD003

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"svcWRSSSDK"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
"Dell AIO Printer A960"="C:\Program Files\Dell AIO Printer A960\dlbfbmgr.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"smgr"=mgrs.exe

R0 NPDORFM;NPDOR File Monitor;C:\WINDOWS\system32\Drivers\NPDORFM.sys
R3 P0630VID;Creative WebCam Live!;C:\WINDOWS\system32\DRIVERS\P0630Vid.sys
R3 vidcap;vidcap;C:\WINDOWS\system32\DRIVERS\vidcap.sys
S3 FastLynx;FastLynx;\??\C:\Program Files\FastLynx\FastLynx.sys
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\System32\svchost.exe -k p2psvc
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\System32\svchost.exe -k p2psvc
S3 p2psvc;Peer Networking;C:\WINDOWS\System32\svchost.exe -k p2psvc
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\System32\svchost.exe -k p2psvc
S3 SQLAgent$MICROSOFTBCM;SQLAgent$MICROSOFTBCM;C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlagent.EXE -i MICROSOFTBCM

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc p2psvc p2pimsvc p2pgasvc PNRPSvc


Contents of the 'Scheduled Tasks' folder
2006-10-16 18:18:55 C:\WINDOWS\Tasks\RegCure.job - C:\Program Files\RegCure\RegCure.exe
2007-08-15 19:00:00 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job - C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
2005-08-27 08:01:26 C:\WINDOWS\Tasks\XoftSpy.job - C:\Program Files\XoftSpy\XoftSpy.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-15 20:00:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

**************************************************************************

Completion time: 2007-08-15 20:05:26 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-15 20:04

--- E O F ---
================================================================

Logfile of HijackThis v1.99.1
Scan saved at 20:25, on 2007-08-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\lexpps.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://login.passport.net/uilogin.srf?id=2
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file)
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mp4: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.dotphoto.com/ImageUploader4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NPDOR File Monitor Service (NFMService) - Unknown owner - C:\WINDOWS\System32\NPDORNT.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

#5 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:05:50 AM

Posted 16 August 2007 - 07:46 AM

Copy and paste ALL the following blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\SYSTEM32\gln.exe
C:\WINDOWS\SYSTEM32\urqrppo.dll
C:\WINDOWS\SYSTEM32\khfddef.dll
C:\WINDOWS\SYSTEM32\tuvwxus.dll
C:\WINDOWS\SYSTEM32\gln.dll
C:\WINDOWS\SYSTEM32\qpqss.ini2
C:\WINDOWS\SYSTEM32\qpqss.bak1
C:\WINDOWS\SYSTEM32\ssqpq.dll.vir
C:\WINDOWS\SYSTEM32\byxxxxx.dll.vir

Folder::
C:\Program Files\Viewpoint

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{57D6708C-88E2-4CAB-9FA4-78BB8CA3A3C4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6674BE31-150F-435E-B54C-D1975AD8B382}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D55F78D-57E0-7A56-9975-02E12506D1B4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4E7CAAB-6535-4243-99BD-F12350B584A2}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57D6708C-88E2-4CAB-9FA4-78BB8CA3A3C4}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\eeadadade]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khfddef]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aida]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Consumer Input Update]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ejqlkj]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\elodaf]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\erurwdyj]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Magicantispy]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebBuying]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{DB-B1-14-44-ZN}]

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Posted Image
Posted Image

#6 gramsay

gramsay
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:11:50 PM

Posted 17 August 2007 - 08:30 AM

Hello Richie UK,

Thanks for your help so far.

Before you requested the info,
I thought I fixed the problem by running:

AdAware 2007
a-squared Free
Spybot

then hours later I got popups to fake antispyware websites

So I still have some problems.

Here is the requested info:

==============================================================================


ComboFix 07-08-15.3 - "GARY" 2007-08-17 8:42:11.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.595 [GMT -4:00]
Command switches used :: C:\Documents and Settings\GARY\Desktop\CFScript.txt

FILE::
C:\WINDOWS\SYSTEM32\gln.exe
C:\WINDOWS\SYSTEM32\urqrppo.dll
C:\WINDOWS\SYSTEM32\khfddef.dll
C:\WINDOWS\SYSTEM32\tuvwxus.dll
C:\WINDOWS\SYSTEM32\gln.dll
C:\WINDOWS\SYSTEM32\qpqss.ini2
C:\WINDOWS\SYSTEM32\qpqss.bak1
C:\WINDOWS\SYSTEM32\ssqpq.dll.vir
C:\WINDOWS\SYSTEM32\byxxxxx.dll.vir


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\ini.ini\
C:\Program Files\Viewpoint
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream_0305000D.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\ComponentMgr_0305000D.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\ComponentRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\AtmoHWConfig.txt
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\atmosphere.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\AvatarsDefault.prf
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\BlueStreak.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\BookmarksDefault.prf
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\DefaultAvatarIcon.jpg
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\DefaultWorldIcon.jpg
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\ExtremeShot.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\InternetChatHelp.url
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\JpegReader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\LensFlares.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\Mts2Reader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\Mts3Reader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\ObjectMovie.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SceneComponent.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\ServiceComponent.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SWFView.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VectorView.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VETsdk.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMgr.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPVideo.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\WaveletReader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\ZoomView.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\DownloadedComponents\atmosphere_Win\AtmoHWConfig.txt
C:\Program Files\Viewpoint\Viewpoint Media Player\DownloadedComponents\atmosphere_Win\AvatarsDefault.prf
C:\Program Files\Viewpoint\Viewpoint Media Player\DownloadedComponents\atmosphere_Win\BookmarksDefault.prf
C:\Program Files\Viewpoint\Viewpoint Media Player\DownloadedComponents\atmosphere_Win\DefaultAvatarIcon.jpg
C:\Program Files\Viewpoint\Viewpoint Media Player\DownloadedComponents\atmosphere_Win\DefaultWorldIcon.jpg
C:\Program Files\Viewpoint\Viewpoint Media Player\DownloadedComponents\atmosphere_Win\InternetChatHelp.url
C:\Program Files\Viewpoint\Viewpoint Media Player\DownloadedComponents\VMgr_Win\Exec.exe
C:\Program Files\Viewpoint\Viewpoint Media Player\DownLoadHist.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\HostRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MetaStreamConfig.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Media Player\MTSDownloadSites.txt
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\AtmoHWConfig.txt
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\AvatarsDefault.prf
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\BookmarksDefault.prf
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\Cursors.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\DefaultAvatarIcon.jpg
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\DefaultWorldIcon.jpg
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\InternetChatHelp.url
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\SreeDMMX.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\VMPVideo2.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.xpt
C:\WINDOWS\SYSTEM32\byxxxxx.dll.vir
C:\WINDOWS\system32\eeee2c37031a15be62a6db8572e1327c.TMP
C:\WINDOWS\system32\eeee461fcdaab5d33655ab2995d38df1.TMP
C:\WINDOWS\system32\eeeeb0c81f94deeea45d2326b3ff16fc.TMP
C:\WINDOWS\SYSTEM32\ffhkj.bak1
C:\WINDOWS\SYSTEM32\ffhkj.ini2
C:\WINDOWS\SYSTEM32\ffhkj.tmp
C:\WINDOWS\SYSTEM32\gln.dll
C:\WINDOWS\SYSTEM32\gln.exe
C:\WINDOWS\system32\jkhff.dll
C:\WINDOWS\SYSTEM32\khfddef.dll
C:\WINDOWS\SYSTEM32\qpqss.bak1
C:\WINDOWS\SYSTEM32\qpqss.ini2
C:\WINDOWS\SYSTEM32\ssqpq.dll.vir
C:\WINDOWS\SYSTEM32\tuvwxus.dll
C:\WINDOWS\SYSTEM32\urqrppo.dll


((((((((((((((((((((((((( Files Created from 2007-07-17 to 2007-08-17 )))))))))))))))))))))))))))))))


2007-08-17 02:18 <DIR> d-------- C:\DOCUME~1\GARY\APPLIC~1\ABBYY
2007-08-15 19:31 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-14 13:30 <DIR> d-------- C:\DECCHECK
2007-08-14 11:47 <DIR> d-------- C:\Program Files\AviSynth 2.5
2007-08-14 10:52 <DIR> d-------- C:\divx
2007-08-14 10:09 <DIR> d-------- C:\Program Files\AC3Filter
2007-08-14 09:46 <DIR> d-------- C:\Program Files\DVD Decrypter
2007-08-14 09:31 <DIR> d-------- C:\CHINCONN
2007-08-14 09:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-08-14 09:26 <DIR> d-------- C:\Program Files\DVD Shrink
2007-08-14 09:08 <DIR> d-------- C:\Program Files\Google
2007-08-12 16:29 <DIR> d-------- C:\DOCUME~1\GARY\APPLIC~1\DivX
2007-08-12 16:27 9,464 --------- C:\WINDOWS\SYSTEM32\DRIVERS\cdralw2k.sys
2007-08-12 16:27 9,336 --------- C:\WINDOWS\SYSTEM32\DRIVERS\cdr4_xp.sys
2007-08-12 16:27 129,784 --------- C:\WINDOWS\SYSTEM32\pxafs.dll
2007-08-12 15:53 <DIR> d-------- C:\DOCUME~1\ROYES_~1\APPLIC~1\Intuit
2007-08-12 15:44 82,501 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bckg.dll
2007-08-12 15:44 780,885 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\chkrres.dll
2007-08-12 15:44 753,236 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\rvseres.dll
2007-08-12 15:44 66,113 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\shvl.dll
2007-08-12 15:44 57,409 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hrtz.dll
2007-08-12 15:44 48,706 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\rvse.dll
2007-08-12 15:44 42,577 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bckgzm.exe
2007-08-12 15:44 42,575 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\chkrzm.exe
2007-08-12 15:44 42,574 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\rvsezm.exe
2007-08-12 15:44 42,573 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\shvlzm.exe
2007-08-12 15:44 42,573 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hrtzzm.exe
2007-08-12 15:44 41,029 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zcorem.dll
2007-08-12 15:44 40,515 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\chkr.dll
2007-08-12 15:44 4,677 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zeeverm.dll
2007-08-12 15:44 36,937 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zclientm.exe
2007-08-12 15:44 32,339 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\uniansi.dll
2007-08-12 15:44 29,760 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\znetm.dll
2007-08-12 15:44 217,160 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cmnclim.dll
2007-08-12 15:44 2,178,131 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\shvlres.dll
2007-08-12 15:44 18,944 --a------ C:\WINDOWS\SYSTEM32\simptcp.dll
2007-08-12 15:44 18,944 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\simptcp.dll
2007-08-12 15:44 13,894 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zonelibm.dll
2007-08-12 15:44 13,312 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\htrn_jis.dll
2007-08-12 15:44 113,222 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zoneclim.dll
2007-08-12 15:44 1,817,687 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bckgres.dll
2007-08-12 15:44 1,175,635 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hrtzres.dll
2007-08-12 15:44 1,039,955 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cmnresm.dll
2007-08-12 15:28 138,752 --a------ C:\WINDOWS\SYSTEM32\sndvol32.exe
2007-08-12 15:28 138,752 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\sndvol32.exe
2007-08-12 14:53 <DIR> d-------- C:\Program Files\Jasc Software Inc
2007-08-12 14:29 446,464 -ra------ C:\WINDOWS\SYSTEM32\hhactivex.dll
2007-08-12 14:29 176,128 --a------ C:\WINDOWS\SYSTEM32\RcdScan.dll
2007-08-12 12:33 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Citrix
2007-08-12 11:20 <DIR> d-------- C:\Program Files\a-squared Anti-Malware
2007-08-12 08:26 <DIR> d-------- C:\Program Files\BearShare
2007-08-12 08:07 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-08-12 08:07 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-08-12 07:15 <DIR> d-------- C:\VundoFix Backups
2007-08-11 20:44 1,242 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-08-11 20:04 <DIR> d-------- C:\Program Files\RogueRemover FREE
2007-08-11 19:09 92,062,544 --a------ C:\xps08112007.reg
2007-08-11 18:08 <DIR> d-------- C:\HijackThis
2007-08-11 17:18 <DIR> d-------- C:\Program Files\msn gaming zone
2007-08-11 15:30 552 --a------ C:\WINDOWS\SYSTEM32\d3d8caps.dat
2007-08-11 13:06 118,288 --------- C:\WINDOWS\SYSTEM32\eeadadade.dll
2007-08-11 06:47 93,952 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwcwdm.sys
2007-08-11 06:47 72,832 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwbwdm.sys
2007-08-11 06:47 50,176 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyyport.sys
2007-08-11 06:47 49,792 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyzport.sys
2007-08-11 06:47 48,640 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwrwdm.sys
2007-08-11 06:47 3,584 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwcosnt5.sys
2007-08-11 06:47 3,072 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwbmidi.sys
2007-08-11 06:47 3,072 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwbase.sys
2007-08-11 06:47 28,672 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyycoins.dll
2007-08-11 06:47 27,648 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyzports.dll
2007-08-11 06:47 27,648 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyyports.dll
2007-08-11 06:47 27,136 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyzcoins.dll
2007-08-11 06:47 17,152 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyclad-z.sys
2007-08-11 06:47 14,848 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyclom-y.sys
2007-08-11 06:47 117,760 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\d100ib5.sys
2007-08-11 06:47 111,872 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwcspud.sys
2007-08-11 06:46 96,256 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctlsb16.sys
2007-08-11 06:46 60,970 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cpqtrnd5.sys
2007-08-11 06:46 6,912 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctlfacem.sys
2007-08-11 06:46 57,399 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cplexe.exe
2007-08-11 06:46 42,112 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\crtaud.sys
2007-08-11 06:46 4,096 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctwdm32.dll
2007-08-11 06:46 3,712 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctljystk.sys
2007-08-11 06:46 249,856 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctmasetp.dll
2007-08-11 06:46 216,064 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cpscan.dll
2007-08-11 06:46 21,533 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cpqndis5.sys
2007-08-11 06:46 18,944 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cprofile.exe
2007-08-11 06:46 175,104 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\csamsp.dll
2007-08-11 06:45 9,344 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\compbatt.sys
2007-08-11 06:45 44,032 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cnusd.dll
2007-08-11 06:45 39,936 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cnxt1803.sys
2007-08-11 06:44 91,264 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cirrus.dll
2007-08-11 06:44 480,256 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cintsetp.exe
2007-08-11 06:44 45,696 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cirrus.sys
2007-08-11 06:44 248,064 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cl546xm.sys
2007-08-11 06:44 20,736 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cmbp0wdm.sys
2007-08-11 06:44 170,880 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cl546x.dll
2007-08-11 06:44 14,080 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cmbatt.sys
2007-08-11 06:44 111,232 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cl5465.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-17 08:56 --------- d-------- C:\Program Files\Symantec AntiVirus
2007-08-17 02:32 --------- d-------- C:\Program Files\Common Files\AOL
2007-08-17 02:26 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\AOL
2007-08-17 02:20 --------- d-------- C:\Program Files\Common Files\aolshare
2007-08-15 09:11 --------- d-------- C:\Program Files\Lavasoft
2007-08-14 09:08 --------- d-------- C:\Program Files\DivX
2007-08-13 07:43 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-12 15:44 --------- d-------- C:\Program Files\Windows NT
2007-08-12 14:59 --------- d-------- C:\Program Files\Creative
2007-08-12 14:53 --------- d-------- C:\Program Files\Dell Computer
2007-08-12 11:29 --------- d-------- C:\Program Files\Zinio
2007-08-12 11:29 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\ContentGuard
2007-08-12 09:46 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\gtk-2.0
2007-08-12 08:18 9344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-08-12 08:18 8320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-12 02:11 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\Creative
2007-08-11 19:21 --------- d-------- C:\Program Files\RegScrubXP
2007-08-10 04:07 149 --a------ C:\Program Files\ini.ini
2007-08-04 09:06 1972 --a------ C:\Program Files\installer.js
2007-08-03 18:47 --------- d-------- C:\Program Files\eFax Messenger Plus 3.3
2007-08-01 16:19 --------- d-------- C:\Program Files\America Online 9.0
2007-07-25 22:53 43528 --------- C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-07-25 22:53 120056 -----c--- C:\WINDOWS\system32\pxcpyi64.exe
2007-07-25 22:53 118520 -----c--- C:\WINDOWS\system32\pxinsi64.exe
2007-07-14 18:45 --------- d-------- C:\Program Files\MSN Messenger
2007-07-14 18:04 --------- d-------- C:\Program Files\AIM
2007-07-03 17:18 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\MSN6
2007-06-29 22:53 --------- d-------- C:\Program Files\Opera
2007-06-28 23:15 --------- d-------- C:\Program Files\CARCare
2007-06-28 23:15 --------- d-------- C:\Program Files\Automotive Wolf
2007-06-28 23:10 --------- d-------- C:\Program Files\CramMaster
2007-06-28 22:44 --------- d-------- C:\Program Files\Seagate Software
2007-06-28 21:57 --------- d-------- C:\Program Files\Market Research Wizard
2007-06-26 11:13 851968 --a--c--- C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 10:35 665600 --a--c--- C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-26 02:08 1104896 --a--c--- C:\WINDOWS\system32\msxml3.dll
2007-06-26 02:08 1104896 --a--c--- C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 09:31 282112 --a--c--- C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-19 09:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-18 18:44 --------- d-------- C:\Program Files\GIMP-2.0
2007-06-18 18:43 --------- d-------- C:\Program Files\Common Files\GTK
2007-06-15 04:12 96256 --a--c--- C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-15 04:12 616960 --a--c--- C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-15 04:12 55808 --a--c--- C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-15 04:12 532480 --a--c--- C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-15 04:12 474112 --a--c--- C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-15 04:12 449024 --a--c--- C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-15 04:12 39424 --a--c--- C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-15 04:12 357888 --a--c--- C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-15 04:12 3064320 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-15 04:12 251904 --a--c--- C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-15 04:12 205824 --a--c--- C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-15 04:12 16384 --a--c--- C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-15 04:12 151040 --a--c--- C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-15 04:12 1498112 --a--c--- C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-15 04:12 146432 --a--c--- C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-15 04:12 1054208 --a--c--- C:\WINDOWS\system32\dllcache\danim.dll
2007-06-15 04:12 1022976 --a--c--- C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 06:32 18432 --a--c--- C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 06:23 1033216 --a------ C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 06:23 1033216 --a------ C:\WINDOWS\explorer.exe
2007-05-17 07:28 549376 --a--c--- C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-05-17 07:28 549376 --------- C:\WINDOWS\system32\oleaut32.dll
2005-09-10 22:34 774144 --a--c--- C:\Program Files\RngInterstitial.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2007-07-17 09:49]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\Program Files\AIM\aim.exe" [2005-08-05 16:08]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

C:\Documents and Settings\GARY\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\eeadadade]
C:\WINDOWS\system32\eeadadade.dll 2007-08-11 13:06 118288 C:\WINDOWS\SYSTEM32\eeadadade.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Live Menu 3.3.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Tray Menu 3.3.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^GARY^Start Menu^Programs^Startup^Morpheus.lnk]
path=C:\Documents and Settings\GARY\Start Menu\Programs\Startup\Morpheus.lnk
backup=C:\WINDOWS\pss\Morpheus.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^GARY^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^GARY^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\GARY\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^GARY^Start Menu^Programs^Startup^TickerBar.lnk]
backup=C:\WINDOWS\pss\TickerBar.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
"C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearFlix]
"C:\Program Files\BearFlix\BearFlix.exe" /pause

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
"C:\Program Files\BearShare\BearShare.exe" /pause

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Consumer Input]
C:\Program Files\Consumer Input\ConsumerInput.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FineReader7NewsReaderPro]
"C:\Program Files\ABBYY FineReader 7.0 Professional Edition\ABBYYNewsReader.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GreenHorseTickerBar]
C:\Documents and Settings\GARY\TickerBar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hti]
C:\npdor\npdor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetMeter]
C:\PROGRA~1\NETRAT~1\NetMeter\NetMeter.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PD0630 STISvc]
RunDLL32.exe P0630Pin.dll,RunDLL32EP 513

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
"C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SB Audigy 2 Startup Menu]
/L:ENG

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SC2]
C:\Program Files\SecCenter\scprot4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyKiller]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
"C:\Program Files\Spy Sweeper\SpySweeper.exe" /startintray

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WD Button Manager]
WDBtnMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zinio DLM]
C:\PROGRA~1\Zinio\ZDLM.exe /hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zzz_ImInstaller_IncrediMail]

C:\DOCUME~1\GARY\LOCALS~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"svcWRSSSDK"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AIM"=C:\Program Files\AIM\aim.exe -cnetwait.odl
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CamTray.exe"
"msnmsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
"Dell AIO Printer A960"="C:\Program Files\Dell AIO Printer A960\dlbfbmgr.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"smgr"=mgrs.exe

R3 P0630VID;Creative WebCam Live!;C:\WINDOWS\system32\DRIVERS\P0630Vid.sys
R3 vidcap;vidcap;C:\WINDOWS\system32\DRIVERS\vidcap.sys
S0 NPDORFM;NPDOR File Monitor;C:\WINDOWS\system32\Drivers\NPDORFM.sys
S3 FastLynx;FastLynx;\??\C:\Program Files\FastLynx\FastLynx.sys
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\System32\svchost.exe -k p2psvc
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\System32\svchost.exe -k p2psvc
S3 p2psvc;Peer Networking;C:\WINDOWS\System32\svchost.exe -k p2psvc
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\System32\svchost.exe -k p2psvc
S3 SQLAgent$MICROSOFTBCM;SQLAgent$MICROSOFTBCM;C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlagent.EXE -i MICROSOFTBCM

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc p2psvc p2pimsvc p2pgasvc PNRPSvc


Contents of the 'Scheduled Tasks' folder
2006-10-16 18:18:55 C:\WINDOWS\Tasks\RegCure.job - C:\Program Files\RegCure\RegCure.exe
2007-08-16 19:00:00 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job - C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
2005-08-27 08:01:26 C:\WINDOWS\Tasks\XoftSpy.job - C:\Program Files\XoftSpy\XoftSpy.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-17 09:12:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

**************************************************************************

Completion time: 2007-08-17 9:18:38 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-17 09:18

--- E O F ---


===============================================================================

Logfile of HijackThis v1.99.1
Scan saved at 9:26:15 AM, on 8/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\notepad.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://login.passport.net/uilogin.srf?id=2
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: XBTP01621 - {F6104497-54FD-4688-9162-5115CC8AB0FB} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file)
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mp4: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.dotphoto.com/ImageUploader4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: eeadadade - C:\WINDOWS\system32\eeadadade.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NPDOR File Monitor Service (NFMService) - Unknown owner - C:\WINDOWS\System32\NPDORNT.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

#7 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:05:50 AM

Posted 17 August 2007 - 08:57 AM

Copy and paste ALL the following blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\SYSTEM32\eeadadade.dll
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\eeadadade]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SC2]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyKiller]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"smgr"=-

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Posted Image
Posted Image

#8 gramsay

gramsay
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:11:50 PM

Posted 17 August 2007 - 09:50 AM

Hello Again,

Thanks again.

Here is the requested logs:

===============================================================================

ComboFix 07-08-15.3 - "GARY" 2007-08-17 10:03:39.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.508 [GMT -4:00]
Command switches used :: C:\Documents and Settings\GARY\Desktop\CFScript.txt

FILE::
C:\WINDOWS\SYSTEM32\eeadadade.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\ini.ini\
C:\WINDOWS\SYSTEM32\eeadadade.dll


((((((((((((((((((((((((( Files Created from 2007-07-17 to 2007-08-17 )))))))))))))))))))))))))))))))


2007-08-17 02:18 <DIR> d-------- C:\DOCUME~1\GARY\APPLIC~1\ABBYY
2007-08-15 19:31 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-14 13:30 <DIR> d-------- C:\DECCHECK
2007-08-14 11:47 <DIR> d-------- C:\Program Files\AviSynth 2.5
2007-08-14 10:52 <DIR> d-------- C:\divx
2007-08-14 10:09 <DIR> d-------- C:\Program Files\AC3Filter
2007-08-14 09:46 <DIR> d-------- C:\Program Files\DVD Decrypter
2007-08-14 09:31 <DIR> d-------- C:\CHINCONN
2007-08-14 09:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-08-14 09:26 <DIR> d-------- C:\Program Files\DVD Shrink
2007-08-14 09:08 <DIR> d-------- C:\Program Files\Google
2007-08-12 16:29 <DIR> d-------- C:\DOCUME~1\GARY\APPLIC~1\DivX
2007-08-12 16:27 9,464 --------- C:\WINDOWS\SYSTEM32\DRIVERS\cdralw2k.sys
2007-08-12 16:27 9,336 --------- C:\WINDOWS\SYSTEM32\DRIVERS\cdr4_xp.sys
2007-08-12 16:27 129,784 --------- C:\WINDOWS\SYSTEM32\pxafs.dll
2007-08-12 15:53 <DIR> d-------- C:\DOCUME~1\ROYES_~1\APPLIC~1\Intuit
2007-08-12 15:44 82,501 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bckg.dll
2007-08-12 15:44 780,885 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\chkrres.dll
2007-08-12 15:44 753,236 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\rvseres.dll
2007-08-12 15:44 66,113 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\shvl.dll
2007-08-12 15:44 57,409 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hrtz.dll
2007-08-12 15:44 48,706 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\rvse.dll
2007-08-12 15:44 42,577 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bckgzm.exe
2007-08-12 15:44 42,575 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\chkrzm.exe
2007-08-12 15:44 42,574 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\rvsezm.exe
2007-08-12 15:44 42,573 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\shvlzm.exe
2007-08-12 15:44 42,573 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hrtzzm.exe
2007-08-12 15:44 41,029 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zcorem.dll
2007-08-12 15:44 40,515 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\chkr.dll
2007-08-12 15:44 4,677 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zeeverm.dll
2007-08-12 15:44 36,937 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zclientm.exe
2007-08-12 15:44 32,339 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\uniansi.dll
2007-08-12 15:44 29,760 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\znetm.dll
2007-08-12 15:44 217,160 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cmnclim.dll
2007-08-12 15:44 2,178,131 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\shvlres.dll
2007-08-12 15:44 18,944 --a------ C:\WINDOWS\SYSTEM32\simptcp.dll
2007-08-12 15:44 18,944 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\simptcp.dll
2007-08-12 15:44 13,894 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zonelibm.dll
2007-08-12 15:44 13,312 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\htrn_jis.dll
2007-08-12 15:44 113,222 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\zoneclim.dll
2007-08-12 15:44 1,817,687 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bckgres.dll
2007-08-12 15:44 1,175,635 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hrtzres.dll
2007-08-12 15:44 1,039,955 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cmnresm.dll
2007-08-12 15:28 138,752 --a------ C:\WINDOWS\SYSTEM32\sndvol32.exe
2007-08-12 15:28 138,752 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\sndvol32.exe
2007-08-12 14:53 <DIR> d-------- C:\Program Files\Jasc Software Inc
2007-08-12 14:29 446,464 -ra------ C:\WINDOWS\SYSTEM32\hhactivex.dll
2007-08-12 14:29 176,128 --a------ C:\WINDOWS\SYSTEM32\RcdScan.dll
2007-08-12 12:33 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Citrix
2007-08-12 11:20 <DIR> d-------- C:\Program Files\a-squared Anti-Malware
2007-08-12 08:26 <DIR> d-------- C:\Program Files\BearShare
2007-08-12 08:07 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-08-12 08:07 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-08-12 07:15 <DIR> d-------- C:\VundoFix Backups
2007-08-11 20:44 1,242 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-08-11 20:04 <DIR> d-------- C:\Program Files\RogueRemover FREE
2007-08-11 19:09 92,062,544 --a------ C:\xps08112007.reg
2007-08-11 18:08 <DIR> d-------- C:\HijackThis
2007-08-11 17:18 <DIR> d-------- C:\Program Files\msn gaming zone
2007-08-11 15:30 552 --a------ C:\WINDOWS\SYSTEM32\d3d8caps.dat
2007-08-11 06:47 93,952 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwcwdm.sys
2007-08-11 06:47 72,832 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwbwdm.sys
2007-08-11 06:47 50,176 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyyport.sys
2007-08-11 06:47 49,792 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyzport.sys
2007-08-11 06:47 48,640 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwrwdm.sys
2007-08-11 06:47 3,584 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwcosnt5.sys
2007-08-11 06:47 3,072 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwbmidi.sys
2007-08-11 06:47 3,072 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwbase.sys
2007-08-11 06:47 28,672 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyycoins.dll
2007-08-11 06:47 27,648 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyzports.dll
2007-08-11 06:47 27,648 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyyports.dll
2007-08-11 06:47 27,136 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyzcoins.dll
2007-08-11 06:47 17,152 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyclad-z.sys
2007-08-11 06:47 14,848 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cyclom-y.sys
2007-08-11 06:47 117,760 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\d100ib5.sys
2007-08-11 06:47 111,872 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cwcspud.sys
2007-08-11 06:46 96,256 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctlsb16.sys
2007-08-11 06:46 60,970 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cpqtrnd5.sys
2007-08-11 06:46 6,912 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctlfacem.sys
2007-08-11 06:46 57,399 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cplexe.exe
2007-08-11 06:46 42,112 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\crtaud.sys
2007-08-11 06:46 4,096 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctwdm32.dll
2007-08-11 06:46 3,712 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctljystk.sys
2007-08-11 06:46 249,856 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctmasetp.dll
2007-08-11 06:46 216,064 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cpscan.dll
2007-08-11 06:46 21,533 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cpqndis5.sys
2007-08-11 06:46 18,944 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cprofile.exe
2007-08-11 06:46 175,104 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\csamsp.dll
2007-08-11 06:45 9,344 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\compbatt.sys
2007-08-11 06:45 44,032 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cnusd.dll
2007-08-11 06:45 39,936 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cnxt1803.sys
2007-08-11 06:44 91,264 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cirrus.dll
2007-08-11 06:44 480,256 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cintsetp.exe
2007-08-11 06:44 45,696 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cirrus.sys
2007-08-11 06:44 248,064 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cl546xm.sys
2007-08-11 06:44 20,736 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cmbp0wdm.sys
2007-08-11 06:44 170,880 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cl546x.dll
2007-08-11 06:44 14,080 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cmbatt.sys
2007-08-11 06:44 111,232 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cl5465.dll
2007-08-11 06:43 980,034 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cicap.sys


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-17 10:10 --------- d-------- C:\Program Files\Symantec AntiVirus
2007-08-17 02:32 --------- d-------- C:\Program Files\Common Files\AOL
2007-08-17 02:26 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\AOL
2007-08-17 02:20 --------- d-------- C:\Program Files\Common Files\aolshare
2007-08-15 09:11 --------- d-------- C:\Program Files\Lavasoft
2007-08-14 09:08 --------- d-------- C:\Program Files\DivX
2007-08-13 07:43 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-12 15:44 --------- d-------- C:\Program Files\Windows NT
2007-08-12 14:59 --------- d-------- C:\Program Files\Creative
2007-08-12 14:53 --------- d-------- C:\Program Files\Dell Computer
2007-08-12 11:29 --------- d-------- C:\Program Files\Zinio
2007-08-12 11:29 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\ContentGuard
2007-08-12 09:46 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\gtk-2.0
2007-08-12 08:18 9344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-08-12 08:18 8320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-12 02:11 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\Creative
2007-08-11 19:21 --------- d-------- C:\Program Files\RegScrubXP
2007-08-10 04:07 149 --a------ C:\Program Files\ini.ini
2007-08-04 09:06 1972 --a------ C:\Program Files\installer.js
2007-08-03 18:47 --------- d-------- C:\Program Files\eFax Messenger Plus 3.3
2007-08-01 16:19 --------- d-------- C:\Program Files\America Online 9.0
2007-07-25 22:53 43528 --------- C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-07-25 22:53 120056 -----c--- C:\WINDOWS\system32\pxcpyi64.exe
2007-07-25 22:53 118520 -----c--- C:\WINDOWS\system32\pxinsi64.exe
2007-07-14 18:45 --------- d-------- C:\Program Files\MSN Messenger
2007-07-14 18:04 --------- d-------- C:\Program Files\AIM
2007-07-03 17:18 --------- d-------- C:\DOCUME~1\GARY\APPLIC~1\MSN6
2007-06-29 22:53 --------- d-------- C:\Program Files\Opera
2007-06-28 23:15 --------- d-------- C:\Program Files\CARCare
2007-06-28 23:15 --------- d-------- C:\Program Files\Automotive Wolf
2007-06-28 23:10 --------- d-------- C:\Program Files\CramMaster
2007-06-28 22:44 --------- d-------- C:\Program Files\Seagate Software
2007-06-28 21:57 --------- d-------- C:\Program Files\Market Research Wizard
2007-06-26 11:13 851968 --a--c--- C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 10:35 665600 --a--c--- C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-26 02:08 1104896 --a--c--- C:\WINDOWS\system32\msxml3.dll
2007-06-26 02:08 1104896 --a--c--- C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 09:31 282112 --a--c--- C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-19 09:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-18 18:44 --------- d-------- C:\Program Files\GIMP-2.0
2007-06-18 18:43 --------- d-------- C:\Program Files\Common Files\GTK
2007-06-15 04:12 96256 --a--c--- C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-15 04:12 616960 --a--c--- C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-15 04:12 55808 --a--c--- C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-15 04:12 532480 --a--c--- C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-15 04:12 474112 --a--c--- C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-15 04:12 449024 --a--c--- C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-15 04:12 39424 --a--c--- C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-15 04:12 357888 --a--c--- C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-15 04:12 3064320 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-15 04:12 251904 --a--c--- C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-15 04:12 205824 --a--c--- C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-15 04:12 16384 --a--c--- C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-15 04:12 151040 --a--c--- C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-15 04:12 1498112 --a--c--- C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-15 04:12 146432 --a--c--- C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-15 04:12 1054208 --a--c--- C:\WINDOWS\system32\dllcache\danim.dll
2007-06-15 04:12 1022976 --a--c--- C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 06:32 18432 --a--c--- C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 06:23 1033216 --a------ C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 06:23 1033216 --a------ C:\WINDOWS\explorer.exe
2007-05-17 07:28 549376 --a--c--- C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-05-17 07:28 549376 --------- C:\WINDOWS\system32\oleaut32.dll
2005-09-10 22:34 774144 --a--c--- C:\Program Files\RngInterstitial.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2007-07-17 09:49]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\Program Files\AIM\aim.exe" [2005-08-05 16:08]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

C:\Documents and Settings\GARY\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Live Menu 3.3.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Tray Menu 3.3.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^GARY^Start Menu^Programs^Startup^Morpheus.lnk]
path=C:\Documents and Settings\GARY\Start Menu\Programs\Startup\Morpheus.lnk
backup=C:\WINDOWS\pss\Morpheus.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^GARY^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^GARY^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\GARY\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^GARY^Start Menu^Programs^Startup^TickerBar.lnk]
backup=C:\WINDOWS\pss\TickerBar.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
"C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearFlix]
"C:\Program Files\BearFlix\BearFlix.exe" /pause

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
"C:\Program Files\BearShare\BearShare.exe" /pause

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Consumer Input]
C:\Program Files\Consumer Input\ConsumerInput.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FineReader7NewsReaderPro]
"C:\Program Files\ABBYY FineReader 7.0 Professional Edition\ABBYYNewsReader.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GreenHorseTickerBar]
C:\Documents and Settings\GARY\TickerBar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hti]
C:\npdor\npdor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetMeter]
C:\PROGRA~1\NETRAT~1\NetMeter\NetMeter.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PD0630 STISvc]
RunDLL32.exe P0630Pin.dll,RunDLL32EP 513

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
"C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SB Audigy 2 Startup Menu]
/L:ENG

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WD Button Manager]
WDBtnMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zinio DLM]
C:\PROGRA~1\Zinio\ZDLM.exe /hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zzz_ImInstaller_IncrediMail]

C:\DOCUME~1\GARY\LOCALS~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"svcWRSSSDK"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AIM"=C:\Program Files\AIM\aim.exe -cnetwait.odl
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CamTray.exe"
"msnmsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
"Dell AIO Printer A960"="C:\Program Files\Dell AIO Printer A960\dlbfbmgr.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime

R3 P0630VID;Creative WebCam Live!;C:\WINDOWS\system32\DRIVERS\P0630Vid.sys
R3 vidcap;vidcap;C:\WINDOWS\system32\DRIVERS\vidcap.sys
S0 NPDORFM;NPDOR File Monitor;C:\WINDOWS\system32\Drivers\NPDORFM.sys
S3 FastLynx;FastLynx;\??\C:\Program Files\FastLynx\FastLynx.sys
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\System32\svchost.exe -k p2psvc
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\System32\svchost.exe -k p2psvc
S3 p2psvc;Peer Networking;C:\WINDOWS\System32\svchost.exe -k p2psvc
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\System32\svchost.exe -k p2psvc
S3 SQLAgent$MICROSOFTBCM;SQLAgent$MICROSOFTBCM;C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlagent.EXE -i MICROSOFTBCM

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc p2psvc p2pimsvc p2pgasvc PNRPSvc


Contents of the 'Scheduled Tasks' folder
2006-10-16 18:18:55 C:\WINDOWS\Tasks\RegCure.job - C:\Program Files\RegCure\RegCure.exe
2007-08-16 19:00:00 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job - C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
2005-08-27 08:01:26 C:\WINDOWS\Tasks\XoftSpy.job - C:\Program Files\XoftSpy\XoftSpy.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-17 10:38:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

**************************************************************************

Completion time: 2007-08-17 10:45:19 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-17 10:44
C:\ComboFix2.txt ... 2007-08-17 09:18

--- E O F ---

=============================================================================

Logfile of HijackThis v1.99.1
Scan saved at 10:49:15 AM, on 8/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\notepad.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://login.passport.net/uilogin.srf?id=2
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: XBTP01621 - {F6104497-54FD-4688-9162-5115CC8AB0FB} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file)
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mp4: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.dotphoto.com/ImageUploader4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NPDOR File Monitor Service (NFMService) - Unknown owner - C:\WINDOWS\System32\NPDORNT.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

#9 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:05:50 AM

Posted 17 August 2007 - 09:59 AM

You're doing great,lets continue :thumbsup:

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: XBTP01621 - {F6104497-54FD-4688-9162-5115CC8AB0FB} - (no file)
O3 - Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

Exit Hijackthis.

Start SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.

--------------------------------------------------------------

Run 'BitDefender Online Scanner' using Internet Explorer:
http://www.bitdefender.com/scan8/ie.html
Read the 'END USER SOFTWARE LICENSE AGREEMENT' then click 'I agree'.
You'll be prompted to install the activex control,please do so.
Once installed,disable your current antivirus program,then click the 'Click here to scan' button.
The virus signatures will then load.
Once loaded the scan will start.
The scan will take quite some time so please be patient.
Once the scan has finished select the 'Detected Problems' tab.
Click on 'Click here to export scan'.
Save the file as an HTML file to your desktop.
Then click on the saved file and allow it to open with your browser.
Go to 'Edit'/'Select All' then copy and paste that log into your next reply.
*Note*
Don't forget to re-enable your antivirus program.

Also post a new Hijackthis log,let me know how your pc is running now.
Posted Image
Posted Image

#10 gramsay

gramsay
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:11:50 PM

Posted 18 August 2007 - 01:20 AM

[quote name='RichieUK' date='Aug 17 2007, 10:59 AM' post='596093']
You're doing great,lets continue :flowers:

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: XBTP01621 - {F6104497-54FD-4688-9162-5115CC8AB0FB} - (no file)
O3 - Toolbar: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

Exit Hijackthis.

Start SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.

--------------------------------------------------------------

Hello,

I have been following your steps as close as possible.

Right now the PC is stable without any bad effects.

My problem now is that SuperAntiSpyware is taking a long time and is spending a lot of time scanning
".TMP" files in the WINDOWS/SYSTEM32 folder.

Can I delete those ".TMP" files in the WINDOWS/SYSTEM32 folder.

The scan is now in the 7th hour.

Thanks,
Gary :thumbsup:

Posted Image

Posted Image

#11 gramsay

gramsay
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:11:50 PM

Posted 18 August 2007 - 04:41 AM

The SuperAntiSpware scan is in the 11th hour.

I opened up the system32 folder and found that there are:


239,607 files and
32.8 GB of files ...

Is this valid ?
Is this a problem ?


Posted Image

Thanks,
GR :thumbsup:

Edited by gramsay, 18 August 2007 - 05:05 AM.


#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:05:50 AM

Posted 18 August 2007 - 11:09 AM

I opened up the system32 folder and found that there are:
239,607 files and
32.8 GB of files ...
Is this valid ?
Well if the System32 folder is 32.8 GB in size then there is almost certainly a problem.

These Temp files you keep refering to,delete all of them,do the following first:

Clear your 'System Restore' points by doing the following:
Right-click on 'My Computer' and select 'Properties'.
Select 'System Restore'.
Select 'Turn Off System Restore On All Drives'.
Select 'Apply'.
You will then get the following warning:
"You have chosen to turn off System Restore.
If you continue,all existing restore points will be deleted,and you will not be able to track or undo changes to your computer.
Do you want to turn off System Restore?".
Then select 'Yes',your 'System Restore' directories will be purged.

Restart your pc.

Turn 'System Restore' back on:
Right click on 'My Computer' and select 'Properties'.
Select 'System Restore'.
Unselect 'Turn Off System Restore On All Drives'.
Select 'Apply',then click 'Ok'.

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Restart your pc when you've done,post a new Hijackthis log,let me know whats happening now.
Posted Image
Posted Image

#13 gramsay

gramsay
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:11:50 PM

Posted 19 August 2007 - 12:28 PM

The SuperAntiSpware scan is in the 11th hour.

I opened up the system32 folder and found that there are:


239,607 files and
32.8 GB of files ...

Is this valid ?
Is this a problem ?


Posted Image

Thanks,
GR :thumbsup:


I was able to delete the *.TMP files in the system32 folder.

I had to go to DOS to delete them since windows was too slow and non-responsive

Posted Image

Now the system32 folder is: 1.4 GB

Is it known why/how those .TMP files are generated ?

Is there a way to stop them ?

It seems the .TMP files in system32 is not included in "Disk Cleanup"

Thanks,
Gary :flowers:

#14 gramsay

gramsay
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:11:50 PM

Posted 19 August 2007 - 12:40 PM

Well its seems we're making good progress.

The computer has not acted badly nor IE crashing like before.

It seems we're making good progress.

Posted Image


Posted Image


Here are the scan logs you requested: :thumbsup:

===============================================================================
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/18/2007 at 12:03 PM

Application Version : 3.9.1008

Core Rules Database Version : 3288
Trace Rules Database Version: 1299

Scan type : Complete Scan
Total Scan Time : 17:32:10

Memory items scanned : 561
Memory threats detected : 1
Registry items scanned : 7518
Registry threats detected : 2
File items scanned : 622456
File threats detected : 187

BearShare File Sharing Client
C:\PROGRAM FILES\BEARSHARE\BEARSHARE.EXE
C:\PROGRAM FILES\BEARSHARE\BEARSHARE.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\BEARSHARE.LNK
C:\DOCUMENTS AND SETTINGS\GARY\DESKTOP\BEARSHARE.LNK
C:\WINDOWS\Prefetch\BEARSHARE.EXE-35739D34.pf

Adware.Vundo Variant
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{E4EEFFED-93CD-4CF0-A0F3-50D139121FEE}

Adware.Tracking Cookie
C:\Documents and Settings\GARY\Cookies\gary@drivecleaner[1].txt
C:\Documents and Settings\GARY\Cookies\gary@ads.monster[2].txt
C:\Documents and Settings\GARY\Cookies\gary@roiservice[1].txt
C:\Documents and Settings\GARY\Cookies\gary@adserving.cpxinteractive[2].txt
C:\Documents and Settings\GARY\Cookies\gary@html[2].txt
C:\Documents and Settings\GARY\Cookies\gary@sexbuddies[3].txt
C:\Documents and Settings\GARY\Cookies\gary@adrevolver[3].txt
C:\Documents and Settings\GARY\Cookies\gary@atwola[4].txt
C:\Documents and Settings\GARY\Cookies\gary@fastclick[1].txt
C:\Documents and Settings\GARY\Cookies\gary@adopt.euroclick[1].txt
C:\Documents and Settings\GARY\Cookies\gary@doubleclick[1].txt
C:\Documents and Settings\GARY\Cookies\gary@bs.serving-sys[2].txt
C:\Documents and Settings\GARY\Cookies\gary@revsci[1].txt
C:\Documents and Settings\GARY\Cookies\gary@ford.112.2o7[1].txt
C:\Documents and Settings\GARY\Cookies\gary@adrevolver[1].txt
C:\Documents and Settings\GARY\Cookies\gary@statse.webtrendslive[2].txt
C:\Documents and Settings\GARY\Cookies\gary@realmedia[1].txt
C:\Documents and Settings\GARY\Cookies\gary@bluestreak[3].txt
C:\Documents and Settings\GARY\Cookies\gary@advertising[2].txt
C:\Documents and Settings\GARY\Cookies\gary@winantivirus[2].txt
C:\Documents and Settings\GARY\Cookies\gary@stats1.reliablestats[1].txt
C:\Documents and Settings\GARY\Cookies\gary@tacoda[2].txt
C:\Documents and Settings\GARY\Cookies\gary@hitbox[2].txt
C:\Documents and Settings\GARY\Cookies\gary@goclick[3].txt
C:\Documents and Settings\GARY\Cookies\gary@www.burstbeacon[1].txt
C:\Documents and Settings\GARY\Cookies\gary@2o7[1].txt
C:\Documents and Settings\GARY\Cookies\gary@trafficmp[2].txt
C:\Documents and Settings\GARY\Cookies\gary@atdmt[3].txt
C:\Documents and Settings\GARY\Cookies\gary@cpvfeed[3].txt
C:\Documents and Settings\GARY\Cookies\gary@tribalfusion[3].txt
C:\Documents and Settings\GARY\Cookies\gary@serving-sys[2].txt
C:\Documents and Settings\GARY\Cookies\gary@adserver[1].txt
C:\Documents and Settings\GARY\Cookies\gary@www.winantiviruspro[1].txt
C:\Documents and Settings\GARY\Cookies\gary@msnportal.112.2o7[2].txt
C:\Documents and Settings\GARY\Cookies\gary@mediaplex[3].txt
C:\Documents and Settings\GARY\Cookies\gary@bidzcom.112.2o7[1].txt
C:\Documents and Settings\GARY\Cookies\gary@adopt.specificclick[2].txt
C:\Documents and Settings\GARY\Cookies\gary@zedo[3].txt
C:\Documents and Settings\GARY\Cookies\gary@ehg-warnerbrothers.hitbox[2].txt
C:\Documents and Settings\GARY\Cookies\gary@divx.adbureau[2].txt
C:\Documents and Settings\Freda\Cookies\freda@i.screensavers[2].txt
C:\Documents and Settings\Freda\Cookies\freda@partner2profit[1].txt
C:\Documents and Settings\Freda\Cookies\freda@screensavers[1].txt
C:\Documents and Settings\Freda\Cookies\freda@try.screensavers[1].txt
C:\Documents and Settings\GARY\Cookies\gary@adinterax[1].txt
C:\Documents and Settings\GARY\Cookies\gary@ads.addynamix[1].txt
C:\Documents and Settings\GARY\Cookies\gary@ads.pointroll[1].txt
C:\Documents and Settings\GARY\Cookies\gary@adultfriendfinder[1].txt
C:\Documents and Settings\GARY\Cookies\gary@advertising[1].txt
C:\Documents and Settings\GARY\Cookies\gary@atdmt[1].txt
C:\Documents and Settings\GARY\Cookies\gary@atwola[1].txt
C:\Documents and Settings\GARY\Cookies\gary@atwola[2].txt
C:\Documents and Settings\GARY\Cookies\gary@atwola[3].txt
C:\Documents and Settings\GARY\Cookies\gary@bluestreak[1].txt
C:\Documents and Settings\GARY\Cookies\gary@bs.serving-sys[1].txt
C:\Documents and Settings\GARY\Cookies\gary@buycom.122.2o7[1].txt
C:\Documents and Settings\GARY\Cookies\gary@cpvfeed[2].txt
C:\Documents and Settings\GARY\Cookies\gary@drivecleaner[2].txt
C:\Documents and Settings\GARY\Cookies\gary@fastclick[2].txt
C:\Documents and Settings\GARY\Cookies\gary@goclick[2].txt
C:\Documents and Settings\GARY\Cookies\gary@interclick[2].txt
C:\Documents and Settings\GARY\Cookies\gary@mediaplex[2].txt
C:\Documents and Settings\GARY\Cookies\gary@mediatraffic[2].txt
C:\Documents and Settings\GARY\Cookies\gary@msnportal.112.2o7[1].txt
C:\Documents and Settings\GARY\Cookies\gary@revsci[2].txt
C:\Documents and Settings\GARY\Cookies\gary@serving-sys[1].txt
C:\Documents and Settings\GARY\Cookies\gary@sexbuddies[2].txt
C:\Documents and Settings\GARY\Cookies\gary@stats1.reliablestats[2].txt
C:\Documents and Settings\GARY\Cookies\gary@tribalfusion[2].txt
C:\Documents and Settings\GARY\Cookies\gary@winantispyware[1].txt
C:\Documents and Settings\GARY\Cookies\gary@www.burstnet[2].txt
C:\Documents and Settings\GARY\Cookies\gary@yadro[2].txt
C:\Documents and Settings\GARY\Cookies\gary@zedo[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@ad.coupons[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@ad.itbe[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@adinterax[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@adopt.hotbar[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@ads.adbrite[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@ads.as4x.tmcs[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@ads.cwjamaica[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@ads.hi5[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@ads.monster[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@ads1.rodale[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@anat.tacoda[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@atwola[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@e-2dj6wfkikodjolp.stats.esomniture[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@highbeam.122.2o7[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@hotbar[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@icc.intellisrv[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@interclick[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@kanoodle[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@microsoftgamestudio.112.2o7[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@nextag[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@partner2profit[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@pt.crossmediaservices[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@qnsr[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@roiservice[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@sales.liveperson[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@server.cpmstar[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@serving-sys[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@shopping.112.2o7[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@simplestar.122.2o7[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@sources.sourcetool[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@specificclick[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@stat.dealtime[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@track[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@winfixer[2].txt
C:\Documents and Settings\IVY\Cookies\ivy@www.azoogleads[1].txt
C:\Documents and Settings\IVY\Cookies\ivy@www.keepmedia[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@112.2o7[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@ad.yieldmanager[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@adbrite[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@adinterax[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@adlegend[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@adopt.euroclick[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@adopt.hotbar[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@adopt.specificclick[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@ads.cnn[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@ads.einmedia[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@ads.monster[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@ads.pgatour[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@ads.pointroll[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@ads.pricescan[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@ads.realtechnetwork[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@ads1.rodale[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@ads2.drivelinemedia[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@anad.tacoda[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@anat.tacoda[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@apmebf[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@atwola[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@belnk[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@bizrate[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@bs.serving-sys[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@burstnet[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@clicksor[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@cpvfeed[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@cts.metricsdirect[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@data1.perf.overture[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@dist.belnk[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@einmedia[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@gettheinsidetrack[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@h.starware[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@hotbar[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@icc.intellisrv[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@incredimailltd.112.2o7[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@interclick[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@login.tracking101[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@microsoftwlsearchcrm.112.2o7[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@msnportal.112.2o7[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@nbads[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@netmediagroup[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@newsinteractive.112.2o7[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@nextag[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@onlinerewardcenter[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@partner2profit[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@perf.overture[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@redorbit[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@revsci[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@roiservice[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@sales.liveperson[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@spamblockerutility[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@sunrocketinc.112.2o7[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@superstats[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@thomasvillefurniture.122.2o7[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@track.jobviper[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@track.searchignite[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@try.starware[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@winfixer[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@www.azoogleads[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@www.burstbeacon[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@www.burstnet[2].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@www.clickdefense[1].txt
C:\Documents and Settings\ROYES_RAMSAY\Cookies\royes_ramsay@www.rowise[1].txt

Adware.ZToolbar
C:\WINDOWS\system32\azebar.xml

Unclassified.PC MightyMax
HKU\S-1-5-21-3801635458-2927962414-3113290001-1011\Software\PC MightyMax

Adware.ClickSpring/Yazzle
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1162OINUNINSTALLER.EXE.VIR

Adware.WebBuying Assistant-Installer
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\CONFIGS\Y909.EXE.VIR

Adware.ClickSpring
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\PPPATC~1\WAUCLT~1.VIR

Trojan.Unknown Origin
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\WNSINTI.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\WNSINTSV.EXE.VIR

Adware.TrustInCash
C:\WINDOWS\ADULT.ICO
C:\WINDOWS\SPYWAREREMOVAL.ICO

Adware.Unknown Origin
C:\WINDOWS\SHOPPING.ICO

Unclassified.Unknown Origin/System
C:\WINDOWS\SYSTEM32\PPLEYWX.DLL.BAK


===============================================================================

BitDefender Online Scanner



Scan report generated at: Sat, Aug 18, 2007 - 22:32:27





Scan path: A:\;C:\;D:\;E:\;







Statistics

Time
05:42:24

Files
484429

Folders
7549

Boot Sectors
3

Archives
3973

Packed Files
11525




Results

Identified Viruses
18

Infected Files
40

Suspect Files
0

Warnings
0

Disinfected
0

Deleted Files
71




Engines Info

Virus Definitions
733740

Engine build
AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22)

Scan plugins
14

Archive plugins
37

Unpack plugins
6

E-mail plugins
6

System plugins
1




Scan Settings

First Action
Disinfect

Second Action
Delete

Heuristics
Yes

Enable Warnings
Yes

Scanned Extensions
*;

Exclude Extensions


Scan Emails
Yes

Scan Archives
Yes

Scan Packed
Yes

Scan Files
Yes

Scan Boot
Yes




Scanned File
Status

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80000\47BE5AE3.VBN=>(Quarantine-PE)
Infected with: Trojan.Fotomoto.A

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80000\47BE5AE3.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80003\47BE6642.VBN=>(Quarantine-PE)
Infected with: Generic.Zlob.2DDDA041

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80003\47BE6642.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80003\47BE6642.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80006\47BE68E7.VBN=>(Quarantine-PE)
Infected with: Trojan.Vundo.DMP

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80006\47BE68E7.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80006\47BE68E8.VBN=>(Quarantine-PE)
Infected with: Trojan.Vundo.DMP

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80006\47BE68E8.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80007\47BE690C.VBN=>(Quarantine-PE)
Infected with: Trojan.Vundo.DMP

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80007\47BE690C.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80007\47BE690D.VBN=>(Quarantine-PE)
Infected with: Trojan.Vundo.DMP

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80007\47BE690D.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80008\47BE691D.VBN=>(Quarantine-PE)
Infected with: Trojan.Fotomoto.A

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80008\47BE691D.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80009\47BE694F.VBN=>(Quarantine-PE)=>(NSIS o)=>zlib_nsis0001
Infected with: Trojan.Downloader.TR

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80009\47BE694F.VBN=>(Quarantine-PE)=>(NSIS o)=>zlib_nsis0001
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80009\47BE694F.VBN=>(Quarantine-PE)=>(NSIS o)=>zlib_nsis0001
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80009\47BE694F.VBN=>(Quarantine-PE)=>(NSIS o)
Update failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04240001\46BF0D0C.VBN=>(Quarantine-PE)
Infected with: Trojan.Agent.QT

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04240001\46BF0D0C.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04240001\46BF0D0C.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05780001\47FE5024.VBN=>(Quarantine-PE)
Infected with: Trojan.Downloader.TR

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05780001\47FE5024.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05780001\47FE5024.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08940000.VBN=>(Quarantine-PE)
Detected with: Application.Ultimate.BE

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08940000.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08940000.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\089C0000.VBN=>(Quarantine-PE)
Infected with: Trojan.FatObfus.Gen

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\089C0000.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\089C0000.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C000000\4EC2902D.VBN=>(Quarantine-PE)
Infected with: Generic.Zlob.2DDDA041

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C000000\4EC2902D.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C000000\4EC2902D.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C080000\4EBE2FF3.VBN=>(Quarantine-PE)
Infected with: Trojan.Downloader.Winfixer.G

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C080000\4EBE2FF3.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C080000\4EBE2FF3.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C180000\4EBE2A69.VBN=>(Quarantine-PE)
Infected with: Trojan.Vundo.DMP

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C180000\4EBE2A69.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C380000\4EFAFF6A.VBN=>(Quarantine-PE)
Infected with: Trojan.Downloader.Winfixer.O

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C380000\4EFAFF6A.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C380000\4EFAFF6A.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C380000\4EFAFF9A.VBN=>(Quarantine-PE)
Infected with: Trojan.Downloader.Winfixer.O

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C380000\4EFAFF9A.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C380000\4EFAFF9A.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C380001\4EFB7D92.VBN=>(Quarantine-PE)
Infected with: Trojan.Downloader.Winfixer.G

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C380001\4EFB7D92.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C380001\4EFB7D92.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C480000\4ECAB598.VBN=>(Quarantine-PE)
Infected with: Generic.Zlob.2DDDA041

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C480000\4ECAB598.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C480000\4ECAB598.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C900000\4ED31C7F.VBN=>(Quarantine-PE)
Infected with: Trojan.Downloader.TR

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C900000\4ED31C7F.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C900000\4ED31C7F.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CF80000\4EFAB4A7.VBN=>(Quarantine-PE)
Infected with: Trojan.Downloader.TR

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CF80000\4EFAB4A7.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CF80000\4EFAB4A7.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D100000.VBN=>(Quarantine-PE)
Infected with: Trojan.Fotomoto.A

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D100000.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D5C0001\4FDF6095.VBN=>(Quarantine-PE)
Infected with: Trojan.Downloader.TR

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D5C0001\4FDF6095.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D5C0001\4FDF6095.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D700000.VBN=>(Quarantine-PE)
Infected with: Trojan.Clicker.Agent.NP

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D700000.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D700000.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D7C0000\4FFE4C8D.VBN=>(Quarantine-PE)
Infected with: Generic.Zlob.2DDDA041

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D7C0000\4FFE4C8D.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D7C0000\4FFE4C8D.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D7C0002\4FFE52EA.VBN=>(Quarantine-PE)
Infected with: Trojan.Downloader.Winfixer.O

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D7C0002\4FFE52EA.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D7C0002\4FFE52EA.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D7C0002\4FFE532C.VBN=>(Quarantine-PE)
Infected with: Trojan.Downloader.Winfixer.O

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D7C0002\4FFE532C.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D7C0002\4FFE532C.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DF80000\4FFF1988.VBN=>(Quarantine-PE)
Infected with: GenPack:Adware.Webbuying.M

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DF80000\4FFF1988.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DF80000\4FFF1988.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0ECC0000\4EFEEC47.VBN=>(Quarantine-PE)
Infected with: Trojan.Agent.ABLK

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0ECC0000\4EFEEC47.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0ECC0000\4EFEEC47.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F040000\4FBEEBE6.VBN=>(Quarantine-PE)
Infected with: Trojan.Agent.QT

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F040000\4FBEEBE6.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F040000\4FBEEBE6.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F200000\4FE335B1.VBN=>(Quarantine-PE)
Infected with: Generic.Zlob.2DDDA041

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F200000\4FE335B1.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F200000\4FE335B1.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FC40000\4FC71802.VBN=>(Quarantine-PE)
Infected with: Generic.Zlob.2DDDA041

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FC40000\4FC71802.VBN=>(Quarantine-PE)
Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FC40000\4FC71802.VBN=>(Quarantine-PE)
Deleted

C:\Documents and Settings\ROYES_RAMSAY\Local Settings\Temporary Internet Files\Content.IE5\29KNAVS3\CAXTZZAX
Infected with: DeepScan:Generic.Virtumonde.1.70C33C13

C:\Documents and Settings\ROYES_RAMSAY\Local Settings\Temporary Internet Files\Content.IE5\29KNAVS3\CAXTZZAX
Disinfection failed

C:\Documents and Settings\ROYES_RAMSAY\Local Settings\Temporary Internet Files\Content.IE5\29KNAVS3\CAXTZZAX
Deleted

C:\Program Files\installer.js
Infected with: Trojan.Js.Agent.B

C:\Program Files\installer.js
Disinfection failed

C:\Program Files\installer.js
Deleted

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\gln.exe.vir
Infected with: Trojan.Dropper.RHZ

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\gln.exe.vir
Disinfection failed

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\gln.exe.vir
Deleted

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\jkhff.dll.vir
Infected with: DeepScan:Generic.Virtumonde.1.1DF3B8C2

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\jkhff.dll.vir
Disinfection failed

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\jkhff.dll.vir
Deleted

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\pmnlj.dll.vir
Infected with: DeepScan:Generic.Virtumonde.1.1DF3B8C2

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\pmnlj.dll.vir
Disinfection failed

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\pmnlj.dll.vir
Deleted

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ssqpq.dll.vir.vir
Infected with: DeepScan:Generic.Virtumonde.1.D2981B1C

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ssqpq.dll.vir.vir
Disinfection failed

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ssqpq.dll.vir.vir
Deleted

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\winrnt32.dll.vir
Infected with: MemScan:Trojan.Downloader.CWS.AN

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\winrnt32.dll.vir
Disinfection failed

C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\winrnt32.dll.vir
Deleted

C:\VundoFix Backups\awvtu.dll.bad
Infected with: DeepScan:Generic.Virtumonde.1.1DF3B8C2

C:\VundoFix Backups\awvtu.dll.bad
Disinfection failed

C:\VundoFix Backups\awvtu.dll.bad
Deleted

===============================================================================


Logfile of HijackThis v1.99.1
Scan saved at 2:19:10 AM, on 8/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\DivX\DivX Player\DivX Player.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\mspaint.exe
C:\WINDOWS\notepad.exe
C:\Program Files\a-squared Anti-Malware\a2start.exe
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://login.passport.net/uilogin.srf?id=2
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mp4: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.dotphoto.com/ImageUploader4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NPDOR File Monitor Service (NFMService) - Unknown owner - C:\WINDOWS\System32\NPDORNT.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

#15 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:05:50 AM

Posted 19 August 2007 - 04:07 PM

Your log is clean :thumbsup:
If all's ok,please do the following.

Find and delete:
Combofix.exe
C:\Qoobox

Download ATF Cleaner by Atribune:
http://www.atribune.org/ccount/click.php?id=1

Double-click ATF-Cleaner.exe to run the program.
Click 'Select All' found at the bottom of the list.
Click the 'Empty Selected' button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

If you use Opera browser,do this also:
Click Opera at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.
Click 'Exit' on the Main menu to close the program.

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
'How to prevent Malware' by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users