Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan Horse Downloader


  • This topic is locked This topic is locked
19 replies to this topic

#1 ripstussy

ripstussy

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 05 January 2008 - 08:23 PM

Multiple pop ups every time I am using mozilla and or internet explorer. Even after cleaning up with spyware programs the trojan horse continues to re infect.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:52:29 PM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ezSP_Px .exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\Spyware Nuker\swnxt.exe
C:\WINDOWS\avp .exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
D:\PROGRA~1\MICROS~1\rapimgr.exe
D:\Palm\Hotsync.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\26261011.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.usatoday.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\shell.exe
F3 - REG:win.ini: load=C:\WINDOWS\system32\tuvvs.exe
O2 - BHO: (no name) - {0026D161-E6EC-408B-9E73-7A181E632B3E} - C:\Program Files\Windows Media Player\hokenov83122.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2D5796A2-44E0-4E50-A5A0-80BF1EE3EA73} - C:\WINDOWS\system32\hggfghf.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {654E6AB9-160E-4287-B8B9-2B9A1A6622FB} - C:\Program Files\Windows Media Player\hokenov4444.dll (file missing)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px .exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [winshow] "C:\WINDOWS\winshow.exe"
O4 - HKLM\..\Run: [SWN2] C:\Program Files\Spyware Nuker\swnxt.exe /h
O4 - HKLM\..\Run: [BDSwitchAgent] C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe
O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp .exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj .exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Palm Registration.lnk = D:\Palm\register.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = D:\Palm\Hotsync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~1\INetRepl.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://prerelease.trendmicro-europe.com/ho...ivex/hcImpl.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...83/mcinsctl.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan.com/as/cabs/ascstubie.cab
O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://download.sidestep.com/get/k00719/sb028.cab
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} (Actimage Room Control) - http://hutchence.armstrong.com/ib/database...timage40803.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,20/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...200/mcfscan.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll
O20 - Winlogon Notify: hggfghf - hggfghf.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG6 Service (AvgServ) - Unknown owner - (no file)
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\VmGateway.exe
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Video\GPVSvr.exe
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\MSN Gaming Zone\profsyvyqaq.html

--
End of file - 14535 bytes

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:18 AM

Posted 08 January 2008 - 10:59 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum ripstussy
My name is Richie and i'll be helping you to fix your problems.

You pc is very badly infected,you also have a Backdoor Trojan present.
A Backdoor is a software program that gives an attacker unauthorized access to a machine and the means for remotely controlling the machine without the user's knowledge. A Backdoor compromises system integrity by making changes to the system that allow it to by used by the attacker for malicious purposes unknown to the user.

They are typically installed without user interaction through security exploits, and may allow an attacker to remotely control the infected machine. Such risks may allow the attacker to install additional malware and use the compromised machine to participate in denial of service attacks, spamming, and bot nets, or to transmit sensitive data to a remote server. The malware may be cloaked and not visible to the user. These risks severely compromise the system by lowering security settings, installing 'backdoors,' infecting system files, or spreading to other networked machines.

If your computer was used for online banking or has credit card information on it, all passwords should be changed immediately to include those used for email, eBay and forums.
You should consider them to be compromised.
They should be changed by using a different computer and not the infected one,if not an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breech.

Since your computer was compromised read:
How to report ID theft, fraud, drive-by installs, hijacking and malware:
http://www.dslreports.com/faq/10451

When Should I Format, How Should I Reinstall:
http://www.dslreports.com/faq/10063

Let me know how you wish to proceed in your next reply.
Posted Image
Posted Image

#3 ripstussy

ripstussy
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 10 January 2008 - 07:46 PM

Richie,

After thoroughly reading your recommendations, I feel that to re format the hard drive is the best thing to do. Do you have any other thoughts?

ripstussy

#4 ripstussy

ripstussy
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 10 January 2008 - 07:52 PM

Richie,

Is it even worth trying to disinfect my computer? Do we have a shot of cleaning this thing? Can we try before choosing re formatting?

ripstussy

#5 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:18 AM

Posted 11 January 2008 - 03:36 AM

Please download VundoFix.exe to your desktop.
Double-click VundoFix.exe to run it.
When VundoFix re-opens,click the "Scan for Vundo" button.
Once it's done scanning,click the "Remove Vundo" button.
You will receive a prompt asking if you want to remove the files, click "YES".
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed,it will prompt that it will reboot your computer,click "OK".
Post the contents of C:\vundofix.txt into your next reply.
Note:
It is possible that VundoFix encountered a file it could not remove.
In this case,VundoFix will run on reboot,simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

Download SDFix.exe and save it to your desktop:
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

* Double click on SDFix on your desktop,and install the fix to C:\

Please then reboot your computer into Safe Mode by doing the following:

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.

* In Safe Mode,go to and open the C:\SDFix folder,then double click on RunThis.bat to start the script.
* Type Y to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt into your next reply.


If you have previously downloaded ComboFix,please delete that version now.
Warning
You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert.
It is intended by its creator to be used under the guidance and supervision of an expert,not for private use.
Using this tool incorrectly could render your system/pc inoperable.

Now download Combofix by sUBs and save to your desktop:
Note
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.
Note
In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.
Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#6 ripstussy

ripstussy
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 17 January 2008 - 01:35 AM

Here are my results:

VundoFix found no files.

SDFix: Version 1.126

Run by Chris Matthews on Wed 01/16/2008 at 09:21 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
core

Path:
system32\drivers\core.sys

core - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\PROGRA~1\MSNGAM~1\PROFSY~1.HTM - Deleted
C:\Temp\1cb\syscheck.log - Deleted
C:\WINDOWS\system32\drivers\core.cache.dsk - Deleted
C:\WINDOWS\system32\pac.txt - Deleted
C:\WINDOWS\system32\drivers\core.sys - Deleted



Folder C:\Program Files\Helper - Removed
Folder C:\Temp\1cb - Removed
Folder C:\Temp\tn3 - Removed
Folder C:\WINDOWS\system32\Z1 - Removed

Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-16 21:35:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000094
"TracesSuccessful"=dword:00000001

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"="C:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe:*:Enabled:TrueVector Service"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"D:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="D:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="D:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="D:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\printer.exe"="C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\printer.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Dawn Swartwood\\Start Menu\\Programs\\Startup\\findfast.exe"="C:\\Documents and Settings\\Dawn Swartwood\\Start Menu\\Programs\\Startup\\findfast.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\trant.exe"="C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\trant.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\mcrupdate.exe"="C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\mcrupdate.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\spyguard.exe"="C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\spyguard.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Chris Matthews\\Application Data\\trant.exe"="C:\\Documents and Settings\\Chris Matthews\\Application Data\\trant.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="D:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="D:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="D:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\printer.exe"="C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\printer.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Dawn Swartwood\\Start Menu\\Programs\\Startup\\findfast.exe"="C:\\Documents and Settings\\Dawn Swartwood\\Start Menu\\Programs\\Startup\\findfast.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\trant.exe"="C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\trant.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\mcrupdate.exe"="C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\mcrupdate.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\spyguard.exe"="C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\spyguard.exe:*:Enabled:@xpsp2res.dll,-22019"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Chris Matthews\\Application Data\\trant.exe"="C:\\Documents and Settings\\Chris Matthews\\Application Data\\trant.exe:*:Enabled:@xpsp2res.dll,-22019"

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Wed 7 Feb 2007 23,040 ...H. --- "C:\Documents and Settings\Chris Matthews\My Documents\~WRL0177.tmp"
Wed 1 Dec 2004 21,504 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL0033.tmp"
Wed 1 Dec 2004 28,672 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL0048.tmp"
Tue 9 May 2006 35,840 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL0423.tmp"
Sun 16 Oct 2005 24,576 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL0852.tmp"
Wed 16 Nov 2005 19,456 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL1097.tmp"
Sun 16 Oct 2005 22,016 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL1231.tmp"
Mon 22 Nov 2004 21,504 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL1746.tmp"
Wed 1 Dec 2004 22,016 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL2566.tmp"
Sat 15 Oct 2005 20,992 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL2904.tmp"
Tue 19 Dec 2006 31,744 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL3145.tmp"
Sun 16 Oct 2005 26,112 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL3188.tmp"
Wed 1 Dec 2004 22,016 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL3490.tmp"
Wed 1 Dec 2004 20,992 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL3565.tmp"
Wed 1 Dec 2004 21,504 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL3700.tmp"
Tue 2 Nov 2004 20,480 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL3904.tmp"
Tue 16 Nov 2004 36,352 ...H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\~WRL4020.tmp"
Mon 18 Sep 2006 20,992 ...H. --- "C:\Documents and Settings\Chris Matthews\My Documents\Our MS ride donation letter\~WRL2267.tmp"
Tue 9 Oct 2007 74,240 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Desktop\CIT Loan\~WRL1204.tmp"
Mon 8 Oct 2007 73,728 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Desktop\CIT Loan\~WRL1658.tmp"
Sun 26 Aug 2007 49,664 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL0003.tmp"
Mon 27 Aug 2007 49,152 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL0005.tmp"
Tue 7 Aug 2007 60,928 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL0300.tmp"
Sat 25 Aug 2007 44,032 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL0365.tmp"
Sat 25 Aug 2007 44,032 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL0602.tmp"
Tue 7 Aug 2007 60,928 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL0839.tmp"
Fri 17 Aug 2007 41,984 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL0974.tmp"
Sat 25 Aug 2007 44,544 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL1557.tmp"
Fri 24 Aug 2007 42,496 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL1631.tmp"
Thu 16 Aug 2007 41,472 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL1851.tmp"
Mon 8 Oct 2007 50,176 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL2017.tmp"
Sat 25 Aug 2007 43,520 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL2475.tmp"
Fri 17 Aug 2007 41,984 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL2924.tmp"
Mon 13 Aug 2007 59,904 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL3368.tmp"
Mon 13 Aug 2007 60,928 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\CentreforFamilyMedicine,Inc\~WRL3613.tmp"
Wed 7 Feb 2007 33,792 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\~WRL0001.tmp"
Tue 19 Oct 2004 22,016 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\~WRL0002.tmp"
Wed 7 Feb 2007 35,328 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\~WRL0003.tmp"
Tue 14 Sep 2004 23,552 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\~WRL0033.tmp"
Wed 7 Feb 2007 26,112 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\~WRL0776.tmp"
Wed 7 Feb 2007 35,328 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\~WRL1133.tmp"
Wed 7 Feb 2007 30,720 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\~WRL1168.tmp"
Wed 7 Feb 2007 35,328 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\~WRL1432.tmp"
Wed 7 Feb 2007 30,208 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\~WRL1445.tmp"
Thu 8 Feb 2007 34,816 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\~WRL1758.tmp"
Wed 7 Feb 2007 29,696 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\~WRL1963.tmp"
Wed 7 Feb 2007 35,840 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\~WRL3062.tmp"
Wed 7 Feb 2007 32,256 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\~WRL3781.tmp"
Mon 18 Sep 2006 19,456 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL0003.tmp"
Wed 20 Dec 2006 33,792 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL0004.tmp"
Mon 18 Sep 2006 19,456 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL0005.tmp"
Wed 20 Dec 2006 43,008 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL0317.tmp"
Wed 20 Dec 2006 34,816 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL1144.tmp"
Tue 19 Dec 2006 34,304 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL1268.tmp"
Tue 19 Dec 2006 31,744 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL1333.tmp"
Wed 20 Dec 2006 43,008 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL1418.tmp"
Tue 19 Dec 2006 33,280 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL1600.tmp"
Tue 19 Dec 2006 32,768 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL1619.tmp"
Wed 20 Dec 2006 44,544 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL2241.tmp"
Wed 20 Dec 2006 45,056 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL3257.tmp"
Wed 20 Dec 2006 44,032 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL3280.tmp"
Tue 19 Dec 2006 32,768 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL3639.tmp"
Wed 20 Dec 2006 32,256 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL3728.tmp"
Wed 20 Dec 2006 43,008 ...H. --- "C:\Documents and Settings\Chris Matthews\Application Data\Microsoft\Word\~WRL3792.tmp"
Mon 14 Mar 2005 27,136 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Templates\~WRL2409.tmp"
Tue 14 Sep 2004 24,576 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0003.tmp"
Sun 16 Oct 2005 21,504 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0004.tmp"
Mon 17 Oct 2005 26,112 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0005.tmp"
Mon 23 Jul 2007 20,480 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0006.tmp"
Thu 2 Aug 2007 55,808 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0007.tmp"
Fri 17 Aug 2007 49,152 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0008.tmp"
Sun 20 Nov 2005 26,685,440 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0022.tmp"
Tue 9 Oct 2007 72,704 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0055.tmp"
Sun 5 Mar 2006 247,808 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0066.tmp"
Mon 31 Oct 2005 23,552 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0067.tmp"
Sun 5 Mar 2006 248,832 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0091.tmp"
Sun 16 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0110.tmp"
Wed 16 Nov 2005 19,456 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0141.tmp"
Sun 16 Oct 2005 24,064 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0144.tmp"
Tue 9 May 2006 36,352 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0151.tmp"
Sun 30 Oct 2005 26,624 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0158.tmp"
Tue 16 Nov 2004 19,968 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0183.tmp"
Tue 9 May 2006 37,376 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0209.tmp"
Sat 25 Aug 2007 44,544 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0227.tmp"
Mon 17 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0242.tmp"
Mon 31 Oct 2005 26,624 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0246.tmp"
Mon 13 Aug 2007 62,464 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0261.tmp"
Mon 13 Aug 2007 60,416 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0304.tmp"
Wed 7 Feb 2007 28,160 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0329.tmp"
Sun 30 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0363.tmp"
Mon 31 Oct 2005 19,968 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0436.tmp"
Tue 9 May 2006 40,960 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0448.tmp"
Sat 25 Aug 2007 44,544 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0460.tmp"
Sun 12 Mar 2006 34,816 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0517.tmp"
Sun 16 Oct 2005 27,136 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0522.tmp"
Tue 7 Aug 2007 63,488 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0529.tmp"
Tue 14 Sep 2004 25,088 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0531.tmp"
Tue 7 Aug 2007 74,752 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0546.tmp"
Sun 12 Mar 2006 32,768 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0592.tmp"
Sun 5 Mar 2006 250,880 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0616.tmp"
Mon 8 May 2006 35,328 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0669.tmp"
Sun 16 Oct 2005 26,112 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0695.tmp"
Mon 22 Nov 2004 19,456 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0707.tmp"
Wed 7 Feb 2007 23,552 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0718.tmp"
Sat 25 Aug 2007 45,056 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0731.tmp"
Sat 25 Aug 2007 44,544 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0759.tmp"
Sun 12 Mar 2006 29,184 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0793.tmp"
Thu 2 Aug 2007 54,784 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0796.tmp"
Wed 16 Nov 2005 19,456 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0802.tmp"
Mon 17 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0861.tmp"
Tue 9 May 2006 39,936 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0933.tmp"
Mon 8 May 2006 33,792 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0941.tmp"
Sun 16 Oct 2005 22,528 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0949.tmp"
Sat 25 Aug 2007 44,544 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0960.tmp"
Mon 22 Nov 2004 19,456 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL0970.tmp"
Tue 16 Nov 2004 19,456 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1000.tmp"
Mon 31 Oct 2005 22,016 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1031.tmp"
Sat 25 Aug 2007 44,032 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1032.tmp"
Sun 5 Mar 2006 247,296 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1084.tmp"
Tue 9 Oct 2007 72,192 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1088.tmp"
Mon 17 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1139.tmp"
Tue 16 Nov 2004 19,456 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1169.tmp"
Tue 9 May 2006 35,328 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1222.tmp"
Sun 16 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1293.tmp"
Mon 8 May 2006 19,968 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1309.tmp"
Sun 16 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1349.tmp"
Sun 16 Oct 2005 23,552 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1372.tmp"
Mon 31 Oct 2005 22,016 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1396.tmp"
Mon 31 Oct 2005 27,136 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1424.tmp"
Sun 30 Oct 2005 24,576 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1431.tmp"
Thu 26 Oct 2006 36,352 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1502.tmp"
Sun 16 Oct 2005 27,136 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1506.tmp"
Sun 16 Oct 2005 23,552 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1529.tmp"
Sat 25 Aug 2007 51,200 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1530.tmp"
Tue 16 Nov 2004 19,456 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1533.tmp"
Wed 7 Feb 2007 26,624 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1565.tmp"
Mon 17 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1582.tmp"
Mon 8 May 2006 24,064 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1584.tmp"
Mon 8 May 2006 34,816 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1593.tmp"
Mon 13 Aug 2007 61,440 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1595.tmp"
Mon 30 Jul 2007 25,088 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1614.tmp"
Sun 5 Mar 2006 248,320 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1622.tmp"
Sat 25 Aug 2007 44,544 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1623.tmp"
Thu 2 Aug 2007 56,832 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1669.tmp"
Mon 31 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1682.tmp"
Tue 7 Aug 2007 26,624 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1685.tmp"
Mon 13 Aug 2007 61,440 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1703.tmp"
Sun 16 Oct 2005 27,136 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1730.tmp"
Mon 13 Aug 2007 63,488 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1750.tmp"
Sun 16 Oct 2005 22,016 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1755.tmp"
Tue 9 May 2006 35,840 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1758.tmp"
Sat 25 Aug 2007 44,032 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1774.tmp"
Mon 31 Oct 2005 23,552 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1892.tmp"
Mon 17 Oct 2005 26,112 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1894.tmp"
Tue 14 Sep 2004 24,576 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1921.tmp"
Tue 9 May 2006 38,912 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1954.tmp"
Mon 8 May 2006 29,696 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1959.tmp"
Sun 16 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL1981.tmp"
Tue 16 Nov 2004 20,992 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2025.tmp"
Mon 8 May 2006 23,040 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2029.tmp"
Wed 1 Dec 2004 27,648 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2061.tmp"
Tue 14 Sep 2004 24,576 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2087.tmp"
Mon 23 Jul 2007 20,992 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2115.tmp"
Wed 7 Feb 2007 22,016 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2130.tmp"
Sun 16 Oct 2005 21,504 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2137.tmp"
Sun 5 Mar 2006 249,856 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2153.tmp"
Wed 7 Feb 2007 21,504 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2154.tmp"
Mon 17 Oct 2005 25,088 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2155.tmp"
Sun 16 Oct 2005 22,016 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2175.tmp"
Wed 16 Nov 2005 20,480 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2221.tmp"
Sat 25 Aug 2007 44,032 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2237.tmp"
Mon 31 Oct 2005 19,968 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2256.tmp"
Mon 31 Oct 2005 26,112 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2271.tmp"
Mon 17 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2300.tmp"
Mon 13 Aug 2007 61,952 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2318.tmp"
Tue 9 May 2006 35,328 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2331.tmp"
Sun 16 Oct 2005 26,112 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2340.tmp"
Mon 17 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2437.tmp"
Sun 12 Mar 2006 35,840 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2482.tmp"
Sun 16 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2506.tmp"
Wed 7 Feb 2007 30,720 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2518.tmp"
Sat 25 Aug 2007 44,032 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2534.tmp"
Tue 9 Oct 2007 72,704 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2594.tmp"
Sun 5 Mar 2006 246,784 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2640.tmp"
Tue 7 Aug 2007 64,512 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2641.tmp"
Mon 31 Oct 2005 20,992 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2673.tmp"
Sun 16 Oct 2005 23,040 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2683.tmp"
Mon 31 Oct 2005 22,016 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2714.tmp"
Tue 9 May 2006 36,352 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2743.tmp"
Mon 13 Aug 2007 60,928 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2764.tmp"
Mon 31 Oct 2005 24,064 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2768.tmp"
Sat 25 Aug 2007 44,544 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2774.tmp"
Mon 13 Aug 2007 60,928 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2785.tmp"
Tue 14 Sep 2004 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2799.tmp"
Sun 5 Mar 2006 249,344 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2808.tmp"
Mon 22 Nov 2004 23,040 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2850.tmp"
Tue 9 May 2006 37,376 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2876.tmp"
Mon 13 Aug 2007 28,160 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2880.tmp"
Wed 7 Feb 2007 30,208 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2932.tmp"
Mon 8 May 2006 26,624 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2944.tmp"
Mon 17 Oct 2005 26,112 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL2982.tmp"
Fri 19 Nov 2004 19,456 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3083.tmp"
Mon 17 Oct 2005 25,088 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3097.tmp"
Tue 7 Aug 2007 64,512 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3123.tmp"
Sun 5 Mar 2006 249,344 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3126.tmp"
Sun 5 Mar 2006 248,320 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3139.tmp"
Mon 13 Aug 2007 60,928 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3165.tmp"
Sun 12 Mar 2006 36,864 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3189.tmp"
Wed 7 Feb 2007 19,456 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3194.tmp"
Sun 5 Mar 2006 250,880 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3201.tmp"
Mon 31 Oct 2005 23,552 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3415.tmp"
Tue 9 May 2006 35,840 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3429.tmp"
Sun 5 Mar 2006 251,392 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3451.tmp"
Sun 12 Mar 2006 31,232 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3455.tmp"
Mon 31 Oct 2005 23,552 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3556.tmp"
Wed 1 Dec 2004 21,504 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3558.tmp"
Mon 31 Oct 2005 24,064 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3578.tmp"
Tue 9 May 2006 41,472 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3580.tmp"
Sun 12 Mar 2006 35,328 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3582.tmp"
Sat 25 Aug 2007 45,056 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3593.tmp"
Tue 14 Sep 2004 23,552 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3634.tmp"
Wed 16 Nov 2005 20,480 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3647.tmp"
Sun 16 Oct 2005 23,552 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3686.tmp"
Wed 1 Dec 2004 19,968 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3733.tmp"
Mon 17 Oct 2005 26,112 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3751.tmp"
Mon 13 Aug 2007 59,392 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3809.tmp"
Sun 16 Oct 2005 21,504 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3819.tmp"
Sun 5 Mar 2006 245,248 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3825.tmp"
Mon 17 Oct 2005 25,600 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3849.tmp"
Sun 12 Mar 2006 27,648 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3859.tmp"
Sat 25 Aug 2007 44,032 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3875.tmp"
Wed 7 Feb 2007 30,720 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3885.tmp"
Sat 25 Aug 2007 44,032 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3894.tmp"
Sat 25 Aug 2007 44,032 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3897.tmp"
Sun 12 Mar 2006 27,648 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3901.tmp"
Wed 1 Dec 2004 22,528 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL3944.tmp"
Tue 9 Oct 2007 73,728 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL4020.tmp"
Sun 5 Mar 2006 251,392 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL4026.tmp"
Sun 5 Mar 2006 246,272 ...H. --- "C:\Documents and Settings\Dawn Swartwood\Application Data\Microsoft\Word\~WRL4086.tmp"
Sat 29 Oct 2005 19,456 A..H. --- "C:\Documents and Settings\Dawn Swartwood\My Documents\Dawn's Documents\Nursing Research CSULB\~WRL0003.tmp"
Sun 26 Aug 2007 49,664 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL0003.tmp"
Mon 27 Aug 2007 49,152 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL0005.tmp"
Tue 7 Aug 2007 60,928 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL0300.tmp"
Sat 25 Aug 2007 44,032 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL0365.tmp"
Sat 25 Aug 2007 44,032 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL0602.tmp"
Tue 7 Aug 2007 60,928 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL0839.tmp"
Fri 17 Aug 2007 41,984 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL0974.tmp"
Sat 25 Aug 2007 44,544 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL1557.tmp"
Fri 24 Aug 2007 42,496 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL1631.tmp"
Thu 16 Aug 2007 41,472 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL1851.tmp"
Mon 8 Oct 2007 50,176 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL2017.tmp"
Sat 25 Aug 2007 43,520 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL2475.tmp"
Fri 17 Aug 2007 41,984 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL2924.tmp"
Mon 13 Aug 2007 59,904 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL3368.tmp"
Mon 13 Aug 2007 60,928 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\CentreforFamilyMedicine,Inc\~WRL3613.tmp"
Wed 7 Feb 2007 33,792 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\~WRL0001.tmp"
Tue 19 Oct 2004 22,016 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\~WRL0002.tmp"
Wed 7 Feb 2007 35,328 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\~WRL0003.tmp"
Tue 14 Sep 2004 23,552 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\~WRL0033.tmp"
Wed 7 Feb 2007 26,112 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\~WRL0776.tmp"
Wed 7 Feb 2007 35,328 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\~WRL1133.tmp"
Wed 7 Feb 2007 30,720 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\~WRL1168.tmp"
Wed 7 Feb 2007 35,328 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\~WRL1432.tmp"
Wed 7 Feb 2007 30,208 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\~WRL1445.tmp"
Thu 8 Feb 2007 34,816 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\~WRL1758.tmp"
Wed 7 Feb 2007 29,696 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\~WRL1963.tmp"
Wed 7 Feb 2007 35,840 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\~WRL3062.tmp"
Wed 7 Feb 2007 32,256 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\~WRL3781.tmp"
Sat 29 Oct 2005 19,456 A..H. --- "C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\Dawn's Documents\Nursing Research CSULB\~WRL0003.tmp"

Finished!

ComboFix 08-01-15.4 - Chris Matthews 2008-01-16 21:58:39.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.819 [GMT -8:00]
Running from: C:\Documents and Settings\Chris Matthews\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Dawn Swartwood\g2mdlhlpx.exe
C:\Program Files\ini.ini\
C:\Program Files\racle~1
C:\WINDOWS\setup.exe
C:\WINDOWS\system32\svvut.ini
C:\WINDOWS\system32\svvut.ini2

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_CORE


((((((((((((((((((((((((( Files Created from 2007-12-17 to 2008-01-17 )))))))))))))))))))))))))))))))
.

2008-01-16 21:56 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-16 21:23 . 2008-01-16 21:23 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-01-16 21:19 . 2008-01-16 21:20 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-16 20:31 . 2008-01-16 20:31 <DIR> d-------- C:\VundoFix Backups
2008-01-06 11:22 . 2008-01-06 12:42 <DIR> d-------- C:\Documents and Settings\Chris Matthews\.housecall6.6
2008-01-05 08:25 . 2008-01-05 08:25 10,752 --a------ C:\WINDOWS\mgrs8949
2008-01-04 22:30 . 2008-01-16 20:22 <DIR> d-------- C:\Documents and Settings\Chris Matthews\Application Data\AVG7
2008-01-04 21:50 . 2004-10-15 18:32 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
2008-01-04 21:50 . 2004-10-15 18:17 60,496 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2008-01-04 21:50 . 2004-10-15 18:18 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2008-01-04 21:50 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg6n.sys
2008-01-04 21:50 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg5n.sys
2008-01-04 21:50 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg4n.sys
2008-01-04 21:50 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2008-01-04 21:49 . 2008-01-04 21:49 <DIR> d-------- C:\Program Files\Sygate
2008-01-04 21:48 . 2008-01-04 21:48 <DIR> d-------- C:\WINDOWS\McAfee.com
2008-01-04 21:34 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-01-04 21:27 . 2008-01-04 21:27 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-01-04 20:41 . 2008-01-04 20:41 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-04 20:41 . 2008-01-04 20:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-04 20:39 . 2008-01-04 20:39 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-04 16:18 . 2008-01-06 11:21 <DIR> d-------- C:\WINDOWS\system32\HouseCall 6.6
2008-01-04 16:18 . 2008-01-04 16:18 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\Application Data\HouseCall 6.6
2008-01-04 16:13 . 2008-01-04 21:24 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\.housecall6.6
2008-01-04 14:59 . 2008-01-04 15:10 <DIR> d-------- C:\Program Files\Panda Security
2008-01-04 13:05 . 2008-01-04 13:05 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-04 13:05 . 2008-01-10 16:23 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\Application Data\AVG7
2008-01-04 13:04 . 2008-01-04 13:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-04 12:39 . 2008-01-04 12:42 <DIR> d-------- C:\Program Files\Tiny Firewall Pro
2008-01-04 12:39 . 2008-01-04 12:42 <DIR> d-------- C:\Program Files\Common Files\PFShared
2008-01-04 12:39 . 2008-01-04 12:39 8 --a------ C:\WINDOWS\system32\probtp51.cnt
2008-01-04 12:25 . 2008-01-05 08:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-01-04 12:07 . 2008-01-04 12:31 14 --a------ C:\WINDOWS\system32\getfile.dat
2008-01-04 11:49 . 2008-01-04 11:49 <DIR> d-------- C:\kav
2008-01-04 11:04 . 2008-01-04 11:04 10,752 --a------ C:\Program Files\6475601.exe
2008-01-04 11:03 . 2008-01-04 11:03 10,752 --a------ C:\Program Files\6415224.exe
2008-01-04 11:02 . 2008-01-04 11:02 10,752 --a------ C:\Program Files\6354987.exe
2008-01-04 11:01 . 2008-01-04 11:01 10,752 --a------ C:\Program Files\6294871.exe
2008-01-04 09:13 . 2008-01-04 09:13 10,752 --a------ C:\Program Files\5042270.exe
2008-01-04 09:08 . 2008-01-10 17:56 5,680 --a------ C:\WINDOWS\system32\drivers\psntkd20.sys
2008-01-04 08:04 . 2008-01-16 22:07 67,645 --a------ C:\WINDOWS\system32\drivers\pshook11.sys
2008-01-04 08:03 . 2008-01-04 08:08 <DIR> d-------- C:\Program Files\Spyware Nuker
2008-01-02 07:24 . 2008-01-02 12:26 <DIR> d-------- C:\Program Files\EasySpywareCleaner
2008-01-02 07:24 . 2008-01-02 07:24 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\Application Data\EasySpywareCleaner.com
2007-12-31 12:44 . 2008-01-02 07:13 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
2007-12-31 09:37 . 2008-01-02 07:13 155,648 --a------ C:\WINDOWS\system32\NeroCheck .exe
2007-12-31 09:37 . 2008-01-02 07:13 40,960 --a------ C:\WINDOWS\system32\ezSP_Px .exe
2007-12-31 08:42 . 2008-01-04 09:08 <DIR> d--hs---- C:\WINDOWS\Q2hyaXMgTWF0dGhld3M
2007-12-31 08:41 . 2008-01-04 09:08 <DIR> d-------- C:\WINDOWS\system32\mr9
2007-12-31 08:41 . 2007-12-31 09:18 <DIR> d-------- C:\WINDOWS\system32\cc9
2007-12-31 08:41 . 2008-01-02 09:49 <DIR> d-------- C:\WINDOWS\system32\ardCo02
2007-12-31 08:41 . 2008-01-02 09:49 <DIR> d-------- C:\WINDOWS\system32\aj2
2007-12-31 08:41 . 2007-12-31 08:41 <DIR> d-------- C:\Temp\cEeer12
2007-12-31 08:41 . 2008-01-16 21:35 <DIR> d-------- C:\Temp
2007-12-17 10:40 . 2007-12-17 10:40 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\Application Data\Snapfish

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-11 01:34 --------- d-----w C:\Documents and Settings\Dawn Swartwood\Application Data\Ahead
2008-01-05 06:17 --------- d-----w C:\Program Files\Trend Micro
2008-01-03 00:57 --------- d-----w C:\Program Files\DVD Decrypter
2008-01-02 23:14 --------- d-----w C:\Documents and Settings\Chris Matthews\Application Data\Lavasoft
2008-01-02 16:01 --------- d-----w C:\Program Files\AirPort
2008-01-02 15:37 --------- d-----w C:\Program Files\Apoint
2007-12-31 21:03 76 ----a-w C:\Program Files\ini.ini
2007-04-24 00:45 356,352 -c--a-w C:\Documents and Settings\Chris Matthews\cwshredder.dll
2006-07-24 02:35 356,352 -c--a-w C:\Documents and Settings\Dawn Swartwood\cwshredder.dll
2005-07-30 00:24 472 --sha-r C:\WINDOWS\Q2hyaXMgTWF0dGhld3M\kZ1Vurg0nqIXx315xag.vbs
.
<pre>
----a-w		 1,961,984 2007-12-31 20:55:20  C:\Program Files\Ahead\Nero BackItUp\nbj  .exe
----a-w		   409,600 2008-01-02 15:13:50  C:\Program Files\AirPort\APDiskAgent .exe
----a-w		   114,688 2008-01-02 15:13:11  C:\Program Files\Apoint\Apoint .exe
----a-w		   335,872 2008-01-02 15:13:12  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
----a-w		 1,694,208 2008-01-02 15:13:58  C:\Program Files\Messenger\msmsgs .exe
----a-w		   118,784 2008-01-02 15:14:00  C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon .exe
----a-w			98,304 2008-01-02 15:13:30  C:\Program Files\Sony\HotKey Utility\HKserv .exe
----a-w			32,768 2008-01-02 15:13:34  C:\Program Files\Sony\ISB Utility\ISBMgr .exe
----a-w		   167,936 2008-01-02 15:13:28  C:\Program Files\Sony\VAIO Power Management\SPMgr .exe
----a-w		   135,168 2008-01-02 15:13:41  C:\Program Files\Sony\VAIO Update 2\VAIOUpdt .exe
----a-w			28,672 2008-01-02 15:13:24  C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal .exe
----a-w			15,360 2008-01-02 15:13:25  C:\WINDOWS\system32\ctfmon .exe
----a-w			40,960 2008-01-02 15:13:37  C:\WINDOWS\system32\ezSP_Px .exe
----a-w		   155,648 2008-01-02 15:13:45  C:\WINDOWS\system32\NeroCheck .exe
</pre>


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0026D161-E6EC-408B-9E73-7A181E632B3E}]
C:\Program Files\Windows Media Player\hokenov83122.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{654E6AB9-160E-4287-B8B9-2B9A1A6622FB}]
C:\Program Files\Windows Media Player\hokenov4444.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [ ]
"DVDXGhost"="" []
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\nbj .exe" [2007-12-31 12:55 1961984]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"H/PC Connection Agent"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 12:39 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Hcontrol"="C:\WINDOWS\ATK0100\Hcontrol.exe" [ ]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"Mouse Suite 98 Daemon"="ICO.EXE" []
"BluetoothAuthenticationAgent"="irprops.cpl" [2004-08-03 23:56 380416 C:\WINDOWS\system32\irprops.cpl]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [ ]
"HKSERV.EXE"="C:\Program Files\Sony\HotKey Utility\HKserv.exe" [ ]
"ezShieldProtector for Px"="C:\WINDOWS\system32\ezSP_Px .exe" [2008-01-02 07:13 40960]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 08:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"SWN2"="C:\Program Files\Spyware Nuker\swnxt.exe" [2006-06-09 08:11 4060160]
"BDSwitchAgent"="C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe" [ ]
"avp"="C:\WINDOWS\avp .exe" [ ]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-05-02 07:28 155648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-05 08:50 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-05 08:50 219136]

C:\Documents and Settings\Dawn Swartwood\Start Menu\Programs\Startup\
Trend Micro Anti-Spyware.lnk - C:\Program Files\Trend Micro\Tmas\Tmas.exe [2006-05-27 17:24:57]

C:\Documents and Settings\Chris Matthews\Start Menu\Programs\Startup\
Palm Registration.lnk - D:\Palm\register.exe [2005-08-08 11:36:14]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
DataViz Inc Messenger.lnk - C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe [2007-06-09 09:25:51]
HOTSYNCSHORTCUTNAME.lnk - D:\Palm\Hotsync.exe [2004-06-09 13:27:34]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-03-21 17:00:00]
Trend Micro Anti-Spyware.lnk - C:\Program Files\Trend Micro\Tmas\Tmas.exe [2006-05-27 17:24:57]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\MSN Gaming Zone\profsyvyqaq.html
FriendlyName=

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{03A80B1D-5C6A-42c2-9DFB-81B6005D8023}"= C:\Program Files\Trend Micro\Tmas\sshook.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hggfghf]
hggfghf.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

R2 VAIO Entertainment File Import Service;VAIO Entertainment File Import Service;C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe [2004-03-12 16:32]
R3 SPI;Sony Programmable I/O Control Device;C:\WINDOWS\system32\DRIVERS\SonyPI.sys [2001-08-17 04:51]
S2 AvgCore;AVG6 Kernel;C:\PROGRA~1\Grisoft\AVG6\avgcore.sys []
S2 AvgFsh;AVG6 Rezident Driver;C:\PROGRA~1\Grisoft\AVG6\avgfsh.sys []
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 12:50]
S3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;C:\WINDOWS\system32\Drivers\BrSerIf.sys [2004-09-29 03:24]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\WINDOWS\system32\Drivers\BrUsbSer.sys [2004-01-10 04:28]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 16:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 16:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 16:59]
S3 VAIO Entertainment UPnP Client Adapter;VAIO Entertainment UPnP Client Adapter;C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe [2004-03-12 15:57]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-16 22:07:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-16 22:10:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-17 06:10:13
.
2008-01-11 02:05:19 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:16:27 PM, on 1/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ezSP_Px .exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
D:\Palm\Hotsync.exe
D:\PROGRA~1\MICROS~1\rapimgr.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.usatoday.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {0026D161-E6EC-408B-9E73-7A181E632B3E} - C:\Program Files\Windows Media Player\hokenov83122.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {654E6AB9-160E-4287-B8B9-2B9A1A6622FB} - C:\Program Files\Windows Media Player\hokenov4444.dll (file missing)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px .exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [SWN2] C:\Program Files\Spyware Nuker\swnxt.exe /h
O4 - HKLM\..\Run: [BDSwitchAgent] C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe
O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp .exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj .exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Palm Registration.lnk = D:\Palm\register.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = D:\Palm\Hotsync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~1\INetRepl.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...83/mcinsctl.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan.com/as/cabs/ascstubie.cab
O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://download.sidestep.com/get/k00719/sb028.cab
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} (Actimage Room Control) - http://hutchence.armstrong.com/ib/database...timage40803.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,20/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...200/mcfscan.cab
O20 - Winlogon Notify: hggfghf - hggfghf.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG6 Service (AvgServ) - Unknown owner - (no file)
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\VmGateway.exe
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Video\GPVSvr.exe
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\MSN Gaming Zone\profsyvyqaq.html

--
End of file - 13772 bytes

#7 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:18 AM

Posted 17 January 2008 - 08:14 AM

Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\Program Files\6475601.exe
C:\Program Files\6415224.exe
C:\Program Files\6354987.exe
C:\Program Files\6294871.exe
C:\Program Files\5042270.exe
Folder::
C:\WINDOWS\mgrs8949
C:\Program Files\EasySpywareCleaner
C:\Documents and Settings\Dawn Swartwood\Application Data\EasySpywareCleaner.com
C:\WINDOWS\Q2hyaXMgTWF0dGhld3M
C:\WINDOWS\system32\mr9
C:\WINDOWS\system32\cc9
C:\WINDOWS\system32\ardCo02
C:\WINDOWS\system32\aj2
C:\Temp\cEeer12
Registry::
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"%windir%\\system32\\winav.exe"=-
"C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\trant.exe"=-
"C:\\Documents and Settings\\Chris Matthews\\Application Data\\trant.exe"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\winav.exe"=-
"C:\\Documents and Settings\\Chris Matthews\\Application Data\\trant.exe"=-
"C:\\Documents and Settings\\Dawn Swartwood\\Application Data\\trant.exe"=-
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0026D161-E6EC-408B-9E73-7A181E632B3E}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{654E6AB9-160E-4287-B8B9-2B9A1A6622FB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avp"=-
[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hggfghf]

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

Download RenV.exe to your desktop,double click to run it:
http://download.bleepingcomputer.com/sUBs/Beta/RenV.exe
When its finished it will produce a Log.
Please post the contents of that Log into your next reply.
Posted Image
Posted Image

#8 ripstussy

ripstussy
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 17 January 2008 - 01:24 PM

ComboFix 08-01-15.4 - Chris Matthews 2008-01-17 10:11:35.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.782 [GMT -8:00]
Running from: C:\Documents and Settings\Chris Matthews\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Chris Matthews\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\Program Files\5042270.exe
C:\Program Files\6294871.exe
C:\Program Files\6354987.exe
C:\Program Files\6415224.exe
C:\Program Files\6475601.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\5042270.exe
C:\Program Files\6294871.exe
C:\Program Files\6354987.exe
C:\Program Files\6415224.exe
C:\Program Files\6475601.exe
C:\Program Files\EasySpywareCleaner
C:\Program Files\ini.ini\
C:\Temp\cEeer12
C:\Temp\cEeer12\skAt.log
C:\WINDOWS\mgrs8949\
C:\WINDOWS\Q2hyaXMgTWF0dGhld3M
C:\WINDOWS\Q2hyaXMgTWF0dGhld3M\kZ1Vurg0nqIXx315xag.vbs
C:\WINDOWS\system32\aj2
C:\WINDOWS\system32\ardCo02
C:\WINDOWS\system32\cc9
C:\WINDOWS\system32\mr9

.
((((((((((((((((((((((((( Files Created from 2007-12-17 to 2008-01-17 )))))))))))))))))))))))))))))))
.

2008-01-16 21:56 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-16 21:23 . 2008-01-16 21:23 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-01-16 21:19 . 2008-01-16 21:20 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-16 20:31 . 2008-01-16 20:31 <DIR> d-------- C:\VundoFix Backups
2008-01-06 11:22 . 2008-01-06 12:42 <DIR> d-------- C:\Documents and Settings\Chris Matthews\.housecall6.6
2008-01-05 08:25 . 2008-01-05 08:25 10,752 --a------ C:\WINDOWS\mgrs8949
2008-01-04 22:30 . 2008-01-17 09:52 <DIR> d-------- C:\Documents and Settings\Chris Matthews\Application Data\AVG7
2008-01-04 21:50 . 2004-10-15 18:32 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
2008-01-04 21:50 . 2004-10-15 18:17 60,496 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2008-01-04 21:50 . 2004-10-15 18:18 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2008-01-04 21:50 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg6n.sys
2008-01-04 21:50 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg5n.sys
2008-01-04 21:50 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg4n.sys
2008-01-04 21:50 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2008-01-04 21:49 . 2008-01-04 21:49 <DIR> d-------- C:\Program Files\Sygate
2008-01-04 21:48 . 2008-01-04 21:48 <DIR> d-------- C:\WINDOWS\McAfee.com
2008-01-04 21:34 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-01-04 21:27 . 2008-01-04 21:27 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-01-04 20:41 . 2008-01-04 20:41 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-04 20:41 . 2008-01-04 20:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-04 20:39 . 2008-01-04 20:39 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-04 16:18 . 2008-01-06 11:21 <DIR> d-------- C:\WINDOWS\system32\HouseCall 6.6
2008-01-04 16:18 . 2008-01-04 16:18 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\Application Data\HouseCall 6.6
2008-01-04 16:13 . 2008-01-04 21:24 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\.housecall6.6
2008-01-04 14:59 . 2008-01-04 15:10 <DIR> d-------- C:\Program Files\Panda Security
2008-01-04 13:05 . 2008-01-04 13:05 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-04 13:05 . 2008-01-10 16:23 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\Application Data\AVG7
2008-01-04 13:04 . 2008-01-04 13:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-04 12:39 . 2008-01-04 12:42 <DIR> d-------- C:\Program Files\Tiny Firewall Pro
2008-01-04 12:39 . 2008-01-04 12:42 <DIR> d-------- C:\Program Files\Common Files\PFShared
2008-01-04 12:39 . 2008-01-04 12:39 8 --a------ C:\WINDOWS\system32\probtp51.cnt
2008-01-04 12:25 . 2008-01-05 08:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-01-04 12:07 . 2008-01-04 12:31 14 --a------ C:\WINDOWS\system32\getfile.dat
2008-01-04 11:49 . 2008-01-04 11:49 <DIR> d-------- C:\kav
2008-01-04 09:08 . 2008-01-10 17:56 5,680 --a------ C:\WINDOWS\system32\drivers\psntkd20.sys
2008-01-04 08:04 . 2008-01-17 09:52 67,645 --a------ C:\WINDOWS\system32\drivers\pshook11.sys
2008-01-04 08:03 . 2008-01-04 08:08 <DIR> d-------- C:\Program Files\Spyware Nuker
2008-01-02 07:24 . 2008-01-02 07:24 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\Application Data\EasySpywareCleaner.com
2007-12-31 12:44 . 2008-01-02 07:13 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
2007-12-31 09:37 . 2008-01-02 07:13 155,648 --a------ C:\WINDOWS\system32\NeroCheck .exe
2007-12-31 09:37 . 2008-01-02 07:13 40,960 --a------ C:\WINDOWS\system32\ezSP_Px .exe
2007-12-31 08:41 . 2008-01-17 10:17 <DIR> d-------- C:\Temp
2007-12-17 10:40 . 2007-12-17 10:40 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\Application Data\Snapfish

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-11 01:34 --------- d-----w C:\Documents and Settings\Dawn Swartwood\Application Data\Ahead
2008-01-05 06:17 --------- d-----w C:\Program Files\Trend Micro
2008-01-03 00:57 --------- d-----w C:\Program Files\DVD Decrypter
2008-01-02 23:14 --------- d-----w C:\Documents and Settings\Chris Matthews\Application Data\Lavasoft
2008-01-02 16:01 --------- d-----w C:\Program Files\AirPort
2008-01-02 15:37 --------- d-----w C:\Program Files\Apoint
2007-12-31 21:03 76 ----a-w C:\Program Files\ini.ini
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-28 01:39 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-09-04 21:52 65,109 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_09_04_09_03_02_small.dmp.zip
2007-04-24 00:45 356,352 -c--a-w C:\Documents and Settings\Chris Matthews\cwshredder.dll
2006-07-24 02:35 356,352 -c--a-w C:\Documents and Settings\Dawn Swartwood\cwshredder.dll
2006-05-13 14:23 50,302 -c--a-w C:\WINDOWS\Internet Logs\iTunes_2nd_2006_05_11_21_41_37_small.dmp.zip
.
<pre>
----a-w		 1,961,984 2007-12-31 20:55:20  C:\Program Files\Ahead\Nero BackItUp\nbj  .exe
----a-w		   409,600 2008-01-02 15:13:50  C:\Program Files\AirPort\APDiskAgent .exe
----a-w		   114,688 2008-01-02 15:13:11  C:\Program Files\Apoint\Apoint .exe
----a-w		   335,872 2008-01-02 15:13:12  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
----a-w		 1,694,208 2008-01-02 15:13:58  C:\Program Files\Messenger\msmsgs .exe
----a-w		   118,784 2008-01-02 15:14:00  C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon .exe
----a-w			98,304 2008-01-02 15:13:30  C:\Program Files\Sony\HotKey Utility\HKserv .exe
----a-w			32,768 2008-01-02 15:13:34  C:\Program Files\Sony\ISB Utility\ISBMgr .exe
----a-w		   167,936 2008-01-02 15:13:28  C:\Program Files\Sony\VAIO Power Management\SPMgr .exe
----a-w		   135,168 2008-01-02 15:13:41  C:\Program Files\Sony\VAIO Update 2\VAIOUpdt .exe
----a-w			28,672 2008-01-02 15:13:24  C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal .exe
----a-w			15,360 2008-01-02 15:13:25  C:\WINDOWS\system32\ctfmon .exe
----a-w			40,960 2008-01-02 15:13:37  C:\WINDOWS\system32\ezSP_Px .exe
----a-w		   155,648 2008-01-02 15:13:45  C:\WINDOWS\system32\NeroCheck .exe
</pre>


((((((((((((((((((((((((((((( snapshot@2008-01-16_22.09.53.66 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-17 05:57:13 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-17 18:11:08 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-17 05:57:13 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-17 18:11:08 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-17 05:57:13 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-17 18:11:08 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-17 05:57:14 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-17 18:11:09 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-17 05:57:14 5,201,920 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-17 18:11:11 5,201,920 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-17 05:57:15 344,064 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-17 18:11:12 344,064 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0026D161-E6EC-408B-9E73-7A181E632B3E}]
C:\Program Files\Windows Media Player\hokenov83122.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{654E6AB9-160E-4287-B8B9-2B9A1A6622FB}]
C:\Program Files\Windows Media Player\hokenov4444.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [ ]
"DVDXGhost"="" []
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\nbj .exe" [2007-12-31 12:55 1961984]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"H/PC Connection Agent"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 12:39 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Hcontrol"="C:\WINDOWS\ATK0100\Hcontrol.exe" [ ]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"Mouse Suite 98 Daemon"="ICO.EXE" []
"BluetoothAuthenticationAgent"="irprops.cpl" [2004-08-03 23:56 380416 C:\WINDOWS\system32\irprops.cpl]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [ ]
"HKSERV.EXE"="C:\Program Files\Sony\HotKey Utility\HKserv.exe" [ ]
"ezShieldProtector for Px"="C:\WINDOWS\system32\ezSP_Px .exe" [2008-01-02 07:13 40960]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 08:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"SWN2"="C:\Program Files\Spyware Nuker\swnxt.exe" [2006-06-09 08:11 4060160]
"BDSwitchAgent"="C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe" [ ]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-05-02 07:28 155648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-05 08:50 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-05 08:50 219136]

C:\Documents and Settings\Dawn Swartwood\Start Menu\Programs\Startup\
Trend Micro Anti-Spyware.lnk - C:\Program Files\Trend Micro\Tmas\Tmas.exe [2006-05-27 17:24:57]

C:\Documents and Settings\Chris Matthews\Start Menu\Programs\Startup\
Palm Registration.lnk - D:\Palm\register.exe [2005-08-08 11:36:14]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
DataViz Inc Messenger.lnk - C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe [2007-06-09 09:25:51]
HOTSYNCSHORTCUTNAME.lnk - D:\Palm\Hotsync.exe [2004-06-09 13:27:34]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-03-21 17:00:00]
Trend Micro Anti-Spyware.lnk - C:\Program Files\Trend Micro\Tmas\Tmas.exe [2006-05-27 17:24:57]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\MSN Gaming Zone\profsyvyqaq.html
FriendlyName=

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{03A80B1D-5C6A-42c2-9DFB-81B6005D8023}"= C:\Program Files\Trend Micro\Tmas\sshook.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hggfghf]
hggfghf.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

R2 VAIO Entertainment File Import Service;VAIO Entertainment File Import Service;C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe [2004-03-12 16:32]
R3 SPI;Sony Programmable I/O Control Device;C:\WINDOWS\system32\DRIVERS\SonyPI.sys [2001-08-17 04:51]
S2 AvgCore;AVG6 Kernel;C:\PROGRA~1\Grisoft\AVG6\avgcore.sys []
S2 AvgFsh;AVG6 Rezident Driver;C:\PROGRA~1\Grisoft\AVG6\avgfsh.sys []
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 12:50]
S3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;C:\WINDOWS\system32\Drivers\BrSerIf.sys [2004-09-29 03:24]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\WINDOWS\system32\Drivers\BrUsbSer.sys [2004-01-10 04:28]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 16:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 16:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 16:59]
S3 VAIO Entertainment UPnP Client Adapter;VAIO Entertainment UPnP Client Adapter;C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe [2004-03-12 15:57]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-17 10:17:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-17 10:19:50
ComboFix-quarantined-files.txt 2008-01-17 18:19:30
ComboFix2.txt 2008-01-17 06:10:21
.
2008-01-11 02:05:19 --- E O F ---
Ran on Thu 01/17/2008 - 10:23:14.46

----a-w		 1,961,984 2007-12-31 20:55:20  C:\Program Files\Ahead\Nero BackItUp\nbj  .exe
----a-w		   409,600 2008-01-02 15:13:50  C:\Program Files\AirPort\APDiskAgent .exe
----a-w		   114,688 2008-01-02 15:13:11  C:\Program Files\Apoint\Apoint .exe
----a-w		   335,872 2008-01-02 15:13:12  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
----a-w		 1,694,208 2008-01-02 15:13:58  C:\Program Files\Messenger\msmsgs .exe
----a-w		   118,784 2008-01-02 15:14:00  C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon .exe
----a-w			98,304 2008-01-02 15:13:30  C:\Program Files\Sony\HotKey Utility\HKserv .exe
----a-w			32,768 2008-01-02 15:13:34  C:\Program Files\Sony\ISB Utility\ISBMgr .exe
----a-w		   167,936 2008-01-02 15:13:28  C:\Program Files\Sony\VAIO Power Management\SPMgr .exe
----a-w		   135,168 2008-01-02 15:13:41  C:\Program Files\Sony\VAIO Update 2\VAIOUpdt .exe
----a-w			28,672 2008-01-02 15:13:24  C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal .exe
----a-w			15,360 2008-01-02 15:13:25  C:\WINDOWS\system32\ctfmon .exe
----a-w			40,960 2008-01-02 15:13:37  C:\WINDOWS\system32\ezSP_Px .exe
----a-w		   155,648 2008-01-02 15:13:45  C:\WINDOWS\system32\NeroCheck .exe

 Entries:			   14  (14)
 Directories:			0  Files:			14
 Bytes:		  5,309,952  Blocks:	   10,371


#9 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:18 AM

Posted 17 January 2008 - 02:41 PM

Posted Image
Refering to the picture above, drag Log.txt into RenV.exe
When finished, it shall produce a new log for you.
Post that log in your next reply.

Run this online virus/spyware scan using Internet Explorer:
Kaspersky WebScanner
Next click Kaspersky Online Scanner
You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then begin downloading the latest definition files:
Once the files have been downloaded click on NEXT
Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Standard
Scan Options:
Scan Archives
Scan Mail Bases
Click OK
Now under select a target to scan:
Select My Computer
This will start the program and scan your system.
The scan will take a while so be patient and let it run.
Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste the contents of that file into your next reply.

If the above link doesn't work,try this:
http://www.kaspersky.com/kos/english/kavwebscan.html
Posted Image
Posted Image

#10 ripstussy

ripstussy
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 17 January 2008 - 05:09 PM

Ran on Thu 01/17/2008 - 14:07:21.88



----a-w		 1,961,984 2007-12-31 20:55:20  C:\Program Files\Ahead\Nero BackItUp\nbj  .exe

----a-w		   409,600 2008-01-02 15:13:50  C:\Program Files\AirPort\APDiskAgent .exe

----a-w		   114,688 2008-01-02 15:13:11  C:\Program Files\Apoint\Apoint .exe

----a-w		   335,872 2008-01-02 15:13:12  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe

----a-w		 1,694,208 2008-01-02 15:13:58  C:\Program Files\Messenger\msmsgs .exe

----a-w		   118,784 2008-01-02 15:14:00  C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon .exe

----a-w			98,304 2008-01-02 15:13:30  C:\Program Files\Sony\HotKey Utility\HKserv .exe

----a-w			32,768 2008-01-02 15:13:34  C:\Program Files\Sony\ISB Utility\ISBMgr .exe

----a-w		   167,936 2008-01-02 15:13:28  C:\Program Files\Sony\VAIO Power Management\SPMgr .exe

----a-w		   135,168 2008-01-02 15:13:41  C:\Program Files\Sony\VAIO Update 2\VAIOUpdt .exe

----a-w			28,672 2008-01-02 15:13:24  C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal .exe

----a-w			15,360 2008-01-02 15:13:25  C:\WINDOWS\system32\ctfmon .exe

----a-w			40,960 2008-01-02 15:13:37  C:\WINDOWS\system32\ezSP_Px .exe

----a-w		   155,648 2008-01-02 15:13:45  C:\WINDOWS\system32\NeroCheck .exe



 Entries:			   14  (14)

 Directories:			0  Files:			14

 Bytes:		  5,309,952  Blocks:	   10,371


#11 ripstussy

ripstussy
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 17 January 2008 - 07:15 PM

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, January 17, 2008 4:11:30 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/01/2008
Kaspersky Anti-Virus database records: 485016
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 55543
Number of viruses found: 4
Number of infected objects: 37
Number of suspicious objects: 0
Duration of the scan process: 00:51:13

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.ldb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.mdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\VAIO Entertainment Platform\1.0\VzCdb\MtData.ldb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\VAIO Entertainment Platform\1.0\VzCdb\MtData.mdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip/mgrs.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Chris Matthews\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\Chris Matthews\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Chris Matthews\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Chris Matthews\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Chris Matthews\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Chris Matthews\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Chris Matthews\Local Settings\History\History.IE5\MSHist012008011720080118\index.dat Object is locked skipped
C:\Documents and Settings\Chris Matthews\Local Settings\Temp\WCESLog.log Object is locked skipped
C:\Documents and Settings\Chris Matthews\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Chris Matthews\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Chris Matthews\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Chris Matthews\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Dawn Swartwood\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-69ee0d96-7c342a4f.zip/vlocal.class Infected: Trojan-Downloader.Java.Agent.f skipped
C:\Documents and Settings\Dawn Swartwood\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-69ee0d96-7c342a4f.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Dawn Swartwood\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-69ee0e0e-37f04532.zip/vlocal.class Infected: Trojan-Downloader.Java.Agent.f skipped
C:\Documents and Settings\Dawn Swartwood\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-69ee0e0e-37f04532.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Dawn Swartwood\Local Settings\Application Data\Microsoft\CD Burning\LoaderBackup-(2007-10-22).ipd Object is locked skipped
C:\Documents and Settings\Dawn Swartwood\My Documents\LoaderBackup-(2007-10-22).ipd Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Sygate\SPF\debug.log Object is locked skipped
C:\Program Files\Sygate\SPF\rawlog.log Object is locked skipped
C:\Program Files\Sygate\SPF\seclog.log Object is locked skipped
C:\Program Files\Sygate\SPF\syslog.log Object is locked skipped
C:\Program Files\Sygate\SPF\tralog.log Object is locked skipped
C:\QooBox\Quarantine\C\Program Files\5042270.exe.vir Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\QooBox\Quarantine\C\Program Files\6294871.exe.vir Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\QooBox\Quarantine\C\Program Files\6354987.exe.vir Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\QooBox\Quarantine\C\Program Files\6415224.exe.vir Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\QooBox\Quarantine\C\Program Files\6475601.exe.vir Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\SDFix\backups\backups.zip/backups/profsyvyqaq.html Infected: Trojan-Clicker.HTML.IFrame.dn skipped
C:\SDFix\backups\backups.zip ZIP: infected - 1 skipped
C:\SDFix\backups\catchme.zip/core.sys Infected: Rootkit.Win32.Agent.sg skipped
C:\SDFix\backups\catchme.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121926.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121927.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121928.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121929.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121930.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121931.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121932.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121933.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121934.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121935.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121936.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121937.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121946.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121962.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP429\A0121974.exe Object is locked skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP430\A0121976.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP431\A0121986.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP433\A0122106.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP433\A0122107.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP433\A0122108.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP433\A0122109.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP433\A0122110.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP433\change.log Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\user32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\win32k.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\accwiz.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\crypt32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\cryptsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hh.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hhctrl.ocx Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hhsetup.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\html32.cnv Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\itircl.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\itss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\locator.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\magnify.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\migwiz.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\mrxsmb.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\msconv97.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\narrator.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\newdev.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ole32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\pchshell.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\raspptp.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\rpcrt4.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\rpcss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\shdocvw.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\shell32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\shmedia.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\srrstr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\srv.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\urlmon.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\user32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\winsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\dhcpcsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\ndis.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\ndisuio.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\netshell.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\wzcdlg.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\wzcsapi.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\wzcsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828028$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\xpsp2res.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\dao360.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\expsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msexch40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msexcl40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjet40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjetoledb40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjint40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjter40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjtes40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msltus40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\mspbde40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msrd2x40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msrd3x40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msrepl40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\mstext40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\mswdat10.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\mswstr10.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msxbde40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\vbajet32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\fldrclnr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\shell32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\sxs.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\wmp.dll Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\mgrs8949 Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{3BC3A3E4-AABF-49CF-B337-1041338BAA89}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\JET33FB.tmp Object is locked skipped
C:\WINDOWS\Temp\JET34C3.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\4602c6525703517c281f0e32c78133\%temp%dd_msxml_retMSI.txt Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{BE6D594A-9937-4757-9D7D-47F11C10FAC3}\RP433\change.log Object is locked skipped

Scan process completed.

#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:18 AM

Posted 18 January 2008 - 04:27 AM

First enable the viewing of hidden files and folders,reverse the process once you've done below:
http://www.bleepingcomputer.com/tutorials/how-to-see-hidden-files-in-windows/

Delete everything inside this cache:
C:\Documents and Settings\Dawn Swartwood\Application Data\Sun\Java\Deployment\cache

Clear your 'System Restore' points by doing the following:
Right-click on 'My Computer' and select 'Properties'.
Select 'System Restore'.
Select 'Turn Off System Restore On All Drives'.
Select 'Apply'.
You will then get the following warning:
"You have chosen to turn off System Restore.
If you continue,all existing restore points will be deleted,and you will not be able to track or undo changes to your computer.
Do you want to turn off System Restore?".
Then select 'Yes',your 'System Restore' directories will be purged.

Restart your pc.

Turn 'System Restore' back on:

Right click on 'My Computer' and select 'Properties'.
Select 'System Restore'.
Unselect 'Turn Off System Restore On All Drives'.
Select 'Apply',then click 'Ok'.

Click on Start/Run,type cleanmgr into the 'Open:' space,then press Ok.
Let it scan your system for files to remove.
Make sure these 3 are checked and nothing else,then press Ok.
* Temporary Files
* Temporary Internet Files
* Recycle Bin



Download ATF Cleaner by Atribune:
http://www.atribune.org/ccount/click.php?id=1
Do not run it just yet.

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.
Do not run it just yet.

You might want to print/copy the following as you need to be in Safe Mode from here on.

Reboot your computer into SAFE MODE using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Find and delete:
C:\WINDOWS\mgrs8949
C:\SDFix

Now double-click ATF-Cleaner.exe to run the program.
Click 'Select All' found at the bottom of the list.
Click the 'Empty Selected' button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

If you use Opera browser,do this also:
Click Opera at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.
Click 'Exit' on the Main menu to close the program.

Now Start SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.


Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Posted Image
Posted Image

#13 ripstussy

ripstussy
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 18 January 2008 - 03:09 PM

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/18/2008 at 11:38 AM

Application Version : 3.9.1008

Core Rules Database Version : 3382
Trace Rules Database Version: 1376

Scan type : Complete Scan
Total Scan Time : 00:48:59

Memory items scanned : 187
Memory threats detected : 0
Registry items scanned : 6086
Registry threats detected : 1
File items scanned : 35004
File threats detected : 2

Adware.SideStep Toolbar
HKU\S-1-5-21-2478895022-2323910406-1417927495-1005\Software\Microsoft\Internet Explorer\Explorer Bars\{83B28A74-640D-48F4-9F51-E80EED7CC7E0}

Trojan.Unknown Origin
C:\QOOBOX\QUARANTINE\C\WINDOWS\Q2HYAXMGTWF0DGHLD3M\KZ1VURG0NQIXX315XAG.VBS.VIR

Malware.SpywareNuker
C:\WINDOWS\SYSTEM32\DRIVERS\PSHOOK11.SYS




ComboFix 08-01-15.4 - Chris Matthews 2008-01-18 11:55:48.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.821 [GMT -8:00]
Running from: C:\Documents and Settings\Chris Matthews\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\ini.ini\

.
((((((((((((((((((((((((( Files Created from 2007-12-18 to 2008-01-18 )))))))))))))))))))))))))))))))
.

2008-01-18 11:47 . 2008-01-18 11:47 67,645 --a------ C:\WINDOWS\system32\drivers\pshook11.sys
2008-01-18 10:38 . 2008-01-18 11:47 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-18 10:38 . 2008-01-18 10:38 <DIR> d-------- C:\Documents and Settings\Chris Matthews\Application Data\SUPERAntiSpyware.com
2008-01-18 10:38 . 2008-01-18 10:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-17 14:45 . 2008-01-17 14:45 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-17 14:45 . 2008-01-17 14:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-17 10:37 . 2008-01-17 10:37 94 --a------ C:\WINDOWS\wininit.ini
2008-01-16 21:56 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-16 21:23 . 2008-01-16 21:23 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-01-16 21:19 . 2008-01-18 10:44 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-16 20:31 . 2008-01-16 20:31 <DIR> d-------- C:\VundoFix Backups
2008-01-06 11:22 . 2008-01-06 12:42 <DIR> d-------- C:\Documents and Settings\Chris Matthews\.housecall6.6
2008-01-04 22:30 . 2008-01-18 09:10 <DIR> d-------- C:\Documents and Settings\Chris Matthews\Application Data\AVG7
2008-01-04 21:50 . 2004-10-15 18:32 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
2008-01-04 21:50 . 2004-10-15 18:17 60,496 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2008-01-04 21:50 . 2004-10-15 18:18 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2008-01-04 21:50 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg6n.sys
2008-01-04 21:50 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg5n.sys
2008-01-04 21:50 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg4n.sys
2008-01-04 21:50 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2008-01-04 21:49 . 2008-01-04 21:49 <DIR> d-------- C:\Program Files\Sygate
2008-01-04 21:48 . 2008-01-04 21:48 <DIR> d-------- C:\WINDOWS\McAfee.com
2008-01-04 21:34 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-01-04 21:27 . 2008-01-04 21:27 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-01-04 20:41 . 2008-01-04 20:41 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-04 20:41 . 2008-01-04 20:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-04 20:39 . 2008-01-18 10:37 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-04 16:18 . 2008-01-06 11:21 <DIR> d-------- C:\WINDOWS\system32\HouseCall 6.6
2008-01-04 16:18 . 2008-01-04 16:18 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\Application Data\HouseCall 6.6
2008-01-04 16:13 . 2008-01-04 21:24 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\.housecall6.6
2008-01-04 14:59 . 2008-01-04 15:10 <DIR> d-------- C:\Program Files\Panda Security
2008-01-04 13:05 . 2008-01-04 13:05 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-04 13:05 . 2008-01-18 08:58 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\Application Data\AVG7
2008-01-04 13:04 . 2008-01-04 13:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-04 12:39 . 2008-01-04 12:42 <DIR> d-------- C:\Program Files\Tiny Firewall Pro
2008-01-04 12:39 . 2008-01-04 12:42 <DIR> d-------- C:\Program Files\Common Files\PFShared
2008-01-04 12:39 . 2008-01-04 12:39 8 --a------ C:\WINDOWS\system32\probtp51.cnt
2008-01-04 12:25 . 2008-01-05 08:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-01-04 12:07 . 2008-01-04 12:31 14 --a------ C:\WINDOWS\system32\getfile.dat
2008-01-04 11:49 . 2008-01-04 11:49 <DIR> d-------- C:\kav
2008-01-04 09:08 . 2008-01-10 17:56 5,680 --a------ C:\WINDOWS\system32\drivers\psntkd20.sys
2008-01-04 08:03 . 2008-01-04 08:08 <DIR> d-------- C:\Program Files\Spyware Nuker
2008-01-02 07:24 . 2008-01-02 07:24 <DIR> d-------- C:\Documents and Settings\Dawn Swartwood\Application Data\EasySpywareCleaner.com
2007-12-31 12:44 . 2008-01-02 07:13 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
2007-12-31 09:37 . 2008-01-02 07:13 155,648 --a------ C:\WINDOWS\system32\NeroCheck .exe
2007-12-31 09:37 . 2008-01-02 07:13 40,960 --a------ C:\WINDOWS\system32\ezSP_Px .exe
2007-12-31 08:41 . 2008-01-17 10:17 <DIR> d-------- C:\Temp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-11 01:34 --------- d-----w C:\Documents and Settings\Dawn Swartwood\Application Data\Ahead
2008-01-05 06:17 --------- d-----w C:\Program Files\Trend Micro
2008-01-03 00:57 --------- d-----w C:\Program Files\DVD Decrypter
2008-01-02 23:14 --------- d-----w C:\Documents and Settings\Chris Matthews\Application Data\Lavasoft
2008-01-02 16:01 --------- d-----w C:\Program Files\AirPort
2008-01-02 15:37 --------- d-----w C:\Program Files\Apoint
2007-12-31 21:03 76 ----a-w C:\Program Files\ini.ini
2007-12-17 18:40 --------- d-----w C:\Documents and Settings\Dawn Swartwood\Application Data\Snapfish
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-28 01:39 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-09-04 21:52 65,109 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_09_04_09_03_02_small.dmp.zip
2007-04-24 00:45 356,352 -c--a-w C:\Documents and Settings\Chris Matthews\cwshredder.dll
2006-07-24 02:35 356,352 -c--a-w C:\Documents and Settings\Dawn Swartwood\cwshredder.dll
2006-05-13 14:23 50,302 -c--a-w C:\WINDOWS\Internet Logs\iTunes_2nd_2006_05_11_21_41_37_small.dmp.zip
.
<pre>
----a-w		 1,961,984 2007-12-31 20:55:20  C:\Program Files\Ahead\Nero BackItUp\nbj  .exe
----a-w		   409,600 2008-01-02 15:13:50  C:\Program Files\AirPort\APDiskAgent .exe
----a-w		   114,688 2008-01-02 15:13:11  C:\Program Files\Apoint\Apoint .exe
----a-w		   335,872 2008-01-02 15:13:12  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
----a-w		 1,694,208 2008-01-02 15:13:58  C:\Program Files\Messenger\msmsgs .exe
----a-w		   118,784 2008-01-02 15:14:00  C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon .exe
----a-w			98,304 2008-01-02 15:13:30  C:\Program Files\Sony\HotKey Utility\HKserv .exe
----a-w			32,768 2008-01-02 15:13:34  C:\Program Files\Sony\ISB Utility\ISBMgr .exe
----a-w		   167,936 2008-01-02 15:13:28  C:\Program Files\Sony\VAIO Power Management\SPMgr .exe
----a-w		   135,168 2008-01-02 15:13:41  C:\Program Files\Sony\VAIO Update 2\VAIOUpdt .exe
----a-w			28,672 2008-01-02 15:13:24  C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal .exe
----a-w			15,360 2008-01-02 15:13:25  C:\WINDOWS\system32\ctfmon .exe
----a-w			40,960 2008-01-02 15:13:37  C:\WINDOWS\system32\ezSP_Px .exe
----a-w		   155,648 2008-01-02 15:13:45  C:\WINDOWS\system32\NeroCheck .exe
</pre>


((((((((((((((((((((((((((((( snapshot@2008-01-16_22.09.53.66 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-17 05:57:13 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-17 18:11:08 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-17 05:57:13 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-17 18:11:08 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-17 05:57:13 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-17 18:11:08 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-17 05:57:14 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-17 18:11:09 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-17 05:57:14 5,201,920 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-17 18:11:11 5,201,920 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-17 05:57:15 344,064 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-17 18:11:12 344,064 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-18 18:38:28 29,696 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
+ 2008-01-18 18:38:28 18,944 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2008-01-18 18:38:28 65,024 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2005-05-24 20:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 23:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 23:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0026D161-E6EC-408B-9E73-7A181E632B3E}]
C:\Program Files\Windows Media Player\hokenov83122.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{654E6AB9-160E-4287-B8B9-2B9A1A6622FB}]
C:\Program Files\Windows Media Player\hokenov4444.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [ ]
"DVDXGhost"="" []
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\nbj .exe" [2007-12-31 12:55 1961984]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"H/PC Connection Agent"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 12:39 1289000]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Hcontrol"="C:\WINDOWS\ATK0100\Hcontrol.exe" [ ]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"Mouse Suite 98 Daemon"="ICO.EXE" []
"BluetoothAuthenticationAgent"="irprops.cpl" [2004-08-03 23:56 380416 C:\WINDOWS\system32\irprops.cpl]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [ ]
"HKSERV.EXE"="C:\Program Files\Sony\HotKey Utility\HKserv.exe" [ ]
"ezShieldProtector for Px"="C:\WINDOWS\system32\ezSP_Px .exe" [2008-01-02 07:13 40960]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 08:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"SWN2"="C:\Program Files\Spyware Nuker\swnxt.exe" [2006-06-09 08:11 4060160]
"BDSwitchAgent"="C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe" [ ]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-05-02 07:28 155648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-05 08:50 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-05 08:50 219136]

C:\Documents and Settings\Dawn Swartwood\Start Menu\Programs\Startup\
Trend Micro Anti-Spyware.lnk - C:\Program Files\Trend Micro\Tmas\Tmas.exe [2006-05-27 17:24:57]

C:\Documents and Settings\Chris Matthews\Start Menu\Programs\Startup\
Palm Registration.lnk - D:\Palm\register.exe [2005-08-08 11:36:14]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
DataViz Inc Messenger.lnk - C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe [2007-06-09 09:25:51]
HOTSYNCSHORTCUTNAME.lnk - D:\Palm\Hotsync.exe [2004-06-09 13:27:34]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-03-21 17:00:00]
Trend Micro Anti-Spyware.lnk - C:\Program Files\Trend Micro\Tmas\Tmas.exe [2006-05-27 17:24:57]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\MSN Gaming Zone\profsyvyqaq.html
FriendlyName=

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{03A80B1D-5C6A-42c2-9DFB-81B6005D8023}"= C:\Program Files\Trend Micro\Tmas\sshook.dll [ ]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hggfghf]
hggfghf.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

R2 VAIO Entertainment File Import Service;VAIO Entertainment File Import Service;C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe [2004-03-12 16:32]
R3 SPI;Sony Programmable I/O Control Device;C:\WINDOWS\system32\DRIVERS\SonyPI.sys [2001-08-17 04:51]
S2 AvgCore;AVG6 Kernel;C:\PROGRA~1\Grisoft\AVG6\avgcore.sys []
S2 AvgFsh;AVG6 Rezident Driver;C:\PROGRA~1\Grisoft\AVG6\avgfsh.sys []
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 12:50]
S3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;C:\WINDOWS\system32\Drivers\BrSerIf.sys [2004-09-29 03:24]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\WINDOWS\system32\Drivers\BrUsbSer.sys [2004-01-10 04:28]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 16:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 16:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 16:59]
S3 VAIO Entertainment UPnP Client Adapter;VAIO Entertainment UPnP Client Adapter;C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe [2004-03-12 15:57]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-18 12:00:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-18 12:02:56
ComboFix-quarantined-files.txt 2008-01-18 20:02:39
ComboFix2.txt 2008-01-17 18:19:51
ComboFix3.txt 2008-01-17 06:10:21
.
2008-01-11 02:05:19 --- E O F ---

#14 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:18 AM

Posted 18 January 2008 - 04:16 PM

Click Start/Control Panel/Add or Remove Programs and remove Spyware Nuker if present,then restart your pc.

Please download OTMoveIt by OldTimer,save it to your desktop:
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
Please double-click OTMoveIt.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose 'Copy'):

C:\Program Files\Spyware Nuker
C:\Temp
C:\VundoFix Backups
C:\Documents and Settings\Dawn Swartwood\Application Data\EasySpywareCleaner.com
C:\WINDOWS\system32\drivers\pshook11.sys


Return to OTMoveIt, right click on the "Paste Standard List of Files/Folders to be moved" window (under the light blue bar) and choose Paste.
Click the red Moveit! button Posted Image
Copy everything on the 'Results' window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose 'Copy'), and paste it into your next reply.
Close OTMoveIt.
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.
If you are asked to reboot the machine choose Yes.


Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: fix2.reg to your desktop.
Then double click on the fix2.reg file on your desktopPosted Imageand agree to merge the information into the registry,then restart your pc.

REGEDIT4
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0026D161-E6EC-408B-9E73-7A181E632B3E}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{654E6AB9-160E-4287-B8B9-2B9A1A6622FB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SWN2"=-
[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hggfghf]


Download RenV.exe again to your desktop,double click to run it:
http://download.bleepingcomputer.com/sUBs/Beta/RenV.exe
When its finished it will produce a Log.
Please post the contents of that Log into your next reply.

Also post a new Hijackthis log.
Posted Image
Posted Image

#15 ripstussy

ripstussy
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 19 January 2008 - 01:06 AM

Ran on Fri 01/18/2008 - 22:02:17.89

----a-w		 1,961,984 2007-12-31 20:55:20  C:\Program Files\Ahead\Nero BackItUp\nbj  .exe
----a-w		   409,600 2008-01-02 15:13:50  C:\Program Files\AirPort\APDiskAgent .exe
----a-w		   114,688 2008-01-02 15:13:11  C:\Program Files\Apoint\Apoint .exe
----a-w		   335,872 2008-01-02 15:13:12  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
----a-w		 1,694,208 2008-01-02 15:13:58  C:\Program Files\Messenger\msmsgs .exe
----a-w		   118,784 2008-01-02 15:14:00  C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon .exe
----a-w			98,304 2008-01-02 15:13:30  C:\Program Files\Sony\HotKey Utility\HKserv .exe
----a-w			32,768 2008-01-02 15:13:34  C:\Program Files\Sony\ISB Utility\ISBMgr .exe
----a-w		   167,936 2008-01-02 15:13:28  C:\Program Files\Sony\VAIO Power Management\SPMgr .exe
----a-w		   135,168 2008-01-02 15:13:41  C:\Program Files\Sony\VAIO Update 2\VAIOUpdt .exe
----a-w			28,672 2008-01-02 15:13:24  C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal .exe
----a-w			15,360 2008-01-02 15:13:25  C:\WINDOWS\system32\ctfmon .exe
----a-w			40,960 2008-01-02 15:13:37  C:\WINDOWS\system32\ezSP_Px .exe
----a-w		   155,648 2008-01-02 15:13:45  C:\WINDOWS\system32\NeroCheck .exe

 Entries:			   14  (14)
 Directories:			0  Files:			14
 Bytes:		  5,309,952  Blocks:	   10,371

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:05:21 PM, on 1/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ezSP_Px .exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
D:\Palm\Hotsync.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
D:\PROGRA~1\MICROS~1\rapimgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.usatoday.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {0026D161-E6EC-408B-9E73-7A181E632B3E} - C:\Program Files\Windows Media Player\hokenov83122.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {654E6AB9-160E-4287-B8B9-2B9A1A6622FB} - C:\Program Files\Windows Media Player\hokenov4444.dll (file missing)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px .exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [BDSwitchAgent] C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj .exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Palm Registration.lnk = D:\Palm\register.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = D:\Palm\Hotsync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~1\INetRepl.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...83/mcinsctl.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan.com/as/cabs/ascstubie.cab
O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://download.sidestep.com/get/k00719/sb028.cab
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} (Actimage Room Control) - http://hutchence.armstrong.com/ib/database...timage40803.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,20/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...200/mcfscan.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG6 Service (AvgServ) - Unknown owner - (no file)
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\VmGateway.exe
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Video\GPVSvr.exe
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe

--
End of file - 14053 bytes




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users