Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected W/zlobam


  • This topic is locked This topic is locked
6 replies to this topic

#1 fanceigirl

fanceigirl

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:35 PM

Posted 29 April 2008 - 09:35 PM

Downloaded some fake activeX control by accident--
Originally Infected w/ZlobAM, NewMediaCodec, RichVideoCodec1.6, Spyware Isolater and Win32/Pripecs!generic (continuous pop-ups saying my computer was at high risk for spyware and to download their antispyware programs)
Updated installed new CA security software
My CA spyware/antivirus program quarantined all- but New Media Codec and Zlob AM came back after it was quarantined the next time I opened my computer.
Did try an earlier restore point which did not work.
Went on computer geeks site, downloaded smitfruadfix, went through process,which got rid of New Media Codec--
Zlob AM keeps coming back, I am continuing to quaratine it.
Went on your site- prep guide- Downloaded and ran DSS, but my computer kept saying unable to download update for Hijackthis- so it automatically after 30 sec downloaded its own DSS version.
Did not download Kaspersky Online scanner.

I am pasting both logs- main.txt, extra.text.....as well as my antispyware quaratine log from the past week.

Thanks so much for any help on getting rid of this thing!!

MAIN.TXT LOG
Deckard's System Scanner v20071014.68
Run by Terence on 2008-04-29 21:05:55
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
24: 2008-04-30 01:06:10 UTC - RP436 - Deckard's System Scanner Restore Point
23: 2008-04-25 19:43:32 UTC - RP435 - System Checkpoint
22: 2008-04-24 17:37:44 UTC - RP434 - Printer Driver hp officejet 5500 series fax Installed
21: 2008-04-24 17:37:03 UTC - RP433 - Installed 5500Trb
20: 2008-04-24 17:36:42 UTC - RP432 - Installed 5500_Help


-- First Restore Point --
1: 2008-03-27 03:30:03 UTC - RP413 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-04-29 21:09:03
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe
C:\WINDOWS\explorer.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\Network Associates\VirusScan\shstat.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\HP\HP Software Update\hpwuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\Directcd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\3M\PSNLite\PSNGive.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Toolbar\CAGlobal.exe
C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Light\CAGlobalLight.exe
C:\Documents and Settings\Terence\Desktop\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.914.9778\swg.dll
O2 - BHO: DVA Storm - {EA3D41AC-9334-48AD-B582-19F2ADEB5C6A} - C:\WINDOWS\qnmargolqgp.dll (file missing)
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar1.dll
O3 - Toolbar: dpevflbg - {AEC33E75-FFF6-45F3-A755-684638294388} - C:\WINDOWS\dpevflbg.dll (file missing)
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Toolbar\CallingIDIE.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [cafw] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Post-itŪ Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O9 - Extra button: Yahoo Mail Side Bar - {02E629B1-DA2B-4AA4-90ED-7E212089BEA4} - (file missing)
O9 - Extra button: Print Preview - {0B18B4D9-A5E9-4387-ADD9-B26EDFA1CE92} - C:\Program Files\IECustomizer.com\IEButtons\PrintPreview.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://download.microsoft.com/download/e/7.../OGAControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1109560113985
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1196468867986
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._2/axofupld.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O21 - SSODL: vadokmxt - {EA4EE755-A5EA-4033-9026-D94FCC2AEDE3} - C:\WINDOWS\vadokmxt.dll
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe


--
End of file - 10845 bytes

-- HijackThis Fixed Entries (C:\\backups\) -------------------------------------

backup-20070103-085904-239 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
backup-20070103-085904-775 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
backup-20070103-085906-160 O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
backup-20070103-085906-695 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
backup-20070103-085906-886 O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
backup-20070103-085907-357 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
backup-20070103-085913-939 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 OMCI - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>

S3 SMNDIS5 (SMNDIS5 NDIS Protocol Driver) - c:\program files\verizon wireless\vzaccess manager\smndis5.sys <Not Verified; Smith Micro Software, Inc.; QuickLink Wi-Fi>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 McAfeeFramework (McAfee Framework Service) - c:\program files\network associates\common framework\frameworkservice.exe /servicestart <Not Verified; Network Associates, Inc.; McAfee Common Framework>
R2 McTaskManager (Network Associates Task Manager) - "c:\program files\network associates\virusscan\vstskmgr.exe" <Not Verified; Network Associates, Inc.; VirusScan Enterprise>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E965-E325-11CE-BFC1-08002BE10318}
Description: CD-ROM Drive
Device ID: IDE\CDROMHL-DT-ST_CD-RW_GCE-8080N________________2.06____\5&2040CED5&0&0.0.0
Manufacturer: (Standard CD-ROM drives)
Name: HL-DT-ST CD-RW GCE-8080N
PNP Device ID: IDE\CDROMHL-DT-ST_CD-RW_GCE-8080N________________2.06____\5&2040CED5&0&0.0.0
Service: cdrom


-- Scheduled Tasks -------------------------------------------------------------

2008-04-29 20:47:10 442 --a------ C:\WINDOWS\Tasks\RegCure Program Check.job
2008-04-25 16:01:56 460 --a------ C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Terence at 4 00 PM.job
2008-03-23 03:00:02 376 --a------ C:\WINDOWS\Tasks\RegCure.job
2007-10-27 14:50:33 440 --a------ C:\WINDOWS\Tasks\EasyShare Registration Task.job


-- Files created between 2008-03-29 and 2008-04-29 -----------------------------

2008-04-29 21:05:52 0 d-------- C:\WINDOWS\CAVTemp
2008-04-24 11:24:07 3566 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-24 11:23:16 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-04-24 11:23:16 82944 --a------ C:\WINDOWS\system32\404Fix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-04-24 11:23:15 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-24 11:23:15 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-04-24 11:23:15 82944 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-04-24 11:23:14 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-04-24 11:23:14 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-24 11:23:13 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-04-23 12:20:48 0 d-------- C:\Documents and Settings\Terence\Application Data\CallingID
2008-04-23 12:20:34 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-23 12:17:18 0 d-------- C:\Program Files\Common Files\Scanner
2008-04-23 12:16:11 0 d-------- C:\Documents and Settings\All Users\Application Data\CA
2008-04-23 12:15:48 0 d-------- C:\Program Files\CA
2008-04-23 12:06:25 81920 --a------ C:\Program Files\installer_abr.exe
2008-04-23 12:05:19 0 d-------- C:\Documents and Settings\Terence\Application Data\GetRightToGo
2008-04-23 09:51:04 0 d-------- C:\Documents and Settings\Terence\Application Data\TmpRecentIcons
2008-04-22 22:16:50 270336 --a------ C:\WINDOWS\vadokmxt.dll
2008-04-21 12:00:14 0 d-------- C:\Documents and Settings\Terence\Application Data\Smith Micro
2008-04-21 11:55:52 77824 --a------ C:\WINDOWS\system32\ptdmwmcp.dll <Not Verified; DEVGURU; Application Interface DLL>
2008-04-21 11:55:50 0 d-------- C:\Program Files\PANTECH
2008-04-21 11:55:16 0 d-------- C:\Program Files\Verizon Wireless


-- Find3M Report ---------------------------------------------------------------

2008-04-29 20:50:28 29232 --a------ C:\WINDOWS\hpoins03.dat
2008-04-29 20:50:09 108174 --a------ C:\logfile
2008-04-23 12:23:25 0 d-------- C:\Program Files\Common Files\InstallShield
2008-04-23 12:20:34 0 d-------- C:\Program Files\Common Files


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EA3D41AC-9334-48AD-B582-19F2ADEB5C6A}]
C:\WINDOWS\qnmargolqgp.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [03/06/2003 08:00 AM]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [02/25/2003 07:00 AM]
"PCTVOICE"="pctspk.exe" [02/24/2003 04:35 PM C:\WINDOWS\system32\pctspk.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [10/26/2001 03:08 PM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [10/26/2001 03:07 PM]
"DXDllRegExe"="dxdllreg.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/04/2005 12:36 PM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [04/10/2008 12:06 AM]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [03/11/2008 01:46 AM]
"QOELOADER"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe" [04/23/2008 12:19 PM]
"cafw"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [04/04/2008 03:46 PM]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [04/04/2008 03:46 PM]
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [04/04/2008 03:46 PM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [08/04/2003 07:28 PM]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [05/12/2004 04:18 PM]
"AdaptecDirectCD"="C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [02/27/2005 10:21 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [08/08/2007 12:54 PM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [10/18/2006 08:05 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [9/16/2003 7:19:24 AM]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [9/19/2007 4:33:46 AM]
Post-itr Software Notes Lite.lnk - C:\Program Files\3M\PSNLite\PsnLite.exe [10/15/2004 4:26:54 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"= C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\LinkAdvisor\CIDLinkAdvisor.dll [10/15/2007 09:40 PM 1373624]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"vadokmxt"= {EA4EE755-A5EA-4033-9026-D94FCC2AEDE3} - C:\WINDOWS\vadokmxt.dll [04/22/2008 06:06 AM 270336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
UmxWnp.Dll 05/18/2007 01:30 PM 79368 C:\WINDOWS\system32\UmxWNP.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06255cd0-7139-11dc-8b39-00904b127fcf}]
AutoRun\command- D:\system\viewer\FlipVideoforPC.exe
Flip Video for PC\command- D:\system\viewer\FlipVideoforPC.exe




-- End of Deckard's System Scanner: finished at 2008-04-29 21:12:16 ------------




EXTRA.TEXT LOG
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Pentium® III Mobile CPU 1200MHz
Percentage of Memory in Use: 65%
Physical Memory (total/avail): 639.37 MiB / 223.17 MiB
Pagefile Memory (total/avail): 1560.03 MiB / 1141.42 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1933.32 MiB

C: is Fixed (NTFS) - 18.63 GiB total, 4.01 GiB free.

\\.\PHYSICALDRIVE0 - IC25N020ATCS04-0 - 18.63 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 18.63 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.

FW: CA Personal Firewall v10.0.0.157 (CA)
AV: CA Anti-Virus v9.0.0.170 (CA, Inc.)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\system32\\LEXPPS.EXE:*:Enabled:LEXPPS.EXE"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\system32\\LEXPPS.EXE:*:Enabled:LEXPPS.EXE"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Disabled:RealPlayer"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\mshta.exe"="C:\\WINDOWS\\system32\\mshta.exe:*:Enabled:Microsoft ® HTML Application host"
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Terence\Application Data
CLIENTNAME=Console
COLLECTIONID=COL6400
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=TSCAHPPERT
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HMSERVER=https://wwss1proa.cce.hp.com/wuss/servlet/WUSSServlet
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Terence
ITEMID=ps-19683-3
LANG=1033
LOGONSERVER=\\TSCAHPPERT
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
OSVER=winXPP
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Common Files\Adaptec Shared\System;;C:\PROGRA~1\COMMON~1\MUVEET~1\030625
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 11 Stepping 1, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0b01
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONID=1173370049428htx60561a0df30:1114b0dbd61:-6712
SESSIONNAME=Console
SWUTVER=1.0.22.20030804
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Terence\LOCALS~1\Temp
TIMEOUT=0
TMP=C:\DOCUME~1\Terence\LOCALS~1\Temp
TOOLPATH=/C:/Program%20Files/HP/HP%20Software%20Update/install.htm
UPDATEDIR=C:\DOCUME~1\Terence\LOCALS~1\Temp\radC163D.tmp
USERDOMAIN=TSCAHPPERT
USERNAME=Terence
USERPROFILE=C:\Documents and Settings\Terence
VERSION=3.5.0
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

leeschilling.HPS
administrator.HPS (admin)
lynnesbaraglia (new local, admin)
leeschilling (admin)
Terence (admin)
Administrator (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> "C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\setup\ccinstaller.exe" /u /silent /module="fw"
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
3ivx MPEG-4 5.0.1 Decoder (remove only) --> "C:\Program Files\3ivx\3ivx MPEG-4 5.0.1 Decoder\uninstall.exe"
Ad-Aware SE Personal --> C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
BUM --> MsiExec.exe /I{55937F00-A69B-4049-8D3A-1C7729742B6F}
CA Anti-Spyware --> "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\setup\ccinstaller.exe" /u /silent /module="pp"
CA Anti-Virus --> C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\unvet32.exe
CA Desktop DNA Migrator --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{0AFD47CE-CA9C-4372-AA20-CB05D33638FA} /l1033 /s /f1"C:\Program Files\CA\CA Internet Security Suite\CA Desktop DNA Migrator\dnaunset.iss"
CA Internet Security Suite --> "C:\Program Files\CA\CA Internet Security Suite\caunst.exe" /u
CA Pest Patrol Realtime Protection --> MsiExec.exe /X{F05A5232-CE5E-4274-AB27-44EB8105898D}
CA Website Inspector --> MsiExec.exe /X{CDB98E2F-7B2A-42C2-B718-F1F6B31586DF}
CCScore --> MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}
Dell ResourceCD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D78653C3-A8FF-415F-92E6-D774E634FF2D}\setup.exe"
Easy CD Creator 5 Basic --> MsiExec.exe /I{609F7AC8-C510-11D4-A788-009027ABA5D0}
ESSBrwr --> MsiExec.exe /I{643EAE81-920C-4931-9F0B-4B343B225CA6}
ESSCDBK --> MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}
ESScore --> MsiExec.exe /I{42938595-0D83-404D-9F73-F8177FDD531A}
ESSgui --> MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A}
ESSini --> MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765}
ESSPCD --> MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}
ESSSONIC --> MsiExec.exe /I{073F22CE-9A5B-4A40-A604-C7270AC6BF34}
ESSTOOLS --> MsiExec.exe /I{8A502E38-29C9-49FA-BCFA-D727CA062589}
essvatgt --> MsiExec.exe /I{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}
Google Toolbar for Internet Explorer --> MsiExec.exe /X{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
HighMAT Extension to Microsoft Windows XP CD Writing Wizard --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
HijackThis 1.99.1 --> c:\HijackThis.exe /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
HP Image Zone 3.5 --> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP PSC & OfficeJet 3.5 --> "C:\Program Files\HP\Digital Imaging\{0FABD3D7-3036-4e78-B29D-58957ADB0A12}\setup\hpzscr01.exe" -datfile hposcr03.dat
HP Software Update --> MsiExec.exe /X{34957B51-9676-41CE-9E52-44AE91B73F1C}
HP Unload DLL Patch --> MsiExec.exe /X{595D0DE8-C38A-4432-B851-47DECC1A99BD}
kgcbase --> MsiExec.exe /I{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}
KODAK EASYSHARE Gallery Easy Upload, v2.1 --> C:\Documents and Settings\Terence\Local Settings\Application Data\KodakGallery\EasyShareSetup\$SETUP_140007_13aee2\Setup.exe /APR-REMOVE
Kodak EasyShare software --> C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_1e0002_b80fa\Setup.exe /APR-REMOVE
Learn2 Player (Uninstall Only) --> C:\Program Files\Learn2.com\StRunner\stuninst.exe
McAfee VirusScan Enterprise --> MsiExec.exe /I{1912F734-6580-4620-8AFD-ECCCEA19CDE2}
Memories Disc Creator 2.0 --> MsiExec.exe /X{2E132061-C78A-48D4-A899-1D13B9D189FA}
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office XP Professional --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0050048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Windows Journal Viewer --> MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA7}
Mozilla Firefox (2.0.0.1) --> C:\Program Files\Mozilla Firefox\uninstall\uninst.exe
muvee Plugin 1.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{82CA0A0C-A3EC-4167-B694-909205B2EDEC}\setup.exe" -l0x9
netbrdg --> MsiExec.exe /I{4537EA4B-F603-4181-89FB-2953FC695AB1}
OfotoXMI --> MsiExec.exe /I{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}
overland --> MsiExec.exe /I{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}
PANTECH PC USB Modem Software --> C:\Program Files\PANTECH\PANTECH USB Modem\PTDMUninstall.exe
PCTEL 2304WT V.9x MDC Modem Drivers --> ptuninst.exe
Post-itŪ Software Notes Lite --> "C:\Program Files\3M\PSNLite\Uninstall.exe" -Prog"C:\Program Files\3M\PSNLite\PsnLite.exe" -INI"C:\Program Files\3M\PSNLite\uninst.ini"
QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
RealPlayer Basic --> C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
RegCure 1.5.0.0 --> C:\Program Files\RegCure\uninst.exe
SFR --> MsiExec.exe /I{DB02F716-6275-42E9-B8D2-83BA2BF5100B}
SHASTA --> MsiExec.exe /I{605A4E39-613C-4A12-B56F-DEFBE6757237}
skin0001 --> MsiExec.exe /I{5316DFC9-CE99-4458-9AB3-E8726EDE0210}
SKINXSDK --> MsiExec.exe /I{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}
Spybot - Search & Destroy 1.4 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
staticcr --> MsiExec.exe /I{8943CE61-53BD-475E-90E1-A580869E98A2}
Synaptics TouchPad --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
tooltips --> MsiExec.exe /I{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
VPRINTOL --> MsiExec.exe /I{999D43F4-9709-4887-9B1A-83EBB15A8370}
VZAccess Manager --> C:\PROGRA~1\VERIZO~1\VZACCE~1\UNWISE.EXE C:\PROGRA~1\VERIZO~1\VZACCE~1\INSTALL.LOG
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
WIRELESS --> MsiExec.exe /I{F9593CFB-D836-49BC-BFF1-0E669A411D9F}
Yahoo Mail Side Bar for Internet Explorer --> "C:\Program Files\Yahoo!\Installs\IECustomizer.com\unins000.exe"
Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG


-- Application Event Log -------------------------------------------------------

Event Record #/Type3676 / Error
Event Submitted/Written: 04/29/2008 09:09:56 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Event Record #/Type3675 / Error
Event Submitted/Written: 04/29/2008 09:09:56 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Event Record #/Type3674 / Error
Event Submitted/Written: 04/29/2008 09:09:56 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Event Record #/Type3673 / Error
Event Submitted/Written: 04/29/2008 09:09:55 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Event Record #/Type3672 / Error
Event Submitted/Written: 04/29/2008 09:09:53 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type24618 / Error
Event Submitted/Written: 04/29/2008 08:47:21 PM
Event ID/Source: 23 / Print
Event Description:
Printer Lexmark Z45,0 failed to initialize because a suitable Lexmark Z45 driver could not be found.

Event Record #/Type24608 / Error
Event Submitted/Written: 04/29/2008 08:47:16 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The Ati HotKey Poller service failed to start due to the following error:
%%1053

Event Record #/Type24607 / Error
Event Submitted/Written: 04/29/2008 08:47:15 PM
Event ID/Source: 7009 / Service Control Manager
Event Description:
Timeout (30000 milliseconds) waiting for the Ati HotKey Poller service to connect.

Event Record #/Type24602 / Warning
Event Submitted/Written: 04/29/2008 08:44:09 PM
Event ID/Source: 1073 / USER32
Event Description:
The attempt to power off TSCAHPPERT failed

Event Record #/Type24601 / Warning
Event Submitted/Written: 04/29/2008 08:44:01 PM
Event ID/Source: 1073 / USER32
Event Description:
The attempt to reboot TSCAHPPERT failed



-- End of Deckard's System Scanner: finished at 2008-04-29 21:12:16 ------------


QUARANTIONE LOG

CA Anti-Spyware Log Report
This report was generated on: 4/29/2008-10:22:08 PM

4/23/2008-12:58:36 PM , Quarantined , NewMediaCodec , Trojan , Key "hkey_classes_root \msvps.msvpsapp" , -1
4/23/2008-12:58:36 PM , Quarantined , NewMediaCodec , Trojan , File "C:\Documents and Settings\Terence\Desktop\privacy protector.url" , -1
4/23/2008-12:58:36 PM , Quarantined , NewMediaCodec , Trojan , File "C:\Documents and Settings\Terence\Favorites\spyware&malware protection.url" , -1
4/23/2008-12:58:37 PM , Quarantined , NewMediaCodec , Trojan , File "C:\Documents and Settings\Terence\Favorites\privacy protector.url" , -1
4/23/2008-12:58:37 PM , Quarantined , NewMediaCodec , Trojan , File "C:\Documents and Settings\Terence\Desktop\error cleaner.url" , -1
4/23/2008-12:58:37 PM , Quarantined , NewMediaCodec , Trojan , File "C:\Documents and Settings\Terence\Favorites\error cleaner.url" , -1
4/23/2008-12:58:37 PM , Quarantined , NewMediaCodec , Trojan , File "C:\Documents and Settings\Terence\Desktop\spyware&malware protection.url" , -1
4/23/2008-12:58:37 PM , Quarantined , Zlob AM , Downloader , Key "hkey_local_machine \software\microsoft\videoplugin" , -1
4/23/2008-12:58:37 PM , Quarantined , Rich Video Codec 1.6 , Trojan , Key "hkey_local_machine \software\microsoft\windows\currentversion\uninstall\webvideo" , -1
4/23/2008-12:58:37 PM , Quarantined , SpywareIsolator , Rogue Security Software , Key "hkey_users \S-1-5-21-790525478-1563985344-854245398-1007\software\spinstall" value "wmid" , -1
4/23/2008-12:58:37 PM , Deleted , 247RealMedia.com , Tracking Cookie , Cookie "terence@247realmedia[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@247realmedia[1].txt" , -1
4/23/2008-12:58:37 PM , Deleted , 2o7.net , Tracking Cookie , Cookie "terence@2o7[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@2o7[1].txt" , -1
4/23/2008-12:58:37 PM , Deleted , 2o7.net , Tracking Cookie , Cookie "terence@hearstmagazines.112.2o7[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@hearstmagazines.112.2o7[1].txt" , -1
4/23/2008-12:58:38 PM , Deleted , 2o7.net , Tracking Cookie , Cookie "terence@marketlive.122.2o7[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@marketlive.122.2o7[1].txt" , -1
4/23/2008-12:58:38 PM , Deleted , 2o7.net , Tracking Cookie , Cookie "terence@msnportal.112.2o7[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@msnportal.112.2o7[1].txt" , -1
4/23/2008-12:58:38 PM , Deleted , 2o7.net , Tracking Cookie , Cookie "terence@usatoday1.112.2o7[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@usatoday1.112.2o7[1].txt" , -1
4/23/2008-12:58:38 PM , Deleted , 2o7.net , Tracking Cookie , Cookie "terence@wpni.112.2o7[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@wpni.112.2o7[1].txt" , -1
4/23/2008-12:58:38 PM , Deleted , About.com , Tracking Cookie , Cookie "terence@about[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@about[2].txt" , -1
4/23/2008-12:58:38 PM , Deleted , adbrite.com , Tracking Cookie , Cookie "terence@adbrite[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@adbrite[2].txt" , -1
4/23/2008-12:58:38 PM , Deleted , adecn.com , Tracking Cookie , Cookie "terence@adecn[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@adecn[1].txt" , -1
4/23/2008-12:58:38 PM , Deleted , adhostingsolutions.com , Tracking Cookie , Cookie "terence@adhostingsolutions[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@adhostingsolutions[1].txt" , -1
4/23/2008-12:58:38 PM , Deleted , adinterax.com , Tracking Cookie , Cookie "terence@adinterax[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@adinterax[2].txt" , -1
4/23/2008-12:58:38 PM , Deleted , adlegend.com , Tracking Cookie , Cookie "terence@adlegend[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@adlegend[1].txt" , -1
4/23/2008-12:58:38 PM , Deleted , euroclick.com , Tracking Cookie , Cookie "terence@adopt.euroclick[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@adopt.euroclick[2].txt" , -1
4/23/2008-12:58:38 PM , Deleted , specificclick.net , Tracking Cookie , Cookie "terence@adopt.specificclick[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@adopt.specificclick[2].txt" , -1
4/23/2008-12:58:38 PM , Deleted , mediamayhemcorp.com , Tracking Cookie , Cookie "terence@ads.mediamayhemcorp[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@ads.mediamayhemcorp[1].txt" , -1
4/23/2008-12:58:38 PM , Deleted , PointRoll.com , Tracking Cookie , Cookie "terence@ads.pointroll[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@ads.pointroll[1].txt" , -1
4/23/2008-12:58:38 PM , Deleted , realtechnetwork.net , Tracking Cookie , Cookie "terence@ads.realtechnetwork[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@ads.realtechnetwork[1].txt" , -1
4/23/2008-12:58:38 PM , Deleted , revsci.net , Tracking Cookie , Cookie "terence@ads.revsci[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@ads.revsci[1].txt" , -1
4/23/2008-12:58:38 PM , Deleted , revsci.net , Tracking Cookie , Cookie "terence@revsci[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@revsci[2].txt" , -1
4/23/2008-12:58:38 PM , Deleted , e-planning.net , Tracking Cookie , Cookie "terence@ads.us.e-planning[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@ads.us.e-planning[1].txt" , -1
4/23/2008-12:58:38 PM , Deleted , Adtech.de , Tracking Cookie , Cookie "terence@adtech[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@adtech[1].txt" , -1
4/23/2008-12:58:39 PM , Deleted , afy11.net , Tracking Cookie , Cookie "terence@afy11[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@afy11[1].txt" , -1
4/23/2008-12:58:39 PM , Deleted , 600z.com , Tracking Cookie , Cookie "terence@aj.600z[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@aj.600z[1].txt" , -1
4/23/2008-12:58:39 PM , Deleted , tacoda.net , Tracking Cookie , Cookie "terence@anad.tacoda[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@anad.tacoda[1].txt" , -1
4/23/2008-12:58:39 PM , Deleted , tacoda.net , Tracking Cookie , Cookie "terence@anat.tacoda[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@anat.tacoda[1].txt" , -1
4/23/2008-12:58:39 PM , Deleted , worldnow.com , Tracking Cookie , Cookie "terence@analytics.worldnow[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@analytics.worldnow[1].txt" , -1
4/23/2008-12:58:39 PM , Deleted , WWW.Angelfire , Tracking Cookie , Cookie "terence@angelfire[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@angelfire[1].txt" , -1
4/23/2008-12:58:39 PM , Deleted , att.com , Tracking Cookie , Cookie "terence@att[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@att[1].txt" , -1
4/23/2008-12:58:39 PM , Deleted , atwola.com , Tracking Cookie , Cookie "terence@atwola[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@atwola[2].txt" , -1
4/23/2008-12:58:39 PM , Deleted , BeloInteractive.com , Tracking Cookie , Cookie "terence@belointeractive[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@belointeractive[1].txt" , -1
4/23/2008-12:58:39 PM , Deleted , bidvertiser.com , Tracking Cookie , Cookie "terence@bidvertiser[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@bidvertiser[2].txt" , -1
4/23/2008-12:58:39 PM , Deleted , Bizrate , Tracking Cookie , Cookie "terence@bizrate[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@bizrate[1].txt" , -1
4/23/2008-12:58:39 PM , Deleted , BS.Serving-Sys , Tracking Cookie , Cookie "terence@bs.serving-sys[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@bs.serving-sys[2].txt" , -1
4/23/2008-12:58:39 PM , Deleted , BurstNet.com , Tracking Cookie , Cookie "terence@burstnet[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@burstnet[2].txt" , -1
4/23/2008-12:58:39 PM , Deleted , BurstNet.com , Tracking Cookie , Cookie "terence@www.burstnet[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@www.burstnet[2].txt" , -1
4/23/2008-12:58:39 PM , Deleted , Citi.BridgeTrack , Tracking Cookie , Cookie "terence@citi.bridgetrack[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@citi.bridgetrack[1].txt" , -1
4/23/2008-12:58:40 PM , Deleted , monster.com , Tracking Cookie , Cookie "terence@cookie.monster[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@cookie.monster[2].txt" , -1
4/23/2008-12:58:40 PM , Deleted , Ercva.com , Tracking Cookie , Cookie "terence@ercva[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@ercva[1].txt" , -1
4/23/2008-12:58:40 PM , Deleted , expedia.com , Tracking Cookie , Cookie "terence@expedia[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@expedia[1].txt" , -1
4/23/2008-12:58:40 PM , Deleted , eyereturn.com , Tracking Cookie , Cookie "terence@eyereturn[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@eyereturn[1].txt" , -1
4/23/2008-12:58:40 PM , Deleted , gcion.com , Tracking Cookie , Cookie "terence@gcion[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@gcion[2].txt" , -1
4/23/2008-12:58:40 PM , Deleted , HyperTracker.com , Tracking Cookie , Cookie "terence@hypertracker[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@hypertracker[1].txt" , -1
4/23/2008-12:58:40 PM , Deleted , icio.us , Tracking Cookie , Cookie "terence@icio[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@icio[1].txt" , -1
4/23/2008-12:58:40 PM , Deleted , indexstats.com , Tracking Cookie , Cookie "terence@indexstats[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@indexstats[1].txt" , -1
4/23/2008-12:58:40 PM , Deleted , IndexTools.com , Tracking Cookie , Cookie "terence@indextools[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@indextools[1].txt" , -1
4/23/2008-12:58:40 PM , Deleted , infospace.com , Tracking Cookie , Cookie "terence@infospace[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@infospace[2].txt" , -1
4/23/2008-12:58:40 PM , Deleted , insightexpressai.com , Tracking Cookie , Cookie "terence@insightexpressai[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@insightexpressai[2].txt" , -1
4/23/2008-12:58:40 PM , Deleted , interclick.com , Tracking Cookie , Cookie "terence@interclick[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@interclick[2].txt" , -1
4/23/2008-12:58:40 PM , Deleted , kanoodle.com , Tracking Cookie , Cookie "terence@kanoodle[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@kanoodle[2].txt" , -1
4/23/2008-12:58:41 PM , Deleted , keywordmax.com , Tracking Cookie , Cookie "terence@keywordmax[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@keywordmax[1].txt" , -1
4/23/2008-12:58:41 PM , Deleted , liveperson.net , Tracking Cookie , Cookie "terence@liveperson[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@liveperson[1].txt" , -1
4/23/2008-12:58:41 PM , Deleted , liveperson.net , Tracking Cookie , Cookie "terence@sales.liveperson[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@sales.liveperson[1].txt" , -1
4/23/2008-12:58:41 PM , Deleted , liveperson.net , Tracking Cookie , Cookie "terence@sales.liveperson[3].txt" File "C:\Documents and Settings\Terence\cookies\terence@sales.liveperson[3].txt" , -1
4/23/2008-12:58:41 PM , Deleted , liveperson.net , Tracking Cookie , Cookie "terence@sales.liveperson[4].txt" File "C:\Documents and Settings\Terence\cookies\terence@sales.liveperson[4].txt" , -1
4/23/2008-12:58:41 PM , Deleted , liveperson.net , Tracking Cookie , Cookie "terence@sales.liveperson[5].txt" File "C:\Documents and Settings\Terence\cookies\terence@sales.liveperson[5].txt" , -1
4/23/2008-12:58:41 PM , Deleted , liveperson.net , Tracking Cookie , Cookie "terence@sales.liveperson[6].txt" File "C:\Documents and Settings\Terence\cookies\terence@sales.liveperson[6].txt" , -1
4/23/2008-12:58:41 PM , Deleted , hitsprocessor.com , Tracking Cookie , Cookie "terence@loc1.hitsprocessor[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@loc1.hitsprocessor[1].txt" , -1
4/23/2008-12:58:41 PM , Deleted , lycos.com , Tracking Cookie , Cookie "terence@lycos[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@lycos[1].txt" , -1
4/23/2008-12:58:41 PM , Deleted , webtrends.com , Tracking Cookie , Cookie "terence@m.webtrends[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@m.webtrends[1].txt" , -1
4/23/2008-12:58:41 PM , Deleted , marketwatch.com , Tracking Cookie , Cookie "terence@marketwatch[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@marketwatch[1].txt" , -1
4/23/2008-12:58:41 PM , Deleted , mcssl.com , Tracking Cookie , Cookie "terence@mcssl[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@mcssl[1].txt" , -1
4/23/2008-12:58:41 PM , Deleted , mcssl.com , Tracking Cookie , Cookie "terence@www.mcssl[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@www.mcssl[2].txt" , -1
4/23/2008-12:58:41 PM , Deleted , mybloglog.com , Tracking Cookie , Cookie "terence@mybloglog[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@mybloglog[2].txt" , -1
4/23/2008-12:58:41 PM , Deleted , nbcuni.com , Tracking Cookie , Cookie "terence@nbcuni[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@nbcuni[1].txt" , -1
4/23/2008-12:58:41 PM , Deleted , newsvine.com , Tracking Cookie , Cookie "terence@newsvine[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@newsvine[2].txt" , -1
4/23/2008-12:58:41 PM , Deleted , nextag.com , Tracking Cookie , Cookie "terence@nextag[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@nextag[2].txt" , -1
4/23/2008-12:58:41 PM , Deleted , ninemsn.com.au , Tracking Cookie , Cookie "terence@ninemsn.com[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@ninemsn.com[1].txt" , -1
4/23/2008-12:58:41 PM , Deleted , webmd.com , Tracking Cookie , Cookie "terence@o.webmd[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@o.webmd[1].txt" , -1
4/23/2008-12:58:41 PM , Deleted , One-Time-Offer , Tracking Cookie , Cookie "terence@one-time-offer[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@one-time-offer[1].txt" , -1
4/23/2008-12:58:42 PM , Deleted , partner2profit.com , Tracking Cookie , Cookie "terence@partner2profit[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@partner2profit[2].txt" , -1
4/23/2008-12:58:42 PM , Deleted , CyberTrader Pro-Market , Tracking Cookie , Cookie "terence@pro-market[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@pro-market[2].txt" , -1
4/23/2008-12:58:42 PM , Deleted , quantserve.com , Tracking Cookie , Cookie "terence@quantserve[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@quantserve[2].txt" , -1
4/23/2008-12:58:42 PM , Deleted , QuestionMarket.com , Tracking Cookie , Cookie "terence@questionmarket[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@questionmarket[2].txt" , -1
4/23/2008-12:58:42 PM , Deleted , RealMedia.com , Tracking Cookie , Cookie "terence@realmedia[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@realmedia[2].txt" , -1
4/23/2008-12:58:42 PM , Deleted , Revenue.net , Tracking Cookie , Cookie "terence@revenue[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@revenue[2].txt" , -1
4/23/2008-12:58:42 PM , Deleted , roiservice.com , Tracking Cookie , Cookie "terence@roiservice[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@roiservice[1].txt" , -1
4/23/2008-12:58:42 PM , Deleted , adjuggler.com , Tracking Cookie , Cookie "terence@rotator.adjuggler[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@rotator.adjuggler[1].txt" , -1
4/23/2008-12:58:42 PM , Deleted , information.com , Tracking Cookie , Cookie "terence@searchportal.information[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@searchportal.information[1].txt" , -1
4/23/2008-12:58:42 PM , Deleted , Serving-Sys , Tracking Cookie , Cookie "terence@serving-sys[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@serving-sys[1].txt" , -1
4/23/2008-12:58:42 PM , Deleted , Ads.SpecificClick.com , Tracking Cookie , Cookie "terence@specificclick[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@specificclick[2].txt" , -1
4/23/2008-12:58:42 PM , Deleted , netflame.cc , Tracking Cookie , Cookie "terence@ssl-hints.netflame[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@ssl-hints.netflame[2].txt" , -1
4/23/2008-12:58:42 PM , Deleted , DealTime , Tracking Cookie , Cookie "terence@stat.dealtime[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@stat.dealtime[1].txt" , -1
4/23/2008-12:58:42 PM , Deleted , suitesmart.com , Tracking Cookie , Cookie "terence@suitesmart[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@suitesmart[1].txt" , -1
4/23/2008-12:58:42 PM , Deleted , Tacoda cookie , Tracking Cookie , Cookie "terence@tacoda[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@tacoda[1].txt" , -1
4/23/2008-12:58:42 PM , Deleted , thegeoguide.com , Tracking Cookie , Cookie "terence@thegeoguide[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@thegeoguide[1].txt" , -1
4/23/2008-12:58:42 PM , Deleted , TrafficMarketplace , Tracking Cookie , Cookie "terence@trafficmp[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@trafficmp[2].txt" , -1
4/23/2008-12:58:42 PM , Deleted , Travelocity.com , Tracking Cookie , Cookie "terence@travelocity[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@travelocity[1].txt" , -1
4/23/2008-12:58:42 PM , Deleted , trb.com , Tracking Cookie , Cookie "terence@trb[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@trb[1].txt" , -1
4/23/2008-12:58:42 PM , Deleted , adbureau.net , Tracking Cookie , Cookie "terence@tremor.adbureau[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@tremor.adbureau[2].txt" , -1
4/23/2008-12:58:43 PM , Deleted , TribalFusion.com , Tracking Cookie , Cookie "terence@tribalfusion[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@tribalfusion[2].txt" , -1
4/23/2008-12:58:43 PM , Deleted , turn.com , Tracking Cookie , Cookie "terence@turn[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@turn[1].txt" , -1
4/23/2008-12:58:43 PM , Deleted , unicast.com , Tracking Cookie , Cookie "terence@unicast[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@unicast[1].txt" , -1
4/23/2008-12:58:43 PM , Deleted , untd.com , Tracking Cookie , Cookie "terence@untd[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@untd[1].txt" , -1
4/23/2008-12:58:43 PM , Deleted , washingtonpost.com , Tracking Cookie , Cookie "terence@washingtonpost[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@washingtonpost[1].txt" , -1
4/23/2008-12:58:43 PM , Deleted , RealTracker.com , Tracking Cookie , Cookie "terence@web4.realtracker[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@web4.realtracker[1].txt" , -1
4/23/2008-12:58:43 PM , Deleted , whitepages.com , Tracking Cookie , Cookie "terence@whitepages[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@whitepages[2].txt" , -1
4/23/2008-12:58:43 PM , Deleted , burstbeacon.com , Tracking Cookie , Cookie "terence@www.burstbeacon[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@www.burstbeacon[1].txt" , -1
4/23/2008-12:58:43 PM , Deleted , clickmanage.com , Tracking Cookie , Cookie "terence@www.clickmanage[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@www.clickmanage[2].txt" , -1
4/23/2008-12:58:43 PM , Deleted , conversionruler.com , Tracking Cookie , Cookie "terence@www.conversionruler[2].txt" File "C:\Documents and Settings\Terence\cookies\terence@www.conversionruler[2].txt" , -1
4/23/2008-12:58:43 PM , Deleted , eBates.com , Tracking Cookie , Cookie "terence@www.ebates[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@www.ebates[1].txt" , -1
4/23/2008-12:58:43 PM , Deleted , revresda.com , Tracking Cookie , Cookie "terence@www.revresda[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@www.revresda[1].txt" , -1
4/23/2008-12:58:43 PM , Deleted , shopping.com , Tracking Cookie , Cookie "terence@www999.shopping[1].txt" File "C:\Documents and Settings\Terence\cookies\terence@www999.shopping[1].txt" , -1
4/24/2008-10:49:01 AM , Quarantined , Zlob AM , Downloader , Key "hkey_local_machine \software\microsoft\videoplugin" , -1
4/24/2008-10:49:02 AM , Quarantined , NewMediaCodec , Trojan , File "C:\Documents and Settings\Terence\Favorites\error cleaner.url" , -1
4/24/2008-10:49:03 AM , Quarantined , NewMediaCodec , Trojan , File "C:\Documents and Settings\Terence\Favorites\spyware&malware protection.url" , -1
4/24/2008-10:49:04 AM , Quarantined , NewMediaCodec , Trojan , File "C:\Documents and Settings\Terence\Favorites\privacy protector.url" , -1
4/24/2008-3:56:33 PM , Quarantined , Zlob AM , Downloader , Key "hkey_local_machine \software\microsoft\videoplugin" , -1
4/25/2008-4:01:43 PM , Quarantined , Zlob AM , Downloader , Key "hkey_local_machine \software\microsoft\videoplugin" , -1
4/29/2008-8:52:57 PM , Quarantined , Zlob AM , Downloader , Key "hkey_local_machine \software\microsoft\videoplugin" , -1
***End Report***

BC AdBot (Login to Remove)

 


#2 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:09:35 PM

Posted 07 May 2008 - 09:38 PM

Hello fanceigirl,

I (as well as MicroSoft, McAfee and Symantec) recommend that you DO NOT have more than one anti virus product installed and running on your computer at a time.

The reason for this is that if both products have their automatic (Real-Time) protection switched on, then those products which do not encrypt the virus strings within them can cause other anti virus products to cause "false alarms".

It can also lead to a clash as both products fight for access to files which are opened again this is the resident/automatic protection.

In general terms, the two programs may conflict and cause:

1) False Alarms: When the anti virus software tells you that your PC has a virus when it actually doesn't.
2) System Performance Problems: Your system may lock up due to both products attempting to access the same file at the same time.

Therefore please go to add/remove in the control panel and remove one of these.
McAfee Anti-virus or CA Anti-Virus



Download SDFix and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
  • Finally copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log

-- If this error message is displayed when running SDFix: "The command prompt has been disabled by your administrator. Press any key to continue..."
Please go to Start Menu > Run > and copy/paste the following line:
%systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg
Press Ok and then run SDFix again.

-- If the Command Prompt window flashes on then off again on XP or Win 2000, please go to Start Menu > Run > and copy/paste the following line:
%systemdrive%\SDFix\apps\FixPath.exe /Q
Reboot and then run SDFix again.

-- If SDFix still does not run, check the %comspec% variable. Right-click My Computer > click Properties > Advanced > Environment Variables and check that the ComSpec variable points to cmd.exe.
%SystemRoot%\system32\cmd.exe

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 fanceigirl

fanceigirl
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:35 PM

Posted 09 May 2008 - 04:36 PM

Thank you so much for getting back to me!!!!-- I'm going to go through your message and I'll post back my results. And thanks for the info on the anti-virus programs....I definitely knew not to run 2 anti-virus at the same time- I disabled the Macafee when I installed the CA security suite, but didn't know I had to remove the whole program....I'm so psyched to get finally get rid of this Zlob thing!!

#4 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:09:35 PM

Posted 09 May 2008 - 04:43 PM

Hi fanceigirl,

I definitely knew not to run 2 anti-virus at the same time- I disabled the Macafee when I installed the CA security suite, but didn't know I had to remove the whole program



Disabling one of the antivirus program is OK. You do not want two antivirus scanners running at the same time on your computer. It will give you false positives, slow your computer and my cause a crash.

It is far easier to use an online virus scanner when you want to double check your primary virus scanner.

Edited by SifuMike, 09 May 2008 - 04:44 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 fanceigirl

fanceigirl
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:35 PM

Posted 09 May 2008 - 11:18 PM

Hi--
Thanks for your quick reply to the antivirus programs. I decided to get rid of the Mcafee anyway because I won't be using it. Can you suggest an reputable online virus scan for future reference?

But more importantly, I've followed the instructions with SDfix and I think its gotten rid of the Zlob downloader. When my computer restarted it scanned for spyware and it came out clean.

I'm crossing my fingers!
----------------------------------------------------------------------------------------------------------------------------------------------

Here is the report.txt file

SDFix: Version 1.181
Run by Terence on Fri 05/09/2008 at 10:31 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default HomePage Value
Restoring Default Desktop Components Value

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\vadokmxt.dll - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1359.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-09 23:01:39
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\7971f918-a847-4430-9279-4a52d1efe18d]
"FlushCacheFiles"=str(7):"C:\WINDOWS\SoftwareDistribution\EventCache\{009E11A3-739E-4716-B6A0-B995A0A7EE07}.bin\0"

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\system32\\LEXPPS.EXE:*:Enabled:LEXPPS.EXE"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Disabled:RealPlayer"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\mshta.exe"="C:\\WINDOWS\\system32\\mshta.exe:*:Enabled:Microsoft ® HTML Application host"
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\system32\\LEXPPS.EXE:*:Enabled:LEXPPS.EXE"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sat 18 Aug 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Thu 22 Mar 2007 34,304 ...H. --- "C:\Documents and Settings\Terence\My Documents\stef job\~WRL0005.tmp"
Thu 22 Mar 2007 39,424 ...H. --- "C:\Documents and Settings\Terence\My Documents\stef job\~WRL3716.tmp"
Fri 9 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\BIT2.tmp"

Finished!

-----------------------------------------------------------------------------------------------------------------------------------------

Here is the Hijack This Log


Deckard's System Scanner v20071014.68
Run by Terence on 2008-05-09 23:59:48
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Terence.exe) ---------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:12:25 AM, on 5/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Documents and Settings\Terence\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Terence.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.914.9778\swg.dll
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Toolbar\CallingIDIE.dll
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [cafw] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [CaPPcl] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe /scan /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Post-itŪ Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O9 - Extra button: Yahoo Mail Side Bar - {02E629B1-DA2B-4AA4-90ED-7E212089BEA4} - shdocvw.dll (file missing)
O9 - Extra button: Print Preview - {0B18B4D9-A5E9-4387-ADD9-B26EDFA1CE92} - C:\Program Files\IECustomizer.com\IEButtons\PrintPreview.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1109560113985
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1196468867986
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._2/axofupld.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

--
End of file - 8155 bytes

-- Files created between 2008-04-10 and 2008-05-10 -----------------------------

2008-05-10 00:11:55 0 d-------- C:\Program Files\Trend Micro
2008-05-09 22:26:30 0 d-------- C:\WINDOWS\ERUNT
2008-04-29 21:05:52 0 d-------- C:\WINDOWS\CAVTemp
2008-04-24 11:24:07 3566 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-24 11:23:16 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-04-24 11:23:16 82944 --a------ C:\WINDOWS\system32\404Fix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-04-24 11:23:15 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-24 11:23:15 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-04-24 11:23:15 82944 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-04-24 11:23:14 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-04-24 11:23:14 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-24 11:23:13 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-04-23 12:20:48 0 d-------- C:\Documents and Settings\Terence\Application Data\CallingID
2008-04-23 12:20:34 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-23 12:17:18 0 d-------- C:\Program Files\Common Files\Scanner
2008-04-23 12:16:11 0 d-------- C:\Documents and Settings\All Users\Application Data\CA
2008-04-23 12:15:48 0 d-------- C:\Program Files\CA
2008-04-23 12:06:25 81920 --a------ C:\Program Files\installer_abr.exe
2008-04-23 12:05:19 0 d-------- C:\Documents and Settings\Terence\Application Data\GetRightToGo
2008-04-23 09:51:04 0 d-------- C:\Documents and Settings\Terence\Application Data\TmpRecentIcons
2008-04-21 12:00:14 0 d-------- C:\Documents and Settings\Terence\Application Data\Smith Micro
2008-04-21 11:55:52 77824 --a------ C:\WINDOWS\system32\ptdmwmcp.dll <Not Verified; DEVGURU; Application Interface DLL>
2008-04-21 11:55:50 0 d-------- C:\Program Files\PANTECH
2008-04-21 11:55:16 0 d-------- C:\Program Files\Verizon Wireless


-- Find3M Report ---------------------------------------------------------------

2008-05-09 23:12:02 29232 --a------ C:\WINDOWS\hpoins03.dat
2008-05-09 23:11:43 109668 --a------ C:\logfile
2008-05-09 21:46:51 0 d-------- C:\Program Files\Network Associates
2008-05-09 21:46:49 0 d-------- C:\Program Files\Common Files
2008-04-23 12:23:25 0 d-------- C:\Program Files\Common Files\InstallShield


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCTVOICE"="pctspk.exe" [02/24/2003 04:35 PM C:\WINDOWS\system32\pctspk.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [10/26/2001 03:08 PM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [10/26/2001 03:07 PM]
"DXDllRegExe"="dxdllreg.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/04/2005 12:36 PM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [04/10/2008 12:06 AM]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [03/11/2008 01:46 AM]
"QOELOADER"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe" [04/23/2008 12:19 PM]
"cafw"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [04/04/2008 03:46 PM]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [04/04/2008 03:46 PM]
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [04/04/2008 03:46 PM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [08/04/2003 07:28 PM]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [05/12/2004 04:18 PM]
"AdaptecDirectCD"="C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [02/27/2005 10:21 PM]
"CaPPcl"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe" [04/10/2008 10:39 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [08/08/2007 12:54 PM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [10/18/2006 08:05 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [9/16/2003 7:19:24 AM]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [9/19/2007 4:33:46 AM]
Post-itr Software Notes Lite.lnk - C:\Program Files\3M\PSNLite\PsnLite.exe [10/15/2004 4:26:54 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"= C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\LinkAdvisor\CIDLinkAdvisor.dll [10/15/2007 09:40 PM 1373624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
UmxWnp.Dll 05/18/2007 01:30 PM 79368 C:\WINDOWS\system32\UmxWNP.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06255cd0-7139-11dc-8b39-00904b127fcf}]
AutoRun\command- D:\system\viewer\FlipVideoforPC.exe
Flip Video for PC\command- D:\system\viewer\FlipVideoforPC.exe




-- End of Deckard's System Scanner: finished at 2008-05-10 00:14:20 ------------

#6 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:09:35 PM

Posted 10 May 2008 - 12:00 AM

Hi fanceigirl,

I decided to get rid of the Mcafee anyway because I won't be using it. Can you suggest an reputable online virus scan for future reference?


Either use Trend Micro Housecall
or
Panda Acive Scan



I only see one item to fix with Hijackthis. :thumbsup:

Download CCleaner and install it. (default location is best). Do not run it yet!

Beginners Guide to CCleaner

*******************************************

Select the following with HijackThis.
With all windows (including this one!) closed (close browser/explorer windows), please select "fix checked"

O9 - Extra button: Yahoo Mail Side Bar - {02E629B1-DA2B-4AA4-90ED-7E212089BEA4} - shdocvw.dll (file missing)

*******************************************

*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders and does not make backups.

Let's empty the temp files:

Run CCleaner.

CAUTION: Please do NOT use the Issues or Registry button. This is a built-in registry cleaner. If you don't know how to use it, you may cause irreparable damage to your system.

1. Starting with v1.27.260, CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation.
IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbarfree Basic version instead of the Standard Build.


2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"

3. Then select the items you wish to clean up.

In the Windows Tab:
Clean all entries in the "Internet Explorer" section except Autocomplete Forum History.
Clean all the entries in the "Windows Explorer" section.
Clean all entries in the "System" section except for Start Menu Shortcuts and Desktop Shortcuts.
Clean any others that you choose.

In the Applications Tab:
Clean all including cookies in the Firefox/Mozilla section if you use it.
Clean all in the Opera section if you use it.
Clean Sun Java in the Internet Section.
Clean any others that you choose.

4. Click the "Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "OK" and it will scan and clean your system.
7. Click "exit" when done.

If it asks you to reboot at the end, click NO.

CCleaner should be run with the above settings for each User Account!

*******************************************

Reboot your computer, post a new Hijackthis log, and tell me how your computer is running.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:09:35 PM

Posted 15 May 2008 - 04:15 PM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact me or a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users