Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijack And Dss Log- Winspywareprotect


  • This topic is locked This topic is locked
2 replies to this topic

#1 aaronsmom

aaronsmom

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:06:34 PM

Posted 22 June 2008 - 08:35 PM

I keep getting winspywareprotect popups. I ran spybot s&d, trend micro, avast, pc dr, virtumondo cleaner (can't remember the exact name). All of them say nothing found, but that stupid thing keeps popping up and when I try to visit a page on explorer it tells me that the page is infected and asks if I want to be protected or continue unprotected.





Deckard's System Scanner v20071014.68
Run by Aaron on 2008-06-22 21:23:15
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- Last 5 Restore Point(s) --
29: 2008-06-21 23:42:50 UTC - RP239 - Spyware Doctor: Cleaning Threats
28: 2008-06-21 23:13:17 UTC - RP237 - Spyware Doctor: Cleaning Threats
27: 2008-06-21 22:48:51 UTC - RP235 - Spyware Doctor: Cleaning Threats
26: 2008-06-21 22:43:21 UTC - RP233 - Removed Google Toolbar for Internet Explorer
25: 2008-06-20 11:37:50 UTC - RP232 - Windows Update


-- First Restore Point --
1: 2008-05-22 23:12:15 UTC - RP206 - Windows Update


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as Aaron.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:26:55 PM, on 6/22/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\AERTSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Update\1.1.27.3\GoogleUpdate.exe
C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\ProgramData\ADSL Software Ltd\WinSpywareProtect\winspywareprotect.exe
C:\Program Files\Safari\Safari.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Aaron\Desktop\dss.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Aaron.exe
C:\Windows\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {BE0027FB-31FF-4661-82BC-83ADCEF28F0F} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Online Games Toolbar - {0165e3f9-cd53-4d1f-a78d-3af2a012b657} - C:\Program Files\Online_Games\tbOnli.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Google Update Class - {F286500C-177A-4316-9E88-9814FBB1DC3D} - C:\Program Files\Google\Update\1.1.27.3\GoopdateBho.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Online Games Toolbar - {0165e3f9-cd53-4d1f-a78d-3af2a012b657} - C:\Program Files\Online_Games\tbOnli.dll
O3 - Toolbar: Ask Toolbar - {5A074B29-F830-49de-A31B-5BB9D7F6B407} - C:\Program Files\AskBar\bar\bin\askBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SysCB78.exe] C:\SysCB78.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [SysCB78.exe] C:\SysCB78.exe
O4 - HKCU\..\Run: [WinSpywareProtect] "C:\ProgramData\ADSL Software Ltd\WinSpywareProtect\winspywareprotect.exe" /autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1413310504-1170074666-3278358486-1000\..\Run: [TweakVI] "C:\Program Files\TweakVI\tweakvi.exe" -autostart (User 'Moms')
O4 - HKUS\S-1-5-21-1413310504-1170074666-3278358486-1000\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'Moms')
O4 - HKUS\S-1-5-21-1413310504-1170074666-3278358486-1000\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter (User 'Moms')
O4 - HKUS\S-1-5-21-1413310504-1170074666-3278358486-1000\..\Run: [Sys8E79.exe] C:\Sys8E79.exe (User 'Moms')
O4 - S-1-5-21-1413310504-1170074666-3278358486-1000 Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe (User 'Moms')
O4 - S-1-5-21-1413310504-1170074666-3278358486-1000 User Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe (User 'Moms')
O4 - Startup: SpywareGuard.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O8 - Extra context menu item: &Save Image to Folder - res://C:\Program Files\AskBar\bar\bin\askBar.dll/saveimagetofolder.html
O8 - Extra context menu item: &Save Image to MyStuff - res://C:\Program Files\AskBar\bar\bin\askBar.dll/saveimages.html
O8 - Extra context menu item: &Save Link to Folder - res://C:\Program Files\AskBar\bar\bin\askBar.dll/saveltof.html
O8 - Extra context menu item: &Save Link to MyStuff - res://C:\Program Files\AskBar\bar\bin\askBar.dll/savelink.html
O8 - Extra context menu item: &Save Page to Folder... - res://C:\Program Files\AskBar\bar\bin\askBar.dll/savepagetofolder.html
O8 - Extra context menu item: &Save this Page to MyStuff - res://C:\Program Files\AskBar\bar\bin\askBar.dll/savewebpage.html
O8 - Extra context menu item: &Save Video As... - res://C:\Program Files\videodetect\videodetect.dll/201
O9 - Extra button: Video Detect - {0028E570-E86D-4ceb-A108-76158C18DEF3} - C:\Program Files\videodetect\videodetect.dll
O9 - Extra 'Tools' menuitem: Video Detect - {0028E570-E86D-4ceb-A108-76158C18DEF3} - C:\Program Files\videodetect\videodetect.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex...wareControl.cab
O16 - DPF: {5D80A6D1-B500-47DA-82B8-EB9875F85B4D} (Google Gadget Control) - http://dl.google.com/dl/desktop/nv/GoogleG...PluginIEWin.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX28.cab
O16 - DPF: {B4A78D29-52B1-4A7B-BAC0-1471BEDF9836} - http://xscanner.shredderscan.com/setup/webinst.cab
O16 - DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} (GoBit Games Player) - http://www.gamehouse.com/realarcade-webgam...GamesPlayer.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in...l/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.gamehouse.com/realarcade-webgam...opcaploader.cab
O16 - DPF: {FF791555-FDAC-43AB-B792-389E4CC0A6E5} (Toontown TestServer Installer ActiveX Control) - http://download.test.toontown.com/sv1.0.32...est/tt_test.cab
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Update Service (gupdate1c8cf172087e35d) (gupdate1c8cf172087e35d) - Google Inc. - C:\Program Files\Google\Update\1.1.27.3\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 14474 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

S3 DSproct - \??\c:\program files\dellsupport\gtaction\triggers\dsproct.sys
S3 nocashio - c:\windows\system32\drivers\nocashio.sys


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
R2 sprtsvc_dellsupportcenter (SupportSoft Sprocket Service (dellsupportcenter)) - c:\program files\dell support center\bin\sprtsvc.exe /service /p dellsupportcenter

S2 CLTNetCnService (Symantec Lic NetConnect service) - "c:\program files\common files\symantec shared\ccsvchst.exe" /h cccommon (file missing)
S3 DSBrokerService - "c:\program files\dellsupport\brkrsvc.exe" <Not Verified; ; Gteko BrkrSvc Application>
S3 stllssvr - "c:\program files\common files\surething shared\stllssvr.exe" (file missing)


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-06-22 08:02:32 328 --a------ C:\Windows\Tasks\GoogleUpdateTask.job


-- Files created between 2008-05-22 and 2008-06-22 -----------------------------

2008-06-22 18:00:10 0 d-------- C:\VundoFix Backups
2008-06-22 17:44:16 0 d-------- C:\Program Files\Trend Micro
2008-06-22 17:01:18 62910 --a------ C:\Program Files\Uninstall.exe <Not Verified; $PROGRAMNAME; $PROGRAMNAME>
2008-06-22 17:01:18 0 --a------ C:\Program Files\uninstall.dat
2008-06-22 15:06:05 0 d-------- C:\Users\All Users\ADSL Software Ltd
2008-06-22 09:40:14 0 d-------- C:\Program Files\DVDVideoSoft
2008-06-22 09:40:14 0 d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-06-22 09:32:11 0 d-------- C:\tmp
2008-06-22 09:31:27 0 d-------- C:\tmpDownload
2008-06-22 09:31:21 0 d-------- C:\YoutubeGet
2008-06-22 08:01:50 31744 --a------ C:\SysCB78.exe
2008-06-21 19:58:36 0 d-------- C:\Users\Aaron\.housecall6.6
2008-06-21 19:53:29 31744 --a------ C:\SysA90A.exe
2008-06-21 19:45:11 31744 --a------ C:\Sys8E79.exe
2008-06-21 18:45:27 0 d-------- C:\Program Files\Spyware Doctor
2008-06-21 18:44:13 0 d-------- C:\Users\All Users\Google Updater
2008-06-21 16:55:37 31744 --a------ C:\Sys6FD2.exe
2008-06-21 16:47:21 30720 --a------ C:\SysA1EA.exe
2008-06-21 16:47:20 30208 --a------ C:\SysA16D.exe
2008-06-21 16:47:20 31744 --a------ C:\SysA110.exe
2008-06-21 16:47:20 31744 --a------ C:\SysA0A2.exe
2008-06-21 16:47:14 0 d-------- C:\Program Files\PCHealthCenter
2008-06-21 16:00:53 0 d-------- C:\Program Files\Common Files\Axara
2008-06-21 16:00:52 139264 --a------ C:\Windows\system32\xvidvfw.dll
2008-06-21 16:00:52 524288 --a------ C:\Windows\system32\xvidcore.dll
2008-06-21 16:00:52 438272 --a------ C:\Windows\system32\vp6vfw.dll <Not Verified; On2.com; On2_VP6>
2008-06-21 16:00:52 413760 --a------ C:\Windows\system32\mpg4c32.dll <Not Verified; Microsoft Corporation; Microsoft MPEG-4 Video Codec>
2008-06-21 16:00:52 261632 --a------ C:\Windows\system32\mcdvd_32.dll <Not Verified; MainConcept; MainConcept DV Codec "2.0.4>
2008-06-21 16:00:52 1700352 --a------ C:\Windows\system32\GdiPlus.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-06-21 16:00:52 0 d-------- C:\Program Files\Axara
2008-06-21 15:49:53 0 d-------- C:\Program Files\PowerPoint to Flash
2008-06-21 15:45:54 0 d-------- C:\Users\All Users\Apowersoft
2008-06-21 15:44:51 0 d-------- C:\Windows\Application Data
2008-06-21 15:20:39 0 d-------- C:\Program Files\Homevideopage
2008-06-17 19:43:38 0 d-------- C:\Movavi files
2008-06-17 19:06:46 0 d-------- C:\Program Files\videodetect
2008-06-17 18:39:51 0 d-------- C:\Program Files\TubeSucker
2008-06-17 18:26:00 0 d-------- C:\Downloaded Videos
2008-06-17 18:25:42 101888 --a------ C:\Windows\system32\VB6STKIT.DLL <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2008-06-16 19:06:42 0 d-------- C:\Program Files\FDRLab
2008-06-16 18:37:24 0 d-------- C:\Program Files\MyTubePlayer
2008-06-16 18:32:14 0 d-------- C:\E-Zsoft
2008-06-16 18:31:54 0 d-------- C:\Program Files\E-Zsoft
2008-06-16 18:17:10 0 d-------- C:\Downloads
2008-06-16 12:28:56 0 d-------- C:\Program Files\DsNET Corp
2008-06-16 12:14:38 0 d-------- C:\My FLVs
2008-06-16 12:13:45 3596288 --a------ C:\Windows\system32\qt-dx331.dll
2008-06-16 12:13:45 574976 --a------ C:\Windows\system32\divx.dll <Not Verified; DivX, Inc.; DivX®>
2008-06-16 12:13:44 0 d-------- C:\Program Files\YouTubeRobot
2008-06-16 11:58:05 0 d-------- C:\Program Files\LitexMedia
2008-06-15 15:47:53 0 d-------- C:\Program Files\Domain Tools
2008-06-14 07:47:39 0 d-------- C:\Program Files\Tetris
2008-06-12 10:14:33 0 d-------- C:\Program Files\UltraGet Video Downloader
2008-06-11 15:20:01 162944 --a------ C:\Windows\system32\drivers\RT25USBAP.SYS <Not Verified; Ralink Technology Inc.; Ralink 802.11g Wireless USB Adapters>
2008-06-11 12:25:45 0 d-------- C:\Program Files\1964
2008-06-11 12:22:57 4096 --a------ C:\Windows\d3dx.dat
2008-06-11 12:14:35 0 d-------- C:\Program Files\mupen64 0.5
2008-06-08 07:39:30 0 d-------- C:\naevius_temp_folder
2008-06-08 07:39:23 0 d-------- C:\Program Files\Naevius YouTube Converter
2008-06-07 10:06:56 0 d-------- C:\Users\All Users\Activision
2008-06-03 18:46:50 0 d-------- C:\Program Files\Reading Acceleration Machine
2008-06-03 17:44:12 0 d-------- C:\Users\All Users\PlayFirst
2008-06-01 16:45:50 0 d-------- C:\Program Files\YouTube Downloader
2008-05-31 12:30:14 0 d-------- C:\Windows\.jagex_cache_32
2008-05-28 19:25:19 851 --a------ C:\Windows\system32\Infob.dat
2008-05-28 19:25:19 0 --a------ C:\Windows\system32\Infoa.dat
2008-05-28 19:23:28 404 --a------ C:\Windows\system32\treeinfo.dat
2008-05-28 19:23:16 0 d-------- C:\Y.D.T
2008-05-28 19:23:12 53299 --a------ C:\Windows\system32\pthreadVC.dll
2008-05-28 19:23:04 0 d-------- C:\Program Files\E.M. Youtube Video Download Tool


-- Find3M Report ---------------------------------------------------------------

2008-06-22 12:20:09 143440 --ah----- C:\Windows\system32\mlfcache.dat
2008-06-22 09:40:14 0 d-------- C:\Program Files\Common Files
2008-06-21 20:56:25 0 d-------- C:\Program Files\SpywareBlaster
2008-06-21 18:45:27 0 d-------- C:\Users\Aaron\AppData\Roaming\PC Tools
2008-06-21 18:45:10 0 d-------- C:\Program Files\Google
2008-06-21 18:11:10 0 d-------- C:\Program Files\SpywareGuard
2008-06-21 16:01:17 0 d-------- C:\Users\Aaron\AppData\Roaming\Axara
2008-06-21 15:45:54 0 d-------- C:\Users\Aaron\AppData\Roaming\Apowersoft
2008-06-20 14:59:04 0 d-------- C:\Program Files\Safari
2008-06-16 18:22:09 0 d-------- C:\Users\Aaron\AppData\Roaming\Orbit
2008-06-16 12:13:26 0 d-------- C:\Users\Aaron\AppData\Roaming\Download Manager
2008-06-15 14:46:31 0 d-------- C:\Users\Aaron\AppData\Roaming\Jarte
2008-06-15 10:21:54 0 d-------- C:\Users\Aaron\AppData\Roaming\UltraGet
2008-06-13 17:55:19 0 d-------- C:\Users\Aaron\AppData\Roaming\uTorrent
2008-06-11 08:40:00 0 d-------- C:\Program Files\Windows Mail
2008-06-09 06:48:47 0 d-------- C:\Program Files\PC Tools Firewall Plus
2008-06-07 10:06:56 0 d-------- C:\Users\Aaron\AppData\Roaming\Activision
2008-06-07 09:50:50 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-07 09:47:41 0 d-------- C:\Program Files\Activision
2008-06-05 18:01:47 0 d-------- C:\Users\Aaron\AppData\Roaming\PO Kung Fu Challenge
2008-06-03 18:02:50 0 d-------- C:\Program Files\Nick Arcade
2008-06-03 18:02:04 0 d-------- C:\Program Files\Outspark
2008-06-03 17:44:12 0 d-------- C:\Users\Aaron\AppData\Roaming\PlayFirst
2008-06-01 17:19:35 0 d-------- C:\Program Files\InterActual
2008-05-30 19:20:03 0 d-------- C:\Program Files\Common Files\Real
2008-05-30 19:19:58 0 d-------- C:\Users\Aaron\AppData\Roaming\Real
2008-05-25 07:11:27 0 d-------- C:\Program Files\Common Files\Desktop 16
2008-05-13 16:00:27 0 d-------- C:\Program Files\Pokemon PC 2.0
2008-05-10 13:57:35 0 d-------- C:\Users\Aaron\AppData\Roaming\ImTOO Software Studio
2008-05-09 14:38:27 0 d-------- C:\Users\Aaron\AppData\Roaming\Inspiration Software
2008-05-09 13:00:15 0 d-------- C:\Program Files\Crosscountry2
2008-05-08 20:15:43 0 d-------- C:\Program Files\FLV Player
2008-05-07 17:28:17 0 d-------- C:\Users\Aaron\AppData\Roaming\Secret of the Solstice
2008-05-03 14:44:10 0 d-------- C:\Program Files\Replay Converter
2008-05-03 13:43:09 0 d-------- C:\Users\Aaron\AppData\Roaming\GetRightToGo
2008-05-03 13:43:07 737280 --a------ C:\Windows\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2008-04-24 19:22:09 0 d-------- C:\Users\Aaron\AppData\Roaming\Apple Computer
2008-04-02 14:55:13 174 --ahs---- C:\Program Files\desktop.ini


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F286500C-177A-4316-9E88-9814FBB1DC3D}]
06/15/2008 02:39 PM 156144 --a----t- C:\Program Files\Google\Update\1.1.27.3\GoopdateBho.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [01/19/2008 03:38 AM]
"RtHDVCpl"="RtHDVCpl.exe" [01/17/2008 08:22 AM C:\Windows\RtHDVCpl.exe]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [10/03/2006 12:37 PM]
"@"="" []
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [11/15/2007 10:24 AM]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [10/03/2006 12:35 PM]
"00PCTFW"="C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" [11/09/2007 05:00 PM]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [05/15/2008 07:19 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [03/15/2007 09:41 AM]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [03/15/2007 09:41 AM]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [03/15/2007 09:41 AM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [11/15/2007 10:23 AM]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [02/01/2008 12:55 PM]
"SysCB78.exe"="C:\SysCB78.exe" [06/16/2008 05:18 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [01/19/2008 03:33 AM]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [11/15/2007 10:23 AM]
"SysCB78.exe"="C:\SysCB78.exe" [06/16/2008 05:18 PM]
"WinSpywareProtect"="C:\ProgramData\ADSL Software Ltd\WinSpywareProtect\winspywareprotect.exe" [06/22/2008 03:06 PM]

C:\Users\Aaron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [8/29/2003 8:05:35 PM]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [9/4/2007 12:46:34 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"EnableLUA"=0 (0x0)
"EnableUIADesktopToggle"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"=2 (0x2)
"DontDisplayLogonHoursWarnings"=1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\Windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Google Updater.lnk]
backup=C:\Windows\pss\Google Updater.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Antivirus]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"C:\Program Files\DellSupport\DSAgnt.exe" /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
c:\dell\E-Center\EULALauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE Mcx2Svc WebClient SstpSvc
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ac7d3690-5b03-11dc-968e-806e6f6e6963}]
AutoRun\command- E:\dcomchk.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



-- Hosts -----------------------------------------------------------------------

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.1001-search.info
127.0.0.1 1001-search.info
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100sexlinks.com

7794 more entries in hosts file.


-- End of Deckard's System Scanner: finished at 2008-06-22 21:29:35 ------------



Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft® Windows Vista™ Home Premium (build 6001) SP 1.0
Architecture: X86; Language: English

CPU 0: AMD Athlon™ 64 X2 Dual Core Processor 4400+
Percentage of Memory in Use: 49%
Physical Memory (total/avail): 1981.76 MiB / 1001.86 MiB
Pagefile Memory (total/avail): 4210.55 MiB / 2773.74 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1898.3 MiB

C: is Fixed (NTFS) - 288.04 GiB total, 214.13 GiB free.
D: is Fixed (NTFS) - 10 GiB total, 6.22 GiB free.
E: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - ST332062 0AS SCSI Disk Device - 298.09 GiB - 3 partitions
\PARTITION0 - Unknown - 47.03 MiB
\PARTITION1 - Installable File System - 10 GiB - D:
\PARTITION2 (bootable) - Installable File System - 288.04 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.

FW: PC Tools Firewall Plus v2.0.0 (PC Tools)
AV: avast! antivirus 4.8.1201 [VPS 080622-0] v4.8.1201 (ALWIL Software) Disabled
AS: Spyware Doctor v5.5.0.204 (PC Tools)
AS: Windows Defender v1.1.1505.0 (Microsoft Corporation)
AS: avast! antivirus 4.8.1201 [VPS 080622-0] v4.8.1201 (ALWIL Software) Disabled

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\Aaron\AppData\Roaming
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=MOMS-PC
ComSpec=C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\Aaron
LOCALAPPDATA=C:\Users\Aaron\AppData\Local
LOGONSERVER=\\MOMS-PC
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=6b01
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
PROMPT=$P$G
PUBLIC=C:\Users\Public
QTJAVA=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
RoxioCentral=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\Aaron\AppData\Local\Temp
TMP=C:\Users\Aaron\AppData\Local\Temp
USERDOMAIN=Moms-PC
USERNAME=Aaron
USERPROFILE=C:\Users\Aaron
windir=C:\Windows


-- User Profiles ---------------------------------------------------------------

Moms (admin)
Aaron (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> "C:\Program Files\Uninstall.exe"
3D Groove Playback Engine --> RunDll32 C:\Windows\DOWNLO~1\GrooveAX.dll,_RemoveGroove@16
Adobe Flash Player ActiveX --> C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player 11 --> C:\Windows\system32\adobe\SHOCKW~1\UNWISE.EXE C:\Windows\system32\Adobe\SHOCKW~1\Install.log
Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update --> MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
aTube Catcher 1.0 --> MsiExec.exe /I{E81F8ADE-B49B-4242-8FD8-7D9C65A25D68}
avast! Antivirus --> C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
BattlePets --> C:\Program Files\AGD\BattlePets\esuninst.exe C:\Program Files\AGD\BattlePets
Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
Clifford Reading --> C:\Windows\system32\Clifford Uninstall.exe C:\Program Files\Scholastic's Clifford\Clifford Reading\
Conexant D850 PCI V.92 Modem --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1\HXFSETUP.EXE -U -IDel200fz.inf
COWON Media Center - jetAudio Basic --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}\setup.exe" -l0x9 -removeonly
Dell DataSafe Online --> MsiExec.exe /I{2C6C74C2-042F-4D36-B7B0-0C538FCF01AB}
Dell Support Center --> MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
Dell System Customization Wizard --> MsiExec.exe /I{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}
DellSupport --> MsiExec.exe /X{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}
Desktop 16 --> C:\Windows\wnUninstall.exe "Desktop 16"
Digital Line Detect --> C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly
Disney Pirates of the Caribbean Online --> C:\Program Files\Disney\Disney Online\PiratesOnline\uninst.exe
Disney Toontown Online --> C:\Program Files\Disney\Disney Online\ToontownOnline\uninst.exe
Dora Backpack --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D859D35F-E947-4F2A-8591-C76A4D116178}\Setup.exe" -l0x9 -uninst
Fiesta --> C:\Program Files\Outspark\Fiesta\uninstall.exe
Finding Nemo: Nemo's Underwater World of Fun --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{BCB8D603-985E-4765-B4AB-B4B991A535B7} NemoUWFUninstall
FLV Player 2.0, build 24 --> C:\Program Files\FLV Player\uninst.exe
Free YouTube Download 2.2 --> "C:\Program Files\DVDVideoSoft\Free YouTube Download\unins000.exe"
Games, Music, & Photos Launcher --> MsiExec.exe /I{3E25E350-949F-4DB7-8288-2A60E018B4C1}
Google Earth --> MsiExec.exe /I{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}
Google Earth Plugin --> MsiExec.exe /I{B10C92AE-2C2B-11DD-97B5-005056806466}
Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Google Update --> MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Google Updater --> "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
InterActual Player --> C:\Program Files\InterActual\InterActual Player\inuninst.exe
Internet Service Offers Launcher --> MsiExec.exe /I{CCFF1E13-77A2-4032-8B12-7566982A27DF}
iTunes --> MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}
Jarte 3.0 --> "C:\Program Files\Jarte\unins000.exe"
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java™ SE Runtime Environment 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
Magentic --> C:\PROGRA~1\Magentic\bin\mgsetup.exe /remove /addon:Magentic
Microsoft Silverlight --> MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Text-To-Speech 5.1 Setup --> MsiExec.exe /I{4F7C02D5-76FF-4565-BC52-056C29709DD4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 --> MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Works --> MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
Modem Diagnostic Tool --> MsiExec.exe /I{F63A3748-B93D-4360-9AD4-B064481A5C7B}
MSXML 4.0 SP2 (KB927978) --> MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181) --> MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833) --> MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MyTubePlayer --> MsiExec.exe /I{A11DAE22-EB56-44B6-829A-7FAC45DEAA5B}
NetWaiting --> C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly
Nicktoons Basketball --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A3CAC59-129F-4465-A9CC-85021F0CA66D}\Setup.exe" -l0x9 -removeonly
Nintendo Wii Screensaver --> "C:\Program Files\Nintendo Wii Screensaver\unins000.exe"
NVIDIA Drivers --> C:\Windows\system32\NVUNINST.EXE UninstallGUI
NVIDIANetworkDiagnostic --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{EFAD4066-CAF3-4B27-9669-12EED352C376}
Online Games Toolbar --> C:\PROGRA~1\ONLINE~1\UNWISE.EXE C:\PROGRA~1\ONLINE~1\INSTALL.LOG
Outspark Launcher --> C:\Program Files\Outspark\Launcher\uninstall.exe
Over the Hedge™ Demo --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1150\INTEL3~1\IDriver.exe /M{835DE40D-C224-447A-9D65-B015514B3440}
PC Tools Firewall Plus 3.0 --> "C:\Program Files\PC Tools Firewall Plus\unins000.exe"
Picasa 2 --> "C:\Program Files\Picasa2\Uninstall.exe"
PO Kung Fu Challenge (remove only) --> C:\Users\Aaron\AppData\Roaming\PO Kung Fu Challenge\uninst_launcher.exe
Pokemon Global --> C:\Windows\system32\javaws.exe -uninstall -prompt "http://pokeglobal.sourceforge.net/game/beta.jnlp"
Pokemon PC 2.0 --> "C:\Program Files\Pokemon PC 2.0\unins000.exe"
Product Documentation Launcher --> MsiExec.exe /I{89CEAE14-DD0F-448E-9554-15781EC9DB24}
QuickTime --> MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
Rayman Raving Rabbids --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{111E336D-30BF-4CD4-8D69-4541732AFB27}\setup.exe" -l0x9 -removeonly
Realtek High Definition Audio Driver --> RtlUpd.exe -r -m
Registry Mechanic 7.0 --> "C:\Program Files\Registry Mechanic\unins000.exe"
Rhapsody Player Engine --> MsiExec.exe /I{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}
Rhapsody Player Engine --> MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}
Roxio Creator Audio --> MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82}
Roxio Creator BDAV Plugin --> MsiExec.exe /I{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}
Roxio Creator Copy --> MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
Roxio Creator Data --> MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87}
Roxio Creator DE --> MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
Roxio Creator Tools --> MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF}
Roxio MyDVD DE --> MsiExec.exe /I{D639085F-4B6E-4105-9F37-A0DBB023E2FB}
Roxio Update Manager --> MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Safari --> MsiExec.exe /I{C9D96682-5A4D-45FA-BA3E-DDCB2B0CB868}
Scholastic's Huggly Saves The Turtles --> C:\Windows\uninst.exe -fC:\Windows\DeIsL1.isu
Scholastic's I SPY School Days --> C:\PROGRA~1\SCHOLA~2\ISPYSC~1\UNWISE.EXE C:\PROGRA~1\SCHOLA~2\ISPYSC~1\INSTALL.LOG
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Sonic Activation Module --> MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
SpongeBob SquarePants Employee of the Month --> C:\Windows\IsUninst.exe -f"C:\Program Files\THQ\SpongeBob SquarePants\Employee of the Month\Uninst.isu"
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Spyware Doctor 5.5 --> C:\Program Files\Spyware Doctor\unins000.exe /LOG
SpywareBlaster 4.1 --> "C:\Program Files\SpywareBlaster\unins000.exe"
SpywareGuard v2.2 --> "C:\Program Files\SpywareGuard\unins000.exe"
Super Smash Flash EXE Version 1.0 --> "C:\Program Files\Super Smash Flash EXE\unins000.exe"
Tetris --> "C:\Program Files\Tetris\unins000.exe"
Text-to-Speech --> MsiExec.exe /I{ED993825-5744-4707-A65D-7E7CD4D5C6C5}
Text to Speech XP --> MsiExec.exe /X{E32661E0-A745-48A5-A9B9-073FDC6B119C}
Tonka Construction 2 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Hasbro Interactive\Tonka Construction 2\Uninst.isu" -c"C:\Program Files\Hasbro Interactive\Tonka Construction 2\_UnInstall.dll"
TubeSucker --> MsiExec.exe /X{3F9D3AF5-BB74-474A-92C8-410839303DB5}
TweakVI --> "C:\Windows\TweakVI\uninstall.exe" "/U:C:\Program Files\TweakVI\Uninstall\uninstall.xml"
Uninstall 1.0.0.1 --> "C:\Program Files\Common Files\DVDVideoSoft\unins000.exe"
Uninstall Veggie Carnival --> "C:\Program Files\BigIdea\Veggie Carnival\unins000.exe"
URL Assistant --> regsvr32 /u /s "C:\Program Files\BAE\BAE.dll"
User's Guides --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}\setup.exe"
videodetect 1.0 --> "C:\Program Files\videodetect\unins000.exe"
Virtools 3D Life Player --> C:\Program Files\Virtools\3D Life Player\WebplayerConfig.exe -u
Windows Media Player 9 Series Power Toy - Ratings Migration --> RunDll32 advpack.dll,LaunchINFSection C:\Windows\INF\powertoy.inf,Uninstall
Windows Media Player 9 Series TweakMP PowerToy --> RunDll32 advpack.dll,LaunchINFSection C:\Windows\INF\tweakmp.inf,DefaultUninstall
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
WinZip 11.1 --> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}
Yahoo! Install Manager --> C:\Windows\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type27394 / Error
Event Submitted/Written: 06/22/2008 03:07:48 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application Setup_ver1.380.5.exe, version 0.0.0.0, time stamp 0x485e892b, faulting module ntdll.dll, version 6.0.6001.18000, time stamp 0x4791a7a6, exception code 0xc0000005, fault offset 0x00065a20,
process id 0x132c, application start time 0xSetup_ver1.380.5.exe0.

Event Record #/Type27392 / Error
Event Submitted/Written: 06/22/2008 03:05:43 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application vista_sp1.exe, version 0.0.0.0, time stamp 0x00000000, faulting module vista_sp1.exe, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x00001219,
process id 0x1028, application start time 0xvista_sp1.exe0.

Event Record #/Type27389 / Error
Event Submitted/Written: 06/22/2008 09:34:19 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application YoutubeGet.exe, version 4.4.0.0, time stamp 0x4819832d, faulting module kernel32.dll, version 6.0.6001.18000, time stamp 0x4791a76d, exception code 0xc000008f, fault offset 0x000442eb,
process id 0x14c4, application start time 0xYoutubeGet.exe0.

Event Record #/Type27368 / Error
Event Submitted/Written: 06/22/2008 08:02:28 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application GoogleUpdate.exe, version 1.0.0.0, time stamp 0x47ffe7a5, faulting module smumhook.dll_unloaded, version 0.0.0.0, time stamp 0x2a425e19, exception code 0xc0000005, fault offset 0x636f257e,
process id 0x840, application start time 0xGoogleUpdate.exe0.

Event Record #/Type27365 / Warning
Event Submitted/Written: 06/22/2008 08:02:25 AM
Event ID/Source: 1008 / Windows Search Service
Event Description:
The Windows Search Service is attempting to remove the old catalog.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type85369 / Warning
Event Submitted/Written: 06/22/2008 08:01:40 PM
Event ID/Source: 1002 / WinDefend
Event Description:
%Moms-PC27 scan has been stopped before completion.

Scan ID: {D7A5B3C3-6A53-4535-A388-B3F78CE9DF95}

Scan Type: %Moms-PC01

Scan Parameters: %Moms-PC09

User: Moms-PC\Aaron

Event Record #/Type85361 / Warning
Event Submitted/Written: 06/22/2008 05:32:22 PM
Event ID/Source: 3004 / WinDefend
Event Description:
%Moms-PC27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %Moms-PC27 can't undo changes that you allow.

For more information please see the following:
%Moms-PC275

Scan ID: {3275C7C5-689E-4455-9F44-FC08FA1E8DFF}

User: Moms-PC\Aaron

Name: %Moms-PC271

ID: %Moms-PC272

Severity ID: %Moms-PC273

Category ID: %Moms-PC274

Path Found: %Moms-PC276

Alert Type: %Moms-PC278

Detection Type: 1.1.1600.02

Event Record #/Type85357 / Warning
Event Submitted/Written: 06/22/2008 03:06:09 PM
Event ID/Source: 3004 / WinDefend
Event Description:
%Moms-PC27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %Moms-PC27 can't undo changes that you allow.

For more information please see the following:
%Moms-PC275

Scan ID: {5DA063B3-E9E4-43AB-A158-356A5B77153E}

User: Moms-PC\Aaron

Name: %Moms-PC271

ID: %Moms-PC272

Severity ID: %Moms-PC273

Category ID: %Moms-PC274

Path Found: %Moms-PC276

Alert Type: %Moms-PC278

Detection Type: 1.1.1600.02

Event Record #/Type85330 / Warning
Event Submitted/Written: 06/22/2008 08:03:05 AM
Event ID/Source: 4 / Client Side Rendering Spooler
Event Description:
The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key S-1-5-18\Printers\Connections. The print spooler could not open the registry key. This can occur if the registry key is corrupt or missing, or if the registry recently became unavailable.

Event Record #/Type85329 / Warning
Event Submitted/Written: 06/22/2008 08:03:05 AM
Event ID/Source: 4 / Client Side Rendering Spooler
Event Description:
The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key S-1-5-18\Printers\Connections. The print spooler could not open the registry key. This can occur if the registry key is corrupt or missing, or if the registry recently became unavailable.



-- End of Deckard's System Scanner: finished at 2008-06-22 21:29:35 ------------

BC AdBot (Login to Remove)

 


#2 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:03:34 PM

Posted 24 June 2008 - 09:22 PM

Hello aaronsmom,

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

Copy and Paste the entire report in your next reply along with a fresh HijackThis log.

Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediatly.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:03:34 PM

Posted 02 July 2008 - 08:41 PM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact me or a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users