Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Error On Starting The Pc


  • Please log in to reply
10 replies to this topic

#1 Snake_death2

Snake_death2

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:02:36 AM

Posted 09 December 2006 - 11:01 AM

My problem is that, when I start my computer, I get the message

Posted Image
Translated:
"There has been an error while loading C:\WINDOWS\system32\tnfyxll.dll
Access denied."
I don't know how to get rid of it. I haven't taken any actions too, because I think I'll do something wrong.
Btw, the message just pops up, I haven't noticed any problems occuring because of that. I just press "OK" and nothing else happens later on.
This is my log:

Logfile of HijackThis v1.99.1
Scan saved at 16:45:20, on 9/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Telemeter 3.0\telemeter3.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\TrustSoft AntiSpyware\TrustSoftAntiSpyware.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0AC79871-BC8A-1DDC-0363-03DC024C51AD} - C:\WINDOWS\system32\ivmrqhb.dll (file missing)
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Telemeter 3.0] "C:\Program Files\Telemeter 3.0\telemeter3.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TrustSoftAntiSpyware] C:\Program Files\TrustSoft AntiSpyware\TrustSoftAntiSpyware.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [tfnyxll.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\tfnyxll.dll,rjtlcef
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: Dexia netbanking - http://netbanking.dexia.be/PC//Dynamic/Sha...t//DexiaIIA.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{03607F0B-C644-4AA9-9442-0AD6AE8D4DD1}: NameServer = 85.255.116.55,85.255.112.136
O17 - HKLM\System\CCS\Services\Tcpip\..\{3DD977EB-CBF7-4FCA-80B0-921D14BB9E56}: NameServer = 85.255.116.55,85.255.112.136
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0FBA12A-CA93-4730-B0BF-474830DEBB9B}: NameServer = 85.255.116.55,85.255.112.136
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.55 85.255.112.136
O17 - HKLM\System\CS1\Services\Tcpip\..\{03607F0B-C644-4AA9-9442-0AD6AE8D4DD1}: NameServer = 85.255.116.55,85.255.112.136
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.55 85.255.112.136
O17 - HKLM\System\CS2\Services\Tcpip\..\{03607F0B-C644-4AA9-9442-0AD6AE8D4DD1}: NameServer = 85.255.116.55,85.255.112.136
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.55 85.255.112.136
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Windows Media Connect-service (WMConnectCDS) - Unknown owner - C:\Program Files\Windows Media Connect 2\wmccds.exe (file missing)

Edited by Snake_death2, 09 December 2006 - 11:03 AM.

Hell was too full so I came back.

BC AdBot (Login to Remove)

 


#2 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:08:36 PM

Posted 09 December 2006 - 04:30 PM

You have a number of problems


You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout

http://downloads.subratam.org/Fixwareout.exe
or
http://swandog46.geekstogo.com/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

When your system reboots, follow the prompts. Afterwards, Hijack This will launch.
Fix these with HJT – mark them, close IE, click fix checked

O17 - HKLM\System\CCS\Services\Tcpip\..\{03607F0B-C644-4AA9-9442-0AD6AE8D4DD1}: NameServer = 85.255.116.55,85.255.112.136

O17 - HKLM\System\CCS\Services\Tcpip\..\{3DD977EB-CBF7-4FCA-80B0-921D14BB9E56}: NameServer = 85.255.116.55,85.255.112.136

O17 - HKLM\System\CCS\Services\Tcpip\..\{D0FBA12A-CA93-4730-B0BF-474830DEBB9B}: NameServer = 85.255.116.55,85.255.112.136

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.55 85.255.112.136

O17 - HKLM\System\CS1\Services\Tcpip\..\{03607F0B-C644-4AA9-9442-0AD6AE8D4DD1}: NameServer = 85.255.116.55,85.255.112.136

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.55 85.255.112.136

O17 - HKLM\System\CS2\Services\Tcpip\..\{03607F0B-C644-4AA9-9442-0AD6AE8D4DD1}: NameServer = 85.255.116.55,85.255.112.136



If you have connection problems after this

* Go to Control Panel. - If you are using Windows XP's Category View, select the Network and Internet Connections category. If you are in Classic View, go to the next step .
· Double-click the Network Connections icon
· Right-click the Local Area Connection icon and select Properties.
· Hilight Internet Protocol (TCP/IP) and click the Properties button.
· Be sure Obtain DNS server address automatically is selected.
· OK your way out.

* Go to Start > Run and type in cmd
· Click OK.
· This will open a commad prompt.
· Type or copy and paste the following line in the command window:

ipconfig /flushdns
· Hit Enter
· Exit the command window

Do that before you restart.

=============
At the end of the fix, you may need to restart your computer again.

Finally, please post the contents of the logfile C:\fixwareout\report.txt, along with a new Hijack This log.

==================================
If you get an Autoexec nt error do the following

XP Fix - http://www.visualtour.com/downloads/

Scroll down to get XP Fix

And run FixWareout again.


Download AVG Anti-Spyware from http://www.ewido.net/en/download/ and save that file to your desktop. Note: This is NOT the Anti Virus from AVG.

When the trial period expires it becomes feature-limited freeware but is still worth keeping as a good on-demand scanner.
1. Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double click it to launch the set up program.
2. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
3. On the main screen select the icon "Update" then select the "Update now" link.
o Next select the "Start Update" button. The update will start and a progress bar will show the updates being installed.
4. Once the update has completed, select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
6. Under "Reports"
o Select "Automatically generate report after every scan"
o Un-Select "Only if threats were found"
Close AVG Anti-Spyware. Do Not run a scan just yet, we will run it in safe mode.
1. Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.

IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning as it may interfere with the scanning process:
2. Launch AVG Anti-Spyware by double clicking the icon on your desktop.
3. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
4. AVG will now begin the scanning process. Please be patient as this may take a little time.
Once the scan is complete, do the following:
5. If you have any infections you will be prompted. Then select "Apply all actions."
6. Next select the "Reports" icon at the top.
7. Select the "Save report as" button in the lower lef- hand of the screen and save it to a text file on your system (make sure to remember where you saved that file. This is important).
8. Close AVG Anti-Spyware and reboot your system back into Normal Mode.
Post the log from AVG and a new HiJack log
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#3 Snake_death2

Snake_death2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:02:36 AM

Posted 09 December 2006 - 07:19 PM

I do not have connection problems nor autoexec nt error.
And on your request, my HijackThis log and report.txt file.

HijackThis:

Logfile of HijackThis v1.99.1
Scan saved at 1:11:21, on 10/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Telemeter 3.0\telemeter3.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\TrustSoft AntiSpyware\TrustSoftAntiSpyware.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0AC79871-BC8A-1DDC-0363-03DC024C51AD} - C:\WINDOWS\system32\ivmrqhb.dll (file missing)
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Telemeter 3.0] "C:\Program Files\Telemeter 3.0\telemeter3.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TrustSoftAntiSpyware] C:\Program Files\TrustSoft AntiSpyware\TrustSoftAntiSpyware.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [tfnyxll.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\tfnyxll.dll,rjtlcef
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: Dexia netbanking - http://netbanking.dexia.be/PC//Dynamic/Sha...t//DexiaIIA.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Windows Media Connect-service (WMConnectCDS) - Unknown owner - C:\Program Files\Windows Media Connect 2\wmccds.exe (file missing)

Report.txt:

Fixwareout
Last edited 12/06/2006
Post this report in the forums please
...
Prerun check
[HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"="csoyn.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"dmuun.exe"="C:\\WINDOWS\\system32\\dmuun.exe"

...
...
Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}73B4D0A3BA69-5EEB-A194-28D8-41C416C5{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}003E5A76650B-702A-CCC4-4973-892C5F63{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6FB5F24CF2A4-62F8-F9B4-62A6-C290097B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3CE0200773AA-650B-F014-013B-93BAA3FB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\nuumd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\1trap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\2trap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\0mdm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\1mdm
...

Random Runs removed from HKLM
"dmuun.exe"=-
...
...

PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

»»»»» Searching by size/names...
* csr.exe C:\WINDOWS\System32\CSOYN.EXE

»»»»»
Search five digit cs, dm kd and jb files.
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINDOWS\SYSTEM32\CSOYN.EXE 51.208 2006-08-24
C:\WINDOWS\SYSTEM32\DMQCE.EXE 61.969 2004-08-04
C:\WINDOWS\SYSTEM32\DMUUN.EXE 61.969 2004-08-04

Other suspects.
C:\WINDOWS\System32\{BF3AAB39-B310-410F-B056-AA3770020EC3}.exe

»»»»» Misc files.

»»»»» Checking for older varients covered by the Rem3 tool.
...
Postrun check
[HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"system"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00

...
Hell was too full so I came back.

#4 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:08:36 PM

Posted 09 December 2006 - 07:58 PM

You may want to print this or save it to notepad as we will go to safe mode.

Fix these with HiJackThis – mark them, close IE, click fix checked

O2 - BHO: (no name) - {0AC79871-BC8A-1DDC-0363-03DC024C51AD} - C:\WINDOWS\system32\ivmrqhb.dll (file missing)

O4 - HKLM\..\Run: [tfnyxll.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\tfnyxll.dll,rjtlcef

DownLoad http://www.downloads.subratam.org/KillBox.zip or
http://www.thespykiller.co.uk/files/killbox.exe

Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

C:\WINDOWS\system32\tfnyxll.dll

Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

START – RUN – type in %temp% - OK - Edit – Select all – File – Delete

Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

Not all temp files will delete and that is normal
Empty the recycle bin
Boot and post a new log from normal NOT safe mode

Please give feedback on what worked/didn’t work and the current status of your system
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#5 Snake_death2

Snake_death2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:02:36 AM

Posted 12 December 2006 - 03:59 PM

MFDnSC, everything went as you said, no problems occured while doing what u asked me for. The error that kept popping up is gone now, thanks for your help all, keep up the good work :thumbsup: .
And I didn't know what log u meant, the killbox or hijackthis, so I'll just post them both, it might save you some problems :flowers: .

Killbox
Pocket Killbox version 2.0.0.648
Running on Windows XP as Administrator(Administrator)
was started @ dinsdag, december 12, 2006, 9:42 PM

# 1 [Files to Delete]
Path = C:\WINDOWS\system32\tfnyxll.dll
*File Was Deleted

Killbox Closed(Exit) @ 9:45:00 PM
__________________________________________________

HijackThis

Logfile of HijackThis v1.99.1
Scan saved at 21:52:46, on 12/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Telemeter 3.0\telemeter3.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\TrustSoft AntiSpyware\TrustSoftAntiSpyware.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Telemeter 3.0] "C:\Program Files\Telemeter 3.0\telemeter3.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TrustSoftAntiSpyware] C:\Program Files\TrustSoft AntiSpyware\TrustSoftAntiSpyware.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: Dexia netbanking - http://netbanking.dexia.be/PC//Dynamic/Sha...t//DexiaIIA.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


I hope everything is allright now?
Hell was too full so I came back.

#6 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:08:36 PM

Posted 12 December 2006 - 05:01 PM

To be safe lets run AVG's Spyware tool

Download AVG Anti-Spyware from http://www.ewido.net/en/download/ and save that file to your desktop. Note: This is NOT the Anti Virus from AVG.

When the trial period expires it becomes feature-limited freeware but is still worth keeping as a good on-demand scanner.
1. Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double click it to launch the set up program.
2. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
3. On the main screen select the icon "Update" then select the "Update now" link.
o Next select the "Start Update" button. The update will start and a progress bar will show the updates being installed.
4. Once the update has completed, select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
6. Under "Reports"
o Select "Automatically generate report after every scan"
o Un-Select "Only if threats were found"
Close AVG Anti-Spyware. Do Not run a scan just yet, we will run it in safe mode.
1. Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.

IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning as it may interfere with the scanning process:
2. Launch AVG Anti-Spyware by double clicking the icon on your desktop.
3. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
4. AVG will now begin the scanning process. Please be patient as this may take a little time.
Once the scan is complete, do the following:
5. If you have any infections you will be prompted. Then select "Apply all actions."
6. Next select the "Reports" icon at the top.
7. Select the "Save report as" button in the lower lef- hand of the screen and save it to a text file on your system (make sure to remember where you saved that file. This is important).
8. Close AVG Anti-Spyware and reboot your system back into Normal Mode.
Post the log from AVG and a new HiJack log
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#7 Snake_death2

Snake_death2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:02:36 AM

Posted 13 December 2006 - 11:38 AM

I am glad you mentioned to scan my computer, I seem to have 209 infections :thumbsup: . Didn't expect that.
On your request my hijackthis log and the report of AVG Anti-Spyware:

AVG report
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 17:16:59 13/12/2006

+ Scan result:



C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll -> Adware.BHO : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP167\A0070018.exe -> Adware.Trymedia : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP171\A0070287.exe -> Adware.Trymedia : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP177\A0074730.exe -> Adware.Trymedia : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP177\A0074734.exe -> Adware.Trymedia : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP177\A0074737.exe -> Adware.Trymedia : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP180\A0076069.exe -> Adware.Trymedia : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077273.exe -> Adware.Trymedia : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP196\A0077486.exe -> Adware.Trymedia : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP196\A0077491.exe -> Adware.Trymedia : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP196\A0077500.exe -> Adware.Trymedia : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077049.exe -> Adware.VirusBurst : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077128.exe -> Adware.VirusBurst : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP163\A0068590.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP163\A0069590.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP164\A0069609.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP164\A0069617.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP164\A0069633.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP164\A0069667.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP164\A0069707.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP164\A0069717.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP165\A0069755.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP165\A0069763.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP165\A0069776.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP165\A0069800.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP165\A0069818.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP165\A0069825.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP166\A0069836.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP166\A0069843.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP166\A0069866.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP166\A0069883.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP166\A0069890.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP166\A0069903.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP167\A0069966.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP167\A0070032.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP167\A0070037.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP168\A0070046.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP168\A0070064.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP168\A0070071.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP169\A0070084.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP169\A0070095.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP169\A0070105.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP170\A0070150.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP170\A0070155.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP170\A0070162.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP170\A0070175.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP170\A0070193.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP170\A0070204.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP170\A0070211.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP171\A0070224.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP171\A0070252.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP171\A0070259.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP171\A0070269.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP171\A0070279.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP171\A0070290.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP172\A0070309.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP172\A0070316.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP172\A0070323.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP172\A0071323.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP172\A0071394.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP173\A0071401.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP173\A0071408.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP173\A0072408.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP173\A0073409.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP173\A0073422.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP173\A0073429.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP173\A0073436.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP173\A0073445.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP174\A0073460.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP175\A0073539.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP175\A0073544.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP175\A0073550.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP175\A0073570.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP175\A0073577.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP175\A0073585.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP176\A0073642.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP176\A0073656.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP176\A0073667.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP176\A0073674.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP176\A0073689.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP177\A0073698.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP177\A0074698.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP177\A0074706.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP177\A0074711.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP177\A0074722.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP178\A0074782.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP179\A0075867.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP179\A0075952.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP179\A0075961.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP179\A0075970.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP180\A0075986.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP180\A0075994.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP180\A0076004.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP180\A0076013.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP180\A0076023.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP180\A0076041.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP180\A0076060.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP180\A0076077.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP180\A0076087.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP180\A0076097.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP180\A0076113.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP181\A0076285.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP181\A0076298.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP181\A0076305.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP181\A0076321.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP182\A0076343.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP182\A0076351.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP182\A0076366.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP182\A0076376.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP183\A0076393.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP183\A0076402.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP183\A0076411.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP183\A0076420.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP183\A0076436.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP184\A0076467.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP184\A0076482.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP184\A0076497.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP184\A0076507.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP184\A0076516.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP185\A0076531.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP185\A0076542.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP185\A0076555.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP185\A0076564.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP185\A0076573.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP186\A0076591.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP186\A0076600.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP186\A0076609.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP187\A0076653.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP187\A0076662.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP187\A0076671.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP188\A0076698.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP188\A0076707.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP189\A0076741.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP189\A0076752.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP190\A0076816.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP190\A0076826.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP191\A0076841.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP191\A0076865.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP191\A0076874.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP191\A0076894.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP193\A0076924.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP193\A0076930.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP193\A0076955.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP194\A0077017.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP194\A0077026.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP194\A0077035.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077065.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077114.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077141.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077151.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077287.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077297.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077307.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077312.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077339.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077347.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077377.exe -> Downloader.Agent.uj : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077392.exe -> Downloader.Agent.uj : Cleaned.
C:\WINDOWS\system32\csoyn.exe -> Downloader.Agent.uj : Cleaned.
C:\Documents and Settings\Gebruiker\Mijn documenten\CrackDown22\CrackDown Store\[worms 2] Cracks\Worms 2 v1.0 German.zip/BUTCH.exe -> Downloader.INService : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP169\A0070139.exe -> Hijacker.VB.qb : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP169\A0070142.exe -> Hijacker.VB.qb : Cleaned.
C:\Morrowind\TRAINER.EXE -> Logger.Banker : Cleaned.
C:\Morrowind\cls-morrowind-trn.zip/TRAINER.EXE -> Logger.Banker : Cleaned.
C:\Documents and Settings\Gebruiker\Mijn documenten\Cracks\CrackSearcher.exe -> Not-A-Virus.HackTool.Win32.CrackSearch.a : Cleaned.
C:\Documents and Settings\Gebruiker\Local Settings\Temp\laf289.tmp -> Not-A-Virus.Hoax.Win32.Renos.ap : Cleaned.
C:\System Volume Information\_restore{6C10B4E2-891E-4F12-9746-DE1B25E79A28}\RP195\A0077309.dll -> Not-A-Virus.Hoax.Win32.Renos.ap : Cleaned.
:mozilla.94:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.95:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.96:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Gebruiker\Cookies\gebruiker@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Gebruiker\Cookies\gebruiker@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.88:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.10:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.56:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.47:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.48:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.90:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.91:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Gebruiker\Cookies\gebruiker@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.22:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.92:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.93:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
C:\Documents and Settings\Gebruiker\Cookies\gebruiker@stat.onestat[2].txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.115:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.116:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.62:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.65:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.66:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.67:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.68:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Gebruiker\Cookies\gebruiker@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.41:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.119:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.130:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.101:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Gebruiker\Cookies\gebruiker@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.49:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.53:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.54:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.55:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.120:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.44:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.45:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Gebruiker\Cookies\gebruiker@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.46:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.50:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.51:C:\Documents and Settings\Gebruiker\Application Data\Mozilla\Firefox\Profiles\w9dha07s.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\WINDOWS\system32\{BF3AAB39-B310-410F-B056-AA3770020EC3}.exe -> Trojan.Small.fb : Cleaned.


::Report end

HijackThis log

Logfile of HijackThis v1.99.1
Scan saved at 17:21:06, on 13/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Telemeter 3.0\telemeter3.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\TrustSoft AntiSpyware\TrustSoftAntiSpyware.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\svchost.exe
C:\Hijack this\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Telemeter 3.0] "C:\Program Files\Telemeter 3.0\telemeter3.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TrustSoftAntiSpyware] C:\Program Files\TrustSoft AntiSpyware\TrustSoftAntiSpyware.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: Dexia netbanking - http://netbanking.dexia.be/PC//Dynamic/Sha...t//DexiaIIA.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

Also I have noticed on the scanning proces there are adult files located, can I receive those files with a simple popup or only when you visit such sites? Else I wouldn't know where it came from, but I'm not the only one that uses this computer...
Oh, about the file "logger.banker" , does it store passwords? I use online banking service which requires my password. I just hope I wont have banking problems because of this file. I'm a bit worried about it.
Hell was too full so I came back.

#8 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:08:36 PM

Posted 14 December 2006 - 11:06 AM

Those are mainly thrid party cookies that are set from other sites

Looks like soem one was getting craks for some games and that was some of the infection

Add remove programs – remove – Macrogaming or SweetIM

You may want to print this or save it to notepad as we will go to safe mode.

Fix these with HiJackThis – mark them, close IE, click fix checked

O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)

O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)

O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe

O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe

DownLoad http://www.downloads.subratam.org/KillBox.zip or
http://www.thespykiller.co.uk/files/killbox.exe

Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

C:\Program Files\Macrogaming

Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

START – RUN – type in %temp% - OK - Edit – Select all – File – Delete

Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

Not all temp files will delete and that is normal
Empty the recycle bin
Boot and post a new log from normal NOT safe mode

Please give feedback on what worked/didn’t work and the current status of your system
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#9 Snake_death2

Snake_death2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:02:36 AM

Posted 14 December 2006 - 11:54 AM

Everything went as you said it, except this:

O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe

O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe

I couldn't find any of those, so I guess that's a good thing?
And your log you requested:

HijackThis

Logfile of HijackThis v1.99.1
Scan saved at 17:43:09, on 14/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Telemeter 3.0\telemeter3.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\TrustSoft AntiSpyware\TrustSoftAntiSpyware.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Hijack this\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Telemeter 3.0] "C:\Program Files\Telemeter 3.0\telemeter3.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TrustSoftAntiSpyware] C:\Program Files\TrustSoft AntiSpyware\TrustSoftAntiSpyware.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: Dexia netbanking - http://netbanking.dexia.be/PC//Dynamic/Sha...t//DexiaIIA.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

In case you needed this too,
Killbox

Pocket Killbox version 2.0.0.648
Running on Windows XP as Administrator(Administrator)
was started @ donderdag, december 14, 2006, 5:37 PM

# 1 [Files to Delete]
Path = C:\Program files\macrogaming
*File Was Deleted

Killbox Closed(Exit) @ 5:39:12 PM
__________________________________________________

Oh btw, to get into safe mode, I can't do that by tapping F8 while restarting, it shows me with what i want to start (ex. CD-ROM or FLOPPY). I do it by typing "msconfig" in START -> RUN , then select the tab "boot.ini" then check "safe_boot" and restart.
Hell was too full so I came back.

#10 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:08:36 PM

Posted 14 December 2006 - 02:45 PM

Clean Posted Image

Turn off restore points, boot, turn them back on – here’s how

http://service1.symantec.com/SUPPORT/tsgen...src=sec_doc_nam
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#11 Snake_death2

Snake_death2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:02:36 AM

Posted 15 December 2006 - 07:50 AM

Thanks for the help MFDnSC, I'm free once again :thumbsup:
Hell was too full so I came back.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users