Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Winantispyware 2007 Need Removal


  • This topic is locked This topic is locked
12 replies to this topic

#1 Witigo3000

Witigo3000

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:09:07 AM

Posted 19 June 2007 - 04:15 PM

any help would be great thanks.

logfile:
Logfile of HijackThis v1.99.1
Scan saved at 5:13:28 PM, on 6/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\system32\E_S00RP1.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinKey\WinKey.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\poolsv\svhost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\HijackThis\HijackThis.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [\\FAMILY\EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P33 "\\FAMILY\EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500 on Family (from BRYAN_LAPTOP)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P54 "EPSON Stylus Photo RX500 on Family (from BRYAN_LAPTOP)" /O5 "TS003" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX500 on FAMILYCOMPUTER] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P47 "Auto EPSON Stylus Photo RX500 on FAMILYCOMPUTER" /O25 "\\FAMILYCOMPUTER\EPSONSty" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [poolsv] "C:\WINDOWS\poolsv.exe"
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKLM\..\Run: [WinAntiSpyware 2007 Free] "C:\Program Files\WinAntiSpyware 2007\was7.exe" /min
O4 - HKLM\..\Run: [uwas7cw] "C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe" -c
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\bkvaoojo.dll",realset
O4 - HKCU\..\Run: [\\FAMILY\EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P33 "\\FAMILY\EPSON Stylus Photo RX500" /M "Stylus Photo RX500" /EF "HKCU"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: WinKey.lnk = C:\Program Files\WinKey\WinKey.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: PokerNow.net - {3CB10829-C0BC-468a-AE91-E88AC48CB345} - C:\Program Files\PokerNow.net\PokerNownet.exe (file missing)
O9 - Extra 'Tools' menuitem: PokerNow.net - {3CB10829-C0BC-468a-AE91-E88AC48CB345} - C:\Program Files\PokerNow.net\PokerNownet.exe (file missing)
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\poker\Poker.com\poker.exe (file missing)
O9 - Extra button: Aztec Riches Poker - {7FCF69CA-B1D5-4b13-A6B0-31020DD5A976} - C:\Program Files\aztecrichesMPP\MPPoker.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Program Files\royalvegasMPP\MPPoker.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptemplates/AktiveSekurity.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe

BC AdBot (Login to Remove)

 


#2 Witigo3000

Witigo3000
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:09:07 AM

Posted 19 June 2007 - 04:18 PM

also if there is anything else i need to remove to make my computer run smoother and faster that would be nice too thanks

#3 jamielaw

jamielaw

    Malware Ass-Kicker!


  • Members
  • 878 posts
  • OFFLINE
  •  
  • Local time:02:07 PM

Posted 19 June 2007 - 04:59 PM

Hey Witigo3000

RogueRemover

Please download rr-free-setup.exe (by RubbeR DuckY). Save the file to your desktop.

Double-click rr-free-setup.exe. RogueRemover will now be installed - OK the installation prompts. Once it has successfully installed click Check for updates. Download & install any updates.

Click Scan. RogueRemover will now scan your computer for any rogue programs. Once it has finished click Remove Selected if it finds any. Please allow RogueRemover to submit the statistical data.


Rename Hijackthis:

1. Locate the program Hijackthis.
2. Select the file, right-click and select Rename.
3. Please change the name to: jamielaw
4. Then please could you post a new Hijackthis log.
My Website!

"The ultimate measure of a man is not where he stands in moments of comfort and convenience, but where he stands at times of challenge and controversy." - Martin Luther King, Jr.

Posted Image

#4 Witigo3000

Witigo3000
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:09:07 AM

Posted 19 June 2007 - 05:16 PM

thanks for replying. did what you said here are the log files- rogue log file first then hijackthis log

Malwarebytes' RogueRemover
Malwarebytes 2007 http://www.malwarebytes.org
5044 total fingerprints loaded.

Loading database ...
Expanding environmental variables ...

Scanning files ... [ 100% ].
Scanning folders ... [ 100% ].
Scanning registry keys ... [ 100% ].
Scanning registry values ... [ 100% ].

RogueRemover has detected rogue antispyware components! Results below...

Type: File
Vendor: WinAntiVirus 2006
Location: C:\WINDOWS\system32\stera.exe
Selected for removal: Yes

Type: File
Vendor: WinAntiVirus 2006
Location: C:\WINDOWS\system32\drivers\FOPN.sys
Selected for removal: Yes

Type: File
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\Bryan\Desktop\WinAntiSpyware 2007.lnk
Selected for removal: Yes

Type: File
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiSpyware 2007\Contact customer support.lnk
Selected for removal: Yes

Type: File
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiSpyware 2007\Uninstall WinAntiSpyware 2007.lnk
Selected for removal: Yes

Type: File
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiSpyware 2007\WinAntiSpyware 2007 on the Web.lnk
Selected for removal: Yes

Type: File
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiSpyware 2007\WinAntiSpyware 2007 Online Manual.lnk
Selected for removal: Yes

Type: File
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiSpyware 2007\WinAntiSpyware 2007.lnk
Selected for removal: Yes

Type: File
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\Bryan\Application Data\WinAntiSpyware 2007\Logs\update.log
Selected for removal: Yes

Type: Folder
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiSpyware 2007
Selected for removal: Yes

Type: Folder
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\Bryan\Application Data\WinAntiSpyware 2007
Selected for removal: Yes

Type: Folder
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\Bryan\Application Data\WinAntiSpyware 2007\Logs
Selected for removal: No

Type: Folder
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007
Selected for removal: Yes

Type: Folder
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data
Selected for removal: No

Type: Folder
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr
Selected for removal: No

Type: Folder
Vendor: WinAntiSpyware 2007
Location: C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode
Selected for removal: No

Type: Registry Key
Vendor: WinAntiSpyware 2006
Location: HKEY_CLASSES_ROOT\CLSID\{_CLSID_WAShellExecuteCheck}
Selected for removal: Yes

Type: Registry Key
Vendor: WinAntiSpyware 2006
Location: HKEY_CLASSES_ROOT\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}
Selected for removal: Yes

Type: Registry Key
Vendor: WinAntiSpyware 2006
Location: HKEY_CLASSES_ROOT\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}
Selected for removal: Yes

Type: Registry Key
Vendor: WinAntiVirus 2006
Location: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FOPN
Selected for removal: Yes

Type: Registry Key
Vendor: WinAntiSpyware 2007
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WAS7_is1
Selected for removal: Yes

Type: Registry Value
Vendor: WinAntiSpyware 2007
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|uwas7cw
Selected for removal: Yes

Type: Registry Value
Vendor: WinAntiSpyware 2007
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WinAntiSpyware 2007 Free
Selected for removal: Yes

Type: Registry Value
Vendor: ErrorProtector
Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Salestart
Selected for removal: Yes

RogueRemover has found the objects above.
-----------------------------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 6:14:39 PM, on 6/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\system32\E_S00RP1.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinKey\WinKey.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\poolsv\svhost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\RogueRemover\RogueRemover.exe
C:\Program Files\HijackThis\jamielaw.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5ADF3862-9E2E-4ad3-86F7-4510E6550CD0} - C:\WINDOWS\system32\wvdltqgc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {868865EC-0295-4C7D-B25D-9F65314145E9} - C:\WINDOWS\system32\efcaxwx.dll
O2 - BHO: (no name) - {FACE9561-4729-474B-BA11-93D1AC865EA2} - C:\WINDOWS\system32\ddcyv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [\\FAMILY\EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P33 "\\FAMILY\EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500 on Family (from BRYAN_LAPTOP)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P54 "EPSON Stylus Photo RX500 on Family (from BRYAN_LAPTOP)" /O5 "TS003" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX500 on FAMILYCOMPUTER] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P47 "Auto EPSON Stylus Photo RX500 on FAMILYCOMPUTER" /O25 "\\FAMILYCOMPUTER\EPSONSty" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [poolsv] "C:\WINDOWS\poolsv.exe"
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\bkvaoojo.dll",realset
O4 - HKCU\..\Run: [\\FAMILY\EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P33 "\\FAMILY\EPSON Stylus Photo RX500" /M "Stylus Photo RX500" /EF "HKCU"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: WinKey.lnk = C:\Program Files\WinKey\WinKey.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: PokerNow.net - {3CB10829-C0BC-468a-AE91-E88AC48CB345} - C:\Program Files\PokerNow.net\PokerNownet.exe (file missing)
O9 - Extra 'Tools' menuitem: PokerNow.net - {3CB10829-C0BC-468a-AE91-E88AC48CB345} - C:\Program Files\PokerNow.net\PokerNownet.exe (file missing)
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\poker\Poker.com\poker.exe (file missing)
O9 - Extra button: Aztec Riches Poker - {7FCF69CA-B1D5-4b13-A6B0-31020DD5A976} - C:\Program Files\aztecrichesMPP\MPPoker.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Program Files\royalvegasMPP\MPPoker.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptemplates/AktiveSekurity.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: ddcyv - C:\WINDOWS\system32\ddcyv.dll
O20 - Winlogon Notify: efcaxwx - C:\WINDOWS\SYSTEM32\efcaxwx.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe


thats it

#5 jamielaw

jamielaw

    Malware Ass-Kicker!


  • Members
  • 878 posts
  • OFFLINE
  •  
  • Local time:02:07 PM

Posted 20 June 2007 - 06:47 AM

Hey Witigo3000

ComboFix

Please download ComboFix.exe (by sUBs)

Double click ComboFix.exe & follow the prompts. When finished, it shall produce a log for you. Post that log in your next reply.

Note : Do not mouseclick ComboFix's window whilst it's running! That may cause it to stall.
My Website!

"The ultimate measure of a man is not where he stands in moments of comfort and convenience, but where he stands at times of challenge and controversy." - Martin Luther King, Jr.

Posted Image

#6 jamielaw

jamielaw

    Malware Ass-Kicker!


  • Members
  • 878 posts
  • OFFLINE
  •  
  • Local time:02:07 PM

Posted 20 June 2007 - 06:49 AM

Please could you also post a Hijackthis log after you have run ComboFix.
My Website!

"The ultimate measure of a man is not where he stands in moments of comfort and convenience, but where he stands at times of challenge and controversy." - Martin Luther King, Jr.

Posted Image

#7 Witigo3000

Witigo3000
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:09:07 AM

Posted 20 June 2007 - 04:25 PM

1st log is combofix second is hijackthis:

ComboFix 07-06-20 - D:\mozilla downloads\ComboFix.exe
"Bryan" - 2007-06-20 17:16:42 - Service Pack 2 NTFS


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\SalesMonitor
C:\Program Files\Common Files\WinAntiSpyware 2007
C:\Program Files\Common Files\WinAntiSpyware 2007\err.log
C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\Yazzle1549OinAdmin.exe
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe
C:\Program Files\poolsv
C:\Program Files\poolsv\k11u72.exe
C:\Program Files\poolsv\svhost.exe
C:\Program Files\poolsv\WinAntiSpyware2007FreeInstall.exe
C:\Program Files\poolsv\wr-1-0000077.exe
C:\Program Files\poolsv\YazzleBundle-1549.exe
C:\Program Files\svhost
C:\Program Files\svhost\wr-1-0000077.exe
C:\Program Files\WinAntiSpyware 2007
C:\Program Files\WinAntiSpyware 2007\Activate.dat
C:\Program Files\WinAntiSpyware 2007\appupdate.dat
C:\Program Files\WinAntiSpyware 2007\AsAgents.dll
C:\Program Files\WinAntiSpyware 2007\AsAgents.xml
C:\Program Files\WinAntiSpyware 2007\atl71.dll
C:\Program Files\WinAntiSpyware 2007\AutoProcess.dat
C:\Program Files\WinAntiSpyware 2007\bnlink.dat
C:\Program Files\WinAntiSpyware 2007\database\enemies.dat
C:\Program Files\WinAntiSpyware 2007\database\knownfiles.dat
C:\Program Files\WinAntiSpyware 2007\database\TEBase.dat
C:\Program Files\WinAntiSpyware 2007\database\vbpv.dat
C:\Program Files\WinAntiSpyware 2007\dbupdate.dat
C:\Program Files\WinAntiSpyware 2007\diagnosis.dat
C:\Program Files\WinAntiSpyware 2007\fopnl.dll
C:\Program Files\WinAntiSpyware 2007\InstHelp.exe
C:\Program Files\WinAntiSpyware 2007\InstUp.exe
C:\Program Files\WinAntiSpyware 2007\lapv.dat
C:\Program Files\WinAntiSpyware 2007\license.rtf
C:\Program Files\WinAntiSpyware 2007\manual.pdf
C:\Program Files\WinAntiSpyware 2007\manual.url
C:\Program Files\WinAntiSpyware 2007\mfc71.dll
C:\Program Files\WinAntiSpyware 2007\monstate.dat
C:\Program Files\WinAntiSpyware 2007\msvcp71.dll
C:\Program Files\WinAntiSpyware 2007\msvcr71.dll
C:\Program Files\WinAntiSpyware 2007\ps.dat
C:\Program Files\WinAntiSpyware 2007\pv.dat
C:\Program Files\WinAntiSpyware 2007\quaratine.dat\#post_quarantine
C:\Program Files\WinAntiSpyware 2007\readme.rtf
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\1877409be61d466617049f84\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\1877409be61d466617049f84\a070dbed3495401c40b4e5b9\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\1877409be61d466617049f84\a070dbed3495401c40b4e5b9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\1877409be61d466617049f84\a070dbed3495401c40b4e5b9\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\1877409be61d466617049f84\c6b58bbb2f904e08e1bf45a4\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\1877409be61d466617049f84\c6b58bbb2f904e08e1bf45a4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\1877409be61d466617049f84\c6b58bbb2f904e08e1bf45a4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\1877409be61d466617049f84\e114d5a2a4534445d83a2aa2\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\1877409be61d466617049f84\e114d5a2a4534445d83a2aa2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\1877409be61d466617049f84\e114d5a2a4534445d83a2aa2\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\003488b4faf24b72f8371bba\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\003488b4faf24b72f8371bba\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\003488b4faf24b72f8371bba\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\003488b4faf24b72f8371bba\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\050db4957c9e4c0e2f0731a4\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\050db4957c9e4c0e2f0731a4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\050db4957c9e4c0e2f0731a4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\0a5cd3eee8df494843febda6\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\0a5cd3eee8df494843febda6\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\0a5cd3eee8df494843febda6\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\0d9bfadf01e84273acab409e\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\0d9bfadf01e84273acab409e\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\0d9bfadf01e84273acab409e\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\0d9bfadf01e84273acab409e\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\129ad2b19510459eb12957a8\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\129ad2b19510459eb12957a8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\129ad2b19510459eb12957a8\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\18e136232c284f015ab92ca1\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\18e136232c284f015ab92ca1\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\18e136232c284f015ab92ca1\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\1aa3594545864f1b5f661f9d\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\1aa3594545864f1b5f661f9d\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\1aa3594545864f1b5f661f9d\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\1aa3594545864f1b5f661f9d\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\1fe90acd0be24f597006898e\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\1fe90acd0be24f597006898e\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\1fe90acd0be24f597006898e\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\1fe90acd0be24f597006898e\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\22aee28f40c1493bcf4e2a8f\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\22aee28f40c1493bcf4e2a8f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\22aee28f40c1493bcf4e2a8f\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\23aad9184a0e41b9c4dd00bd\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\23aad9184a0e41b9c4dd00bd\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\23aad9184a0e41b9c4dd00bd\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\27bd6f388c0048f80fc6c4b0\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\27bd6f388c0048f80fc6c4b0\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\27bd6f388c0048f80fc6c4b0\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\27bd6f388c0048f80fc6c4b0\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\29bae9016c3d45333e07c88b\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\29bae9016c3d45333e07c88b\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\29bae9016c3d45333e07c88b\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\29eaeb9f8ace471974ef2087\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\29eaeb9f8ace471974ef2087\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\29eaeb9f8ace471974ef2087\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\2b614fab723d486262fe81a8\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\2b614fab723d486262fe81a8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\2b614fab723d486262fe81a8\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\2ca415560d484be2c7f58da2\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\2ca415560d484be2c7f58da2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\2ca415560d484be2c7f58da2\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\2ca415560d484be2c7f58da2\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\31049e7b565c4360cc830ca2\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\31049e7b565c4360cc830ca2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\31049e7b565c4360cc830ca2\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\31a2acc8332141c88a1da2a7\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\31a2acc8332141c88a1da2a7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\31a2acc8332141c88a1da2a7\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\3294f1f54b75466342103bbf\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\3294f1f54b75466342103bbf\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\3294f1f54b75466342103bbf\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\354d92e92e4043d368fd6a9c\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\354d92e92e4043d368fd6a9c\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\354d92e92e4043d368fd6a9c\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\354d92e92e4043d368fd6a9c\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\358aa8b61f694cb262e3d699\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\358aa8b61f694cb262e3d699\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\358aa8b61f694cb262e3d699\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\3b3733bdbe7a45642843ffb7\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\3b3733bdbe7a45642843ffb7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\3b3733bdbe7a45642843ffb7\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\3b3733bdbe7a45642843ffb7\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\3cbe53648a7e4452ff7d0cbc\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\3cbe53648a7e4452ff7d0cbc\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\3cbe53648a7e4452ff7d0cbc\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\3cc814d385bd4be404ca7586\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\3cc814d385bd4be404ca7586\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\3cc814d385bd4be404ca7586\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\4859b120333346858f8c03a4\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\4859b120333346858f8c03a4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\4859b120333346858f8c03a4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\4c9031b622474dc88c0e6198\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\4c9031b622474dc88c0e6198\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\4c9031b622474dc88c0e6198\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\4d485641ef2246eeed9c9694\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\4d485641ef2246eeed9c9694\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\4d485641ef2246eeed9c9694\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\4fb5cc491d044a693c0a889b\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\4fb5cc491d044a693c0a889b\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\4fb5cc491d044a693c0a889b\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\4fb5cc491d044a693c0a889b\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\514d8579217d47959a3d24bf\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\514d8579217d47959a3d24bf\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\514d8579217d47959a3d24bf\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\52a3a0ba6b37414048014aa8\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\52a3a0ba6b37414048014aa8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\52a3a0ba6b37414048014aa8\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\5420083ec34845b7fe9a9cb9\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\5420083ec34845b7fe9a9cb9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\5420083ec34845b7fe9a9cb9\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\54378bcfbe5f4a124820bc93\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\54378bcfbe5f4a124820bc93\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\54378bcfbe5f4a124820bc93\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\5482cc3e48474848039384a6\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\5482cc3e48474848039384a6\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\5482cc3e48474848039384a6\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\5482cc3e48474848039384a6\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\57c8161fe52b40c4d509e99c\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\57c8161fe52b40c4d509e99c\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\57c8161fe52b40c4d509e99c\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\57c8161fe52b40c4d509e99c\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\6276d645fd3a412392b8a981\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\6276d645fd3a412392b8a981\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\6276d645fd3a412392b8a981\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\630e9608535d4a7487cde0b6\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\630e9608535d4a7487cde0b6\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\630e9608535d4a7487cde0b6\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\6eec3f4441c1431cd8afa6bd\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\6eec3f4441c1431cd8afa6bd\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\6eec3f4441c1431cd8afa6bd\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\7b02e4a1be8140a2e4d99a8f\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\7b02e4a1be8140a2e4d99a8f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\7b02e4a1be8140a2e4d99a8f\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\7b02e4a1be8140a2e4d99a8f\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\7c43eea0c90b401deadcd38a\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\7c43eea0c90b401deadcd38a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\7c43eea0c90b401deadcd38a\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\7c43eea0c90b401deadcd38a\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\874802f6541e402fa6f3e6a5\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\874802f6541e402fa6f3e6a5\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\874802f6541e402fa6f3e6a5\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\874802f6541e402fa6f3e6a5\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\895bfe028108401e41d62c85\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\895bfe028108401e41d62c85\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\895bfe028108401e41d62c85\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\8ae4dd29e5ed4d7f9d0bd9ab\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\8ae4dd29e5ed4d7f9d0bd9ab\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\8ae4dd29e5ed4d7f9d0bd9ab\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\8ae4dd29e5ed4d7f9d0bd9ab\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\920e05652bf54ddf57a35c9f\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\920e05652bf54ddf57a35c9f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\920e05652bf54ddf57a35c9f\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\920e05652bf54ddf57a35c9f\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\95e94071f9f34059db6cf89d\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\95e94071f9f34059db6cf89d\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\95e94071f9f34059db6cf89d\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\aa2e958ce7db44c6a5fe2eaf\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\aa2e958ce7db44c6a5fe2eaf\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\aa2e958ce7db44c6a5fe2eaf\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\b0493158d2ba412815b1a3aa\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\b0493158d2ba412815b1a3aa\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\b0493158d2ba412815b1a3aa\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\b403bdde025342700b3af986\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\b403bdde025342700b3af986\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\b403bdde025342700b3af986\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\b5cfecf537b54d30b2be75a6\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\b5cfecf537b54d30b2be75a6\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\b5cfecf537b54d30b2be75a6\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\bc5923f511c14d40ecb4aebc\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\bc5923f511c14d40ecb4aebc\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\bc5923f511c14d40ecb4aebc\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\c1bba2db902a47a35b59ffa6\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\c1bba2db902a47a35b59ffa6\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\c1bba2db902a47a35b59ffa6\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\c1bba2db902a47a35b59ffa6\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\c3a1e430b573411814ed8c80\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\c3a1e430b573411814ed8c80\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\c3a1e430b573411814ed8c80\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\c6b027d1c37948a4050e48b4\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\c6b027d1c37948a4050e48b4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\c6b027d1c37948a4050e48b4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\caf7e2eb1df2432b98182799\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\caf7e2eb1df2432b98182799\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\caf7e2eb1df2432b98182799\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\cd3b0fd4ba0d4a332a842f9c\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\cd3b0fd4ba0d4a332a842f9c\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\cd3b0fd4ba0d4a332a842f9c\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\cd3b0fd4ba0d4a332a842f9c\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\cdd72917b1604b505a8c39a2\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\cdd72917b1604b505a8c39a2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\cdd72917b1604b505a8c39a2\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\cdd72917b1604b505a8c39a2\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\d06e229255504c572ee3a58b\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\d06e229255504c572ee3a58b\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\d06e229255504c572ee3a58b\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\d63be79d5248457ddc3feabd\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\d63be79d5248457ddc3feabd\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\d63be79d5248457ddc3feabd\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\e29665356c9743e3cc4458b9\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\e29665356c9743e3cc4458b9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\e29665356c9743e3cc4458b9\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\e4ae8a639fe945cd18cf69bd\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\e4ae8a639fe945cd18cf69bd\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\e4ae8a639fe945cd18cf69bd\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\e649662c5d5045fe80edd5bd\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\e649662c5d5045fe80edd5bd\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\e649662c5d5045fe80edd5bd\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\e649662c5d5045fe80edd5bd\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\ea8c62fc8f4d4a21dd554594\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\ea8c62fc8f4d4a21dd554594\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\ea8c62fc8f4d4a21dd554594\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\ea8c62fc8f4d4a21dd554594\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\ef236a8d5a5645fe138962be\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\ef236a8d5a5645fe138962be\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\ef236a8d5a5645fe138962be\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\f521f7b93ba54be911dbab8d\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\f521f7b93ba54be911dbab8d\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\f521f7b93ba54be911dbab8d\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\f533dadbf37344e25ffd1fba\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\f533dadbf37344e25ffd1fba\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\f533dadbf37344e25ffd1fba\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\f7cda46009404e72fe653392\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\f7cda46009404e72fe653392\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\f7cda46009404e72fe653392\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\9969cc1a24eb424d081cccb8\f7cda46009404e72fe653392\Bryan
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\f970b17cf3fd476794c89284\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\f970b17cf3fd476794c89284\07d8fc70eb834e2bb6e47388\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\f970b17cf3fd476794c89284\07d8fc70eb834e2bb6e47388\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\f970b17cf3fd476794c89284\07d8fc70eb834e2bb6e47388\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\f970b17cf3fd476794c89284\56b565af0ff84a7f2ffde094\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\f970b17cf3fd476794c89284\56b565af0ff84a7f2ffde094\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\f970b17cf3fd476794c89284\56b565af0ff84a7f2ffde094\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\f970b17cf3fd476794c89284\5bfea1f642204474a2bfdab4\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\f970b17cf3fd476794c89284\5bfea1f642204474a2bfdab4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\f970b17cf3fd476794c89284\5bfea1f642204474a2bfdab4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\f970b17cf3fd476794c89284\f7828c223b3a4a47f0dd62ae\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\f970b17cf3fd476794c89284\f7828c223b3a4a47f0dd62ae\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\814656ed707f437323170dad\f970b17cf3fd476794c89284\f7828c223b3a4a47f0dd62ae\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\0622007b7697496ae69bc1ad\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\0622007b7697496ae69bc1ad\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\08a709a3db234b80f74dea90\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\08a709a3db234b80f74dea90\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\0917fa8ae3714149a80ed8ad\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\0917fa8ae3714149a80ed8ad\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\099909d8ce194d865192a3ba\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\099909d8ce194d865192a3ba\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\0a976215279c4ec67535f493\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\0a976215279c4ec67535f493\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\141539921a0c4faa2838df94\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\141539921a0c4faa2838df94\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\1e2cb281d179428e7644d993\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\1e2cb281d179428e7644d993\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\23ef13afe273426fe73bd0a7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\23ef13afe273426fe73bd0a7\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\286bcb0cb5824045deed40b9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\286bcb0cb5824045deed40b9\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\3ca395cefdcb4b7a0f30a2b7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\3ca395cefdcb4b7a0f30a2b7\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\435c419553794c3b60930aad\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\435c419553794c3b60930aad\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\478d5759ddc848c2d3d573b3\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\478d5759ddc848c2d3d573b3\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\47dce06bb8e848a15ecaf581\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\47dce06bb8e848a15ecaf581\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\49e0a183035c468ebd760985\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\49e0a183035c468ebd760985\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\573aa717e95a468acf1893a8\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\573aa717e95a468acf1893a8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\573aa717e95a468acf1893a8\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\5ac47053bade4abb9d46e1a1\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\5ac47053bade4abb9d46e1a1\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\5ac583ed941e4bc90fa823b0\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\5ac583ed941e4bc90fa823b0\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\5b390449e9104dabf1d421b7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\5b390449e9104dabf1d421b7\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\5bb22223d1b846d19fb9a089\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\5bb22223d1b846d19fb9a089\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\5c71d64f7f1744021345a184\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\5c71d64f7f1744021345a184\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\5e0cb3db424843d906e99fa3\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\5e0cb3db424843d906e99fa3\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\65ae79dd933c4bb4dfc6ffad\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\65ae79dd933c4bb4dfc6ffad\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\67efe5d44c244cff19444eaf\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\67efe5d44c244cff19444eaf\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\6a29445498384a0f5038799d\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\6a29445498384a0f5038799d\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\6bdbfde023f14395a100e7af\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\6bdbfde023f14395a100e7af\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\70258fcf0e1b4be182061094\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\70258fcf0e1b4be182061094\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\735c88b444f7432ac4f12db2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\735c88b444f7432ac4f12db2\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\765a80f9ecef44b2462e958f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\765a80f9ecef44b2462e958f\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\771e07368f68400c758b9280\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\771e07368f68400c758b9280\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\7989ed32aa8e4ebaf5398294\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\7989ed32aa8e4ebaf5398294\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\79fc8677e7c84a23f5a74f90\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\79fc8677e7c84a23f5a74f90\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\84f1ff99b5c744ce16542cad\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\84f1ff99b5c744ce16542cad\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\84f1ff99b5c744ce16542cad\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\9955f27cbdb2429cc2893e9a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\9955f27cbdb2429cc2893e9a\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\9e2ac2c878164caeb36bf591\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\9e2ac2c878164caeb36bf591\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\a789382fa82b4b687c0cc192\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\a789382fa82b4b687c0cc192\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\a8fcc527f8a84a40deb68cad\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\a8fcc527f8a84a40deb68cad\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\ac058692528748cec162db8f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\ac058692528748cec162db8f\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\aed6bd34c24142f985f4788a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\aed6bd34c24142f985f4788a\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\b4bd755a748341fde489b7bb\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\b4bd755a748341fde489b7bb\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\b5f4993cb0564e6323f352a8\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\b5f4993cb0564e6323f352a8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\b5f4993cb0564e6323f352a8\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\b8681746af504658ef8b50aa\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\b8681746af504658ef8b50aa\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\bfe06094342e4d491fb3c7b2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\bfe06094342e4d491fb3c7b2\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\c910c21fcccb489da0c1acb8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\c910c21fcccb489da0c1acb8\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\d08bb3232c144ca0efc99589\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\d08bb3232c144ca0efc99589\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\d765152242d7470cd5afe9b3\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\d765152242d7470cd5afe9b3\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\e8aa39faaf5e492ad6413eb0\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\e8aa39faaf5e492ad6413eb0\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\ec2e5c3d2a8d485edd591dbf\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\ec2e5c3d2a8d485edd591dbf\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\f87d0fcee0a14260e94d1297\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\f87d0fcee0a14260e94d1297\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\fe1ed3b8a3b64122d1f0d2b9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\fe1ed3b8a3b64122d1f0d2b9\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\fe8374ce76c544b97b58bdaf\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\ce0e2d41b58844199bde1893\fe8374ce76c544b97b58bdaf\#startup
C:\Program Files\WinAntiSpyware 2007\scanlog.xml
C:\Program Files\WinAntiSpyware 2007\settings.ini
C:\Program Files\WinAntiSpyware 2007\shellext.dll
C:\Program Files\WinAntiSpyware 2007\shellext.xml
C:\Program Files\WinAntiSpyware 2007\Summary.dat
C:\Program Files\WinAntiSpyware 2007\support.url
C:\Program Files\WinAntiSpyware 2007\tasks.dat
C:\Program Files\WinAntiSpyware 2007\threatnet.dat
C:\Program Files\WinAntiSpyware 2007\threatnet.ini
C:\Program Files\WinAntiSpyware 2007\unins000.dat
C:\Program Files\WinAntiSpyware 2007\unins000.exe
C:\Program Files\WinAntiSpyware 2007\uninstall.ico
C:\Program Files\WinAntiSpyware 2007\UnWizard.exe
C:\Program Files\WinAntiSpyware 2007\unwizard.xml
C:\Program Files\WinAntiSpyware 2007\up.dat
C:\Program Files\WinAntiSpyware 2007\updater.dat
C:\Program Files\WinAntiSpyware 2007\was7.exe
C:\Program Files\WinAntiSpyware 2007\WAS7.url
C:\Program Files\WinAntiSpyware 2007\WAS7.xml
C:\Temp\iee
C:\WINDOWS\hosts
C:\WINDOWS\poolsv.exe
C:\WINDOWS\retadpu77.exe
C:\WINDOWS\svhost.exe
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\msxml3a.dll
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\wanpacket.dll
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\wr.txt


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\nm
-------\NPF


((((((((((((((((((((((((( Files Created from 2007-05-20 to 2007-06-20 )))))))))))))))))))))))))))))))


2007-06-20 17:16 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-19 21:17 <DIR> d-------- C:\VundoFix Backups
2007-06-19 19:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
2007-06-19 18:50 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-06-19 18:12 <DIR> d-------- C:\Program Files\RogueRemover
2007-06-19 17:36 <DIR> d-------- C:\Program Files\Lavasoft
2007-06-19 17:36 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-06-19 04:38 <DIR> d-------- C:\DOCUME~1\Bryan\APPLIC~1\DivX
2007-06-18 22:24 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-18 21:56 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2007-06-18 21:56 18,432 --a------ C:\WINDOWS\system32\drivers\ApiMon.sys
2007-06-18 21:56 <DIR> d-------- C:\WINDOWS\system32\o09PrEz
2007-06-18 21:56 <DIR> d-------- C:\Temp
2007-06-18 21:49 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-06-18 21:49 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-06-18 21:49 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-06-18 21:49 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-06-18 21:49 116,472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-06-04 15:18 9,344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 15:17 8,320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 15:14 6,272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-31 02:45 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-05-31 02:44 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-05-31 02:44 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-05-31 02:44 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-05-31 02:44 740,442 --a------ C:\WINDOWS\system32\DivX.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-20 01:00:35 -------- d-----w C:\DOCUME~1\Bryan\APPLIC~1\Azureus
2007-06-19 22:53:21 -------- d-----w C:\Program Files\AVPersonal
2007-06-19 21:35:59 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-06-19 01:49:37 -------- d-----w C:\Program Files\DivX
2007-06-15 21:11:14 -------- d-----w C:\Program Files\mIRC
2007-06-04 05:42:34 -------- d-----w C:\Program Files\Azureus
2007-06-02 18:09:49 -------- d-----w C:\Program Files\PokerRoom.com
2007-06-02 18:09:43 -------- d-----w C:\Program Files\PokerHost
2007-06-02 18:08:54 -------- d-----w C:\Program Files\Nokia
2007-06-02 18:08:04 -------- d-----w C:\Program Files\neXBC
2007-05-28 17:49:25 -------- d-----w C:\Program Files\Wolfenstein - Enemy Territory
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-23 00:15:29 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-04-23 00:15:25 36,624 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-04-23 00:15:18 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-04-23 00:02:34 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-04-23 00:02:34 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-04-23 00:02:33 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-04-23 00:02:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-04-23 00:02:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-04-23 00:02:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-04-23 00:01:47 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-04-23 00:01:46 124,472 ----a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-13 19:19:52 7,680 ----a-w C:\WINDOWS\system32\lsdelete.exe
2005-03-10 04:37:53 104 --sh--r C:\WINDOWS\system32\7CF222693C.sys
2005-03-10 04:37:53 5,642 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-11-22 14:46]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-03-02 13:02]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
{5ED0E778-7776-46B9-BD6D-4EEBD2091D93}=C:\WINDOWS\system32\ddcyv.dll []
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll [2005-11-10 14:22]
{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}=C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll [2005-06-01 14:44]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 09:57]
"nwiz"="nwiz.exe" [2006-10-22 12:22 C:\WINDOWS\system32\nwiz.exe]
"ASUS Probe"="C:\Program Files\ASUS\Probe\AsusProb.exe" [2002-12-06 17:07]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 20:40]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2004-12-20 14:41]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2004-03-24 06:41]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 20:42]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 18:05]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 14:03]
"ViewMgr"="C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" [2004-11-11 00:15]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-05-21 19:36]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 16:24]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="" []
"\\FAMILY\EPSON Stylus Photo RX500"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.exe" [2003-06-01 16:00]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ClearRecentDocsOnExit"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4567AB12-B980-44A5-B259-9B09EBEA6331}"="C:\Program Files\WinAntiSpyware 2007\shellext.dll" []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]


**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-20 17:20:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
\\FAMILY\EPSON Stylus Photo RX500 = C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P33 "\\FAMILY\EPSON Stylus Photo RX500" /M "Stylus Photo RX500" /EF "HKCU"?y????????????h?w?????????????????????????????????????h?w????????????<???8???????????-??w???????????????w????????????)??|???????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"\\\\FAMILY\\EPSON Stylus Photo RX500"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I2K1.EXE /P33 \"\\\\FAMILY\\EPSON Stylus Photo RX500\" /M \"Stylus Photo RX500\" /EF \"HKCU\"\00y\02\00\00\00\00\00\00\12\00hw\09\13\00\00\00\00\00\01\00\00\00\00\00\00\00\13\01\00\00\13\01\00\00\00\00\12\00hw\00\00\13\01\13\01\00\00\00\00<\01\108\12\00\03\00\00\00\10\12\00-w\00\00\13\01\13\01\00\00\00\00?w\13\01\00\00\13\01\12\00)ǀ|\00\00\00\00\12"

Completion time: 2007-06-20 17:22:19 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-20 17:22

--- E O F ---

hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 5:23:33 PM, on 6/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\E_S00RP1.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinKey\WinKey.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\HijackThis\jamielaw.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5ED0E778-7776-46B9-BD6D-4EEBD2091D93} - C:\WINDOWS\system32\ddcyv.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [\\FAMILY\EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P33 "\\FAMILY\EPSON Stylus Photo RX500" /M "Stylus Photo RX500" /EF "HKCU"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: WinKey.lnk = C:\Program Files\WinKey\WinKey.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: PokerNow.net - {3CB10829-C0BC-468a-AE91-E88AC48CB345} - C:\Program Files\PokerNow.net\PokerNownet.exe (file missing)
O9 - Extra 'Tools' menuitem: PokerNow.net - {3CB10829-C0BC-468a-AE91-E88AC48CB345} - C:\Program Files\PokerNow.net\PokerNownet.exe (file missing)
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\poker\Poker.com\poker.exe (file missing)
O9 - Extra button: Aztec Riches Poker - {7FCF69CA-B1D5-4b13-A6B0-31020DD5A976} - C:\Program Files\aztecrichesMPP\MPPoker.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Program Files\royalvegasMPP\MPPoker.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptemplates/AktiveSekurity.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe

#8 jamielaw

jamielaw

    Malware Ass-Kicker!


  • Members
  • 878 posts
  • OFFLINE
  •  
  • Local time:02:07 PM

Posted 21 June 2007 - 11:46 AM

Hey Witigo3000

Uninstall List
1. Open Hijackthis and select: Open the Misc Tools section.
2. Then choose: Open Uninstall Manager and click Save List.
3. Save the list to your computer.
4. Then copy the contents of the list back to your thread.

==========

Upload Files

You have a file(s) of interest to us. It would help the detection rates of the tools we use by getting hold of samples of these infections.

1. Please download Suspicious File Packer.
2. Then restart your computer in safe mode.
3. Double-click Suspicious File Packer. Then copy and paste this list of files:

C:\WINDOWS\system32\7CF222693C.sys
C:\WINDOWS\system32\KGyGaAvL.sys


4. Then click Continue. Close the program down.
5. Restart your computer in normal mode.
6. On your desktop should be a file like this: requested-files[2007-06-20_15_36].cab.
7. Open up Submit Files!
8. Then fill in the details:

Link: http://jamielaw.ipbfree.com
File: Locate your file: requested-files[2007-06-20_15_36].cab

9. Then click Send File.

==========

Fix these Hijackthis Items

1. Open HijackThis and select the Do a system scan only option.
2. Place a check next to the following items:

O2 - BHO: (no name) - {5ED0E778-7776-46B9-BD6D-4EEBD2091D93} - C:\WINDOWS\system32\ddcyv.dll (file missing)
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [\\FAMILY\EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P33 "\\FAMILY\EPSON Stylus Photo RX500" /M "Stylus Photo RX500" /EF "HKCU"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: WinKey.lnk = C:\Program Files\WinKey\WinKey.exe
O9 - Extra button: PokerNow.net - {3CB10829-C0BC-468a-AE91-E88AC48CB345} - C:\Program Files\PokerNow.net\PokerNownet.exe (file missing)
O9 - Extra 'Tools' menuitem: PokerNow.net - {3CB10829-C0BC-468a-AE91-E88AC48CB345} - C:\Program Files\PokerNow.net\PokerNownet.exe (file missing)
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\poker\Poker.com\poker.exe (file missing)
O9 - Extra button: Aztec Riches Poker - {7FCF69CA-B1D5-4b13-A6B0-31020DD5A976} - C:\Program Files\aztecrichesMPP\MPPoker.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Program Files\royalvegasMPP\MPPoker.exe (file missing)
O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptemplates/AktiveSekurity.cab

3. Close all open browsers and windows, except HijackThis. Then select fix checked . Then close HijackThis.

==========

How is your computer running? Ignore speed issues for now - we'll deal with that later.

==========

Jamie :thumbsup:
My Website!

"The ultimate measure of a man is not where he stands in moments of comfort and convenience, but where he stands at times of challenge and controversy." - Martin Luther King, Jr.

Posted Image

#9 Witigo3000

Witigo3000
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:09:07 AM

Posted 21 June 2007 - 04:23 PM

Uninstall list:
3DMark03
ABBYY FineReader 5.0 Sprint Plus
AC3Filter (remove only)
Ad-Aware 2007
Adobe Acrobat 5.0
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player 9 ActiveX
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Stock Photos 1.0
Adobe SVG Viewer 3.0
AOL Instant Messenger
AOL Toolbar 2.0
ArcSoft Software Suite
ASUS Probe V2.22.00
AsusUpdate
Azureus
BitTornado 0.3.7
BitTorrent 3.4.2
coverXP (remove only)
DAEMON Tools
DiscWizard for Windows
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
DVD Decrypter (Remove Only)
DVD Shrink 3.2
EPSON CardMonitor
EPSON Copy Utility
EPSON Photo Print
EPSON PhotoStarter3.0
EPSON Printer Software
EPSON RX500 Reference Guide
EPSON Scan
EPSON Smart Panel
Google Earth
Half-Life® 2
HijackThis 1.99.1
InCD
InCD EasyWrite Reader
iPod for Windows 2006-03-23
iTunes
J2SE Runtime Environment 5.0 Update 1
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment Standard Edition v1.3.1_04
LimeWire PRO 4.8.1
Macromedia Shockwave Player
Microsoft Halo
Microsoft Office Professional Edition 2003
mIRC
Mozilla Firefox (1.0.6)
Mozilla Thunderbird (1.0)
MP3 Workshop 1.2
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 Parser and SDK
myTunes Redux 1.0
Nero Media Player
Nero OEM
NeroVision Express 2
Network Stumbler 0.4.0 (remove only)
NVIDIA Drivers
Outerinfo
PokerStars
PowerDVD
PowerQuest PartitionMagic 8.0
QuickTime
Realtek RTL8139/810x Fast Ethernet NIC Driver Setup
RogueRemover 1.20
ScanToWeb
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917537)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
SoundMAX
Spybot - Search & Destroy 1.4
Starcraft
Steam™
Sygate Personal Firewall
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Installer Clean Up
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
WinKey
WinMX
WinPcap 3.1 beta4
WinRAR archiver
Wolfenstein - Enemy Territory
Xfire (remove only)
xp-AntiSpy 3.93
XviD MPEG-4 Video Codec
Yahoo! Toolbar

#10 Witigo3000

Witigo3000
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:09:07 AM

Posted 21 June 2007 - 04:41 PM

computers running great need any other logs and what else do i need to fix?
also i would like to make my graphics card run to its fulll potential and run the game counter-strike better and smoother.
any other help or tweaks you can give me to make my computer run faster and smoother would be great thanks so much for the help

#11 jamielaw

jamielaw

    Malware Ass-Kicker!


  • Members
  • 878 posts
  • OFFLINE
  •  
  • Local time:02:07 PM

Posted 22 June 2007 - 11:36 AM

Hey Witigo3000

computers running great need any other logs and what else do i need to fix?
also i would like to make my graphics card run to its fulll potential and run the game counter-strike better and smoother.
any other help or tweaks you can give me to make my computer run faster and smoother would be great thanks so much for the help


I'm glad that your computer is running better :thumbsup: With speed issues theres not much I can offer....you'd need to look at the amount of RAM you have, processor speed and virtual memory available. If possible make sure you have no other programs running whilst you play the game is my only advice really.

==========

Update Java

Your version of Java is now outdated. Java vulnerabilites are commonly exploited by malware so I strongly recommend you update it.

Please download Java Runtime Environment .

Install the update and restart your computer. Then remove any older versions from Add or Remove Programs in the Control Panel.

==========

Uninstall Bad/Unnecessary Programs

1. Click Start >> Control Panel >> Add/Remove Programs
2. Select each of these programs, click Remove and follow the prompts to uninstall them:

BitTornado 0.3.7
BitTorrent 3.4.2
J2SE Runtime Environment 5.0 Update 1
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment Standard Edition v1.3.1_04
LimeWire PRO 4.8.1
Outerinfo
PokerStars
Viewpoint Manager (Remove Only)


==========

Delete Files

Please download KillBox.exe (by Option^Explicit)

Note : In the event you already have Killbox, this is a new version that I need you to download.

Double-click Killbox.exe to run it. Select Delete on Reboot, then select All Files. Then copy and paste this list of files:

C:\WINDOWS\system32\7CF222693C.sys
C:\WINDOWS\system32\KGyGaAvL.sys


Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

Note : Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!)

==========

Please post a fresh Hijackthis log

==========

Jamie :flowers:
My Website!

"The ultimate measure of a man is not where he stands in moments of comfort and convenience, but where he stands at times of challenge and controversy." - Martin Luther King, Jr.

Posted Image

#12 Witigo3000

Witigo3000
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:09:07 AM

Posted 22 June 2007 - 12:11 PM

Logfile of HijackThis v1.99.1
Scan saved at 1:10:59 PM, on 6/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\E_S00RP1.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\jamielaw.exe
C:\WINDOWS\system32\wuauclt.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\npjava131_04.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\npjava131_04.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe

#13 jamielaw

jamielaw

    Malware Ass-Kicker!


  • Members
  • 878 posts
  • OFFLINE
  •  
  • Local time:02:07 PM

Posted 22 June 2007 - 03:29 PM

Hey Witigo3000

Install Antivirus Software:

Please either download AntiVir OR Avast

Once you have downloaded the Antivirus software you would like please install it.

Tutorials: AntiVir / Avast

==========

This is my normal post for when you are clear - which you now are - or seem to be. Please advise of any problems you still have :-

Please pay particular attention to Step A & G!

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - You should disable and re-enable system restore to make sure there are no infected files found in a restore point. Sometimes viruses can hide in there and if you ever needed to restore your system you would then re-infect your self
    You can find instructions on how to enable and re enable system restore here:Windows XP System Restore Guide

    Or simply follow these instructions:
    • Click Start, run and type SYSDM.CPL
    • Select the System Restore Tab
    • Check the box to Turn off System Restore on all drives
    • Click Apply and then OK to the confirmation window
    • Then uncheck the box, click apply and then OK.

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialise and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an Anti Virus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
    Computer Safety On line - Anti-Virus
  • Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For an article on Firewalls and a listing of some available ones see the link below:
    Computer Safety On line - Software Firewalls
  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install Ad-Aware - Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here:
    Computer Safety on line - Anti-Malware
  • Install HostsMan - HostsMan will add a large list of restricted websites to your hosts file. This will prevent you from visiting some bad websites.
    Download Hostsman here!
  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Stand up and be Counted.

NOW is the time you can start to hit back at the people who infected you.
Posted Image
Please take the time to go and complain - that forum has a topic for your infection which is ................ please post as a reply, you do not need to register to do so (but you can if you wish). It will also have a list of other places you can go to to register your complaint, depending on the country you are resident in. Please read the topics and complain, it is only with such complaints to goverment or government agances that something will get done.


Happy Surfing!

Jamie
My Website!

"The ultimate measure of a man is not where he stands in moments of comfort and convenience, but where he stands at times of challenge and controversy." - Martin Luther King, Jr.

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users