Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Stubborn Buggers -- Gotta Get 'em Out Of My Pc!


  • Please log in to reply
7 replies to this topic

#1 Darren7543

Darren7543

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:22 PM

Posted 11 July 2007 - 03:46 PM

Yesterday I accidentally opened some Active X window or something that started a frenzy of warnings and error messages and popups on my PC. I've learned that all the "anti-spyware" and "protection" programs it keeps saying I need are indeed spyware, malware, trojans, virus-laden pests, etc., themselves. I've gotten through doing a HJT scan, and also a ComboFix, and am copying the resulting logs below. I have Windows XP, and also have Norton, SpyBot and AOL's Spyware Protection all on my computer as well. I hope I've put together the info and scans needed to ask for help; if not, please let me know what else I need to do to clarify.

Specifically, the popups I get are related to: Ultimate Cleaner; WinAntiVirus; and Trojan.W32.Looksky.

Here is the HJT scan results:

Logfile of HijackThis v1.99.1
Scan saved at 1:06:34 PM, on 7/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Common Files\AOL\1128383060\ee\AOLSoftware.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
C:\Program Files\Creative Home\Hallmark Card Studio 2006\Planner\PLNRnote.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
c:\program files\common files\aol\1128383060\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1128383060\ee\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: MSVPS System - {335C00B1-DB93-4EEA-8A75-C9EA3B67E895} - C:\WINDOWS\qnxplugin.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1128383060\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AntiSpywareBot] C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe -boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Event Planner Reminder.lnk = C:\Program Files\Creative Home\Hallmark Card Studio 2006\Planner\PLNRnote.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} - http://www.worldwinner.com/games/v46/scrab...rabblecubes.cab
O16 - DPF: {18C3FD15-74F6-4280-9C98-3590C966B7B8} - http://www.worldwinner.com/games/v46/skillgam/skillgam.cab
O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} - http://www.worldwinner.com/games/v48/brickout/brickout.cab
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} - http://community.webshots.com/html/atx/wsaxcontrol.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} - http://www.worldwinner.com/games/v49/luxor/luxor.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} - http://www.worldwinner.com/games/v67/swapit/swapit.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} - http://www.worldwinner.com/games/v41/hangman/hangman.cab
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} - http://www.worldwinner.com/games/v41/tilecity/tilecity.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} - http://www.worldwinner.com/games/v43/paint/paint.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe



And here is the ComboFix log:

((((((((((((((((((((((((( Files Created from 2007-06-11 to 2007-07-11 )))))))))))))))))))))))))))))))


2007-07-11 12:13 1,893,383 --a------ C:\Program Files\stinger.exe
2007-07-11 11:34 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-11 11:32 1,124,674 --a------ C:\Program Files\ComboFix.exe
2007-07-11 01:17 <DIR> d-------- C:\DOCUME~1\DARREN~1\APPLIC~1\AntiSpywareBot
2007-07-10 13:10 <DIR> d-------- C:\WINDOWS\privacy_danger
2007-07-06 01:21 <DIR> d-------- C:\Program Files\Corel
2007-07-06 01:21 <DIR> d-------- C:\Program Files\Common Files\Corel
2007-07-06 01:08 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-07-06 01:06 9,393,768 --a------ C:\Program Files\winzip111.exe
2007-07-05 15:06 <DIR> d-------- C:\Digital
2007-07-03 21:46 <DIR> d-------- C:\Program Files\FlashGet
2007-06-24 18:05 <DIR> d-------- C:\Downloads
2007-06-14 12:31 <DIR> d-------- C:\Program Files\Common Files\Nova Development
2007-06-14 12:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative Home
2007-06-14 12:30 <DIR> d-------- C:\Program Files\Creative Home


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-11 17:57:14 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-07-09 05:17:21 -------- d-----w C:\Program Files\FinePixViewer
2007-07-02 05:30:59 -------- d-----w C:\Program Files\QUICKENW
2007-06-29 04:21:00 -------- d-----w C:\Program Files\Microsoft IntelliType Pro
2007-06-13 16:38:14 -------- d-----w C:\Program Files\Napster
2007-06-10 22:01:28 -------- d-----w C:\Program Files\ItsDeductible2005
2007-06-10 21:59:41 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-10 21:59:41 -------- d-----w C:\Program Files\ComfyWare
2007-06-10 21:52:22 -------- d-----w C:\DOCUME~1\DARREN~1\APPLIC~1\Uniblue
2007-06-10 21:42:03 -------- d-----w C:\Program Files\Microsoft IntelliPoint
2007-06-10 17:05:16 -------- d-----w C:\Program Files\Uniblue
2007-06-05 05:26:56 -------- d-----w C:\Program Files\hp deskjet 960c series
2007-06-05 05:26:53 -------- d-----w C:\Program Files\Hewlett-Packard
2007-05-27 06:55:12 -------- d-----w C:\Program Files\Shockwave.com
2007-05-27 06:46:35 -------- d-----w C:\Program Files\uTorrent
2007-05-26 10:02:52 -------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-05-26 04:39:30 -------- d-----w C:\Program Files\Pure Networks
2007-05-23 19:48:48 -------- d-----w C:\Program Files\Norton Internet Security
2007-05-23 19:48:29 -------- d-----w C:\Program Files\Symantec
2007-05-23 19:48:23 48,776 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-05-23 19:48:23 115,000 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-05-23 19:08:33 -------- d-----w C:\Program Files\Norton Password Manager
2007-05-22 19:25:21 -------- d-----w C:\Program Files\Google
2007-05-22 17:44:48 -------- d-----w C:\DOCUME~1\DARREN~1\APPLIC~1\HP
2007-05-21 00:44:53 142,067 ----a-w C:\WINDOWS\hpwins05.dat
2007-05-21 00:35:07 -------- d-----w C:\Program Files\HP
2007-05-21 00:34:27 -------- d-----w C:\Program Files\Common Files\HP
2007-05-21 00:29:48 -------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2007-05-19 07:36:27 -------- d-----w C:\Program Files\Common Files\AOL
2007-05-16 15:12:02 683,520 ------w C:\WINDOWS\system32\inetcomm.dll
2007-05-08 07:51:57 16 ----a-w C:\WINDOWS\popcinfo.dat
2007-04-25 14:21:15 144,896 ------w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 05:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 05:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 05:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 05:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 05:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 05:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 05:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 05:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-17 05:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
2007-04-13 17:31:03 103,984 ----a-w C:\WINDOWS\system32\AOLDial.dll
2004-08-04 12:00:00 94,784 --sh--w C:\WINDOWS\twain.dll
2004-08-04 12:00:00 50,688 --sh--w C:\WINDOWS\twain_32.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
2006-09-06 10:09 439872 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-10-22 23:08 62080 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}]
2006-09-05 23:18 93400 -ra------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{335C00B1-DB93-4EEA-8A75-C9EA3B67E895}]
C:\WINDOWS\qnxplugin.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 --a------ C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
2007-01-20 00:55 2403392 -ra------ c:\program files\google\googletoolbar4.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
2007-06-15 01:18 325048 --a------ C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
2007-05-15 22:05 163840 --a------ C:\Program Files\FlashGet\getflash.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="Mixer.exe" [2003-03-20 14:21 C:\WINDOWS\mixer.exe]
"HostManager"="C:\Program Files\Common Files\AOL\1128383060\ee\AOLSoftware.exe" [2006-09-25 17:52]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-10-03 16:45]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-06-21 11:54]
"CXMon"="C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2000-08-14 16:48]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 14:43]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 23:32]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-11-21 10:38]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-07-07 16:14]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 16:15]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-05 19:22]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"NapsterShell"="C:\Program Files\Napster\napster.exe" [2007-01-12 20:36]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 05:50]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"AntiSpywareBot"="C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-15 01:18]
"ccleaner"="C:\Program Files\CCleaner\ccleaner.exe" [2007-05-10 04:01]
"Uniblue SpeedUpMyPC"="C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe" [2007-05-23 14:03]
"AOL Fast Start"="C:\Program Files\America Online 9.0\AOL.exe" [2005-07-11 22:17]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"=0 (0x0)
"SynchronousUserGroupPolicy"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 Pml Driver HPZ12 Net Driver HPZ12

*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST

Contents of the 'Scheduled Tasks' folder
2007-07-11 10:00:04 C:\WINDOWS\tasks\AntiSpywareBot Scheduled Scan.job
2007-07-07 03:00:00 C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Darren Oke.job
2007-07-06 06:21:00 C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
2007-05-27 06:21:40 C:\WINDOWS\tasks\Uniblue SpeedUpMyPC.job
2007-07-10 20:35:50 C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job
2007-06-25 04:49:57 C:\WINDOWS\tasks\Uniblue SpyEraser.job

**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-11 13:21:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-11 13:22:34
C:\ComboFix ... 2007-07-11 13:22
C:\ComboFix-quarantined-files.txt ... 2007-07-11 13:22
C:\ComboFix2.txt ... 2007-07-11 11:41

--- E O F ---



How's that for providing the necessary info? Please help! Thank you so much!!

Darren

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:22 PM

Posted 11 July 2007 - 04:51 PM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum Darren7543 :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

Please download the OTMoveIt by OldTimer:
http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\WINDOWS\privacy_danger

Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
Click the red Moveit! button.
Close OTMoveIt

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.
If you are asked to reboot the machine choose Yes.

--------------------------------------

Copy and paste the following bold blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: fix.reg to your desktop.
Then double click on the fix.reg file on your desktopPosted Imageand agree to merge it into the registry,then restart your pc.

REGEDIT4
[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]

--------------------------------------

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: MSVPS System - {335C00B1-DB93-4EEA-8A75-C9EA3B67E895} - C:\WINDOWS\qnxplugin.dll (file missing)
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)

Exit Hijackthis.

Start SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.
Also post a new Hijackthis log,let me know how your pc is running now.

Posted Image
Posted Image

#3 Darren7543

Darren7543
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:22 PM

Posted 12 July 2007 - 11:13 AM

Thanks, Richie, I'm so glad to have your help!

Okay, I did all the steps you listed exactly. The only problem I had was with the OTMoveIt step. After copying in the file path C:\WINDOWS\privacy_danger and pasting it to the Paste area and trying to move it, the following message appeared in the Paste area: "File/Folder C:\WINDOWS\privacy_danger not found", and an error message popped up in front that said "Cannot create file C:\_OTMoveIt\MovedFiles\07122007_010156.log". I tried it again and the same thing happened.

I hope its okay, but I proceeded with the rest of the instructions after that, and had no other problems...everything else appeared exactly as you said it would. The computer does seem to be running a little better, though the default homepage kept going to the Ultimate Cleaner webpage. However, in the SuperAntiSpyware program, I found an option to permanently change your homepage to what you want and prevent any other program to change it without asking you first, so I changed it. Since then, it still went to Ultimate Cleaner once but has gone to my correct homepage the other times.

Here is the SuperAntiSpyware Scan Log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/12/2007 at 02:24 AM

Application Version : 3.9.1008

Core Rules Database Version : 3268
Trace Rules Database Version: 1279

Scan type : Complete Scan
Total Scan Time : 00:49:27

Memory items scanned : 781
Memory threats detected : 0
Registry items scanned : 6174
Registry threats detected : 0
File items scanned : 40738
File threats detected : 428

Adware.Tracking Cookie
C:\Documents and Settings\zBackup\Cookies\zbackup@ads.adbrite[2].txt
C:\Documents and Settings\zBackup\Cookies\zbackup@atwola[1].txt
C:\Documents and Settings\zBackup\Cookies\zbackup@ads.web.aol[2].txt
C:\Documents and Settings\zBackup\Cookies\zbackup@revsci[2].txt
C:\Documents and Settings\zBackup\Cookies\zbackup@adbrite[2].txt
C:\Documents and Settings\zBackup\Cookies\zbackup@doubleclick[1].txt
C:\Documents and Settings\zBackup\Cookies\zbackup@01[1].txt
C:\Documents and Settings\zBackup\Cookies\zbackup@html[2].txt
C:\Documents and Settings\zBackup\Cookies\zbackup@atdmt[2].txt
C:\Documents and Settings\zBackup\Cookies\zbackup@mediaplex[2].txt
C:\Documents and Settings\zBackup\Cookies\zbackup@advertising[2].txt
C:\Documents and Settings\zBackup\Cookies\zbackup@mediaservices.myspace[1].txt
C:\Documents and Settings\zBackup\Cookies\zbackup@2o7[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@2o7[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@ad.yieldmanager[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@ads.pointroll[1].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@ads.web.aol[1].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@advertising[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@atdmt[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@atwola[1].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@casalemedia[1].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@doubleclick[1].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@drivecleaner[1].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@go.drivecleaner[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@go.winantispyware[1].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@go.winantivirus[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@mediaplex[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@questionmarket[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@revsci[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@stats.privacyprotector[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@stats1.reliablestats[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@trafficmp[1].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@tribalfusion[1].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@winantispyware[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@winantivirus[2].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@www.winantispyware[1].txt
C:\Documents and Settings\Darren Oke\Cookies\darren oke@zedo[2].txt
C:\Documents and Settings\Pam\Cookies\pam@2o7[1].txt
C:\Documents and Settings\Pam\Cookies\pam@ad.yieldmanager[1].txt
C:\Documents and Settings\Pam\Cookies\pam@adbureau[1].txt
C:\Documents and Settings\Pam\Cookies\pam@adinterax[1].txt
C:\Documents and Settings\Pam\Cookies\pam@adlegend[2].txt
C:\Documents and Settings\Pam\Cookies\pam@admarketplace[2].txt
C:\Documents and Settings\Pam\Cookies\pam@adopt.specificclick[2].txt
C:\Documents and Settings\Pam\Cookies\pam@adrevolver[1].txt
C:\Documents and Settings\Pam\Cookies\pam@adrevolver[3].txt
C:\Documents and Settings\Pam\Cookies\pam@ads.addesktop[2].txt
C:\Documents and Settings\Pam\Cookies\pam@ads.addynamix[2].txt
C:\Documents and Settings\Pam\Cookies\pam@ads.adsag[1].txt
C:\Documents and Settings\Pam\Cookies\pam@ads.as4x.tmcs[1].txt
C:\Documents and Settings\Pam\Cookies\pam@ads.belointeractive[2].txt
C:\Documents and Settings\Pam\Cookies\pam@ads.cnn[2].txt
C:\Documents and Settings\Pam\Cookies\pam@ads.heraldnet[1].txt
C:\Documents and Settings\Pam\Cookies\pam@ads.pointroll[2].txt
C:\Documents and Settings\Pam\Cookies\pam@ads.traderonline[2].txt
C:\Documents and Settings\Pam\Cookies\pam@ads.web.aol[2].txt
C:\Documents and Settings\Pam\Cookies\pam@adultfriendfinder[2].txt
C:\Documents and Settings\Pam\Cookies\pam@adv.webmd[1].txt
C:\Documents and Settings\Pam\Cookies\pam@advertising[1].txt
C:\Documents and Settings\Pam\Cookies\pam@anad.tacoda[1].txt
C:\Documents and Settings\Pam\Cookies\pam@anat.tacoda[2].txt
C:\Documents and Settings\Pam\Cookies\pam@apmebf[2].txt
C:\Documents and Settings\Pam\Cookies\pam@atdmt[1].txt
C:\Documents and Settings\Pam\Cookies\pam@atwola[2].txt
C:\Documents and Settings\Pam\Cookies\pam@banners.pictures.sprintpcs[2].txt
C:\Documents and Settings\Pam\Cookies\pam@belnk[1].txt
C:\Documents and Settings\Pam\Cookies\pam@bizrate[1].txt
C:\Documents and Settings\Pam\Cookies\pam@bluestreak[1].txt
C:\Documents and Settings\Pam\Cookies\pam@bookspan.122.2o7[1].txt
C:\Documents and Settings\Pam\Cookies\pam@bs.serving-sys[1].txt
C:\Documents and Settings\Pam\Cookies\pam@burstnet[2].txt
C:\Documents and Settings\Pam\Cookies\pam@casalemedia[1].txt
C:\Documents and Settings\Pam\Cookies\pam@citi.bridgetrack[1].txt
C:\Documents and Settings\Pam\Cookies\pam@cnn.122.2o7[1].txt
C:\Documents and Settings\Pam\Cookies\pam@counter.hitslink[1].txt
C:\Documents and Settings\Pam\Cookies\pam@data1.perf.overture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@data3.perf.overture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@dist.belnk[2].txt
C:\Documents and Settings\Pam\Cookies\pam@doubleclick[1].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wakiondjsfo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wakyckdjcgp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfk4ajcjsgo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfk4khajcko.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfk4kjcjwgo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfk4kncjsgp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfk4skd5odq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfkiamc5kbp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfkiklajokp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfkiqidzwdp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfkiqpdpafo.stats.esomniture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfkiuidpmkp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfkiwkczceq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfkycgd5maq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfkyuhc5gfq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfl4aoc5khp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfl4cmdjogo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfl4eic5egp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfl4giczafp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wflickczcco.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfligod5gep.stats.esomniture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wflikkajkep.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfliqocpmeo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wflokpd5cfp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfloqjdpcdq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wflowjazgbq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wflyggdzghp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfmyagajeep.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfmycncpido.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfmycpazmgp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfmygjc5cgp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wfmyuic5geo.stats.esomniture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wgk4wkazcap.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wgkicnc5ahp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wgkiokazwkq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wgkiqmd5who.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wgkowld5oco.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wgkychajidp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wgkyondjelo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wgkywlazwep.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wgkywmc5iao.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wgmycmdjmbq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wgmyokazkbo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6whkiwkazghq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6whkoupdpwap.stats.esomniture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6whlocgcjcbp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjk4akdjifq.stats.esomniture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjk4chcpaco.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjk4coc5aho.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjk4egczekp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjk4eidzifo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjk4endzogo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjk4gldjkfp.stats.esomniture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjk4kmdjoco.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjk4qidpglq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkoakajmho.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkoeodjwkq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkogldjcfo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkokgczslq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkokhdjolq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkokodzgap.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkospcjgap.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkouicpaeo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkowhczkbp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkowhd5ghp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkowhdpgcq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkowlc5sap.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkyaod5cfp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkycjazmep.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkygic5cep.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkykiajchp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkykodjagq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkyojd5kcp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkyqmd5cbo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjkyugajgdq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjl4oidzofo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjl4ojczccq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjl4qmd5ilp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjl4uldjmdo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjl4wnczklo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjliahdpgbq.stats.esomniture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjlianczwho.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjliggcpkao.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjliokdzclq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjliqhc5chp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjliqicjkfp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjliqkdjiep.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjlockajclp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjloggdpccq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjloggdpkko.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjlokgdpgdp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjlokhd5eaq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjloumczocp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjlyakdzwgo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjlyeodpebo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjlygpc5seq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjmiagd5oep.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjmicnazeeq.stats.esomniture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjmiomc5sbp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjmycncjclo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjmykmcpclq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjmyomdzsco.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjmyqkdzcfo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjmyqndzgko.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjmyshajmbp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjmywpdpsgo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjny-1icpkc.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjny-1id5wg.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjny-1ncjeb.stats.esomniture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnyaldzmko.stats.esomniture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnyaodjcdo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnychdjsbo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnycjdpcfo.stats.esomniture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnycndpcep.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnyemdjkap.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnyghczgeo.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnyghdjoeq.stats.esomniture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnyoodjmcp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnyopdjofp.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnyskdzeep.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnyugazckq.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnyunc5gko.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnyuoc5iao.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnywpczoao.stats.esomniture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@e-2dj6wjnywpdpwhq.stats.esomniture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@eb.adbureau[1].txt
C:\Documents and Settings\Pam\Cookies\pam@edge.ru4[2].txt
C:\Documents and Settings\Pam\Cookies\pam@ehg-attworldnet.hitbox[1].txt
C:\Documents and Settings\Pam\Cookies\pam@ehg-dig.hitbox[1].txt
C:\Documents and Settings\Pam\Cookies\pam@ehg-littletykes.hitbox[2].txt
C:\Documents and Settings\Pam\Cookies\pam@ehg-luggageonline.hitbox[2].txt
C:\Documents and Settings\Pam\Cookies\pam@ehg-nestlepurinapetcare.hitbox[2].txt
C:\Documents and Settings\Pam\Cookies\pam@ehg-traderpublishing.hitbox[2].txt
C:\Documents and Settings\Pam\Cookies\pam@ehg-worldvision.hitbox[1].txt
C:\Documents and Settings\Pam\Cookies\pam@fastclick[2].txt
C:\Documents and Settings\Pam\Cookies\pam@fcstats.bcentral[2].txt
C:\Documents and Settings\Pam\Cookies\pam@fin.adbureau[2].txt
C:\Documents and Settings\Pam\Cookies\pam@hitbox[2].txt
C:\Documents and Settings\Pam\Cookies\pam@icc.intellisrv[2].txt
C:\Documents and Settings\Pam\Cookies\pam@image.masterstats[1].txt
C:\Documents and Settings\Pam\Cookies\pam@indexstats[1].txt
C:\Documents and Settings\Pam\Cookies\pam@indextools[2].txt
C:\Documents and Settings\Pam\Cookies\pam@interclick[2].txt
C:\Documents and Settings\Pam\Cookies\pam@kaboose.112.2o7[1].txt
C:\Documents and Settings\Pam\Cookies\pam@keywordmax[1].txt
C:\Documents and Settings\Pam\Cookies\pam@marthastewart.122.2o7[1].txt
C:\Documents and Settings\Pam\Cookies\pam@media.fastclick[2].txt
C:\Documents and Settings\Pam\Cookies\pam@mediaplex[2].txt
C:\Documents and Settings\Pam\Cookies\pam@microsoftwga.112.2o7[1].txt
C:\Documents and Settings\Pam\Cookies\pam@msnportal.112.2o7[1].txt
C:\Documents and Settings\Pam\Cookies\pam@nextag[1].txt
C:\Documents and Settings\Pam\Cookies\pam@overture[2].txt
C:\Documents and Settings\Pam\Cookies\pam@pageconcepts.112.2o7[1].txt
C:\Documents and Settings\Pam\Cookies\pam@partner2profit[2].txt
C:\Documents and Settings\Pam\Cookies\pam@paypal.112.2o7[1].txt
C:\Documents and Settings\Pam\Cookies\pam@perf.overture[1].txt
C:\Documents and Settings\Pam\Cookies\pam@pt.crossmediaservices[1].txt
C:\Documents and Settings\Pam\Cookies\pam@questionmarket[1].txt
C:\Documents and Settings\Pam\Cookies\pam@radxcore.xlayoutsx[1].txt
C:\Documents and Settings\Pam\Cookies\pam@realmedia[1].txt
C:\Documents and Settings\Pam\Cookies\pam@revsci[1].txt
C:\Documents and Settings\Pam\Cookies\pam@roiservice[2].txt
C:\Documents and Settings\Pam\Cookies\pam@rotator.adjuggler[2].txt
C:\Documents and Settings\Pam\Cookies\pam@rotator.dex.adjuggler[1].txt
C:\Documents and Settings\Pam\Cookies\pam@s.clickability[2].txt
C:\Documents and Settings\Pam\Cookies\pam@sales.liveperson[1].txt
C:\Documents and Settings\Pam\Cookies\pam@server.iad.liveperson[1].txt
C:\Documents and Settings\Pam\Cookies\pam@serving-sys[2].txt
C:\Documents and Settings\Pam\Cookies\pam@specificclick[2].txt
C:\Documents and Settings\Pam\Cookies\pam@stat.onestat[2].txt
C:\Documents and Settings\Pam\Cookies\pam@statcounter[1].txt
C:\Documents and Settings\Pam\Cookies\pam@statse.webtrendslive[1].txt
C:\Documents and Settings\Pam\Cookies\pam@tacoda[2].txt
C:\Documents and Settings\Pam\Cookies\pam@thunderbolt.adjuggler[2].txt
C:\Documents and Settings\Pam\Cookies\pam@tradedoubler[1].txt
C:\Documents and Settings\Pam\Cookies\pam@trafficmp[2].txt
C:\Documents and Settings\Pam\Cookies\pam@tribalfusion[2].txt
C:\Documents and Settings\Pam\Cookies\pam@tripod[1].txt
C:\Documents and Settings\Pam\Cookies\pam@usatoday1.112.2o7[1].txt
C:\Documents and Settings\Pam\Cookies\pam@webstat.yamaha[2].txt
C:\Documents and Settings\Pam\Cookies\pam@www.burstbeacon[1].txt
C:\Documents and Settings\Pam\Cookies\pam@www.burstnet[1].txt
C:\Documents and Settings\Pam\Cookies\pam@www.clickmanage[2].txt
C:\Documents and Settings\Pam\Cookies\pam@www.nextag[1].txt
C:\Documents and Settings\Pam\Cookies\pam@z1.adserver[1].txt
C:\Documents and Settings\Pam\Cookies\pam@zedo[2].txt
C:\Documents and Settings\zBackup\Cookies\zbackup@ad.yieldmanager[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@2o7[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@ad.yieldmanager[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@adbrite[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@adinterax[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@adopt.euroclick[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@adopt.specificclick[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@adrevolver[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@adrevolver[3].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@ads.adbrite[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@ads.as4x.tmcs[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@ads.pointroll[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@ads.web.aol[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@adserving.cpxinteractive[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@advertising[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@anad.tacoda[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@apmebf[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@atdmt[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@atwola[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@bs.serving-sys[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@casalemedia[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@doubleclick[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@ehg-wyndhamvacationownership.hitbox[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@fastclick[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@go.winantispyware[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@hitbox[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@mediaplex[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@microsoftwlmessengermkt.112.2o7[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@nextag[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@questionmarket[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@realmedia[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@revsci[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@server.iad.liveperson[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@serving-sys[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@sex[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@sixapart.adbureau[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@snapfish.112.2o7[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@specificclick[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@statcounter[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@stats1.reliablestats[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@statse.webtrendslive[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@tacoda[2].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@tradedoubler[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@trafficmp[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@tribalfusion[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@winantispyware[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@winantivirus[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@www.premiumsexsites[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@www.winantispyware[1].txt
C:\Documents and Settings\zBackup\Local Settings\Temp\Cookies\zbackup@zedo[2].txt

Desktop Hijacker.AboutYourPrivacy
C:\QOOBOX\QUARANTINE\C\WINDOWS\MSDDX.DLL.VIR

Trojan.Net-MSV/VPS
C:\QOOBOX\QUARANTINE\C\WINDOWS\QNXPLUGIN.DLL.VIR

Trace.Known Threat Sources
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\8NTFI6JL\main_top2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\K1QVGHYN\download[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\K1QVGHYN\home[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\0HY7WTA7\ind_img5[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\YD2FQN4B\css[1].css
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\K1QVGHYN\spacer[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\2PPQBU5W\shadow_con_right[1].png
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\17FNPTO6\shadow_con_right[1].png
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\2PPQBU5W\ind_img3[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\0HY7WTA7\shadow_cut1[1].png
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\SPMNK1IN\cut2_4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\OXSLS56T\orng_cut4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\SPMNK1IN\con4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\YD2FQN4B\load_img1[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\K1QVGHYN\cut3_4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\OBGN4BML\load_txt2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\17FNPTO6\cut4_4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\OBGN4BML\ind_box[1].jpg
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\K1QVGHYN\cut4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\8NTFI6JL\ind_txt[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\2PPQBU5W\ind_tbl_bord[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\SPMNK1IN\cut1_4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\OBGN4BML\orng_cut3[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\SPMNK1IN\ind_txt_bg[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONMDS3UL\03[1].swf
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\8NTFI6JL\box_cut3[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\YD2FQN4B\download_bttn[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\8NTFI6JL\cut2_2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\OXSLS56T\box_bttm_bord[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\SPMNK1IN\shadow_right[1].png
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\C9QBC92J\cut1[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONMDS3UL\shadow_bottom3[1].png
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONMDS3UL\favicon[5].ico
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\YD2FQN4B\ind_img1[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONMDS3UL\load_bttn[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\SPMNK1IN\bg_tbl[1].jpg
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\0HY7WTA7\main[1].htm
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\SPMNK1IN\buy_n[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\YD2FQN4B\load_flash_bg[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\2PPQBU5W\shadow_left2[1].png
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONMDS3UL\cut3_2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\8NTFI6JL\cut1_2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\0HY7WTA7\cut3[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\K1QVGHYN\support[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\2PPQBU5W\main_top[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\17FNPTO6\shadow_cut3[1].png
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONMDS3UL\orng_cut1[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\YD2FQN4B\shadow_cut4[1].png
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\0HY7WTA7\cut2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\17FNPTO6\ind_img4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\OXSLS56T\bord_bttm[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\OXSLS56T\02[1].swf
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\OXSLS56T\con2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONMDS3UL\spacer[5].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\OXSLS56T\css_land[1].css
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\0HY7WTA7\shadow_bottom[1].png
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONMDS3UL\con3[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\K1QVGHYN\shadow_con_left[1].png
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\SPMNK1IN\logo[1].jpg
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\2PPQBU5W\shadow_bottom[1].png
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\K1QVGHYN\ind_box1[1].jpg
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\8NTFI6JL\box_cut4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\SPMNK1IN\home_s[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\C9QBC92J\down_n[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\8NTFI6JL\load_pointer[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\OBGN4BML\WinAntiVirusPro2007FreeInstall[1].exe
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\SPMNK1IN\spacer[3].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\YD2FQN4B\orng_cut2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\C9QBC92J\bord_lr2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\ONMDS3UL\shadow_left[1].png
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\YD2FQN4B\load_txt3[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\K1QVGHYN\styles[2].css
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\17FNPTO6\load_bg[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\YD2FQN4B\con1[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temp\Temporary Internet Files\Content.IE5\8NTFI6JL\load_txt[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\9VNX7XZ4\home_s[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\6LMBW9YF\down_n[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\GVRSGL02\shadow_con_right[1].png
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\9VNX7XZ4\cut2_4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\NBXNN1SO\load_txt[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\43U5STW6\main_top2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\6LMBW9YF\cut1_4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\J6JBF5JY\cut2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\I5BO5KRE\cut2_2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\F5NBIS10\cut1[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\6LMBW9YF\shadow_bottom[1].png
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\GRPRMUNT\bord_bttm[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\I70N70TC\spacer[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\2KWX6KLZ\load_bg[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\I70N70TC\load_pointer[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\I70N70TC\bord_lr2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\GRPRMUNT\con4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\9VNX7XZ4\load_img1[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\EOQTVTCG\load_txt3[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\F5NBIS10\cut3[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\2VU7AP63\03[1].swf
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\7A7LP1F3\con2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\43U5STW6\main_top[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\7A7LP1F3\main[1].htm
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\WRFP94XL\con3[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\GVRSGL02\buy_n[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\3TVZY4T0\load_flash_bg[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\NBXNN1SO\load_txt2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\H3PJ1UB5\cut4_4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\I5BO5KRE\cut1_2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\NBXNN1SO\con1[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\2VU7AP63\load_bttn[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\5U8IF9TS\cut3_4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\2VU7AP63\cut4[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\9VNX7XZ4\cut3_2[1].gif
C:\Documents and Settings\zBackup\Local Settings\Temporary Internet Files\Content.IE5\EOQTVTCG\shadow_con_left[1].png







and here is the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 9:00:27 AM, on 7/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\Program Files\Common Files\AOL\1128383060\ee\AOLSoftware.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\WINDOWS\system32\MDM.EXE
C:\Program Files\Creative Home\Hallmark Card Studio 2006\Planner\PLNRnote.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
c:\program files\common files\aol\1128383060\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1128383060\ee\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1128383060\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AntiSpywareBot] C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe -boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Event Planner Reminder.lnk = C:\Program Files\Creative Home\Hallmark Card Studio 2006\Planner\PLNRnote.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} - http://www.worldwinner.com/games/v46/scrab...rabblecubes.cab
O16 - DPF: {18C3FD15-74F6-4280-9C98-3590C966B7B8} - http://www.worldwinner.com/games/v46/skillgam/skillgam.cab
O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} - http://www.worldwinner.com/games/v48/brickout/brickout.cab
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} - http://community.webshots.com/html/atx/wsaxcontrol.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} - http://www.worldwinner.com/games/v49/luxor/luxor.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} - http://www.worldwinner.com/games/v67/swapit/swapit.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} - http://www.worldwinner.com/games/v41/hangman/hangman.cab
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} - http://www.worldwinner.com/games/v41/tilecity/tilecity.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} - http://www.worldwinner.com/games/v43/paint/paint.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe



What should I do next? Thanks again!

Darren

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:22 PM

Posted 21 July 2007 - 07:19 AM

Sorry for the late response Darren,i somehow missed your reply :thumbsup:
If you still require help then post a fresh Hijackthis log please.
Let me know how your pc is running now.
Posted Image
Posted Image

#5 Darren7543

Darren7543
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:22 PM

Posted 22 July 2007 - 04:42 PM

Okay, below is another HJT log for the scan I just ran. My computer doesn't seem to have the Ultimate Cleaner virus going on much now, though it still runs pretty slow and I probably need to look into the forums on how to speed things up. The main lingering problem from the virus attacks a couple weeks ago, though, is a strange issue with my Desktop background. Whenever I reboot or login to one of our IDs, instead of the design or picture I've chosen and set as a default, it instead makes the entire screen white, with a blue box behind each of the program icons...similar to what it looks like when your mouse has highlighted them but not clicked on them yet. (I feel like if I clicked at that point, every program would try to open up at the same time, so I haven't clicked!) I have to go redo my Desktop background each time. I'm also just a little worried that all latent issues haven't been resolved and perhaps just haven't reared their ugly heads yet, since I only got the one set of instructions from you and ran them through, and haven't had any follow-up steps since then.

So, here's the log, and I look forward to your next recommendations! Thanks!

Darren


Logfile of HijackThis v1.99.1
Scan saved at 2:33:59 PM, on 7/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\Program Files\Common Files\AOL\1128383060\ee\AOLSoftware.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\WINDOWS\system32\MDM.EXE
c:\program files\common files\aol\1128383060\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1128383060\ee\aolsoftware.exe
C:\Program Files\Creative Home\Hallmark Card Studio 2006\Planner\PLNRnote.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1128383060\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AntiSpywareBot] C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe -boot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Event Planner Reminder.lnk = C:\Program Files\Creative Home\Hallmark Card Studio 2006\Planner\PLNRnote.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} - http://www.worldwinner.com/games/v46/scrab...rabblecubes.cab
O16 - DPF: {18C3FD15-74F6-4280-9C98-3590C966B7B8} - http://www.worldwinner.com/games/v46/skillgam/skillgam.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/share...GamesLoader.cab
O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} - http://www.worldwinner.com/games/v48/brickout/brickout.cab
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} - http://community.webshots.com/html/atx/wsaxcontrol.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinner.com/games/v49/luxor/luxor.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} - http://www.worldwinner.com/games/v67/swapit/swapit.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} - http://www.worldwinner.com/games/v41/hangman/hangman.cab
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} - http://www.worldwinner.com/games/v41/tilecity/tilecity.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinner.com/games/v43/paint/paint.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:22 PM

Posted 22 July 2007 - 07:05 PM

Download SDFix.exe and save it to your desktop:
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

* Double click on SDFix on your desktop,and install the fix to C:\

Please then reboot your computer into Safe Mode by doing the following:

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.

* In Safe Mode,go to and open the C:\SDFix folder,then double click on RunThis.bat to start the script.
* Type Y to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt into your next reply.

----------------------------------------------------------------------

Download SmitfraudFix (by S!Ri), to your desktop.
Double click on Smitfraudfix.cmd
Select option 1 Search, by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy and paste the content of that report into your next reply.

*IMPORTANT*
Do NOT run any other options until you are asked to do so!
Posted Image
Posted Image

#7 Darren7543

Darren7543
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:22 PM

Posted 22 July 2007 - 11:38 PM

I hope I don't sound like an idiot, but I have a little glitch. I downloaded the SDFix program and installed it to C:, but when I restarted my computer and hit F8 after the beep, the menu with the options I want did show up.....however, my keyboard refused to work at all at that point. Pressing the arrows didn't scroll up or down, and hitting Enter did nothing -- no keys, not even several Ctrl-Alt-Del attempts had any affect at all -- it was as if the keyboard was not even attached. I pressed the reset button on the CPU and tried it again three more times. I even changed the keyboard's batteries just in case, and pushed the button to connect its wireless signal to the infrared port again, but still it did nothing, so I don't know how to proceed with this step!

Is there some reason with this F8 startup DOS menu that this should happen? Is there a way for me to proceed without going into Safe Mode? Help! Thanks!

Darren

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:22 PM

Posted 23 July 2007 - 04:09 AM

You need to be able to boot into Safe Mode, Darren,lets try the following:

If you have the Microsoft Windows XP installation disk.
Click Start>Run,type sfc /scannow then press Ok.
Leave a space in between sfc and /scannow
Reboot when you've done.

If still no joy try a Repair Install.
Configure your computer to start from the CD-ROM drive.
[Boot into the Bios and set your CD-Rom drive as first boot device].
For more information about how to do this,refer to your computer's documentation or contact your computer manufacturer.
Then insert your Microsoft Windows XP Setup CD,and restart your computer.
When the 'Press any key to boot from CD' message is displayed on screen, press a key.
Press ENTER when you see the message to setup Windows XP now, and then press ENTER displayed on the 'Welcome to Setup' screen.
Do not choose the option to press R to use the Recovery Console.
In the Windows XP Licensing Agreement, press F8 to agree to the license agreement.
Make sure that your current installation of Windows XP is selected in the box, and then press R to repair Windows XP.
Follow the instructions on the screen to complete Setup.

If the issue persists,start a new topic in the link below.
Windows XP Home and Professional:
http://www.bleepingcomputer.com/forums/f/56/windows-xp-home-and-professional/

If you manage to get the issue resolved,return to this topic and carry on with my last instructions please Darren.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users