Author Topic: Please Help! Spyware/Virus Infection  (Read 1777 times)

Offline warriorsd

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
Please Help! Spyware/Virus Infection
« on: January 21, 2009, 03:28:31 PM »
Hi Guys

I have recently been infected with some nasty stuff that stops me from downloading updated virus defination files as well as when browsing the internet redirects my browser to adultmatchmaker sites. Also when trying to play a video from youtube I get a msg that says that my system is attacking them with Troj/Rustok-N. I have tried to manually remove this as there are some instructions on the net but have failed to do so as the files that Im ment to be removing are none existaned on my drive. I have Windows Defender, Avast and Ad-Aware AE but still seem to have problems. Below is my hijackthis log. Please help!


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:20:04 AM, on 22/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Microsoft Time Zone\TimeZone.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\HalReader\HalReader.exe
D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: PaltalkWebLogin - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: scriptproxy - {6D0386B3-FD72-488E-9740-90355AE21735} - C:\WINDOWS\system32\diga32.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [Timezone] "C:\Program Files\Microsoft Time Zone\TimeZone.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Ultra Hal Text-to-Speech Reader Startup.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZUxdm486YYAU
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - D:\FlashCapture\fciext.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w...ntrol_en_US.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...etup1.0.1.1.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www4.snapfish.com.au/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.Email Removed.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 12394 bytes

Offline warriorsd

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
Please Help! Spyware/Virus Infection
« Reply #1 on: January 21, 2009, 03:54:29 PM »
I just thought I'll add one more thing. Whenever I'm using IE to browse websites and click onto a link IE opens up a new window now rather then opening the link in the already open window. Not sure if this info is any usefull but just thought i'd add it. Thx

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please Help! Spyware/Virus Infection
« Reply #2 on: January 21, 2009, 04:18:10 PM »
Download [color=\"#FF0000\"]> ATF Cleaner <[/color] by Atribune and save it to your Desktop.

Double Click on ATF-Cleaner.exe to Run it
Check the boxes to the left of:

Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
*Prefetch (Windows XP) only.
Java Cache

The rest are optional - if you want to remove the lot, check "Select All".
Finally click Empty Selected. When you get the "Done Cleaning" message, click OK.
If you use Firefox browser
      Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit from the Main menu

download Malwarebytes' Anti-Malware from Here or Here
Save the installer to desktop

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to [color=\"#006400\"]Update Malwarebytes' Anti-Malware[/color] and [color=\"#006400\"]Launch Malwarebytes' Anti-Malware[/color], then click Finish.
       
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
       
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
       
  • Make sure that everything is checked, and click Remove Selected.
        * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
       
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

With that log from MBAM

Download [color=\"blue\"]random's system information tool (RSIT)[/color] by [color=\"#6600cc\"]random/random[/color] from >>[color=\"red\"]here[/color]<< and save it to your desktop.
  • Double click on RSIT.exe to launch program.
  • Click Continue at the disclaimer screen.
  • Your firewall may alert you that RSIT is requesting Internet access. Please allow it.
  • Once it has finished, two logs will open:  log.txt[color=\"red\"]<-- this will be maximized[/color] and info.txt[color=\"red\"]<-- this will be minimized[/color].
Post both those logs please
NOTE: You may get an error message posting back log.txt
If you do, can you upload it, if you need instructions to upload, let me know

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline warriorsd

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
Please Help! Spyware/Virus Infection
« Reply #3 on: January 22, 2009, 02:45:01 AM »
Hi guestolo

 

Thanks for your help so far! Please find latest logs below.

 

 

Malwarebytes' Anti-Malware 1.33
Database version: 1675
Windows 5.1.2600 Service Pack 3

22/01/2009 6:37:52 PM
mbam-log-2009-01-22 (18-37-52).txt

Scan type: Quick Scan
Objects scanned: 58133
Time elapsed: 4 minute(s), 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 27
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6d0386b3-fd72-488e-9740-90355ae21735} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d0386b3-fd72-488e-9740-90355ae21735} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d0386b3-fd72-488e-9740-90355ae21735} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\SYSTEM32\gaopdxixfkgerc.dll (Trojan.DNSChanger) -> Quarantined and deleted successfully.






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:44:25 PM, on 22/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Microsoft Time Zone\TimeZone.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\HalReader\HalReader.exe
D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\3 Mobile\3 Mobile Broadband\3 Mobile Broadband.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: PaltalkWebLogin - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Timezone] "C:\Program Files\Microsoft Time Zone\TimeZone.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Ultra Hal Text-to-Speech Reader Startup.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - D:\FlashCapture\fciext.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w...ntrol_en_US.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www4.snapfish.com.au/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.Email Removed.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{86F288A6-0FB3-4F82-B407-44AF60354279}: NameServer = 202.124.68.130 202.124.76.98
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 12278 bytes

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please Help! Spyware/Virus Infection
« Reply #4 on: January 23, 2009, 09:17:11 AM »
Are you still being redirected?
Can you please run rsit.exe and post it's logs I asked for earlier

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline warriorsd

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
Please Help! Spyware/Virus Infection
« Reply #5 on: January 23, 2009, 04:56:10 PM »
Hi guestolo sorry I overlooked the request to run rsit.exe
I'm still suffering from the same problem -(
Please find the 2 rsit logs below:



info.txt logfile of random's system information tool 1.05 2009-01-24 08:53:37

======Uninstall list======

-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\InstallShield Installation Information\{36C41D70-56F5-4E2B-81DA-6BEB7502D7A1}\setup.exe -runfromtemp -l0x0009 -removeonly
-->C:\Program Files\InstallShield Installation Information\{B2C4A8C4-AA20-425D-9FEE-C78039238C81}\setup.exe -runfromtemp -l0x0009 -removeonly
-->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
-->C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
3 Mobile Broadband-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3EAAC5FD-E209-4856-8C49-D4EA40F85032}\setup.exe" -l0x9  -removeonly
Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
Adobe Bridge 1.0-->MsiExec.exe /I{AE3D38A6-13B1-40B3-9423-D1FA9982FB6A}
Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5102}
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Help Center 2.0-->MsiExec.exe /I{8FFC924C-ED06-44CB-8867-3CA778ECE903}
Adobe Premiere Pro 2.0-->msiexec /I {FA17A726-B229-4116-B793-A2AB1A4EAE2E}
Adobe Reader 7.1.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002}
Adobe Reader for Pocket PC 2.0-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{291A772C-FFB9-4681-B720-AB2A0A620896}
Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-1437-443D-B06E-79A00FE45110}
ALPS Touch Pad Driver-->C:\Program Files\Apoint\Uninstap.exe ADDREMOVE
Apple Mobile Device Support-->MsiExec.exe /I{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ATI Control Panel-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
Bridge Building Game-->D:\Bridge Building Game\uninstall.exe
Broadcom Management Programs 2-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{64A77F14-0E08-4A97-A859-E93CFF428756} /l1033
Canon Utilities EOS Utility-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "D:\Canon\EOS Utility\Uninst.ini"
Canon Utilities PhotoStitch-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "D:\Canon\PhotoStitch\Uninst.ini"
CinemaForge-->C:\WINDOWS\system32\xmirage.exe d\CinemaForge\UninstallCF.xmfg
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Conexant D110 MDC V.9x Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_8086&DEV_24x6&SUBSYS_542214F1\HXFSETUP.EXE -U -Idel5422k.inf
Dell Media Experience Update-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CDE4CC8B-134B-421E-943C-90799E56F664}\setup.exe" -l0x9 -L0x9 /SMAINT
Dell Media Experience-->MsiExec.exe /I{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}
Dell Photo Printer 720-->C:\WINDOWS\system32\spool\drivers\w32x86\3\DLBCUN5C.EXE -dDell Photo Printer 720
Digital Line Detect-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
DivX Converter-->C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
DivX Converter-->C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
eBay Toolbar-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DB5FD00-BB93-4AF3-B925-77DAA0E4E2F4}\setup.exe" -l0x9
FLV Player 2.0, build 24-->D:\FLV Player\uninst.exe
FreeStar Free iPod Video Converter 3.0.6-->C:\Program Files\ivc\uninst.exe
Godtube Video Downloader 3.00-->"D:\Godtube Video Downloader\unins000.exe"
GVC 2008.5-->D:\GVC\uninst.exe
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotspot Shield 1.05-->C:\Program Files\Hotspot Shield\Uninstall.exe
HP Photo & Imaging 3.1-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP PSC & OfficeJet 3.0-->"C:\Program Files\HP\Digital Imaging\{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}\setup\hpzscr01.exe" -datfile hposcr03.dat
HP Software Update-->MsiExec.exe /X{CC0A24CB-87C9-4F1C-A1F2-F87D8D4DDCAF}
HyperCam 2-->D:\HyCam2\UnHyCam2.exe
Intel® PROSet/Wireless Software-->C:\WINDOWS\Installer\iProInst.exe
Internal Network Card Power Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F528948-0E80-4C96-B455-DE4167CB1DF7}\setup.exe" -l0x9 UNINSTALL APPDRVNT4
iTunes-->MsiExec.exe /I{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}
Jasc Paint Shop Photo Album-->MsiExec.exe /I{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}
Jasc Paint Shop Pro 8 Dell Edition-->MsiExec.exe /I{81A34902-9D0B-4920-A25C-4CDC5D14B328}
Java(tm) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Lizardtech DjVu Control (autoinstall)-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\DjVuLite.us.inf,DefaultUninstall,5
Macromedia Shockwave Player-->C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\Install.log
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee SecurityCenter-->c:\PROGRA~1\mcafee.com\shared\mcappins.exe /v=3 /uninstall=1 /appid=msc /interact=1 /script_proactive=0 /start=c:\PROGRA~1\mcafee.com\agent\uninst\screm.ui::uninstall.htm
mCore-->MsiExec.exe /I{6DE14BE4-6F04-4935-8ABD-A0A19FE2E55A}
mDrWiFi-->MsiExec.exe /I{F6090A17-0967-4A8A-B3C3-422A1B514D49}
Memories Disc Creator 2.0-->MsiExec.exe /X{2E132061-C78A-48D4-A899-1D13B9D189FA}
mHlpDell-->MsiExec.exe /I{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft ActiveSync 4.0-->MsiExec.exe /I{B208806F-A231-4FA0-AB3F-5C1B8979223E}
Microsoft Age of Empires II-->"C:\Program Files\Microsoft Games\Age of Empires II\UNINSTAL.EXE" /runtemp /uninstall
Microsoft Base Smart Card Cryptographic Service Provider Package-->"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft OpenType Font Properties Extension (Remove Only)-->RunDll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\system32\ShellExt\TTFExt.inf, UninstallNT
Microsoft Text-to-Speech Engine 4.0 (English)-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msTTSa22.inf, Uninstall
Microsoft Time Zone-->MsiExec.exe /I{03F7DFF0-A406-4F1A-9E37-F75E6D614ABC}
Microsoft User-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Works 7.0-->MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}
mIRC-->"C:\Program Files\mIRC\mirc.exe" -uninstall
mIWA-->MsiExec.exe /I{3E9D596A-61D4-4239-BD19-2DB984D2A16F}
mIWCA-->MsiExec.exe /I{6FFFE74E-3FBD-4E2E-97F9-5E9A2A077626}
mLogView-->MsiExec.exe /I{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}
mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
Modem Helper-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
mPfWiz-->MsiExec.exe /I{90B0D222-8C21-4B35-9262-53B042F18AF9}
mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
mSSO-->MsiExec.exe /I{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
mToolkit-->MsiExec.exe /I{CA9BAADB-C262-4E05-B2E2-CEE8CE9809EC}
mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
mXML-->MsiExec.exe /I{9CC89556-3578-48DD-8408-04E66EBEF401}
My Pictures 3D 1.1-->"D:\My Pictures 3D ScreenSaver\unins000.exe"
mZConfig-->MsiExec.exe /I{94658027-9F16-4509-BBD7-A59FE57C3023}
NetWaiting-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
Nokia Connectivity Cable Driver-->MsiExec.exe /X{3BFFC6B8-4EC0-4240-858C-998FD4077983}
Nokia PC Suite-->MsiExec.exe /I{02091327-B124-4216-9D71-58C0E24F5392}
Paltalk Messenger-->C:\WINDOWS\iun6002.exe "C:\Program Files\Paltalk Messenger\irunin.ini"
PaltalkScene-->"C:\WINDOWS\Paltalk Messenger\uninstall.exe" "/U:C:\Program Files\Paltalk Messenger\irunin.xml"
PC Connectivity Solution-->MsiExec.exe /I{04F3BF74-9E34-4D3E-93C3-D3D1F24199C8}
Plato Video Converter 4.16-->"D:\Plato Video Converter\unins000.exe"
PowerDVD 5.3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe"  -uninstall
PowerQuest PartitionMagic 8.0-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}
Privacy Guardian 4.0-->"C:\Program Files\Privacy Guardian\unins000.exe"
QuickSet-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C5074CC4-0E26-4716-A307-960272A90040}\setup.exe" -l0x9 UNINSTALL APPDRVNT4 - ALL
QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Security Update for Step By Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Encoder (KB954156)-->"C:\WINDOWS\$NtUninstallKB954156_WM9L$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Sonic DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
Sonic MyDVD-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
Sonic Update Manager-->MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
Sony Picture Utility-->C:\Program Files\InstallShield Installation Information\{D5068583-D569-468B-9755-5FBF5848F46F}\setup.exe -runfromtemp -l0x0009 uninstall -removeonly
Ulead COOL 3D 3.5 Trial-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BA1BE991-D723-41BE-AD16-42EAFDA794EA}\Setup.exe"
Ultra Hal Text-to-Speech Reader-->MsiExec.exe /X{96EF451E-A402-44D8-BAEE-D70D558A4122}
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Videora iPod Converter 3.04-->D:\Red Kawa\Video Converter 3\uninstaller.exe
Viewpoint Media Player (Remove Only)-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe -u
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
Vuze-->D:\Vuze\uninstall.exe
Windows Defender-->MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}
Windows Driver Package - Nokia (WUDFRd) WPD  (11/03/2006 6.82.26.2)-->C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccswpddri_6B630EE2E66584353C6CD8683D447072872F34D8\pccswpddriver.inf
Windows Driver Package - Nokia Modem  (11/03/2006 6.82.0.1)-->C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_4EFFAAE27A08EDFDE145390033D8EF099DA65567\nokbtmdm.inf
Windows Live Messenger-->MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
Windows Media Encoder 9 Series-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Encoder 9 Series-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 10 Hotfix - KB894476-->"C:\WINDOWS\$NtUninstallKB894476$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG

=====HijackThis Backups=====

F3 - REG:win.ini: load=C:\WINDOWS\svchost.exe

======Security center information======

AV: avast! antivirus 4.8.1296 [VPS 090123-0]

System event log

Computer Name: D1JD5F1S
Event Code: 6005
Message: The Event log service was started.

Record Number: 138143
Source Name: EventLog
Time Written: 20081228232511.000000+660
Event Type: information
User:

Computer Name: D1JD5F1S
Event Code: 6009
Message: Microsoft ® Windows ® 5.01. 2600 Service Pack 3 Uniprocessor Free.

Record Number: 138142
Source Name: EventLog
Time Written: 20081228232511.000000+660
Event Type: information
User:

Computer Name: D1JD5F1S
Event Code: 6006
Message: The Event log service was stopped.

Record Number: 138141
Source Name: EventLog
Time Written: 20081228232401.000000+660
Event Type: information
User:

Computer Name: D1JD5F1S
Event Code: 20159
Message: The connection to HUAWEI3G.3 Mobile Broadband made by user  using device COM10 was disconnected.

Record Number: 138140
Source Name: RemoteAccess
Time Written: 20081228232344.000000+660
Event Type: information
User:

Computer Name: D1JD5F1S
Event Code: 7036
Message: The Pml Driver HPZ12 service entered the stopped state.

Record Number: 138139
Source Name: Service Control Manager
Time Written: 20081228232340.000000+660
Event Type: information
User:

Application event log

Computer Name: D1JD5F1S
Event Code: 0
Message:
Record Number: 15687
Source Name: EvtEng
Time Written: 20080614091716.000000+600
Event Type: information
User:

Computer Name: D1JD5F1S
Event Code: 1001
Message: Fault bucket 796227241.

Record Number: 15686
Source Name: Application Error
Time Written: 20080613191559.000000+600
Event Type: error
User:

Computer Name: D1JD5F1S
Event Code: 1000
Message: Faulting application iexplore.exe, version 7.0.6000.16674, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x00018fea.

Record Number: 15685
Source Name: Application Error
Time Written: 20080613191554.000000+600
Event Type: error
User:

Computer Name: D1JD5F1S
Event Code: 101
Message: msnmsgr (4068) The database engine stopped.

Record Number: 15684
Source Name: ESENT
Time Written: 20080613191512.000000+600
Event Type: information
User:

Computer Name: D1JD5F1S
Event Code: 103
Message: msnmsgr (4068) \\.\C:\Documents and Settings\Basti\Local Settings\Application Data\Microsoft\Messenger\worriorsdEmail Removed\SharingMetadata\Working\database_10FC_1BD6_FC1B_B4C6\dfsr.db: The database engine stopped the instance (0).

Record Number: 15683
Source Name: ESENT
Time Written: 20080613191512.000000+600
Event Type: information
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\PROGRA~1\COMMON~1\SONICS~1\;C:\Program Files\Common Files\Sonic Shared;D:\Ulead DVD MovieFactory 3.5 Suite;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\Common Files\Adobe\AGL;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 13 Stepping 8, GenuineIntel
"PROCESSOR_REVISION"=0d08
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip

-----------------EOF-----------------





Logfile of random's system information tool 1.05 (written by random/random)
Run by Basti at 2009-01-24 08:53:26
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 2 GB (6%) free of 35 GB
Total RAM: 1023 MB (42% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:53:32 AM, on 24/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Microsoft Time Zone\TimeZone.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\HalReader\HalReader.exe
D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\3 Mobile\3 Mobile Broadband\3 Mobile Broadband.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Basti\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Basti.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: PaltalkWebLogin - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [Timezone] "C:\Program Files\Microsoft Time Zone\TimeZone.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Ultra Hal Text-to-Speech Reader Startup.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - D:\FlashCapture\fciext.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w...ntrol_en_US.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www4.snapfish.com.au/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.Email Removed.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{86F288A6-0FB3-4F82-B407-44AF60354279}: NameServer = 202.124.68.130 202.124.76.98
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 12125 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1128157255.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22D8E815-4A5E-4DFB-845E-AAB64207F5BD}]
eBay Toolbar Helper - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll [2009-01-18 525552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{502C3BA4-2C3E-4317-BC29-C0445E82B1F9}]
PaltalkWebLogin - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll [2006-01-27 102400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
DriveLetterAccess - C:\WINDOWS\System32\DLA\DLASHX_W.DLL [2006-06-13 110652]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{92085AD4-F48A-450D-BD93-B28CC7DF67CE} - eBay Toolbar - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll [2009-01-18 525552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"=C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2004-10-30 385024]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2004-12-04 344064]
"Dell QuickSet"=C:\Program Files\Dell\QuickSet\quickset.exe [2005-02-07 606208]
"DMXLauncher"=C:\Program Files\Dell\Media Experience\DMXLauncher.exe [2004-09-15 86016]
"DXDllRegExe"=dxdllreg.exe []
"eBayToolbar"=C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe [2009-01-18 632048]
"EZSleepAutoStart"= []
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe [2007-09-25 132496]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2006-09-29 185784]
"MCUpdateExe"=C:\PROGRA~1\mcafee.com\agent\mcupdate.exe [2005-07-08 212992]
"DLA"=C:\WINDOWS\System32\DLA\DLACTRLW.EXE [2006-06-13 127036]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-11-27 81000]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-03 866584]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-01-19 506712]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Timezone"=C:\Program Files\Microsoft Time Zone\TimeZone.exe [2004-10-19 712704]
"msnmsgr"=C:\Program Files\MSN Messenger\msnmsgr.exe [2007-01-19 5674352]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2005-04-22 1196032]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Messenger (Yahoo!)"=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2008-05-27 4269296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\Apoint\Apoint.exe [2004-09-13 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
D:\DAEMON Tools\daemon.exe [2007-04-04 165784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe [2004-10-12 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [2003-06-26 212992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd.exe [2003-06-25 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraAssistant]
C:\Program Files\Logitech\Video\CameraAssistant.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideo[inspector]]
C:\Program Files\Logitech\Video\InstallHelper.exe /inspect []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
c:\PROGRA~1\mcafee.com\agent\McAgent.exe [2005-07-01 303104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
c:\PROGRA~1\mcafee.com\agent\mcupdate.exe [2005-07-08 212992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe]
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPSExe]
c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKAGENTEXE]
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe [2007-01-19 5674352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
C:\Program Files\McAfee.com\VSO\oasclnt.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe [2006-11-28 222720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe [2006-09-29 214448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2006-09-29 185784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe [2004-01-07 110592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
C:\Program Files\McAfee.com\VSO\mcvsshld.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipDiscount]
C:\Program Files\VoipDiscount.com\VoipDiscount\VoipDiscount.exe -nosplash -minimized []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe /checktask []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [2008-04-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GetRight - Tray Icon.lnk]
C:\PROGRA~1\GetRight\getright.exe [2005-02-23 2301952]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
C:\PROGRA~1\Kodak\KODAKE~1\bin\EASYSH~1.EXE -h []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
C:\PROGRA~1\Kodak\KODAKS~1\7288971\Program\BACKWE~1.EXE  []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^palstart.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\palstart.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalStart.lnk]
C:\PROGRA~1\PALTAL~1\palstart.exe [2006-10-26 30720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
C:\PROGRA~1\PALTAL~1\paltalk.exe [2008-11-15 11376640]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Unwired Launchpad.lnk]
C:\PROGRA~1\Unwired\UwSCT.exe  []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
C:\PROGRA~1\WinZip\WZQKPICK.EXE [2004-12-17 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Basti^Start Menu^Programs^Startup^Unwired Launchpad.lnk]
C:\PROGRA~1\Unwired\UwSCT.exe  []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MskService"=2
"mcupdmgr.exe"=2
"McTskshd.exe"=2

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Ultra Hal Text-to-Speech Reader Startup.lnk - C:\WINDOWS\Installer\{96EF451E-A402-44D8-BAEE-D70D558A4122}\New_Shortcut_S1449_0EB7CDB78E0C4A918D2CA535D5B8160C.exe

C:\Documents and Settings\Basti\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Picture Motion Browser Media Check Tool.lnk - D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2004-12-04 90112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll [2004-09-07 110592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=36
"NoDriveAutoRun"=FFFFFFFF

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:*:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Paltalk Messenger\paltalk.exe"="C:\Program Files\Paltalk Messenger\paltalk.exe:*:Enabled:Paltalk Messenger 8.2"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"D:\Vuze\Azureus.exe"="D:\Vuze\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Wi

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please Help! Spyware/Virus Infection
« Reply #6 on: January 24, 2009, 01:51:45 PM »
Temporarily disable your Anti-Virus software
Right click on the Avast icon by the clock and "Stop On access protections"

Then, Download the latest version of [color=\"blue\"]Kaspersky Virus Removal Tool[/color][/b].
Ensure to download the setup with the latest modified date
  • Close all other applications and double-click and run the installer.
  • When AVPTool starts, select all the scanable items except for CD-ROM drives and click the Scan button.
  • If malware is detected, place a checkmark in the Apply to all box, and click the Delete button (or Disinfect if the button is active).
  • After the scan finishes, if any threat remains in the Scan window (Red exclamation point), click the Neutralize all button
  • In the window that opens, place a checkmark in the Apply to all box, and click the Delete button (or Disinfect if the button is active).
  • If advised that a special disinfection procedure is required which demands system reboot: click the Ok button to close the window.
  • In the Scan window click the Reports button and select Save to file.
  • Name the report AVPT.txt, and save it to the Desktop.
  • Close AVPTool.
  • You will be prompted if you want to uninstall the program; click Yes.
  • You will then be prompted that to complete the uninstallation, the computer must be restarted. Select Yes to restart the system.
  • Post the report you saved in your next reply.

Continue to keep me updated how things are running please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline warriorsd

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
Please Help! Spyware/Virus Infection
« Reply #7 on: January 25, 2009, 06:46:40 AM »
Hi guestolo
I tried to download the latest version of [color=\"blue\"]Kaspersky Virus Removal Tool[/color][/b] using the link you provided but always got the following error msg:

"Connection Interrupted  
The document contains no data.
The network link was interrupted while negotiating a connection. Please try again"

I ended up downloading it from Download.com not without problems tho... When installing the software it had alot of problems making a conection to download the latest updates. Anyway i ended up running a scan which took 4.5 hours to complete but it did find a few things. See log below:



Protection : running
--------------------
Total scanned:    277136
Detected:    13
Untreated:    0
Start time:    25/01/2009 5:59:32 PM
Duration:    04:31:37


Detected
--------
Status    Object
------    ------
deleted: malware Exploit.Java.ByteVerify    File: C:\Documents and Settings\Basti\.housecall\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/BlackBox.class
deleted: malware Exploit.Java.ByteVerify    File: C:\Documents and Settings\Basti\.housecall\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/VerifierBug.class
deleted: Trojan program Trojan-Downloader.Java.OpenConnection.aa    File: C:\Documents and Settings\Basti\.housecall\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/Beyond.class
deleted: malware Exploit.Java.ByteVerify    File: C:\Documents and Settings\Basti\.housecall6.6\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/BlackBox.class
deleted: malware Exploit.Java.ByteVerify    File: C:\Documents and Settings\Basti\.housecall6.6\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/VerifierBug.class
deleted: Trojan program Trojan-Downloader.Java.OpenConnection.aa    File: C:\Documents and Settings\Basti\.housecall6.6\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/Beyond.class
deleted: Trojan program Trojan.Java.ClassLoader.ao    File: C:\Documents and Settings\Basti\.housecall6.6\Quarantine\crtdcghcn.jar-9f9b6ca-5e0b5e6e.zip.bac_a04088//CryptFF.b/BaaaaBaa.class
deleted: Trojan program Trojan.Java.ClassLoader.ao    File: C:\Documents and Settings\Basti\.housecall6.6\Quarantine\crtdcghcn.jar-9f9b6ca-5e0b5e6e.zip.bac_a04088//CryptFF.b/VaaaaaaaBaa.class
deleted: Trojan program Trojan.Java.ClassLoader.ao    File: C:\Documents and Settings\Basti\.housecall6.6\Quarantine\crtdcghcn.jar-9f9b6ca-5e0b5e6e.zip.bac_a04088//CryptFF.b/Baaaaa.class
deleted: virus Heur.Invader (modification)    File: C:\WINDOWS\catchme.exe//PE_Patch.UPX
will be deleted when the computer is restarted: new threat Hidden.Object (modification)    File: C:\WINDOWS\SYSTEM32\gaopdxixfkgerc.dll
will be deleted when the computer is restarted: new threat Hidden.Object (modification)    File: C:\WINDOWS\SYSTEM32\DRIVERS\gaopdxvoqylbet.sys
deleted: Trojan program Trojan-Downloader.Java.OpenConnection.aa    File: C:\Documents and Settings\Basti\.housecall6.6\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b


Events
------
Time    Event
----    -----
25/01/2009 4:58:42 PM    You are advised to perform a full computer scan as soon as possible.
25/01/2009 4:58:42 PM    Database is out of date, leaving your computer at risk of infection. Please update your database.
25/01/2009 4:58:42 PM    Protection of your computer is enabled.
25/01/2009 4:59:38 PM    Process  (PID 516) tried to access Kaspersky Anti-Virus process (PID 2568), but the action has been blocked by the Self-Defense component. No action on your part is required.
25/01/2009 4:59:38 PM    Process  (PID 516) tried to access Kaspersky Anti-Virus process (PID 3636), but the action has been blocked by the Self-Defense component. No action on your part is required.
25/01/2009 4:59:44 PM    Process  (PID 1500) tried to access Kaspersky Anti-Virus process (PID 2568), but the action has been blocked by the Self-Defense component. No action on your part is required.
25/01/2009 4:59:44 PM    Process  (PID 1500) tried to access Kaspersky Anti-Virus process (PID 3636), but the action has been blocked by the Self-Defense component. No action on your part is required.
25/01/2009 5:02:06 PM    Process  (PID 1500) tried to access Kaspersky Anti-Virus process (PID 3912), but the action has been blocked by the Self-Defense component. No action on your part is required.
25/01/2009 5:02:38 PM    Process  (PID 1196) tried to access Kaspersky Anti-Virus process (PID 2568), but the action has been blocked by the Self-Defense component. No action on your part is required.
25/01/2009 5:17:24 PM    File C:\Documents and Settings\Basti\.housecall\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/BlackBox.class: detected: malware 'Exploit.Java.ByteVerify'.
25/01/2009 5:17:24 PM    Security threats have been detected. You are advised to neutralize them immediately.
25/01/2009 5:17:24 PM    File C:\Documents and Settings\Basti\.housecall\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/BlackBox.class: is still infected, postponed.
25/01/2009 5:17:24 PM    File C:\Documents and Settings\Basti\.housecall\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/VerifierBug.class: detected: malware 'Exploit.Java.ByteVerify'.
25/01/2009 5:17:24 PM    File C:\Documents and Settings\Basti\.housecall\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/Beyond.class: detected: Trojan program 'Trojan-Downloader.Java.OpenConnection.aa'.
25/01/2009 5:17:31 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/BlackBox.class: detected: malware 'Exploit.Java.ByteVerify'.
25/01/2009 5:17:31 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/BlackBox.class: is still infected, postponed.
25/01/2009 5:17:31 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/VerifierBug.class: detected: malware 'Exploit.Java.ByteVerify'.
25/01/2009 5:17:31 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/Beyond.class: detected: Trojan program 'Trojan-Downloader.Java.OpenConnection.aa'.
25/01/2009 5:17:31 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\crtdcghcn.jar-9f9b6ca-5e0b5e6e.zip.bac_a04088//CryptFF.b/BaaaaBaa.class: detected: Trojan program 'Trojan.Java.ClassLoader.ao'.
25/01/2009 5:17:31 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\crtdcghcn.jar-9f9b6ca-5e0b5e6e.zip.bac_a04088//CryptFF.b/BaaaaBaa.class: is still infected, postponed.
25/01/2009 5:17:31 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\crtdcghcn.jar-9f9b6ca-5e0b5e6e.zip.bac_a04088//CryptFF.b/VaaaaaaaBaa.class: detected: Trojan program 'Trojan.Java.ClassLoader.ao'.
25/01/2009 5:17:31 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\crtdcghcn.jar-9f9b6ca-5e0b5e6e.zip.bac_a04088//CryptFF.b/Baaaaa.class: detected: Trojan program 'Trojan.Java.ClassLoader.ao'.
25/01/2009 5:17:51 PM    Update error: Connection terminated.
25/01/2009 5:17:51 PM    Database is out of date, leaving your computer at risk of infection. Please update your database.
25/01/2009 5:19:40 PM    Process  (PID 1500) tried to access Kaspersky Anti-Virus process (PID 3616), but the action has been blocked by the Self-Defense component. No action on your part is required.
25/01/2009 5:59:32 PM    You are advised to perform a full computer scan as soon as possible.
25/01/2009 5:59:32 PM    Security threats have been detected. You are advised to neutralize them immediately.
25/01/2009 5:59:32 PM    Database is out of date, leaving your computer at risk of infection. Please update your database.
25/01/2009 5:59:33 PM    Protection of your computer is enabled.
25/01/2009 6:00:44 PM    Process  (PID 1488) tried to access Kaspersky Anti-Virus process (PID 3280), but the action has been blocked by the Self-Defense component. No action on your part is required.
25/01/2009 6:00:44 PM    Process  (PID 1488) tried to access Kaspersky Anti-Virus process (PID 1328), but the action has been blocked by the Self-Defense component. No action on your part is required.
25/01/2009 6:17:46 PM    File C:\Documents and Settings\Basti\.housecall\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/BlackBox.class: detected: malware 'Exploit.Java.ByteVerify'.
25/01/2009 6:17:46 PM    File C:\Documents and Settings\Basti\.housecall\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/BlackBox.class: is still infected, postponed.
25/01/2009 6:17:46 PM    File C:\Documents and Settings\Basti\.housecall\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/VerifierBug.class: detected: malware 'Exploit.Java.ByteVerify'.
25/01/2009 6:17:46 PM    File C:\Documents and Settings\Basti\.housecall\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/Beyond.class: detected: Trojan program 'Trojan-Downloader.Java.OpenConnection.aa'.
25/01/2009 6:17:52 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/BlackBox.class: detected: malware 'Exploit.Java.ByteVerify'.
25/01/2009 6:17:52 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/BlackBox.class: is still infected, postponed.
25/01/2009 6:17:52 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/VerifierBug.class: detected: malware 'Exploit.Java.ByteVerify'.
25/01/2009 6:17:52 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/Beyond.class: detected: Trojan program 'Trojan-Downloader.Java.OpenConnection.aa'.
25/01/2009 6:17:52 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\crtdcghcn.jar-9f9b6ca-5e0b5e6e.zip.bac_a04088//CryptFF.b/BaaaaBaa.class: detected: Trojan program 'Trojan.Java.ClassLoader.ao'.
25/01/2009 6:17:52 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\crtdcghcn.jar-9f9b6ca-5e0b5e6e.zip.bac_a04088//CryptFF.b/BaaaaBaa.class: is still infected, postponed.
25/01/2009 6:17:52 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\crtdcghcn.jar-9f9b6ca-5e0b5e6e.zip.bac_a04088//CryptFF.b/VaaaaaaaBaa.class: detected: Trojan program 'Trojan.Java.ClassLoader.ao'.
25/01/2009 6:17:52 PM    File C:\Documents and Settings\Basti\.housecall6.6\Quarantine\crtdcghcn.jar-9f9b6ca-5e0b5e6e.zip.bac_a04088//CryptFF.b/Baaaaa.class: detected: Trojan program 'Trojan.Java.ClassLoader.ao'.
25/01/2009 7:23:06 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/agentins.ini: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/agntcons.vbs: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/agntinst.htm: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/agntinst.vbs: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/agntlang.vbs: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/default.htm: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/header.vbs: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/HtmlUtil.vbs: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/images/bg_left_1x314.gif: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/images/bg_left_MSC_165x314.gif: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/images/icon_info_16x16.gif: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/images/icon_mcafee_61x61.gif: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/images/icon_progress_checked_13x13.gif: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/images/icon_progress_hot_13x13.gif: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/images/icon_progress_unchecked_13x13.gif: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/InstUtil.vbs: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/instwiz.css: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/instxp.css: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/mcccom.lpk: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/pbar.vbs: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/setcss.vbs: is password protected.
25/01/2009 7:23:07 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0006.BIN/SubInfoData.vbs: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/appcons.vbs: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/appinst.htm: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/appinst.vbs: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/applang.vbs: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/default.htm: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/header.vbs: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/images/bg_left_165x314.gif: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/images/bg_left_1x314.gif: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/images/icon_info_16x16.gif: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/images/icon_mcafee_61x61.gif: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/images/icon_progress_checked_13x13.gif: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/images/icon_progress_hot_13x13.gif: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/images/icon_progress_unchecked_13x13.gif: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/instwiz.css: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/instxp.css: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/mcccom.lpk: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/mpfins.ini: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/pbar.vbs: is password protected.
25/01/2009 7:23:08 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0017.BIN/setcss.vbs: is password protected.
25/01/2009 7:23:15 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0024.BIN/screm.ui/agntcons.vbs: is password protected.
25/01/2009 7:23:15 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0024.BIN/screm.ui/agntlang.vbs: is password protected.
25/01/2009 7:23:15 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0024.BIN/screm.ui/comctl.lpk: is password protected.
25/01/2009 7:23:15 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0024.BIN/screm.ui/config.ini: is password protected.
25/01/2009 7:23:15 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0024.BIN/screm.ui/pbar.vbs: is password protected.
25/01/2009 7:23:15 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0024.BIN/screm.ui/UnInsStr.vbs: is password protected.
25/01/2009 7:23:15 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0024.BIN/screm.ui/uninst.vbs: is password protected.
25/01/2009 7:23:15 PM    File C:\Program Files\McAfee.com\Agent\mpfpinst.exe//WISE0024.BIN/screm.ui/uninstall.htm: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/agentins.ini: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/agntcons.vbs: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/agntinst.htm: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/agntinst.vbs: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/agntlang.vbs: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/default.htm: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/header.vbs: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/HtmlUtil.vbs: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/images/bg_left_1x314.gif: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/images/icon_info_16x16.gif: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/images/icon_mcafee_61x61.gif: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/images/icon_progress_checked_13x13.gif: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/images/icon_progress_hot_13x13.gif: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/images/icon_progress_unchecked_13x13.gif: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/images/vssver.scc: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/InstUtil.vbs: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/instwiz.css: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/instxp.css: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/mcccom.lpk: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/pbar.vbs: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/setcss.vbs: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0006.BIN/vssver.scc: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/appcons.vbs: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/appinst.htm: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/appinst.vbs: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/applang.vbs: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/default.htm: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/header.vbs: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/images/bg_left_1x314.gif: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/images/icon_info_16x16.gif: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/images/icon_mcafee_61x61.gif: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/images/icon_progress_checked_13x13.gif: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/images/icon_progress_hot_13x13.gif: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/images/icon_progress_unchecked_13x13.gif: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/instwiz.css: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/instxp.css: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/mcccom.lpk: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/mpsins.ini: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/pbar.vbs: is password protected.
25/01/2009 7:23:17 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0018.BIN/setcss.vbs: is password protected.
25/01/2009 7:23:18 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0022.BIN/mpsrem.ui/comctl.lpk: is password protected.
25/01/2009 7:23:18 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0022.BIN/mpsrem.ui/config.ini: is password protected.
25/01/2009 7:23:18 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0022.BIN/mpsrem.ui/pbar.vbs: is password protected.
25/01/2009 7:23:18 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0022.BIN/mpsrem.ui/uninstall.htm: is password protected.
25/01/2009 7:23:19 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0023.BIN/RemoveMPS.exe//WISE0005.BIN/comctl.lpk: is password protected.
25/01/2009 7:23:19 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0023.BIN/RemoveMPS.exe//WISE0005.BIN/config.ini: is password protected.
25/01/2009 7:23:19 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0023.BIN/RemoveMPS.exe//WISE0005.BIN/uninstall.htm: is password protected.
25/01/2009 7:23:21 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0026.BIN/screm.ui/agntcons.vbs: is password protected.
25/01/2009 7:23:21 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0026.BIN/screm.ui/agntlang.vbs: is password protected.
25/01/2009 7:23:21 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0026.BIN/screm.ui/comctl.lpk: is password protected.
25/01/2009 7:23:21 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0026.BIN/screm.ui/config.ini: is password protected.
25/01/2009 7:23:21 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0026.BIN/screm.ui/pbar.vbs: is password protected.
25/01/2009 7:23:21 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0026.BIN/screm.ui/UnInsStr.vbs: is password protected.
25/01/2009 7:23:21 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0026.BIN/screm.ui/uninst.vbs: is password protected.
25/01/2009 7:23:21 PM    File C:\Program Files\McAfee.com\Agent\mpsinst.exe//WISE0026.BIN/screm.ui/uninstall.htm: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/appcons.vbs: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/appinst.vbs: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/apputil.vbs: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/default.htm: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/header.vbs: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/images/bg_left_MSK_165x314.gif: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/images/icon_info_16x16.gif: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/images/icon_progress_checked_13x13.gif: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/images/icon_progress_hot_13x13.gif: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/images/icon_progress_unchecked_13x13.gif: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/images/vssver.scc: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/install.htm: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/instwiz.css: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/instxp.css: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/lang_app.vbs: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/mcccom.lpk: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/mskins.ini: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/pbar.vbs: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/setcss.vbs: is password protected.
25/01/2009 7:23:23 PM    File C:\Program Files\McAfee.com\Agent\mskinst.exe//WISE0017.BIN/vssver.scc: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/countries.js: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/default.htm: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/header.vbs: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/HtmlUtil.vbs: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/images/bg_left_VS_165x314.gif: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/images/icon_info_16x16.gif: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/images/icon_progress_checked_13x13.gif: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/images/icon_progress_hot_13x13.gif: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/images/icon_progress_unchecked_13x13.gif: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/install.htm: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/instwiz.css: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/instxp.css: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/lang_countries.vbs: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/lang_vso.vbs: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/mcccom.lpk: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/pbar.vbs: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/setcss.vbs: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/VsoConst.vbs: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/vsoins.ini: is password protected.
25/01/2009 7:23:30 PM    File C:\Program Files\McAfee.com\Agent\vsoinst.exe//WISE0023.BIN/VSOPropConst.vbs: is password protected.
25/01/2009 7:23:38 PM    File C:\Program Files\McAfee.com\Agent\Uninst\screm.ui/agntcons.vbs: is password protected.
25/01/2009 7:23:38 PM    File C:\Program Files\McAfee.com\Agent\Uninst\screm.ui/agntlang.vbs: is password protected.
25/01/2009 7:23:39 PM    File C:\Program Files\McAfee.com\Agent\Uninst\screm.ui/comctl.lpk: is password protected.
25/01/2009 7:23:39 PM    File C:\Program Files\McAfee.com\Agent\Uninst\screm.ui/config.ini: is password protected.
25/01/2009 7:23:39 PM    File C:\Program Files\McAfee.com\Agent\Uninst\screm.ui/pbar.vbs: is password protected.
25/01/2009 7:23:39 PM    File C:\Program Files\McAfee.com\Agent\Uninst\screm.ui/UnInsStr.vbs: is password protected.
25/01/2009 7:23:39 PM    File C:\Program Files\McAfee.com\Agent\Uninst\screm.ui/uninst.vbs: is password protected.
25/01/2009 7:23:39 PM    File C:\Program Files\McAfee.com\Agent\Uninst\screm.ui/uninstall.htm: is password protected.
25/01/2009 7:34:19 PM    File C:\WINDOWS\catchme.exe//PE_Patch.UPX: detected modification of virus 'Heur.Invader'.
25/01/2009 7:55:34 PM    File C:\WINDOWS\SYSTEM32\gaopdxixfkgerc.dll: detected modification of new threat 'Hidden.Object'.
25/01/2009 7:55:34 PM    File C:\WINDOWS\SYSTEM32\gaopdxixfkgerc.dll: is still infected, postponed.
25/01/2009 7:56:44 PM    File C:\WINDOWS\SYSTEM32\DRIVERS\gaopdxvoqylbet.sys: detected modification of new threat 'Hidden.Object'.
25/01/2009 7:56:44 PM    File C:\WINDOWS\SYSTEM32\DRIVERS\gaopdxvoqylbet.sys: is still infected, postponed.
25/01/2009 8:02:13 PM    File c:\documents and settings\basti\.housecall\quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/BlackBox.class: detected: malware 'Exploit.Java.ByteVerify'.
25/01/2009 10:27:40 PM    Process  (PID 1740) tried to access Kaspersky Anti-Virus process (PID 1328), but the action has been blocked by the Self-Defense component. No action on your part is required.
25/01/2009 10:27:49 PM    File c:\documents and settings\basti\.housecall\quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768//CryptFF.b/BlackBox.class: is still infected, skipped by user.


Reports
-------
Component    Status    Start    Finish    Size
---------    ------    -----    ------    ----
Proactive Defense    running    25/01/2009 5:59:32 PM        0 bytes
File Anti-Virus    running    25/01/2009 5:59:32 PM        146.5 KB
Mail Anti-Virus    running    25/01/2009 5:59:32 PM        0 bytes
Web Anti-Virus    running    25/01/2009 5:59:32 PM        95.9 KB
Scan startup objects    completed    25/01/2009 6:01:45 PM    25/01/2009 6:03:57 PM    600.6 KB
Scan    completed    25/01/2009 6:05:11 PM    25/01/2009 10:27:48 PM    54.4 MB
Update    running    25/01/2009 10:26:44 PM        18.4 KB


Quarantine
----------
Status    Object    Size    Added
------    ------    ----    -----


Backup
------
Status    Object    Size
------    ------    ----
Infected: Trojan program Trojan.Java.ClassLoader.ao    c:\documents and settings\basti\.housecall6.6\quarantine\crtdcghcn.jar-9f9b6ca-5e0b5e6e.zip.bac_a04088    31.6 KB
Infected: Trojan program Trojan-Downloader.Java.OpenConnection.aa    c:\documents and settings\basti\.housecall6.6\quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768    27.7 KB
Possibly infected: new threat Hidden.Object (modification)    C:\WINDOWS\SYSTEM32\DRIVERS\gaopdxvoqylbet.sys    69.5 KB
Possibly infected: new threat Hidden.Object (modification)    C:\WINDOWS\SYSTEM32\gaopdxixfkgerc.dll    55.5 KB
Possibly infected: virus Heur.Invader (modification)    c:\windows\catchme.exe    132 KB
Infected: malware Exploit.Java.ByteVerify    c:\documents and settings\basti\.housecall\quarantine\count.jar-3d3316dc-25e30f93.zip.bac_a00768    27.7 KB


Im still getting the following error msg when trying to play a video online:


Your computer  (IP: xxx.xxx.x.xxx)  generates an attacking DOS requests at our servers. This attack was provoked by the  spyware/virus named 'Troj/Rustok-N

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please Help! Spyware/Virus Infection
« Reply #8 on: January 25, 2009, 11:00:42 AM »
Download ComboFix from one of these locations:

[color=\"#0000FF\"]Link 1[/color]
[color=\"#0000FF\"]Link 2[/color]
[color=\"#0000FF\"]Link 3[/color]
[color=\"#FF0000\"]Save it ONLY to your Desktop[/color]

      --------------------------------------------------------------------
[color=\"#2E8B57\"]Temporarily Disable your AntiVirus, AntiSpyware and Firewall applications, usually via a right click on the System Tray icon. They may otherwise interfere with this tool[/color]

  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


[color=\"#2e8b57\"]**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[/color]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply

NOTE: Do not mouseclick inside ComboFix window as it's running, it may cause it to stall
ComboFix will run again on startup, it will prompt that it's creating a log
This process could take up to 10 minutes, let it run uninterrupted please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline warriorsd

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
Please Help! Spyware/Virus Infection
« Reply #9 on: January 25, 2009, 06:02:24 PM »
Hi guestolo

I downloaded ComboFix and ran it, find the log in 2 post since it is to long to post in one. I couldnt attach the .txt file since its larger then 500kb. I zipped it hope thats ok.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please Help! Spyware/Virus Infection
« Reply #10 on: January 25, 2009, 06:06:45 PM »
Just post it back in mulitiple responses
I can't open the archive, sorry

Or instead of zipping it, upload the file to Savefile.com
No registration required
http://www.savefile.com/selectplan.php

Supply the link to the upload

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline warriorsd

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
Please Help! Spyware/Virus Infection
« Reply #11 on: January 25, 2009, 06:14:22 PM »
Hi guestolo


The link to the .txt log file is:
http://www.savefile.com/files/1981291

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please Help! Spyware/Virus Infection
« Reply #12 on: January 25, 2009, 10:21:52 PM »
Wow, that is a long list, almost appears like you just reinstalled

Can you do the following please
Copy ALL the BLUE text below and Paste to notepad
Don't use anything else than notepad or the script will not work

[color=\"#0000FF\"]
KillAll::
Driver::
GAOPDXSERV
gaopdxvoqylbet
File::
C:\WINDOWS\SYSTEM32\gaopdxixfkgerc.dll
C:\WINDOWS\SYSTEM32\DRIVERS\gaopdxvoqylbet.sys
[/color]
Save this as txtfile on your desktop, with the exact name of
CFScript

Drag CFScript.txt into ComboFix.exe
Combofix will start>>Follow the prompts
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

When finished, it shall produce a log for you  with the same name C:\ComboFix.txt..

Post that log along with a fresh hijackthis log and keep me informed how things are running please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline warriorsd

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
Please Help! Spyware/Virus Infection
« Reply #13 on: January 27, 2009, 03:21:06 AM »
Hi guestolo

Please find below the 2 logs as requested:


ComboFix 09-01-21.04 - Basti 2009-01-27 19:02:34.3 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1023.444 [GMT 11:00]
Running from: c:\documents and settings\Basti\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Basti\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1296 [VPS 090126-0] *On-access scanning disabled* (Updated)
 * Created a new restore point

FILE ::
c:\windows\SYSTEM32\DRIVERS\gaopdxvoqylbet.sys
c:\windows\SYSTEM32\gaopdxixfkgerc.dll
.

(((((((((((((((((((((((((   Files Created from 2008-12-27 to 2009-01-27  )))))))))))))))))))))))))))))))
.

2009-01-25 22:29 . 2009-01-25 22:29    220    --ahs----    c:\windows\klif.spi
2009-01-25 16:27 . 2009-01-25 16:27    <DIR>    d--------    C:\kav
2009-01-24 08:53 . 2009-01-24 08:53    <DIR>    d--------    C:\rsit
2009-01-22 18:32 . 2009-01-22 18:32    <DIR>    d--------    c:\program files\Malwarebytes' Anti-Malware
2009-01-22 18:32 . 2009-01-22 18:32    <DIR>    d--------    c:\documents and settings\Basti\Application Data\Malwarebytes
2009-01-22 18:32 . 2009-01-22 18:32    <DIR>    d--------    c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-22 18:32 . 2009-01-14 16:11    38,496    --a------    c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-01-22 18:32 . 2009-01-14 16:11    15,504    --a------    c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-01-22 07:09 . 2009-01-19 08:35    15,688    --a------    c:\windows\SYSTEM32\lsdelete.exe
2009-01-21 23:25 . 2009-01-19 08:30    64,160    --a------    c:\windows\SYSTEM32\DRIVERS\Lbd.sys
2009-01-21 23:24 . 2009-01-21 23:24    <DIR>    d--------    c:\program files\Lavasoft
2009-01-21 23:24 . 2009-01-21 23:25    <DIR>    d--------    c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-21 23:24 . 2009-01-21 23:24    <DIR>    d--h-c---    c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-01-21 20:40 . 2009-01-21 22:41    <DIR>    d-a------    c:\documents and settings\All Users\Application Data\TEMP
2009-01-21 19:40 . 2009-01-21 19:40    <DIR>    d--------    c:\program files\Windows Defender
2009-01-20 00:43 . 2005-04-25 17:04    <DIR>    d--------    c:\documents and settings\Administrator\Application Data\Sonic
2009-01-20 00:43 . 2005-04-25 16:55    <DIR>    d--------    c:\documents and settings\Administrator\Application Data\Intel
2009-01-20 00:43 . 2009-01-20 00:43    <DIR>    d--------    c:\documents and settings\Administrator
2009-01-17 18:30 . 2009-01-17 18:30    0    --a------    c:\windows\nsreg.dat
2009-01-07 19:09 . 2009-01-19 23:59    <DIR>    d--------    c:\documents and settings\Basti\Application Data\Azureus
2009-01-07 19:09 . 2009-01-07 19:09    <DIR>    d--------    c:\documents and settings\All Users\Application Data\Azureus
2008-12-27 18:26 . 2008-12-27 18:26    <DIR>    d--------    c:\documents and settings\Basti\Application Data\Snapfish

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-25 12:15    ---------    d-----w    c:\program files\Alwil Software
2009-01-18 03:52    ---------    d-----w    c:\program files\Paltalk Messenger
2009-01-17 14:49    ---------    d-----w    c:\documents and settings\All Users\Application Data\WholeSecurity
2008-12-28 12:23    ---------    d-----w    c:\program files\MSN Messenger
2008-12-11 10:57    333,952    ----a-w    c:\windows\system32\drivers\srv.sys
2008-11-29 14:09    ---------    d-----w    c:\program files\ivc
2008-09-27 09:55    32,768    -csha-w    c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012008092720080928\index.dat
.

(((((((((((((((((((((((((((((   snapshot_2009-01-26_ 9.46.42.09   )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-27 08:07:29    16,384    ----atw    c:\windows\TEMP\Perflib_Perfdata_3c4.dat
+ 2009-01-27 08:08:40    16,384    ----atw    c:\windows\TEMP\Perflib_Perfdata_670.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Timezone"="c:\program files\Microsoft Time Zone\TimeZone.exe" [2004-10-19 712704]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2005-04-22 1196032]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-05-27 4269296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-04 344064]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 86016]
"eBayToolbar"="c:\program files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2009-01-18 632048]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-09-29 185784]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\mcupdate.exe" [2005-07-08 212992]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-19 506712]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-27 81000]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 1634304]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\Basti\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
Picture Motion Browser Media Check Tool.lnk - d:\sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-05-25 385024]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-04-25 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 233472]
Ultra Hal Text-to-Speech Reader Startup.lnk - c:\windows\Installer\{96EF451E-A402-44D8-BAEE-D70D558A4122}\New_Shortcut_S1449_0EB7CDB78E0C4A918D2CA535D5B8160C.exe [2007-02-21 40960]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 19:08 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GetRight - Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\GetRight - Tray Icon.lnk
backup=c:\windows\pss\GetRight - Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^palstart.exe]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\palstart.exe
backup=c:\windows\pss\palstart.exeCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalStart.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PalStart.lnk
backup=c:\windows\pss\PalStart.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Unwired Launchpad.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Unwired Launchpad.lnk
backup=c:\windows\pss\Unwired Launchpad.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Basti^Start Menu^Programs^Startup^Unwired Launchpad.lnk]
path=c:\documents and settings\Basti\Start Menu\Programs\Startup\Unwired Launchpad.lnk
backup=c:\windows\pss\Unwired Launchpad.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
--a--c--- 2004-09-13 14:33 155648 c:\program files\Apoint\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2007-04-04 09:29 165784 d:\daemon tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
-----c--- 2004-10-12 19:54 57344 c:\program files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a--c--- 2003-06-26 19:50 212992 c:\program files\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a--c--- 2003-06-25 12:24 49152 c:\program files\HP\HP Software Update\hpwuSchd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 18:57 289576 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
--a------ 2005-07-01 20:22 303104 c:\progra~1\McAfee.com\Agent\mcagent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
--a------ 2005-07-08 18:16 212992 c:\progra~1\McAfee.com\Agent\mcupdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-14 11:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a--c--- 2006-11-28 15:12 222720 c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2006-09-29 18:15 214448 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-09-29 18:15 185784 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a--c--- 2004-01-07 04:01 110592 c:\program files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MskService"=2 (0x2)
"mcupdmgr.exe"=2 (0x2)
"McTskshd.exe"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Vuze\\Azureus.exe"=

R0 Lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [2009-01-21 64160]
R1 aswSP;avast! Self Protection;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [2008-07-03 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [2008-07-03 20560]
R4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-19 921936]
R4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17b9818e-b3fb-11dc-a59e-0012f04276e6}]
\Shell\AutoRun\command - H:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6149c55c-f7e9-11dc-a658-00114374ee38}]
\Shell\AutoRun\command - setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6149c55d-f7e9-11dc-a658-00114374ee38}]
\Shell\AutoRun\command - G:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77254c42-a94d-11dc-a588-0012f04276e6}]
\Shell\AutoRun\command - G:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a133486a-a94b-11dc-a587-0012f04276e6}]
\Shell\AutoRun\command - G:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a133486b-a94b-11dc-a587-0012f04276e6}]
\Shell\AutoRun\command - G:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a133486c-a94b-11dc-a587-0012f04276e6}]
\Shell\AutoRun\command - H:\AutoRun.exe
.
Contents of the 'Scheduled Tasks' folder

2009-01-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-19 08:34]

2008-12-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-11-01 c:\windows\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1128157255.job
- c:\program files\HP\hpcoretech\comp\hpdarc.exe [2003-06-26 19:50]

2009-01-27 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
FF - ProfilePath - c:\documents and settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
FF - component: c:\documents and settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\[email protected]\components\coolirisstub.dll
FF - plugin: c:\windows\system32\Npindeo.dll
FF - plugin: c:\windows\system32\npmirage.dll
FF - plugin: c:\windows\system32\npwmsdrm.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-27 19:08:22
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...  

scanning hidden autostart entries ...

scanning hidden files ...  

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1228)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\SYSTEM32\LEXBCES.EXE
c:\windows\SYSTEM32\LEXPPS.EXE
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\McAfee.com\Agent\Mcdetect.exe
c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\windows\SYSTEM32\WBEM\UNSECAPP.EXE
d:\halreader\HalReader.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-01-27 19:13:44 - machine was rebooted [Basti]
ComboFix-quarantined-files.txt  2009-01-27 08:13:26
ComboFix2.txt  2009-01-25 22:48:34
ComboFix3.txt  2007-10-17 08:49:27

Pre-Run: 2,039,926,784 bytes free
Post-Run: 2,023,432,192 bytes free

265    --- E O F ---    2009-01-25 22:37:30







Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:18:28 PM, on 27/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft Time Zone\TimeZone.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
D:\HalReader\HalReader.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\3 Mobile\3 Mobile Broadband\3 Mobile Broadband.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: PaltalkWebLogin - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Timezone] "C:\Program Files\Microsoft Time Zone\TimeZone.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Ultra Hal Text-to-Speech Reader Startup.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - D:\FlashCapture\fciext.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w...ntrol_en_US.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www4.snapfish.com.au/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.Email Removed.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{86F288A6-0FB3-4F82-B407-44AF60354279}: NameServer = 202.124.68.130 202.124.76.98
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 11668 bytes

Offline warriorsd

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
Please Help! Spyware/Virus Infection
« Reply #14 on: January 27, 2009, 03:23:46 AM »
"Wow, that is a long list, almost appears like you just reinstalled"

I have never reinstalled on this machine actually

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please Help! Spyware/Virus Infection
« Reply #15 on: January 27, 2009, 06:49:31 PM »
It may have been because of updating to SP3, anyways
Can you do the following, I want to double check for hidden files

Download the [color=\"#FF0000\"]GMER Rootkit Scanner[/color]. Unzip it to your Desktop.

[color=\"#FF0000\"]Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.[/color]

Double-click gmer.exe. The program will begin to run.

[color=\"#FF0000\"]**Caution**
These types of scans can produce false positives. Do NOT take any action on any[/color] "<--- [color=\"#0000FF\"]ROOKIT[/color]" [color=\"#FF0000\"]entries unless advised![/color]

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.

    * Click NO
    * In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
    * Now click the Scan button.
      Once the scan is complete, you may receive another notice about rootkit activity.
    * Click OK.
    * GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
    * Save it where you can easily find it, such as your desktop.


Post the contents of GMER.txt in your next reply.

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline warriorsd

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
Please Help! Spyware/Virus Infection
« Reply #16 on: January 27, 2009, 07:14:02 PM »
Hi guestolo
I downloaded the GMER Rootkit Scanner and ran it as instructed.

After double clicking on gmer.exe The program began to run and only the screen below appeared (see link)
I dont believe rootkit acticity was found and i was not asked to perform a full scan.
Please correct me if I'm wrong.

http://www.savefile.com/files/1984239


Thx

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please Help! Spyware/Virus Infection
« Reply #17 on: January 27, 2009, 07:41:09 PM »
I'm not sure why your linking to a Screenshot of your activity

Did you read thoroughly the instructions I posted
Was that screenshot AFTER you clicked on SCAN
I still need you to run the Scan

Please go back over my previous instructions carefully, post the log afterwards
« Last Edit: January 27, 2009, 07:41:44 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline warriorsd

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
Please Help! Spyware/Virus Infection
« Reply #18 on: January 27, 2009, 08:19:46 PM »
Hi guestolo
 
 I tried to follow your instructions but something is not working right i dont think.
I downloaded the [color=\"#ff0000\"]GMER Rootkit Scanner[/color]. Unziped it to my Desktop and double-clicked gmer.exe. The program began to run but stoped after about 2 seconds at the screenshot that i posted earlier. It didnt tell me if rootkit activity was found and I wasnt asked if I  would like to perform a full scan.

    "In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked."
 I couldnt actually see a box that says "Show all"
 When I tried to click the Scan button nothing at all happened. I'm not sure what I'm doing wrong...

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please Help! Spyware/Virus Infection
« Reply #19 on: January 27, 2009, 08:42:24 PM »
Ok, let's try a different approach
Download and save to your desktop
[color=\"#FF0000\"]OTScanIt2[/color][/url]
by OldTimer

Double click on it to Run it and then Extract it to a folder on desktop
Open that newly created folder and double click on OTScanIt2.exe
Leave all defaults selected
Except, change Rootkit Search to YES

Then click on [color=\"#0000FF\"]Run Scan [/color]

When done, it will produce a log
Can you post the contents of that log back here please
A copy of it can also be found it the OTScanIt2 folder on desktop
NOTE: If you do get an error posting this log, please Upload it, but Only if you get an error

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here